Detecting Monero Miners with Bpftrace(blog.px.dev) |
Detecting Monero Miners with Bpftrace(blog.px.dev) |
That doesn't actually matter at all. Monero is used for these purposes probably just because it's mineable only on CPU, thus viable to mine on ordinary hardware. (Bitcoin requires ASIC and Ethereum high-end GPU)
Counterintuitively, I think this also makes it more susceptible to nation state attacks, since you can easily deputize fleets of existing CPUs to 51% attack the network, whereas no nation state on the planet can easily get enough sha256 ASIC miners to attack bitcoin, not even accounting for the enormous electricity requirements to sustain a destructive attack.
Then again, the consolidation of bitcoin mining as an industry is also a systemic risk compared to millions of individuals in the network mining. Tradeoffs.
I guess the controllers of these botnets seem to agree that there's no reason to kill the cash cow and (aside from the fact that they're running a botnet) don't tend to act maliciously towards the network.
You're not wrong, but it can be and is mined on GPUs. Not sure about the payback period though because it is very CPU sensitive and the top benchmarks are for AMD's EPYC processors which don't come cheap. An i9-12k handily mines several times more than an Nvidia GPU so GPU mining payback is also potentially slow.
At least according to the online guides it's also a losing proposition relative to the costs of electricity. So then allegedly the only way to profitably mine it is on someone else's energy and maybe their hardware too. For anyone truly seeking anonymity it seems like far less work to buy Monero from a localcoin vendor rather than mint your own, unless you have a lot of free time and hardware on your hands. Which may explain why antivirus software assumes if you're mining with xmrig, you've been pwned.
What if you set up several sock puppet mining pools, all supposedly independent and in competition with each other, and beat the existing pools on fees by enough that miners join you en masse? That would take some investment on your end as you would have to run pool infrastructure at a loss. But if you are a nation state, it's not a huge investment. You don't need to have any mining hardware of your own if you offer miners better returns for the use of their hardware than the other pools do.
Once your pools, taken together, have a dominant share of miners, I would think you could run a 51% attack without ever acquiring a single ASIC. The reputation of your pools will not survive but I think you could complete a 1 hour attack (reversing 6-conf transactions) before you lose the miners.
Would this work?
I would bet more on cloud infrastructure providers being able to do better than nation-states in a CPU takeover of an ASIC-resistant network like Monero.
Motivations aside, it still comes down to cost though, and without any handwaving, Monero just isn't that important to take over.
ethash, the algo ETH uses, is memory controller bound (aka: memory hardness), not compute bound.
https://www.vijaypradeep.com/blog/2017-04-28-ethereums-memor...
They have no problems giving us space heaters though.
As largely a joke, I sometimes fire up monero mining on my laptop at home because the average proceeds exceed electricity cost, even though it’ll take me about a decade to ever get a block. The heat is just cake icing.
Why don't you join a pool to get some of that average payout?
Don't delete it.
Hiding processes and tidying up the CPU time (adding it to System Idle Process on Windows, etc.) is Rootkits 101. This technique has been documented in books for 15+ years. If they don't get the info from you, they'll get it somewhere else just as easily.
I wouldn't feel bad about it. The article provides info for security experts about a potential attack vector that exists. That doesn't change if you unpublish the post.
Keep it up!
I'm wondering, how would one go about finding one of these rootkits? Looking through loaded kernel modules for anything "weird"?
EDIT: I should really start reading the articles before going to comments, how to find these is litterally what the article is about..
I frequently receive emails from anonymous persons asking for help and even some of them are willing to pay me to set up it for them… so you can imagine what these last ones are using it for.
"We want to detect traces of RandomX (the CPU-intensive mining function for Monero) running on a cluster. "
This isn't for "Has someone rooted my laptop and started mining Monero on it", this is for "Have any of the nodes in my cluster (of potentially thousands of machines) been rooted and had Monero miners dropped on them." Your comment about being pwned totally applies to your container orchestration or hypervisor though...
https://hackaday.com/2022/01/19/identifying-malware-by-sniff...
From docs: > Web mining is infeasible due to the large memory requirement and the lack of directed rounding support for floating point operations in both Javascript and WebAssembly.
So you can do whatever you want, but you will end with nothing.
I've bought goods and services directly with Monero plenty of times. I've paid invoices that the merchant put in Bitcoin, while using a third party to pay in Monero, which the third party then paid in Bitcoin.
Now in the 2020s I can swap Monero directly to SECRET network, a Tindermint/Cosmos blockchain where all smart contract executions are private (such as the amount and quantity of your erc20-style wrapped Monero), allowing further bridging over to the EVM ecosystem for all the liquid DeFi trading activities, and Tornado cash if desired.
and the times when I use KYC to convert it to fiat, I haven't cared either. I like that the OTC desk or exchange doesn't even receive the address I sent from, much more similar to wiring from another bank account, where the receiving bank can't look at all your prior records and balances at the source of money and just has to assume the other place is compliant. it should be obvious that someone with an illicit source of their Monero will need to reintegrate their value into the broader economy first, so that they can account for it properly. with access to the entire DeFi ecosystem now, that is extremely easy.
all crypto users should restore that level of privacy.
It's certainly going to matter come tax season to businesses which are/will be forced to convert Monero to local fiat.
> I've bought goods and services directly with Monero plenty of times. I've paid invoices that the merchant put in Bitcoin, while using a third party to pay in Monero, which the third party then paid in Bitcoin.
What exactly do you buy with Monero?
You're still relying on this pool of independent miners to not defect after you initiate your attack.
Also a 6 block re-org is not unheard of and does happen naturally with the standard consensus rules on rare occasion. That's not enough to cause massive destruction of confidence. Security and confidence in your transaction's immutability has always been a continuous function of how much work has been piled on top of it, and how much energy it would take to redo that work. If you are transacting a very large amount of money, it behooves you to give it even more than 6 blocks for real confidence.
Even if this was a realistic way to cause a 6 block re org..it seems like tons of work for a relatively small attack
But also, this would a purely destructive attack. A 51% attack isn't something that would ever allow a single entity to actually take control of the network, because you either a) obliterate public confidence and crash the value of the token, making mining a pure cost and the network worthless, or b) you incentivize the honest network participants to fork the network away from your computational dominance, leaving you with a ton of wasted money and possibly a worthless fleet of miners.
There is nothing unique about crypto or monero in that regard, what did you have in mind?
It would push people to p2p, at the expense of cryptocurrency prices. Big win for the environment and people hoping to use crypto as currency. Big loss for people holding for speculative gains.
I haven't mined in years and I know they changed away from the cryptonight algorithms but I used to mine on both CPU and GPU.
| CUDA # | AFFINITY | 10s H/s | 60s H/s | 15m H/s |
| 0 | -1 | 1710.7 | n/a | n/a | #0 01:00.0 NVIDIA GeForce RTX 3080 Ti
| - | - | 1705.3 | n/a | n/a |It also means that bitcoin miners are completely tied to the success or failure of the bitcoin network, since their hardware is worthless for any other application, and therefore can't be easily coerced to harm the network. A network of miners who have generic chips could be more easily coerced to harm the network since their hardware wouldn't be a complete sunk cost.
Bitcoin hardware isn't worthless for any other application, any other sha256 based network works just fine (see BCH). The problem there is that it is just ripe for 51 attack because there can only be one top coin on each algo/compute layer. BTC = ASIC, ETH = GPU, Monero = CPU. The rest of them are all interesting datapoints on https://www.crypto51.app/
Seems like a misleading comparison, to get into a position to be able to do this you'd need significant investments in specialized hardware for the likes of Bitcoin and Ethereum. I've seen estimates of multiple billions of USD. And keep in mind that should the attack be discovered, which with coins running on open ledgers seems likely sooner rather than later, the price is going to tank, trust in Bitcoin will be broken and your special-purpose hardware will likely massively lose value. You'd have successfully destroyed billions of your own money.
On the other hand, the real cost of attacking some smaller coins may be even lower than that, because botnets are free or the electricity may simply be stolen, which happens a lot and can easily be done in less developed countries where the utility companies don't have sophisticated meters keeping track of where it all goes in the neighborhoods.
Still. I am inclined to call that "impractical". In the same way softfloat-in-JS miners are impractical. A vast botnet of such might buy a coffee after a year or two.
At a certain point, slow enough turns into impractical, and then practically impossible.
[1] http://www.righto.com/2015/05/bitcoin-mining-on-55-year-old-...
The problem with that is that the rental market is an open bid supply/demand market. The second you start to rent out enough hashrate, the rental price also increases. That isn't factored into the numbers.
You are correct that the cost of capex/opex for ETH/BTC is in the billions, which is also what makes them so secure and attacking the network would also destroy the network. It is a brilliant feedback loop.
That is, after all, the whole idea behind asymmetric cryptography. You could perhaps crack some things by brute forcing until the heat death of the universe, but that's so slow as to be impossible for all practical purposes.
> What are advantages of doing all those steps using Monero instead Fiat? I understand that you can hide your trances but if you buy legits things, who cares?
I had a balance of Monero. It was convenient. Online payments are a lot easier when you don't have to fill in a bunch of information, what "steps" were you imagining? I didn't have to go get Monero, I had already accumulated it. Just like the Miners in the article have already accumulated it, just like anybody earning for Monero by providing a service had already accumulated it.
in any case, compared to attempting to pay with fiat, a crypto payment form typically lacks:
- First Name,
- Last name,
- Company Name,
- Street Address,
- City,
- State,
- Postal Code
- [] Is Billing Address the Same or Different.
- Card Number
- Security Code
- Expiration Date
Similar to how convenient Apple Pay is this decade. Crypto users had that last decade, Monero users had that and less leaking of their finances.
Aside from the pared-down user experience, I also like that the merchant isn't storing all that personal information just to process a transaction, but thats just icing on the cake, not really a motivating factor.
Two decades ago actually, Bitcoin launched in 2009.
its been 8 years now, I guess off the top of my head:
groceries, domain names, registered agent services, compute instances, graphic design, press releases
0: search.marginalia.nu
So looking up
Monero tail emission
might help, but I don't think there is more formal literate that just focuses on that, maybe some enthusiasts in university have something on SSRN
This is really basic stuff. You will never be caught unless other evidence leads them from the original crime to you.
Unless you fuck up it’s not possible to link incoming Moneroj to any specific source, this means that you can fairly easily hide your money laundering activities even from somebody with full visibility into your business.
Unlike criminal law where you are "innocent until proven guilty", in most AML/KYC situations you are "guilty until proven innocent".
I’ve dealt with AML/KYC for cryptocurrency businesses with much higher volumes, nobody ever asked for anything crazy. Just basic accounting, website urls, linkedin profiles.
> You live in some fantasy land if you think you can just say "oh, I just received 100 dollars worth of Monero from 1 million unknown entities, my $100 million is totally legit, fuck off"
I think the only takeaway here is that “323” is too stupid and greedy to survive as a money launderer. Don’t try to cash out $100M in monero at once, live a wonderful life with $5-10M a year.
That's pretty much the whole NFT craze, but without Monero which makes it even dumber.
You pay taxes on stolen gains. The IRS is explicitly forbidden from reporting the gains themselves.
>IRC 6103(i)(1) provides that, pursuant to court order, return information may be shared with law enforcement agencies for investigation and prosecution of non-tax criminal laws.
Were they legit businesses or illegal?
It makes a difference because there's more than just you and the KYC exchanges reporting, and it's survivor bias to assume they appear the same.
> It makes a difference because there's more than just you and the KYC exchanges reporting, and it's survivor bias to assume they appear the same.
Exchanges are usually the least of your problems, it’s the banks.
Even very high risk businesses don’t face scrutiny which isn’t easily overcome when all of your incoming payments are anonymous and untraceable. It’s really not hard to create a fake ecommerce business that would be entirely indistinguishable from a real one.
White collar law enforcement is an illusion, backed by the occasional example.
There are 13k FBI special agents and most have case loads focused on things like "murder" than some e-commerce website with traffic numbers that don't add up.
A one hour cursory look on public clearnet hacking forums will surface hundreds of felonies by people with poor opsec, Feds scroll past them on a daily basis. It's not what they're after.
And no, the IRS has been trimmed to bones for decades, they probably audit <10 laundromats via water and power analysis a year, the same way Apple built literally two iPhone recycling robots (that do a thousand devices a year) but spend millions on marketing.
That's the harsh truth.
Where I live, THC is illegal, and its distribution usually ends with time served.
Interestingly, CBD (more accurately THC-less) stores are everywhere, taking prime locations in city centers, blaring thousands of positive reviews on Google Maps. Their top product is CBD oil (or rather, THC-less cannabis oil). Prices of their products are suspiciously similar to that of their illegal counterparts.
Yet when you pass in front of such stores, there's usually just a single person tending, sometimes with a friend because it gets boring as there's virtually no customer.
It's basically the caffeine pills + decaffeinated coffee product split, where caffeine is illegal.
Following the supply chain would not only find the laundering, but also the distribution and production of a substance considered illegal.
But cops stick to chasing dealers, and the fisc doesn't really chase businesses that seem to pay their taxes.
Second, just obviously spend a little money and time on those things? It’s a minor cost to run shitty ad campaigns.
The business doesn’t need to be good, it just has to look real. Do things a real business would do, except unlike a real business you will have a 100% chance of success.