SlideShare a Scribd company logo
John Bambenek
VP, Security Research and Intelligence, ThreatSTOP
I'm All Up in your Blockchain, Hunting
Down the Nazis
About me
• VP of Security Research and Intelligence at ThreatSTOP
• Lecturer at the University of Illinois at Urbana-Champaign
• Producer of open-source threat feeds
• Assist international cybercrime investigations
What is Blockchain?
Obligatory Venn Diagram
Why people like bitcoin…
• No centralized authority
• Ease of discrete movement of assets
• Can “mine” money out of nothing
• Anonymity of finances (NOT the same as privacy)
Why neonazis like bitcoin
• No centralized authority and can’t be blacklisted from the system*
• Ease of discrete movement of assets
• Can “mine” money out of nothing
• Anonymity of finances
Why I like bitcoin
• I get to follow people’s money without bribing bankers
• The public ledger means I can see all transactions for all of time
• Relationships between wallets are easily seen
• Privacy-enabled cryptocurrencies post a problem (monero, etc)
Bitcoin “can” be very secure
Security vs Usability
• Users are lazy… and to be fair we aren’t much better…
• Who here regularly uses GPG for e-mail?
• People use the same wallet for everything.
• People use online services because ”this company” will do the “hard”
stuff for me.
That’s not a great bet…
Interesting bitcoin facts we will come back to
• Question for the crowd: What’s the value of bitcoin?
• If you took top 10 transactional banks in the US, they hold 55% of all
assets.
• If you took the top 10 cryptocurrency exchanges, they have 70% of
the market share.
• (Yes, that’s not an apples to oranges comparison)
Why does that matter?
• Cryptocurrency has value because I can get money or get things that
take money with it.
• The places where I can turn cryptocurrency into cash and vice-versa
are radically few (~200 or so).
• Those institutions have a wealth of information about who is using
them.
• Even when they don’t keep info, that comes with other advantages.
What started this research…
Some of these names are familiar
• Weev, in a sense, is “one of us”. He self-identifies as a security
researcher.
• Many in our community supported him against a CFAA case from
exposing Apple data.
The Great Printer Troll of 2016
So I took a closer look…
Weev begs for bitcoin too…
A couple of notes….
• There is a persistent rumor that some of these groups are funded
directly or indirectly by the Russian government.
• It is a line of agitation they use in their own propaganda directed at us and
Europe.
• There are some ”connections” between some of them and Russia.
• To what extent is it true?
• Many of the mass shootings in the past 3 or so years have had ”some
connection” to these groups.
Bitcoin attribution
• Between forums, social media, and just plain ole websites, lots of
bitcoin wallets are self-attributed by the owner.
• This reduces attribution in some case to a Google/Bing/DuckDuckGo
problem. (Like the above cases).
• Sometimes this can identify donors too if they are sloppy.
• Most of them are.
There is even a helpful list out there..
• Those random strings don’t identify you (hence
anonymous), but I can still see everything they do.
• However, if you let the world know who is behind a
wallet because you post it to the web, you no longer
have anonymity either.
• They really have no choice here, you can’t donate if
you don’t know where to send the money.
There’s good money in being a racist…
People starting taking services away
• After Charlottesville, Google suspended Daily Stormer website,
Cloudflare kicked them off.
• They moved to a tor hidden service, but their “fans” didn’t know how to use
tor.
• There are only a couple tech savvy fascists, most are the opposite.
• Payment providers were also suspending them: GoFundMe, Paypal,
Stripe…
• Hatreon was created in part to help them raise money, but traditional
systems were more or less closed to them.
What if we could disrupt their bitcoin funding
• During Wannacry, another researcher created a twitter bot that
posted every ransom payment made to DPRK (who also moved their
money into Monero).
• Had thought of why not do the same here to highlight exactly what
they have, and how much they are getting.
• https://github.com/bambenek/bitcoin_tracker (NodeJS, easily
adaptable to any wallet(s) you want to track)
Not all twitter bots are bad
• @neonaziwallets
For some reason, this made them mad
But it also hindered their fundraising
• The various wallets used by neo-Nazis were given to “friendly”
cryptocurrency exchanges who agreed to blacklist them.
• You could always donate via multiple hops, but most of their donors and fans
are not sophisticated.
• They could donate in monero, but that requires multiple steps and was “too
complicated” for their smaller donors and fans.
• Other donors were afraid of being “outed” by researchers now that
the data was made public.
Weev’s history
• Has been in bitcoin and cryptocurrency a long time.
• He has had “some” donations, but he has had bitcoin prior to the
surge and prior to the alt-right becoming a problem.
• He gets paid doing tech work (sometimes for other alt-right groups).
• Also makes money “day-trading” cryptocurrencies.
High-level wallet relationships
There are ways to follow them into monero
A PARTIAL listing of all deposits to weev's monero account. Some may involve him
moving money to himself.
{ "timestamp": "2017-09-12 02:57:08", "withdraw":
"48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q
Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "0.14880000", "deposit
Type": "XMR", }
{ "timestamp": "2017-09-02 23:02:35", "withdraw":
"48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q
Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "71.51690596", "deposit
Type": "XMR", }
{ "timestamp": "2017-09-02 21:06:14", "withdraw":
"48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q
Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "0.03890519", "deposit
Type": "XMR", } …
Cross-currency Database
• ”Soon” I’ll have a database online mapping relationships between
bitcoin wallets and various altcoins (and vice versa).
• Broader use case than just neo-Nazis, but I was able to see other
groups paying Weev via a cryptocurrency exchange otherwise
invisible to the blockchain.
They didn’t like it when I pointed that out
There was a large funder of Daily Stormer
• Just after Daily Stormer was taken offline by Google and when Anglin
was hustling to “keep the lights on”, this donation appeared…
• This was about $60,000 at the time. That donor is likely sitting on
$28.8M in bitcoin in today’s dollars.
That money has an interesting backstory…
• Ultimately the bitcoin can be traced by an oldtime bitcoin user who
was selling bitcoins on forums way back in 2010/2011.
• Likely the donor bought from this person (interestingly enough a
bilingual English/Russian speaker) and has rode bitcoin from
essentially nothing to where it is today.
• I get asked a lot if “Russian” money is behind the alt-right, I haven’t
been able to substantiate that yet.
Bitcoin surge
1488
• 14 words: We must secure the existence of our people and a future
for white children. – David Lane
• 88, either:
• 88 precepts (also by David Lane)
• 8th letter in alphabet is H. HH for Heil Hitler.
Some other examples
Searching by transaction attributes
Over 4500 transactions were found (and
counting)
The end game…
The end game…
• Many of the ones with actual cryptocurrency wealth are facing
lawsuits and in varying forms “in hiding”.
• Can their be adversarial seizing of bitcoin (given a legal judgement)?
Questions?
John Bambenek / @bambenek
jbambenek@threatstop.com

More Related Content

PDF
What is cryptocurrency everything you need to know - ultimate guide
PDF
History of Distributed Computing
PDF
Lec5_Bitcoin
PPTX
Blockchain Tutorial and Facebook Libra Ver. 190620
PDF
BitCoin, Blockchain, and Cryptocurrency
PDF
BitCoin, Blockchain, and Cryptocurrencies
PPTX
Stamford innovation week - blockchain day
PDF
Bitcoin Blockchains on Twitter timelines: A Social Media analysis of cryptocu...
What is cryptocurrency everything you need to know - ultimate guide
History of Distributed Computing
Lec5_Bitcoin
Blockchain Tutorial and Facebook Libra Ver. 190620
BitCoin, Blockchain, and Cryptocurrency
BitCoin, Blockchain, and Cryptocurrencies
Stamford innovation week - blockchain day
Bitcoin Blockchains on Twitter timelines: A Social Media analysis of cryptocu...

Similar to I'm All Up in Your Blockchain - Hunting Down the Nazis (20)

PDF
Intro to Bitcoin
PPTX
Bitcoin 101 - Bitcoin For Beginners by World Bitcoin Network
PPTX
Bitcoin presentation slides
ODP
Bitcoin Talk at Rainbow
PPTX
CryptoCamp Version 1.0 as of Mar. 15, 2019
PPTX
Overview of Bitcoin - Sweden
PPTX
Bitcoin Masterclass TechweekNZ v3.1.pptx
PDF
Cryptocurrencies and the Blockchain
PPTX
ATMIA Bitcoin Presentation-rvsd
PPTX
PDF
Bitcoin - suwerennosc jednostki slajdy wprowadzajace Roberta
PPTX
@jdrive btc deck 7.0
PDF
Money Code Space Hidden Power In Bitcoin Blockchain And Decentralisation 1st ...
PDF
Bitcoin: money of the future
PDF
Web3 Visitors
PDF
Topic 1 Blockchain and Cryptocurrency Overview BW.pdf
PDF
Crypto currencies presentation by Dr. Andre Gholam
DOCX
What is bitcoin?
PDF
Bitcoin and Blockchain: Relevance to Anti-Poverty Research
PDF
The Future of Bitcoin
Intro to Bitcoin
Bitcoin 101 - Bitcoin For Beginners by World Bitcoin Network
Bitcoin presentation slides
Bitcoin Talk at Rainbow
CryptoCamp Version 1.0 as of Mar. 15, 2019
Overview of Bitcoin - Sweden
Bitcoin Masterclass TechweekNZ v3.1.pptx
Cryptocurrencies and the Blockchain
ATMIA Bitcoin Presentation-rvsd
Bitcoin - suwerennosc jednostki slajdy wprowadzajace Roberta
@jdrive btc deck 7.0
Money Code Space Hidden Power In Bitcoin Blockchain And Decentralisation 1st ...
Bitcoin: money of the future
Web3 Visitors
Topic 1 Blockchain and Cryptocurrency Overview BW.pdf
Crypto currencies presentation by Dr. Andre Gholam
What is bitcoin?
Bitcoin and Blockchain: Relevance to Anti-Poverty Research
The Future of Bitcoin
Ad

More from John Bambenek (19)

PPTX
THOTCON - The War over your DNS Queries
PPTX
SANSFIRE18: War Stories on Using Automated Threat Intelligence for Defense
PPTX
HITCON 2017: Building a Public RPZ Service to Protect the World's Consumers
PPTX
MISP Summit 2018: Barncat: Using MISP for Bulk Malware Surveillance
PPTX
SANSFIRE - Elections, Deceptions and Political Breaches
PPTX
Tracking Exploit Kits - Virus Bulletin 2016
PPTX
Defcon Crypto Village - OPSEC Concerns in Using Crypto
PPTX
Corporate Espionage without the Hassle of Committing Felonies
PPTX
HITCON 2015 - DGAs, DNS and Threat Intelligence
PPTX
ANALYZE'15 - Bulk Malware Analysis at Scale
PPTX
PHDAYS: DGAs and Threat Intelligence
PDF
THOTCON 0x6: Going Kinetic on Electronic Crime Networks
PPTX
Blackhat USA 2014 - The New Scourge of Ransomware
PDF
IESBGA 2014 Cybercrime Seminar by John Bambenek
PDF
Thotcon 0x5 - Retroactive Wiretapping VPN over DNS
PDF
Champaign EDC Cybersecurity Seminar by John Bambenek - March 25, 2014
PPT
Cybercrime and Computer Forensics Seminar - Chicago Bar Association CLE May 2...
PPTX
Cybercrime & Computer Forensics - ISBA Master Series CLE, Nov 18, 2011
PPTX
Introduction to Computer Crime - John Bambenek talk to Champaign Seniors Poli...
THOTCON - The War over your DNS Queries
SANSFIRE18: War Stories on Using Automated Threat Intelligence for Defense
HITCON 2017: Building a Public RPZ Service to Protect the World's Consumers
MISP Summit 2018: Barncat: Using MISP for Bulk Malware Surveillance
SANSFIRE - Elections, Deceptions and Political Breaches
Tracking Exploit Kits - Virus Bulletin 2016
Defcon Crypto Village - OPSEC Concerns in Using Crypto
Corporate Espionage without the Hassle of Committing Felonies
HITCON 2015 - DGAs, DNS and Threat Intelligence
ANALYZE'15 - Bulk Malware Analysis at Scale
PHDAYS: DGAs and Threat Intelligence
THOTCON 0x6: Going Kinetic on Electronic Crime Networks
Blackhat USA 2014 - The New Scourge of Ransomware
IESBGA 2014 Cybercrime Seminar by John Bambenek
Thotcon 0x5 - Retroactive Wiretapping VPN over DNS
Champaign EDC Cybersecurity Seminar by John Bambenek - March 25, 2014
Cybercrime and Computer Forensics Seminar - Chicago Bar Association CLE May 2...
Cybercrime & Computer Forensics - ISBA Master Series CLE, Nov 18, 2011
Introduction to Computer Crime - John Bambenek talk to Champaign Seniors Poli...
Ad

Recently uploaded (20)

PPTX
Cyber Hygine IN organizations in MSME or
PPTX
Reading as a good Form of Recreation
PPTX
artificialintelligenceai1-copy-210604123353.pptx
PDF
si manuel quezon at mga nagawa sa bansang pilipinas
PDF
Exploring The Internet Of Things(IOT).ppt
PDF
Understand the Gitlab_presentation_task.pdf
PPTX
Introduction to cybersecurity and digital nettiquette
PDF
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
PPTX
Slides PPTX: World Game (s): Eco Economic Epochs.pptx
PPT
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PDF
Slides PDF: The World Game (s) Eco Economic Epochs.pdf
PPTX
Layers_of_the_Earth_Grade7.pptx class by
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PDF
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
DOC
Rose毕业证学历认证,利物浦约翰摩尔斯大学毕业证国外本科毕业证
PPTX
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
PPTX
Database Information System - Management Information System
PPTX
t_and_OpenAI_Combined_two_pressentations
PPTX
newyork.pptxirantrafgshenepalchinachinane
Cyber Hygine IN organizations in MSME or
Reading as a good Form of Recreation
artificialintelligenceai1-copy-210604123353.pptx
si manuel quezon at mga nagawa sa bansang pilipinas
Exploring The Internet Of Things(IOT).ppt
Understand the Gitlab_presentation_task.pdf
Introduction to cybersecurity and digital nettiquette
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
Slides PPTX: World Game (s): Eco Economic Epochs.pptx
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
Slides PDF: The World Game (s) Eco Economic Epochs.pdf
Layers_of_the_Earth_Grade7.pptx class by
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
Rose毕业证学历认证,利物浦约翰摩尔斯大学毕业证国外本科毕业证
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
Database Information System - Management Information System
t_and_OpenAI_Combined_two_pressentations
newyork.pptxirantrafgshenepalchinachinane

I'm All Up in Your Blockchain - Hunting Down the Nazis

  • 1. John Bambenek VP, Security Research and Intelligence, ThreatSTOP I'm All Up in your Blockchain, Hunting Down the Nazis
  • 2. About me • VP of Security Research and Intelligence at ThreatSTOP • Lecturer at the University of Illinois at Urbana-Champaign • Producer of open-source threat feeds • Assist international cybercrime investigations
  • 5. Why people like bitcoin… • No centralized authority • Ease of discrete movement of assets • Can “mine” money out of nothing • Anonymity of finances (NOT the same as privacy)
  • 6. Why neonazis like bitcoin • No centralized authority and can’t be blacklisted from the system* • Ease of discrete movement of assets • Can “mine” money out of nothing • Anonymity of finances
  • 7. Why I like bitcoin • I get to follow people’s money without bribing bankers • The public ledger means I can see all transactions for all of time • Relationships between wallets are easily seen • Privacy-enabled cryptocurrencies post a problem (monero, etc)
  • 8. Bitcoin “can” be very secure
  • 9. Security vs Usability • Users are lazy… and to be fair we aren’t much better… • Who here regularly uses GPG for e-mail? • People use the same wallet for everything. • People use online services because ”this company” will do the “hard” stuff for me.
  • 10. That’s not a great bet…
  • 11. Interesting bitcoin facts we will come back to • Question for the crowd: What’s the value of bitcoin? • If you took top 10 transactional banks in the US, they hold 55% of all assets. • If you took the top 10 cryptocurrency exchanges, they have 70% of the market share. • (Yes, that’s not an apples to oranges comparison)
  • 12. Why does that matter? • Cryptocurrency has value because I can get money or get things that take money with it. • The places where I can turn cryptocurrency into cash and vice-versa are radically few (~200 or so). • Those institutions have a wealth of information about who is using them. • Even when they don’t keep info, that comes with other advantages.
  • 13. What started this research…
  • 14. Some of these names are familiar • Weev, in a sense, is “one of us”. He self-identifies as a security researcher. • Many in our community supported him against a CFAA case from exposing Apple data.
  • 15. The Great Printer Troll of 2016
  • 16. So I took a closer look…
  • 17. Weev begs for bitcoin too…
  • 18. A couple of notes…. • There is a persistent rumor that some of these groups are funded directly or indirectly by the Russian government. • It is a line of agitation they use in their own propaganda directed at us and Europe. • There are some ”connections” between some of them and Russia. • To what extent is it true? • Many of the mass shootings in the past 3 or so years have had ”some connection” to these groups.
  • 19. Bitcoin attribution • Between forums, social media, and just plain ole websites, lots of bitcoin wallets are self-attributed by the owner. • This reduces attribution in some case to a Google/Bing/DuckDuckGo problem. (Like the above cases). • Sometimes this can identify donors too if they are sloppy. • Most of them are.
  • 20. There is even a helpful list out there.. • Those random strings don’t identify you (hence anonymous), but I can still see everything they do. • However, if you let the world know who is behind a wallet because you post it to the web, you no longer have anonymity either. • They really have no choice here, you can’t donate if you don’t know where to send the money.
  • 21. There’s good money in being a racist…
  • 22. People starting taking services away • After Charlottesville, Google suspended Daily Stormer website, Cloudflare kicked them off. • They moved to a tor hidden service, but their “fans” didn’t know how to use tor. • There are only a couple tech savvy fascists, most are the opposite. • Payment providers were also suspending them: GoFundMe, Paypal, Stripe… • Hatreon was created in part to help them raise money, but traditional systems were more or less closed to them.
  • 23. What if we could disrupt their bitcoin funding • During Wannacry, another researcher created a twitter bot that posted every ransom payment made to DPRK (who also moved their money into Monero). • Had thought of why not do the same here to highlight exactly what they have, and how much they are getting. • https://github.com/bambenek/bitcoin_tracker (NodeJS, easily adaptable to any wallet(s) you want to track)
  • 24. Not all twitter bots are bad • @neonaziwallets
  • 25. For some reason, this made them mad
  • 26. But it also hindered their fundraising • The various wallets used by neo-Nazis were given to “friendly” cryptocurrency exchanges who agreed to blacklist them. • You could always donate via multiple hops, but most of their donors and fans are not sophisticated. • They could donate in monero, but that requires multiple steps and was “too complicated” for their smaller donors and fans. • Other donors were afraid of being “outed” by researchers now that the data was made public.
  • 27. Weev’s history • Has been in bitcoin and cryptocurrency a long time. • He has had “some” donations, but he has had bitcoin prior to the surge and prior to the alt-right becoming a problem. • He gets paid doing tech work (sometimes for other alt-right groups). • Also makes money “day-trading” cryptocurrencies.
  • 29. There are ways to follow them into monero A PARTIAL listing of all deposits to weev's monero account. Some may involve him moving money to himself. { "timestamp": "2017-09-12 02:57:08", "withdraw": "48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "0.14880000", "deposit Type": "XMR", } { "timestamp": "2017-09-02 23:02:35", "withdraw": "48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "71.51690596", "deposit Type": "XMR", } { "timestamp": "2017-09-02 21:06:14", "withdraw": "48qaHU2UZELTgDcAqk4WS3CS84wr6GkuyBnuzovpwUUJeTvSGiAzF5TFLQSPoXU8q Ue33hwVsR7HW7nzmsyP9jzXAUhXjry", "deposit Coin": "0.03890519", "deposit Type": "XMR", } …
  • 30. Cross-currency Database • ”Soon” I’ll have a database online mapping relationships between bitcoin wallets and various altcoins (and vice versa). • Broader use case than just neo-Nazis, but I was able to see other groups paying Weev via a cryptocurrency exchange otherwise invisible to the blockchain.
  • 31. They didn’t like it when I pointed that out
  • 32. There was a large funder of Daily Stormer • Just after Daily Stormer was taken offline by Google and when Anglin was hustling to “keep the lights on”, this donation appeared… • This was about $60,000 at the time. That donor is likely sitting on $28.8M in bitcoin in today’s dollars.
  • 33. That money has an interesting backstory… • Ultimately the bitcoin can be traced by an oldtime bitcoin user who was selling bitcoins on forums way back in 2010/2011. • Likely the donor bought from this person (interestingly enough a bilingual English/Russian speaker) and has rode bitcoin from essentially nothing to where it is today. • I get asked a lot if “Russian” money is behind the alt-right, I haven’t been able to substantiate that yet.
  • 35. 1488 • 14 words: We must secure the existence of our people and a future for white children. – David Lane • 88, either: • 88 precepts (also by David Lane) • 8th letter in alphabet is H. HH for Heil Hitler.
  • 38. Over 4500 transactions were found (and counting)
  • 40. The end game… • Many of the ones with actual cryptocurrency wealth are facing lawsuits and in varying forms “in hiding”. • Can their be adversarial seizing of bitcoin (given a legal judgement)?
  • 41. Questions? John Bambenek / @bambenek jbambenek@threatstop.com