New wallet security measures on Alphabay

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Our primary role as the biggest online marketplace is to protect our
buyers and seller in case they get arrested and we must make sure that
nothing can be proven. As a way to achieve this, Alphabay implemented
additional security measures on its wallets to prevent profiling.

- --- How do we know that you are sending money to a Darknet Market? ---
Some sites like Circle and Coinbase are known for their rapidity in shutting
down accounts who send coins to darknet markets. How do they know? This
is done via a technique that we call "address input clustering". Let's say 3
users deposit coins to Alphabay, and they use addresses A, B, C. Three
other users deposit, and use addresses D, E, F. If I make a withdrawal and
get coins from A and B, blockchain analysis can reveal that A and B are part
of the same "cluster". The default behavior of Bitcoind is to combine inputs in
a single transaction, so it is assumed that 2 inputs used in the same transaction
are part of the same wallet. If I withdraw again and get money from D, E, F, then
we have another cluster. We now have 2 clusters: AB, and DEF. If another
withdrawal uses B and D, then we just linked the 2 clusters together, and
we have one big cluster ABDEF. The process goes on until we have a pretty
good idea on the marketplace's holdings, which is the technique used by
WalletExplorer.com. Sites like Coinbase and Circle make their own analysis
and hold a list of addresses, updated daily, that are presumed to be part
of a Darknet Market, and shut down accounts who get involved with an
address part of those "clusters".

- --- What consequence does this have? ---
Most major Bitcoin exchanges also analyze the blockchain this way, and file a
suspicious transaction report if a user is suspected to be involved in a DMN.
Although Blockchain analysis is not court-admissible evidence in the USA,
it gives the investigators a very good clue on where to start the investigation.
If you don't use a tumbler, you can be traced. Investigators obviously won't
bother following every transaction, but better be safe than sorry.

- -- How did Alphabay mitigate the issue? ---
As most of you probably noticed, in the past 3 days, withdrawals were sent in
multiple small transactions. We were still using the old wallet while testing the
new features. We are now using a brand new hot wallet with brand new
addresses. Transactions will be sent in small increments like now, with a
randomized fee and randomized time frame, and always using single inputs,
preventing all kinds of blockchain analysis. Alphabay's wallets are now totally
secret, and no service can shut you down for "illegal use". If you check the
"request single transaction" checkbox, your transaction will be sent like all
other withdrawals, but to a temporary address, and upon the first confirmation,
sent to your wallet, adding around 15 minutes to the process.
In addition to this new technique, we also take additional measures:
- - All addresses and transaction IDs associated with you are deleted after 7 days.
- - No more reusing of deposit address. All addresses are brand new.
- - All order notes are deleted after 30 days.

For up to 48 hours, deposits sent to old addresses belonging in the previous
wallet will be automatically added. After that, we will accept support tickets for
up to 5 days regarding missing coins (if any). Always check your Balance page
before depositing. 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCgAGBQJW0hEjAAoJEOAZpE/dncxmhtwH/jh2Afp1rGwc5K4vKZ55pyEo
42p8DbSFATN0rADigeM7rCNsxy2w8WsnTvLZ7/yvYoMp2ZKnOsLS5GUSg4GEJ/La
SlhpIuYGxgt7XXWODYJV2eOjaF46/S/fJb5ch26zzwWLI5YxIXV87pdu29wwAogD
x1Oe+CyVzOcsSVrHGPC6E3o5/3MffFJaLk3myHaBOpaaQPWf2siFVRlVFC0bOvz8
+sJggvVsT+5M9qvv6fdOb/0g26tpLY3wJ5WU1tVDBBpT4PEKriYBVk61MJwZlGyp
wNvGM3Zf4nSJQN6itP3y1D4HbKhybi4pT7u2j60Vq2A718VJjxDvk/yTsAyEo/s=
=McEm
-----END PGP SIGNATURE-----


Comments


[12 Points] d3emSt3rz:

Alpha Bay Mods just refunded me 1K$... People definitely get phished and lose btc on AB, but doesnt mean it's necessarily their fault... It's not fuckin Amazon


[5 Points] 180K:

Excellent move! I've said before, it's about pattern recognition and predictable behavior on the parts of markets that makes it easy for coinbase/circle to determine this is dnm activity. Good, this should be the new standard of operation. Keep the transactions random.


[5 Points] xxxMDMA:

You can downvote me all you'd like and say I am shilling for AB as I am sure many will but I am a vendor on AB. Have been for a good amount of time. Level 6 vendor, almost $100k in sales. Not .00001btc missing from my account since I have started. I keep paper ledgers, each one separate for each market, to keep track of sale amounts and make sure it all adds up.

Of course I use a unique password, have 2FA enabled, and never click a random link. Maybe everyone should do that too?

I do not know if AB is the "biggest market" as they claim and others dispute but I do know that my sales are triple on AB than they are on any other market.

If I run into an issue ever I am sure there will be a logical explanation.

As far as I can see, keep up the good work AB.

PLUR <3


[3 Points] ItsShatterDay:

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.


[3 Points] Vendor_BBMC:

Its already confusing with alphabay. Walletexplorer lists "old" and "new" alphabay wallets. Here is the balance of your old wallets - on 25th Feb when their use was discontinued:-

https://www.walletexplorer.com/wallet/AlphaBayMarket-old

I didn't realise that alphabay started 6 weeks after Evolution exit scammed. The first transaction is on April 30th last year (the very day gwern told us about subpoenagate). You are different carders though, right? Because evo's exit scam was a failure - I felt at the time that it would have happened finally on April fool's day if it hadn't been called.

Verto didn't pay his own admins. The German ones grassed him up to a BTVA member, we voted, I posted this https://www.reddit.com/r/DarkNetMarkets/comments/2zc89r/complaintwarning_british_tor_vendors_association/

The marketplace was gone within hours, then NSWGreat confirmed it that evening when he realised the gig was up.

Verto tried to prematurely launch it's replacement ("Ironclad") within hours to prevent the vendors swimming to agora but it wasn't quite finished. Then 2 weeks later it had a lick of paint and an extra funnel attached and he tried to launch "Revolver". He likes to show us he's fooled us all, he would have pointed out that the new marketplace name contains the word "Evolve", but of course we spotted that. I guess Alphabay started a month after that.

If R EVO LVER had taken off, I'm sure he would have run it for 11 months from April fools day, then started nonsense with its wallets for the last month, and then made a grandiose announcement that we've been fooled again on April 1st 2016. He's one of those hasty, easy-to-predict psychopaths

https://www.walletexplorer.com/wallet/AlphaBayMarket-old?page=83

here is the balance of the "current" wallets:-

https://www.walletexplorer.com/wallet/AlphaBayMarket

As you can see, they were first used on September 2nd last year:-

https://www.walletexplorer.com/wallet/AlphaBayMarket?page=6114

So I guess this will be a 3rd set.

264 btc is about 5 times what you usually hold on a Sunday. Not that we're constantly watching you or anything....(cough). The current bitcoin system has used a quarter of a million addresses so far. Here is a list of them:-

https://www.walletexplorer.com/wallet/AlphaBayMarket/addresses

It does indeed look like lots of different addresses are used to store people's balance, and what they see is a fake wallet dashboard that isn't connected to the blockchain. But you've been doing this for 5 months, what's changed? Is this your "transactiion malleability" that you're going to blame withdrawal issues on for as long as you can string people along?

This is just my personal opinion, not a BTVA marketplace warning. I only post from the BTVA account if we are in agreement


[3 Points] Vendor_BBMC:

Incidentally, most of the Evolution bitcoin hasn't been spent yet.

It was stashed in a load of wallets, then each one marked with one of these 0.005 btc payments

https://www.walletexplorer.com/txid/f8bf92b54254ed0dc6ce9cd1ed9dae3e7500820cd1b98d2c12af9a3882aed3a6

Ive never actually published this before. You can see the bitcoin being stolen out of Evolution here, on 18th March. (I expect one carder's market will exit and another will launch around this time every year):-

https://www.walletexplorer.com/txid/f8bf92b54254ed0dc6ce9cd1ed9dae3e7500820cd1b98d2c12af9a3882aed3a6

Only about 2,100 btc, when bitcoin was quite low. Sheepmarketplace stole 96,000 btc when it was $1000 per bitcoin.

Evolution's exit scam was cut short. Sheepmarket was a hundred alphabays, worth chasing through the blockchain.


Note to self:- stop looking at wallets, this is how you always start. Alphabay's vendors know it's run by carders and know what is going to happen.

Don't get involved.


[2 Points] samsungthrow123:

Does this mean that theres no need for tumblering when using Alphabay? I.e can just go straight from Exchange > ELectrum (tails) > Alphabay?


[0 Points] MitalikaSucks:

Alphabay rocks, and all the haters can continue ejaculating every time they hear the word Abraxas


[1 Points] block-anal-izer:

I sent you a private message on the AB forums about 6-9 months ago suggesting that you implement this feature, and you responded that you felt it was the responsibility of the user to protect their anonymity through tumbling. Glad you finally came around.


[0 Points] d3emSt3rz:

Can someone plz tell me what market is larger than AB???

Cause i keep reading it and idk why the hell anyone thinks it's not the biggest...Obv there isn't THAT many legit listings, but what market has more vendors,buyers,products,listings?


[-4 Points] Darknet_Retard:

How about you address the missing coins from users' wallets every day?


[-6 Points] octomarvel:

biggest online market.

Citation needed.

=)