Bitfinex never ‘repaid’ their tokens, they started a ponzi scheme
medium.com
medium.com
If I remember correctly the last ramp up happened during Mt. Gox era. They were having USD withdrawal issues which resulted in BTC prices being very high on the exchange. But it din't deter them from publishing prices and making markets.
Now is the case of Bitfinex suffered from a hack like Mt. Gox and are trying to stay afloat. As per coinmarketcap, has nearly 15% of bitcoin volume which is pretty high to ensure market follows in-step to their market making. A quick search on Google turns up pages of people asking about Bitfinex withdrawals.
For people who are curious about this, there was an article yesterday about Zimbabwean Bitcoin soaring to 12k USD, which obviously hinges a lot on counterparty risks and resulting low liquidity: https://news.ycombinator.com/item?id=15627608
If you can't get USD out of Bitfinex, you'd buy BTC and withdraw, pushing the exchange rate up on Bitfinex. Then you'd sell the BTC on another exchange, pushing the exchange rate down there.
We're not seeing that: https://imgur.com/a/2vxV7
For a while earlier this year, it was
MTGox abused the latency of withdraws in an attempt to attract BTC desposits (after their original deposits were stolen) on their exchange and presumably sell those back for cash via other outlets to slowly pay off customers and appear solvent.
MTGox also manipulated the market with trader bots.
https://willyreport.wordpress.com/2014/05/25/the-willy-repor...
https://www.theguardian.com/technology/2014/may/29/bitcoin-b...
Not if the counterparty risk causes you to be unable to withdraw national currency, thus forcing you to buy bitcoins for national currency and then withdraw the bitcoins.
The only way for the price to go down, in a scenario like this, is if it's possible to sell bitcoins on the exchange (thus pushing down the price) and withdraw the proceeds.
In a BTCUSD market, if you are unable to withdraw BTC you will sell BTC for USD and withdraw USD, thus pushing down the price. And if you're unable to withdraw USD you will buy BTC for USD and withdraw BTC, thus pushing up the price.
Me - Cryptocurrency markets are not mature that is why we have lot of arbitrage opportunity between exchanges.
You - Why do you think they're mature and perfect enough to worry about arbitrage opportunities?
So, let me repeat again - It is exactly because they are not mature there are issues. If they are mature, there is nothing to worry. And that is the sauce you are looking for.
Add to the fact that, increased risks means people want more out of their BTC. So, if x is a fair price in other exchange, they want x + y% for the same BTC on exchange with issues.
Some of these people become aware of withdrawal issues later or buy some other crypto currency, move to another exchange to cash out.
They were hacked few years ago.
It was never difficult to hold bitcoins. All you had to do was send them to an address you control with a long passphrase.
You invoke side channels -- what about these side channels: https://jochen-hoenicke.de/trezor-power-analysis/
If you insist that one should err on the side of being paranoid when handling money, you can argue that hardware wallets are secure iff you manufacture your own hardware.
Want true security without going into hardware manufacturing?
Pick a private key and write it down on a piece of paper (ideally you'd do it in your head) along with the corresponding public key. Then send bitcoin to an address that's controlled by the keypair you just created. If you did all the calculations in your head while wearing a tin-foil hat your bitcoin should be reasonably secure.
Your threat model almost certainly is one in which writing down a strongly-generated password is much more secure than anything else, if you take efforts to secure the written copy.
I feel like passwords are some kind of magical Wild West of crypto, where everyone has rolled their own and the "best practice" recommendations are often nonsense that ignores threat modeling and I'm just taking crazy pills for thinking we should treat it like other kinds of crypto where users only apply standard methods with verified entropy generation.
> However, this doesn’t stop Bitfinex from tripping over their shoelaces to immediately list a fork which doesn’t exist, in order to make money off of suckers.
That is not correct. Bitfinex didn't list Bitcoin Gold. They listed a future contract of Bitcoin Gold (though the naming "token" is a bit confusing). You can create a future contract about anything, like the weather or soccer.
> Prior to publishing this post I was informed that Tethers are on the rise. Today, at the time of this post there has been another 25,000,000 USDT printed.
First, a new creation of Tether doesn't result in a pump. That would be too obvious for traders to arb the effect.
Second, Tether is not used by Bitfinex heavily. Tether biggest clients are Polonix and Bittrex. And there is blockchain proof for that: https://wallet.tether.to/richlist
Orly? -> https://www.dropbox.com/sh/lylx2da2vobps8h/AAAN0q62s1X_Wl0H-...
Tether is issued by Bitfinex-related company. There is no reason for USA to stockpile US dollars if they can print it. China would be the biggest client of US dollar and first place at dollar richlist.
That's still pretty scammy.
Some of the claims he makes are disingenuous. Bitcoin Gold has nothing to do with Bitfinex, and is listed on a number of exchanges. It's definitely a pretty sketchy project, but it was a BTC fork and users tend to dislike when their exchange keeps forked tokens to themselves. EOS/IOTA are big projects with large market caps and real teams. Did some weird accounting happen after the Bitfinex hack? Maybe. Did most of the people end up getting their money back? Yes. Does it matter now? Not really. This is the largest BTC exchange (by volume) in the world. They generate tens of millions of revenue from exchange fees every month. There's no clear reason for them to engage in any weird, illegal money schemes at this point, they already have a money printing factory.
https://tether.to/wp-content/uploads/2017/09/Final-Tether-Co...
This engagement does not contemplate tests of accounting records or the performance of other procedures performed in an audit or attest engagement.
In addition, our services do not include a determination of compliance with laws and regulations in any jurisdiction. All inquiries made throughout the consulting process have been directed toward, and the data obtained from, the Client and personnel responsible for maintaining such information.
In other words, that document is not an audit. Just like previous "audits" published by Bitfinex connected companies, it’s an internal management report created for the management by an accounting firm. Such reports assume that everything they’re told by management is true: why would management lie to themselves? What would be the point?
If you’re an external entity on the other hand, eg a shareholder in the company say who wants an external third party to validate claims made by management, then you will only rely on a real audit made by a company that sends staff to check on those claims personally. This document is not such an audit & it’s authors are at pains to point that out.
Edit: The auditors did confirm bank balances with the holding banks, but did not perform an audit that would find any corresponding liabilities, nor that the claimed Trustee relationship between the company and the individual named on the account had any legal force. What this document shows is that people connected with the company had accounts with the claimed $Xmillion in them in total on the day in question & this was confirmed by the accountants. That’s it - it’s still not an audit.
No, they checked the balances with the banks. They verified the amount as stated was held by the bank at the time. You can see that in the section that begins "FLLP confirmed each bank account directly with the respective bank"
https://news.bitcoin.com/bitfinex-bitcoin-cash-deposits-with...
Bitfinex (unwisely) specified that during the Bcash-Bitcoin fork, lenders would get Bcash for lent-out Bitcoin. However if Alice lends 1 Bitcoin to Bob before the fork and Bob sells it to Carol then Bitfinex will owe both Alice and Carol one Bcash after the fork, but they will only have one to distribute. So they split it up.
This can get worse when Carol lends it out again, etc, etc, and in the end Zack withdraws the Bitcoin. Unbounded liability and potentially no assets. So them paying out 15% less than expected was a pretty good result.
There were also occasionally rolling rebuys of bfx tokens at the face value of $1.
As per coinmarketcap.com:
EOS is ranked 19, 442 million in marketcap
IOTA is ranked 11, 950 million in marketcap
ETP is ranked 70, 73 million in marketcap
Anyone can throw some light on what these coins really are?
Additionally, BTC markets:
https://coinmarketcap.com/currencies/bitcoin/#markets
shows Bitfinex raking in over 15% of the current market volume. I wonder what will happen to the price if they go under.
While I agree to most of the article, specially the Tethers part, Debt to Equity swap is a real thing and not a Ponzi scheme:
http://www.investopedia.com/terms/d/debtequityswap.asp
Though whether the equity shares are worth as much as Bitfinex is claiming them to be is an another question.
[1] https://iota.org/IOTA_Whitepaper.pdf
[2] https://lab.ruuvi.com/iota/
[3] https://xdk.bosch-connectivity.com/
[4] https://medium.com/@harmvandenbrink/how-elaadnl-built-a-poc-...
[5] https://www.reddit.com/r/Iota/comments/6vl57m/iota_modum_ask...
[6] https://domschiener.gitbooks.io/iota-guide/content/chapter1/...
However, at least the execution is dubious: not only was a major cryptographic vulnerability found a few months ago[0], it highlighted that
1. they made their own unproven crypto hash, which is a red flag, (in production, you should always prefer crypto that has survived many years of cryptanalysis) and
2. they were really not up-to-date on cryptanalysis techniques, as being vulnerable to differential cryptanalysis is, as Bruce Schneier puts it, "a rookie mistake".
Worse than that, they seem to rely on security through obscurity, purposefully making it hard to analyse their systems by making it base 3 (instead of the obvious base 2 that all of practical computer science relies on).
Finally, their justification for the coordinator is also a red flag[1].
[0] https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
[1] https://medium.com/@ercwl/iota-is-centralized-6289246e7b4d
Regarding crypto, you can read their response & reasoning here: https://blog.iota.org/curl-disclosure-beyond-the-headline-18...
"The replacement Kerl hash function is unmodified KECCAK-384 that only converts its input and output from/to 243 trits to 48 bytes using basic two’s complement. KECCAK-384 is well vetted and researched."
> "The replacement Kerl hash function is unmodified KECCAK-384 that only converts its input and output from/to 243 trits to 48 bytes using basic two’s complement. KECCAK-384 is well vetted and researched."
"Replacement" really does mean replacement, i.e. what they substituted in after the researchers successfully attacked their original hash function. (The new one is called "Kerl" and the old one is called "Curl", which seems confusing.)
I'm not sure how asserting that the replacement is well-researched addresses the OP's point that their history of (a) rolling their own hash function, and (b) not adequately considering differential cryptanalysis, is a red flag. True, that specific vulnerability can now be considered fixed, which might not be clear from the OP's post - but it's still evidence of incompetence, which doesn't bode well for the quality of the rest of their design.
Curl is meant to be a lightweight crypto for IOT, a field of very active research. None of this is controversial to anyone that isn't looking for things to latch negativity onto.
This seems to contradict the researcher's own post [1]:
> We discovered a vulnerability in IOTA after reviewing their code on GitHub in July. We disclosed what we found to the IOTA team on July 14th, and have been in contact with them since then as we discovered new issues and exploits.
Finally, even if Curl is meant as a new, lightweight hash function, it was broken by differential cryptanalysis, not some novel, exotic attack vector. Sounds like it needs a lot of work before it's fit for purpose.
[1] https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
https://blog.iota.org/curl-disclosure-beyond-the-headline-18...
This article also answers the wrong question. If the crytocurrency is not cryptographically secure all that stands between an attacker and a victim is a piece of malware or social engineering. The fact that the researchers didn't go all the way and document a specific attack that could be performed tomorrow does not mean that Curl was secure in practice.
Finally this continues to fail to address many salient points. Like why use trits? Why wasn't kekkac used from day one?
2. Bitcoin had no privileged nodes, nor does it now. All miners compete on the same terms. A central coordinator by definiton does not, or it wouldn’t be centralized.
[1] https://docs.google.com/document/d/1J8hehbnZWzcIUMQcxMiGbjz8...
I’m highly skeptical of this claim since there’s a cost to running any system. It seems more likely that they just made fees implicit rather than explicit (as in Bitcoin) but, regardless, someone needs to be paid to keep servers running.
Unless the cost of verifying transactions is zero, this just means that the cost is now measured in CPU cycles at the client. In the end, this may be higher than whatever you pay with Bitcoin, depending on how much work you need to do. This is what I mean by "making fees implicit" - there's still work to be done, but not putting a price on this work doesn't mean it's free.
Then there is a price; it's just measured in watt-hours of energy spent instead of denominated in cryptocurrency.
Is it when your equity's value does not match the face value
If you disagree I'll sell you 1% of equity in my lemonade stand for $1000
> Though whether the equity shares are worth as much as Bitfinex is claiming them to be is an another question.
I am not sure but they might be restricting the IOUs or shares to trade on their platform. So they are raking in commissions on the shares being traded. In which case it is surely a scam. But to be pedantic it is not a Ponzi scheme.
To be precise, it is not the debt-to-equity swap that the author is comparing to a Ponzi scheme, but the part where it is suggested they get their money back by selling on to a second round of 'investors' - but pedantic arguments over what to call it can only distract from the central issue of fraud.
I assume none have any real value. Though IOTA seems like it has different spins on what it is doing and is trying to do real things with the coin. I've heard positives and negatives. I'm not entirely familiar with the details. Regardless for that reason and in general risk reasons, i wouldn't stake a claim in IOTA or almost small altcoins like the ones you mentioned for long.
TLDR: as an investment, it is not my biggest investment, but as a technology it is my favourite in the crypto space.
The above being said, it looks like you are in your own EOS bubble.
You should zoom out of it, and I'd suggest further zoom out of the crypto coin hype, look at the digital coins objectively and decide if you want to lose your money, or risk increasing it.
That being said, some starting points for you:
Coins are trying to become money. We have tons of money, in fact we never had more historically.
After the last few crashes, the CBs dumped primes near zero (to avoid Max style of societial developments), and we even have more money around (cheap debts etc).
But, now we are doing fine.
BIS had a report weeks ago, outlining money contractions, salaries going up, cheap workforce from China+India joining the global economy 20 years ago stabilizing, and all that.
Cheap money, on this planet (so , not in the crypto world, or USA, or Luxemburg, but on this planet) will start contracting.
Crypto valuations, TAM and market caps are as high because people have a lot of extra fiat to dump into it (or in real estate, iPhones, high margin cars, etc).
As money becomes less obtainable, take a guess where they'll be drawn out from (well, Canadian real estate, but other stuff too).
So, after all of the above being said; I'm really glad you have a job as a c++ optimization expert in coin attempt number 3 by your CTO, but I suggest you remain sceptical about it success prospects.
EOS is not a money though. It is a trustless high-throughput decentralized execution environment or 'decentralized trustless cloud' so to say. It is an amazing project from technical point of view, (when your cloud application runs, it is run on 21 block producer clusters independently which are voted by stakeholders). And I find it antiintellectual to downvote somebody that speaks positively about this project, while serious and honest debate about it is very rare on the net. (I understand you did not downvote me). Whether it is a good investment, is a tougher question that is why it is not my biggest investment as I mentioned.
As for digital money: Do we need a decentralized trustless money and payment network? There can be a debate about it, but I think, yes. There is a lot of competition in this space, and there is a possibility that because of network effects only one of them will become mainstream. I think DASH is the one that has the biggest potential to achieve this.
They allowed people to convert to equity as an option. A choice. They paid back everyone who didn't choose to do that, in full, and quite quickly. Bitfinex's response to that hack should be considered a model for any future company in that situation. Hopefully such a thing won't happen, but if it does, there's no better way to respond than exactly how Bitfinex did.
It's great for you that you were able to be repaid at the cost of other victims who were robbed and swindled, but that isn't a responsible way to handle these things, and is most definitely not a model for handling losses. It's illegal for a reason.
Not going to afford another mtgox are we?
Even better than a Ponzi Scheme, let's just sell "shares" of this "company" (which by the way has a paper value of a very round and big ZERO) for cash
Toilet paper provides better value
Oh wait, he "buys low and sells high", that explains it.
EOS and IOTA are legit!
If you're praising Bitcoin, EOS, IOTA or whatever FooBarToken, please add a short note at the end to explain what you stand to gain. Either: "I'm long IOTA", or "I don't own IOTA and have no plans to initiate a position on the short term".
Similar rules apply at forums where penny stocks and other volatile traditional securities are discussed, so it's absolutely not an unreasonable thing to ask.
1) For the pumper poster, it makes them more conscious of the lie. Promoting a coin and forgetting to mention your holdings feels like a little white lie of omission. Actively lying about your holdings feels like deceit.
2) For the reader, it’s an important reminder that a seemingly objective technical-looking comment can be motivated by greed.
Which is why I already just assume everyone who doesn't do this but makes claims about a certain coin is talking out of their ass.
(I own BTC enough to buy a nintendo game)
Nothing to disclose though! I don’t care much about the space. But the volume of outright scams is the highest I’ve ever seen in any market.
Just a few points:
A) Iota is a legit currency trying to do something new in the crypto space.
B) The listing Bitcoin gold did not 'create' 2 bn usd - if you tried to liquidate even a fraction of that, you would drive the price to 0. There was significant demand from trader and speculators for its listing (not that I agree with it, but anyway).
C) Saying that a company that generates 30 mil. usd in revenues each month is worthless is really laughable.
D) This author has had a bone to pick with bitfinex for a long time. I consider him a shill with an agenda, and it is surprising that he is given so much space (even on HN) to spew his BS.
edit: formatting
That looks totally incompetent to me. Then mention centralized coordinator and they throw fits. Refuse to discuss it because it is only temporary.
But judge for yourselves. Look at this nice comment by Vitalik Buterin (Ethereum) and the childish retorts from the IOTA people: https://www.reddit.com/r/CryptoCurrency/comments/72l7kp/why_...