28 ms·
No, you couldn't have made more money than the Twitter hacker
- blatchcorn 6y agoNo one really knows and it can't be proven one way or the other, so this isn't worth debating
- tlb 6y ago(Also true of 99% of all the topics people debate) As far as this topic goes: you could prove the argument false by doing a better hack and making a lot more money. Or we could gain confidence in it as years pass and hacks happen but no one makes a lot more money.
- dumbfoundded 6y agoI'm guessing they could've inflated the price of bitcoin as well. Like have some major fund managers say they were moving into Bitcoin in a big way.
- ALittleLight 6y agoThe point about how you couldn't make money on the stock market is that the SEC has tools to catch insider trading? You could as easily say you couldn't hack Twitter because the FBI has tools to catch hackers. Many people, hundreds if not thousands, have long positions on Hertz. They may be able to find something suspicious, but not anything that could differentiate you from "I read on wallstreetbets that buying these Hertz calls was a good idea." Especially if you seed your account with a few similar bets first.
- AndrewBissell 6y agoHundreds of thousands may have long positions on HTZ, but the vast majority are all day trading punters with relatively small positions that wouldn't net all that much money. The intersection of those with large enough positions to yield a large profit and those who perfectly timed their sale at the very peak before the market realized it was a fake rumor would be a lot smaller than you might think.
- Sebb767 6y agoYes, but for that you first need a lot of money (especially if you're buying other positions as 'cover') and a lot of preparation time (as going deep into puts just before the hack is extremely suspicious). And then you're still in hell, because instead of having a total damage amount of 120k$ plus some vague twitter downtime you now have cost investors millions of dollars and are in the highly illegal territory of stock market manipulation, instead of a rather simple scam with modest damage. Also, saying "I've read that on WSB" is nice, but the FBI is still going to take your equipment for a nice inspection. No fun, I can tell you that.
- mrfredward 6y agoTo trade you need to open an account with your name, social security number, address, occupation, and other details. Your broker will have to verify most of these details under federal anti-money laundering regulations. Immediately following the hack, your brokerage will be asked to provide a list of people who traded around the hack and benefited. All of your personal information will be in the hands of the SEC and FBI within a few days, and you will be one of very few people with no trading history who made a million dollars out of no where. Yes, the FBI can do much more with having all your personal and financial information handed directly to them then they can with the IP address of a VPN exit node in a server log. There is no comparison.
- falcolas 6y agoPerhaps they couldn't have made more money, but they could have devastated the global market with a few well placed rumors from "verified" tweets. That frightens me more.
- dhosek 6y agoOr started WWIII by provoking North Korea into a first strike with a tweet from Trump.
- netsharc 6y agoDespite NK's paranoia, I think even they are clever enough to see if Trump's bark/tweet would have a bite. I don't think they would strike before being certain about an attack.
- deleted 6y ago[deleted]
- AndrewBissell 6y agoYeah the only way I can imagine that you might have been able to get profits out of the regulated markets without getting caught would be to put on a short position a few weeks in advance and then send out a bunch of fake scary geopolitical items from the verified news accounts like Bloomberg's. And even doing it this way, if that's the only activity in your account the SEC still might find you.
- VBprogrammer 6y agoI find it interesting that there were at least 100 people who both had enough money lying about in BitCoin (or at least, where able to figure out how to buy bitcoin on short notice) who intersect with the group of people who will fall for something which has all of the hallmarks of a scam.
- dhosek 6y agoI don't. Bitcoin as investment is already pretty scammy.
- roywiggins 6y agoIf I were the scammer I'd send some money to myself to make it look like more people were sending money than really were. Social proof, etc.
- ehsankia 6y agoDidn't the address also send back 2K to a few people? Making your theory even more plausible.
- Avicebron 6y agoNot sure if they did or not. But when this scam was around on Runescape that was generally the way it worked.
- rcxdude 6y agoYou don't need to send it any actual users. Just set up some transactions between wallets you control and use some sockpuppet accounts to make apparent 'winners'.
- kaicianflone 6y agoWait til the next runescape scam - buying $TSLA 2400 - just send it to my account here first and I will send you the money in BTC.
- 6y ago
- bmmayer1 6y agoStep 1: buy TSLA puts Step 2: @elonmusk: "I'm retiring effective immediately. Don't believe what you read in the news tomorrow." Step 3: Profit
- AndrewBissell 6y agoAs the article points out, if you do this in enough size to make serious money, you're highly likely to get caught.
- benlumen 6y agoBut until you did, you would have made more money than the Twitter hacker.
- SilasX 6y agoYes, but there's a lot of room between ~$150k (that the defrauded bitcoins are worth) and what counts as "serious money" that will get you caught -- contradicting the clickbait thesis of "you couldn't have made more money" than the hacker. This is especially true in an environment of a stock that's heavily shorted already. And if you really want to be pedantic, the hacker has made $0 from it so far, since the Bitcoins haven't been transferred anywhere to cash out. Which is pretty easy to beat :-p
- AndrewBissell 6y agoThe SEC frequently goes after proverbial insider trading dentists who make ill gotten gains in the $100K range. Given the intense focus there would be to catch the market manipulators, a sub-$1 million haul wouldn't be much protection.
- SilasX 6y agoThose types are caught because they're people who do virtually no active trading and then buy an individual stock while related (and connected by phone/email contact) to an insider. Not day traders who have joined a massive herd of the world's favorite stock to short.
- tyingq 6y agoI think I could have rotated/edited the BTC addresses faster by editing or deleting/resending tweets and taking over new accounts in a random pattern. The money stopped flowing in pretty quick when the popular exchanges blocked sending to the destination address.
- felixarba 6y agoTesla is one of the most heavily shorted stocks, and earning 1 million honestly wouldn't even be such a big deal considering how many instititutional and retail investors are swing trading it. Unless you bought some ridiculously short dated options, in huge amounts and then immediately faked Elon's tweets and cashed out, you could've made 500k easily no one would even think twice about it.
- jamiequint 6y agoThe SEC would think twice about it after it became obvious what was going on. This stuff gets actively investigated.
- tick_tock_tick 6y agoNot with earning in the next few days now is a reasonable time to gamble.
- SilasX 6y agoThey're going to heavily investigate everyone that made a half million on a super high volume, widely shorted stock in a time of extreme volatility? To the point of finding a smoking gun that connects them to the hackers? I'm happy to be proven wrong about this but it seems implausible unless they were sloppy.
- AndrewBissell 6y ago> They're going to heavily investigate everyone that made a half million on a super high volume, widely shorted stock in a time of extreme volatility? These arguments all seem to be operating on the assumption that there would be a large number of day/swing traders who would exit their positions with perfect timing, but this is unlikely because they wouldn't have the knowledge that the price move was ephemeral and driven by a false rumor. The number of people who made a half million off it would be a lot smaller than you think.
- SilasX 6y ago
- usmannk 6y agoTheir whole point on the stock market is this: > The big issue with all of these is that it’s very difficult to participate in the stock market anonymously. The SEC has all sorts of monitoring in place to catch more common forms of insider trading and fraud and you can guarantee that they would conduct a long, thorough investigation into a hypothetical hack-based market fraud. Unlike Bitcoin transactions, wire transfers and stock purchases can be reversed after the fact, and the exposure and risk go way up when you’re actually working with US dollars. But this is divorced from reality. In reality you'd be one of thousands of people holding HTZ calls or TSLA puts in your Robinhood account. You could make a huge payday and be indistinguishable from the crowd. With the crypto scam, one person will eventually have to turn this BTC into fiat. With market manipulation, you've made thousands of retail investors indistinguishable from yourself rich. Which one sounds like a better idea?
- jamiequint 6y agoAnonymizing BTC is a lot easier than hiding from the SEC. There are that many people holding massive amounts of short-term TSLA options (enough to make >$500k on a single day movement) that the SEC can't look at each of them.
- Sebb767 6y agoI highly doubt that the SEC wouldn't put the required resources into this. After all, this would've caused tens of millions in damages, rather than the mediocre 100k$. Also, you could filter for new traders and traders overly invested in TSLA. Giving the rather mediocre execution (i.e. single Bitcoin address), I doubt the attacker had a lot of time and capital upfront to hide in these masses. Lastly, stock market transactions can be paused and are reversible - there's a good chance of a circuit breaker hitting or a reversal happening with that blatant market manipulation.
- JumpCrisscross 6y ago> the SEC wouldn't put the required resources into this Keep in mind that a lot of the SEC's enforcement breadth comes from brokers' compliance departments. Any time anyone makes an unusual profit around corporate actions, the SEC basically requires a thorough investigation by the broker's compliance staff.
- quotemstr 6y agoThe blackmail option isn't mutually exclusive with the BTC scam. Maybe the attackers slurped up all the DMs and will use or sell them later.
- paconbork 6y agoHeck, you could even sign a message saying you own the DMs with the private key that corresponds to the address that all the hacked accounts posted if you wanted to sell them / use them for blackmail
- ehsankia 6y ago> They managed to run off with a little over $100,000 before Twitter got the situation under control. Not quite, I believe most major exchanges banning the address probably did a lot more to control the situation. Twitter took way way too long to react and their best course of action was just blocking all tweets from verified users...
- toephu2 6y agoThey made off with $117k in their bitcoin wallet, which is not connected to any exchanges: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
- hajimemash 6y agoIt is since a decent chunk'o people be on that convenient Coinbase Wallet-aaS and if CB be like "hold up this a scam hunny" all that sweet koin finna stop rollin' in
- Mojah 6y agoOne point I don't see made often: in order to short or long any market, you need _initial_ capital too. This whole "ask 1 BTC to get 2 BTC" requires 0 initial upfront costs from the attacker. It's a win/win situation, they can't lose. They've invested nothing in their scam to begin with.
- ZachPruckowski 6y agoNot just any initial capital, clean US dollars in a brokerage account under somebody's real name. You can't use BTC or rubles or drug money or whatever.
- varbhat 6y agoActually, earning money by cheating is bad.
- AbraKdabra 6y ago> and it must not be Why not?
- varbhat 6y agoMoney can be goal but not the prime goal. Prime goal must be their interests.
- synaesthesisx 6y agoThe SEC fails to catch or even detect the vast majority of market manipulation and insider trading. A volatile stock like Tesla has so much volume that a large amount of contracts (calls/puts) wouldn't even look unusual. They most certainly could have gotten away with some form of manipulation using Elon's (or someone else's) account and gotten away with it.
- SilasX 6y agoBecause most attacks aren’t this high profile. In cases like this, they’ll be a little more determined.
- marcinzm 6y agoWe still don't know if the hackers didn't steal all the DMs to sell on the dark web. They basically can prove without a shadow of a doubt to anyone that they were the hackers involved (by sending BTC from the publicized address). That removes any questions of authenticity for potential DMs and is likely to increase the price. They or someone else they resell to can then go about the blackmail aspects of the whole thing. If they didn't mean the BTC address to be an authenticity stamp after the fact it seems silly to not have varied it to get around blocks. edit: They can also use it for blackmail even if there's no incriminating DMs. By making up fake DMs and then using the authenticity stamp to "prove" they were authentic. Could cause quiet a bit of chaos if released in the right way and be worth something to someone.
- dickjocke 6y agoI doubt Apple or Bill Gates have very many incriminating Twitter DMs. Kanye is a non-factor, nobody serious cares what a, respectfully, manic-depressive is DMing about. Elon Musk might have some suspect DMs, but honestly I think his crazy Twitter behavior is priced into TSLA already.
- marcinzm 6y agoLike I said, you don't need incriminating DMs, you just need the threat of incriminating DMs and enough authenticity proof to cause chaos. I can imagine certain governments who would pay money to have incriminating DMs about Joe Biden be released right before the election.
- deadso 6y agoThis assumes they could only access DMs of people that sent out the spam (which includes Biden). In reality they could have pulled Trump and friends' DMs also, who have a history of using twitter for official use and seem to have questionable operational security.
- jasonhansel 6y agoIndeed. Who knows what else they did while spamming those accounts? Hopefully Twitter has some very good auditing/logging in place...
- rootsudo 6y agoI disagree, with the stock market manipulation. The idea isn't to be anonymous per se, it is to blend in with the crowd. You join a few communities, you can easily, easily pull the Casino Royale short position/puts. Say that production is halted, that you discovered faulty accounting, immediate recall, etc. Tesla would've plummeted. And that's if you want to blend in with the crowd of volume and people holding puts, which, are not that expensive, especially if you push out a few weeks. -- With bitcoin, it is not anonymous. You will have a pain to cashout 100k+ of bitcoin. The address is now literally blacklisted, the coins will be forever tracked, exchanges blocked and whenever there's movement, ironically, twitter threads will appear similar, if not akin to bitmex margin calls. Any localbitcoin dealer worth their salt, would flag it because even if it's in escrow, it is most likely that small amount would blacklist their own account, especially since most traders are cheap and will send from exchange>localbitcoin escrow.
- notyourday 6y ago> The idea isn't to be anonymous per se, it is to blend in with the crowd. You join a few communities, you can easily, easily pull the Casino Royale short position/puts. This significantly underestimates effectiveness of market surveillance tools.
- b1ur 6y agoEven so, I think that there's enough random idiots making random trades on the market that you could get away with it. You could anonymously post something that sounds vaguely credible on reddit's WSB board and use that as your justification if the SEC asks. If you do a good job, you've just convinced 100 people to be your patsies (and made them a handsome sum in the meantime)
- notyourday 6y agoThat is predicated on dumb money not trading in patterns that are visible to market surveillance. We know for it not to be the case. First of all, market surveillance is going to score trades based on profitability and on the expected value of outcomes. If the actor in question does not have a habit of trading options in certain patterns, he will be sticking out of the sea of other bets, significantly reducing the number of actors he can hide in. This will flag money movement. This will flag strange account funding. This will flag strange volume. This will flag strange time the order was placed in compared to the usual trades of this individual. > If you do a good job, you've just convinced 100 people to be your patsies (and made them a handsome sum in the meantime) This will probably not increase but decrease randomness. The trick of avoiding being picked up on a market surveillance is not to hide among others who do what one does rather it is to hide a specific action one performs among a pattern of one's typical actions. That is why a hacker who does not normally trade options will most likely get nailed should he win based on a hack.
- lordnacho 6y agoI think they could have made more with just better ad copy. Send 1 get back 2 just stinks so much like a scam, most people wouldn't do it. What if you just asked for a donation in some good cause, and frame it as a contest between Elon and the other billionaires? Also use different addresses per account. Should be really easy.
- recursivecaveat 6y agoI think the hacker has to be some insider who knew their window was closing quickly, because the ad copy does seem incredibly lazy. Like if you had Musk 'crowdfund' the next Tesla, while Biden announces that the USD will be pegged to Monero if he's elected, and Apple takes 'deposits' for the next iPhone, it seems like you could have done much better. Maybe we're overestimating the relative value of the big-name accounts though.
- ss2003 6y agoI like that idea, Bidden tweets he's thinking of some pro-crypto policies if elected, donate to his election campaign now if you want this to happen!
- 0x00000000 6y agoAn ICO for a new fake ERC20 token would probably have convinced far more people to send far greater amounts than what they did.
- vchak1 6y agoWhy not combine the methods? Use the BTC stuff to fund the stock stuff, and have different twitter accounts do different things. Biden's for BTC, and Musk's for stock market manipulation. Plus steal the DM's for sale on the dark web.
- ve55 6y agoDisagree strongly. The main reason is one needs to understand how much leverage you can gain by successfully playing very risky far-out-of-the-money call/put options, but also that the volume on stocks (and derivatives) like $TLSA is insane, and millions are being traded in it every single minute. $TSLA OTM call/put options with the right tweet could easily make someone millions, and the liquidity and open volume is crazy enough on them that it'd be very hard to be found out. If that isn't good enough, you could post rumors and tweets beforehand to cause many others to also buy in, and there would be no way to reasonably separate who was behind it and who just joined in on it. For example: 1) Tweet as Elon musk "Very good TSLA news coming up" 2) many more people buy calls, including yourself 3) Tweet as Elon musk "TSLA earning are going to beat by so much" 4) sell your calls for puts 5) Tweet very negative/offensive/terrible content
- clarkmoody 6y agoYou have total control of 15 Twitter accounts of your choosing for 90 minutes. What do you do? This Twitter hack could have changed history, could have made some group of insiders fabulously wealthy, could have started a war, etc. Yet they "waste" it on an obvious scam. My competing hypotheses: - The hacker got way in over his head and panicked (the wasted opportunity branch) - The hacker siphoned the DMs from the hacked accounts (and others that did not tweet out the scam), and this is just the beginning - There are larger forces at work, and this was a demo for a larger client and is part of a longer play
- shadowgovt 6y agoOccam's Razor suggests the likeliest scenario is that the hacker got in way over his head and panicked. Most hackers aren't international criminal masterminds; they're infosec warriors or, fundamentally, bored clever people who enjoy the puzzle of finding out the true limits of what can be done with the technology in front of them. The name of 2600 magazine is inspired by the story of people who---having discovered the worldwide telecommunications grid could be manipulated by properly-sequenced audio tones---used that knowledge and power to make free long-distance phone calls.
- Sebb767 6y agoAdditional hypotheses: - The hacker intentional choose a rather low-crime way with modest damage amount so that Twitter catches most the heat and he doesn't have all three letter agencies hunting for his head. - He knows that OP-SEC is hard and choose a way that was simple enough to avoid traps.
- katmannthree 6y agoCertainly possible but I think the bar has absolutely been passed for three-letter agency involvement.
- Sebb767 6y agoSure, but millions of stock market damages are another league than a bit of chaos on Twitter and 120k$ in scammed money. You can easily find a car which is worth more. So yes, there's definitely going to be a search, but he could've gotten far more heat.
- vmception 6y agoHey guys, so articles like this are no better than long winded hackernews comments. Which we all debate the semantics of and unceremoniously decide are wrong. So lets treat this article that way: You absolutely could make money in the stock market instead and it has happened before buy trading the indices. The "problems" with individual companies don't exist when trading indices like the SPX or VIX. This has already happened before, Associated Press' hacked twitter account sent out something alarming sending the indices in a brief frenzy. Like long enough for trading to react before correcting.
- meowface 6y agoSure, that is true, if you make a bunch of extra assumptions (resides in an applicable country; has a lot of fiat capital already; has a history of trading; has all the necessary financial knowledge and capabilities), and if you don't factor in the probabilities of getting caught. On paper, the stock strategy could make more money. In practice, I think it's extremely unlikely it would be the optimal strategy here, or even a decent strategy. The maximum potential reward would be higher, but the expected value would be lower. (Perhaps it'd be negative, even, depending on the probability assigned to imprisonment and asset seizure.) I think the attackers chose pretty much the best possible strategy if their sole goal was maximizing profit and minimizing risk of getting caught. Someone else suggested maybe setting up a fake call for charity donations, which might have worked even better, but overall I think they picked the smartest plan.
- azangru 6y agoI am just surprised that these tweets actually worked. It would have made total sense if the hijacked accounts suggested doubling others' donations to certain charities, as we have seen played out in the beginning of June. In fact, the first time I saw those tweets, with their "giving back" theme, I misread them as meaning exactly that, doubling donations to charities. But instead they were proposing to immediately send the money back, doubled. Asking people for money first is hardly a believable "giving back" offer; it should have raised so many eyebrows and red flags. Especially coming from Biden's account — I might almost believe it coming from Elon, but for Biden that would be completely out of character; he wouldn't have the imagination.
- Avicebron 6y agoIt could have been a demonstration of power, maybe a state actor was testing their team, and they decided to Runescape meme on Twitter to show they could make a bigger play later.
- surround 6y agoNo, the hacker isn’t going to have a hard time cashing out their Bitcoins. All they have to do is pass the coins through a few Bitcoin tumblers before exchanging it for cash. https://en.wikipedia.org/wiki/Cryptocurrency_tumbler https://en.wikipedia.org/wiki/Cryptocurrency_tumbler
- hnick 6y agoA $100k windfall income would have to be explained to tax authorities in most places won't it? Taking it as hard cash sounds risky or laborious. Taking it to a bank account will trigger red flags. A story will have to be told that makes sense and holds up. Converting it slowly over years is an option, but I'd put that in the 'hard' category especially if you keep doing this and sending the balance up.
- adrr 6y agoWith my experience at running technology and security at a large fintech. It would relatively easy to purchase stock anonymously with a stolen identify. KYC(Know your customer) checks that online financial firms use to verify identity revolve around credit report data that can easily be bought or hacked. Think of all the online companies that offer access to your credit report. Any foreign actor could get a brokerage account with relative ease compared to hacking a major social network. For the SEC to investigate, they would have to go through multiple companies to find the account. First would be the exchanges to search for suspicious trades. Next the clearing brokerage firms which online fintechs use to do the trades and then lastly the the fintech that stolen account was created on. Much longer to investigate than it takes for the money to settle from the trade and to get money out of the account. Also there is a good change that you wouldn't trip any of the online FI's monitoring. If the money went out to the same account it came in on, that isn't that suspicious and happens all the time. The cash transfers would generate SAR(suspicious activity report) but still that would take a while for government to process and investigate. Authentication of a person is broken in the US and needs to be fixed. We can't rely on credit report data and SSN.
- ttul 6y agoI would not target stocks - that requires too much capital. Rather target currencies. A retail investor can leverage currency transactions 100 to 1 -- and such speculators are numerous. Also, Forex runs 24x7. What if the US Federal Reserve had tweeted out a link to fake economic data suggesting an enormous fall in the USD was around the corner? Algorithmic trading could shift the USD by $0.01, which when multiplied 100x could have a pretty large impact on your USD/EUR play.
- Exuma 6y agoCondescending headlines are so stupid. Right...
- easton_s 6y agoI got 5k for an OAuth bypass on one of Google APIs. The leaked data was much less harmful then being able to post on any twitter account.
- sakopov 6y agoThis identical scam has been running in full force on YouTube ever since Bitcoin's halving event. I wonder how much this contributed to the lack of success of the Twitter scam.
- victoriasun 6y agoTIL I'm the only person on HN who thinks that making 100k in 15 minutes is a pretty great feat.
- jobigoud 6y agoSurely finding the vuln and exploiting it in a way that can't be traced back to them took way longer than 15 minutes.
- SilasX 6y agoIf successful and untraceable, yeah I agree with you. (Great in the sense of impressive, of course, not morally laudable.) But, in fairness, they haven’t actually made it yet though: it’s not cashed out and everyone’s watching the address like a hawk.
- ALittleLight 6y agoThe transfer happened in fifteen minutes. Unknown how long it took to engineer. Regardless, you compare things to their alternatives. Here the alternatives are: make much more money, make less money, don't commit crime. The first and last alternative each have logical reasons to recommend them, the middle one doesn't.
- y-c-o-m-b 6y agoOne thing to consider: the $100k gained in this attack is completely random. The attacker(s) had no way of knowing they would get that much. It could just as easily have been $5k or less. People are framing it like the attacker knew they'd be getting that much coin.
- TwoBit 6y agoI think the hacker(s) expected more than 100K.
- chucksmash 6y agoI don't see how one can say "the SEC is good at investigating stock market shenanigans, therefore you couldn't possibly profit that way, end of story." That was a pretty common take in the other thread as well. This is not insider trading. When an insider tips off an associate, investigators have full information on the pool of insiders. "Who knew about this ahead of time?" is a strong filter. Assuming the attacker had perfect opsec and the attack itself doesn't leave evidence that exposes them, they live in a much larger and murkier pool. Additionally, the attacker might have known of this vector months ahead of time. This gives them time to lay groundwork, find accomplices, and prepare. Quick thought experiment: There is a bar I used to go to pretty often. It was cash only. Aside from cell tower pings, possible Google Maps location history, and N days worth of security footage, there is nothing tying me to that bar. I've known one of the bartenders there for five years now. We grew up in the same town. We're not Facebook friends, we don't talk on the phone, but we've now known each other in this context for quite a while. If you had a perfect "back home" social graph, we're probably ~3-4 degrees of separation. Linking us to one another locally starting from his perspective would involve very invasive investigation (i.e. putting names to faces for everybody on the N days of security footage that bar has archived, a subpeona for bulk subscriber data of people who have been to that bar, etc). If I try to involve him in my market manipulation scheme, there's the risk he turns me in outright or that he rips me off and keeps the money for himself. Basically, the criminal conspiracy version of counterparty risk. Set that risk aside for a moment. Assume that he's on board with the plan. Also assume that I, as the attacker, leave no digital evidence pointing back to me. Think about how egregious his trading behavior would have to be to bring enough scrutiny upon himself that the SEC has people reviewing this bar's security footage, building profiles of the randos who have been to that bar, all that. I don't claim that "tipping off the bartender" is the world's most original securities crime, but unearthing that connection is a much more involved process than the cases of "spouse/sibling/college roommate/tennis partner of CEO bought OTM options a week before acquisition was announced." X people make, say, 1-10 million dollars off of a zany bet on stocks. Imagine how obvious your trade would have to be such that Y years from now, one of those new millionaires moves back to East Bumblef and makes a money-losing real estate transaction with another East Bumblefian (say, moi), and the SEC jumps over a hedge like "ah-HA! We've been watching your accounts this whole time, that other East Bumblefian knows how computers work and lived in an apartment four blocks from your old workplace in 2015, nobody could possibly negotiate this poor of a land deal, checkmate!"
- ben174 6y agoIf this article is accurate, and the hacker did consider alternative ways to make more money, or legal ways, then this really puts the blame on Twitter. If their bug bounty wasn't absolutely ridiculously low ($7,700 for oauth account takeover), then they could have prevented this. Essentially they're putting the value of security for their entire user base as $7,700. This bounty should be in excess of $1 million easily.
- sfkdjf9j3j 6y agoWould a social engineering attack even qualify for the bounty program?
- abhorrence 6y agoTypically social engineering attacks are excluded. However given the large scale of this attack, there’s an argument to be made that there should be systems in place to limit the damage one rogue (or manipulated) employee can do.
- mrfox321 6y agoThat assumes that the bounty should approximate the expected payout from some lawsuit against twitter plus loss of future cash flow due to the vulnerability. If that value is still small, then there is no incentive to raise the price of the bounty.
- rmason 6y agoThey didn't mention the most nefarious thing you could do - spring an October surprise and throw a presidential election in the U.S. I'm basing this on the fact that both the Trump and Biden campaign staffers are probably sending a lot of DM's. Releasing the most embarrassing information at the right time could prove pivotal.
- paxys 6y agoThat is very unlikely. There's no serious internal communication happening over Twitter DMs.
- duaoebg 6y agoI wonder if people are paying more in a patron or only fans way. Supporting it as an attack on their least favorite blue check mark. Also, I wonder if more of the value of the blackmail could captured with an auction mechanic; as in donate to X for public release or donate to Y to keep it private at a certain time the account with the most money wins. This mechanic could be manipulated behind the scenes for even more money.
- aripickar 6y agoI disagree with some of the things that this article is saying since there are ways to fundamentally do the same scam, but not make it so incredibly obvious that it's a scam. Or, the user could cause disruption in other markets that are not obvious. 1. Change the order of who they targeted. The hacker started by attacking Elon Musk and a few other high profile celebrities. But, later in the hack, they tweeted from Mr. Beasts profile, a Youtuber who is known for giving away large sums of money. If they had started with Mr Beast, then there would be a lot less skepticism and a lot more confusion, since it would have been a lot more likely to not actually be a scam in users minds. 2. Target poorly regulated markets. Theres a decent amount of Liquidity on the betting market for the US presidential election on betfair. Have Biden tweet something out about him dropping out due to heart problems, have the Reuters/AP tweet a breaking news article confirming it, bada bing bada boom millions of dollars coming your way. Its not like the only liquid markets are well regulated. It looks like a hack thats designed to scare people for political points, but you can make money off it.
- ayqod 6y agoSEC have no time for that. Don't forget old days: The Securities and Exchange Commission is drawing Republican criticism following reports that senior agency staff used government-issued computers to surf pornographic websites, according to the Associated Press. An internal memo obtained by the AP said the SEC's inspector general has investigated 33 employees for looking at porn in the past five years, and 31 of those probes occurred since the financial turmoil began. This conduct violates governmentwide ethics rules, the memo stated.
- toephu2 6y agoSo how is this person going to cash their BTC since all the transactions from the now most famous bitcoin wallet address in the world are traceable?
- jonshariat 6y agoI want to know this as well. Isn't every transaction traceable? I don't know much about BTC, anyone can elaborate?
- deviation 6y agoHe/She might have a fair amount of luck throwing the BTC through scrambler/tumblers. These are services offered to mask your BTC address as other legit customers, making it much more difficult to track. That being said... There is technology out there the FBI is hopping in bed with that is used to track this exact thing. I think if they tumbled it an insane amount, they might get away with about 90% of the principal.
- rasz 6y ago>Elon: Limited early run 50 Cybertrucks and 50 Roadsters giveaway. Send 0.05 BTC to qualify ... >Gates: Coronavirus vaccine found. Secure yours by sending 0.01 BTC. Dont forget about your family ... >nvidia: Limited early run 50 RTX 3080 and 50 RTX 3090 giveaway. Send 0.01 BTC to qualify ... and so on and on There was so much more targeting/personalization they could do beyond old tired 'double your ISK scam'.
- wmil 6y agoI think I could have. Just straight up sell the hack as a service. For 1 btc you can make any blue check say whatever you want. 4chan would go wild.
- tutfbhuf 6y agoI think there might have been other options with different risk odds, but at the end we talk about 100k for a massive hack with international attention. In review of that it's just a very small amount and not worth the risk. There are other ways to steal 100k without getting the attention of the whole world, especially if you're a "smart" hacker.