The Department of Justice said today that it has taken down the massive dark web child-porn site Welcome to Video. The site generated and distributed exploitative content, and had infrastructure in place that could have supported up to a million users. In a press conference this morning, US attorney Jessie Liu called it “one of the worst forms of evil imaginable.”
The site’s operator, 23-year-old Jong Woo Son of South Korea, has already been charged and convicted by South Korean officials and is currently serving his sentence there. Wednesday’s announcement unsealed a nine-count US indictment against Son by a federal grand jury in the District of Columbia. In addition to the site takedown and Son’s indictment, officials around the world also arrested a total of 337 Welcome to Video users in 23 US states, Washington DC, and in 11 other countries. The initiative resulted in the rescue of at least 23 children being abused by site participants.
The takedown is notable also for the investigation that enabled it, which focused not on offensive hacking efforts or surveilling encrypted communications, but on tracing bitcoin transactions.
“In August 2017 an investigation began into the illicit transactions of virtual currency on the dark net. By following the funds on a blockchain it ultimately uncovered the severity of Welcome to Video, a Tor network-based child pornography site that accepted payment in bitcoin,” deputy assistant attorney general Richard Downing said in the press conference. “The Department of Justice will not stand for exploitation of our nation’s children. Let today’s announcement send a message: If you were involved in these crimes we are coming for you.”
Welcome to Video launched in June 2015 and operated until law enforcement shut it down in March 2018. The DoJ collaborated with South Korean and UK officials on the initiative along with other US law enforcement groups, including Internal Revenue Service Criminal Investigation and Homeland Security Investigations.
Officials seized 8 terabytes of child porn videos during the investigation and site takedown, which included more than 250,000 unique videos. Law enforcement officials and the National Center for Missing and Exploited Children are analyzing the footage to potentially identify more children and perpetrators of exploitation. Almost half of the videos seem to be previously unknown to officials.
Welcome to Video made money by charging fees in bitcoin, and gave each user a unique bitcoin wallet address when they created an account. Son operated the site as a Tor hidden service, a dark web site with a special address that helps mask the identity of the site’s host and its location. But Son and others made mistakes that allowed law enforcement to track them. For example, according to the indictment, very basic assessments of the Welcome to Video website revealed two unconcealed IP addresses managed by a South Korean internet service provider and assigned to an account that provided service to Son’s home address. When agents searched Son’s residence, they found the server running Welcome to Video.
To “follow the money,” as officials put it in Wednesday’s press conference, law enforcement agents sent fairly small amounts of bitcoin—roughly equivalent at the time to $125 to $290—to the bitcoin wallets Welcome to Video listed for payments. Since the bitcoin blockchain leaves all transactions visible and verifiable, they could observe the currency in these wallets being transferred to another wallet. Law enforcement learned from a bitcoin exchange that the second wallet was registered to Son with his personal phone number and one of his personal email addresses.
The investigation extended beyond Son as well. Law enforcement agents worked with the blockchain analysis firm Chainalysis to map user transactions with Welcome to Video wallets and attempt to trace individuals who interacted with the site. Chainalysis says that during the three years it operated, Welcome to Video received almost $353,000 worth of bitcoin from thousands of transactions. By charting the web of Welcome to Video users’ assigned wallets and the bitcoin wallets or exchanges they used, officials identified several US-based cryptocurrency exchanges that users had gone through to pay for their Welcome to Video viewing. US law requires cryptocurrency exchanges to collect customer information and verify their identities, meaning law enforcement can subpoena exchanges for these records.