The 75-Cent Mistake That Exposed a Cold War Spy Ring

The 75-Cent Mistake That Exposed a Cold War Spy Ring
On his second day at a new job in 1986, an out-of-work astronomer was asked to explain a 75-cent accounting error. Most people would have called it a rounding mistake and moved on. Cliff Stoll did the math by hand and discovered it wasn’t a rounding mistake. Ten months later, he had personally exposed a KGB spy ring that had broken into 400 U.S. military computers.
Stoll was an astronomer with Einstein-style hair and a doctorate in planetary science. When his grant ran out, the Lawrence Berkeley National Laboratory kept him on payroll by reassigning him to their computer center. He barely knew Unix. He was now a sysadmin.
On his second day, his manager asked him to find out why the previous month’s books were 75 cents short on a $2,387 bill.
Stoll found that the lab’s billing code didn’t round. Which meant someone had used 9 seconds of computer time without paying for it. Which meant someone was on the lab’s computer who had no right to be there.
The intruder had a username Stoll had never seen before. Just one word.
*Hunter.*
Within days, Stoll realized Hunter wasn’t a curious student. Hunter had full administrative access to the entire system — obtained by exploiting a flaw in GNU Emacs that almost nobody on Earth knew about yet. From inside Berkeley’s computer, he was using the lab as a stepping stone to break into Air Force bases, Army facilities, defense contractors, NASA, MIT, and military command networks across the United States.
Stoll, more curious than alarmed, started watching.
He spent one famous weekend dragging fifty borrowed terminals into the lab and wiring them to every modem line in the building — so that when Hunter logged in, Stoll could capture every keystroke on a printout in real time. He bought a pager and clipped it to his belt. Whenever it buzzed in the middle of the night, he jumped on his bicycle and pedaled across Berkeley to watch live as a stranger half a world away poked through American defense networks.
He slept under his desk for nights at a time. His girlfriend brought him sandwiches and hand-knitted sweaters.
He went to the FBI. They laughed him off — no significant money was missing, and the lab held no classified information. He went to the CIA, the NSA, and the Air Force Office of Special Investigations. For months, almost no one in the United States intelligence community thought a 75-cent billing error was worth taking seriously.
So Stoll kept investigating himself.
He traced the intruder’s patterns and determined he was operating from central Europe. He worked with phone engineers to trace the connection across the United States, across the Atlantic, through a satellite to West Germany, and finally to an apartment in Hanover.
But West German police needed the intruder to stay online for at least 45 minutes at a time to complete a trace. Hunter usually logged off after ten or fifteen minutes.
So Stoll and his girlfriend invented a solution.
He built a fake department on Berkeley’s network — a fictitious office working on Ronald Reagan’s Strategic Defense Initiative — and filled its files with hundreds of pages of completely useless phony documents. He invented an imaginary secretary. He made the bait irresistible to a Cold War spy.
What Cliff Stoll had built was, by most accounts, the first honeypot in computer security history.
It worked.
Hunter parked himself on Berkeley’s computer for hours at a time, downloading fake SDI documents. West German police completed the trace, knocked on a door in Hanover, and arrested a young hacker named Markus Hess, along with his co-conspirators.
They had spent several years breaking into roughly 400 U.S. military computers and selling everything they found to a KGB officer in East Berlin.
Their total payment from the KGB over the entire operation: around $54,000 in cash — and, according to legal records, a quantity of cocaine.
Hess and his ring went to trial in 1990. The Berlin Wall had just fallen. The judge gave them suspended sentences. None of them served prison time. They smiled as the verdicts were read.
Stoll flew to Germany to testify, then went home to Berkeley and wrote it all up — first as an academic paper, then as a 1989 bestseller called *The Cuckoo’s Egg*, which is still on the required-reading list of nearly every major cybersecurity course on Earth.
He went back to making strange things in his basement. Hand-blown Klein bottles. Joyful, scatterbrained TED talks. He kept his Einstein hair. He was, by every account, one of the gentlest, weirdest, most curious people in the early history of the internet.
He died in May 2024, at the age of 73.
The world’s first cyber-spy ring was caught because one curious astronomer, on his second day at a new job, refused to write off a 75-cent billing error.
Pay attention to the small things.
Sometimes they are the only signs anyone ever sends you.



