Monday, July 14, 2014

Enjoy Sochi Spam Starting to Stick

My last post I talked a bit about the Enjoy Sochi block chain spam from February, and to my surprise I am coming back to talk about it again.  Despite the contribution of one kind reader, I still haven't been able to get my hands on any of the old unconfirmed transactions from the February spends.  Well, it looks like I won't have to because some new transactions have been generated, and they also have started to stick in the blockchain.

I'll spare you the tower of unconfirmed transactions and instead show a detail of some of the spends:

14 July 2014 detail of some Enjoy Sochi spam
What is astonishing is that some of these satoshis that have been sent out have already been spent.  Not everyone practices good coin control.

Another interesting tidbit comes in the dissemination of these transactions.  These spams were conformed in about three separate blocks:
Enjoy Sochi Spam Balance Early July 2014
The specific blocks are block at height 309657, 309740, and 310357.  If you drill into the coinbase of each of those transactions you get a pointer to a smaller pool at bcpool.io, with a web page title of GilHASH.io (which doesn't resolve at the moment).  This of course tells us nothing about the connection between the two, which could range from being in total cahoots to having a very liberal policy on accepting any and all transactions that fit.

What are the impacts of these transactions?

That someone would go through the effort to build these two towers, and then come back and make sure over 60 of the transactions clear (out of a little over 2000 possible) poses some interesting questions about scale and denial of service.  

First, if the whole tree were transacted at about 750 UTXO per transition, that would create over one and a half million new rows for the UTXO database, and would bloat it by about a third of a gigabyte (assuming that there are about 256 bytes per UTXO in the DB).  For a forensic database it is closer to a half a gigabyte of fluff when you include the back links.  That sounds like a lot except that the current block chain is about 20GB, so that would represent about 1-2% wasted from a single spam attach.

Second, this may have been designed to make "taint" calculations more difficult.  If every wallet had one more path to calculate that links increases the commutation time by increasing the number of paths to traverse.  Even if calculated in reverse the memory requirements can go up as well.  Although if you put some heuristics in your calculations (i.e. tell your code not to check for taint on sub-bit sized coins from a small list of spammers) you can avoid the combinetric explosion.

Finally, this has an impact on block propagation.  Each of the blocks containing the spam were each nearly a megabyte in size, which is the current network limit.  Some hashing pool are giving some pushback to generating larger block themselves based on the premise that they lead to longer delays verifying the block and (more critically to the miners) downtime in calculating what the merle root of the next block will be.  The longer the delays the higher the chance an orphan block race could start across the network.

But seeing unknowns like this pop up in the Bitcoin ecosystem is educational for all.  Who knows, this little experience might actually be a good thing.

Friday, June 27, 2014

Did You Enjoy Sochi? Not According to the Block Chain.

Back during the 2014 Winter Olympics an unknown party sent out 1200 separate satoshi sized transactions to over a thousand separate wallets.  Then these unspent outputs were sent out to other peoples wallets.  Much reddit freaking out ensued.  Astonishingly enough CoinDesk didn't cover the story.  I guess they were too wrapped up with the Mt. Gox saga, a larger investor story for sure. So the best discussions can be found on the tech boards, such as bitcoin talk.

You would think with such a large scatter spray or transactions someone would have cashed in that free money.  Right?  More asonishinly, the answer is no.  Not a single transaction.  But what is left over is the staging that set up the spam spray.  A chart of balance over time shows a narrow range of activity, all deposits no withdraws.
Enjoy Sochi balance over time

Most of the business happened before 10 Feb, specifically between blocks 284500 and 285200.

Enjoy Sochi Main Load Sequence
One question you should be asking however is how do I know the two addresses are tied?  Why am I speaking of them one and the same?  Here's the transaction graph of all of the loads occurring.  (warning: tall chart on load).
Enjoy Sochi Main Load Graph
This is about 600 transaction in two roughly parallel chains, representing all 1200 or so sochi addresses.  Here's a detail for those who don't want to zoom:
Enjoy Sochi Transaction Graph Detail
Each transaction sent two coins/UTXOs one to each of enjoy and sochi.  The change was sent to the same address, and the split went almost the same all the way down.  Except at the highlighted detail one small changes occurred.  The tower took a break between blocks 284840 and 284912, between 8 to 9 hours.  It then reduced the coin size form 129.99 bits to 107.49 bits.

So why don't we see any more evidence on the blockchain?  All of those thousands of transactions to other peoples wallets never confirmed.  After a while the nodes started forgetting about them and not broadcasting them, and eventually all the memory pool was emptied of those transactions.  None of them cleared because the didn't post a fee and never attained high enough priority to be included in a block (presuming the mining pools didn't explicitly bar those transactions).

The greatest loss of information, however, is that I cannot find any of these unconfirmed transactions on the internet, they have all gone to the bit bucket.  None of the block explorers I've seen keep long term records of all the unconfirmed or rejected transactions for all time.  The closest I've found is one that tracks it back to late February, about two weeks after this dust storm blew over.

So what was the motivation behind this?  We may never know.  As a spam attack it caused only negative sentiment and zero monetization.  If the goal was to clog up the free transaction pool I'de say it was a failure.  If any transaction had cleared then you could argue it took up space other transaction could have used, but no such luck.  If it was designed to slow down the transaction processing of the nodes feeding the minors, no one noticed.  These are questions we may never know the answer to.

Monday, June 16, 2014

US Marshals Bitcoin Auction: Not a Clean Wallet Sweep

Last Thursday the FBI announced it would be selling coins associated with the Silk Road not attributed to Ross Ulbricht AKA Dread Pirate Roberts or DPR (here is the US Marshals notice and a Coindesk story).  They claim to be auctioning off 29,656.513 065 29 bitcoins.  They have been kind enough to identify the bitcoin wallet (1Ez69SnzzmePmZX3WpEzMKTrcBF2gpNQ55) that contains the auctioned coins. What's great about bitcoin is you can look into the transactions and see what is going on.  First, lest's look at the activity on the address as a whole:

Silk Road Original Seized Wallet
This is quite the hairball of transactions.  Most for he coins actually seized by the US Marshals Service are stored in larger coins (10BTC to 2,500 BTC).  The bulk of the transactions are blockchain spam, either "marker" coins people claim they can use to track or using it to post random begging, political statements, or pump and dump claims on blockchain.info.  Here's the previous graph with all transactions prior to 11 Jun or so stripped out.

Silk Road Seized Wallet Unspent Coins

The green ovals are the leftover dust that the USMS didn't sweep into the auction coins.  I'm not sure why they missed those coins, because when you look at the wallet attributed to DPR it is a very clean sweep.

Here is the same analysis with the wallets believed to be associated with the DPR case (1FfmbHfnpaZjKFvyi1okTjJJusN455paPH / 1i7cZdoE9NcHSdAL5eGjmTJbBVqeQDwgw)
DPR Seized Wallet
Apologies, I had to downsample the image 1:2 to get the image under Blogger's image size limit.  But the organization of the coins is fascinating to explore.  I'm not sure what the obsession with 324 BTC wallets is however.  It places the value in the USD$50,000 range at the time of the movements.

DPR Seized Wallet Unspent Coins
But the old transaction strip is downright readable without scaling.  No stray dust from that sweep.  This makes me wonder why all of the coin spam got swept into DPRs coins but only some into the Silk Road Seizures.

Thursday, April 10, 2014

FTB #05 - My Heart Bleeds for Two Factor Authentication



The HeartBleed bug is making waves across the internet, and has already been implicated in at least one BTC heist.  CryptoCoinNews has a detailed account of coin being stolen from BTCJam.  We take a quick look at the tumbler network the coins were fed into.

Follow the Bitcoin 1.2 Released. Now on the Mac App Store!

Follow the Bitcoin version 1.2 has been released.

The biggest news is that the app is now on the Mac App Store [link].  I had to change the icon to appease a reviewer, but I hope to get the old icon back.

You can also install the app as a plain old installer.  I have installers for Windows [exe][msi], Mac [dmg] and two bundles for Linux [rpm][deb].  Follow the Bitcoin version 1.2 is also free as in speech, so you can also install and run the software from source yourself [zip][tar.gz].  You will need Java 8 and a cursory knowledge of Gradle to build it from source.
DownloadMD5 Sum
Windows .EXE  27553c582085f8a1419df5686302a1c0
Windows .MSI  99f4c6338422c9770a7ac7d17db510ce
Mac OSX .dmg  306d8a73e06481b5bbb811dff01bd91b
Linux RPM  b054980cb066ca2195f56db25c2a3dd4
Linux deb  12ca47614be5632de8f3ac1e7b6676ab
source in a zip  f53a335c03684f1ad7dcc914e56bb03c
source in a tar.gz  870380e6d9c4ed9bc4441b29f57f28e6

There is one principal new feature in this release: some rudimentary analysis functions.  You can climb and descend Split Pyramids (like the one form Mt. Gox).  You can also follow what I term Spend and Change trails.

I hope to have a video about Spend and Change next week, but this week I jumped at the chance to show a tumbler in action.  Expect to see that video later today.

Edited to add MD5 sum table.

Thursday, April 3, 2014

FTB #04 - Not All Pyramids are the Same



There was at least one other pyramid that showed up on the blockchain the same weekend as Mt.Gox found their 200K.  But I don't think this is Mt.Gox bitcoin, and I don't think it is Dread Pirate Roberts bitcoin either, although it has the taint.

The BitcoinTalk thread I first showed: https://bitcointalk.org/index.php?topic=310600.0
And another wild speculation thread: https://bitcointalk.org/index.php?topic=508683.0 - note that the old Mt. Gox leak lines up with some of his pre-sweep deposits.

And the Github project for this tool: https://github.com/shemnon/FollowTheBitcoin

Thursday, March 27, 2014

Mt. Gox Pyramids were not a closed system

Last week Mt. Gox all but admitted the 200K in pyramid splits were theirs, and that they were moving bitcoin that was reported to the Japanese authorities over their civil rehabilitation.  The implication was it was all money Mt. Gox already had.  Not so fast.



While I have only identified pocket change (not even enough to buy Dorian lunch anywhere, maybe a candy bar) there is definitely coin that did not exist in Mt. Gox's system prior to the split and merge games they just did.  Principally because it was mined until after Mt. Gox went into bankruptcy.  You don't need to presume malice, because it most likely represents standard distributions from GHash.  Maybe.