DOJ Says Chinese State-Backed Hackers Breached The Fed, DOJ, Senate And NASA

While the show spent most of Thursday on Bitcoin's order books, a story broke in the background that says as much about the current AI moment as any chart does. The Justice Department says a Chinese state-sponsored hacking group broke into some of the most sensitive networks in the United States.
WHO GOT HIT
The Federal Reserve, the U.S. Senate, the Department of Justice, NASA and other federal agencies were victims of computer intrusion by a Chinese state-sponsored hacking group, the DOJ said as it announced the seizure of internet domains used for hacking platforms described as having been "used to target U.S. critical infrastructure and other sensitive networks." DOJ identified the alleged targets as NASA, the Federal Reserve, the departments of Justice, Energy and Health and Human Services, the National Institutes of Health and the U.S. Senate. Other alleged targets included hospitals, telecommunications providers, power companies, financial institutions and defense contractors, as well as four unnamed companies in the U.S. and South Korea.
HOW THE OPERATION WORKED
Court documents unsealed in California federal court said that a Chinese state-sponsored group known as "QTFY" created and operated the hacking platforms, which were employed by Nanjing Xinjiuwei Network Technology Co., a China-based company. According to DOJ, QTFY sold hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army.
QScan automatically infected thousands of IoT devices worldwide, routers, cameras and smart home hardware, conscripting them into a network called QTRouter. DOJ described QTRouter as a system designed to hide the source of malicious activity, making it appear to come from outside China, sometimes from devices located near the targeted networks. DOJ said the court-authorized seizure made both QScan and QTRouter inoperable. An affidavit said the infrastructure had been used to compromise U.S. and global critical infrastructure and sensitive networks since at least 2018.
Attorney General Todd Blanche said in a statement: "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise." The DOJ did not detail the damage to the agencies or other targets from the computer intrusions.
WHY THIS MATTERS BEYOND WASHINGTON
This lands in the same stretch of weeks that has seen AI-generated vulnerability reports surface real bugs across Bitcoin infrastructure, from a cold card exploit to this week's Core Lightning disclosure. The two stories are not the same event, but they point at the same shift: AI has lowered the cost of finding weaknesses in software, whether the target is a nation state's federal agencies or an open-source Bitcoin wallet. The U.S. is racing to both regulate and out-build AI at the same time it is defending against state-backed actors using the same tools offensively. That tension is not going away, and neither is the pressure it puts on every piece of infrastructure, government or otherwise, that has not yet been stress-tested against it.
This story comes from the Simply Bitcoin Live show. Watch the full episode.




