A Chinese podcast · Same story, 4 levels

两亿四千五百万美元,一分钱都不是抢来的:一个二十二岁的人打了两年电话,每一笔都是对方自己交出去的
Not One Cent of the $245 Million Was Taken by Force: a 22-Year-Old Spent Two Years on the Phone, and Every Victim Handed It Over Themselves
About this story
A 22-year-old pleaded guilty in September 2026 to a conspiracy that took more than $245 million in cryptocurrency over two years - one of the largest crypto thefts in US history. Nothing was hacked. Callers impersonated support staff, manufactured trust and urgency, and had victims read their own security codes aloud. Chinese listening practice at four levels. HSK 5-6 Chinese listening practice.
This is an HSK 5-6 Chinese listening episode that runs about 5 minutes. The full Mandarin script is shown with tap-for-pinyin and a line-by-line English translation, so you can listen and read at once — comprehensible input in the sense of Stephen Krashen's i+1 theory. It teaches 12 key vocabulary words such as 控制、机构、成本 and walks through 3 grammar patterns, each explained in English with examples. The same news story is retold at 4 difficulty levels — use the level selector above to find the version that is challenging but still understandable for you.
Read at your level
原文Read the complete story in Chinese. Reveal pinyin and English only when you need them.
English transcript reference
This episode is about a case that just ended in a guilty plea, and about a conclusion I think matters more than the case: in cryptocurrency, what gets breached is usually not the system. It is a person.
The facts first.
Last week, a twenty-two-year-old man pleaded guilty in the United States to participating in a criminal enterprise.
Over roughly two years, the group he belonged to stole and laundered more than two hundred and forty-five million dollars in cryptocurrency.
By value, it is one of the largest cryptocurrency thefts on record in the United States.
The asset needs describing first, or the method makes no sense.
Cryptocurrency does not sit in a bank account. It is recorded on-chain, and control of it is determined by a private key.
A private key is a string of characters; holding the key is equivalent to holding the asset.
There is no lost-key process, no reversing a transaction, no deposit insurance.
The strength and the weakness of that design are the same fact: no institution can freeze your assets, and therefore no institution can recover them for you.
Once you understand that, you understand why crime aimed at cryptocurrency rarely goes down the route of breaking things.
The cryptography itself is hard; a frontal attack is prohibitively expensive with a negligible success rate.
So the attack surface has shifted wholesale to the other side: get the holder to surrender the private key or the verification information themselves.
The collective name for these methods is social engineering.
The name sounds highly technical. In practice it is usually a phone call.
This group's operation breaks into four steps.
Step one is target selection.
Blockchain transaction records are publicly queryable, so how much sits at which address and whether it has moved recently are all out in the open.
Which means an attacker can rank a list of targets without ever contacting any of them.
Step two is establishing an identity.
They impersonated customer support staff at large technology companies and cryptocurrency exchanges and called targets directly.
In one specific case, the victim received calls purporting to come from a search company and from a trading platform.
Step three is manufacturing two psychological states at once: trust and urgency.
Trust comes from the identity — they name a company you know and already use.
Urgency comes from the script — there has been an unusual login on your account, we are dealing with it, we need you to act now.
The two together compress the target's thinking time considerably.
One thing needs stating plainly here: being deceived has nothing to do with intelligence.
The mechanism of urgency is to move cognitive resources from "who is this person" to "what should I do".
In that state, a person's tendency to execute instructions rises noticeably, and the step of verifying who they are talking to gets skipped.
Step four is extraction.
They ask the target to read out a verification code received on their phone, or to open a page and read out what it contains.
The instant the target reads it, control transfers.
In one of these cases, a victim lost over four thousand bitcoin in this process.
The group occasionally used physical methods, including breaking into homes, but by value the overwhelming majority came through communications.
What follows has no technical content at all — only spending.
The ringleader acquired more than thirty cars, several of them custom sports cars.
He bought a watch worth about two million dollars.
Beyond that: mansions, chartered aircraft, and enormous nightclub bills.
This also formed one of the threads in the investigation — the gap between a young man's spending and his lack of any legitimate income cannot be made internally consistent.
Law enforcement traced him and made the arrest; he now faces a maximum of twenty years.
Back to the conclusion at the top.
Two hundred and forty-five million dollars, and not one cent of it was obtained by breaking a password.
Every last transfer was made by a holder acting voluntarily.
These victims were not technically naive — anyone holding crypto assets on that scale usually understands the system far better than average.
What was breached, every time, was one person's judgement about identity over thirty seconds; the mathematical strength of the private key was never tested.
The scope of this extends well beyond cryptocurrency.
Any system that hands final control to a judgement someone makes on the spot has a security ceiling set not by its technology, but by that judgement.
Two questions to leave you with.
The first is concrete: someone calls claiming to be support at a company you currently use, saying there is an anomaly on your account and they need your cooperation.
In those thirty seconds, what can you actually use to determine who they are?
The second is bigger: when a system treats irreversibility as a design virtue, who has it moved the risk onto?
Listen again
Try it without the transcript and notice what sounds clearer.
What vocabulary does this episode teach?
词汇HSK 4. 控制权由一把私钥决定 — and control is what actually changes hands.
HSK 6. No institution can freeze it, and therefore none can recover it.
HSK 6. 正面攻击成本极高 — why nobody bothers attacking the cryptography.
HSK 5. 把认知资源从"这个人是谁"转移到"我该怎么办"。
HSK 4. The thing that was actually breached, in thirty seconds.
HSK 5. The closing question asks who irreversibility moves it onto.
持有私钥即等同于持有资产 — the sentence the entire threat model follows from.
It shifted wholesale from the cryptography to the person holding the key.
Sounds technical; in practice it is a phone call.
Public records let attackers rank a target list without ever making contact.
紧迫来自话术 — the urgency is written in advance, not improvised.
A design virtue that quietly moves all the risk onto the individual.
* beyond level超纲词
What grammar patterns appear in this episode?
语法即等同于……
Is thereby equivalent to. A compressed formal equivalence — used where a definition has consequences the listener must carry forward.
私钥是一串字符,持有私钥即等同于持有资产。
这里要说清楚一件事:……
One thing needs stating plainly. An explicit interruption to head off a misreading before it forms.
这里要说清楚一件事:受骗与智力无关。
任何……的系统,……都由……决定
Any system that does X has its Y determined by Z. Generalises a specific case into a rule, which is how the episode ends.
任何把最终控制权交给"某个人当场做的一个判断"的系统,安全上限都不由技术决定,而由那一刻的判断决定。
Proper Nouns
专有名词Sources
来源Free account
Keep learning from this story
Create a free account to keep saved words and your preferred level together.
- Keep words with their story context
- Remember your preferred level
- Build your vocabulary over time