pastry Profile picture
Jun 23, 2024 25 tweets 10 min read Read on X
$24 million dollars, luxury watches, and the largest sim swap hack ever.

this is how teenage gamers became the most wanted cybercriminals, their entire empire collapsing from greed before they could even drive..🧁
this story begins with ellis pinsky, who at 13, loved video games and trash-talking other players.

one night - he took the trash talking too far.

after a match, a player messaged him: "how's the weather in irvington?"

his heart sank.. Image
how did he know where he lived?

ellis shut off the game.

this was the next level of the game, he thought.

the internet held many secrets, and he wanted to unravel them all.

this new game of hacking stimulated him more than video games ever could..
over the next few months, ellis, mentored by fellow gamer "ferno", learned how to uncover hidden information abt people online.

ferno taught him everything abt hacking in exchange for the passwords, emails, & ssns ellis retrieved.

he also introduced ellis to the ogusers forum. Image
ogusers was the start of an empire for ellis.

it was a place where young hackers shared their techniques to steal valuable social media handles - which could then be sold for money.

ellis was really good at this.

his abilities quickly surpassed his mentor's. Image
he mastered sql injections & sim swaps.

sql injections allow you to retrieve unauthorized data from databases (such as a username or email).

whereas sim swapping involves bribing wireless carrier employees to switch a sim card from a target's phone to one in your control.
Image
Image
combining these techniques, all ellis needed to hack was a username or email.

he could attempt to log in, hit "forgot password," then receive the 2FA code due to the sim swap.

this method allowed him to obtain terabytes of data, making him a valuable commodity on ogusers. Image
at 14 yrs old, he had insiders working for him at every major carrier & "could hack anyone."

it was only a matter of time until he used his powers to steal millions - not thousands of dollars.

that opportunity struck him in jan 2018, when a user named harry dmd him.. Image
"hey man, could you hack an at&t phone? i have a target i think is good."

this wasn't your ordinary target - it was michael terpin. you may know him as the founder of .

terpin owned hundreds of millions worth of crypto on exchanges. match.com
Image
ellis and harry wanted it.

on jan 7th, 2018, they executed their attack, right when terpin was attending a crypto conference in las vegas.

a rogue at&t employee facilitated the sim swap, and the two were in.

they reset the password to his email, then ran a script. Image
it scanned his email for references to crypto passwords or private keys.

on one of terpin's outlook emails, it caught a file named "keys."

"holy shit.’ we open that file, & see that there’s just a bunch of keys to various wallets.” - pinsky recalls.

the two had just made $24m. Image
ellis used 6-7 of his friends from ogusers to help exchange the stolen funds to btc.

in return, they kept ~$20k per batch.

one of these was fellow sim swapper nicholas truglia.

however, he wasn't as compliant as the rest. Image
after an initial $500k, ellis sent him another $1m to exchange for btc.

then, he left the call.

nicholas had different plans.

he wanted all the money for himself.

& unlike ellis, he wasn't too safe abt it.

in fact, he was the reason their house of cards came tumbling down.
Image
Image
nicholas was a notorious sim swapper.

although he only played a small role in the terpin incident, he was responsible for dozens of other hacks.

over the years, he gradually revealed himself to friends and unbeknownst to him - one of them was taking notes.. with a lawyer.
Image
Image
this friend had been compiling evidence against him for months - and sharing it with terpin's lawyers.

part of this evidence includes pictures of nicholas attempting to sim swap in the act.

furthermore, law enforcement was closing in on his paper trail.. Image
in the months after the terpin hack, nicholas carried out 6 more attacks.

the react task force traced hacked funds back to wallets on coinbase.

they subpoenaed coinbase for the information..

and this is what they got: Image
on nov 13th, 2018, they raided his apartment.

inside his icloud backup, they found messages the day of the terpin hack:

"today my life changed forever."

"i'm a millionaire i'm not kidding. i have 100 btc."

he also hired escorts & ordered them tickets to the superbowl. Image
in 2019, terpins lawyer's submitted a civil lawsuit under the rico act.

this ordered the perpetrators to pay $72m worth in restitution to terpin - 3x the hacked amount.

however, nicholas was only responsible for less than 10% of the hacked funds.

the rest was ellis'. Image
terpin was already onto ellis.

shortly after christmas in 2018, one of his lawyers emailed ellis' mom.

the email accused ellis of being the mastermind behind the $24m hack against terpin.

after viewing the message his mom hired him a lawyer. (fake email)
w his lawyer, ellis returned what he stole in full - 562 btc, a patek watch, and $100k in cash under his bed.

however, that wasn't the end. when ellis returned the money, its value had fell to $2m.

on his 18th birthday, terpin surprised him with yet another lawsuit.
this time requesting he's paid the usd value at the time ( > $10m) + $72m restitution.

two weeks after this news went public, 4 masked men broke into ellis' house - likely expecting to find the money.

ellis had long expected this moment, even bought a shotgun in anticipation. Image
his family was alarmed by their security system, and barricaded upstairs pointing a shotgun at the door until police came.

the fight didn't end there.

after a drawn out legal process, the two came out on favorable terms.

nicholas plead guilty to several counts of wire fraud.
he was sentenced to 18 months & ordered to pay $20m in restitution to terpin.

he finished his sentence in 2023, & was arrested again for civil contempt after he said he did not have access to the funds to pay for restitution.

he could be held indefinitely until it's paid off.
Image
Image
ellis was too young to serve any time.

instead, he was ordered to pay an additional $22m in restitution on top of what he'd already returned.

he is currently enrolled at nyu studying computer science and philosophy. Image
if you enjoyed this thread, please consider leaving a like and retweet.

and remember to be weary of the kids you talk shit to online.

they might just take all your money someday..🧁

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with pastry

pastry Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @PastryEth

Jun 14, 2024
Hacking time to recover $3m worth of lost Bitcoin.

Sounds crazy, right?

This is how two white hackers cracked an 11 year old password behind this massive fortune.. 🧁
In 2013, an anonymous crypto user, 'Michael,' purchased 43.6 BTC (approximately $5,000 at the time).

He stored the BTC in a password-protected digital wallet.

The password, a 20-character string, was created randomly using a password generator called RoboForm. Image
Too paranoid to store the password inside RoboForm, Michael uploaded it to an encryption tool called TrueCrypt.

Good enough.. Or so he thought.

Eventually, the container storing his password got corrupted.

Any hopes of accessing it was gone.
Read 28 tweets
Dec 30, 2023
In February 2022, government agents swiftly entered a high-rise in NYC.

Their target: two individuals with over $4.5 billion in stolen crypto assets.

Their findings unraveled a fascinating story behind what is now the largest crypto seizure ever..🧁
Image
Image
This sum of money stems from a fateful evening on August 2nd, 2016.

On this day, investors were faced with terrible news: A crypto exchange had been hacked for 125,000 BTC.

Immediately succeeding the news, the price of Bitcoin plummeted 20%+. Image
The culprits?

No, it wasn't a group of North Korean hackers, or some teenage prodigies.

Instead, we have Heather Morgan, also referred to as "Razzlekhan."

Heather is a self-proclaimed economist, software CEO, and rapper.
Read 25 tweets
Apr 13, 2023
Layer 2 rollups have helped Ethereum scale by an order of magnitude.

Soon, there will be an upgrade that will reduce the cost of them by 10-100x, and shepherd in a new era of low cost on-chain activity..🧁
What is EIP-4844?

EIP-4844, also referred to as "Proto Danksharding" is an upgrade to Ethereum moving towards adopting an architecture called "sharding."
Sharding is a method that improves scalability by dividing a blockchain network into smaller units called ‘shards.’

Such a system enables multiple shards to process transactions in parallel, drastically improving scalability. Image
Read 10 tweets
Mar 17, 2023
How much will the @arbitrum airdrop be worth?

Let's dive into the protocol and compare it to its competitor to make an educated guess on how much one $ARB might be worth..🧁
Arbitrum and its competitor Optimism are layer 2 solutions designed to help Ethereum scale.

Layer 2 solutions process transactions off-chain, allowing for faster and cheaper transactions that are then settled on Ethereum.
Both Arbitrum and Optimism use a technology called Optimistic Rollups to bundle txs into a single proof and submit it back to Ethereum mainnet.

They differ in their smart contract compatibility, dispute resolution mechanisms, block confirmation times, & withdrawal periods.
Read 12 tweets
Mar 14, 2023
Recent events have shed light on how fragile our stablecoin ecosystem is.

Many are still reliant on centralized parties and expose us to their risks.

For this reason, I think we will see a huge shift toward decentralized stablecoins.

Below is my best bet on this narrative..🧁
Before jumping straight into the protocol in question, I would like to point out a few things about what unfolded this past week.

While a great stress test, it should raise some important questions for those involved in the cryptocurrency space.
Namely:

"Is it really decentralized finance if the fault of a single bank could result in our downfall?"

"Have we placed too much trust in centralized parties?"

"Has crypto become too dollar dependent?"

If you haven't asked yourselves these questions, the time is now.
Read 19 tweets
Mar 3, 2023
EigenLayer.

An idea so big that if it works, it will absorb the majority of $ETH in existence.

What is restaking, and how might it help hyperscale Ethereum? 🧁..
Eigenlayer is a protocol built on Ethereum that introduces the concept of "restaking."

Restaking allows users to re-use their staked ETH to secure multiple networks and earn rewards on their extended capital.
EigenLayer aims to address the challenge of fragmented security across Actively Validated Services (AVSs).

AVSs are systems used by modules that rely on inputs from outside of Ethereum, such as sidechains, data availability layers, keeper networks, oracles, bridges, etc.
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(