Power plant operators ended up arrested in the Ukraine for mining cryptocurrency in the Yuzhnoukrainsk nuclear power plant facility, said officials at the Security Service of Ukraine (SBU).
The crypto miners compromised the nuclear facility’s security via their mining setup’s Internet connection — and reportedly ended up leaking classified information on the plant’s physical protection system, according to a Wednesday report in the English-language Ukrainian news site UNIAN.
SBU detectives obtained a search warrant and performed an investigation on July 10.
The SBU confiscated six Radeon RX 470 GPU video cards, a motherboard, power supplies and extension cords, a USB and hard drive, and cooling units installed in the South Ukrainian Nuclear Power Plant, according to the report.
All of the equipment was located in a single office in the administrative wing separate from the power facility, from the state-owned Energoatom enterprise.
The power plant is registered as a state secret and outside computer equipment is not authorized to enter the property.
The same day, a National Guard of Ukraine branch uncovered additional crypto mining equipment at the same facility. In this search and seizure, 16 GPU video cards, 7 hard drives, 2 solid-state drives and router were uncovered.
It is unknown what type of cryptocurrencies were being mined.
Cryptocurrency mining is a power-hungry endeavor that consumes more electricity globally than some nations do.
The enterprise was a small-scale operation and didn’t involve hijacking the plant’s equipment, which would have compromised its safety. Instead, the suspects deployed several computers tailored for the kind of computation needed for mining in one of the plant’s administrative buildings, siphoning electricity from the local grid, court papers cited by local media said.
“In the latest news out of Ukraine, nuclear plant engineers installed unauthorized devices plus an Internet connection in their internal network, which likely went undetected for months or longer, exposing critical infrastructure to potentially catastrophic safety issues,” said Phil Neray, vice president of industrial cybersecurity at CyberX, a Boston, MA-based critical infrastructure and industrial cybersecurity firm. “This is a great example of ‘trust but verify’ – even with the strictest policies and regulations in the world, it’s all theoretical if you aren’t continuously monitoring for unusual or unauthorized activity.”

