episode.ascii — live render
● episode

The Treasure Hunt

TL;DRHardware hacker Joe Grand ("Kingpin") used fault injection to crack a Trezor hardware wallet for Dan Reich and his friend, who had forgotten the PIN to ~$3M in Theta crypto they'd bought for $50K in 2018.

The story of the hunt for a couple million bucks in lost crypto. With Joe Grand AKA Kingpin from the L0pht.

Check out Joe's YouTube channel: https://www.youtube.com/c/JoeGrand/featured

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: I mean, I'm an equal opportunity hacker.

Speaker 2: Back in 2018, a guy named Dan Reich and his buddy decided to buy some crypto. They buy $50,000 US worth of a new token called Theta. They shuffle that crypto around a little bit before eventually transferring the all important keys to a physical hardware wallet. The idea behind a hardware wallet is actually pretty simple. Instead of you holding a copy of the private key that lets you control all that crypto, or storing that key on the servers of a crypto exchange, you can store those keys on a physical device. A little thumb drive style machine protected by a pin.

Speaker 1: So you could have a massive amount of money that is protected by, you know, a simple four digit pin.

Speaker 2: That's not Dan, by the way. That's Joe, who we're gonna meet in a little while. As long as you have that hardware wallet and you keep that PIN secret, only you can access that crypto. It's almost like keeping something really, really valuable inside of a combination safe. You obviously need the safe and you need the combination. So the value of those theta tokens they bought then did what a lot of crypto does, and it it crashed down to half of its value. And then it spiked, and then it crashed again. And eventually, Dan just said, yeah, I want off this roller coaster. Let's cash out. But his friend, ironically, a professional poker player, which would suggest having a very good memory, had forgotten the pin. So they start guessing and guessing, trying to get access to their money.

Speaker 1: Anytime where there's a PIN or password or something a human has to remember, generally, if they don't have it written down somewhere and assuming, you know, if that paper might get thrown away, which happens often, people forget their passwords and their PINs, and they can't get access to things, especially when you think about cryptocurrency. You know, like, if you're using your bank card and you have a four digit PIN, you're using that pretty often. A lot of people are buying cryptocurrency and then sitting on it, hodling, as you might say, and, they don't use their PIN very often. So you set up the the hardware wallet, you enter your PIN, throw it in your safe or wherever, and then say a year from now or two years or five years or ten years goes by, and then you wanna access your your cryptocurrency, and you don't remember your PIN.

Speaker 2: But this hardware wallet where they'd stored the keys, a Trezor hardware wallet, has two very important security features regarding that pin, that combination to the safe, so to speak. First, every time you guess wrong, the amount of time you have to wait until you can guess again doubles, which is inconvenient. But second, and this is the important part, if you guess wrong 16 times, the wallet would erase itself. And the only copy of that private key to all that crypto vanishes. So Dan and his friend guessed, and they guessed, and they guessed about a dozen times. And then they stopped, lest they erase the only key to what was still tens of thousands of dollars. Stuck in this weird limbo, In possession of a seemingly uncrackable safe, but not of the combination to that safe. Call it a really hard one lesson. Call it a very expensive story. Until around the end of twenty twenty, when all that theta did the other thing that crypto sometimes does, and it just went to the moon. From a low point of about $12,000, it starts to climb in value until Dan and his friend had at its high point about $3,000,000 locked inside of that little device. Which is, I think we can all agree, too expensive a story. So they started looking around for a safecracker.

Speaker 3: We're joined today by the seven members of the loft.

Speaker 2: A brief aside. There's this really cool footage of the first congressional hearings focusing specifically on cybersecurity. It happened in May 1998, and in it, the seven members of the loft

Speaker 3: hacker think tank in Cambridge, Massachusetts.

Speaker 2: Testified in front of Congress about really just the idea that all of the computers we were building more of our infrastructure on are vulnerable to attack.

Speaker 3: Due to the sensitivity of the work done at the loft, they'll be using their hacker names.

Speaker 2: And one of those first publicly televised hackers went by the code name

Speaker 3: Kingpin.

Speaker 2: Like any good crew, they all had kind of a specialty, and Kingpins was hardware hacking. Electrical engineering, the physical stuff. The kind of person who could take apart a machine and just figure out how it worked.

Speaker 4: Good morning. My name is Kingpin. I am the youngest member

Speaker 5: of the loft and one of the electrical engineers and hardware hackers. While some of

Speaker 4: the loft members concentrate on software programming, I work with hardware design and implementation of electronic circuits. My interest in

Speaker 2: Kingpin's legal name is Joe Grant. And in the decades after that senate hearing, Joe went on to have a storied career as an educator, a TV show creator, and a hardware hacker. So in 2020, when Dan Reich went looking for someone with the electrical engineering and hacking knowledge necessary to crack a hardware device that sole purpose is to be uncrackable, well, all roads led to Joe.

Speaker 1: I'm formally trained as an engineer because when I was a kid, you couldn't make a career being a hacker. Like, it wasn't even it wasn't even an option. I mean, you could make a career being a hacker, but you probably would eventually get in trouble for it. So I'd always wanted to be an engineer. And then on nights and weekends and after school, I was a hacker. Right? So I was able to see both sides of that, and and and that's exactly it. It's like the design and and the reverse engineering or the undesign are really two two sides of the same coin. It's just how you approach, the problem.

Speaker 2: It's estimated that people have lost track of roughly 3,700,000 or about $80,000,000,000 worth of Bitcoin alone. Electrical engineering never used to be that useful of a skill in a treasure hunt, but now it suddenly is. So Dan and Joe made a deal. And Dan got on a plane to Portland with a little hardware wallet worth a couple million bucks in his pocket to meet Joe Grand in his home lap to see if they could crack the treasure inside.

Speaker 1: And, that's the benefit of being a hacker is, like, you know, every every chip in a in a system may have some sort of weakness undiscovered or already discovered that could be exploited in some way. So it's just a massive landscape of fun physical things to mess with.

Speaker 2: This is the treasure hunt Here on

Speaker 5: Hacked.

Speaker 2: So Joe Grand has gotten into YouTube. He makes these really, really well produced YouTube videos about these hardware hacks that he does. It's where I got a bunch of the audio that I'm using in this episode. You should definitely check his channel out. But because of those videos, now, Joe gets a lot of emails from people who have lost access to their crypto looking for help. But back in 2020, when all of this started, he wasn't really known as a guy that can hack crypto hardware wallets in the way that he is very publicly known for that now. And he gets this email from Dan Reich outlining this situation. Back then, it was not an email he typically got.

Speaker 1: But I got one that somebody had had lost their pin, for their for their Trezor, Trezor One cryptocurrency harbor wallet, and it was just a very well written email. You know? It was well thought out. They had clearly done their research. They knew what research was out there already. They knew what my skills were. So they'd clearly done some investigation before reaching out to me, which which is hugely appreciated. You know? Like, a a lot of unsolicited emails I get, people haven't done their research, and they ask questions about things that are completely online already, things that I've already put online. So, yeah, this email just struck me as being something that I should should maybe investigate a little bit further. And, so I reached back out, and I the first thing really I wanted to make sure is that they were you know, that this guy was legit. I wanted to know his story. I wanted to have a a Zoom meeting so I could actually see his face, see his surroundings.

Speaker 2: So Joe gets on the horn with Dan, and he learns a little bit about him. Dan is technical. He's trained as an engineer, and he really understood the risks of going into a project like this, of trying to crack a piece of hardware like they're trying to do. If we go back to that safe and combination metaphor, it's almost like whatever is inside of that safe is extraordinarily delicate. Dan understood that first, this is kind of doing surgery on a piece of hardware. You're prying an apart manipulating it in ways that are like dangerous enough that you could theoretically lose the information stored on that wallet just by trying to access it. If you took one wrong turn in this process, the money could vanish. And second, he understood the amount of research and legwork that goes into a project like this. Because hacking a hardware wallet in a way that has never been done before isn't a try unplugging it and plug it back in kind of problem. It is a dedicate a couple months of your life just researching this problem kind of problem.

Speaker 1: So he kind of understood the risks of going into this project, the fact that we're physically tampering with his device to try to extract these, you know, the recovery seed out of it to get access to his cryptocurrency. So it really was like this perfect scenario, because I think a lot of times people don't necessarily understand the how hard hacking is. Whether it's hardware or software or whatever. Like, the legwork that goes into this stuff can take months or years of people banging their heads against the wall to find something that works. And, and then you usually only see the end result. Right? You only see this as success. You don't really see the whole thing. And luckily, this particular attack that I was using had already been done. It it had been proven that these types of devices can be hacked. The problem is those were, you you know, public presentations that only had to be basically done once on a device to prove the device could be hacked. But it wasn't robust enough or to the point, where the risk was reduced enough to make me comfortable doing it on a device that actually had a huge amount of money on it. So that was the legwork for me is taking that existing work and then trying to, first of all, understand everything I possibly could about the attack, for my own personal, education and then trying to figure out if I could reduce the risk to a point where it would be suitable for Dan to fly across the country with his device, and us try to hack it.

Speaker 2: Joe goes out and he buys three of these Trezor hardware wallets, and he starts to experiment. Joe wasn't the first person to try and crack these things. So there were some public case studies, there were some giants whose shoulders he could try and sit on. Publicly given talks where people had found different vulnerabilities. But again, as you have different versions of wallets with different versions of firmware installed on them, each situation is just different. So he's looking to the way this has been done, but he's trying to apply it to what he is very specifically trying to do. It's almost like a lawyer looking for precedent in legal texts, or a doctor pouring over medical case studies.

Speaker 1: Yeah. I mean, that's a that's a great point. It's kind of thinking about, you know, doctors reading medical studies. Right? And and you kind of learn how a test may be worked on certain on a certain population, and then you have to take that and apply it to your own, patients. So I think the research is hugely important. I mean, part of the beauty of of the hacking community, at least what I grew up with, is if you discover something, you share it with other people. And whether it's full technical details or at least showing some high level process, but letting people know that that's possible. And then people take that and build on it, and and maybe somebody writes a paper, maybe somebody gives a talk, maybe now somebody makes a video. But it was all about sharing information when I was a kid, you know, for bragging rights, but also for inspiring other people to then go and do something with it. So the sharing of information is what makes, to me, what makes the hacker community so special, is that information sharing through these hacker conferences, through these presentations and videos and things. So the research part, and and seeing what other people had done up to that point is hugely important. And it's something that if you skip that part, you're basically recreating the wheel. Right? If you don't know what's happened in history, you're gonna waste a lot of time reinventing those things. And, yeah, I mean, it it's it's the first thing I do every every time I work on a project is is the information gathering, the research. And there's nothing wrong with building on other people's success or building on their failures. Right? Understanding what their failures are.

Speaker 2: So Joe has his three wallets. He has his case studies, and he starts to dig. And remember, whatever tactic he ends up figuring out, it can't be like a brute force thing where you guess the pen over and over again. Because you only get so many guesses before that device wipes itself. Itself, which is how Joe arrives at a technique called fault injection.

Speaker 1: So we basically couldn't use just like a brute forcing the pin because there was the pin counter and that would erase it. What we ended up doing is something called fault injection, where we're basically causing, like, a very quick kind of brownout of the core voltage on the CPU that basically causes the the chip to kinda skip over an instruction or return an invalid response to that instruction, something that kinda screws up the internal logic of the chip. And if if you do that at just the right time while the chip is is verifying if it has security enabled or not, you can downgrade the level of security and then continue on with an attack to try to extract the the recovery key. And, that essentially, you have unlimited tries.

Speaker 2: So he's testing this technique. And he's testing it, and he's testing it. And eventually

Speaker 1: Eventually, I was able to unlock the device and downgrade the security.

Speaker 2: He was able to unlock the device. Hooray. Right? But even though he had gotten in

Speaker 1: But it turns out that I had corrupted something in the flash memory itself. So once I had downgraded security, it never reset. So that just proved how un unpredictable things are. Like, if I had corrupted the memory in a way that instead wasn't beneficial to me, but in a way that could have locked me out forever or even worse, erased the contents of the memory, those are the types of things that you just don't know what's gonna happen. When you're dealing you're basically dealing with physics at this point and hoping that, you know, something something misbehaves properly, not misbehaves improperly, and it's totally a crapshoot.

Speaker 2: So Grand is trying to troubleshoot this problem in his approach, and he's experimenting and iterating. And eventually, he stumbles into this new solution inspired by all the case study hacks that came before, but still uniquely his own. It had to do with the specific version of firmware that he figured Wrike probably had installed on his wallet. And with this specific version of the firmware

Speaker 1: For some reason, during the initialization of the Trezor, when you plug it in, it copies your recovery seed, your your private key information from its nonvolatile area of the chip, so in flash memory, into RAM. And RAM is a volatile memory area. Meaning if you if you remove power, those contents go away. But RAM is also much faster to to to access. So I'm not exactly sure why that information was copied into RAM, but that was a key part of our attack.

Speaker 2: If he could glitch the device at the exact moment, he could downgrade the wallet security and read the RAM where all of the good stuff he was looking for was temporarily stored. And since all of that important info was just copied into RAM, there was less likelihood of it getting accidentally erased than the other techniques he tried. But, and this is really, really important, it required thousands of attempts to get the exact timing to find the exact moment that would let him downgrade the wallet security. Using automated software, it was hours just waiting with no guarantee that because it worked once it would work again. With no guarantee that because it worked on Grand's tests, it would work on Dan's wallet. The funny thing about this is that later, when Joe told Trezor about all this

Speaker 1: The response from Trezor, basically was like, oh, yeah. We know about the fault injection, and Joe did that attack on an old version of firmware, 1.6 o. So they were they were kinda downplaying the the end result. But the reality is, first of all, most people are not gonna upgrade their firmware of their device because you're gonna load the cryptocurrency on it. You put it away, and then you forget about it, right, until the value goes up or until you need to access it and you get it back. So just like people forget their pins because they don't use it, they're not using their device to do firmware updates. I also know from experience that I don't wanna upgrade my firmware until it's been tested and proven by other people, but it's also really inconvenient.

Speaker 2: But the technique that Grand had cooked up, it was hopeful. Enough hope that it was time to try with the real thing. Enough hope for Dan to put the wallet in his pocket and drive to the airport and get on a plane. Joe told him to try and not let the hardware wallet go through like the security scanner just in case, God forbid, there was some sort of electromagnetic glitch with the microcontroller. But airport security did not care what some hacker told this man, and they made him scan it anyway, and it was all fine. Dan made it across the country with the wallet intact and in hand.

Speaker 1: You wanna do it? Gonna do the hand off?

Speaker 5: Yeah. Yeah. Let's do it. Okay. Alright.

Speaker 1: Okay. Wow. There it is. Alrighty. Thank you. So now that I have it, you're not allowed to touch it. Right? Great.

Speaker 5: I don't wanna touch

Speaker 1: it anymore. It's in your hands. This is it. Millions of dollars on this exact Trezor wallet, and we're gonna, we're gonna hack it.

Speaker 2: It was time to get to work. Joe Grand's home lab is cool looking. It's like it's an it's a full on electrical engineering lab. It's what you would expect. Lots of hardware and little boxes full of capacitors and gizmos and very intense looking microscopes and tools. And the two of them, they they hunker down and Joe takes him through this process. Here's Joe from his YouTube doc again.

Speaker 1: So, yeah, let me give you a rundown of, like, the whole setup, just so you can kinda get a feel for the process and what we're seeing.

Speaker 2: Joe briefly outlines the tactic. He shows all the different gear he's gonna be using to do this, and there's a bunch of it because you don't really run a hack like this by connecting the thing to a USB port and starting to type. You really tear the machine apart with scalpels and solvents and soldering.

Speaker 1: We need a way to power cycle the Trezor over and over and over again. In order to power cycle the Trezor, I'm using a device called the Fi Whisperer. We're just using it to power the device on and off. This glitch only works if we glitch the chip on power up. So it's something where we have to turn the device on, try to glitch it. If it doesn't work, turn the device off, turn it on. Once power to the Trezor is applied, we want to try to defeat the security check at exactly the right time to trick the chip into thinking that we have access to it when in reality we shouldn't. To do that, we use a tool called the chip whisperer, and we're using an attack called a fault injection or a voltage glitch. That basically means that we're trying to force the chip into misbehaving in some way that's beneficial to us.

Speaker 2: Joe had told his kid about this whole project over the months he'd been working on it, and the metaphor that his kid came up with was was pretty fun.

Speaker 1: When Miles, my my nine year old came in here and I started doing this, I'm like, it's kind of like when you're glitching a video game. Yeah.

Speaker 5: You

Speaker 1: know? And, like, you find somebody finds some bug and you can skip the level or do whatever. He's like, oh, so you just have to get the timing right to to do the glitch? And I'm like, yes.

Speaker 2: So Joe has explained to Dan what he's going to do. He checks that the Trezor has the right version of the firmware for their glitch, which it does, which is good. Which means that all that's really left to do is crack this thing open.

Speaker 1: Okay. Should we do it?

Speaker 2: First up, there's a coating that protects the components but makes soldering a good connection really, really hard. So he has to go in with a little chemical brush to wash all that coating off. Get everything as clean as possible so he can create good solid connections. He checks his work under the microscope, and everything is looking good. Next step, he has to remove these little capacitors. The capacitors make it hard for him to glitch out the chip, and the risk at this stage in removing them is that he'll pull off a little bit of the circuit board. So he gets in there and everyone waits, but Joe is able to remove them. Now, all he has to do is add the external connectors that let him rig into his hardware, and they're off to the races.

Speaker 1: You can tell I'm nervous. You're like cool and collected and I'm sitting here like tapping my feet.

Speaker 2: When Joe was cooking up this hack way before Dan arrived, he was just spending hours and hours staring at his screen as the automated software tried over and over again waiting for a result. So after a while, Joe decides to save himself all of the just staring, and he programs a little alarm.

Speaker 1: I didn't wanna just stare at the computer waiting for it to just say succeeded.

Speaker 2: The sound he used from the classic film hackers was

Speaker 1: so I'd added in a little, like, text to speech thing that said hack the planet.

Speaker 2: When this works, you'll hear hack the planet.

Speaker 1: Which is, you know, a throwback to the hacker's movie in the nineties and just something that was a little bit tongue in cheek, but also, like, pretty funny.

Speaker 2: Everything is ready for him to launch his hack, to let it start looping and testing and testing until it does or does not work hours later.

Speaker 1: So now we wait. This is it. It's the police stakeout.

Speaker 5: Yeah.

Speaker 1: We sit here and eat donuts, and then a couple hours later, something good happens.

Speaker 2: So they order pizza. Joe gets vegan pepperoni. Apparently, it's pretty good. And they wait.

Speaker 1: Should we take bets on how long it's gonna take? I'll I'll say it goes

Speaker 5: it's gonna go within within an hour. Then one hour.

Speaker 1: I'm gonna I'm gonna say it's gonna be between three and four hours. Okay.

Speaker 2: Joe Grand is an educator. He teaches folks about hardware hacking, and I asked him kind of about misconceptions. What's the most common misconception that his students are occupied by? What's the thing that he tells them that you can tell is really shifting some core understanding they have?

Speaker 1: Yeah. Probably the most common one is is people don't realize, especially engineers who might be coming into the class trying to learn how a hacker approaches hacking something, is they go, wow. I didn't realize that somebody could actually use that against me. Right? So there's a lot of things on circuit boards that are put in place by the engineers, by the manufacturers to make their job easier, to make the manufacturing process more reliable and robust and better yields, and we can use those things. So, you know, we're looking for test points and debug interfaces and markings on the board that could give us some clues about what's going on. All the things that the engineers and manufacturers put in there, that they use during development and and manufacturing, we can use also.

Speaker 2: Conveniences are footholds. Everything that makes life easier for the person making something makes it easier for the person trying to hack it. Every shortcut a creator takes is a shortcut the hacker can take. And I'm certain the people who design Trezor hardware wallets are smart as hell, a lot smarter than me. But the question isn't whether they're smart. The question is, what did all of these very smart people do to make life easier for themselves? And could Joe, over his months of just taking this thing apart, identify those shortcuts? That's the big question. And the answer came exactly three hours and nineteen minutes later. Stomach's full of vegan pepperoni.

Speaker 1: There's like nothing to do. There's literally nothing to do.

Speaker 2: And right as Joe is like, shrugging back in his chair. And he says

Speaker 1: This is torture.

Speaker 2: The computer says

Speaker 5: Hack the planet.

Speaker 2: And they were in.

Speaker 1: Oh, yes. Like it's new. Yes. I'm like, this is torture back on planet.

Speaker 5: Oh, it's awesome. It's like, open.

Speaker 2: What they found.

Speaker 1: Okay. So that

Speaker 2: After the break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, That's shopify.com/hacked.

Speaker 6: When you need to build up your team to handle the growing chaos at work, use Indeed sponsored jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

Speaker 7: Sierra has all the best active and outdoor brands for the super athletic stuff, like running gear for cruising up the trail. Whoo. And the super athletic stuff, like fish and gear for chilling by the creek. Nice cast. Fitness apparel to push for higher reps. You got this. And golf balls priced so you can afford to lose one. Or a few. Head to Sierra or Sierra Dot Com for the brands you want at the prices that let let you do it all. From athletic to athletic ish, Sierra's got it.

Speaker 8: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 1: Three hours and three hours and nineteen minutes, which is right within that sweet spot.

Speaker 2: I asked Joe the obvious question, really just how did it feel when that little hack the planet audio clip played, when the first step of the hack worked?

Speaker 1: I don't normally get, like, really excited about things, and I'm not a very, like, publicly, like, you know, blah type of person. But this was really one of those times where where I was legitimately like, oh, thank god. Like, it actually worked. Like, this is so cool.

Speaker 2: But this wasn't in the bag yet. This hack that Joe cooked up was actually a two part process. The first part, the part with all the waiting, that had worked. But there was still this other question.

Speaker 1: But that was only the first step. Like, that proved that we could downgrade the security, but it didn't show us yet that we actually had the contents that we were trying to get to. And that was the next phase of the attack that we didn't harp on too much in in the video, but that was equally as nerve wracking.

Speaker 2: Now Joe had to run an external program to extract that RAM and see if what they were looking for, the pin and the key, were actually there.

Speaker 1: Now, I'm going to run the external program to extract the RAM.

Speaker 2: Now, Joe had to run another program to extract the contents off the RAM

Speaker 1: and

Speaker 2: to see if what they were looking for, the key, the pin, the important stuff, was actually stored there.

Speaker 1: Okay. We've successfully copied the RAM out of the device. Now, we can run strings and look at that file, which has been sucked off of this device. So we're done with this hardware. Mhmm. If the contents are in the RAM, we have it on my computer right now. I'm so nervous right now. You don't even understand. I don't know if you can see, like, sweaty palms. Sweaty palms.

Speaker 2: There's no long pause this time. No dramatic tension. Just a process to run and a result. The pin and the key, the combination to the safe, or not. Months of work for something or for nothing. So Joe hits run on step two.

Speaker 1: Alright. Okay. Ready?

Speaker 2: And the three and a half hours from step one is compressed down to a second and a half. And step two

Speaker 1: Three, two, one. Works. Yeah, buddy.

Speaker 2: Which is the whole plan. The plan worked. The number appears on the screen in front of them. They found it. Found the treasure.

Speaker 1: Oh, that actually reminds me. Can you pay me now?

Speaker 5: Yeah. That's awesome.

Speaker 2: Oh my god. And the four digit pin that the professional poker player and Dan had forgotten. Yeah. You could see it right on the screen.

Speaker 1: 12514. We did it.

Speaker 2: It was actually five digits. There are plenty of famous cases about this topic of people losing a lot of money in crypto. There's this famous one right now, this Welsh guy who threw out a hard drive he says has, like, I think half $1,000,000,000 worth of crypto on it. He is currently proposing to comb through a landfill somewhere in Wales. Again, there is $80,000,000,000 in lost Bitcoin alone. And Joe grand kingpin, is uniquely equipped to find that treasure. Also, I I use both treasure hunting and cracking as safe as metaphors in this thing, which is sloppy. But anyway, but even though Joe Grand is uniquely equipped to hunt treasure, he is not a treasure hunter. He's a hacker. So he doesn't go where the treasure is. He goes where his curiosity leads him.

Speaker 1: From a hacker perspective, it maybe would be worth it. But then, again, it comes down to allocating where do I wanna spend my time and and what do I wanna do? Like, I have a list of stuff I wanna work on, that isn't about breaking cryptocurrency. It's just about doing fun things. And then it's like, okay. When I have time, I have to kinda prioritize what stuff is what. But, yeah, I mean, security really is like it it it all comes down to, is it worth somebody to hack that device? And what are they getting out of it? And what value are they getting out of it?

Speaker 2: For a long time, I associated Joe Grand with that 1990 senate hearing, and then I associated him with those YouTube videos and kind of as an educator. But his history with hacking obviously goes back way before any of that, back to when he was just a young guy alerting to hack.

Speaker 1: I didn't grow up as somebody who followed the rules and went to school and took a, you know, took an engineering class and decided that was the best career path to go down. Like, it was very much not that way, but it was 100% following my passion and and kind of my rules and not thinking about the ramifications, which is how ultimately I got arrested because I didn't was not thinking about what happens when you do things. And, I was 16 when that happened, and that kinda changed my perspective a little bit. And it's

Speaker 2: really cool to watch these two guys, Dan and Joe, cheer and bounce around this lab having solved this problem together and to think about the long arc of his career as a hacker.

Speaker 1: I think that hacking as a whole has grown with a lot of us. It's evolved with a lot of us. And and many of us who were involved in in hacking in the early early eighties and on, it was a much different time, a much different world. Technology was much different. So even just hacking itself has grown as we have grown and matured and and thought about things as well, which is really, yeah, really kind of interesting. Like like, this this community and and this industry, like, yes, there have been hackers well before us, and there will be hackers well after I'm here, I hope. But this sort of it was like a seed. You know? Like, this this there was no industry around it. There was a a very small community of people that really were fascinated with with this stuff and maybe were a little socially awkward, like, didn't wanna play sports or hang out at school, but it was easier for them to communicate online and do things online and talk on the phone where you weren't face to face. And, like, I think that's how a lot of us got involved in this type of stuff. Like, I was made fun of it in school for being overweight and for being a nerd in into computers and wearing clothes that I got at a thrift store. And it just seemed like the the computer world was just a natural a natural fit for me. And so we all kind of grew. You know? It was like we were little kids, and now the industry is growing and we're growing. And it's like things are constantly changing, and, acceptance of hacking has changed. And, you know, when in the nineties, when I was in the loft, we were always trying to show the good side of what hackers can do because you always had this negative misconception about hacking, and there's always going to be a negative element of anything you look at. Right? So we were always just trying to focus on the on the good, the positive benefits of that.

Speaker 2: Since Joe has started on this new project, cracking hardware wallets, he's also been working to help keep them more secure. And, admittedly, some companies are more interested or receptive than others. And those companies can choose whether or not they want to care about what a dude is posting on his YouTube. But Joe has to care a lot about what he shares. So he doesn't share some information that creates a vulnerability that gets a bunch of people, himself including, in a bunch of trouble. And that imbalance is kind of how it always goes. As Joe and I were wrapping up, we kind of landed on this tool metaphor that hacking is a tool, and what you build with it is up to you. My day job is in advertising and you can use advertising to raise funds for a charity or you can use it to sow disinformation in an election. It is a tool and what you build with it is really your responsibility. And Joe sees hacking the exact same way. I guess I just like knowing that there are folks out there like Joe, You can wield this tool that in the wrong hands is very very destructive. But, who chooses to do cool, interesting, constructive things with that tool. Joe built a pizza compass. This is a really big aside right as we're wrapping up. Yeah. Joe Grand built a GPS powered compass that instead of pointing north, points towards the nearest pizza place. Look it up. It's a very cool invention. Joe Grand uses hacking to understand things and to make things and to occasionally find treasure. He is not primarily a treasure hunter. And when so many of these episodes of the show are about the destructive things we do with these tools, I think that's really cool to meet. So I'll leave you with Joe's thoughts on that. Not on pizza, but on the tools we learn to use and what we choose to build with them.

Speaker 1: I I like to think about hacking or techniques or techniques or exploits as tools. Right? And you can you can use a hammer, and you can do something constructive with it, like building a house. Or you could use a hammer and do something negative with it, like smashing somebody's head in. And this is an an analogy that we've used over and over within the loft of, like, showing that positive aspect. And, yeah, you could say that with lots of other things in the world. And it really comes down to how you're using the tool in a responsible way that's helping somebody, and it really comes down to to humanity just operating in a way that's kind and helpful to other people. But I think hacking in general, you're always gonna have the people that are that are negative, and you're gonna have the people that are positive. And it just, you know, all comes down to, like, trying to have more of the positive than the negative. You know? Have the positive, outweigh the negative, and then then we're gonna do just fine.

Speaker 2: Thanks for listening everybody, and big old thank you to Joe Grand for being very generous with his time and chatting with me about this story. He sat down for an interview, he let us use clips from his YouTube doc. I was all just very kind. Check out his YouTube channel. It is some world class content. There is a technical canyon I descended into in the middle of this. I hope I got all the details generally right, and I hope you enjoyed. If you like the show and you wanna support at patreon.com/hackedpodcast, that's patreon.com/hackedpodcast, a great way to support the show. Thank you very much for listening. Catch you in the next one.

Speaker 9: There's a new way to sweet green. Meat wraps. Handheld, hearty, and made for life on the move. With bold chef crafted flavors, fresh ingredients, and over 40 grams of protein, they're built to satisfy without slowing you down. Try wraps today in the app or at order.sweetgreen.com. Available at all participating locations.

Speaker 10: Athletic brewing company crafts award winning non alcoholic beers for those who wanna be part of every round with over 185 flavor awards. They're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar restaurant or store near you. Near beer, athletic brewing company, fit for all times.

Speaker 11: From lashes for days with the viral liquid lash extensions mascara to awakening your eyes with lift and color from the brilliant eye brightener, Thrive Causemetics is the go to when you want to amplify your everyday look. Plus, every product is 100% vegan, cruelty free, and made with clean skin loving ingredients that work with your skin. And for every product purchased, Thrive Cosmetics donates to help communities thrive. So every time you use your favorite Thrive Cosmetics product, you're helping communities you care about too. Amplify your everyday. Go to thrivecosmetics.com/shine26 for an exclusive offer of 20% off your first order. That's thrive cosmetics, causemetics.com/shine20six.