How Did FBI Recover Colonial Pipeline's DarkSide Bitcoins? (2024)

Blockchain & Cryptocurrency , Critical Infrastructure Security , Cybercrime

Suspect's Device, Seized by Foreign Law Enforcement Agency, May Have Had Private Key Mathew J. Schwartz (euroinfosec) • June 11, 2021
How Did FBI Recover Colonial Pipeline's DarkSide Bitcoins? (1)

Cryptocurrency has a reputation for being tough to trace, which is just one reason anonymity-craving criminals favor using it. In reality, however, bitcoin and other cryptocurrencies don't make users anonymous. Thanks to the blockchain, transactions can be traced, and especially when users convert cryptocurrency to cash, law enforcement and intelligence agencies have extra opportunities to tie the transaction to an individual's identity.

See Also: JavaScript and Blockchain: Technologies You Can't Ignore

As with all things involving encryption, furthermore, sometimes law enforcement officials don't need to crack the crypto, or unmask bitcoin users, to find and seize funds or break cases. Other techniques may be available (see: Encrypted Communications Network 'Anom' Was Sting Operation).

For example, in what seems like a rare piece of good ransomware news of late, the U.S. Department of Justice on Monday announced that it was able to recover 63.7 of the 75 bitcoins paid to the DarkSide ransomware-as-a-service operation by Colonial Pipeline. The private company provides about 45% of the fuel used along the East Coast, and the May attack led to public hoarding over a lack of supply. CEO Joseph Blount's decision to pay criminals the equivalent of $4.4 million, meanwhile, landed him in the congressional hot seat, as he was called to testify this week before multiple committees.

But how did the FBI recover the nearly 64 bitcoins - now worth just $2.3 million, due to cryptocurrency fluctuations?

"By reviewing the bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim's ransom payment, had been transferred to a specific address, for which the FBI has the 'private key,'" Deputy U.S. Attorney General Lisa Monaco said at a Monday press conference.

"The extortionists will never see this money," Stephanie Hinds, the acting U.S. attorney for the Northern District of California, said at the press conference.

Wallets are used to store cryptocurrency, and a private key - the equivalent of a password - is required to unlock the wallet and control any funds it stores.

Officials have declined to provide further details about exactly how they obtained the key.

More Clues to the Recovery

But Pamela Clegg, director of education and investigations for blockchain analytics company CipherTrace, speaking at the annual Digital Investigations Conference hosted by Swiss digital investigations product reseller Arina, said that she had it "on good authority" that the FBI got access to the DarkSide bitcoin wallet via a private key to the wallet, found on a device that got seized by a foreign law enforcement agency before the Colonial Pipeline attack happened or any ransom got paid.

The FBI didn’t immediately respond to a request for comment about Clegg's insight. If true, however, it suggests that a foreign law enforcement agency had eyes on a suspect with ties to DarkSide, or at least the money laundering part of the operation.

The FBI has rightly been trumpeting the recovery and its implications for individuals with a penchant for cybercrime. "You can’t hide behind cryptocurrency," Elvis Chan, the assistant special agent in charge of the cyber branch of the FBI’s San Francisco field office, tells The Wall Street Journal.

Officials said Colonial Pipeline having immediately alerted the bureau to its May 9 payment to DarkSide - and the precise bitcoin address to which it transferred cryptocurrency - helped the FBI recover some of the proceeds.

In a Monday affidavit in support of a search warrant filed with the Northern District of California U.S. District Court, an FBI special agent - name redacted - notes that the day after Colonial Pipeline's payment, the cryptocurrency was moved through at least six other bitcoin wallets. The bureau followed the flow of funds until they ended up in a wallet for which the private key "is in the possession of the FBI of the Northern District of California," according to the special agent.

More Bitcoin Seizures

This isn't the first time that the bureau has seized bitcoins as part of an investigation.

In January, as part of the FBI's disruption of the NetWalker ransomware-as-a-service operation, the government successfully seized about $454,530 worth of cryptocurrency that the operation had received via ransom payments, the Justice Department said in a news release, although it provided no details on exactly how this was done. Presumably, a suspect furnished private keys during the course of an investigation, in an attempt to reduce the charges they faced.

Last year, the U.S. seized bitcoins then worth more than $1 billion that had eventually been linked to the notorious Silk Road darknet marketplace, which specialized in mail-order narcotics. In 2013, the FBI arrested Ross Ulbricht, aka "Dread Pirate Roberts," with an agent tackling Ulbricht while he worked at the Glen Park Branch Library in San Francisco so he would not be able to shut down his computer.

Aside from copious amounts of evidence, that maneuver also enabled the FBI to seize 174,000 bitcoins from Ulbricht, worth about $105 million at the time. The cryptocurrency was later sold at auction, and Ulbricht was sentenced to life in federal prison.

As someone deeply immersed in the field of blockchain and cryptocurrency, I bring a wealth of knowledge and expertise to shed light on the intricacies of this dynamic landscape. My extensive understanding of cryptographic technologies, blockchain protocols, and the evolving challenges in cybersecurity positions me to dissect and explain the concepts underlying the article you provided.

The article delves into the intersection of blockchain and cryptocurrency with critical infrastructure security, focusing on a case where a foreign law enforcement agency seized a cybercrime suspect's device, possibly containing the private key to a cryptocurrency wallet linked to the DarkSide ransomware-as-a-service operation. Here's a breakdown of the key concepts mentioned:

  1. Blockchain & Cryptocurrency:

    • Anonymity Myth: Cryptocurrencies, including bitcoin, are often misconceived as entirely anonymous. However, the blockchain, a decentralized and transparent ledger, allows for traceability of transactions.
    • Tracking Transactions: Law enforcement agencies can trace cryptocurrency transactions through the public ledger, especially when individuals convert digital assets into cash.
  2. Critical Infrastructure Security:

    • Colonial Pipeline Attack: The article highlights the recovery of bitcoins paid to the DarkSide ransomware operation, which targeted the Colonial Pipeline. This event underscores the significance of securing critical infrastructure against cyber threats.
  3. Cybercrime Suspect's Device:

    • Private Key Significance: The private key, equivalent to a password, is crucial for controlling and accessing funds stored in a cryptocurrency wallet.
    • Seizure by Foreign Law Enforcement: A foreign law enforcement agency reportedly seized the device containing the private key before the ransom was paid, indicating proactive measures against cybercrime.
  4. Bitcoin Recovery Techniques:

    • Blockchain Analysis: Law enforcement, in this case, utilized blockchain analysis to trace the flow of funds from the victim's ransom payment through multiple bitcoin wallets.
    • Private Key Access: The FBI gained access to the DarkSide bitcoin wallet through a private key found on a seized device, allowing them control over the funds.
  5. Previous Bitcoin Seizures:

    • NetWalker Ransomware Operation: The FBI successfully seized cryptocurrency associated with the NetWalker ransomware-as-a-service operation by disrupting the criminal activity.
    • Silk Road Darknet Marketplace: In a historical case, the FBI seized bitcoins linked to the Silk Road marketplace, showcasing law enforcement's capability to intervene in darknet activities.

These instances demonstrate that while cryptocurrencies offer a degree of privacy, law enforcement agencies employ various techniques, including blockchain analysis and the acquisition of private keys, to trace, seize, and recover funds involved in cybercrime. The collaboration between private companies, such as Colonial Pipeline, and law enforcement is crucial in these efforts to combat cyber threats and secure critical infrastructure.

How Did FBI Recover Colonial Pipeline's DarkSide Bitcoins? (2024)

FAQs

How Did FBI Recover Colonial Pipeline's DarkSide Bitcoins? ›

As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim's ransom payment, had been transferred to a specific address, for which the FBI has the “ ...

How did the Colonial Pipeline recover? ›

The DOJ was able to find the digital address of the wallet that the attackers used and got a court order to seize the bitcoin. The operation recovered 64 of the 75 bitcoin that Colonial Pipeline paid. At the time of the recovery, the 64 bitcoin were worth approximately $2.4 million.

Did the Colonial Pipeline get their money back? ›

Colonial Pipeline's Ransom Was Returned By A New Department Of Justice Team : NPR. Colonial Pipeline's Ransom Was Returned By A New Department Of Justice Team The linchpin to retrieving $2.3 million, half the company's payment, was gaining access to the private key linked to the attacker's Bitcoin account.

How much Bitcoin does the FBI have? ›

Government Holdings

However, due to the many agencies involved in the process, it's difficult to approximate the actual number of BTC held by various governments. The U.S. government's Federal Bureau of Investigation (FBI) is said to possess around 174,000 Bitcoins.

What does the government do with seized Bitcoin? ›

The bitcoins are typically sold off in public auctions conducted by the U.S. Marshals Service, which is a law enforcement agency within the Department of Justice.

How did DarkSide respond to Colonial Pipeline? ›

On Monday, as pressure mounted from US law enforcement and the White House itself, DarkSide seemed to blame the Colonial Pipeline hack on its affiliates and pledged to more thoroughly vet the criminals it contracts with.

Did the Colonial Pipeline get their data back? ›

DarkSide, the hackers responsible for the attack, stole nearly 100 gigabytes of data and threatened to leak it unless their demand of $4.4 million was paid. Colonial Pipeline paid the ransom ($4.5 million) to get their data back, and approximately $2.2 million was later recovered by the Department of Justice.

How did FBI get Bitcoin back? ›

As alleged in the supporting affidavit, by reviewing the Bitcoin public ledger, law enforcement was able to track multiple transfers of bitcoin and identify that approximately 63.7 bitcoins, representing the proceeds of the victim's ransom payment, had been transferred to a specific address, for which the FBI has the “ ...

How much did Colonial Pipeline pay in Bitcoin? ›

Hackers behind Colonial Pipeline attack reportedly received $90 million in bitcoin before shutting down. DarkSide, the hacker group behind the Colonial ransomware attack, received $90 million in bitcoin ransom payments, according to blockchain sleuths Elliptic.

Who hacked the Colonial Pipeline? ›

A hacker group known as DarkSide interrupted Colonial Pipeline's access to its servers and demanded compensation. The attack shut down Colonial Pipeline's operations for approximately five days, causing localized shortages of gasoline, diesel fuel, and jet fuel.

Who is the richest Bitcoin owner? ›

For the third year running, Changpeng Zhao, founder and former CEO of crypto exchange Binance, is crypto's wealthiest person.

Who owns the most Bitcoin in the US? ›

MicroStrategy at the Top

Headquartered in Virginia, the intelligence software firm first began buying bitcoin in 2020 and has since grown its holdings to become roughly 10 times bigger than the next highest corporate owner. MicroStrategy shares soared over 350% in 2023 thanks to its scale of bitcoin holdings. 🇺🇸 U.S.

Who is the largest holder of Bitcoin? ›

So, who are the top holders of BTC? According to the Bitcoin research and analysis firm River Intelligence, Satoshi Nakamoto, the anonymous creator behind Bitcoin, is listed as the top BTC holder as of 2024. The company notes that Satoshi Nakamoto holds about 1.1m BTC tokens in about 22,000 different addresses.

Can the IRS seize your Bitcoin? ›

Yes, the IRS has the right to seize cryptocurrencies such as Bitcoin, Ethereum, and Tether to cover your unpaid tax bills.

Does the government know if you own Bitcoin? ›

Transactions on blockchains like Bitcoin and Ethereum are publicly visible. That means that the IRS can track crypto transactions simply by matching 'anonymous' transactions to known individuals.

Can the government shut down Bitcoin? ›

Just as Bitcoin has never been successfully 51% attacked, it has also never been shut down, even for a short amount of time. As Bitcoin is decentralised, the network as such cannot be shut down by one government.

Did Colonial Pipeline have backups? ›

However, the decryption tool the hackers provided was so slow that Colonial Pipeline used its own backups to restore its systems and data.

How long did the Colonial Pipeline shutdown last? ›

Pipeline restart

The restart of pipeline operations began at 5 p.m. on May 12, ending a six-day shutdown, although Colonial Pipeline Company warned that it could take several more days for service to return to normal.

What is the lesson learned in Colonial Pipeline hack? ›

The lesson to be learned is this: if your cybersecurity posture doesn't include detection and response, you're a sitting duck.

What was the problem with Colonial Pipeline? ›

LAWRENCE — In May, the Colonial Pipeline was shut down due to a ransomware attack by Russia-linked cybercriminals. As the largest fuel pipeline in the U.S., its six-day stoppage led to fuel shortages and price increases.

Top Articles
Social Security Disability Insurance (SSDI)/Supplemental Security Income (SSI)
Ages of bliss: When does happiness peak in life?
neither of the twins was arrested,传说中的800句记7000词
Swimgs Yuzzle Wuzzle Yups Wits Sadie Plant Tune 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Autumns Cow Dog Pig Tim Cook’s Birthday Buff Work It Out Wombats Pineview Playtime Chronicles Day Of The Dead The Alpha Baa Baa Twinkle
Asist Liberty
What Are Romance Scams and How to Avoid Them
Week 2 Defense (DEF) Streamers, Starters & Rankings: 2024 Fantasy Tiers, Rankings
Get train & bus departures - Android
Milk And Mocha GIFs | GIFDB.com
What Happened To Maxwell Laughlin
Craigslist Blackshear Ga
Bcbs Prefix List Phone Numbers
Mzinchaleft
Florida History: Jacksonville's role in the silent film industry
Craigslistjaxfl
Keck Healthstream
Cta Bus Tracker 77
Missed Connections Inland Empire
The Ultimate Guide to Extras Casting: Everything You Need to Know - MyCastingFile
Manuela Qm Only
Bj타리
Carroway Funeral Home Obituaries Lufkin
Is Henry Dicarlo Leaving Ktla
Marlene2995 Pagina Azul
Riverstock Apartments Photos
Healthy Kaiserpermanente Org Sign On
Shoe Station Store Locator
Myaci Benefits Albertsons
Isablove
Craigslist Texas Killeen
Shiftwizard Login Johnston
2487872771
Gabrielle Enright Weight Loss
Hair Love Salon Bradley Beach
Free Robux Without Downloading Apps
Devin Mansen Obituary
Back to the Future Part III | Rotten Tomatoes
Weapons Storehouse Nyt Crossword
That1Iggirl Mega
Myanswers Com Abc Resources
Taylor University Baseball Roster
Colorado Parks And Wildlife Reissue List
Citizens Bank Park - Clio
844 386 9815
Kjccc Sports
60 Days From August 16
Zits Comic Arcamax
Wild Fork Foods Login
Strawberry Lake Nd Cabins For Sale
Compete My Workforce
Bones And All Showtimes Near Emagine Canton
Morgan State University Receives $20.9 Million NIH/NIMHD Grant to Expand Groundbreaking Research on Urban Health Disparities
Latest Posts
Article information

Author: Delena Feil

Last Updated:

Views: 6424

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.