this post was submitted on 20 Mar 2024
218 points (100.0% liked)

news

23090 readers
238 users here now

Welcome to c/news! Please read the Hexbear Code of Conduct and remember... we're all comrades here.

Rules:

-- PLEASE KEEP POST TITLES INFORMATIVE --

-- Overly editorialized titles, particularly if they link to opinion pieces, may get your post removed. --

-- All posts must include a link to their source. Screenshots are fine IF you include the link in the post body. --

-- If you are citing a twitter post as news please include not just the twitter.com in your links but also nitter.net (or another Nitter instance). There is also a Firefox extension that can redirect Twitter links to a Nitter instance: https://addons.mozilla.org/en-US/firefox/addon/libredirect/ or archive them as you would any other reactionary source using e.g. https://archive.today . Twitter screenshots still need to be sourced or they will be removed --

-- Mass tagging comm moderators across multiple posts like a broken markov chain bot will result in a comm ban--

-- Repeated consecutive posting of reactionary sources, fake news, misleading / outdated news, false alarms over ghoul deaths, and/or shitposts will result in a comm ban.--

-- Neglecting to use content warnings or NSFW when dealing with disturbing content will be removed until in compliance. Users who are consecutively reported due to failing to use content warnings or NSFW tags when commenting on or posting disturbing content will result in the user being banned. --

-- Using April 1st as an excuse to post fake headlines, like the resurrection of Kissinger while he is still fortunately dead, will result in the poster being thrown in the gamer gulag and be sentenced to play and beat trashy mobile games like 'Raid: Shadow Legends' in order to be rehabilitated back into general society. --

founded 4 years ago
MODERATORS
 

On March 10th, several days after Incognito Market was assumed to be shut down or no longer be processing transactions, the site posted a message to its homepage that reads as follows:

”Expecting to hear the last of us yet? We got one final little nasty suprise for y'all. We have accumulated a list of private messages, transaction info and order details over the years. You'll be surprised at the number of people that relied on our "auto-encrypt" functionality. And by the way, your messages and transaction IDs were never actually deleted after the "expiry"...”

”SURPRISE SURPRISE !!! Anyway, if anything were to leak to law enforcement, I guess nobody never slipped up. We'll be publishing the entire dump of 557k orders and 862k crypto transaction IDs at the end of May, whether or not you and your customers' info is on that list is totally up to you. And yes... YES, THIS IS AN EXTORTION !!! As for the buyers, we'll be opening up a whitelist portal for them to remove their records as well in a few weeks.”

”Thank you all for doing business with Incognito Market”

Exit scams are not uncommon on dark web markets, but this one is particularly large and openly threatening compared to most. Incognito Market requires the loading of cryptocurrency to a site-based wallet, which can then be used for in-house transactions only. All cryptocurrency on the site was seized from user’s wallets, estimated to be anywhere from $10 million to $75 million. After seizing the cryptocurrency wallets of all of the marketplace’s users, the site now openly explains that it will publish transactions and chat logs of users who refuse to pay an extortion fee. The fee ranges from $100 to $20,000, a volume based 5 tier buyer/seller classification.

Incognito Market also now has a Payment Status tab, which states ”you can see which vendors care about their customers below.” and lists the some of the market’s largest sellers. Sellers which have allegedly paid the extortion fee to not have their transaction records released are displayed in green, while those who have not yet paid are displayed in red.

Additionally, in a few weeks the site claims it will have a “whitelist portal” which would allow buyers to wipe their transactions and re-encrypt chat records.

Whoever is behind the website must be extremely, extremely confident in their anonymity, already working with government agencies, or both, because a bounty on this person is likely worth millions.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 42 points 8 months ago (23 children)

For christs sake:

Only ever explicitly discuss serious illegal activities in person, preferably outdoors and without any technology on you

Only coordinate meetings to discuss the above over an encrypted messaging method such as signal, and in this avoid specifics and keep this to an absolute minimum (metadata can also be incriminating, and phones out computers can be compromised)

If significant payment is involved, cash, barter or work trade are the only acceptable forms. Ever.

Don't be a fucking sucker

Any questions?

[–] [email protected] 26 points 8 months ago (11 children)

Buying drugs in person puts someone at risk of violence and death. Buying drugs on a DNM (assuming you use a very basic amount of opsec) the biggest risk is losing a little bit of crypto.

Don't be a fucking sucker Any questions?

Such an ignorant and privileged thing to say.

[–] [email protected] 5 points 8 months ago (2 children)

The risk I'm more concerned about is the risk of cops accessing info and of felony charges.

[–] [email protected] 10 points 8 months ago

The risk of cops busting a buyer (of personal use amounts, or even enough for a couple friends) is almost nil for the DNMs because of the amount of work necessary, but a buyer's odds of getting caught during an in-person deal go up drastically because even if they're just after the dealer, the buyer usually gets fucked too since they're right there and part of the bust. The risk of cops busting a dealer/vendor depends a lot on the volume they move, whether it's online or in person. With good opsec the risk is still much lower for vendors than it is for dealers in person. There's also no risk of getting jumped and beaten/killed while you're making a transaction.

[–] [email protected] 5 points 8 months ago* (last edited 8 months ago)

Unfortunately, nearly all sellers keep records of their customers and there isn't anything you can do about it. Your number is in your IRL plug's phone and the cops will seize it. The cops may raid your DNM vendor's house while he's using the computer and has everything decrypted. With thoughtful market design you can ensure that only the seller has your info, so that this risk is no higher than for IRL transactions with no third party. But it'll never be 0

load more comments (8 replies)
load more comments (19 replies)