# Killing with Keyboards – How Your Digital Footprint Can Be Weaponized - Noah Jelich | ETHDam III

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2025-10-07
- Duration: 15:02
- Watch: https://streameth.org/watch/yt-l3Hfudjyyx0
- YouTube: https://www.youtube.com/watch?v=l3Hfudjyyx0

## Description

Welcome to the 3rd Edition of ETHDam, hosted May 9–11, 2025 in Amsterdam. This year, we brought together the brightest minds in privacy, security, and AI for a unique 48-hour hackathon + conference combo.
🌷 https://www.ethdam.com// 🌷

------------------

Killing with Keyboards – How Your Digital Footprint Can Be Weaponized - Noah Jelich | ETHDam III - 2025     

🎤 About the Speaker: 
Noah is a security researcher known for publishing live analyses of major hacks and uncovering countless vulnerabilities during his time at Hacken. Beyond research, his hands-on experience with projects has given him a deep understanding of the operational challenges non-technical founders face when securing their assets. This unique blend of technical expertise and real-world insight allows him to bridge the gap between cutting-edge security threats and practical defense strategies.

𝕏 Follow:
https://x.com/NoahJelich

------------------

About ETHDam & CryptoCanal
ETHDam is powered by CryptoCanal, an education and events platform rooted in Amsterdam, expanding into Rotterdam and Zürich.

Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

CryptoCanal unites crypto enthusiasts committed to making a positive impact. Unapologetically political, we prioritize education, events, and services while championing cypherpunk values like privacy, sovereignty, and censorship resistance.

------------------

🎥 Credits:
Intro / outro by babyPRO -  https://babypro.art/
ETHDam Photography by Paulus – https://concretestate.eu/ 
MC of ETHDam -  Collins Ejiofor - developer working at the intersection of Web3 and AI. Check out his LinkedIn for more about his work and upcoming projects! https://www.linkedin.com/in/collins-ejiofor/ 

------------------

Special thanks to our partners who made ETHDam possible: 
🌹 Hackathon – Bouquet:
Oasis Network https://oasisprotocol.org/ 

🌷 Hackathon – Petal:
Circles https://aboutcircles.com 

💛 Conference – Gold:
Zano https://zano.org/ 
Dash https://www.dash.org/ 
Bitvavo https://bitvavo.com/en 

🩶 Conference – Silver:
Igra Labs https://igralabs.com/hero

💛 Conference – Copper:
Lido https://lido.fi/ 
DeTrip https://detrip.travel/
Cake Wallet https://cakewallet.com/ 
The Grid https://thegrid.id/ 
Calimero Network https://calimero.network/ 
0xbow https://0xbow.io/ 
Mina https://minaprotocol.com/
JobStash https://jobstash.xyz/ 
Cyber Capital https://www.cyber.capital/  
POAP https://poap.xyz/ 
Acronym Foundation (Supported our Top 10 Hackers) https://acronymfoundation.org/ 

🌱 Sponsor:
EF Ecosystem Support Program https://esp.ethereum.foundation

------------------
0:00 Intro – Keyboard Killers  
0:12 Meet the Speaker  
1:14 Story of Sashko  
2:13 Meet Kim the Googler  
3:01 Kim Finds Sashko  
4:33 Tracing Digital Clues  
6:02 Identity Revealed  
7:50 Vulnerability Targeting  
8:35 Social Engineering at a Conference  
11:00 The Attack Aftermath  
13:07 Takeaways & Threat Models

## Transcript

Welcome to East to East to East to East to East. Uh, okay. Um, technical issues aside, uh, I think we're ready to get started. So, today, uh, this one will be fun. Um, it's killing with PE keyboards, which is about uh, you know, North Korean hackers and other AP advanced persistent thread groups that have a lot of resources and what they can do with all the data you put out there. But first, a little bit about me so that in case there's any hackers in the audience, they can later use this uh, to abuse me. Um, so I'm a security researcher and fullstack dev. I started actually with Minecraft modding and infinity go. Uh but now I work with fuzzers. I develop stuff. I do some obscure topics in terms of research and I also co-created was uh a while ago with Barto Barikoski from Hacken. Since leaving Hacken I had a bit more experience working directly with founders and honestly that terrified me. I'm now scarred because uh well how about a little story time? Meet Sashko. Oh my. No, something's really Okay, something is a bit weird. Um, meet Sashko. He's a Ukrainian engineer working at Kovchek Systems. That's like a hardware secure devices company. He's a chill guy. He's good at his job and uh he has a happy little family and doesn't do anything particularly unusual except that from time to time he will chat with other security professionals and follow up on what's new in the field, always anonymously. uh you know stuff like the ETH security community and uh you know blink and you'll miss him uh but he does often pop up and he shares the knowledge that he has and various bits of like useful information with others. He's generally well respected in the chats etc because you know he's a useful guy. On the other side of the pond and you know one continent over uh there is a girl. Meet Kim. Uh she's a teenager from the Democratic People's Republic of Korea and she's a Googler. Okay. Every day she fulfills her role collecting information and creating files on various topics for others to use others you know co-workers and today she got lucky because today she found Sashko. She was doing some general research around you know the STM32 chip as a keyword uh that was provided by the government. Uh right now she doesn't know much about him. Not even that he's a he. But let's get back to Sashka then. Um so the team uh that he leads hit a major program milestone and everyone was given an expected bonus for performance reasons. Uh for Bognan, a manager that was one step closer to his retirement farm which you know everybody in tech desires, right? Uh and uh then it was yet another half day spent in a quarterly security update briefing talking about security stuff and you know Bogdan of course promised that they would have less of these like boring security briefings and stuff like that cuz it's just a waste of time anyway you know and uh that is the general attitude you know after the briefing the team walked into a new place uh serving kas uh that was just you know opened up in the tech park. It caters to the companies in the park including Kofch Systems and it's it's like a nice place for you know tech workers. It has free Wi-Fi. It has these small quiet rooms for meetings, phone calls, etc. Uh and a 15% discount for the tech employees, you know, to keep them loyal. You just need to show your ID. It's it's great. It's a great place to get some, you know, refreshments. And while in line, Sashka was talking to his team members about, you know, do you really think a person with a security clearance needs to be reminded about like this stuff? Like nobody does dumpster diving anymore. There's great security on premises and stuff. The security guys have no clue what they're talking about in general that nobody likes security, you know. Meanwhile, uh Kim's progress was slow but steady. uh you know it takes a while. It takes a while you know um searchers need to be very very patient. uh it may take weeks to find something important just you know running through different comments through different messages trying to figure out if there's maybe a pattern there's maybe some writing style clues there but uh you know each petal helps you identify the flower it came from and thus each piece of the puzzle provides a new search opportunity and uh you know Kim followed the trail from one site to another um there were many dead ends, but sometimes even seemingly unimportant bits can yield, you know, great results. Uh or stuff that you thought was deleted could be still found in a cache. In this case, uh it was a username that they gave him away. Uh he left a review for a book that he read under his, you know, cool username and he later changed it, but the review stayed in like archive.org torque somewhere. Uh, so you know, you never know. And as I said, each petal helps you identify the flower it came from. Once she had his name, it was very, very easy. Uh, she could find all this other info on Facebook, on Twitter, on YouTube, you know, the old Google+ that he forgot about. All of these things, they exist. The dude even had MySpace that he didn't delete. And even if he had, you know, archive.org exists. And uh each of these clues was producing more and more new information. You know, digging deeper into the lives of others, just finding out what what they're doing with their lives. It's uh it was actually sort of fun for Kim, you know, meeting this other person, knowing so much about him, knowing what he likes, what he dislikes, how he thinks. She even had a little bit of a crush on him. and she dug deeper, you know, finding even uh the stuff that those closest to him didn't know about his earlier years. Uh the less legal stuff that he did until one day Kim's work on Sashko was over. Her leader rewarded her very very well for her 200th file. She was allowed to recommend a family member to join her at school. Soon she wouldn't have the honor of teaching her 13-year-old sister all she learned about Googling, you know. And uh meanwhile, the information about Sashko was available to use freely as needed by, you know, others in the organization. I mean, it's a corporate office. Uh, and then one eternity later, you know, maybe a year, maybe more, who knows? Who knows? Um, Kim's uh government found out about maybe a certain vulnerability in some versions of like the chip architecture. You know, the formal verification process maybe didn't catch something or there was some mismatch between the inputs and outputs. and they were thinking maybe we could use this and they knew that Sashko's company did use some of those ships but they didn't know they didn't know which exactly they used they didn't know which products they were in and they did have a specific highv value target they're going after so um you know they wanted to check so there was a conference just like this one you know here we are in Amsterdam And uh it's it's like it's a conference like this. It's not really classified. U but the attendance is somewhat restricted. You need to register. You know, they will if there is an fairly obvious North Korean here, we would probably catch them, right? Uh and people generally need some sort of company sponsorship. There's uh guards in front of the center and there's like closeup spaces. There's open spaces. You know, the cafe you can enter without a badge, but some other stuff maybe not. And uh for the sessions of course you need to have your badges and uh you know a few days were already gone with the conference and uh Sashka was a bit tired uh and he was at the bar you know and he saw a guy wearing a Dina Mokv hat you know he had seen him around a few times in the past few days. He was hanging in the conference. He was working on his laptop, you know, looking like he fits in in general in the lobby, maybe some elevators. And uh he walked over like you don't see that every day. And he was like, you know, Dina Makv here? Really? Like, you know, people have merch. I have merch on me. Uh and yeah, like, wow, yeah, you're the first one to notice. Wow. Yeah, of course. I'm a fan. Okay. And uh you know they start talking. Are you at the conference? Yeah. Yeah. Yeah. But let's not talk about work. I'm not allowed to anyway. You know, if you ask me a question, I cannot tell you literally anything. Uh so they talked about other stuff. They talked about work. No, didn't talk about work. They talked about sports. They talked about life, children, women, blah blah blah blah blah blah. And then a little bit about work. Just just a little bit. You know, it is tough. My boss bothers me a bit, but careful not to say too much. Uh, just venting. Eventually, Jack offered lunch. And of course, you know, they've been talking. Sashka accepted. He was a bit hungry. Uh, and they talked some more. They were really bonding. It was it was a good conversation. One of those really good conversations that you remember. And uh at some point Jack just asks, you know, uh I was hoping to hear if anyone else was using the you know the latest STM32s cuz uh I'm not sure how good the documentation is. I heard some rumors and uh I'd hate to be the first one to use you know the latest line that I know of it. You know it's it's risky, right? It's it's scary to work with something like that. and Sashko just said, you know, it's don't worry, don't worry. We have them in all of our products. We're on this version, you know, and uh they are generally well documented. You didn't have to worry, you know, it's it's fairly easy to implement. And sometime later, you know, they talk some more. This was just a few sentences in a conversation. You you you miss it, you know, you miss it. And then Jack had to go. he had an early flight, you know, another conference in another city. He had to leave soon. Um, I mean, it's better that way than for someone to realize that he was maybe not even attending the conference. Uh, and he was happy. He was very happy with how that went. You know, Jack got the confirmation he needed. He would even be able to contact Sashko again if need be. and uh and all of that without being forced to do anything unkind. A few weeks passed and another dreadful exploit drops. Um it would seem that like the zero day in the in the chip was used um to actually get control of a private key that was held on a hardware wallet. that you know was produced by Kche Systems and um that meant that you know you could uh you could get an upgrade uh through the multisig and soon you know the rest is history. So what can you do? Well, the thing with this talk is that it's really just my journey with paranoid schizophrenia. No, no, not for real. But um you first need to know what you're defending, okay? Like OBSC isn't a magic list of just do this rules you blindly follow and then everything is fine. No, no, no. It's like calculated moves based on your specific risks. Uh you don't just throw on a VPN and call it the day. You need to you need to build your defenses based on who's after you, what what you're actually protecting and what happens if they succeed. So, um the first question is who are you protecting? Are you just guarding your own personal data? Are you guarding confidential business information? Are you guarding illegal activities maybe or just you know your right with privacy? Are you a journalist activist, a hacker or someone who just you know loves privacy as a concept? because different assets require different levels of protection. The other thing is uh who is chasing because each of these operates differently. Some use social engineering, some use technical exploits and others can just brute force with legal power. So the stronger your enemy, the more airtight your ops needs to be. And lastly, what happens if they win? What's the worst case scenario if your data identity or location falls into the wrong hands? Do you lose access to your accounts? Do you face legal consequences, arrest, die? If the consequences are lifealtering, you better not play around. But on the other hand, you know, you don't want to be a paranoid schizophrenic here. And that's where compartment translation, anonymity, and airtight security protocols can come in. But it's a long long story. So if you got any questions, we can talk privately right after this talk or you can contact me on Telegram or LinkedIn. Thank you very much for listening to my talk.
