Bitcoin is losing its lustre with some of its earliest and most avid fans — criminals — giving rise to a new breed of virtual currency.
Privacy coins such as monero, designed to avoid tracking, have climbed faster over the past two months as law enforcers adopt software tools to monitor people using bitcoin.
A slew of analytic firms such as Chainalysis are getting better at flagging digital hoards linked to crime or money laundering, alerting exchanges and preventing conversion into traditional cash.
The European Union’s law enforcement agency, Europol, raised alarms three months ago, writing in a report that “other cryptocurrencies such as monero, ethereum and Zcash are gaining popularity within the digital underground”.
Online extortionists, who use ransomware to lock victims’ computers until they fork over a payment, have begun demanding those currencies instead. On 18 December, hackers attacked up to 190 000 WordPress sites per hour to get them to produce monero, according to security company Wordfence.
For ransomware attacks, monero is now “one of the favourites, if not the favourite”, Matt Suiche, founder of Dubai-based security firm Comae Technologies, said in a phone interview.
Monero quadrupled in value to US$349 in the final two months of 2017, according to coinmarketcap.com, placing it among a number of upstart coins that that rose faster than bitcoin, the world’s most valuable digital currency. Bitcoin roughly doubled in the same period.
In monero’s case, criminals are snapping it up because bitcoin’s underlying technology can work against them.
Called blockchain, the digital ledger meticulously records which addresses send and receive transactions, including the exact time and amount — great data to use as evidence. Match an address to a crime and then watch the bitcoin universe carefully, and you can see the funds disappear and reappear in other locations.
Sleuths have developed databases and techniques for digesting that information to eventually nab wrongdoers. Say, for example, a coffee shop in Berkeley is known to have a certain bitcoin address, and a wallet used by an extortionist transfers the same amount there every morning at 9am. Police can stop by and make an arrest.
Started in 2014, monero is very different. It encrypts the recipient’s address on its blockchain and generates fake addresses to obscure the real sender. It also obscures the amount of the transaction.
The techniques are so potent that software that flags coins suspected of being obtained through crime now tags just about anything converted into or out of monero as high risk, according to Pawel Kuskowski, CEO of Coinfirm, which helps exchanges and other companies avoid tainted money. That compares to only about 10% of bitcoin, he said.
“What we treat ‘high risk’ is something that’s anonymising funds,” he said in a phone interview. “How are you going to prove that these funds are not coming from illegal sources?”
Monero is one of many privacy-focused coins, each offering different security features. Its main competitor, Zcash — which isn’t known to have a significant criminal following — can offer even better privacy protection. Instead of creating fake addresses to hide senders, it encrypts their true address. That makes it impossible to identify senders by looking for correlations in addresses used in multiple transactions to pinpoint the real one — a vulnerability for monero.
Still, Princeton University researchers recently developed a tool that helps them analyse Zcash transactions at least to some extent — but they haven’t been able to crack monero. And Zcash high-security features can’t be used on disposable burner phones, a favourite of criminals eager to stay anonymous.
Developers behind monero say they simply created a coin that protects privacy. Most people use it legitimately — they just don’t want others to know whether they’re buying a coffee or a car, Riccardo Spagni, core developer at monero, said in a phone interview.
“As a community, we certainly don’t advocate for monero’s use by criminals,” Spagni said. “At the same time if you have a decentralised currency, it’s not like you can prevent someone from using it. I imagine that monero provides massive advantages for criminals over bitcoin, so they would use monero.”
Yet criminals are probably only a fraction of monero’s users, according to Lucas Nuzzi, a senior analyst at Digital Asset Research, which provides research to institutional investors.
“As with any disruptive technology, many of the initial use cases revolve around illicit activities,” he wrote in an e-mail. But as everyday people grow concerned about privacy and surveillance, “there is utility in these currencies that go beyond just a means of exchange for illicit goods”. — Reported by Olga Kharif, (c) 2017 Bloomberg LP