BitFinex down due to Bitcoin security breach - 120k BTC stolen
reddit.com
reddit.com
Bitfinex uses BitGo for multi-signature (MultiSig) transactions. 2-of-3 signatures must be present for user funds to be released.
Keys present:
- Offline key held by Bitfinex
- Online key held by Bitfinex to initiate user withdrawals
- Online key held by BitGo to confirm user withdrawals are within constrained limits in a set timeframe
zanetackett, Product Development of Bitfinex, confirmed that Bitfinex's offline key was not compromised. The attack was also not internal [1]. Another set of comments also suggested that BitGo limits were set in place by Bitfinex [2-3].
The automatic limits are designed to constrain BitGo from signing any transaction from Bitfinex that are irregular in volume or exceed a set amount in any rolling timeframe. Somehow they were bypassed. What we have currently suggests that the limits were too large or that BitGo was not enforcing the limits. BitGo and Bitfinex are also separate established entities, so that both of them being compromised for this attack is unlikely. An improper setup between Bitfinex and BitGo is more likely.
[1]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
[2]: https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_sh...
[3]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
Source: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
The same scheme can be implemented as a one-page smart contract on Ethereum: http://www.blunderingcode.com/ether-vaults/
Of course Ethereum had its own giant theft, but that was from a convoluted, poorly-written, and much larger contract. There are ways to avoid the sorts of vulnerabilities that were exploited there: http://www.blunderingcode.com/writing-secure-solidity/
Probably other vulnerabilities will be discovered. But I think simple contracts that secure ether with multiple keys, timelocking, and so on are a pretty good solution for anyone just storing and sending ether. They're also starting to incorporate formal verification of contracts; the online Solidity compiler includes it now, though it doesn't yet support all Solidity features.
It's possible to have customer balances of $60 million and not lose them. Thousands of businesses manage this. They suffer $5+ million dollars of damages in less than 0.1% of business-years. (SWAG on a reasonable upper bound-- ask an actuary. This is an insurable risk.) Bitcoin exchanges with this level of deposits sustain $5+ million dollars of damages 20%+ of exchange-years.
Running Bitcoin exchange probably requires $10 million a year in engineering and compliance costs, and consequential changes to the business model with an eye towards a) paying for the actual costs of running the business and b) compromising on other things that users/investors care about, like speed of withdraw, degree of engagement with the regulatory state, and growth rate. Instead of making that tradeoff, Bitcoin businesses continue trying to grow at 100%+ YOY on four, five, or six digit risk budgets. And this works... until it doesn't.
"How do we not transfer substantially all of our assets to fraudsters?" would be an acceptable job interview question at the Medici bank in the early 15th century. It was a solved problem then.
that's true with US cash too. the problem with some of these exchanges is that they essentially have these buildings with $50M+ cash sitting inside them, but they are NOT also running bank vault level security, quality-wise, to protect that stash. some are better than others, but it makes sense that the worst of them will be run by underqualified people.
I've had the opportunity to look/study behind the scenes at a few major Bitcoin websites, early on, and... let's just say you never wanted to learn how the sausage in the sausage factory gets made. "This PHP kinda works on my box... Let's ship!"
Of course, understanding the difference between an exchange and a bank is worthwhile - but these guys getting rinsed repeatedly and taking out user wallets is a problem that can't be waved away.
http://finance.yahoo.com/news/hackers-steal--100-million-fro...
So, people should trust or build on existing system if they care about their stuff disappearing or being stolen. There's mitigations that work for that situation for the common case. Unlike Bitcoin and its exchanges.
> Running Bitcoin exchange probably requires $10 million a year in engineering and compliance costs
Well, that looks like it's much cheaper to just wing it and take the damages. So that's what the free market will do.
By forcing Bitcoin into a central clearing house model like most of these exchanges are doing you arguably have the worst security properties of both models.
[0] https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_sh...
Yes, that's a scary precedent.
1) in actual fact, very few votes were cast for ETH. Although many people ran the clients that supported a fork, most of them simply did so because it was the only option for their chosen client - there was no non-fork client option easily available to them. Very few people explicitly chose the clients to support the fork.
2) "Will of the people" defeats the point of ETHs smart contracts. If everyone in the pool decided to buy in on a bet of a digital coin toss, and the bet ends up 51% heads and 49% tails, is it ok for the heads bettors to simply consensus the bet out of the chain and reclaim their money in the event that tails wins?
Despite this fundamental truth, blockchains are extremely useful.
The future is all about multiple versions of reality maintained simultaneously. There's no reason there has to be a single monetary system with agreement. Small groups of people with different values can have a totally different view of who has how much money.
You're right it's confusing, that's why this hasn't started happening until the software age. Now that we have software, we don't have to understand the books, we just have to be able to write software that can make sense of them.
There will always be a "main Ethereum" for people who need a single-source-of-truth and don't want to deal with multiple realities. But the point of anarchist software is that everyone doesn't have to agree. Everyone can just do their own thing, and elect to share realities when they want to.
This idea that there is one Bitcoin Network and one Ethereum Network is the biggest misconception people have about federated technologies. People imagine consensus means "one truth". But consensus means many truths, each which only have consensus within themselves. There's always been many Bitcoins. We just ignore most of them, by choice. We're so used to someone forcing us at gunpoint to agree to a single universal legal reality that we have a hard time imagining a world where there are lots of different sets of conflicting rules, and individuals choose which ones to pay attention to.
So if you're playing along at home: the consensus Bitcoin chain is the longest one consistent with the rules of Bitcoin Core, the lineal descendant of the Satoshi client.
This consensus chain currently includes 1+ transactions T, which effected this theft.
The proposal is for a large number of miners to abandon the consensus chain and start mining a new chain at one transaction prior to T, replaying all real transactions minus T plus a new transaction which would moot T.
With enough hashpower, this chain eventually surpasses the current longest chain and at that point all points on network, not just mining cartel, will agree that T never happened.
This is supposed to be impossible because it is incentivize-incompatible, as the mining cartel would lose an incredible amount of segniorage to make it happen and it wouldn't be a sure thing. Point #2 is mooted by mining centralization, a ship which has sailed. Point #1 could get mooted by a payment outside the standard understanding of the Bitcoin protocol.
Comedy gold!
It might be one of the first cases of bribery where the briber doesn't have to talk to the bribee to discuss the object of the conspiracy, the price, or how the bribe would be delivered.
Comedy. Gold!
(Of course, this would likely drive the value of 1 BTC to exactly $0)
(Edit: This is all a demonstration of how the security of the blockchain absolutely depends on mining hashpower being widely decentralized and distributed)
Kinda reminds me of Eliezer's concept of acausal blackmail
> This is supposed to be impossible because it is incentivize-incompatible
Enter the wonderful world of coco values and side payments in game theory. Incentive compatibility and strategyproofness arguments break down when parties are compensated (implicitly or explicitly) out-of-band. That's not always a bad thing - it can lead to more efficient, utility maximizing equilibria. That said, under the status quo, we're trading one flavor of centralization (monetary policy) for another (core committers and mining pools).
Very different from the ethereum situation. Miners won't go for it though. Would cost them too much from confidence loss.
It has never happened. This time will not be different.
Interesting history: Luke-jr (core dev) blacklisted some addresses in a package install of bitcoin he maintained, but this sort of censorship was never in the mainline source.
Source: joined Bitcoin community in early 2011, been enjoying bottomless popcorn ever since :-)
I'm sure it's talked about, but I've never really found a straightforward explanation of how it should be done - is there even an agreed upon set of best practices? If so, why are these supposedly sophisticated exchanges not able to successfully apply them?
2. Have a warm wallet on a computer with a firewall that only connects to 3, with 1% of your funds
3. Have a web-facing server that sends back commands to 2 when it needs to send money.
2 alerts someone when it needs more money, who then goes to the cold wallet and transfers some, creating the transaction offline and using a new USB key to transfer it to a computer with internet.
The last step can also require multiple people if desired.
If I wanted to make a trustworthy rate limit, I'd have the machine from (1) not airgapped, but connected by a serial (unidirectional) line to the machine from (2) along which it would periodically send signed transactions sending some of the money from "lukewarm" storage to hot storage, and sending change back to the very same "lukewarm" storage address. The machine from (1) can then implement a rate limit.
Edit: actually nvm, didn't get the part about unidirectional. I don't deal with networking but I assume that's possible physically and there's no way to reverse the flow?
Sometimes known as a Data Diode.
What good is that proof of control? Literally the next second it could be drained and no one would know until the next scheduled proof of control. I've never been sure what publishing proof of control is meant to protect against exactly.
There are more sophisticated schemes that allow you to check the amount in your account, and verify that your account was included in the total, without seeing the size of other accounts: https://iwilcox.me.uk/2014/proving-bitcoin-reserves .
[0] https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
Ikeboy(sibling comment)'s explanation is as good as you'll get, in my opinion. And you can even skip steps 2 and 3, as we have done for two years on BitMEX.
It's our opinion that customer funds are simply too important to expose to this kind of risk, so we process withdrawals only once a day from airgapped multisig wallets. It's a bear, and it's slow - we developed a few internal tools to make the review process easier and separate signal from noise - but aside from some manual work we've never had a problem.
The #1 surprise, to me, was that customers don't mind the inconvenience. Sure, a few wonder why they can't simply get their funds immediately. But it's explained to them, they seem to appreciate the sensibility of managing this risk seriously. Compared to alternatives like ACH, at least it only takes one day and runs on weekends.
I can't imagine a nightmare worse than losing millions of dollars of other people's money. I hope for Bitfinex's sake that they are able to recover a portion and continue operating. We've spoken personally with much of the team and enjoy the relationship. They - and their customers - don't deserve this loss.
Waiting a day for a transfer now seems hilariously outdated now to me.
I understand there are other benefits to bitcoin but something seems inherently wrong if transfers have to be intentionally delayed so long to make the system more secure.
My understanding is that the inconvenience of ACH is by design - they are security delays. If you need to send money from one account to another instantly, you use a wire. If you have the amount of money in your account that is typical of people that need to send wires, they are often freely included with your higher-end checking account. Wires send the money instantly.
I commonly see wires hit within ~30 seconds of hitting the "confirm" button, and almost always within <=5 minutes, and that's between separate US banks.
Here is a report which uses the guideline to assess a company's posture after a hack: https://www.scribd.com/doc/309591980/ShapeShift-Postmortem (sorry about the scribd link, haven't been able to find pdf.)
Here is a narrative description of the hack that the above report is about: http://moneyandstate.com/looting-of-the-fox/
Why bother? It's much more profitable to pretend to secure the wallet, and then take the money and run.
Though in this case it looks like it was a hack on a third party provider, which is why relying on third parties for core functions is not a good idea. Why would Bitfinex use that provider instead of a multi-sig cold storage is anybody's idea.
Are the destination wallet addresses for the heist visible in any block chain explorers? Would it even be possible to mix those coins or will they be impossible to spend as tainted?
you can't send the tainted coins to an exchange or a bank, because they risk getting seized and your identity compromised
you can give someone the private key on a flash drive for goods, services, or an army.
you can move varying amounts to different addresses each for a different flash drive, to exchange for goods, services, or an army.
physical transfers wouldn't show up on the blockchain.
you can also mix them over time for whatever amount you need. $50,000 a day wouldn't be impractical.
and you can also build up your own bitcoin infrastructure yourself, start another bitcoin casino and all the players get paid out in your otherwise tainted coins
do an ICO for a new project and fund it with all your tainted coins, and others. most crowdsales - like Ethereum's - have one or two large investors amongst the little amounts everyone else contributes.
honestly all the transparency perks of the blockchain is just to rosy it up to regulators. but it undermines any and every capital control in existence.
(no sarcasm here, I totally agree that's what the ecosystem is like.)
> you can give someone the private key on a flash drive for goods, services, or an army.
But for this part, what if the one who gives out the private key moves the coins later? That's not a finalized transaction at all if both side have the private key.
Conceptually It can be alleviated with having the coins in multisig address where a third party creates one of the signing keys and the original thief retained one, and ideally the second recipient also had a third signing key. Still have the problem of getting the third signing key generated in a way that required no trust, in advance
https://www.reddit.com/r/Bitcoin/comments/3igv0r/bitfinex_pr...
> "There is a good story here, waiting to be written by some investigative journalist. Perhaps we will have to wait for some catastrophe before that happens."
http://www.cnbc.com/2016/06/06/ny-fed-first-rejected-cyberhe...
1 - A monetary system without any regulation accessible online (i.e. Bitcoin) needs perfect security.
2 - There is no such thing as "perfect security".
Therefore: A monetary system without any regulation accessible online (i.e. Bitcoin) is deemed to fail.
Seriously, there is a curious coincidence with the BTC-driven pump and dump currently going on at the Etherium's dead chain.
Another curious coincidence is that the price started falling before the closure, as if someone did some insider trading.
Seems like it is good advice not to invest more in Bitcoin than you can comfortably lose...
Not losing bitcoin isn't any harder than not losing cash.
Problem here is people storing their coins with unqualified third parties.
And anyway, robbing safes is easy. But try emptying a bitcoin wallet encrypted with a good password, it's very easy to make impossible.
There's the problem with adoption. "SFYL you should have been smarter" means there will always be a % of the population who should never use it.
If you're talking physical cash, a person would have to get to the physical location to take it (as opposed to being available to everyone in the world with an internet connection).
If you're talking digital cash in a bank, most banks have a form of insurance that will cover your losses (for example, most US banks are FDIC insured and cover up to $250,000 USD in losses).
Stock assets may be the closest comparison, as brokerage firms aren't backed by an independent agency, and losses that occur from cyber-theft would only be reimbursed if the firm wanted to.
But it does not protect you from hacking of your individual account. If someone tricks your broker/custodian into selling your stocks and wiring them the money, SIPC (perhaps surprisingly) will not save you.
See: http://www.reuters.com/article/us-investing-hackedaccounts-i...
Obviously you can't go with "You can trust us, we know what we're doing"
You could find a party that is endorsed by someone going "You can trust them, They know what they are doing, Trust us on this, we know what we're doing"
But that just moves the point of concern.
Is there yet any "You can trust them, if we are wrong about that we will cover your losses" insurance. (even then how can you be certain they will follow through)
Surely you wouldn't store your cash in a bitcoin exchange? It's not a bank.
With bitcoin you don't even necessarily need a third party, a hardware wallet could do just fine. That can be stored in a safety deposit box if you feel like it.
>Is there yet any "You can trust them, if we are wrong about that we will cover your losses" insurance. (even then how can you be certain they will follow through)
While you can certainly insure anything if you pay enough, I don't think there's anyone publicly offering that in the crypto space. But then there doesn't seem to exist a similar mechanism for USD accounts of any significant size either.
And a reminder that no need to store your bitcoins online.
Major retailers leak tens of thousands of credit card numbers.
Banks routinely have embarrassing security holes.
The very building blocks these systems are built on have bugs that laid dormant for years (OpenSSL, Secure Transport)
Why does anyone still believe computer security is anything but an illusion?
Leaving aside the fact that (what I call) the semi-intrinsic value of BTC is designed to increase over time, when the end is in sight either because of security snafus or actual source exhaustion, the greater fool will go elsewhere, leaving the lesser fools holding the bag.
Nobody seems to be handling BTC correctly, and nobody seems to agree on the correct way to handle it. That leads me to my own thesis: if a currency is so convoluted to handle that consensus can't be reached on proper handling of escrow funds or deposit balances, it's not a currency, it's just a long-running argument.