They Cracked the Code To a Locked USB Drive Worth $235 Million in Bitcoin. Then It Got Weird. (wired.com) 61
Unciphered, a Seattle-based startup, claims to have cracked the seemingly unbreakable encryption of IronKey S200, a decade-old USB thumb drive. By exploiting an undisclosed vulnerability in the device, the company says it can bypass the drive's feature that erases its contents after 10 incorrect password attempts. The breakthrough came within a day of receiving a test device, suggesting that the firm's hacking technique, powered by high-performance computing, could have far-reaching implications.
The startup's focus is not just technological; it's after a specific IronKey that holds 7,002 bitcoins, valued at roughly $235 million, stored in a Swiss bank vault. The device belongs to Stefan Thomas, a Swiss crypto entrepreneur, who has forgotten the password and has only two password attempts left before losing access to his fortune. Unciphered believes its hacking capabilities could unlock Thomas' crypto vault and is preparing to reach out to him to offer its services. The only problem: Thomas doesn't seem to want their help. Wired: Earlier this month, not long after performing their USB-decrypting demonstration for me, Unciphered reached out to Thomas through a mutual associate who could vouch for the company's new IronKey-unlocking abilities and offer assistance. The call didn't even get as far as discussing Unciphered's commission or fee before Thomas politely declined. Thomas had already made a "handshake deal" with two other cracking teams a year earlier, he explained. In an effort to prevent the two teams from competing, he had offered each a portion of the proceeds if either one could unlock the drive. And he remains committed, even a year later, to giving those teams more time to work on the problem before he brings in anyone else -- even though neither of the teams has shown any sign of pulling off the decryption trick that Unciphered has already accomplished.
That has left Unciphered in a strange situation: It holds what is potentially one of the most valuable lockpicking tools in the cryptocurrency world, but with no lock to pick. "We cracked the IronKey," says Nick Fedoroff, Unciphered's director of operations. "Now we have to crack Stefan. This is turning out to be the hardest part." In an email to WIRED, Thomas confirmed that he had turned down Unciphered's offer to unlock his encrypted fortune. "I have already been working with a different set of experts on the recovery so I'm no longer free to negotiate with someone new," Thomas wrote. "It's possible that the current team could decide to subcontract Unciphered if they feel that's the best option. We'll have to wait and see." In past interviews, Thomas has said that his 7,002 bitcoins were left over from a payment he received for making a video titled "What is Bitcoin?" that published on YouTube in early 2011, when a bitcoin was worth less than a dollar. Later that year, he told WIRED that he'd inadvertently erased two backup copies of the wallet that held those thousands of coins, and then lost the piece of paper with the password to decrypt the third copy, stored on the IronKey. By then, his lost coins were worth close to $140,000.
The startup's focus is not just technological; it's after a specific IronKey that holds 7,002 bitcoins, valued at roughly $235 million, stored in a Swiss bank vault. The device belongs to Stefan Thomas, a Swiss crypto entrepreneur, who has forgotten the password and has only two password attempts left before losing access to his fortune. Unciphered believes its hacking capabilities could unlock Thomas' crypto vault and is preparing to reach out to him to offer its services. The only problem: Thomas doesn't seem to want their help. Wired: Earlier this month, not long after performing their USB-decrypting demonstration for me, Unciphered reached out to Thomas through a mutual associate who could vouch for the company's new IronKey-unlocking abilities and offer assistance. The call didn't even get as far as discussing Unciphered's commission or fee before Thomas politely declined. Thomas had already made a "handshake deal" with two other cracking teams a year earlier, he explained. In an effort to prevent the two teams from competing, he had offered each a portion of the proceeds if either one could unlock the drive. And he remains committed, even a year later, to giving those teams more time to work on the problem before he brings in anyone else -- even though neither of the teams has shown any sign of pulling off the decryption trick that Unciphered has already accomplished.
That has left Unciphered in a strange situation: It holds what is potentially one of the most valuable lockpicking tools in the cryptocurrency world, but with no lock to pick. "We cracked the IronKey," says Nick Fedoroff, Unciphered's director of operations. "Now we have to crack Stefan. This is turning out to be the hardest part." In an email to WIRED, Thomas confirmed that he had turned down Unciphered's offer to unlock his encrypted fortune. "I have already been working with a different set of experts on the recovery so I'm no longer free to negotiate with someone new," Thomas wrote. "It's possible that the current team could decide to subcontract Unciphered if they feel that's the best option. We'll have to wait and see." In past interviews, Thomas has said that his 7,002 bitcoins were left over from a payment he received for making a video titled "What is Bitcoin?" that published on YouTube in early 2011, when a bitcoin was worth less than a dollar. Later that year, he told WIRED that he'd inadvertently erased two backup copies of the wallet that held those thousands of coins, and then lost the piece of paper with the password to decrypt the third copy, stored on the IronKey. By then, his lost coins were worth close to $140,000.
Subcontract (Score:2)
Re:Subcontract (Score:5, Interesting)
Well I suppose they need a clause for what if they encryption is cracked but the only think on it is autorun.inf
Re:Subcontract (Score:5, Insightful)
Re:Subcontract (Score:4, Informative)
Re: (Score:2)
a taxable capital gain event in many countries
But not all. Stand aside as the winning bidder picks up his purchase with Nauruan passport in hand.
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
I would. That gives me a guaranteed payout so I wouldn't have to sell the Bitcoins. Trying to cash out on that much coin requires a lot of suckers and would probably disrupt the market.
But, hey... I'm not a collector or hoarder. I can't relate to the super-rich who have 1,000 times more than their basic needs.
Lifespan of data? (Score:2)
Re: (Score:2)
Re: (Score:2)
That said, I don't know to what extent the longer life of MLC extends to years as opposed to rewrite cycles.
Re: (Score:2)
Re: (Score:1)
Nah.. he was relying on his $200 device as the sole means to temporarily hold $7200 left over from buying something else.
Re: (Score:2)
It was only a few thousand when he put his key on it. And he apparently had two other copies in different places that he somehow managed to lose.
I think I would have been more careful with $5k, but I guess a lot of people aren't.
Re: (Score:2)
Re: (Score:2)
Because if you can find some poor dumbass to sell it to at the right time you can get rich and buy a lambo. Well, provided you can remember your password.
It's just another get rich quick scheme, this time nicely mixed with some gold standard / central bank conspiracy theory.
Stefan seems to be rather clumsy (Score:2)
I wonder if he actually stored on that key what he thinks he did.
Re: (Score:3, Funny)
Re: (Score:3)
I suspect that he may have been caught off-guard by Unciphered's claim. He probably as intending to launch another one of those scammy "everybody give me money to try and decrypt this, I'll give you a small percentage of my zillion bitcoin if I'm successful" schemes we've seen a few times.
He collects a bunch of cash from credulous people, occasionally pretending he might be making some sort of progress while just laughing to himself.
Bullshit alert (Score:5, Insightful)
Nobody waits indefinitely for $235 million dollars'maybe' when they could have it now 'pretty sure'.
If he really had bits worth that much on the USB drive, he'd tell his current contractor to get it done and make a deal with the new team if they had to, or they'd lose the contract.
So... I suspect the original claim was bullshit and he never expected anyone to have the ability to prove it.
Re: (Score:2)
This. If there really is that sort of money on the drive he could easily afford to pay off the other groups, give unciphered a large percentage of the 235M and still have a fortune in the bank. But no, some kind of "honour" with the hackers is more important. GMAFB.
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
I agree, he should just tell his current 2 contractors to work it out with Unciphered, and share the $, that's the smart thing to do. Or, he knows there isn't that much BTC on the key and is r
Re: (Score:2)
Re: Bullshit alert (Score:1)
But it's a very large price to pay if the Unciphered attempt fails!
Re: (Score:1)
Re: Bullshit alert (Score:2)
Re: (Score:2)
Is this what you call being a smart idiot?
Sigh... (Score:2)
After a blessed respite, suddenly three stories about crypto-crap get posted in less than 24 hours. Apparently the cryptobros think enough time has passed that we have forgotten about their ultra-shady house of cards.
Re: (Score:3)
After a blessed respite, suddenly three stories about crypto-crap get posted in less than 24 hours. Apparently the cryptobros think enough time has passed that we have forgotten about their ultra-shady house of cards.
And curiously, right after there has been a sudden jump in the BTC price because of rumors that a big Wall Street firm is getting into crypto.
Guess someone fell for the ruse (Score:3)
To me this sounds like someone wanted to know whether the device is actually secure, got his answer, and all that for free.
whose problem? (Score:5, Funny)
Rich people's problems. I'm rooting for the USB drive.
Re: (Score:2)
Sealed asset value (Score:3)
As long as the USB isn't decrypted its owner can continue to be claimed to be *potentially* worth millions regardless of whether it contains nothing more than a never_gonna_give_you_up.mp3
As for the devs they never checked to see if they weren't developing a solution in search of a problem first. They just assumed. It's not like Bitcoin is something people value because it's so useful for spending.
Forgive my skepticism... (Score:2)
The more this guy claims he really, really wants his drive decrypted, except by the people who might actually be able to do it, strongly suggests to me that the drive's entire value rests on the fact that nobody except him knows what's on it...if anything.
Re: (Score:3)
On the one hand, I can see this guy's point of view. He made an agreement with some people and his own moral code won't allow a breach of that agreement. I am the same way.
On the other hand, the clock is ticking on the charge state of those cells... The sooner you can read the data, the better.
Re: (Score:2)
On the one hand, I can see this guy's point of view. He made an agreement with some people and his own moral code won't allow a breach of that agreement. I am the same way.
On the other hand, the clock is ticking on the charge state of those cells... The sooner you can read the data, the better.
And he might not even KNOW that these devices have a limited lifespan...
Re: (Score:1)
Why deleting the data? (Score:2)
"Handshake deal" (Score:2)
Re: (Score:2)
For real. And since you are talking about $250 million, assuming these other guys are working on commission for whatever is recovered, you'd want to put into said contract a clause like "in the event the data is recovered via other means" (like...I finally found the post it note with my passwords) then you pay them time+materials and some amount of money.
Likewise these 'other guys' would probably want some time+materials guarantee payment if the USB drive turns out not to have Bitcoin on it.
But overall th
Proof of worth? (Score:1)
Swiss Crypto "Entrepreneur" (Score:1)
More like Swiss-Cheese brain.
- lost the first drive
- lost the second drive
- lost the paper backup
- thinks he has $235M but won't let anyone prove it.
I think he's Craig Wright for sure. Prove me wrong if you disagree.
How dumb are these people?! (Score:1)
No, you need to sell the technique to one of the other 2 teams.
Btw I had over $100 million in crypto in 2010 and sold MOST of it in 2011. But I finally "cracked" a non-encrypted but damaged wallet I thought had about 5 BTC in it. Nope. All balances were in earlier addresses/keys/whatever and the fallback wallet I restored from a backup had access to all of them and no funds were added in the time between when the wallet broke and wh
Not weird and barely even suspicious. (Score:1)
I started reading this thinking they were gonna say feds showed up with a cease-and-desist order, or aliens or time travelers showed up demanding the key or something like that. I'm disappointed that this was utterly mundane.
What's With 10 Tries? (Score:5, Insightful)
I just want to point out how ridiculous it is to build a device that destroys it's contents after 10 failed attempts. They could increase it to 100 without decreasing the security by a meaningful amount but it would give the owner a lot more breathing room to access their data.
Re: (Score:2)
password1234
password12345
password123456
password1234567
May I give it a shot?
Re: (Score:2)
I just want to point out how ridiculous it is to build a device that destroys it's contents after 10 failed attempts. They could increase it to 100 without decreasing the security by a meaningful amount but it would give the owner a lot more breathing room to access their data.
Their target customer isn't IT people. I'm sure this device is targeted at people who know next to nothing about IT like doctors, dentists, lawyers, etc. Also it might be targeted at companies who are off the charts risk averse.
yeah sure (Score:2)
What is it with rich crypto bros being unable to prevent their losses of these invaluable assets? First Craig Wright, now this guy, purport to lose significant wealth in ways that defies believing they were ever intelligent to begin with.
In any event, this story is probably just an "explanation" ruse to paper over behavior that otherwise would be hard to ignore, such as money laundering or tax avoidance. The thumb drive probably contains nothing.
why is this weird? (Score:2)
It seems on the face of it that he made a deal with a couple of others, and is giving them more time.
Not to mention perhaps the liability of an implied contract and what a court might deem an insufficient time granted to accomplish the task.
It's not like the value isn't appreciating, so if he doesn't need the money, well, why not?
Nothing guarantees their 'magic solution' will work either.
Fundamental Crypto Flaw? (Score:2)
Sounds like given enough time, all crypto will be ‘lost’.
Re: (Score:2)
That's not a bug, it's a feature! It just increases the deflationary nature of bitcoin. So if you HODL long enough, not only will you own a good chunk of the world's money, if you're the last one, you'll have it ALL.
It's like Highlander. There can be only one.
I'd guess the drive will be corrupt if decrypted (Score:2)
This problem with USB flash storage devices is one reason that today, I only buy name brand devices, from known sellers. Won't prevent a fake product getting in
Re: (Score:1)
LOL. (Score:2)
I had one of these IronKey's. They were hardware-based "encrypted" and physically-hardened USB drives.
Nothing you can't replicate with more securely using VeraCrypt and a reliable, high-quality USB drive.
Funny thing: a fed once recommened Iron Key to me. (Score:1)
One night while I talked with him (before I learned he was a fed), he recommended that I use a product called IronKey, and he gushed to me about how it was secure and totally unbreakable.
Needless to say, I have been suspicious of IronKey ever since that experience. I assumed it had some kind of backdoor to allow law enforcement or intelligence agencies to look at hidden data.