I'm the guy who bought 259684 Bitcoins for under $3000 yesterday
forum.bitcoin.org
forum.bitcoin.org
The security practices are appalling, and their lack of clarity on the counter-party issue is damning. If I were Kevin---or, indeed, any customer of that exchange---I'd take my money and go elsewhere.
Still, it's pretty astounding how myopic the rest of the Mt Gox forum users appear. They're taking a situation that's beyond a doubt the fault of the Mt Gox admins and getting ready to lynch a dude who seems to have acted rather reasonably (intentionally not exploiting a known loophole to exceed the withdrawl limit, reporting his disposition immediately to the site's maintainer, et cetera).
He did place the $0.0101 buy. Your quote is regarding withdrawing the bitcoins from Mt Gox.
Raises other questions about whether clients can 'conspire' to hold records of sales (vs rolling back the transactions). In real 'cash' situations you have to give back the actual currency, in a bitcoin world its a rollback of the sell record, but now you've created Heisencoins have you not? Sold by some accounts, not sold by others?
Interesting to watch the intersection of the protocol and the reality.
He writes he was aware that probably the hack is causing this and decided to take advantage of it.
He should give the BitCoin back to MtGox, who would then proceed to roll back the transactions. Simple as that.
He didn't. He could have withdrawn it all if he wanted.
>who would then proceed to roll back the transactions.
But that's the thing; as he said, regardless of his money, rolling back all the transactions sets a bad precedent. How can people trust Mt Gox now?
If I own a grocery store, the onus is not on me to determine whether the person offering me money in exchange for goods came by that money legitimately. They give me money, I give them goods. That's the extent of my responsibility in the transaction.
This is the case in physical realms too. For instance, if you buy a stereo for a hugely marked down price out of the back of a guy's car and the cops find out about it, you may get charged. You will certainly have to give it back to the original owner, and if they don't catch the crook, you are the one who is out the money. Even if you don't get caught, you probably wouldn't tell your friends because this is not the sort of thing decent people do.
Buying them through MtGox wasn't the same as buying bitcoins out of the back of some guy's car.
What about people who had standing buy orders? They could never had known about the market free-fall and conditions surrounding their eventually accepted orders.
Also, what if it wasn't an attack? What if someone with a lot of bitcoins was running a malconfigured script? We've seen flash crashes in the real world caused by automated trading; why would btc be any different?
I think that the OP considered the above possibilities and acted rationally. However, he also considered the possibilitiy of this being an attack/theft/hack and acted NOT like a dick.
Yeah, I think initially there was that. But after he bought he began to suspect there was fraudulent activity. And he still transferred the money out. The problem was not the buying, it is suggesting the MtGox is responsible for providing him with a free lunch now.
> wasn't the same . . .
No, but there was a commonality in that foul play was suspected. The point of the car analogy is not the appropriateness of the forum, because MtGox is unquestionably an appropriate forum. It's about how much evidence you have to suggest that something is amiss.
> What about people who had standing buy orders
We're (I'm) not talking about them.
FYI, the information I'm basing this on comes from a similar case in the Wikipedia article:
"""
In 1997 the U.S. Supreme Court adopted the misappropriation theory of insider trading in United States v. O'Hagan, 521 U.S. 642, 655 (1997). O'Hagan was a partner in a law firm representing Grand Metropolitan, while it was considering a tender offer for Pillsbury Co. O'Hagan used this inside information by buying call options on Pillsbury stock, resulting in profits of over $4 million. O'Hagan claimed that neither he nor his firm owed a fiduciary duty to Pillsbury, so that he did not commit fraud by purchasing Pillsbury options.[16]
The Court rejected O'Hagan's arguments and upheld his conviction.
The "misappropriation theory" holds that a person commits fraud "in connection with" a securities transaction, and thereby violates 10(b) and Rule 10b-5, when he misappropriates confidential information for securities trading purposes, in breach of a duty owed to the source of the information. Under this theory, a fiduciary's undisclosed, self-serving use of a principal's information to purchase or sell securities, in breach of a duty of loyalty and confidentiality, defrauds the principal of the exclusive use of the information. In lieu of premising liability on a fiduciary relationship between company insider and purchaser or seller of the company's stock, the misappropriation theory premises liability on a fiduciary-turned-trader's deception of those who entrusted him with access to confidential information.
"""
Of course, IANAL and I could be wrong, but it sounds like the same sort of thing. Information is created about a company by a third party, and someone else uses that information to make trades.
Then again, these two situations are also not analogous, because this guy's trades on MtGox were based on public information (namely that the value of bitcoins was falling precipitously). So he might not have done anything technically illegal, were this a real exchange. However, his trades would probably have been rolled back in a real exchange (assuming the trades were enough to move the market like this), so that still supports my overall perspective that he should not expect to get away with the money.
And I've never seen him say he should keep the money (he said they didn't even ask him the money back), he just disagrees with the decision of rolling back by force, which affects the whole Bitcoin market, not just himself.
I'm aware, read my last paragraph.
> disagrees with rolling back by force
Of course he does. If his suggestions are implemented, he stands to make a lot of money.
Mt Gox is run in such amateurish way, it's appalling.
In real life, with many brokers you trade doesn't close in 3 days and as such you can't withdraw proceeds from the trade for 3 days (but you can use the proceeds to continue trading).
In this situation Mt Gox is effectively both exchange and the broker. Not to have rule in place to block funds from recent transactions is like people who designed it never traded real stock with real brokers.
And this isn't a fraud prevention measure, it's a legacy of the days when settlement included someone carting a stack of stock certificates from one bank's vault to another.
Lastly, most traders trade on a contractual basis, not a settlement basis, so their trades are considered binding as soon as the agreement is in place.
1. In the US, most exchange operators are the counter-parties to all trades. They also interact with settlement and clearing services that ensure the verification of proper ownership and conveyance of securities. In the old days, something like a third of all trades failed to meet the three-day window because some part of this process would fail.
2. There are very very specific rules regarding how the orders are crossed (buy and sell side) and which orders take precedence in the (limit order) book. It looks like the MtGox guys didn't think this through and the trader in question took advantage of this naivete on the part of MtGox.
3. Most exchanges are "brokered" to facilitate trades while MtGox is more like a swap-meet. Brokered exchanges are more expensive to trade in but they have the advantage that brokers can "know" how to get price-improvement based on market conditions. In short, they are "informed traders" vs the "uninformed traders" you see in most post/notice markets. When the informed meet the uninformed, you see situations like this where someone takes the whole shebang home.
Personally, I find it amusing that the Bitcoin fanboys are clamoring for intervention here. It's almost like they are getting to the idea that a strong regulatory environment is a /good/ thing for the free market. If this were the cryptopunk/libertarian paradise that everyone dreams of for Bitcoin, there would be /no/ recourse.
The real problem is that the market was able to descend to that level to begin with. There should have been some sort of circuit breaker limits in the Mt. Gox system that would have halted such a massive decline, similar to what exist in the US equity and futures markets.
As to #3, really the only thing that matters in terms of exchange access in the US is that you satisfy the appropriate compliance burdens (broker-dealer status) and can pay the fees required for naked access. That may be good selection criteria for "informed traders" but it certainly isn't any guarantee.
As for #3, naked access is a relatively new invention and the rules are sufficiently constructed to virtually guarantee that only implicitly informed parties are ever going to see "naked" access.
Circuit breakers (actually the lack of them) is one of those things that enabled this to occur. The party in question essentially copied a strategy that was used by the HFT guys to soak up the offer. The seller got liquidity but it came at a very dear price.
And that's really the issue here: circuit breakers are a compromise between liquidity and price discovery. If the exchange suddenly sees that price discovery is trending outside of a range, they shut down trading. If the problem is a systemic market one, then this probably is a good idea. But if price movement is because of new information, then all the circuit breakers in the world wont help you because as soon as trading resumes, the new regime will be in play.
I blame hubris. Bitcoin is an enterprise where tech-focused people think they have a better (or at least equivalent) solution than what decades or centuries of economics and finance or whatever have come up with. An over-focus on its legitimate advantages and their own abilities ends up blinding people like this to the lessons of experience from the old model and from domain experts. In a very real sense, because they're convinced it's better and that they know what they need to know from economics and finance and banking, they're going to keep making the mistakes that the people they're replacing solved long ago.
The problem is that the entire Bitcoin model has the same weakness. There's no rule for rolling back a bitcoin transaction because there couldn't be such a single authority because bitcoin is merely a "decentralized" algorithm.
This illustrate one of the inherent problems of Bitcoin. Any currency system today must be based not on simple transfers but on valid transactions. Valid transactions require that there exists an authority to validate those transactions.
Real world brokers though have settlement period for releasing funds for exactly this reason - so the transaction could be rolled back if necessary.
If you're real world is drug sales in a shady corner somewhere, that might be true.
Elsewhere, we have this thing called the "legal system" which actually exists primarily to enforce something called a "contract", which is essentially a transaction.
... and getting everyone to agree to the rollback might be difficult.
... and considering you would be using the state's court system, the state feel like refusing to use their money wasn't very generous. IE, if the Feds could sink bitcoin transactions just by saying they wouldn't engage in any Fraud protection on them.
I decided a while ago that arguing against the "bitcoin has no problems" crowd was futile: people are too enamored with the idea to see problems like this until they happen.
... it ain't credible.
On the other hand, it sounds like they would have a great career path at the federal reserve...
I don't mean to be too harsh, but I can't see any value in this part of your comment. It will only possibly lead to derailment of this discussion.
Mt Gox Exchange =/= BTC Currency Nasdaq Exchange =/= USD Currency
If the community wants rollbacks when transactions aren't "fair," what's the point of BitCoin again?
Likewise the freedom from government intervention that is the point of Bitcoin does not ensure freedom from government intervention in trading platforms built upon it.
Not that I don't expect problems to emerge with Bitcoin itself...
"We must do something, {random} is something, therefore we must do {random}" is generally regarded as a fallacy.
"Folks, in the grown-up world, trades are unwound when the market malfunctions. --Jeff Garzik, bitcoin core dev team"
In the grown-up world, currency is controlled by governments, the financial industry is regulated, and money cannot be transferred large distances anonymously. The whole sales pitch of BitCoin is that it is free of all this control. Invoking "the grown-up world" to describe BitCoin is absurd.
So true.
The main reason why Bitcoin can't be considered grown-up is because there aren't guys like Soisson showing up dead.
No they don't. I think the FATF would have words with countries that allowed this to happen.
The Bitcoin "community" is an emergent, distributed boiler room. They could just as easily be selling pink clam shells, tulips, or shares in an insolvent company that had a business plan to make pool cleaning agents. The underlying commodity doesn't matter. What does matter is that the widely disbursing the underlying commodity early gave them enough of a following, including folks who are savvy enough to think that they are the ones getting rich off the marks (a classic element of fraud), to attempt to convince other people that there is actually intrinsic value in what they are selling.
Every article about Bitcoin which makes it to HN -- yes, including ones in mainstream publications -- is in effect a PR hit planted by a new breed of the old boiler room scam.
If you want to view BTC as a currency, it doesn't look that way... IMO.
BTC appears entirely dysfunctional as currency.
"currency refers to a generally accepted medium of exchange." http://en.wikipedia.org/wiki/Currency
BTC is neither generally accepted nor does it have the STABLE VALUE needed to become more accepted as a medium of exchange. And last element is something the Bitcommunists just utterly miss. Because a currency is medium, just a means, it will not function unless its value is stable. Not decreasing OR increasing.
Whenever the BTC shills tout the increasing value, they've accomplished the old "switch-a-roo" from currency to speculative commodity.
But currencies are also dual-purposed as commodities (c.f., forex traders).
Especially when the exchange is just a spot market - speculation in futures and options wouldn't undermine the viability of the currency as an actual means of exchange in the way that this situation will.
That's something like what would happen if someone dumped 1 trillion USD onto a bond exchange. There are only a couple entities who could do this.
So how did 1/12 of the value in this ecosystem wind up in one account at Mt Gox? I'd have to think that it's likely an insider/early adopter. (or Mt Gox itself?) There's a limit on the number of entities who could amass that sort of 'fortune'.
Edit (added link) + post 122 as well. http://forum.bitcoin.org/index.php?topic=20207.120
It's not what Mt Gox allows that matters - it's been hacked and compromised specifically to allow people to do things that are not allowed
This was a "test account" that had no real user attached to it. After all, if the trade is internal on MtGox, it's just a double in a database.
If that is the case, then hell yes, I can see why MtGox would want this rollback.
That is why trades can be instantaneous, and don't require confirmation the network (except when you are sending to or withdrawing from MtGox itself).
In this case, if you could hack the DB and convince MtGox that you had more BTC in your account than you really did, you could still withdraw BTC, but there would no longer be enough BTC for everyone to withdraw.
If this is really the case, he couldn't possibly edit the main database with only that.
'Sell' fake coins. Crash the price. Buy 'real' coins. A virtual coin laundering. Fascinating.
Judging by the amateur security issues they've had lately, I think it's highly unlikely that they have the right controls in place to catch something like that automatically.
Dude, don't use double to represent money.
http://en.wikipedia.org/wiki/Double_precision
So using double is in fact perfectly OK in this case.
The bitcoin client and protocol itself doesn't use doubles internally, but fixed-point numbers. I don't know about MTGox, though.
Floating point representation for financial data. That does sound like something MtGox would do...
The two leading theories are that it was the account that trading fees go into, or it was an account that didn't really have that many bitcoins, but had its balance altered by SQL injection.
Even if it's illegal to manipulate the US Dollar, it is most certainly legal to manipulate the BitCoin, whose express purpose was to be wholly unregulated!!!
Mt. Gox, however is fairly self-regulated; everyone who participates in it wants it to be.
"Unlike stocks, futures or options, currency trading does not take place on a regulated exchange. It is not controlled by any central governing body, there are no clearing houses to guarantee the trades and there is no arbitration panel to adjudicate disputes. All members trade with each other based on credit agreements. Essentially, business in the largest, most liquid market in the world depends on nothing more than a metaphorical handshake." - 1
So basically, the method of bitcoin exchange isn't all that different from ForEx. What's happened here is that the trading house has taken a fall, but doesn't appear prepared to take it on the chin. I don't know much about Mt. Gox. Any guesses as to whether or not they're insured? If this turns out to be a case of Mt. Gox's systems being hacked, are they liable?
What's most interesting for me is the irony on display. Bitcoin, Mt. Gox, and the whole ecosystem were established on principles like lack of regulation, anonymity, and un-traceability, yet here they are, hoist by their own petard.
[1] http://www.investopedia.com/articles/forex/06/SevenFXFAQs.as...
However, he has two technical mistakes in his post from a security perspective:
1) We don't know the attack vector. For example: If Mt Gox has a SQL injection vulnerability, then a sophisticated attacker will not waste their time doing a rainbow attack on a random user. Instead, if the account balance is not encrypted and the key kept secret, then the attacker simply needs to do a SQL injection attack that returns the account with the largest balance:
select top 1 t1.account_id, t1.balance from Account t1 order by t1.balance desc
Instantly, the attacker knows the largest balance. This automatically reduces the attack space. This is a standard trick attackers use to bypass even needing to guess a password.
2) Compounding this issue, it seems Kevin is right, the attacked account had a naive password susceptible to a rainbow attack. According to rumors, this attack was a pooled account that mediated all the assets traded on the exchange. This implies that MtGox used a password susceptible to a rainbow attack to secure the master account. To answer Kevin's question, what user would amass $8M in bitcoins and use a bad password? The system administrators. 0xDEADBEEF.
Postscript: I have never traded or owned bitcoins, or even signed up for an exchange. I just find the security breach fascinating!
the most interesting part I think is that he was actually able to withdraw 643.27 bitcoins (much more than usual daily limit) when they were for around $1.55 each which means withdrawal limit for BTC was calculated at current market prices.
If this is all true, then hacker is probably banging his head against the wall now because he was likely able to steal millions without any hope being ever caught. or did he?
MtGox claims he got away with only $1,000 worth of bitcoins however if he took them out of the exchange right after the crash when their market value was around $0.01... oh well, there is something very fishy going on here. I suspect MtGox doesn't have enough bitcoins to back their accounts now. If you see in upcoming days people complaining about MtGox not willing to physically transfer bitcoins back to their traders, it will be more than obvious.
No investor with a sane mind would consider Bitcoins a solid investment decision. Unfortunately, ideas like this tend to attract both extremely savvy people as well as a bunch of lazy people who would otherwise be lapping up "Make 10,000 a week with Clickbank" e-books.
There will likely be many more stories in the same vein as this one.
In my mind, the wealth of this discussion isn't who is right and who is wrong, it's the fact that we're recognizing the current faults in a new and ambitious system, in the hopes that we can make a better one in the future.
I'm quite surprised that a service with accounts holding millions of dollars would store passwords without salt or a stronger hash algorithm than MD5!
http://consumerist.com/2011/06/how-hackers-stole-200000-citi...
The most important thing is the how slow it is, and it's likely that if they'd taken defaults bcrypt would actually have been faster.
The saddest thing is that many of the people howling about MD5 are proposing weaker alternatives like straight SHA-512 with a static "salt" embedded in the source code.
In fact, MTGOX almost deployed such a replacement in their upgrade until they were cluesticked by people screaming to not invent you own cryptographic functions.
See, for example, http://www.golubev.com/gpuest.htm
The sale was not legit, it should not stand. The rest of the rollback is fuzzier, but on this gentlemans coins, a seizure should occur.
http://www.lexisnexis.com/community/corpsec/blogs/bus-law-an...
I'm still confused about whether or not bitcoin transactions are traceable. If they have deniability, it might be impossible to prove/disprove that you knew the goods were stolen.
Of course, I am neither a lawyer nor a crypto specialist and this isn't legal advice.
(In particular, the rules vary depending on whether the property is realty, on whether you have a Torrens system, whether you have fused equity and what your local courts and legislatures have decided).
(IANAL, TINLA).
Say I am 99 years old and have only one week left to live. What if I go on a car stealing spree and steal Porsche cars for my extended family. Then I sell it to them for a symbolic 1 cent each, claiming that I have collected them over my lifetime and now want my family to benefit.
You, the thief, are still on the hook for your crime.
The buyer, if they really are a bona fide purchaser for value without notice, is not.
Your family would probably not meet the test, as this would be the first time they've heard of the Porsches.
(IANAL, TINLA)
I can't imagine that it works that way. I can believe that as a buyer of stolen good without knowing they were stolen, you won't be punished. But you will still have to return the stuff. I am not a lawyer either, though.
If it works as you describe, let's found a guild of 99 year old Robin Hoods...
Note "for value". If the price is unrealistically cheap, the courts can point out that the buyer should have been suspicious.
> I can't imagine that it works that way. I can believe that as a buyer of stolen good without knowing they were stolen, you won't be punished. But you will still have to return the stuff.
You don't have to return it, it's yours now. The point is that the bona fide purchaser is not a criminal and acted in good faith. If, however, there is the slightest whiff of a hint of a suspicion, those bona fides collapse and title reverts to the original owner.
It is harder to prove bona fides than you might think. Got a great price? Not for value, test fails. Knew the seller? Not bona fides, test fails. Bought it from someone who has no history of selling those items? Possible notice, test fails. And so on.
Look, here's the thing. Lawyers and judges have been working on this system (the common law) for nearly a thousand years. For day-to-day stuff like property, the loopholes are well and truly closed and have been for hundreds of years.
That I was an inadequate law student and now am an inadequate explainer does not change the fact that the common law is pretty damn adequate at providing sensible legal protection for almost all imaginable transactions.
(IANAL, TINLA)
What if I never even noticed it was stolen?
In fact, as the thief, why even bother with stealing? Why not just sell, say, houses on ebay that don't belong to me?
If you had multiple sets of keys and some were stolen, then by repossessing the you are potentially a thief if the intermediate buyer was bona fide.
2. Whether or not you noticed is irrelevant, the crime was committed and the Crown or the People will take an interest.
3. Selling things that you neither possess nor own is fraud.
(IANAL, TINLA)
A thief steals a widget from you and sells it to me for $x. I have no reason to suspect it was stolen.
The thief then absconds with the $x and spends it on consumable goods; even if caught, the cash can't be recovered from him.
I currently have the widget and have lost nothing; you're currently the thief's only victim. But if the court takes the widget from me and gives it to you, you're fully compensated, while I am now the victim, because my $x has effectively been stolen with no compensation.
In other words, there are two people who have been victimized by the thief, but all the court can do is re-assign victimhood to one party or the other, which, all things being equal, it should be indifferent to. Allowing the purchaser to keep the widget is basically the same as saying that they'll have no part in deciding who is to be the victim, and allowing circumstance itself to determine that.
But the thief himself is always responsible, and it's entirely appropriate to extract from him as much compensation for both victims as is possible.
But in most of the US, that scheme doesn't apply.
This rule only applies in some law systems. Where I live you need both to perform all the reasonable checks and 3 years time to become the owner of the stolen property.
If the original owner shows up before 3 years have passed then you have to get back whatever you have bought. This happens even if you have performed all of the reasonable legitimacy checks.
One exception is land registration - entries in the public land register (even those obtained illegally) protect the purchasers from claims by the original owners (this does not apply to bad faith buyers.)
If I own something, I have legal rights enforceable on it, regardless of whether anyone else thinks it's valuable. If I owned the bitcoins -- I suspect common law would have little difficult in identifying these as distinctly ownable -- then I have enforceable rights in them. I can ask the court to order those rights be respected.
Property rights in virtual property is a fast-growing area of law, however, so: IANAL, TINLA.
"Virtual currency used by drug traffickers stolen from users, courts play world's tiniest violin."
If a drug dealer steals a kilo from another drug dealer he's not going to take it to the courts. Thinking you will be entitled to some form of legal recourse should something similar happen to you when trading bitcoins is, IMO, foolish at this point.
As you can imagine, courts do not uphold contracts where there is an unlawful objective ("I paid him to beat my boss and he didn't!") and in most jurisdictions you cannot obtain property rights in certain things (in others you can, but asking for enforcement exposes you to criminal prosecution so in practice it doesn't happen).
Bitcoin is not a prohibited item and the exchange of bitcoins looks very much like contracts that don't have a unlawful objective.
Put another way: courts would probably enforce rights for trades made on Mt Gox, but not on Silk Road.
(IANAL, TINLA)
Property law does not require physical property in order to be applicable.
(IANAL, TINLA)
You are assuming bitcoins are like a negotiable instrument. They aren't, they are much closer to bearer bonds. Whoever holds the wallet owns the bitcoins. There is no other recorded title.
This has nothing to do with what a bitcoin wants to be, but what law in the US is with regards to stolen property.
I also find it interesting that the person who supposedly initiated the trade has yet to be heard from. Their story would really help clarify things, not to mention that they have not been heard from yet makes it seem as if there is no such single user...
I'd love to see how this would go down in the courts.
Bitcoin is meant to be unregulated, but MtGox and its identifiable customers all have legal personality. The main challenge would be identifying jurisdiction, but after that I suspect usual laws would be found to be applicable.
(IANAL, TINLA)
But almost certainly not any collisions with very simple and very short passwords. The hash output space is sufficiently large.
Someone who (given infinite time) found a brute-force collision would likely find one of the shorter preimages first – you aren't really gaining anything by going ever-longer, after your preimage choice has as many bits as the hash output.
But if the attacker truly needed to brute-force it over the entire 160-bit (SHA1) or larger (other hashes) output space, unconstrained by usual simple-password-like limits on what to try as preimages, that's impractical, and you've achieved your goal... even if you overdid it on the input.
Take N to be 10, assume 7 bits per character. Then all 10-character passwords fill no more than 2^70 of the 2^128 MD5 space. Any 11-or-larger character password then has a less than 1-in-2^58 chance of colliding with any shorter password. (That's how much larger the full space is, from which each longer-password hash will be drawn.) That's 1-in-288-quadrillion for us decimal apes.
The service would probably never deliver a useful warning before MD5 falls completely to a preimage attack.
The analysis for such a service only gets harsher for 160/256/512 bit hashes.
I don't have the requisite knowledge, and probably not the fiduciary responsibility, but I'd like to at least observe your progress. Email in profile.
I'd be down for that, it sounds like a fun project in an interesting domain and I was actually thinking about what building one would entail as I've been reading though the comments here.
and finding a legally safe location to put a business like that.
For that I'll put my ego aside and do a few weeks of boring work. and yeah, I was fantasizing about neat-o technology problems too. I'd love to build an order matching system. Then I got to thinking about the market size, and taking a cut of each transaction.
If you create a clear, well defined entity there very well may be an opening in the market for another bitcoin exchange.
In fact, i'd say there absolutely is an opening and I presume the market will grow over time. Skim 0.75% off each side of the transaction and you're looking to be in good shape. Particularly as btc trading activity increases.
It would take 21.9 years to withdraw the full amount of that account.
Or it wasn't a real account...
"It was definitely all our bitcoins that mtgox had in one account! I remember a few days before, people saying that some big bitcoin movements on bitcoin monitor were from mtgox, and the quantity being moved was around 400 000 to 500 000 bitcoins. No single user lost that quantity, it was our coins, from all of us!"
I know because I have access to the source code of the site.
You can't post a trade from 'all' accounts; if a large trade pushed the price down, then a large trade pushed the price down, and that trade was executed from a single account.
Given Mark's statement that the logins which had been dormant for more than a few months were the easily rainbow-table attacked ones, it seems that someone had sent in a lot of bitcoins and then stopped using the system for a while; they apparently had a weak / rainbow-table vulnerable password.
If that's the situation, I'd call this a medium-sophisticated attack; better would have been to drive prices down slowly over a day or so, then use other hacked accounts to buy them up cheaply and withdraw over BTC. That might have taken some time to notice and unravel.
As it is, it looks like someone tried to flash-crash the market, then send out $1,000 worth of BTC at very low market rates, so a lot of BTC. Someone who would do this intrinsically believes in the resilience of bitcoin by the way, which is interesting. I'm not sure how they would plan on dealing with the taint on their coins, though. They'd have needed some sort of high-volume laundering service; none of the ones I know have enough volume to deal with this.
All that source code you're looking at means nothing if the attacker gained arbitrary SQL execution on the database.
What if he were in it to destroy Mt. Gox, as they say, "for the lulz"?
Making all their customers angry and causing a run on their escrow accounts might just do it more effectively than trying to withdraw whatever could be obtained through their online trading platform.
That alone makes cancellations bad policy. If you're worried about so-called erroneous trades, you should disallow market orders; make all traders provide an explicit buy or sell price and there is no such thing as a bad trade except in the event of systems failures.
UNLESS, of course, you're having second thoughts because you're related to the hacking and backed off when you got nervous, seeing how far the prices went down and how the massive buy order did manage to go through... just a possibility, no offense. The fact that you gave them your id and didn't behave like a shady guy is irrelevant as long as it's impossible that you be proven guilty, in fact that's exactly how the clever shady guy should be behaving... like "not guilty", because money is usually traced in the end, and you want to look like a saint when that happens. So, their position about contacting you is perfectly reasonable and natural; to them you might be related to the hackers anyway and anything they say to you (nothing they could say would be good- a conversation with them would be full of unanswered questions) is likely to end up in a public forum. Not good pr.
One thing that has become abundantly clear from reading all of the comments on the Bitcoin forums is that the investing knowledge of most BTC traders is much less than your average equities, fixed income, or ForEx trader.
MtGox is a pretty low budget operation, but even a low budget operation isn't just going to let someone steal the equivalent of $10,000,000 USD and not reverse the transactions. It would be like your bank telling you "sorry, someone transferred money out of your account without your authorization, but we're just going to let them keep it because, hey, they won it fair and square by hacking your account."
(As I write this last line I realize there was recently a court case regarding this exact issue, ETF fraud, but it occurred over many days and the company had authorized an agreement that they would check their account balance daily for fraudulent transactions.)
I just don't see how an exchange that doesn't have builtin failsafes/circuit breakers can just roll back trades. I think that in this case, the exchange should be liable. He was just exploiting the market.
There's some speculation that when some more powerful market participants (read: Goldman Sachs) are on the losing end of a questionable trade they complain to the exchange and get the trade busted far more frequently than when it happens to less powerful participants.
In regards to this MtGox issue using the same argument, if it is known that an attack did happen, an that attack was directed at MtGox directly, then yes, they should roll back that trade because someone is out money/BTC due to an attack that could not have been prevented by that account holder. The only way to legitimately know who is responsible for the sell off is to be transparent, however, it seems that MtGox hasn't fully released details of the incident and we are all speculating on what exactly happened.
"Unlike stocks, futures or options, currency trading does not take place on a regulated exchange. It is not controlled by any central governing body, there are no clearing houses to guarantee the trades and there is no arbitration panel to adjudicate disputes. All members trade with each other based on credit agreements. Essentially, business in the largest, most liquid market in the world depends on nothing more than a metaphorical handshake."
- http://www.investopedia.com/articles/forex/06/SevenFXFAQs.as...
It doesn't surprise me that someone who is on the site would notice an ongoing crash faster than people who were doing something else. It further doesn't surprise me that someone who is already involved with the site would find it easier to get through an overloaded system than others - for one thing they don't need to go through the login process.
I'm not saying that Kevin wasn't associated with the break-in. I'm just saying that the evidence provided is not very good evidence of anything other than that Kevin was at the right place at the right time. Given that the site is actively used, there will always be people in that boat, and they will have an advantage over people who aren't.
Do you think this guy deserves $5 million worth of bitcoins because of the work of a hacker? Uh no.
His rationalizations for his behavior are astonishing. Assuming he is not the hacker, he got caught up in the excitement of buying cheap bitcoins (as we all would have), realized after the fact he probably did something wrong, and through contacting Mt Gox and coming out to the community he was hoping to get away with at least some profits. He shouldn't be able to keep any of it. Sorry Kevin.
[1] http://www.amazonsellercommunity.com/forums/thread.jspa?thre... [2] http://articles.moneycentral.msn.com/Banking/BetterBanking/B... [3] http://www.thestar.com/business/markets/article/806459--regu...
No it isn't, there's no precedent for this because it hasn't existed before. The nearest thing I can think of is when that fake letter was sent out about some company causing the stock to tank. Did all the people who bought the stock when it was low have their transactions rolled back? Because that's what happened here, someone used highly technical means to cause an artificial price dive and one guy was able to take advantage of it. It's not at all clear to me that he should give any of it back.
The problem with a trading house like Mt. Gox is that some people assume that all of the players are altruistic (these "some people" being "me", somebody with a technical, non-financial interest in bitcoin).
What happened here is just natural selfishness: the person that executed this buy order knew that the market was crashing, and that something was going wrong, but decided to exploit it regardless.
Then trying to withdraw $5 million USD from Mt. Gox?
I guess it's just crowd psychology. "If I don't exploit this market, somebody else will!"
It's sad, and it's just my naivety showing here, but bitcoin looks like a nerdy sandbox from the outside (casually reading about it on HN); it's a place for crypto/economics geeks to play around with finance.
Of course it isn't, and the actions of this [very greedy] person demonstrate that.
So why do I want to use bitcoin? What advantages does it offer me over USD right now? Before seeing this crash for the last couple of days, it felt like the advantage was that bitcoin users were mostly geeks, and mostly trustworthy. The regulation that bitcoin is avoiding is starting to look pretty darn appealing.
How stupid/childish of me is it to daydream about a world where somebody saw this crash happening, did exactly what he did (or maybe put in the buy order at exactly $0.02), held the bitcoins until the crash ended, then just gave them back to the sellers at cost?
He didn't do that. He withdrew $1000, once, and some bitcoins. Then notified the administrators.
Honestly, this whole forum post reeks of "I know I did something wrong, hopefully posting here will make the pit in my stomach go away."
Same goes for contacting magicaltux (the admin of mtgox) -- I bet he was absolutely losing his mind when the trade went through. I know I would have been.
Are you seriously putting these words in my mouth? I didn't say anything like that. The gist of my post was that from a casual reader's perspective, bitcoin was a hobby for cryptographic nerds, and that this demonstrated that it's "lost its innocence", so to speak.
Am I "upset" by this? Sure. In the same way that I would be upset if I was competing on something like allrgb, but nvidia decided to come in and destroy me and my friends by building custom glass. Is nvidia be "immoral" there? No. Are they being, to be blunt, assholes?
Thoughtcrime? Convicted?
I want this to be clear to anybody reading this that doesn't understand the context of what I'm saying: (I'm trying to say this in the most polite way possible) your response here is completely incorrect, and without merit.
You're accusing me of something that I consider morally abhorrent (accusing somebody of "thoughtcrime"), and it's ridiculous.
That's the thought, and you treat it like a crime. Hence, thought-crime.
In case you missed the context here, my original argument was that my naivety caused me to assume that people playing with bitcoin were mostly just cryto geeks.
This is what you said about him contemplating transferring more money out of mtgox. You're acting like he did something abhorrent, or should think he did.
> my naivety caused me to assume that people playing with bitcoin were mostly just cryto geeks.
They are. But you're trying to say "... and I'm surprised one of them would be thiefly, like this guy."
Really, all this shows is that he should have transferred all the bitcoins out immediately. Then mtgox would have to deal with him instead of just slandering him. Now that he's pointed everything out to them he's just a scapegoat.
> Then trying to withdraw $5 million USD from Mt. Gox?
He was stating that he could have withdrawn the entire amount, but didn't want to appear shady (especially since doing so would have made him seem even more like a hacker that initiated the sell order).If the limit had been $10,000 -- I'm sure he would have gone for that.
The right to sell something is predicated on owning the item in question.
A buyer of stolen goods is unable to take legal ownership, it doesn't matter if he doesn't know the item is stolen. (i.e. I steal a car, and sell it to you, you don't own the car even though you gave me money and you didn't know the car was stolen)
It does matter that the coins were not put up for sale by the owner.
This is (subject to numerous exceptions) not correct. While in common law you are correct, in equity, if the buyer is a bona fide purchaser for value without notice, he or she can get title.
(IANAL, TINLA)
How is a buyer supposed to know if the seller is making a bona fide offer, esp. where the buyer may place its buy order in advance of the sell order?
I stand by my position that it's up to the exchange and the seller to protect against unauthorized sell orders.
Of course, under extreme circumstances, the buyer will see that something is out of place – as is exactly the case here, where the buyer came forward because he felt that the sell order was not valid.
BUT (and here's the most important point): who gets to decide when a case is "extreme" enough to put the burden on the buyer? It's not a call anyone should be able to make, unless there are clear rules, published up front.
The buyer isn't liable as he didn't know the property was stolen, but he don't get to keep the property. Typically in this case he would need to seek damages from the exchange to recover his assets (the dollars used in the trade)
IANAL but I have first hand seen this type of stuff on various exchanges. (i.e. stock gets fraudulently wired out one account, and sold. Trades get busted)
It sucks all around, but the fact of the matter is the great deal the buyer was getting never would have existed if somebody didn't steal from someone else. If I stole your life savings and sold it to your neighbor for a dollar, you don't really think your neighbor should be able to keep it do you?
Buying stolen goods on an exchange doesn't make it ok. It sounds to me that you'd like it to be - but that isn't how it works.
What happened here is akin to me logging into your brokerage account with a stolen password and selling all your securities. This happens and those trades get busted. Sometimes the selling bank just eats the loss as it would take too much work or too much embarrassment to recover, but other times they work with the counter-party to unwind.
I'm not asserting this happens in all cases. As I said above, IANAL. I know equity laws in particular are a bit different than a lot of other types of property which fall under common-law.
That is kind of moot though as equity laws don't apply here - bit-coins aren't equity.
--
http://en.wikipedia.org/wiki/Rogue_trader - shows other examples too
Quite frankly, Mt. Gox never struck me as particularly secure. I'm very surprised anyone would keep a large amount of money in it, instead of transferring it out to their accounts.
Yeah whatever. 90% of the people using Bitcoin don't believe in the Federal Reserve system or fiat money and just want anonymous online cash transactions. There is nothing wrong with such beliefs or desires, but the idea that such people are on a higher moral plane is the complaint of a naive person at best.
All others moaning about what he did who bid at 0.1 weren't?
A system robust against outright criminals still works when you have decent people. The converse is not true.
Having said that, regulatory rules should not have retroactive effect.
https://forum.bitcoin.org/index.php?topic=18858.msg237804#ms...
It sounds to me, as the first commentator on bitcoin.org says, that someone would like to keep their fat booty.
I expect from my bank that they give me back my money if it is being stolen from me, why would I not expect it from MtGox (if it is within their power). Banks routinely roll back fraud transactions and nobody complains - except the fraudsters, of course.
Suppose I gamble my life savings, buy Kleenex shares. Tomorrow a report comes out showing that using paper tissues causes allergies and prolongs colds. The shares tank ... I'd like a rollback please!
Strangely enough the guy that saw the report first and shorted those shares making millions doesn't want a rollback.
Of course he wants to keep the money, he traded correctly on what was apparently a correctly operating exchange and won. That's how this sort of gambling works.
MtGox screwed up. Why would they allow a transaction that crashed the exchange so easily?
If tomorrow it was discovered that the BitCoin protocol has been hacked and BitCoins are worthless, a rollback wouldn't be justified.
First up, who stole the bitcoins from whom?
Second, why allow trades that you know that you won't honour and will instead want to roll back?
Third, rarely the bank loses, why do they get a do-over just because they lost at playing at forex?
Allegedly one account with a lot of BTC was hacked. The Bitcoins were stolen from that account.
People on the Mt.Gox forums are sceptical because the amount traded appears to be equal to the entire Mt.Gox trading volume (from the little I've read).
The speculation is that it is either Mt.Gox himself/themselves, an account representing the entire volume of all Mt.Gox traders or some other buyer who has been in from the start and has somehow escaped the notice of the other traders (this last option also accounts for the ability to break in as the account security apparently was very weak and hasn't been forcedly enhanced).
If I was on a public IP, it'd be very hard for me to not sprint with that much coinage.
I had a thread last week on HN where I was downranked severely for asking what mt. gox was, i.e. if it was a mountain, in what was a sort of snarky, derogatory tone (I'll admit it). I would like that thread upranked now thx.
As long there is someone, somewhere willing to put up products or state currency in exchange for bitcoins, bitcoins will have their value. The best case scenario for bitcoin could be for MtGox to go down in flames because if it bitcoin held its value, it would prove that its fundamentals are sound, and its price is based on legitimate demand for an anonymous medium of exchange, not pure speculation.
If a MtGox collapse did cause a bitcoin collapse, it would show that bitcoin is not the real deal, just the result of a speculative frenzy. This may be hard to stomach, but it's better than continuing to ignorantly pile money into a bubble so fragile it can be popped by the guessing of a single password.
In my opinion this guy, if he really wants the best for bitcoin, should sue MtGox hard if he honestly thinks what they did is wrong/illegal/breaks contractual agreements. Let bitcoin sink or swim on its own merits.
Mt Gox doesn't do bitcoin trades (as in make tx in the main chain), they do trades inside of their own system and it's converted to btc when the user withdraws money. You cannot undo a btc tx (one in the block chain). Once confirmed, it's there.
[1] Based on a search for "bitcoin" on HNTrends, http://www.hntrends.dotcloud.com/
Bitcoin are just bits on a computer.
Just like piracy, when we copy bits from one place to another, is it really "stealing"?
Anyone that says "yes", better double-check their stance on software piracy as well.
I buy an MP3 from Amazon. I then copy it 'copy bits' over to another computer. Agreed, at this point all is fine. However, then I go try to sell the copied song for value to a 3rd-party. I may profess to 'own' the original download and the copy, however that doesn't give me the right to sell the song. It's the same with Bitcoin, if you just copied my Bitcoins, it's not theft in a sense, it's when you try to sell or exchange my Bitcoins for value that theft comes into play.
If I copy your file and the file is the asset then I don't deny you free enjoyment of that file. If you own the right to prevent me copying that file and are not disclaiming it then an unlawful copyright infringement has occurred. You and I both get to use the file, this is essentially why the file is not "stolen".
If I copy your file and the file acts as a token for a real sum of money, and I acquire that sum of money (be it virtual or whatever), then I deny you free enjoyment of that file. Once used to extract the value it tokenises the file no longer has value and so I deny you the value inherent in the file by my use of it. This is stealing. It may also be a copyright infringement in this case.
Compare the second action to using a one-use credit card number. If you copy the details off my one-use credit card number then you've more than likely acted unlawfully. If you use your copy to spend the money that those details represent then you've stolen from me.
Similarly, my password to my bank account is "just bits on a computer", but you could steal that from me, and take all of my [real] money. In that sense, it is theft. Piracy is copying, theft is moving.
Piracy: A has bits X. A wants to give B copy of X. B wants copy of X. Third party C (record label) objects. [A pirates a copy to/with B]
Bitcoin: A has bits X. A does not want to give B copy of X. B makes one anyway. A objects. Third party C (person who mined coins originally and willingly transferred to A) does not care. [B steals coins from A]
The two scenarios do not line up at all. In fact, if you made a bitcoin scenario that did line up:
Bitcoin': A has wallet X. A wants to give copy of wallet X to B. B wants copy of wallet X. Third party C (original miner of coins) objects. [A wants B to be able to spend his coins for whatever reason]
well, in the Bitcoin' scenario, I think almost everyone would agree that C has no moral authority to object.
Even though MtGox never stated they'd interfere, being hacked is unexpected enough to allow some leeway with follow-up. If the flashcrash happened organically, I doubt MtGox would revert the trades.
What of the repeated security warnings and downplaying by MtGox mentioned by the author of this post?
At some point it becomes willful ignorance, which usually leads to bad outcomes.
If they were hacked, it's their responsibility to make things right with the party that was hacked, and not interfere with anyone else's accounts/trades. Anything less does severe damage to faith in the exchange, which tends to lead people to only keep money and BTC in the system for as long as they need to to make a trade, and then pull it out. That's not good for the exchange or the economy.
Exactly. Trust and consistency are the foundations of a usable exchange. Without those two things, there is no confidence, and the house of cards falls down. Mt. Gox is acting in their own interest. They're changing the rules of the game as they go.
As much as I hate to use analogies, its the best way I can think to explain my reasoning. If someone (a hacker) robs a bank (user on MtGox), and they throw the money on the ground as they fleeing the scene of the crime, only for it to be picked up by bystanders (profiting users), what do you do?
To me, simply returning the money (rollback) seems to be the simplest effective solution. Maybe I'm being too utilitarian, but it seems too complex to add additional funds into the system, especially when we're talking about nearly 10% of the entire value of BTC. Additionally, it establishes a strange and dangerous precedent: hackers can get away with upsetting the market. And who can make sure the hackers & profiteers aren't working together?
I don't think there's really much you can do to repair faith in the exchange in the immediate future. More importantly, people will keep money as BTC the exchange if it is value is stable (or deflating). Even now, I'd be more worried about the market than hackers.
I'd love to see an insurance company spring up. It'd require major capital, but it'd really help strengthen the value of BTC by providing security and resolving nearly all of these issues. (Things I'd do with $1M...)