Individual gains access to Russian crypto accounts and transfers BTC to Ukraine’s war efforts

Individual gains access to Russian crypto accounts and transfers BTC to Ukraine’s war efforts

On April 26, analytics firm Chainalysis issued a study detailing how one Bitcoiner utilised a blockchain feature to raise the alarm on 986 Bitcoin addresses. The vigilante’s messages, written in Russian, accuse the wallets of being involved in hacking operations.

“We recently discovered what appears to be an example of a more direct, aggressive usage of Bitcoin for counterintelligence, through the unprecedented weaponization of the OP_RETURN field,” claimed Chainalysis in the now-deleted report.

The OP_RETURN field is commonly used to indicate that a Bitcoin transaction is invalid, but it also allows users to attach messages to transactions and broadcast them to the whole blockchain. While describing their allegations to the blockchain, the individual effectively destroyed over $300,000 in bitcoin. This is significantly more than is required in order to access the Bitcoin blockchain’s OP_RETURN field.

“Under ordinary circumstances, it would be difficult to detect cryptocurrency addresses used by hostile actors unless you were actively looking for them. But starting on February 12, 2022 — weeks before the Russian invasion of Ukraine — and ending on March 14, 2022, an anonymous Bitcoin user sounded the alarm and called out nearly 1,000 addresses they claim to belong to Russian security agencies.”

It is unclear whether the individual’s claims are real. What’s evident is that the individual gained access to at least some of the addresses. They claim have been acquired by Russia, maybe through hacking or even (if the claims are true) an inside operation.

The anonymous user utilised the function to send hundreds of transactions to addresses. Stating they were used in hacking activities by one of three Russian agencies: the Foreign Military Intelligence Agency (GRU). As well as the Foreign Intelligence Service (SVR), and the Federal Security Service (FSB). 

When Russia invaded Ukraine, the user stopped burning BTC and began transferring Russian-linked funds to Ukrainian aid wallet addresses. 

“The possibility that the OP_RETURN sender acquired private keys for Russian-controlled addresses also suggests that the Putin regime’s crypto operations aren’t secure,” wrote Chainalysis.

If these allegations are genuine, the sender accomplished something “very powerful” in the context of cyber warfare, according to Chainalysis. Because of the OP_RETURN function, the Russian government has lost access to this Bitcoin. And it will be impossible for these agencies to utilise these addresses for similar purposes in the future.

Related Posts