Breaking open the Mt. Gox case, part 1
blog.wizsec.jp
blog.wizsec.jp
> Some of the funds moved to BTC-e seem to have moved straight to internal storage rather than customer deposit addresses, hinting at a relationship between Vinnik and BTC-e.
and he was stupid enough to deposit them back to his account on MtGox:
> Moving coins back onto MtGox was what let us identify Vinnik, as the MtGox accounts he used could be linked to his online identity "WME" http://archive.is/6cFcY
All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme.
I wonder, if BTC-e somehow artificially pumped the bitcoin valuation leveraging the huge amount of bitcoins they put hands on, same as what MtGox did.
Also, it looks like that Mark Karpeles wasn't involved in the whole scheme, and the hack was that simple thanks to the low or no security and engineering culture at MtGox:
> In September 2011, the MtGox hot wallet private keys were stolen, in a case of a simple copied wallet.dat file.
> the shared keypool of the wallet.dat file lead to address reuse, which confused MtGox's systems into mistakenly interpreting some of the thief's spending as deposits, crediting multiple user accounts with large sums of BTC and causing MtGox's numbers to go further out of balance by about 40,000 BTC. None of these users seem to have reported their "sudden luck".
Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.
In itself, it's not an indicator of wrongdoing.
BTC-e was operating illegally for a very long time and everyone knew this.
If your dislike of KYC and AML laws led you to believe that BTC-e was on solid legal ground, then you're simply stupid.
http://www.reuters.com/article/us-greece-russia-arrest-bitco...
I don't see how this proves he had direct involvement in the scheme instead of just running a laundering service for people.
This blog post mentioned he was connected to other thefts as well:
>> The stolen MtGox coins were not the only stolen coins handled by Vinnik; coins stolen from Bitcoinica, Bitfloor and several other thefts from back in 2011 and 2012 were all laundered through the same wallets.
Not much solid evidence here of direct involvement in the hacks despite the bold claims, but it does look like there is some connection to the crime at the post-hack stage...
It's like robbing a bank, just to waltz in with their money the following week and deposit it into that same bank.
Is this type of visualization common in Bitcoin? Is it a tool anyone can easily use?
Edit, let me restate my question. "Is there a tool that generates Sankey diagrams from blockchain data that is easy to use?"
Anyone who has the blockchain downloaded can run their own analysis algorithms on it - it's already there for you to see.
https://github.com/znort987/blockparser
https://web.archive.org/web/20161027122545/http://compbio.cs...
I have to admit, that is a reasonable assumption. This may show the limits of the usefulness of heuristics, and the importance of organizations like exchanges, that have very significant fiduciary duties, to undertake a systematic process after a security breach to eliminate all possible remaining vulnerabilities, no matter how unlikely and counterintuitive.
Well now know turns out the biggest one was doing just that
"I'm not sending my living money to a sketchy exchange in Japan"
This is the exact sketchy kind of thing I imagined would be happening.
I really have to disagree. You get breached, you change your private keys. There shouldn't be a debate about that.
It costs dirt to move your coins. It's not remotely reasonable if you're in the Bitcoin world at all - if you have any reason to believe that an attacker had any access to your wallet the advice is always the same. Make a new wallet and transfer all the coins ASAP.
It's still insane to me that MtGox never moved coins to a wallet or acknowledged the breach until long after it was too late. You would think if you have billions of dollars sitting somewhere and you realize someone is starting to take them you would, you know, do something.
I had like 0.000001 BTC in mtgox and it was worth it for the cute sticky unfoldy postcard thing I got from the Japanese court.
There's no chance of that, right? (Hence ":)")
At the time of the MtGox implosion I was bummed to have lost a few hundred $ worth of BTC. Now I'd be very interested in recovering that balance ... in BTC.
How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect?
If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, and then "shuts down everything" if they're detected.
It's a fun piece of trivia one crypto currency guy told me and it seems to be true.
ಠ_ಠ
https://web.archive.org/web/20100701145902/http://blog.magic...
The MtGox pivot from trading cards to Bitcoin was pretty dramatic.
So either McCaleb built a brand new exchange from the ground up in one week, or he reused code from his Magic card trading service.
McCaleb sold the site to Karpeles 8 months later, and 3 months after that, it was breached for the first time. Allegedly, the hacker used McCaleb's old admin credentials to arbitrarily assign himself any amount of bitcoin, which he then started selling off to crash the price. Since the price crashed to $0.01, the dollar value of the withdrawal limit represented several thousand bitcoin, which the attacker promptly sent off-site.
No matter if the site was reused code from a Magic card exchange, or was written from the ground up, it never should have been within a thousand miles of anything of value.
Or he spent some time writing the new service while the previous one was still running.
The analogy would be scanning the block chain looking for tree firm's account numbers to verify all transactions are accounted for.
I don't know for the life of me why basic stuff like this isn't implemented. The crypto currency world is like a big joke.
There were one or two exchanges that did things "right" (e.g. TradeHill) and were immediately driven out of business by their own high costs.
It's pretty straightforward to compute the sum of all coins in your wallets, I would assume. It's also straightforward to compute the sum of all account deposits tracked by your database. Just knowing those two numbers is really simple stuff, like a single SQL query on the DB. All they need to do is calculate those numbers and report on it daily or weekly and they'd have detected the fraud the very first time coins were taken.
(Not physical cards traded online, mind you, these were virtual cards in the game Magic: The Gathering Online.)
They were simultaneously bit by an attack exploiting a fault in their wallet implementation in combination with transaction malleability. You can invert all the bits in a transaction id and if you also take the complement of the signature then the signature is still valid. The transaction still happens but you never see the transaction ID come over the network (it's actually the complement of the txid). After a while, most clients concluded that it wasn't broadcast successfully and either aborted or retry, so their wallet balance diverged. And yes they probably did not check it against the official client balance.
A significant number of frontend nodes participated in this transaction malleability attack over a sustained period of time, probably more than a lone-wolf attacker could access (although renting botnets isn't all that expensive, especially if you are sucking out bitcoin at the same time...)
The interesting question is whether they had someone on the inside, although it could also be explained by incompetence and an attacker probing for weaknesses who comes to realize that the bug wasn't being patched.
> It's pretty straightforward to compute the sum of all coins in your wallets, I would assume.
You assume incorrectly. It's a cold wallet. It's not connected to anything; that is its purpose. To monitor the balance, one would have to write software to watch the blockchain and calculate the balance of specific addresses. This is by no means impossible but in 2011 there were very very few engineers on Earth competent to do it and Mt Gox was trading bitcoins for pennies. Don't underestimate how fast Bitcoin went from a strange curious technology to being worth significant money.
Ultimately you are judging their actions through the lens of hindsight. Best practices weren't even established yet.
630,000 BTC to USD = 1,560,069,000.00 US Dollars
Crazy.
$1.5 billion USD = 2.5% of Bitcoin's market cap ($40 billion) and someone stole it.
The life expectancy of a user is 1-2 years as their tissue starts to die.
I think it's an apt comparison of the 'potence' of these two things. People who take coke don't rot alive and die within a few years. Similarly penny stocks are (relatively) harmless, never used to buy illegal stuff and people who do them don't go around saying that penny stocks will replace all finances and currencies and cause a revolution against the corrupt banker filled governments and accuse everyone of being governmental propagandists (yada, yada..), many of Bitcoin proponents on the other hand...
At the same time, in some weird massive cognitive dissonance, anytime one of these evil governments they hate so much decides to legitimize bitcoin in some way by recognizing it as some financial instrument or when USD/BTC rises (and let's remember - dollars are a fiat currency a.k.a. useless pieces of paper that bankers print and force people to use) they are giddy as hell.
I even seen comments saying that Satoshi becoming instant billionaire (richest in the world by far, in pure currency, not 'net worth' that's hard to liquidate and spend) if bitcoin really became global currency is deserved for his contribution to humanity. Can you imagine someone saying Dennis Ritchie should own 5% to 10% for his contributions to Unix, C, etc. (that largely went unrewarded and he died the same time Jesus of electronics Steve Jobs did so no one even cared). Or RMS for the FSF? I just can't imagine how much you have to like a thing (FOSS, Unix, C, Bitcoin, ..) to say its creator should be rewarded that heavily and become the richest person in Earth's history.
http://wizsec.jp/images/theft_flow.svg
I like graphs like this. They remind me of Charles Joseph Minard's famous Napoleon graph:
https://en.wikipedia.org/wiki/Charles_Joseph_Minard#/media/F...