Earlier this afternoon, the DoJ announced they had seized the bitcoin (specifically, the private key) from the #ColonialPipeline ransomware attack. How might that have happened? Here is a working hypothesis. [1] @ahcastor@BennettTomlin@KimZetter
The attackers were operating a bitcoin full node and using the default attached wallet. Their full node was running on a hosted server in Northern California per “Warrant to Seize Property Subject to Forfeiture”. [2]