13k BTC, 300k LTC Stolen from Cryptsy Exchange
blog.cryptsy.com
blog.cryptsy.com
If this happened, it means what were thought of as "cold wallets" were not implemented properly. When handling millions of dollars of coins, as Cryptsy was, a deep cold wallet [1] should be used. Take an offline computer and an offline printer. Generate a bunch of (optionally multisig) addresses. Print the private keys. Copy the addresses to your server that processes transactions. Lock away the private keys (optionally in multiple places). Never connect the offline computer or printer to the internet. Send every X bitcoins to a new address from the cold wallet.
This takes a few hours and a few hundred bucks to implement. It requires human intervention to access the cold wallet (to replenish the internet-facing "hot" wallet), but that is what you want! It is a whole lot easier to manually move coins once a week than it is to check for bugs and backdoors in your whole stack. Worst case, customers suffer a delay in withdrawals and a hack causes you to lose X bitcoins.
Edit: Of course, it could also be an inside job. An "exit scam." Moving coins to a new address and then not spending them is pretty hard to get caught doing.
Has there ever been any real or serious evidence to demonstrate that any of these seemingly numerous Bitcoin 'hacks' have been legit and not inside jobs, which is exactly what they all look like?
There are so many 'exit hacks' it seems virtually standard practice in the Bitcoin world, perhaps because nobody seems to actually go to jail for it or even face any serious legal investigations into it.
If a bank announced a multi-million dollar 'hack' I'd expect the authorities would be heavily involved, immediately, and everyone with a position to have facilitated a theft would be under suspicion and investigated until ruled out.
One the one hand Bitcoin is a supposedly serious, game changing currency and has billions of dollars tied up in it; on the other, it's treated as little more than internet karma points, and if people have it stolen from a wallet or someone announces yet another million dollar 'hack' at some comical 'exchange' any old clown/scammer can throw up, it seems to be simply 'tough shit' and nothing to see here.
This may be the non-regulated world the fanatics want, but it's a major reason why sane people (currently almost everyone on Earth) will continue to avoid Bitcoin like the plague.
>Has there ever been any real or serious evidence to demonstrate that any of these seemingly numerous Bitcoin 'hacks' have been legit and not inside jobs, which is exactly what they all look like?
You're asking people to prove a negative[1]. It's a common logical fallacy.
>nobody seems to actually go to jail for it or even face any serious legal investigations into it.
Really? This claim is trivially disprovable. Numerous people have been arrested, including Mark Karpeles of Mt Gox. You've never heard of that case? $500 million allegedly stolen
https://www.google.com/search?q=bitcoin+exchange+arrested
http://www.wsj.com/articles/japanese-police-arrest-mark-karp...
http://siliconangle.com/blog/2015/02/23/mintpal-scammer-ryan...
For example an identified backdoor and logs pointing to an external hack is exactly what you'd expect to see planted if this were a halfway clever inside job, right? So how do you possibly rule that out?
Imagine how strange it would be if you had a breach at your home, a very large amount of value would be stolen and you'd not make any effort to alert the authorities and if the only thing that would prove that it was an outsider was your say-so. Of course, you could make it look like a burglary when it really was you but the various agencies would most likely be able to tell the difference, or in fact may be able to conclusively prove that you were the one doing it in the first place.
Lots of real-life fraudsters get caught this way, I don't see why on-line fraudsters should get a free pass on having to at least meet the same level of proof before they are believed.
No, he's asking for proof that there has been a non-internal Bitcoin hack. That's a simple existence proof.
If he were asking one to prove a negative, he'd have to ask something like "prove that there have been no internal Bitcoin hacks" (which is likely easily refuted but beside the point).
(He may be implicitly claiming a negative proof, by implying that there isn't any evidence that these are non-internal hacks, and therefore they must be inside jobs. But that's merely asking others to disprove a negative, which is trivial with evidence.)
In reality it's not simple. How would you prove it?
However you define this, a very serious problem with the OPs request for proof is the pseudonymous nature of Bitcoin, combined with the difficulty of definitively connecting a real life identity to an online action.
The Cryptsy 'hack' is a neat example of this. The money was moved once, 18 months ago, and for observers, that transfer of money did not appear suspicious at the time. It looked just the same as an internal movement of funds for security or accounting purposes. The money even remains where it was moved.
But now Cryptsy's owner has announced that the money was not moved by him.
How can we prove or disprove his claim?
We can say that he dishonestly hid the theft, but it seems impossible to prove that he stole it. Even if his ISP is ordered by a court to release logs that show his home IP address did the theft, he could claim that his computer was hacked. But for someone doing an inside job, anyway there are so many ways to hide their identity and IP address.
Edit: So, should anyone offer evidence of a non-internal Bitcoin hack, the OP can simply make these arguments, to plausibly suggest that it may really have been an internal hack, disguised as an external hack
Personally I'd be already more inclined to believe it was an outsider if they filed this breach with the authorities and if they turned over all their evidence. You'd have to be fairly cocky to do that if you were the one that made off with the loot (not that it wouldn't happen, but it would happen a lot less frequently).
But in the cryptocurrency space, judicial authorities lack expertise, geographic jurisdiction can be unclear, and invesigators may not be able to unearth the truth. The Bitcoinica thefts are an example of that, Mt Gox may be another. Every time, it would be easy to prove negligence, but definite proof of criminality is hard.
It is true that if Cryptsy had reported the crime at the time, the story would have been more plausible, but even then there still would have been much doubt and a genuine possibility that it was fraud. At least the possible evidence, logs and whatnot, would have been fresh.
To me this is an extremely important aspect and it moves the needle from 'could be fraud' to 'definitely fraud'. Nobody taking a hit like that would try to hide it from both their end users and the authorities if they weren't involved, no possible gain could come from trying to cover this up other than to see if they could do it again.
Covering up a breach of this magnitude (which is simply the end for the company, assuming the funds won't be recovered, and which should be the end of the company even if the funds are recovered) is a much higher risk than being frank about it for the simple reason that the trail will be cold by the time the truth eventually comes out.
Unfortunately, there is a possible gain, at least from the viewpoint of the owner: Simply keeping the business, and his normal life, running --- presumably hoping that a magical solution will appear from the clouds. (or to be try to be more charitable to him, maybe he hoped for a foolish new investor, or a dramatic change in bitcoin price)
If that's what happened, it was irresponsible, very stupid, and certainly fraudulent, but many people have done similarly stupid things in similar situations.
No matter what happened, that ridiculously long delay in reporting the theft is a most serious red flag, like you said.
Maybe you're asking a rhetorical question, but historical precedent suggests the chance of recovering the funds in this sort of crime is really small. There have been tens of relatively big cryptocurrency heists like this, and but only in perhaps three or four cases that I know were funds recovered from the thief
But, to again imagine the Cryptsy site owner's viewpoint, statistics and probability are no match for pure human desperation, so, if we believe the 'hack' story, then a desperate plan based on the ill-advised belief that the funds could be recovered from the thief is not totally unbelievable. Though it sounds even more unlikely because the owner only announced a public bounty yesterday, not 18 months ago when the money was stolen.
I suspect several of the higher profile data leaks and acts of vandalism that were blamed on outsiders but where subsequent follow up was never shown to actually prove that this was the case were in fact inside jobs, especially in those cases where the company did not file the issue with the authorities.
I think that if a company claims 'a hacker did this' that they should provide conclusive evidence and absent that we should simply assume that it really was an inside job.
No, I'm asking for examples of investigations where authorities have concluded that so-called 'hacks' at Bitcoin exchanges were indeed hacks and not simply thefts by scammers running the services.
>Really? This claim is trivially disprovable. Numerous people have been arrested, including Mark Karpeles of Mt Gox. You've never heard of that case? $500 million allegedly stolen
Karpeles has not been arrested over "$500 million allegedly stolen", which is perhaps why you linked to a story about something else, behind a paywall.
As for Moolah guy, if you have 'proof' that he was arrested over the hacked Mintpal coins that amounts to more than Chinese whispers on Bitcoin forums/blogs, let's see it. All your link does is link to another site that claims he was arrested, almost a year ago, and doesn't even state why.
Even if we assume he might be one day charged with the theft of the coins, that's one person involved in a Bitcoin inside job facing prosecution over it.
I'm sure I can find more than one person involved in an inside job at a bank (involving dollar amounts considerably smaller than we're talking about with Bitcoin 'hacks') doing actual time for it.
http://arstechnica.com/business/2012/03/bitcoins-worth-22800...
They hacked Linode's customer service portal, and compromised 8 Linode customers. So I guess it could be an inside job of a Linode employee instead of one of the bitcoin exchange's employees.
And yet you have wealthy Silicon Valley Venture Capitalists actively promoting this crap, and no one is calling for heads.
Am I the only one who finds it a bit amusing that an e-currency bank needs people to physically move the bullion from one vault to the other?
Some of the parameters you can pick from:online vs offline ("cold"), hosted vs not, SPV vs full node, multisig, dedicated hardware wallet, etc.
And you can combine them in various permutations: e.x. offline + multisig is just about the most secure thing you can imagine.
Can you tell me the last time some you know had money go missing from their bank account?
http://www.economist.com/blogs/schumpeter/2013/03/cyprus-bai...
Question to ask Bitcoin exchanges: are your people bonded, and who's the bonding company. If they answer "What?", they're clueless about vault operations.
Only for millions of coins? What about the savings of the average person? A loss would be devastating. Do you recommend the same security measures? If the system is insecure, it's insecure.
The idea that Bitcoin is in any way ready for the mainstream is kind of funny.
I'm genuinely curious. Can you envision any possible distributed internet currency that wouldn't require human interaction for the highest level of security? Keep in mind, the threat model here is someone gaining read access to a few kb of data. With an automated, internet-facing system, I see an airgap as the only reasonable defense against that threat.
If someone gains read access to, say, your bank session cookies, they could also feasibly clean you out. The only difference is the bank might be able to reverse the transaction (undesirable a decentralized currency) or cover your losses (not a bad idea).
This happened back in July 2014. $5M stolen and you didn't call the cops. They continued to do business and accept deposits even though insolvent. Only when a class action was filed because they were not paying out timely withdrawals did they disclose this theft.
That just screams "inside job".
(Yesterday I made the comment on another thread that Bitcoin exchanges seemed to be doing better; no major exchange had collapsed in 2015. Here we go again.)
Where is this company based? Trading while insolvent is explicitly illegal, at least in the UK (https://en.wikipedia.org/wiki/Trading_while_insolvent).
Also, Paul Vern, the CEO, seems to be missing. One site claims he's in China, based on an IP address seen.
Name: PAUL VERNON
Organization: CRYPTSY INTERNATIONAL LTD
Street: 5 CALLE AL MAR
City: BELIZE CITY
State/Province: BELIZE
Postal Code: 00000
Country: BZ
Phone: +1.8889639935
which is a "virtual office" space in Belize.[1]Cryptsy is not in Dun and Bradstreet or the Florida Department of Corporations database. But they have another corporate name, "Project Investors Inc." It has a BBB rating of F, with 17 complaints.[2] That business is registered with the state of Florida.[3] Those records include the CEO's home address, which is in Boynton Beach, FL.
[1] https://www.abcn.com/offices-belize-city--calle-al-mar-3605 [2] http://www.bbb.org/south-east-florida/business-reviews/busin... [3] http://search.sunbiz.org/Inquiry/CorporationSearch/SearchRes...
The wrinkle is when you're insolvent and also a financial institution, which has been a critical failure mode since the Medicis.
> Imagine a SaaS company which takes out a loan for $100k to acquire customers and has $10k in bank at any time. That company is insolvent.
That's simply wrong. Many companies have more assets than liabilities; Revlon, for example has around $2 billion in assets and $2.5 billion in liabilities last I looked, but they're not insolvent or in any particular danger of becoming so; the market values them as being worth around $1.5 billion.
At least in the US, insolvency is a question of cash flow. Your example SaaS company is able to service its debts and make payroll, thus it is solvent. The fact that it might have negative shareholder equity is quirk of accounting that nobody really worries about.
(If you already knew that, my apologies.)
I don't think that is right. Yes, they have more in liabilities than assets but insolvency would mean that you can't service your currently due debt. If you took out a loan with a $5000/mo payment, you would not be insolvent until you cannot make that payment.
In the case of an exchange, that liability doesn't have a future due date - so they would be insolvent once they do not have the assets to cover their liabilities.
It is only when a corporation is liquidating that it matters (for purposes of determining insolvency) if liabilities exceed assets.
So, basically, someone re-released a new, modified codebase for an abadoned coin, and they ran it on their servers without proper isolation, so the backdoor could access their other wallets?
The lack of isolation between the various coins reminds me of Allcrypt, the exchange that ran their Bitcoin-trading software on the same database with the same password as their WordPress website. In their explanation they managed to absolve themselves of all responsibility and blame their marketing person whose account was stolen, when in fact the marketing person was the only responsible one in the whole company, alerting the technical folks about the unexpected password reset email: https://archive.is/2UY7e
> Q: You morons! You had a WordPress site that allowed uploading of new files?!?!
> A: It was the marketing director’s account. Beings that he was constantly updating files, it was necessary for his account to have the ability to upload new files.
The real question, of course, being "You morons! You had a WordPress site on the same server as critical financial services?!?!"
edit: Also:
> Q: Your security sucks!
> A: I see you running an exchange successfully, I’ll take your advice.
Says the guy running an exchange unsuccessfully.
It's really a joke the lack of security these bitcoin "banks" have around their vaults. Our PCI auditor wouldn't pass us if he audited our firewall and noticed the crypto servers that stored the credit cards had outbound access to anything other then the 1 vlan that acted as a API layer from those servers and the banks.
These companies should really just follow PCI and start there.
The US government et al should really classify these as banks and force them to address the same privacy, disclosure, fraud prevention etc regulations.
The potential of Bitcoin as something your grandparents could one day use is constantly being undermined by these cowboy operators.
2) I think far more damage is being done to Bitcoin by the political fighting and poor technical decisions of the core developers. Bitcoin weathered Mt Gox, it can weather Cryptsy.
[1]http://seekingalpha.com/instablog/7360901-robert-wagner/2715...
http://www.zerohedge.com/news/2015-11-04/there-are-now-293-o...
One case, Bernie Madoff: $65 billion stolen
Though that 1 in 14 number which you cited is barely even a guesstimate, for bitcoin it is easier to estimate the rate of theft, because at least you know exactly how many bitcoins exist now, or will exist in future, unlike the USD.
A few other points for us to consider..
* About 75%-80% of banknotes in developed countries have traces of illegal drugs. One study suggested about 4% were involved in illegal activity such as purchasing, selling or using drugs[1]. Other crimes do not leave obvious chemical traces of course.
* The further back into history you look, into colonial times and earlier, the more true becomes the statement "All wealth is stolen"
From bop.gov:
BERNARD L MADOFF
Register Number: 61727-054
Age: 77
Race: White
Sex: Male
Located at: Butner Medium I FCI
Release Date: 11/14/2139I think given his age that he'll be released in a horizontal position a lot sooner than that.
If this crap had happened to an institution that was audited, protected, and enumerated in US dollars, this whole fiasco would be only a bad day for the Cryptsy owners, not the depositors also.
But you get what you get when you go with a non-fiat currency. It's interesting to me to watch people in the BTC space re-learn the lessons learned by financial systems since the dawn of currencies; at least they're learning them faster in the digital age.
Using the bitcoin client directly: the addmultisigaddress command. https://en.bitcoin.it/wiki/Multisignature
Using bitaddress.org, an "Open Source JavaScript Client-Side Bitcoin Wallet Generator". Makes use of Shamir's. https://bitaddress.org (save the page locally and run it while disconnected)
Using Shamir's directly. Split one private key into multiple points. https://bitcointalk.org/index.php?topic=393159.0
There is one nice thing about bitcoin multisig as opposed to running ssss on a private key. With multisig, you can generate three keypairs on three computers, then combine their public keys into a (say) 2-of-3 multisig. I'm pretty sure that using ssss would require the full-authority key to exist on a single computer at creation time, and it would be split afterwards, which is less secure.
Something, perhaps your idea, needs to be done, before Bitcoin can have long-term success. Because you're exactly right. It's just too tempting. This isn't the first time something like this has happened. Not the second time. Not the third time!!!
I've been working on this exact thing for a while: https://github.com/mappum/mercury However, I'm still waiting for the altcoins to adopt BIP65, a Bitcoin patch that adds a new script opcode, which is necessary for cross-chain atomic swaps. Bitcoin recently adopted this change, so the altcoins should follow in the near future.
"You know what's cooler than a million dollars? Virtual currency backed by nothing and nobody."
Here's Bitcoin explained using a Venn diagram. If you don't understand this diagram, you're the ideal Bitcoin user. http://www.thereformedbroker.com/2013/11/20/bitcoin-likely-u...
Bitcoin resembles tulipmania much more than investing. At least I can pay my taxes with the fiat currency that is the US dollar. The only thing I can do with Bitcoin is pass it on to a greater fool or to someone who will use it as an intermediate "currency" which he will immediately convert to something more tangible.
Bitcoin is very useful as a short term medium of exchange. It's not an investment and it's not a store of value.
Most "short term" media I use, I don't expect transaction finalization in scales of hours.
It would be better to store savings in an interest bearing account with a bank or other investments, some of which might include bitcoin and some of it's possible successors.
For me at least, the compelling thing about cryptocurrencies is the possibility of cheap transactions, but bitcoin itself doesn't really seem to fit the bill as it stands, so it seems like a high risk investment.
But you demonstrably don't escape price fluctuation by moving to a non-fiat currency; you just move the causes around.
In the 21st century, customers of traditional banks usually don't lose any money when a bank is robbed.
If you're arguing that the state of Bitcoin is analogous to banks in the 1800s, that's fine as a perspective on the relative state of advance; to me, it's a wonderful way of saying I should keep my money as far away as I can from BTC.
The issue is that the uptake of these solutions is slow, because of reasons like backward compatibility and poor software engineering and govt meddling.
300k LTC x $3.31 = $ 993,000
Total: $5,795,070
That's the email they received, and did business with this company, while overseeing millions of dollars in other people's money. Then got ripped off. Who needs banks?
>If they are returned, then we will assume that no harm was meant and will not take any action to reveal who you are. If not, well, then I suppose the entire community will be looking for you.
Not the FBI? Oh, right, they don't care. By the way, the guy who stole the coins was part of "the community".
>2. Somebody else comes in to purchase and run Cryptsy while also making good on requested withdrawals.
How is that even an option?
What a bizarre story.
"In fact, I’m offering a bounty of 1000 BTC for information which leads to the recovery of the stolen coins."
e.g.: ~$350k! This could quickly escalate into an bounty head.
Money directly stolen out of a platform wallet is an unneeded problem. It should never happen. It should not be possible for an attacker to give that instruction. The system should not even know where to send such instruction to. So, how could an attacker ever do that?
The real difficulty is to prevent an attacker to inject misleading/deceptive messages into the system that cause the system to pay out to the wrong address. This does happen, if only because of bugs in the system.
If so, I would wager global law enforcement organizations will want to step in and offer merchants and users a service which traces and blacklists the outputs from thefts like this (until/unless returned to the original owner). If so, it would create a big rift between the many who enjoy cryptocoins' fungibility and independence from the state and those who want to punish/deter thieves. Big merchants like Overstock would want to publicly align themselves with "bitcoin is legit" and "we don't want to profit from that theft" activity.
There'd be little that anyone could do to stop the law enforcement agencies from providing such a theft tracking service. And little anyone could do to stop merchants from integrating it into their services. It would be an interesting threat to the fungibility of bitcoin.
Some cryptocoins (monero, et al) use ring-signatures that mask their specific input/output address path. I suspect if these events came to pass, those coins would become much more popular.
https://github.com/alerj78/lucky7coin/issues/1
It's like a living Underhanded C competition.
Because the insurance would have been way too expensive, or would have demanded way better operational security and auditing. And because they were able to operate without one.
It's time to get an arrest warrant out for the CEO, Paul Vernon.
(When the CEO calls himself "Big Vern", one might question the legitimacy of the company.)
Question is what a buyer would be interested in: Their platform is suspect from a security standpoint - if they got this much wrong, then what else did they get wrong? Their brand is shot. The code is hardly going to be worth even a fraction of what it'll cost to make customers good.
And it's exceedingly ridiculous to get caught out in this way: No isolation of third party coin daemons, and a very creative interpretation of cold wallets (why in the world was it possible for someone to get the keys for the cold wallets via a network breach)
They've demonstrated they can't be trusted to be open about problems, and that they can't be trusted to get even basic security precautions right, so even if they got the funds back somehow, it's extremely unlikely that they'd manage to repair the damage to their trust.
So, yes, it's probably the end, whether or not they manage to recover some of the stolen coins.
So really the banks are correct in their assesment, the real value quite obviously is indeed in the blockchain technology.
100% growth in few months?
Of course, that replaces the issue of technological fraud with insurance fraud (and the technological risk of compromise to the insurance holder itself, though "put all your eggs in one basket and make sure it's the BEST basket" is an old and trusted software engineering paradigm). It actually feels like a way big, stodgy institutions could get into the BTC space if they chose to.
Seemingly this is the year that Bit Coin stumbled.
We're truly living in the future.