# The Chaos Computer Club, the Btx heist, and the hack that ended in a forest

> Germany's hacker scene took a different road from America's: organised, political, and arguing in front of cameras. In 1984 the Chaos Computer Club moved 134,000 marks out of a bank overnight and gave it back on television. Four years later, a different Hanover crew sold their intrusions to the KGB, and one of them died in a forest at twenty-three.

Source: https://ronutz.com/en/learn/chaos-computer-club-btx-and-the-kgb  
Updated: 2026-08-28

---

## A club, not a crew

The Chaos Computer Club was founded in 1981 in the offices of a left-wing Berlin newspaper, and that origin explains almost everything about how German hacking differs from the American story. Where the US underground organised itself into rival crews with handles and feuds, the CCC organised itself as an **association** - with a name, a postal address, a magazine, an annual congress and, eventually, standing as an expert witness before Germany's constitutional court.

Its founder **Wau Holland** took Steven Levy's hacker ethic and added two clauses that the American original lacked, both of which read as prophecy now: *do not litter in other people's data*, and *use public data, protect private data*. That second line is the whole of modern privacy politics compressed into six words, written by a hacker in 1984.

## The Btx heist: 134,000 marks, returned on camera

The club's founding demonstration came in November 1984. The Bundespost, the German state telecoms monopoly, was promoting **Btx** - Bildschirmtext, a videotex system for banking and shopping - and insisting publicly that it was secure. CCC members found otherwise: a page-buffer overflow in the system leaked the access credentials of a Hamburg savings bank, and Btx billed users automatically for viewing paid pages.

So they wrote a script that repeatedly called a CCC-owned premium page using the bank's account, all night. By morning the meter read roughly **134,000 Deutschmarks** owed by the bank to the Chaos Computer Club.

Then they did the thing that made them an institution rather than a criminal case: they called a press conference, explained the flaw in detail, and **gave the money back**. The Bundespost, which had denied any weakness, had to concede in public. The Btx hack is the founding template of the CCC method - technical proof deployed as civic argument, with restitution built into the demonstration so the argument cannot be dismissed as theft.

## The KGB hack: the other road

Four years later the German scene produced its darkest chapter, and it is essential that the two stories sit in the same article, because they are the two available destinations for the same skills.

A loose group around Hanover - **Markus Hess**, **Karl Koch**, and others on the fringes of the CCC's world - began breaking into US military, university and defence-contractor systems and selling the access to the Soviet **KGB** for cash and drugs. This was no longer curiosity, and it was not politics either. It was espionage, and it was the far end of the trail that [Cliff Stoll followed from a 75-cent accounting error](https://ronutz.com/en/learn/the-cuckoos-egg) at Berkeley.

The human cost fell hardest on Karl Koch, who hacked as **Hagbard Celine**, after a character in the *Illuminatus!* trilogy, and who had convinced himself that the number 23 governed reality. Drug use and paranoia had hollowed him out well before the arrests. He confessed to German authorities and was granted amnesty; in May 1989 he was found burned to death in a forest outside Hanover, in a case officially ruled suicide and disputed ever since. He was twenty-three, which the people who knew him could not help but notice. The story became the German film *23*, and the scene's most-repeated cautionary tale.

The CCC's response was to state a boundary out loud: hacking for a foreign intelligence service is not part of the ethic, and never was. That the club had to say it - and that some members had drifted anyway - is the honest part of the history.

## Why the German model outlasted

Four decades on, the CCC runs the **Chaos Communication Congress**, one of the world's largest hacker gatherings, and functions as a permanent technical opposition: it demonstrated that Germany's biometric passport fingerprints could be lifted from a glass, published the analysis of a state surveillance trojan the government preferred not to discuss, repeatedly broke electronic voting proposals, and has been called as an expert before the Bundesverfassungsgericht.

The American scene produced better legends. The German scene produced better **institutions** - and the difference traces directly back to a decision made in 1984, to give the money back and hold the press conference. Proof plus restitution plus publication turned out to be a strategy that survives its founders, which is more than most of this history can claim.
