3 ms·
Well this sure is a pretty fascinating case, if it proves to be true, which it _seems_ to be? One thing I'm not seeing mentioned here is discussion of the pass
by itsthejb 4y ago
Well this sure is a pretty fascinating case, if it proves to be true, which it _seems_ to be?
One thing I'm not seeing mentioned here is discussion of the password for that wallet.dat. This reminds me of back during the 2017 bull run, when I tried to help a friend recover a forgotten password for a bottom 6-figures Dash coin wallet. We went even so far as spinning up some EC2 GPU instances to run Hashcat. In the end, considering the modest value of the wallet, it wasn't cost effective to brute-force. I think we got up to the threshold of 7-9 characters where the time/cost becomes prohibitive.
So I'm wondering, assuming the guy even HAD a password on the database file, or that we didn't have a password.txt on this server, I wonder about the sequence of events where:
1. Server is hacked a few months ago, either knowingly (target a core dev), or farmed (searching for vulnerable servers, grabbing high value assets such as wallet.dats)
2. wallet.dat is copied. IIRC gives free access to the public key, therefore revealing a high value wallet
3. In the meantime, attacker employs compute resources to crack the private key
4. After some months of doing this, finds the passwords, empties the wallet
This would seem to match my quick reading of the events. I'm now intrigued to do some sums to work out the feasibility of doing this when a 7-figure wallet is found. This is assuming compute prices are that much cheaper than 5 years ago, and that this might be a independent attacker, not some NK-style state actor.
I may come back to this and do the calculations...