The Dutch Police are aggressively pursuing arrests and new investigations into Dark Web sellers using the data they gathered from the closure of the Hansa drug market.
Currently, various security researchers and former Hansa vendors have identified two ways in which Dutch authorities are proceeding against former Hansa vendors.
Police are reportedly gaining access to Dream Market accounts through reused passwords.
In the first case, Dutch authorities managed to decrypt the passwords of sellers who had the same usernames on the Hansa drug market and Dream Market, which is today's leading Dark Web marketplace after the closure of Hansa and AlphaBay.
If sellers are found to be reusing passwords and have not enabled 2FA on their Dream Market accounts, authorities will take control of their profiles and change their passwords, effectively kicking the sellers out.
Dream Market and the Dark Web community have identified 14 vendor accounts that have had their PGP keys changed: 00DRGREEN00, BoulderMedical, cannab1z, cocaMG, dutchcandyshop, DrPoseidon, GlazzyEyez, Gridlockdope, guessguess, ibulk, iCoke, MarcoPolo420, mushrooms, wolfydutch
One of the aforementioned sellers confirmed on Reddit that he lost access to his Dream Market account because he was using the same password on Hansa.
The locktime file
The second method used by the Dutch Police and detected by the Dark Web community involves so-called “locktime” files that were present on the Hansa marketplace, which closed on July 20.
Under normal circumstances, a lock time file is a simple log of a seller’s purchase transaction, containing details of the item sold, the buyer, the time of sale, the price, and Hansa’s signature. The files are used as an authentication check by sellers to request the release of Bitcoin funds after a sale is completed or if the market goes down for technical reasons.
According to people familiar with Hansa's inner workings, Hansa's locktime files were usually just a text file.
Before the site was shut down, these lock files were replaced with Excel files containing a hidden image. When a vendor opens the file to view transaction details, the image is loaded onto the vendor's computer.
Once the image is loaded, the Hansa server records the user's IP address. If the user was not using a VPN, proxy, or was only visiting the page through Tor, the server records their real IP address.
Even after Hansa's closure, some sellers may still have the files on their computers. After Hansa's closure, sellers may have opened the saved files looking for ways to recover their money locked in Hansa accounts.
Dutch police seized Hansa's servers on June 20 and secretly collected data from sellers until July 20, when the marketplace was officially announced to be closed.
When Europol announced the seizure of the Hansa marketplace servers, it provided the following audio message, which today seems more relevant than ever.
In recent weeks, Dutch police have gathered valuable information about high-value targets and delivery addresses for a large number of orders. Around 10,000 foreign addresses of Hansa market buyers were passed on to Europol.
