And that this is expensive.
And that this is expensive.
That's why exchanges are regulated. Step one of the regulation is getting the identity of all the owners. Step two is having servers and backups on regulated soils so you can seize everything at any time and reconstruct the ledgers.
You start off selling maybe 100 bitcoins which you've 'created', so the value of bitcoins on your exchange is 100 higher than in your 'wallet'. No-one can audit that and no one will notice because it's a tiny amount compared to the total volume. The more you do this, the more popular your exchange looks and the more you can repeat it and get away with it.
Eventually you be holding only a tiny fraction of the exchange book in actual bitcoin having cashed out 90% of it generating large amounts of money for yourself in the process.
If it ever looks like there's a run and you can't provide people with their bitcoin you claim "hack".
By the time you exit scam and claim "hack" the missing coins are gone but really they didn't exist so there's nothing to trace.
An exchange who works like a normal eWallet, so your money are stored in their database only, is seriously suspicious. I understand there are people who will fall for these scams, but there are scammed people everywhere in the world.
Also, a serious bitcoin trader/buyer should always have the bulk of his Bitcoins on a personal wallet not on an exchange.
Wouldn't selling created bitcoin lower the price of bitcoin at your exchange? A lower price would attract USD and the exchange would leak BTC with people doing arbitrage.
Then if you claim a hack wouldn't you have to show that value moved to the hackers wallets and that value and the value you retain had to add up to the total value received in BTC? And if the "stolen" amount of BTC couldn't be shown to be in another wallet, wouldn't the fraud be discovered?
Not necessarily. For example you can trade on GDAX (between ETH/BTC/LTC/USD) without hitting the blockchain. Once you "withdraw" your purchase and deposit it into "your" (because it's not really your wallet) wallet on Coinbase, then maybe.
Many of these "internal" exchange transactions are only reflected in their internal DB and not public blockchain.
Currently this is very easy to do. Such trades are local to the exchange, so they don't register on the blockchain. If you execute them as "maker" (limit) orders, there aren't any fees either. So you can fake significant market activity for free.
This is like saying that open source software is more secure than closed source software because the code is public and auditable.
Sure it is auditable, but nobody is doing it. And then shellshock happens.
Here's the money from the NiceHash hack two weeks ago (or "hack") getting moved out, in plain sight:
https://bitinfocharts.com/bitcoin/address/1EnJHhq8Jq8vDuZA5a...
You can kinda see what's happening (how it's being laundered) but you can't pin it on a given entity or idividual, unless they make a mistake.
Yeah
Sorry, but this is so bloody annoying that I have to tell you:
"crypto" = cryptography (stuff like symmetric/asymmetric encryption, hashing, etc.)
"crypto currency" = useless shit like bitcoin
So I think you meant "exit scams" in the crypto currency space.
Fixed that for you. Banks can accept risks to liquidity pretty readily because cash is centrally controlled. Considering that cryptocurrencies are hyper-liquid and are unrecoverable short of a hard fork in the event of a catastrophic event (e.g. with eth after the DAO hack), exchanges need to have measures in place which would be unheard-of at most other firms.
If we are to have currencies beyond the reach of laws and courts (which seems to be the point of bitcoin and the like), we will need actually capable organizations.
I wonder what countries and governments will do ? Because we all know that they won't actually have good security practices.
Depends on the size of the liquidity crunch. It's not exactly unknown to bring a financial institution to its knees for lack of liquidity.
> cryptocurrencies are hyper-liquid
How so?
> unrecoverable short of a hard fork
Which is the usual way of dealing with this. I can't think of any cryptocurrencies that are decentralised enough that a small quorum of people can't effect a substantial change.
> exchanges need to have measures in place which would be unheard-of at most other firms
What are they doing that's more than financial institutions? Startups selling coffee or whatever, sure.
Exchanges can mitigate this by storing the majority of their funds in multisig cold wallets.
Users can mitigate attacks against exchanges by never sending all of their coins to an exchange. For cashing out I recommend to 1) send a small number of coins to the exchange 2) wait until those converted USD arrive in the bank account 3) go back to step one.
The big difference here is that if a hacker transfers large sums out of a bank, the bank can just reverse those charges, whereas with a cryptocurrency exchange those funds are gone for good (for a solution to this problem see Covenant-based vaults [0]). Not only does draining a bank require serious investments in criminal organization and rare knowledge it also leaves a pretty big evidence trail.
[0]: https://link.springer.com/chapter/10.1007/978-3-662-53357-4_...
When the Bangladesh central banks was hacked through an incredibly insecure backdoor and 2 Billion was stolen, the hackers ended up with only 100 million, and only through shady other financial institutions. Who knows if they’ll end up with anything since that money will be hounded through the financial system.
Trust has an important place when dealing with such large sums of money, sorry to say it cryptoheads.
You need to get your transactions into the batches somehow. And the batch needs to still pass all automated checks. Then you need to stay under the limits set for the bank on the correspondent account at the other bank / clearing house.
Banks know this and really don't have nearly good enough security practices for running a bitcoin exchange..
If a bank said that customers were responsible for the money stored in the bank and that the bank could not undo transactions (from the POV of the genuine client) then we'd be demanding much stronger banking passwords.
A consequence of making that formal is that the total owned amount of bitcoin would be more than 21m, because the hacker would own bitcoin and the users would own bitcoin on the exchange.
As long as there isn't a bank run, that discrepancy would not be a problem, but it would deflate the currency, also seen as unacceptable to bitcoin purists.
edit: access -> accept.
And that evidence is pretty clear. I do not remember any hacking incidents resulting in large-scale losses to consumer, so they seem to be doing something right.
Simply because these are decentralized assets/tokens/etc being corralled ina centralized manner. Square peg in round hole. Bank security is still not secure, regardless of what we think today.
The only viable solution to this is to go DEX (distributed exchange) only. You control to keys, wallet and swap directly with other peers. Bitshares and others facilitate this already and it’s only a matter of time before the tools get easier and enough exchanges get hacked that people wise up.
Nothing is secure, but in practice, consumer funds are much, much more secure in a bank than in a cryptowallet.
Why do you assume that's not already happening: https://bitcointalk.org/index.php?topic=5441.msg1413156#msg1...
Oh right, regulation.