Darket Diaries
Darket Diaries

118: Hot Swaps

This is the story of Joseph Harris (https://twitter.com/akad0c). When he was a young teen he got involved with stealing video game accounts and selling them for money. This set him on a course where he flew higher and higher until he got burned. Joseph sometimes demonstrates vulnerabilities he finds

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: The episode follows Joseph Harris’s rise from teenage account thief to sophisticated crypto criminal, showing how social engineering, SIM swapping, and leaked account data enabled large-scale thefts. It culminates in a $20M Crowd Machine heist, his arrest, jail time, and eventual shift to ethical hacking, while emphasizing practical security lessons about 2FA, cloud-stored secrets, and email/account protection.

Main Topics: Early gambling analogy and failed strategy simulation (Priority: 2/5): The opening story uses a craps simulation to illustrate how hidden rules and fees can invalidate seemingly profitable systems, mirroring the later hacking story’s theme of overlooked details. Teenage account takeover and social engineering (Priority: 5/5): Joseph explains how he began by doxxing players, tricking AOL/Yahoo support, taking over email accounts, and reselling RuneScape/Club Penguin accounts and gold. Transition from game accounts to crypto theft (Priority: 5/5): He moved from stealing usernames to targeting people with Bitcoin/crypto holdings, using leaked email addresses, password reuse, and exchange account access to steal funds. SIM swapping and carrier/provider weaknesses (Priority: 5/5): Joseph describes abusing weak telecom verification, then later finding Verizon and T-Mobile flaws that exposed account data or message access, enabling password resets and OTP interception. Crowd Machine heist and escalation to millions (Priority: 5/5): The largest segment details how he used a Gmail/2FA bypass, Google Drive backups, and source code leaks to take control of a company wallet and steal millions in tokens. Arrest, jail, and consequences (Priority: 5/5): After the Crowd Machine operation, law enforcement traced him via hotel and device evidence, leading to arrest, jail, prosecution in California, and a 16-month sentence. Aftermath and ethical hacking (Priority: 4/5): Joseph says prison changed his priorities; he now reports vulnerabilities through bug bounty programs and warns listeners to secure accounts and avoid cloud-stored secrets.

Key Arguments: Small oversights like VIG in craps or account-number disclosure in telecom systems can completely change outcomes. Email providers and telecoms were once weak enough that simple social engineering could reset accounts and enable theft. Password reuse and predictable password patterns made cracking email accounts significantly easier. SIM swapping became a powerful primitive for taking over emails, crypto accounts, and MFA-protected services. Cloud backups of seed phrases, private keys, and photos create catastrophic single points of failure. The Crowd Machine theft showed that one exposed credential or backup file can cascade into a multi-million-dollar breach. Law enforcement and platform defenders improved over time, making these attacks harder and pushing the subject toward bug bounties.

Data Points: Craps simulation rolls: 100,000+ - Joseph simulated craps betting strategies in college to test whether any bet would beat the house. Club Penguin sale: $1,500 - Highest single account sale Joseph reported from stealing game accounts. BTC found in an account: 20–25 BTC - He found a blockchain wallet with roughly this amount, but backup protection prevented withdrawal. First crypto heist: $1,000 - He converted stolen altcoin from a Cripsy account into Bitcoin and then PayPal. BTCE-linked earnings: $10,000–$20,000 - Estimated amount he made from accounts tied to the BTCE database list. Bitcoin from password guessing run: 30 BTC - He estimated this haul from cracking email accounts using breach-derived passwords and variants. Early crypto value of 30 BTC: $10,000–$15,000 - Approximate dollar value of the 30 BTC at the time. AOL/Yahoo account-reset security detail: Last 4 digits of ZIP/address checks - Used in explaining how weak support verification enabled account takeovers. Age during early scams: 11–12 - Joseph says he started with game accounts as a child. Age during BTCE/crypto operations: 17–19 - He was a minor for part of the crypto theft period and about 19 during the BTCE list exploitation. Crowd Machine wallet taken: $15,000,000 - He transferred most of the company’s main token wallet after discovering the private key. Crowd Machine total control: $20,000,000 - He says he had access to about $3M plus $17M in related wallets/source-code-derived access. Amount demanded in ransom deal: $8,000,000 BTC - He offered to return the stolen tokens if Crowd Machine paid him in Bitcoin. Arrest bail: $500 - Initial bail after the earlier Instagram-related arrest. Later bail: $14,000,000 requested; $1,000,000 reduced - In the Crowd Machine case, prosecutors initially sought very high bail, later reduced by the judge. Sentence: 16 months - Final prison sentence after conviction. SWAT response: Police and SWAT team - He was swatted after a threat over a Twitter username. React task force response time: 3 days - The episode states React identified and helped arrest Joseph quickly after the Crowd Machine incident. Crowd Machine heist location: Oklahoma hotel room - He carried out the attack while staying in a hotel before fleeing.

Pivotal Quotes: "The house always wins. The game is designed that way. There's no way around it." — Narrator/Joseph: Opening craps story explaining why simulated betting strategies kept failing until a hidden fee was missed. "I was willing to go the lengths to get these people's accounts, and I didn't feel guilty about it." — Joseph Harris: He describes his mindset during the period when he was stealing accounts and money online. "What I learned is my freedom's more important than millions of dollars in crypto." — Joseph Harris: His reflection after arrest and prison, explaining why he now chooses ethical hacking.

Implications: The transcript shows how account recovery flaws, SIM swaps, and cloud-stored secrets can turn ordinary user data into catastrophic theft. Strong MFA, hardware keys, offline backups, and better carrier/support security are essential.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries