It was impossible to know the details of this exact bug - but it was possible to know that something was wrong at MtGox before the takedown.
Of the two-dozen or so people I know who held Bitcoin at the time only one lost funds on MtGox - the rest had long left Gox or were never comfortable using it.
The main administrative issues were withdrawal delays[0], MtGox not being able to prove their reserves satisfactorily[1] and having accounts seized[2]. ID verification was slow, and support was almost non-existent.
If you read the forums in the ~12-18 months before MtGox went down there was a lot of conversation about what was wrong at MtGox.
The tech issues were horrible code[3] (read the description of that repo and tell me if you would trust it with bitcoin), previous hacks[4], many more hack claims and the internal trading bot being traced by outside researchers.
I don't blame anybody for not seeing these issues - there was a lot of FUD at the time and many who saw attacks on MtGox as attacks on Bitcoin. Nobody really wrote a good and concise "this is why you shouldn't use MtGox" post anywhere. Hearing after it was taken down that someone knew it was bad is useless and only self-serving.
I don't think it is possible for a third party to hold your bitcoins for you in a secure way that is also convenient. You can pick any bitcoin company or exchange and claim its insecure and you'll eventually be right for many users.
One of the only ways to avoid the problems and store your bitcoins safely but also still be able to use them is with a hardware wallet. There has been a lot of improvement since MtGox with "vault" products, better multisig implementations, better auth, and offline signing etc. but still some way to go.
[0] https://bitcointalk.org/index.php?topic=179586.0
[1] https://bitcointalk.org/index.php?topic=209362.0
[2] https://techcrunch.com/2013/08/23/feds-seize-another-2-1-mil...
[3] https://github.com/MagicalTux/btclib
[4] http://www.dailytech.com/Inside+the+MegaHack+of+Bitcoin+the+...
I'm shocked, absolutely shocked that the Magic The Gathering Online Exchange wasn't suitable dealing with hundreds of millions of dollars.
The signs were obvious that it was being run by amateurs for anyone that spend five minutes doing a google search.
When I heard a friend had deposited more money than he could afford to lose on MtGox, I immediately jumped in the car and drove 2 hours to his house. I convinced him, basically at the point of physical violence to take his BTC out of MtGox and store them in a wallet on his computer, encrypted and backed up on several cloud sites.
One month later MtGox was hacked. I received an apology and a very nice bottle of whiskey from my friend.
I've been threatened by inlaws for subscribing to practices that will end in my damnation -- something much more significant than losing savings. They genuinely believe this. And I still don't think that's right, and it wouldn't be right if everything they said turned out to be true.
I may revise my opinion if I start seeing cryptocoin exchanges founded by people whose LinkedIn profiles include job titles like "VP for Regulatory Affairs" or "Head of Risk and Compliance". Right now, I'm mainly seeing CS grads and people who spent a couple of years on a trading desk.
We know it can be done, and we k ow that none of the exchanges do it anymore.
As hopeful as I am, I know that scaling number of users is much more important for exchanges than advancing security through cryptography that users can verify.
Early in our history, we thought once-a-day withdrawal would be a problem customers would be quite vocal about. Instead, we found many of them appreciate what it means - that the keys aren't hooked up to a hackable webserver, but are actually protected. Accessing funds should be difficult and should require human interaction.
https://support.coinbase.com/customer/portal/articles/166237...
This counts for a lot IMO. Of course there are still questions of whether and how the insurance comes through. But it's a big step to make such a declaration, and the implications on security are significant.
When trading on their platform you always trade directly with one other customer. The funds are transfered directly from your Fidor bank account.
Of course, the BTC/BCH will still be on the marketplace until you remove them.
Common wisdom these days is: The only safe place for crypto coins are paper wallets (and, arguably, hardware wallets).
A bitcoin exchange really isn't all that different from a metals exchange, if you substitute "physical delivery of gold" for "emit an actual on chain bitcoin transaction".
If cryptocoin startups can't recruit the right talent, then I think that's a strong indicator of their fundamental business value.
May 2, 2013: CoinLab sues MtGox, says MtGox promised to let CoinLab operate its North American branch. This makes no sense -- why would MtGox surrender its most valuable territory to a virtual unknown? -- but MtGox doesn't explain what's going on and simply shrugs their shoulders. They will be doing this a lot.
May 15, 2013: US Government seizes $5 million from a bank account held by MtGox. MtGox shrugs their shoulders.
June 20, 2013: MtGox stops USD withdrawals; bitcoin and JPY withdrawals continue to operate normally. People ask when they'll be restored, MtGox shrugs their shoulders.
July 4, 2013: MtGox says USD withdrawals are back to normal. This is a lie. When people ask why USD withdrawals are still not going through, MtGox.. well, you guessed it. They shrug their shoulders and just repeat the lie.
By this point, alarm bells should have been blaring in people's heads. Anyone who claims that this kind of crap was the norm for the bitcoin world should keep in mind that Coinbase had launched in 2012 and was running a much tighter ship.
By this point, people still had more than 6 months to get their bitcoins out.
August ~13th, 2013: CEO blames issues on Mizuho bank; claims that Mt. Gox was greater than 50% of Mizuho's SWIFT volume (!) and DOSed their banking systems multiple times (!!); also says that Mizuho has limited them to ~10 outgoing wires per day.
https://bitcointalk.org/index.php?topic=179586.msg2924021#ms...
When Tux's #2 told me he couldn't do it because Mark was asleep (time zones! etc), it became pretty clear they didn't have a clue about what they were doing.
Some people have tried telling me in the past that I'm full of shit for pointing out the delays and what they meant. I moved my coin away about a month or so before the big hack.
Stay sharp, friend.
The presence of a persistent arb premium was what made me back off Gox. As a quant trading guy it just seemed too fishy that a one-way arb could persist. I wrote an arb engine to take advantage of the price difference but I concluded there was too much credit risk in it. Which turned out to be correct. At best the arb was explicable as slow operations getting money out of the bank, but that would in the very best case be total incompetence. Plus the forums were saying a lot of not nice things about the management, so definitely failed the sniff test. Remember it's not the balance of probabilities that matters; it's the worst case.
Coinbase, by contrast, has VC backing that you would think means they'd find someone who understood regulatory issues. They'd also have links to proper tech people who understood security and exchange coding, a pretty small subset of coders since it's quite specialised. They may not have started with everything required but chances are they've found the money to buy it by now.
A few months before the big collapse, I lucked into some money and started looking at arbitrage opportunities on bitcoin exchanges.
Want to know what stopped me? The cost benefit vs. risk ratio. Here's an exchange with a really dodgy past, and the price is just shooting up, and people are shouting, and damn this seems too good to be true!
(edit: I did some trial runs, and had gone through their painful verification process - the above decision came about when I was starting with the "big boy" sums of money)
Funnily enough, I have the exact same thoughts about the crypto ecosystem right now.
I think it's probably unwise to hold coins right now, and whether the scam unfolds this year or not, I'm experiencing that very same spidey-sense this seems to good to be true worry from the Mt. Gox days.
Especially for ICOs and Eth more generally, but also for Bitcoin, Litecoin, Dash, etc.
We use our financial system to combat international crime. Why on earth would governments allow unregulated blockchains and currency transfers to circumvent their controls?
> Because MtGox is a money black hole, absorbing all your money and refuse to pay back. The only way to exit is to buy bitcoins there and sent them elsewhere, this explains the consistent buying pressure there. An arbitrage is meaningless if your money cannot leave, right?
https://bitcointalk.org/index.php?topic=273410.0
People including me saw the signs and exited.
https://twitter.com/patio11/status/370728763790594048
Note the date. I only posted that after I was sure I could beat the libel suit; was pretty sure much earlier.
Here's me telling someone not to build a BitCoin trading platform on September 11th, 2011: https://news.ycombinator.com/item?id=2974770
Here's how that went over the next couple of years: https://en.bitcoin.it/wiki/Bitcoinica https://www.dailydot.com/business/bitcoin-exchange-bitcoinic...
In a way, the issue here is that if you want to operate in this space, you do need to take the discussion about BitCoin being money seriously. (Even if you don't think it's "money", it's still definitely a money-like asset.)
I remember how amateurish Coinbase was in the early days, and you can look up a lot of the controversy on HN. People have been coming out saying they haven't processed $5k deposits, that they haven't responded to support claims in months, and on and on. If you're looking for "This exchange is run by amateurs," look no further than Coinbase.
Yet it's not that simple. Coinbase has somehow managed to become the #1 exchange to go to if you're a US citizen that needs an easy way to convert BTC into USD. So I just don't get this line that if an exchange is run by amateurs, it's a sign of insolvency. We have evidence that demonstrates that's not true.
I don't have any particular knowledge or experience with CB or BTC in general. Just pointing out that it's possible success was despite great risk, and the advice to avoid may have been entirely correct given the evidence at the time.
If you bought the line that traditional banks were simply unable to process more than 10 wires a day, rather than it being that Mt Gox was so risky that they refused to process 10 wires a day, then you need to work on critical thinking. Likewise, exhortations that banks were placing restrictions on exchanges because "they were scared of Bitcoin" rather than being because these partners were shady and didn't have sufficient controls should have been met with suspicion.
And yes, Coinbase was also risky. The fact that things worked out doesn't mean it wasn't risky to begin with. I didn't give them any money for the first several years they were in business specifically because I saw them as high risk. In hindsight, Coinbase had the benefit of having backing by VCs with real business experience and subsequently hiring people with experience in the space, which reduced risk.
Having said that bankers would be part of the inexperienced group.
Real banks are also not trusted blindly; they get audited a lot by central banks and other regulators. And they still mess up and get flamed to hell for it. The chance that amateurs in a completely unregulated field do it better is very unlikely.
> It was not impossible to tell this was going on.
How do you tell, though? The comment you replied to was about the lack of signs, so claiming that signs existed doesn't really help anyone.
Mt. Gox said lots of things, including some things which were, ahem, very effing improbable and yet which alleged very specific facts about people outside of the building. "We're totes solvent; all of our assets are on deposit at Mizuho", "All of our problems are due to banking partners", "The Financial Services Agency said we're compliant with all their regulations", "Japanese banks can't send more than 10 wire transfers per day; it's physically impossible because they're technologically backward", etc etc.
This is sort of similar to "But how do you know that their application is vulnerable, $SECURITY_RESEARCHER?" The answer "I bothered to look" might be unsatisfying, but it is not inaccurate.
Writing on-dead-tree letters is a flowery way of describing what you did, but it gives no actionable signal.
I cannot agree that you had insufficient notice from me regarding my opinions of Bitcoin or operations in the Bitcoin economy. That tweet went as close to the line as I could without risking arrest, contemporaneously. It was preceded by probably a few hundred comments on HN and Twitter about Bitcoin and businesses in the ecosystem.
I appreciate that you want a list of steps you can take in the future. I have described a way to reproduce the unpaid, unpublished original research project which I did, in sufficient detail for any competent researcher to reproduce it.
You think that that series of steps is not actionable. I respectfully submit that you are not capable of reproducing it; these are two different things. You are illiterate in the language that the research was conducted in. I'm sorry; that is true, and it is the nicest possible way to phrase it unambiguously.
You should, in the future, not make investments which you are incompetent to evaluate the risk factors of. If you must, you should secure the advice of competent professional advisors. If you believed yourself competent to evaluate the risks of doing business with Mt. Gox or believed the quality of the advice you had to be adequate, you should be skeptical of your self-assessments of your competence or your ability to evaluate competence in a professional advisor, and apply this skepticism to your reasoning process about future investments.
Patrick, I respect your writing. But your answers are rarely straightforward. Even now, when you risk nothing, you refuse to reveal precisely what you knew and how you came to know it. I'm skeptical that you knew anything of consequence, and I think this is a way for you to appear prescient. But if you say you discovered something, we have no choice but to believe you on reputation alone. I wish you'd share with us what the Great Sages know, but who can blame you for wanting to stay a member of their ranks? It's only through secrecy and obfuscation that you can maintain the aura.
> you refuse to reveal what precisely
> you knew and how you came to know it
I see, in his previous comment: > Mt. Gox said lots of things, including
> some things which were, ahem, very effing
> improbable and yet which alleged very
> specific facts about people outside of the
> building
and then a list of those facts that could be fact-checked.The simplest answer is "nothing," but we're meant to believe otherwise.
We could go through each item on that list and try to reverse engineer which entity he wrote and what he asked, but this indicates he isn't being straight with us. That's fine; it's his right. But it's a little odd. If someone performed some badass investigative journalism that could've blown the whistle on the Gox case long before anyone knew about it, who wouldn't want to brag about it after the fact? Especially when it'd be so easy to illustrate the steps taken.
We're talking basic questions like "What did you write?" and "What did they say?" But we're meant to guess.
If a big-name bank operated a bitcoin exchange that was repeatedly hacked, came up with a mountain of excuses about why people can't withdraw, made nonsensical claims about doing business (e.g. 10 wires/day, not trading in the USA etc.), no-one would use them.
(edit: in The Real World, I imagine they'd have been shut down in seconds flat thanks to regulations, but for the sake of convenience let's pretend regulations don't exist)
Instead, we had a plucky new underdog that people wanted to believe was creating history.
Bitstamp, Bitfinex, Cryptsy, more I've forgotten, were the competitors really more reliable?
I've been in a position to see some absolutely insane stuff happen on exchanges [most of it gets quietly buried), and I really don't think MtGox was anything remarkably different.
what if the answer you're looking for is, "he called up someone at mizuho, went and got a beer, and the guy let it slip that that gox is broke."
then what? hmm? haha what are you going to do about that? that's how the vast majority of insider information (note i didn't say insider trading) is passed. are you going to replicate that the next time around on a specific asset that's about to crash, or a specific company that's going to go insolvent? good luck, friend. this is how the world works; you clearly were not in on it, none of us were, that's why a bunch of people were left holding their dicks in one hand and an empty wallet in the other (i don't deal in bitcoin because i'm too dumb to comprehend it, but i saw the carnage online).
at the end of the day he believed something differently than most. it's not any more complicated than that. that's how people generally make a bunch of money, or in this case, prevent from losing a bunch of money.
also, he lived or lives in japan and speaks japanese, so that's probably going to be the major hurdle for you to grasp his process - he has a lot more day to day context of how all this stuff works in that country. unless of course, you live there too, in which case, that's even worse for you. sorry pal.
Then... That's the answer. Obviously. The point is, he's given no answer yet made grandiose claims.
I suppose it's lucky he doesn't feel like telling tall tales. He could cook up something convincing.
People who say that are people who don't understand fiat money's ONLY purpose is to track who owes what. It's debt-based. If Alice pays 1 unit of currency to Bob is because Bob gave her a product or service worth 1 unit of currency. Bitcoin is great at tracking "debt": universal, electronic, decentralized, robust, inflation-proof.
I don't understand how someone can hold the opinion that Bitcoin has no value. At the very least, it enables a lot of crime, which is valuable to criminals.
The problem is that most of us can't wait until time -> infinity.
Really, memories of the alleged $20,000 per week consulting gigs which were miraculously abandoned surface again.
Edit: just saw that other comments say the same thing with more detailed informations, at least it add a data point that even an amateur saw it
I moved my coin from Mt.Gox about a month before the last major hack because just the thought of using it made the hairs on the back of my neck stand up. Something was amiss and I felt it.
The most glaring issue was that of inexplicable server load. When you are dealing with a service that handles money or valuable assets, things like this are very bad omens and should never be brushed off. It was clear that either A) the website was experiencing unusual traffic (in this case, I believe what came out was that the one of the attackers were testing their method.. supposedly this same method was used in the Silk Road hack) or B) the staff was not equipped to properly and securely run a server and were an attack to take place, they would not be ready to handle it. One bad security practice with such a critical service is indicative of generally bad security practices and lack of accountability.
You have to pay attention to your gut. If something feels amiss, and the service is critical, you have to assume that something is indeed amiss.
It'd be akin to buying up a bond fund vs. keeping a stack of treasury notes in your house. Only here the broker or whatever who is running the bond fund has only been up and running for <10 years, has basically no SEC oversight, and when your funds don't show up in the right amount of time your official method of recompense is "yea just wait awhile longer, we're going through a massive growth phase and are having difficulty dealing with the scale". Oh and in this hypothetical world, this is also the #1 broker in the world who handles >50% of all trades.
http://www.nytimes.com/2013/07/21/business/a-shuffle-of-alum...
> The story of how this works begins in 27 industrial warehouses in the Detroit area where a Goldman subsidiary stores customers’ aluminum. Each day, a fleet of trucks shuffles 1,500-pound bars of the metal among the warehouses. Two or three times a day, sometimes more, the drivers make the same circuits. They load in one warehouse. They unload in another. And then they do it again.
https://cointelegraph.com/news/mt-gox-trial-update-karpeles-...
https://cointelegraph.com/news/new-wizsec-report-points-to-d...
If Mt. Gox successfully manipulated the price of Bitcoin using bots how do we know other exchanges aren't doing the exact same thing right now?
https://www.bitstamp.net/article/Bitstamp-BTC-Proof-of-Reser...