Stories from the Laundromat: Talking Money Laundering with the Author of "Rinsed" and "Lazarus Heist" Goeff White
37m 48s
TRM Labs, headed by Erie Redboard, offers blockchain intelligence software aiding law enforcement and financial entities in combating financial crimes in the digital asset space. Ransomware attacks, including recent incidents with CDK Global and AT&T, have been traced using blockchain intelligence. The rise of ransomware-as-a-service has made cybercrime more accessible, with developers offering malicious software to affiliates for profit sharing. Jeff White's book "Rinsed: From Cartels to Crypto" explores money laundering in the tech industry, shedding light on cases like the Lazarus Heist and the Din Sister case. The conversation on TRM Talks covers investigative journalism, cybercrime, and the impact of money laundering on organized crime. White emphasizes the crucial role of disrupting money laundering to curb criminal activities effectively, showcasing the evolution of financial crimes from cash to cryptocurrencies.
Transcription
7794 Words, 44449 Characters
I'm Erie Redboard, and this is TRM Talks.
I am global head of policy at TRM Labs.
At TRM, we provide blockchain intelligence software to support law enforcement investigations
and to help financial institutions and cryptocurrency businesses mitigate financial crime risk within
the emerging digital asset economy.
Prior to joining TRM, I spent 15 years in the U.S. federal government versus a prosecutor
at the Department of Justice, and then as a Treasury Department official where I worked
to safeguard the financial system against terrorist financiers, weapons of mass destruction
proliferators, drug kingpins, and other rogue actors.
On TRM Talks, I sit down with business leaders, policymakers, investigators, and friends from
across the crypto ecosystem who are working to build a safer financial system.
Today we're going to be talking to Jeff White, a claimed journalist and author of Lazarus
Heiss about his most recent book, rinsed from cartels to crypto, how the tech industry washes
money for the world's deadliest crooks.
But first, inside the lab, where I share data-driven insights from our blockchain intelligence team.
This summer we've seen a spate of ransomware attacks on a diverse set of businesses, from
Telcom to Automotive, ransomware attacks against CDK Global, a major provider of software solutions
for auto dealers, and Telcom giant AT&T.
Reportedly, in both cases, ransom payments were made in cryptocurrency and were traced
by TRM to known ransomware actors.
Since the 2021 watershed attack on colonial pipeline, we have seen a global response to
the ransomware epidemic, yet we have seen attacks continue.
Because payments are made in cryptocurrencies, however, law enforcement, using blockchain
intelligence, can track ransom payments and disrupt ransomware groups, such as LockBit.
Over the last few years, we've seen a proliferation of something called ransomware as a service.
Ransomware as a service significantly lowers the barriers to entry for malicious actors.
Ransomware as a service is a business model used by cybercriminals that allows non-technical
attackers to deploy ransomware attacks with minimal effort.
In this model, experienced ransomware developers create the malicious software and offer it
to affiliates.
Think the fast food McDonald's model, but for cybercriminals.
The affiliates then execute the attacks.
In exchange, the developers receive a share of the ransom payments.
Key features of ransomware as a service includes a user-friendly interface, profit sharing,
support, and updates.
A key feature is also darknet-enabled anonymity and accessibility.
Examples of ransomware as a service platform include revel, darkside, and LockBit.
So why are we seeing more attacks over the last few months?
As we see more and more ransomware as a service, it simply becomes easier to execute these
types of attacks, even against entities as large as CDK and AT&T.
We're likely to see a combination of continued attacks, but also governments globally coming
together, public-private partnerships, and law enforcement activity to stop and disrupt
ransomware action.
For much more on ransomware, check out our TRM's insights page.
Now let's sit down with Jeff White.
Jeff, thank you so much for joining TRM Talks again.
Thank you.
Thanks for having me.
This is a bit of a crazy story, and I would love to kind of get your reaction to it.
So in the U.S. rinsed releases on August 16th, is that correct?
I thought 13th, but you might be right.
13th, somewhere in that range.
But I'm in the U.S. and I needed to read this thing, and I went on to Amazon, and I noticed
that I couldn't get the hard copy until that 13th date.
So I ended up clicking on a link that said "paperback" and ended up with this copy here,
which was really interesting to me because I didn't think this book would be out in paperback
probably for another year or so, depending on whatever the cycle or your publisher.
So I'm a little nervous right now that I have a counterfeit copy of a book about money laundering.
I thought of all people, you'd be super interested in how this happened.
It came from India to be full disclosure, but if you're looking at it, it's very legit.
You look at the spine, it has the penguin.
So maybe this is something that's going to come out in a year or is in a warehouse somewhere.
Like, do you have any thoughts around this?
Yeah, sometimes the publisher's the one to ask about this, and honestly, the publishing
industry for anybody who's worked with it or in it, this becomes no surprise, but yeah,
they do make copies available in sort of a paperback form internationally, and particularly
in markets like India where they'll make that available.
But there will be, I mean, there will be an actual proper paperback, a new edition with
probably a different cover.
So you've got your hands on some contraband goods there, Ariad, and how you've done that.
That's so interesting.
I was thinking I had, which was crazy.
So I owe you, I think, about $25, and I'll make sure to get that to you.
But yeah, no, I was thinking like the irony is so crazy that I ended up with a counterfeit
copy of a book about money laundering.
Exactly.
It's probably crazy on so many levels.
Anyway, it does seem like it is the actual book, and I have read it, and it's really
fantastic and we're going to dig into that in a moment.
Thank you.
The kickoff, as we typically do on TRM Talks, just hearing a little bit about your journey.
Yeah, fair enough.
Well, I started out as a general journalist and I'd worked for an internet company many
years before.
So whenever a tech story came up in the newsroom, I would be the one to say, "Oh, I think
we should do that.
We can do that story."
And gradually became us a technology journalist.
And at the time it was the sort of Steve Jobs product launches.
Steve Jobs was still the head of Apple and Alive at that point.
The problem was the stories were kind of light, they were kind of not particularly hard news.
And what worried me about that was that, number one, I came into the job to do hard news.
The idea was to break stories and to reveal things that were hidden.
But secondly, if you're doing these lighter weight stories, they tend to be at the end
of the program, at the bottom end of the running order.
And so if something juicy comes in at the top, you get pushed off the end.
And so we kept getting pushed off the end, and so I decided, "Well, we need to do harder
news stories.
We need to actually start investigating things."
So that's how I started down the kind of investigative track.
And the brilliant thing about technology stories for an investigative journalist is there's
almost always a trail.
It's very hard not to leave some artifact or some trace on the internet.
So for investigation, it was really, really useful.
So that's how I started down the investigative journalism sort of route, as it were.
Started getting interested in cybercrime, because obviously that's hard news, people
being affected, people losing their life savings, companies getting hacked.
And I realized that was, you know, that was an area of interest, a zone of interest.
So I started looking at that, put out a book called crime.com, which was everything you
ever wanted to know about cybercrime, or at least back when it was released in, I think,
2018.
And one of the chapters of that book was about North Korea, and the now famous Lazarus Group
and the Lazarus Heist podcast grew out of that.
And then the subsequent book grew out of the podcast.
So that's sort of how I've ended up covering this stuff.
But I'm sure we get onto this, you know, one of the interesting things about covering
North Korea is the country's accused of stealing money to keep the regime afloat.
Now if you steal money, particularly if you're under sanctions, you have to find a way to
launder that money.
So that's what sort of led me to this current phase of looking at money laundering specifically.
That is such an interesting connection.
Just going back a tiny bit, do you remember what it was?
Like what was that hard news story that you're like, "I don't want to keep getting buried
here.
I'm going to go from an Apple release to this."
Like do you remember what that like hard story was that got you at the top of the show?
Yeah, absolutely.
We were getting up the running order.
I was starting to do, you know, more and more decent, what I regard as decent hard news stories.
And we discovered that, you know, the contactless cards that you pay with, we discovered that
if your phone has an NFC reader, you could download some software that would allow you
to hold your phone against a card and to pull the details off the card because the details
were amazingly, and I think they maybe still are, broadcast in the clear.
So that's your card number, expiry date and name.
You don't get the three digit number from the back, but of course what we discovered
was there's a whole bunch of sites at the time, Amazon included, where you didn't need
the three digit number.
You could just make an order using the card.
So we showed how anybody in a bar could loiter next to you, run their phone over your contactless
payment card, steal your details and then order goods on the internet.
And that led to the program.
And when you lead the program in TV news, if you're a TV news program and you lead, it's
very difficult to drop you because all of the headlines are, you know, cut and everything.
So you're almost un-droppable that stage.
That was the story that I was really proud of.
We led the program and I thought finally technology and tech security has arrived as
a news subject.
It really is.
It really affected regular people, which is like why it was such a powerful story.
People saw this and they were like, "I remember seeing this story.
What part of your career I want that I don't know that is well covered is your career's
a thesbian?
Tell me a little bit about the secret life of your mobile phone."
Yeah.
Well, we've been covering tech security for a while and data security and privacy were
a big part of that.
It's interesting.
The privacy world and the data security and information security world are sort of two
sides of the same coin, but weirdly they're separate industries in a way.
So privacy was a big part of what we did.
We wanted to show the data that was leaking from people's phones.
There's a project I launched at Channel 4 News called Data Baby, which was, we created
a fictional identity and we showed the sort of data that was leaking out of people's phones
out of their internet usage using this persona, this personality, which is called Rebecca Taylor.
We showed sort of, you know, lots of different aspects of the data leakage and privacy kind
of scene.
And we wanted to sort of take this on the road.
I wanted to put it in front of an audience and explain to them how this worked.
And so there's a program called Wireshark, which is a bit old now, but basically Wireshark
is amazing.
It sort of sits between your computer or your phone and the internet and shows you everything
that's going back and forth between them in a sort of grid pattern.
And then you can map where all of your data is going and you can look at the packets and
stuff.
It's really, really interesting software.
And as soon as I came across it, I thought, this is fascinating.
If we put this in front of an audience, they get it because you talk about personal data,
it's not really personal.
But if you have an audience of people and we would set up a Wi-Fi network and we would
start basically hoovering up the audience's traffic and putting it on the screen and
showing them using Wireshark, this is what your traffic looks like, this is where your
data is going.
And suddenly people are switched on because it's not somebody else's data, it's not
something out there that's ethereal, it's their phone on that screen.
And so we decided to take this on the road.
So in the end, we ended up doing the Edinburgh Festival.
We sold out.
We sold out the Edinburgh Fringe Festival, which was quite an experience.
Now, frustratingly, you can only do that a few hundred people at a time, but the impact
that you have on those few hundred people who've been in the audience and been in the
theatre when that happened, you know, we really sparked off some interesting conversations
with that.
They just put you in a whole different world.
I think one of the interesting things about being a journalist, about being a person generally
is trying to put yourself in different situations and trying to learn from them.
So suddenly we're dealing with theatre people, we're meeting actors and directors and producers
from the world of theatre and just made me encounter a whole bunch of new people.
It's really, really interesting.
It's so cool.
You're extraordinary.
And it really does speak to this, the storyteller, I think, that you are.
And when you read a Lazarus Heist, it's really a story about people.
And you know, that's something that was one of my major takeaways is like, hey, I mean,
we talk all the time about North Korea stall a billion dollars, they launder it through
this mixer, this is what they're doing.
But the reality is like, you know, there was a hacker behind that and that person had a
family and, you know, how were they indoctrinated and how are they, you know, threatened into
this role?
And I feel like you sort of piece that out.
And you really do the same thing with rints, where each chapter is dedicated to a different
story.
But we'd love to kind of just, you know, kick things off with your take on the book and
maybe the process of writing it.
Yeah, it's interesting.
So anybody who's heard the Lazarus Heist podcast or read the book will know this is about North
Korea and the accusations of North Korea stealing money from banks and cryptocurrency companies,
among others.
And of course, whenever you steal money, as I say, if you've done it illegally, if you
steal money, it's criminal money, or if you're North Korea and you're subject to sanctions,
you have to hide the trail.
And so one of the interesting things about the Lazarus Heist, both the podcast and the
book is if you're paying attention on the surface, it sounds like a cybersecurity cyber
crime story.
But actually about between a third and a half of the story at any one moment, it's about
money laundering.
It's about how they're moving the money around that actually that became for me one of the
more interesting bits and the sort of crazy cast of characters they ended up working with
to do this, that there was the famous Instagram influencer, Hush Puppy, who originally hailed
from Nigeria but ended up in Dubai, helped laundered millions of dollars of money for
North Korea.
And his sort of accomplished big boss, this guy, you know, is born with a silver spoon
in his mouth in Canada and ended up teaming up with Hush Puppy.
And so these characters became really interesting.
But more widely, the world of money laundering became interesting to me.
And I sort of realized that unless you have the laundering, you can't do the crime.
So going back to the Bangladesh Bank example, the famous 2016 attempted theft of a billion
dollars.
They broke into the bank in 2015, and they were there for a solid year.
They had access for a solid year, which makes you wonder, well, why didn't they steal the
money earlier?
Why did they risk waiting around for a year?
Well, the answer is laundering.
It took them a year to line up the routes to escape the money.
If they hadn't have got those routes, they wouldn't have been able to steal the money.
And as I've looked at this, it's not just cyber criminals who rely on money launders.
It's all types of organized crime.
They all make money.
They all need to hide it and move it somewhere.
So you've got this whole industry serving almost every type of organized crime.
And without that industry, the crime doesn't happen.
If we could get rid of money laundering, a lot of crime, like a lot of crime, would be
solved overnight.
Really well said at TRM.
We talk all the time about adding friction to the money laundering process to make it
harder to execute that, which ultimately should disparage at least some of the criminal
activity to begin with.
One thing you do really well, I think, to make this point, again, like I've thought about
money laundering most of my career, but it's like, I love when you get a new perspective
on it.
And reading the first chapter, well, the preface into the first chapter on Pablo Escobar of
the book, it's this idea where you're having just piles of cash.
And like, what the hell am I supposed to do with this?
And that's really the birth of money laundering.
And now, and we can get into crypto in a minute, but like, crypto is the same problem except
you're on block chains, essentially.
But talk me through that a little bit.
Well, no, it's interesting, the major problem with cash cash is brilliant because it's anonymous,
which is great.
The problem is it's bulky and it's suspicious.
In fact, there's a whole bunch of problems with cash for criminals.
So briefly about Pablo Escobar there, Pablo Escobar's problem or one of his problems
was that what made cocaine brilliant for him as a product was it's packageable, it's small,
smugglable across the borders.
The problem is he was selling it for cash, which is bulky for every one plane of coke
he sent north to America to sell, he had to smuggle back two planes of cash.
So this became a huge issue, how you actually handle all of this cash.
And it's an issue for lots of types of crime gangs, cartel, drug dealing, prostitution rings,
people smugglers, a lot of it's cash business.
So firstly, it's bulky.
Secondly, it's suspicious.
Cash is innately suspicious if you have too much of it.
The police pull you over and you've got 100,000 pounds in your car.
They have the right to ask you where you got it, that is a legitimate line of inquiry.
It's obviously stealable, so a rival crime gang can come along and nick your cash.
And also, and this doesn't get thought about a lot, it's subject to inflation.
Obviously, inflation is a phenomenon in society.
So again, your cash is worth less the more you sort of hang on to it.
So for all of these reasons, you need to get rid of cash and to put it into some kind of
financial system.
And obviously go at the bank with a suitcase full of used 10 pound or $10 notes is again
innately suspicious.
So that's the birth of money laundering is sort of how do I take what is ultimately what
I wanted, which was cash, which is anonymous, but make it more solid and more usable by
putting it into financial system.
That's almost step one in your kind of money laundering journey.
And I think what the book really does is sort of tells that story, you know, first it was
cash.
And as we move more and more into a digital world, you're running into a lot of those
same problems.
I mean, right?
It's the same issue in crypto today.
One story that I love in the book is in the din sister case that you dedicated a chapter
of the book to, would you talk us through that case because I think it's one of the
most interesting.
Well, I was looking for a place to start the book.
I mean, the opening chapter is about Pablo Escobar, which I thought was a good idea to
start with.
Lots of people have seen narcos, the cocaine cowboy zero was sort of the birth of modern
money laundering.
But I wanted to sort of open up with a case that looked at that kind of cartel drug dealing,
big drug dealing, but looked at the move into cryptocurrency, which a lot of these groups
have done.
So yeah, it's interesting that you focused on the sort of all the other things that were
used for money laundering, all the other goods, luxury goods, cars, you know, putting money
into the store, likely as opposed to the crypto, because it did feel to me like this was a
really interesting transition case where crypto is like a small part of a much larger
sort of laundering scheme with that one of your takeaways as well.
Yes, they definitely weren't that particular gang were not laundering everything through
crypto.
But what was interesting was speaking to the police about this, there was a famous sort
of encrypted phone service called Encro Chat, which was a service used by lots of criminals,
encrypted phones kind of targeted almost at criminals.
And when they started, the service was famously hacked by the Dutch and French law enforcement.
When they started interpreting those messages and decoding those messages between criminals,
they discovered a lot of traffic about cryptocurrency payments and I think that was a big eye-opener
actually for law enforcement, particularly certainly in Europe.
I think one of the most interesting stories in the book, and I love the way you sort of
transition from the Pablo Escobar, like the piles of cash to the DIN sister case where
crypto meets cash meets luxury goods.
Would you talk us through these characters?
Yeah.
So on the surface, the DIN sisters were a couple of middle-aged, quite glam sisters working
in north of England, in Manchester, and they ran a beauty business.
They ran an online beauty store where you could order all sorts of undrants to put on
your face and eyelash curlers, eyebrow curlers and stuff like that, not eyebrow curlers.
You can tell I don't really work in the beauty business.
Me neither.
But by night, they were drug dealers.
They were actually smuggling in heroin and selling it on the streets of northern England.
They had a whole network of couriers who were doing this.
And to go back to that point about currency and a hard cash being suspicious, the police
kept stopping the couriers.
So the DIN sisters hit on a scheme to, instead of using cash, they would swap the money into
Bitcoin.
Now that makes a lot of sense because if you think about it, they've got to get the drugs
from somewhere.
We think it was Pakistan.
If you're earning cash in the UK, you've got to somehow bundle up that cash.
Take it to some money broker who's going to send it across to Pakistan.
When it arrives in Pakistan, the cash there, is that going to be secure?
How's that all working?
Whereas if you look at Bitcoin, if you can change your money to Bitcoin, it's outside
the traditional banking system.
So there's no suspicious questions, awkward questions being asked.
It's instantly transferable to whichever wallet you want in the world, anywhere in the world.
But the best thing I think for the drug dealers for this was when the investigation was done
afterwards, it was discovered that they were paying something like 4% fee for this service.
Now anyone who knows anything about money laundering knows that's an absolute steal.
You'd normally pay 20% as much as 60% for those services.
And that translates into tens of thousands of pounds more profit for the drug gang, which
of course they can spend on more drugs.
But what's an interesting postscript to this is when the DIN sisters were convicted, they
got about 10 years each of the DIN sisters.
The police seized all sorts of stuff, there's an amazing list of everything they seized,
Mercedes cars and Rolex watches and a whole wardrobe of designer labels.
What they didn't seize was cryptocurrency, because the police frankly had their hands
full with everything else, weren't able to recover the crypto.
So the money that the gang made in crypto, potentially when they get out of prison in
whatever is five, six years time, depending on how long they serve with their whole sentence,
they can actually potentially pick up the crypto that they earned, and it might even
be worth more depending on how Bitcoin's price goes in the future.
So again, in terms of that long-term planning as money laundering, that makes a lot of sense.
You're putting your money somewhere where potentially you're going to make a long-term
return.
And if you do do jail time, you can come out and get your money back.
It's interesting.
One chapter that really hit home for me, I was a federal prosecutor for many years focused
on human trafficking and child exploitation and those types of cases.
And I will tell you that almost every one of them had Backpage.com in those cases at
the time.
I then went to do a short detail for about six months in the U.S. Senate when I was
at DOJ, and I was on the permanent subcommittee for investigations, which did a lengthy report
on Backpage.com and the way it was being used, particularly tying village voice and a lot
of things you actually do in the book really well.
But talk to me about what you learned in your research around Backpage and that whole story.
So Backpage surfed this very fine line between advertising prostitution and advertising sexual
services.
Now, the other problem with that was some of the services being advertised there quite
clearly to investigators involved, children who obviously can't consent to sex.
So they are being trafficked.
That is, that is sexual abuse of children.
And so the whole slew of cases went against Backpage to try and get them to stop these
services being advertised.
Backpage fought back using Section 230, which is a law which allows internet companies to
effectively publish first and kind of ask questions later.
Now a lot of the time that works in our favor, you know, we're able to publish stuff from
Facebook and not have to join a queue of people, you know, getting our stuff vetted before we
post it.
The downside of course is often harmful material will be posted online and we only get to ask
questions about it later once it's been posted online.
That's exactly what Backpage did.
Now, what was interesting, the money laundering angle was as Backpage started to be discovered
and sniffed around by people like yourself and other people at the subcommittee and Department
of Justice, this became a big issue because they were making money from these adverts
and they wanted to hide that money and particularly hide it from the credit card companies, Visa,
MasterCard, American Express, who increasingly were saying, we don't want to touch this
money.
You know, you may have a legal defense, but we just don't like it.
And so Backpage used a lot of financial chicanery to launder and wash their money and that's
what eventually got them.
Only in the past few months, actually, we've had the conclusion of the final legal case
against Backpage.
The site was shut down and this final legal case against one of the founders and was found
guilty on money laundering.
The only charge they found him guilty on was money laundering.
All the other charges, enabling prostitution and so on, all of them dropped, all of them
didn't go.
Money laundering, they got the person on in the end.
And I find that super fascinating.
Again, it's money laundering.
If you can crack down on the laundering, you can prosecute, you can get people and you
can stop them doing the crimes.
How did you feel piecing that together?
Honestly, it was really difficult.
So the first book I wrote, I mentioned is called crime.com and that's pretty much chronological.
It starts certainly in the 1970s, the birth of computers really, the birth of modern computing
and the birth of computer hacking at the same time, which at that point wasn't really a crime
because there was no money to steal really.
It was a sort of fun exercise, a kind of intellectual exercise.
So you have this chronological narrative.
Lazarus Heist, again, is mainly chronological.
We start really with the Sony hack of 2014.
That's the sort of big launch pad for the Lazarus Group.
We go all the way through.
And obviously, the story is, as you know, it's still going on and there's cases we can talk
about.
They're in the book, rinsed, you know, tornado cash, the amazing laundering of $625 million.
Rinsed isn't like that, doesn't have that chronological narrative.
And so trying to work out how to piece together a book about money laundering where you don't
have a chronology to fall back on, you don't have a narrative art, is quite difficult.
What I ended up doing was using the three stages of money laundering, sort of three classic
stages of money laundering, there's placement where you put your money into financial system,
there's layering where you mix it around, and there's integration where you finally
get suspended and enjoy your ill-gotten gains.
And so I use that as the pattern.
I was like, okay, we're going to look at each of those stages, and we're going to look at
how technologies change each of those stages.
And then in the final chapters, we'll look at how it all ties together with this amazing
North Korean example that the $625 million theft.
Teach us money laundering 101 through the stories that you tell and rinsed.
Well, I mean, placement, going back to the Dinsisters example, for them, placing this
money, there's tens of thousands, sometimes hundreds of thousands of pounds of cash from
the heroin dealing they were doing.
Placing that into a bank was a non-start, so it was never going to happen.
Placing it into a money broker who could send it to Pakistan or wherever, okay, but risky.
There's another financial system that has a whole new financial system of cryptocurrency.
Placing it into that financial system, well, that's as simple as finding someone who'll
turn a blind eye to where the money came from, of whom there are quite a lot apparently.
So again, that sort of placement side, technology's starting to really kind of pick up on that.
Layering is the stage where you mix the money around.
You move it from place to place, account to account, to try and throw the investigators
off the scent.
Because the problem is, even if you place the money into the bank and you convince a bank
or a crypto firm to take the money, if you're then found out, if you're subsequently discovered
to have committed the crime, they can trace the money to the bank and seize it.
So putting it into the bank's not enough.
You need to take it from the bank, put it into another bank and another bank and maybe
turn it to crypto and change it into gold and back into cash.
That's the layering stage.
And then the final stage is integration, where you clean your cash, you then take it and
spend it.
And as I say, they're not spending it necessarily on prostitutes and cocaine, they'll often
be spending it on property.
They'll be spending it on art or valuable assets that will increase in value and be
there when they get out of prison, if they go to prison.
And again, each of those stages being influenced by technology.
The layering stage, you've talked briefly there about Helix, which is a crypto mixer.
You should take crypto and mixes it around with other people's crypto.
That's layering.
That can be used for layering.
In fact, Helix was entirely about that.
Helix is an interesting one because it was clearly advertising on a dark net market saying,
"If you've stolen funds or you have elicit drug proceeds, we're your service."
And that's essentially what they were prosecuted for.
Ultimately, money laundering and conspiracy, Larry Harmon was the administrator.
He pled guilty and has gone to jail subsequently.
But you also write and there's a full chapter dedicated to our tornado cash, which is sort
of different.
Talk me through sort of like why tornado cash was interesting to you.
I think it's been interesting to you.
How do you use it in the book to continue this narrative?
It's interesting.
I was looking in the book for the payoff chapter, that you're working up to something
and you're trying to push the readers through and say, "We're going somewhere with this.
This is going to end up somewhere really, really quite stunning."
And so you're looking for that showstopper.
And so tornado cash is it.
It's almost like it's the kaleidoscopic case that involves every aspect that I wanted to
pick out from the book, including North Korea.
The story goes that North Korea, it's alleged, broke into a video game called Axie Infinity.
It's hugely lucrative and popular video game.
And it's a phishing email they sent.
It was actually a job offer to one of the employees, which is an amazing way of managing
to fish somebody.
They managed to get into the company, break in digitally to the company.
They realized that the entire game was built on crypto assets.
So you play these little characters called Axies based on axolotl salamanders.
You could actually buy and sell your team of Axies and you could buy and sell the plots
of land in the game.
It was for sale.
The whole game was basically effectively a marketplace, but all those things you were
buying and selling were actually in the end, ultimately crypto assets that were moved around
on a blockchain within Axie Infinity.
So if I sold my team to you, you'd be buying my team, but actually a crypto asset would
be moving on the blockchain from me to you, from my wallet to your wallet.
The North Koreans realized this and realized that if they could work out how to steal all
that money, there was a huge amount of money there to be stolen.
There was a blockchain inside the game inside Axie Infinity, tracking the players' deals
effectively, their trades, but the whole thing was funded through ether cryptocurrency, which
is tracked on the Ethereum blockchain next to the external blockchain.
In order to make the two ledgers match up effectively, Axie Infinity invented a thing
called the Ronin Bridge, which, as the name suggests, was a bridge between the external
ledger and the internal ledger, and the hackers realized if they could take over the bridge,
they could steal the money, which is what they did.
The bridge, in effect, it was nine computers around the world that validated all the transactions
and matched up the ledgers, and most importantly, if the ledgers didn't match, they would move
assets from the internal blockchain, the external blockchain, to level everything up.
The hackers broke into the game, they managed to find their way to the bridge, they managed
to take over the bridge, and they stole what was worth at the time $625 million.
Now, I've been slightly circumspecting the book about this, but I'm more bold in podcasts
like this one.
This is the biggest theft of all time.
The problem then, of course, for the North Koreans is you've got half a billion of hot
crypto.
Where do you go with it?
Again, it's that thing of you can't go to the bank with the suitcase of money.
That's what led them to Tornado Cash, which is a mixer, like Helix, that mixes crypto
around.
What's interesting about Tornado Cash that's slightly different to Helix is it was set
up as what's called a DAO, it's a decentralized autonomous organization.
The idea was users of Tornado Cash would control the service.
The guys who built it at one stage just destroyed their passwords and said, "That's it, we don't
run it anymore."
If you interact with Tornado Cash, if you use it, you're given a voting token, and you
can use those voting tokens to make changes to the service.
Effectively, we're taking our hands off the rudder, and it's now over to the users to
run this thing, and it's done using smart contracts.
These are effectively pieces of code, pieces of software that you can use to dictate what
happens to your money.
This whole thing Tornado Cash was this supposedly a rudderless, leaderless, captainless boat
on the high seas of crypto.
The North Koreans apparently dropped $455 million of crypto into Tornado Cash, which
did exactly what it was programmed to do, rinsed it around, washed it around, spat it
out to a new wallet address.
Maybe you'll correct me if I'm wrong, Harry, but as far as we're aware, we don't know now
where that money is.
It has been laundered, it has gone, potentially into the coffers of the North Korean government.
It's interesting.
Obviously, it becomes what we do play a lot.
The role in is that cat and mouse game that occurs throughout that process.
We have the ability to trace through many mixers today, but can that elicit actor, can North
Korea get to an off-ramp to convert those funds to more usable currencies before law
enforcement using tools can get there?
That's really become the issue.
I will say that we'll see funds from a hack that happened years ago, the Harmony Bridge
Hack, for example.
We'll still see funds from those hacks being laundered today.
I think because of this cash issue that you identify in the Pablo Escobar chapter, and
that is like, the more money you steal, the harder it is to launder.
That's true in crypto as well.
It's easy to move smaller amounts of funds without being identified much harder to move
larger amounts of funds.
We talked about the Biffeneck hack.
That was the fatal flaw, really, at the end of the day for those hackers.
It's interesting.
The way cryptocurrency has solved a lot of challenges of laundering, but created a whole
bunch of new challenges, and a lot of that comes down to the fact that you can't eat
crypto.
At some stage, you have to change the crypto into some usable thing.
For North Korea, it might be missile parts or nuclear weapons.
For drug dealers, it might be a yacht somewhere or a Lamborghini.
You can't, in most cases, the vast majority of cases, buy those things just without crypto.
You have to, at some stage, say, off-ramp your crypto into fiat currency or get it into
some financial system out the other side, some fiat-based dollar or pound or yen-based
system.
Actually, we may have talked about this, but the actual infinity job is the high point,
I think, of North Korean crypto hacking so far.
There's been a bit of a slowdown subsequently, and one of the theories behind that is possibly
that that glut of money that they're trying to now launder is taking so much time to percolate
through that it's caused a backlog effect as a jam, which again goes back to that point
of, "Cut the laundering.
You cut the crime."
If that is true, it seems that because of the difficulties of laundering all that money,
the other crimes have been slowed down because there's now a sort of queue effectively money
moving through.
I don't know whether that's the case.
It sort of logically makes sense.
It does.
I get asked this question all the time around have tornado cash, Sinbad, other types of mixing
services that have been sanctioned or actions have been against these services.
I get asked all the time, "Do I believe that those have had an impact?
Is this helping?
How do we measure that?"
My usual answer is something around, "Look, I think we're seeing significant friction
added to the laundering process.
We're making it harder and harder.
They're still going to have success with the exploits and the laundering the funds, but
if we can add some friction there, and I think sanctions, I think enforcement actions have
had some impact, but this is a very, very determined group of very sophisticated actors."
What for you was the most interesting part of writing this book?
I think for me, there's a couple of chapters in the book about a crime group called the
Black Axe, which originates in West Africa, particularly Nigeria, during the 1970s.
It's an amazing sort of backstory where it starts out as a political emancipation movement
really and then morphs into this horrific crime gang.
Most of the crimes that the Black Axe carry out, people will have heard of, they are behind
a lot of the romance fraud that goes on where people get seduced online and then tricked
into parting with money.
There's sort of modern twist on that where there's cryptocurrency scams involved, business
email compromise where business will get an email from their supplier saying, "Hey, we've
changed our bank account, please pay our new bank account," and then the email comes from
the hackers and the new bank account is the hacker's bank account, cartel drug dealing,
again, people trafficking, prostitution, forced labor, Black Axe is involved in all of it.
They're an astonishing, what I call a polymorphic criminal enterprise, and again, coming back
to the money laundering point, they're the interfloor of money laundering.
If you steal money from a victim in Germany and you want to launder it and exit it in
Hong Kong, there'll be Black Axe operatives who'll help you that they're bound together
by sort of close bonds effectively through this movement that they've all joined.
I'd heard, I think, a bit of Black Axe, which has had no idea of the scale of this thing.
The book just scrapes the surface of it.
I just look at the money laundering side, but it's an absolutely astonishing sort of
group of people, and the methodology's behind it are sort of endlessly fascinating.
I find that interesting because it's almost like wherever the Black Axe puts down roots,
it takes on a different type of criminality.
So depending on where they are in the world, they will sort of commit a different type
of crime.
I'll tell folks, we're going to drop this podcast as soon as August 13th comes around,
so folks don't have to do what I do and can buy an actual copy of Rinst, not something
that I got into FedEx from India.
Jeff, thank you so much for joining us.
It's kind of crazy when I think about it.
I've literally spent the last, I don't know, 15 or more years of my life thinking about
money laundering, and when I can visualize it in new ways or visualize these types of
typologies that we talk about every day, it's like you feel like it's a gift.
Jeff's book and then this conversation really does that, right?
This idea where money laundering at its heart is just, it's to solve a problem, and that
is you're dealing with piles of cash and overwhelmed by the volume.
This story about Pablo Escobar needing two planes back for every one plane of Coke for
the cash really, I think, speaks to the issue.
What the book really does so well is tells that story of money laundering from those
kind of early days of cash, bulk cash smuggling, to kind of what we have today, which is sophisticated
money laundering in the crypto space, and he talks about where crypto in some respects
makes money laundering easier, right?
We can move larger amounts of funds faster than ever before, but we can now track and
trace those funds.
I love the way, my favorite part of the conversation was when he breaks down the different pieces
of money laundering from placement to layering ultimately to integration, and really kind
of tells that story with what he calls the showstopper North Korea's hack of the Ronin
Bridge where they stole $625 million and laundered much of that through tornado cash.
It is this ability I think that Jeff really has, and we saw this in Lazarus Heist, both
the book and the podcast, to tell really complicated stories about money laundering and financial
crime and cyber crime in a way that there are characters, and we got into those characters
in the book today, the Den Sisters, and Hush Puppy, and Big Boy, and Coin Ninja, and Helix,
and Larry Harman, I mean, just even actually summarizing this right now, I'm like, wow,
we talked about a lot of stuff today.
So it's really extraordinary to tell stories that I think really hammer home the point
about money laundering.
Next on TRM Talks, I sit down with Tax Bits Europe lead Max Bernt for what I promise will
be the liveliest discussion of crypto and tax you have ever heard.
If you love the show, leave a review wherever you're listening to it.
Follow us on LinkedIn to subscribe to our newsletter the weekly roundup to get the latest
news on crypto regulation, compliance, and investigations.
TRM Talks is brought to you by TRM Labs, the leading provider of blockchain intelligence
and anti-money laundering software.
This episode was produced in partnership with Voltage Productions.
The music for this show was provided by Ecolix.
Now let's get back to building.
Podcast Summary
Key Points:
TRM Labs provides blockchain intelligence software for law enforcement and financial institutions.
Ransomware attacks have increased, with payments traced using blockchain intelligence.
Ransomware-as-a-service model lowers entry barriers for cybercriminals.
Jeff White discusses his book "Rinsed
The interview delves into topics like investigative journalism, cybercrime, and money laundering, including cases like the Lazarus Heist and the Din Sister case.
Summary:
TRM Labs, headed by Erie Redboard, offers blockchain intelligence software aiding law enforcement and financial entities in combating financial crimes in the digital asset space. Ransomware attacks, including recent incidents with CDK Global and AT&T, have been traced using blockchain intelligence. The rise of ransomware-as-a-service has made cybercrime more accessible, with developers offering malicious software to affiliates for profit sharing.
Jeff White's book "Rinsed: From Cartels to Crypto" explores money laundering in the tech industry, shedding light on cases like the Lazarus Heist and the Din Sister case. The conversation on TRM Talks covers investigative journalism, cybercrime, and the impact of money laundering on organized crime. White emphasizes the crucial role of disrupting money laundering to curb criminal activities effectively, showcasing the evolution of financial crimes from cash to cryptocurrencies.
FAQs
TRM Labs provides blockchain intelligence software to support law enforcement investigations and help financial institutions and cryptocurrency businesses mitigate financial crime risk within the emerging digital asset economy.
Ransomware as a service is a business model used by cybercriminals that allows non-technical attackers to deploy ransomware attacks with minimal effort, where experienced ransomware developers create the malicious software and offer it to affiliates.
Law enforcement, using blockchain intelligence, can track ransom payments and disrupt ransomware groups by tracing payments made in cryptocurrencies.
Money laundering is essential for criminal activities as it helps hide the trail of illegally obtained money, making it harder for law enforcement to track and identify the perpetrators.
Cash poses challenges for criminals as it is bulky, suspicious, can be stolen, and is subject to inflation, leading to the need for money laundering to convert cash into a more usable and less suspicious form.
The Dinsister case is highlighted in the book as an example of a cartel's transition into using cryptocurrency for money laundering, showcasing the shift from traditional cash-based transactions to digital methods in criminal activities.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.