logo

How we recovered $XXX,000 in Bitcoin from an encrypted zip file

Conference:  Defcon 28

2020-08-01

Summary

The main idea of the conference presentation is that attacks on cryptography will only get better and it is important to choose the best software and have a plan for upgrading crypto in any product that uses it.
  • Attacks on cryptography only get better
  • Choose the best software and have a plan for upgrading crypto in any product that uses it
The speaker discussed a consulting job they did for a client where they estimated the total cost to be around $100,000 but due to extra cryptanalytic work, the hardware cost ended up being only around $10-15,000. The client gave them a big bonus afterwards.

Abstract

About six months ago, a Russian guy contacted me on LinkedIn with an intriguing offer. He had hundreds of thousands of dollars in Bitcoin keys locked in a zip file, and he couldn't remember the password. Could I break into it for him? He found my name by reading an old cryptanalysis paper I wrote nearly 20 years ago. In that attack, I needed five files to break into a zip archive. This one only had two files in it. Was it possible? How much would it cost? We had to modify my old attack with some new cryptanalytic techniques and rent a GPU farm, but we pulled it off. Come hear how.

Materials:

Tags:

Post a comment

Related work

Conference:  Defcon 29
Authors:
2021-08-01