A Convicted Bitcoin Thief Is Out of Prison Years Early

Just over a year after being sentenced to five years in prison for one of the largest crypto thefts in history, Ilya Lichtenstein is free.

The man behind the laundering of billions of dollars in stolen Bitcoin announced his early release on X, thanking President Donald Trump and pointing to the First Step Act as the reason he is no longer behind bars.

For the crypto world, this moment is unsettling. Not because the law was followed, but because of what this says about accountability in digital finance.

What the First Step Act Actually Did Here

The First Step Act, passed in 2018 during Trump’s first term, was designed to reduce mass incarceration and reward good behavior. It allows inmates to earn time credits that can shorten sentences or move them into home confinement.

According to a Trump administration official, Lichtenstein served significant time and is now under home confinement in line with federal policy.

Legally, this checks out. Symbolically, it hits very differently.

The Bitfinex Hack That Would Not Go Away

Lichtenstein and his wife, Heather Morgan, were arrested in 2022 for laundering Bitcoin stolen in the 2016 Bitfinex hack, a breach that sent shockwaves through the early crypto economy.

At the time, the theft was considered catastrophic. Billions vanished. Trust collapsed. The industry promised it would mature.

Morgan, also known online as the rapper Razzlekhan, received an 18 month sentence and was quietly released early as well. She announced it herself from a bathtub on social media months ago.

Both are now free. The Bitcoin is mostly recovered. The message remains unclear.

From Cybercriminals to Streaming Content

Since their arrest, the couple has been transformed into content.

There is a Netflix docuseries. A feature film is in development. Their story is framed less as a cautionary tale and more as a bizarre cultural moment.

This shift matters. When high profile cybercrime becomes entertainment, it blurs the line between consequence and celebrity.

Why This Bothers the Cybersecurity World

Cybersecurity professionals have spent years warning that crypto crime is not victimless. Exchanges fail. Users lose savings. Markets destabilize.

When the perpetrator of a historic hack walks free early and publicly talks about returning to cybersecurity, it raises uncomfortable questions.

Is punishment meant to deter future attacks, or just to check a box?

The Blockchain Industry’s Image Problem Gets Worse

Crypto has struggled to shed its reputation as a playground for scams, hacks, and regulatory loopholes.

This case reinforces the perception that consequences are lighter when crimes are technical, complex, or wrapped in innovation language.

For regulators already skeptical of blockchain platforms, this only strengthens the argument that the industry still lacks meaningful self policing.

What This Means for Everyday People

For regular users, this is not just a headline about a hacker.

It is a reminder that digital systems move faster than accountability. That financial crimes committed through code can feel abstract until the penalties evaporate.

Trust in crypto is not just about security architecture. It is about whether the system treats massive digital theft with the seriousness it deserves.

Right now, many people are not convinced it does.

Email inquiries to hello@laterstack.com


Related Laterstack Stories

MSCI’s Bitcoin Index Debate Reveals Who Decides What Counts as a Real Company

Do Kwon Sentenced to 15 Years as Terra Collapse Becomes Crypto’s Defining Fraud Case

A Hollywood Crypto Scam Shows How Speculation Slipped Into the Mainstream

Inside the Quiet Rise of Crypto Casinos and the New Gambling Wild West

Major Gainsight Supply Chain Breach Hits 200+ Companies

SAN FRANCISCO – Google has confirmed that hackers stole Salesforce-stored data from more than 200 companies in a large-scale supply chain hack via apps published by Gainsight, a customer support platform.

Austin Larsen, principal threat analyst at Google Threat Intelligence Group, stated that the company is “aware of more than 200 potentially affected Salesforce instances.”

The breach was claimed by the hacking collective Scattered Lapsus$ Hunters, which includes members of the ShinyHunters gang. The hackers stated they accessed data from major companies, including Atlassian, CrowdStrike, Docusign, F5, GitLab, LinkedIn, Malwarebytes, SonicWall, Thomson Reuters, and Verizon.

How the Hackers Gained Access

The hackers reportedly leveraged a prior campaign against Salesloft, which provides AI-driven marketing tools like Drift. They stole authentication tokens from Salesloft customers, allowing them to break into linked Salesforce instances through Gainsight.

“Gainsight was a customer of Salesloft Drift, they were affected and therefore compromised entirely by us,” said a spokesperson for ShinyHunters.

Salesforce confirmed the breach did not stem from vulnerabilities in its platform and has temporarily revoked active access tokens for Gainsight-connected apps as a precaution. Gainsight is collaborating with Google’s incident response unit, Mandiant, to investigate the incident.

Company Responses and Mitigation Efforts

Several affected companies provided statements on their current security posture:

CrowdStrike: Not affected; terminated a suspicious insider.

Docusign: No evidence of compromise; terminated Gainsight integrations and contained data flows.

Verizon & Thomson Reuters: Actively investigating.

Malwarebytes: Aware and investigating Gainsight/Salesforce issues.

Salesforce has stated it is following its policy of not commenting on specific customer cases.

Hacker Extortion Plans

The Scattered Lapsus$ Hunters collective has a history of data theft and extortion campaigns. Following the breach, they announced plans to launch a dedicated website to extort victims, mirroring tactics used in the October Salesloft incident. The group has previously targeted high-profile companies including MGM Resorts, Coinbase, and DoorDash.

These groups rely on social engineering and other techniques to compromise corporate systems, emphasizing the growing threat of sophisticated supply chain attacks in the cybersecurity landscape.

Looking Ahead

This incident highlights the risks of third-party software in enterprise environments, especially platforms connected to cloud services like Salesforce. Companies are advised to monitor unusual activity, enforce strict access controls, and coordinate with incident response teams to mitigate further exposure.

Related Laterstack Stories:

US Border Patrol Surveillance, Massive DDoS Attacks, and FBI Spying Make Headlines

Incognito Mode offers less privacy than most people think

WASHINGTON – The US Border Patrol is operating a predictive-intelligence program that tracks millions of American drivers far from the border, according to an Associated Press investigation. Covert license-plate readers hidden in traffic cones, barrels, and roadside equipment feed data into an algorithm that flags “suspicious” routes, quick turnarounds, and travel to and from border regions. Local police are then alerted, resulting in stops for minor infractions, such as window-tint violations or marginal speeding.

AP records show drivers have been questioned, searched, and sometimes arrested, even when no contraband was found. Internal group chats obtained through public-records requests revealed Border Patrol agents and Texas deputies sharing hotel records, rental car status, home addresses, and social media information in real time while coordinating “whisper stops” to obscure federal involvement. Plate-reader sites have been identified as far as 120 miles from the Mexican border in Phoenix, with additional locations near Detroit and Chicago.

Legal experts expressed concern over the program’s scale, warning it raises new Fourth Amendment issues. A UC Law San Francisco official described the system as a “dragnet” tracking Americans’ movements, associations, and routines.

Microsoft Thwarts Record-Breaking Cloud DDoS Attack

Tech giant Microsoft said it mitigated the largest distributed denial-of-service (DDoS) attack ever recorded in a cloud environment. The attack, launched on October 24 against a single Azure endpoint in Australia, reached 15.72 Tbps with 3.64 billion packets per second. Microsoft attributed the attack to the Aisuru botnet, a network of compromised consumer devices including home routers and cameras.

The Azure DDoS Protection network successfully absorbed the traffic with no disruption to service. Researchers have noted that Aisuru is increasingly using AI-driven attacks, credential stuffing, and HTTPS floods via residential proxies.

SEC Drops Remaining Claims Against SolarWinds

The U.S. Securities and Exchange Commission dismissed its remaining claims against SolarWinds and its CISO, Tim Brown, ending litigation tied to the 2020 supply-chain hack allegedly carried out by Russian SVR operatives. The lawsuit, filed in 2023, had largely been dismissed in 2024. SolarWinds hailed the dismissal as vindication and said it may ease concerns among CISOs regarding future regulatory scrutiny.

FBI Spied on Immigration Activist Signal Group

Law enforcement records revealed that the FBI accessed messages from a private Signal group used by New York immigration court-watch activists. A report dated August 28, 2025, labeled the nonviolent participants as “anarchist violent extremist actors” and circulated assessments nationwide.

The documents, obtained by the transparency group Property of the People, show that activists monitored public hearings and collected information on federal personnel. Civil liberties experts warned that the surveillance mirrors prior FBI campaigns targeting lawful dissent, potentially chilling protected political activity.

Other Notable Cybersecurity News

WhatsApp Exposure: Researchers at the University of Vienna demonstrated that phone numbers can still be extracted en masse via WhatsApp’s discovery feature, exposing billions of users.

Vape Detector Surveillance: U.S. high schools are using advanced vape detectors with microphones, raising privacy concerns among non-vaping students.

Cisco Security Warning: Cisco warned that outdated networking equipment is increasingly vulnerable as AI tools simplify exploitation of unpatched systems.

Anti-Virus Monitoring at Conferences:
New Zealand’s Kawaiicon conference tracked CO2 levels to improve attendee safety, creating real-time air-quality monitoring systems.

Related stories on Laterstack:

Incognito Mode offers less privacy than most people think

12 Steps to Better Cybersecurity in 2025