Bitcoin Sinks After Hackers Steal $65M from Exchange
bloomberg.com
bloomberg.com
How does someone actually steal from an exchange?
As I understand most of the funds(80-90+%) are kept in cold storage. Was the exchange not following this "best practice"? Is this not a best practice?
The way the cash equities markets work is you make a trade to buy or sell shares and they get delivered in 3 days time. Why does a bitcoin exchange need to have any bitcoins at all in a wallet accessible to any machine connected to the internet? Could they not work in a manner like this?
Why not net all trades and do settlement at the end of the day. If people want to withdraw bitcoins batch the requests up until the end of the day and then you can have a person or software review all requests before they are put into a hot wallet and sent out.
I've written my fair share of risk systems over the past 15 years. I think I understand how to manage risk, and delaying transaction settlement is considered part of risk management. You can trade as fast as you want but the actual settlement, by design, lags trading to allow for errors to be caught.
My question is why do you need any bitcoins at all in hot storage?
What's wrong with netting until the end of the day and then put the required amount of coins in a hot wallet to do settlement say 24 hours after a trade?
Wouldn't this cooling off period give software and risk managers a chance to find invalid transactions and keep funds from being stolen out of a hot wallet?
In the Bitfinex case essentially all bitcoins were in hot storage. Why they switched to that system I don't know. Perhaps they were convinced by BitGo marketing brochures that this would be more secure. Or, they were forced to do that by regulators.
In the general (not Bitfinex) case, you need hot storage in order to process withdrawals quickly. No one is going to use a cryptocurrency exchange which makes you wait 24h to withdraw, this is unacceptable in such dynamic markets.
https://www.reddit.com/r/Bitcoin/comments/4vykkr/1000_btc_gi...
https://bitcointalk.org/index.php?topic=1574127.0
He is sending the coins as we speak: https://blockchain.info/address/1BfxSuxJqXuizBbTcP238JZY9DT4...
As a contingency, to plan for his possible arrest/death/etc, he signed a NLOCKTIME transaction that would automatically destroy these 1000 BTC in a week if no action is taken.
His handle "rekcahxfb" spells "bfxhacker" in reverse. No plans yet on what he will do with the remaining 118 500 BTC.
In Bitcoin land this is both more feasible and more complex at the same time -- it's very easy for a poorly planned version of this to make the thief no harder to identify, and even a well-executed version requires vigilance in the future to avoid betraying the identity of the thief vs. the identity of one of the giveaway recipients.
Or maybe, you are right, he is not directly attempting to launder, but just "creating noise" in the block chain to make it hard for investigators to trace the stolen coins.
[edit: okay, paulcole just beat me to the punch.]
Is there something urgent they need to spend thousands of bitcoins on right now that they can't just launder a hundred bitcoins a day through tumblers over the next few years?
My assumption is that they're selfish assholes who want to successfully launder stolen Bitcoins. Holding on to Bitcoins and laundering them through tumblers gradually would allow them to do that. But it seems like every time a thief steals a large amount of Bitcoin, they try to put it through a tumbler all at once or come up with some other scheme that doesn't work to launder it all at once.
> While trading was halted in all digital currencies, including ethereum, the exchange said losses were limited only to bitcoin. It also said U.S. dollar deposits were not impacted.
As someone standing on the crypto currency sidelines with a bag of popcorn, I feel like this movie has gone from cyber punk drama to a played out comedy where you already know all the jokes and punchlines.
Every time a company attempts any form of "hot" storage for Bitcoin this seems to happen. At this point, I'm convinced it's only a matter of "when" not "if" for anybody else doing it. People keep trying to find an intersection between security and convenience but the lines are parallel!
If you generated weak keys then it's not theft for me to guess/calculate them and allocate those coins to myself.
This is why BTC is described as proving the strength of hash functions, etc. If it was easy to cheat, someone would claim the public bug bounty by giving themselves all the coins. Because they haven't, we have a fairly good minimum bound on the difficulty.
But giving yourself all the coins means demonstrates that the system doesn't work conclusively, and guarantees that no one will accept the coins for goods and services, so while giving yourself "all the coins" destroys a lot of value, it doesn't actually capture any value. So, if you wanted to profit from an exploit you developed, you would not do that (if you wanted to discredit bitcoin and had developed the exploit, you would do that.)
Pre Hack: $600 Low Point Post Hack: $465 Currently: $560
The price has actually been dropping consistently since the 31st of July.
Granted, this hack has caused a the drop to be bigger, but attributing the entire drop to it makes no sense. The timeline doesn't fit.
The most likely reason the price has been dropping is because the Bitcoin miners have ran out of reasons and deadlines to stop the bitcoin hardfork which will cause an increase in block size, which is the main reason why Bitcoin is artificially blocked from accepting more customers and grow.
Investors likely don't think its worth holding onto a currency if it has (and reached) an artificial ceiling.
I'm an investor and I think it's worth holding onto a currency if I see it as a good store of value, it doesn't matter if not everyone on earth is using it (eg: does everyone use gold? Could everyone use gold? No. Still a good store of value). So please don't speak on my behalf.
There's no such thing as a bitcoin customer. And by growth, the only obstacle is number of transactions/block which is limited by design.
But there's no tps limit that we wouldn't blow through in a day if it were free. Building a distributed DB? Nah, just dump it all in the blockchain and make the world hold it for you. Without a limit, and the prices that come from approaching that limit, the system would never reach a balance.
The goal is that transaction costs pay miners. That only works if blocks are small enough to reasonably process and scarce enough to justify paying for.
For everything else, build a sidechain and do your micropayments on it - link to BTC every now and then for larger fund transfers.
For individuals who lose Bitcoin because of exchanges getting hacked, it's because they leave Bitcoin in the exchange. This is antithetical to how Bitcoin is intended to be used. The answer is, don't do that. Make cold storage paper wallets and keep your Bitcoin there.
Only in bitcoin land is theft considered good for the ecosystem.
Only in bitcoin land does it make sense to blame laypeople for storing their money with financial institutions.
Only in bitcoin land is it a best practice to secure your money using a password written on a piece of paper.
Only in bitcoin land is it reasonable to expect consumers to do a better job of keeping their money secure than corporations with on staff security experts.
Uh, yeah. That's the entire point of Bitcoin.
> Only in bitcoin land is it a best practice to secure your money using a password written on a piece of paper.
God no, at least not a password intended for human consumption. That's not what a cold wallet should be. It should be a key.
> Only in bitcoin land is it reasonable to expect consumers to do a better job of keeping their money secure than corporations with on staff security experts.
No, non-expert consumers should be using off-the-shelf security solutions made by a staff of security experts that they can use locally (i.e. physical Bitcoin wallets). It's just that not many people are working on that stuff, because most of the companies making Bitcoin stuff are catering to speculators trying to get rich quick.
There are a lot of really smart people working on creating centralized Bitcoin solutions, but frankly, that's just a bad idea, as evidenced by almost every centralized Bitcoin solution having been hacked at least once. A centralized system has too wide an attack surface and too high an incentive for attackers, and defeats most of the benefits of Bitcoin anyway.
Sure, it makes Bitcoin a poor choice for speculators looking to get rich quick, but I don't care in the least. They're outsiders who don't understand the tool and aren't on board with the philosophy of why Bitcoin is important.
If you don't understand decentralization and you try to be in Bitcoin, you're going to have a bad time.
The entire point of bitcoin is to avoid financial institutions? That sounds like a pretty big disadvantage compared to other forms of money that work well with financial institutions.
> That's not what a cold wallet should be. It should be a key.
A distinction without a difference as far as it relates to having all your money stolen.
> Sure, it makes Bitcoin a poor choice for speculators looking to get rich quick
It makes bitcoin a poor choice for the general population since most people fall into the category of "outsiders who don't understand the tool and aren't on board with the philosophy of why Bitcoin is important"
It is a huge disadvantage for some purposes, but there are plenty of advantages to avoiding financial institutions.
If you want to work with financial institutions, there are plenty of ways to do that already. Go get a savings account or a mutual fund; it's not complicated.
If you want to transfer money at low fees across national boundaries, or make your money harder for governments to seize, or make your money anonymous, Bitcoin can do those things better than other financial vehicles. And that's because it's not tied in with financial institutions.
> A distinction without a difference as far as it relates to having all your money stolen.
It's a huge difference. Humans are notoriously bad at creating secure passwords. A SPRNG-generated key is far more secure.
> It makes bitcoin a poor choice for the general population since most people fall into the category of "outsiders who don't understand the tool and aren't on board with the philosophy of why Bitcoin is important"
True. The same can be said of almost any investment vehicle--most people have very little understanding of most investment vehicles. I'd also say that for example futures and options are much harder to leverage well than Bitcoin. That doesn't mean they aren't useful, it means you have to know what you're doing to use them.
As Warren Buffet said, "Don't invest in things you don't understand."
I have no problem with people investing in Bitcoin purely for speculation to make money, but I'm also not going to cry if they make a bad investment because they can't be arsed to understand what they're investing in. I wouldn't invest in mining futures because I don't know how to leverage mining futures, and they shouldn't invest in decentralized currencies if they don't understand the implications of decentralization.
If you keep your money in an exchange, you're gonna have a bad time. Lots of people (myself included) were saying this before even the Mt. Gox stuff happened, so it's not like this isn't predictable.
The obvious next step is that Bitfinex will have to file for bankruptcy protection. Whether people get their cash balances / other crypto / etc. back or some proportion of the remaining assets will be up to the bankruptcy trustee. The trustee will follow the law but I don't know if they were properly registered, aka where depositers fall on the list or whether any of the assets would be considered secured.
Right now with the price falling that could be an easier proposition tomorrow or next week.