Every Privacy Tool They Used Became Evidence
What two Chinese intelligence officers, an "untraceable" Bitcoin payment, and an FBI double agent reveal about why privacy tools fail
What two Chinese intelligence officers, an "untraceable" Bitcoin payment, and an FBI double agent reveal about why privacy tools fail
There is a second comforting myth about privacy, and it is the mirror image of the first. The first myth says that if you are disciplined enough, you can stay invisible. The second says that if you use the right tools, encryption, a crypto mixer, disappearing messages, a burner, then you are safe. The case of two Chinese intelligence officers named Guochun He and Zheng Wang demolishes the second myth as thoroughly as the Skripal poisoning demolishes the first. He and Wang were professionals. They used encryption, a Bitcoin tumbler, message deletion, pay phones, and rotating wallets. Every single one of those tools became a piece of evidence in a federal complaint against them. Not one of them worked, because privacy is not something a tool gives you. It is a property of the whole situation, and their situation was owned by the FBI from the first handshake.
What follows is how the operation ran, why every layer of tradecraft failed at once, and what that failure teaches anyone who has ever assumed a privacy app was doing more than it actually does.
THE CORE IDEA. A privacy tool protects one narrow thing under one narrow set of conditions. It does not make you anonymous. Anonymity is a property of the entire system you operate in, and if any part of that system belongs to your adversary, every tool you layer on top of it just produces a cleaner record.
The operation
The FBI assessed Guochun He and Zheng Wang as officers of a Chinese intelligence service, working undercover as staff of a Chinese policy magazine. Their target was not a person but a court case: the U.S. federal prosecution of Huawei in the Eastern District of New York. They wanted the inside of that prosecution, the witness lists, the identities of cooperating witnesses, the trial strategy, and the charges the government planned to bring next.
To get it, they had a source. Beginning in 2017, they cultivated a U.S. government employee, referred to in the complaint as GE-1, and paid that person over time to feed them non-public information. Over several years, the payments climbed from a two-thousand-dollar Western Union wire, to cash handed over in person, to cash and jewelry, and eventually to tens of thousands of dollars in Bitcoin. It was, on paper, a textbook human intelligence operation: a foreign service, a paid insider, a slow professional escalation, and a valuable target.
There was one problem, and it was total. GE-1 was an FBI double agent. From the very first contact, the person He and Wang believed was their asset was working for the other side, and every message, every payment, and every request they made was flowing directly into an FBI file.
Compromised at the first handshake
This is the master lesson of the case, and everything else is a footnote to it. The operation was not lost at some later moment when a tool failed. It was lost at inception, because the single human access point the entire operation depended on belonged to the adversary. Once that is true, nothing downstream can recover it.
Think about what that means for every clever thing He and Wang did afterward. They encrypted their messages, but the FBI was the party reading them. They mixed their Bitcoin, but the FBI controlled the wallet receiving it. They deleted their chat history, but the FBI already held the other side of every thread. Each of those tools is designed to protect you from an outside observer who is trying to break into your communications. None of them does anything when the person you are communicating with is the observer. The tools were not defeated. They were simply pointed at the wrong threat, and so they quietly converted a secret operation into a documented one.
THE ONE-LINE LESSON.Tradecraft applied to a compromised channel does not protect the operation. It documents it. A privacy tool used against the wrong threat model is not neutral, it actively manufactures evidence.
That principle scales all the way down to ordinary life. Encryption on a messaging app protects your conversation from someone intercepting it in transit. It does nothing if the person you are talking to screenshots it, if their phone is compromised, or if they are not who they claim to be. The tool is doing its narrow job perfectly. The narrow job was just never the thing that mattered.
The untraceable payment that traced perfectly
The most instructive part of the case is the money, because that is where He and Wang were most confident and most wrong.
When it came time to pay for the stolen material, He told GE-1 that Bitcoin was "easy to handle and safe" and "difficult to trace." He arranged two payments, roughly forty-one thousand dollars in November 2021 and roughly twenty thousand dollars in October 2022, and he ran them through Wasabi Wallet, a service that uses a technique called CoinJoin to mix many users' coins together and obscure the trail. He rotated to a fresh wallet for the second payment. He staggered and divided amounts "for safety purposes." He even suggested laundering the proceeds into cash through a Las Vegas casino. By the standards of someone who believes crypto is anonymous, he did everything right.
None of it survived contact with reality. The blockchain analytics firm Elliptic examined the case and concluded that all of the bribe payments traced straight back to Wasabi, using nothing more than the information in the public complaint and standard tracing tools. Mixing raises the cost of following the money. It does not erase the trail, and where users make small mistakes, timing, amounts, wallet fingerprints analysts can partly unwind the mix. But the deeper problem was simpler and fatal: the FBI controlled the receiving wallets. The moment each payment landed, the exact amount and the exact timestamp were fixed forever on a public, permanent, self-authenticating ledger that needs no subpoena to read and never expires. He had chosen, as his "safe" option, the single most durable evidentiary record available anywhere in the operation.
KEY TAKEAWAY. Mixing and tumbling are obfuscation, not erasure. A public ledger is permanent, self-authenticating, and needs no subpoena to read, so every attempt to launder a transaction leaves the transaction sitting right there forever. Permanence works entirely in the investigator's favor: the payment you think disappeared is the one that lasts longest.
There is a second, quieter lesson buried in the payment history. Before the Bitcoin, there was a Western Union wire, then cash, then cash and jewelry, then crypto. Read in order, that escalation is its own signature. It shows a relationship deepening and professionalizing over years, and the affidavit reads it back like a ledger of intent. Your financial trail is not a series of isolated transactions. It is a narrative, and it is legible to anyone who can assemble it.
Pseudonymous is not anonymous
He's fatal confidence about Bitcoin came down to blurring two words that sound like synonyms and are not. The gap between them is arguably the single most expensive misconception in personal privacy, so it is worth pulling apart slowly.
Anonymous means no identity is attached to an action at all. No name, no handle, no token, and, most importantly, nothing that links one action to the next. A stranger who pays cash for a newspaper and walks away is anonymous. There is no thread to pull, because no thread was ever created.
Pseudonymous means your real name is replaced by a stable stand-in: a pen name, a username, a phone number, a wallet address. The stand-in hides who you are, but it does something anonymity never does. It links everything you do under it into a single connected history. A Bitcoin wallet is the perfect example. The address is not your name, so it feels anonymous. But every transaction that address ever makes is recorded, in public, permanently, and all of them are tied to one another. The wallet is a pseudonym, and a pseudonym is only as private as its single weakest moment.
That last point is the whole trap. Under anonymity, a slip exposes one action. Under pseudonymity, a slip exposes everything, backward and forward. The moment one transaction on that wallet is tied to a real person, through an exchange that checked an ID, a delivery address, or a receiving wallet the FBI happens to control, the entire history behind the pseudonym collapses at once. He did not lose one payment. He lost every payment the instant the ledger touched a real identity, because pseudonymous records aggregate and they never expire.
None of this makes pseudonymity worthless. For most people most of the time it is the sensible middle ground, and it has genuine advantages:
- It is usable. A pseudonym can hold a conversation, build a reputation, receive replies, and persist over time. Pure anonymity can do none of that, because continuity is exactly what it refuses.
- It is low friction. A pen name or a throwaway handle takes seconds and works fine against the threat most people actually face: an advertiser, an acquaintance, or a casual snoop, not a federal investigator.
- It separates your lives. Keeping a work self, a private self, and a public self under different names is sound practice, and pseudonymity does useful, everyday work.
The costs are just as real, and they are the ones people forget:
- Everything under the pseudonym is linkable. Aggregate enough actions and the pattern alone can identify you, even when the name never does.
- The record is usually permanent. A pseudonym you abandon does not erase its history. It sits there waiting for a future correlation that you cannot see coming.
- It collapses all at once. A single tie-point anywhere in the pseudonym's life de-anonymizes all of it, retroactively.
- It breeds false confidence. The feeling of using a "burner" or a "private" wallet tempts people into doing things under it they would never do under their real name, which is precisely how a pseudonym turns into a confession.
Anonymity is the stronger idea in principle and the far harder one in practice. Its strength is that there is no thread: no persistent token to correlate, so no single compromise unravels a history. Its weakness is that it is brutally fragile and nearly impossible to hold. One reused password, one login from your home network, one payment from a card in your name, one distinctive turn of phrase, and it is gone. It also gives you nothing to build on, because the moment you establish any continuity, a handle people recognize, a wallet you reuse, you have quietly converted your anonymity into pseudonymity without noticing. And as this case shows from another angle, the very effort of staying anonymous, the burner phones and the wiped histories, becomes its own visible behavior.
KEY TAKEAWAY. Anonymity means no thread connects your actions. Pseudonymity means a hidden name connects all of them. The danger is mistaking the second for the first, because a pseudonym feels private while it quietly aggregates everything you do and collapses completely the instant one action ties back to you. Most "anonymous" tools are really pseudonymous, so the question is not "is your name hidden?" but "if one point in this chain is exposed, how much of the rest comes with it?"
Encryption protects the message, not the conversation
He and Wang ran nearly all of their communication through an encrypted messaging app, and He deleted messages compulsively, wiping entire threads on multiple occasions, including the same day he confirmed a payment had landed. Both moves feel like security. Both were worse than useless here.
The encryption failed for the reason already covered: it defends content against a third party in transit, and the FBI was not a third party; it was the counterparty. But the deletion did something actively harmful. It destroyed nothing, because the FBI retained the full record from its own side, and at the same time it created a new signature. A pattern of wiping messages immediately after sensitive exchanges is, to a prosecutor, evidence of consciousness of guilt. The attempt to erase became a data point in its own right.
This is worth separating cleanly, because the distinction is the whole game:
WHAT A PRIVACY TOOL CAN DO.Protect the content of a message from an outside party trying to intercept it while it travels. Encryption does this well, and it is genuinely worth using.
WHAT IT CANNOT DO.Protect you from the person on the other end. Prove the conversation never happened. Erase a record the counterparty already holds. Or hide the fact that you used it, because the act of hiding is itself observable and often incriminating.
The tradecraft that became evidence
Step back and look at the full inventory of security measures He and Wang used, because the pattern is the point. Every one of these is a real, deliberate operational-security technique. Every one of them also appears in the federal affidavit as affirmative evidence of clandestine intent:
- Encrypted messaging for all sensitive coordination, which captured the content natively because the FBI held the other end.
- Public pay-phone protocols, with He asking GE-1 to take calls from a street kiosk to defeat call-record correlation. Preserved verbatim in the complaint as proof of clandestine method.
- A second phone for imagery, with He coaching GE-1 to "use another phone" to photograph documents in a secure room. Documented as tasking.
- Bitcoin through a mixer, chosen precisely because it felt untraceable, now the most permanent record in the case.
- Rotating wallets and staggered payments "for safety purposes," language that reads as sophistication and lands as intent.
- Compulsive message deletion, which erased nothing and added a consciousness-of-guilt signature.
- Refusing direct contact, with He calling it "too dangerous" for Huawei to speak to the source, another line quoted back as evidence of a covert structure.
The uncomfortable truth in that list is that the act of hiding is not invisible. Every measure taken to reduce a signature is itself a behavior, and that behavior has its own signature. Signature reduction that ignores this ends up broadcasting exactly what it was meant to conceal.
Two ways to lose your anonymity
This case is best understood beside its opposite. In the Skripal poisoning, a team of Russian GRU officers was exposed with no human source at all, undone instead by leaked and purchasable government databases, sequential passport numbers, and the bureaucratic signatures baked into their cover identities. He and Wang are the mirror image:
- He and Wang, human-relationship failure. There was no database leak and no clever forensic reconstruction needed. They were beaten through the single human connection at the center of the operation, and their money and their messages betrayed them through that compromised channel.
- Skripal and the GRU, institutional-signature failure. No compromised human anywhere. They were undone by records and registries that existed independent of anyone's field conduct.
Almost every way a person or an operation gets unmasked falls into one of those two buckets, and defending against one does nothing for the other. You can pick the perfect tools and still be handed over by the one person you trusted. You can trust no one and still be sold out of a database you never knew held your name. Real security has to account for both surfaces at once, and He and Wang, like most people and most organizations, were only watching one.
What to actually do with this
The instinct after reading a case like this is to go find better tools. That instinct is exactly the mistake the case is warning against. He and Wang had excellent tools. What they lacked was a correct picture of who could see them, and no app fixes that.
THE MINDSET SHIFT.Stop asking which tool will make you private, and start asking who can see this and what happens to the record after you are done. A tool is only as good as the threat model it is aimed at. Aimed wrong, the strongest privacy tool on the market becomes the cleanest evidence against you.
A few concrete habits follow directly from the case:
- Identify the counterparty before you trust the channel. Encryption secures the pipe, not the person at the other end. Who you are talking to, and whether their device and identity are what you think, matters more than which app you use.
- Treat every payment and every account as permanent. A blockchain entry, a transaction record, a login, a message "deleted" on your side but retained on theirs: assume all of it is durable and reconstructable. Pseudonymous is not anonymous.
- Remember that hiding is a behavior that can be seen. Burner devices, wiped histories, and privacy tools all leave their own traces, and the pattern of concealment can be as revealing as the thing concealed. Use them where they genuinely help, not as a reflex that draws a line under you.
- Audit the whole chain, not the strongest link. Source, channel, money, device, location. The security of an operation, or a private life, is set by its weakest link, and layering tools on a compromised foundation only produces a better-documented failure.
The two Chinese officers in this case are still in China, beyond the reach of a U.S. courtroom, which is the only reason there is no trial. That is not a tradecraft victory. It is the last intact defense of an operation that lost everything else, and it holds only for as long as they never travel. Every digital tool they trusted did precisely what it was built to do, and it did not save them, because the tools were never the thing standing between them and exposure. The system was, and the system was not theirs.
The comforting version of privacy says: install the right app, and you are protected. This case says something harder and truer. A tool secures one narrow thing against one narrow threat, and the moment you mistake it for anonymity, it turns into the most honest witness against you. Privacy is not a product you buy. It is an understanding of who is watching, and that understanding is the one thing no download can provide.