New message from Mt. Gox
mtgox.com
mtgox.com
So from that perspective, I'm not really mad about them losing the money. It's unfortunate, it even really sucks, but shit happens. Sometimes that shit is an apocalyptic event.
What makes me angry though is their utter failure to communicate, to admit what happened. I feel like they're taunting their ex customers, or at the very least they don't give a crap about anything at all. That's what's really off-putting, and that's what breeds speculation about them being the ones who perpetrated the theft in the first place (which I personally don't believe). Instead what we see here is an absolute non-message from them.
It's like this Seinfeld episode with the shirt at the dry cleaners. We know they shrunk it, they know they shrunk it, so they should just come right out and admit "we shrunk it"!
They were the market leader, with substantial revenue and lots of cash flow.
Why they didn't prioritize hiring some people and securing their platform is still beyond my understanding. It's up there with the $100+ billion in cash Apple is evidently not using to hire enough code reviewers or implement adequate security processes for their most important and sensitive code that supports their entire (massively profitable) business.
I really wonder where people's priorities are. They're not total morons; it must be an interesting reason why these circumstances happen. It's not hard to solve these problems with money - so there has to be a neat (if utterly dysfunctional) story behind it.
Seriously, guys. Spend $20 on a flu shot for your golden goose.
I imagine there's also a bit of outsider-preference going on here. There's no lack of people who could have been hired to implement controls and audits that would have easily caught a slow leak of coins, but they're part of the Obsolete Fiat Economy and thus irrelevant. "Dunning-Krugerrands", indeed.
That's a substantial generalisation. Some people, especially in software engineering, spend a great deal of their day thinking how best to prepare for theoretical risk.
In my job I do the very thing you describe. That said, I'm spending a lot more of my day preparing for the more likely risks, rather than the ones I can just dream up. I doubt many people here are posting from their bomb shelters full of emergency food and water rations, antibiotics, radiation treatments, either.
My point is that I could forgive the first lapse. Fool me once, and so on. But Mt. Gox had their precarious position quite expensively demonstrated to them. A competent management team would have made security and fraud management their top priority nearly 3 years ago when they were last caught with their pants down. It's hard to see them as victims in this because they were so negligent in their responsibilities to their customers.
It's naive to think that the more people you throw at the problem, the less bugs there will be.
See also: The Mythical Man-Month.
The intel agencies (both the ones where Apple lives, and all the other ones too) are black box testing this stuff, every single point release, automatically - you can be sure. Why Apple isn't is confusing. They wouldn't even have to be on the team or in the building with the development efforts themselves.
There's something we're missing here.
If you are saying "hiring more highly-skilled people to review the code won't work," then I'll disagree. App sec engineers can be had for the price.
[1] I say this despite the fact that this was a bug that leapt out at people who had no security knowledge. The one before this and the one after this won't be like that.
Oh, and unit tests.
Apple's mes sup is pure management goof based on culture same as MTGX
Have you ever read The Mythical Man-Month? These things are very hard to solve, no matter how many resources you throw at the problem. Sometimes, it's just a choice between quick iteration / innovation and bad bugs vs slow-release and less bugs. Since reliability is fairly difficult to assess above certain levels, people will pay for the new shiny, not for less bugs.
> They were the market leader, with substantial revenue and lots of cash flow.
Yes, but there are any number of examples where being the market leader breeds indifference and irresponsibility -- example Microsoft.
> Why they didn't prioritize hiring some people and securing their platform is still beyond my understanding.
It's likely they grew from a tiny operation to a very large one without anyone fully grasping the meaning of the change and adjusting to the new reality and taking the precautions that their new status demanded.
It's hard not to conclude that they outright lied. First it was malleability, then it was "we're waiting on bitcoin developers," then it was "we've moved due to protesters and security problems," and now it's "we've closed our site due to recent news reports."
I wonder when precisely they realized that >700,000btc were missing.
Once they stole the 700,001st bitcoin?
>I wonder when precisely they realized that >700,000btc were missing.
Stating the obvious, but it didn't occur all at once. If my speculation bears any resemblance to reality, it would be interesting to know when MtGox' solvency tipped past any chance of recovery, and how long Kerpeles has known that to be the case. I'm thinking that a year or more may have passed.
...
... I shrunk it.
Edit : Here's the link : http://www.reddit.com/r/Bitcoin/comments/1x9gue/my_protest_a...
What if Mt. Gox didn't really lose a post-Panamax boatload of Bitcoin (just a small amount)? They're just manufacturing a panic so they can buy Bitcoins at fire-sale prices, declare "We have all the BitCoin we need after all, we fixed our bug, everything's fiiiine" and maybe even turn a cash profit on the upside?
</conspiracy theory, assumes a modicum of competence, etc>
They could actually have lost the bitcoins. They could be still having technical problems.
Fennecfoxen's theory could be illegal market manipulation, but I wouldn't be surprised if the BTC market is weird enough that it doesn't fit under the laws against that. Or at least that it'd be such a mess to prosecute that prosecutors would all find something better for their careers to do.
Market manipulation in general isn't illegal, so it would basically boil down to if the SEC considered BTC a currency or not.
I don't know, but I don't think so. For the law you may be trading in monopoly money at your risk.
So Kome I'll make you a deal, I've got a ownership title for the Brooklyn Bridge and I'll trade this title to you for a case of beer... deal? Deal. Sucka. Then it goes to court. Assuming you can convince the court I knew the title was fake, and the case of beer is worth more than the fake title (maybe the title has artistic merit, or maybe the beer was worthless American Lite "beer" of negative worth) then its pretty cut and dried as fraud.
But its still probably illegal just about everywhere.
Should there be the same laws kick in if they drive the price up, by say, adding fake orders on their exchange? I don't even think that should be illegal.
The market should move as it moves, through whichever means: fairness, deceit or ruse. I wouldn't want BTC any other way.
I strongly agree, and I do believe that there's price manipulation going on with the Gox situation at the moment. Is it just an attempt by Gox to make some money back? Or is it something far bigger aimed at damaging the reputation of BTC? Don't forget that Karpeles has recently been vulnerable to manipulation from the USG [1].
But It's surprising that you wouldn't want BTC, when on the road ahead lies Open Transactions, distributed exchanges, and so much more innovation that will take your above statement and put it directly into code. Thus making these wall-street tactics obsolete.
[1] http://thegenesisblock.com/warrant-for-mt-gox-wells-fargo-ac...
So here is a fun exercise, think of bitcoins as soda cans and rethink the whole situation.
It's likely the unregulated nature of Bitcoin that makes this easy to do. After all, who is going to chase down market manipulators with search warrants and wiretaps?
What I don't understand is why people would continue selling at any reasonable volumes at firesale prices when other exchanges are doing "fine" (Bitstamp down ~25% vs 2 months ago). Unless I misunderstand it, the malleability bug won't prevent sending btc to other wallets. Is mtgox going to block their users from sending btc and only allow them to sell internally? That would be pretty much equivalent to seizing all their users' coins. Is it just the combination of lots people who own small enough amounts of btc not to care going "fuck it, I just want out"? People not trusting other exchanges after this, or betting that other exchanges will crash too before they can get accounts verified at them and sell their coins?
The people holding bitcoins will get nothing.
So, even ignoring the Bitcoin, they lost quite a lot of dollars.
Weren't a number of Mt. Gox's bank accounts already seized for other reasons? Before the loss of bitcoins issue, wasn't this already a source of concerns about Gox's viability?
That's only relevant if you can move your bitcoins to a different exchange. If your bitcoins are held with MTGOX and you're able to run a transaction that extracts any value then that's better than the potential case in which MTGOX simply declare all bitcoins have gone and close all accounts.
I posted this idea a few weeks ago (IIRC) - basically if MTGOX could crash the price then they could buy the bitcoins at a lower price; make an announcement that they're now fine, rebound the price and then afford to cover losses and possibly make a profit too.
It strikes me that's not moral, though some may consider it so, but it's probably not illegal to manipulate "toy" currencies. In the financial sector it seems it's only really considered wrong to fix real ones if you get caught.
"For your convenience, all your Bitcoins have been deleted."
"Dear MtGox Customers,
In the event of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly.
Best regards, MtGox Team"
Way out there, but it's anyone's guess right now, and I thought I'd throw this hat in the ring.
> We will be closely monitoring the situation and will react accordingly.
As if they're just sitting back, staring at their screen, waiting to see what will happen. Passively.
That passive voice is maddening!
"Because people discovered that we lost or stole money, and that would destroy our operations, someone who doesn't want to be responsible for making a decision decided that we could try causing a market crash by dramatically wiping our accounts, lowering the price enough that we could buy our way back to solvency. It didn't entirely work, so we're making this announcement, which is also meant to lower the price, or if that doesn't work, allow us to segue back into operations. We will be monitoring the Bitcoin price and will react accordingly."
The second time you visit the page, you'll get your cookie-stored statement.
Almost seems like they want to be able to change their statement without previous visitors seeing the changes.
<html> <head> <title>MtGox.com</title> </head> <body> <p><img src="/img/mtgox_logo_mail.png"/></p> <p>Dear MtGox Customers,</p> <p>In the event of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly.</p> <p>Best regards,<br/> MtGox Team</p> </body> </html>
<html>
<head>
<title>MtGox.com</title>
<script type="text/javascript">
var AKSB=AKSB||{};AKSB.q=[];AKSB.mark=function(b,a){AKSB.q.push(["mark",b,a||(new Date).getTime()])};AKSB.measure=function(b,a,c){AKSB.q.push(["measure",b,a,c||(new Date).getTime()])};AKSB.done=function(b){AKSB.q.push(["done",b])};AKSB.mark("firstbyte",(new Date).getTime());
AKSB.prof={custid:"223233",ustr:"",originlat:0,clientrtt:19,ghostip:"23.51.248.44",ipv6:false,pct:10,xhrtest:false,clientip:"130.223.174.194"};
(function(b){var a=document.createElement("iframe");a.src="javascript:false";(a.frameElement||a).style.cssText="width: 0; height: 0; border: 0; display: none";var c=document.getElementsByTagName("script"),c=c[c.length-1];c.parentNode.insertBefore(a,c);a=a.contentWindow.document;a.open().write("<body onload=\"var js = document.createElement('script');js.id = 'aksb-ifr';js.src = '"+b+"';document.body.appendChild(js);\">");a.close()})(("https:"===document.location.protocol?"https:":"http:")+"//aksb-a.akamaihd.net/146060/aksb-a/aksb.min.js");
</script>
</head>
<body>
<p><img src="/img/mtgox_logo_mail.png"/></p>
<p>Dear MtGox Customers,</p>
<p>In light of recent news reports and the potential repercussions on MtGox's operations and the market, a decision was taken to close all transactions for the time being in order to protect the site and our users. We will be closely monitoring the situation and will react accordingly.</p>
<p>Best regards,<br/>
MtGox Team</p>
</body>
</html>
This is very odd behaviour. <html><head><title>MtGox.com loading</title></head><body><p>Please wait...</p><script>function xdec(data){var o="SOME_RANDOM_BASE_64_THAT_KEEPS_CHANGING";var o1,o2,o3,h1,h2,h3,h4,bits,i=0,ac=0,dec="",tmp_arr=[];if(!data){return data}data+='';do{h1=o.indexOf(data.charAt(i++));h2=o.indexOf(data.charAt(i++));h3=o.indexOf(data.charAt(i++));h4=o.indexOf(data.charAt(i++));bits=h1<<18|h2<<12|h3<<6|h4;o1=bits>>16&0xff;o2=bits>>8&0xff;o3=bits&0xff;if(h3==64){tmp_arr[ac++]=String.fromCharCode(o1)}else if(h4==64){tmp_arr[ac++]=String.fromCharCode(o1,o2)}else{tmp_arr[ac++]=String.fromCharCode(o1,o2,o3)}}while(i<data.length);dec=tmp_arr.join('');return dec};document.cookie=xdec('MORE_RANDOM_BASE_64_THAT_KEEPS_CHANGING').replace(String.fromCharCode(0),'').split('').reverse().join(''); location.href='/';</script></body></html>Or so it was when I posted my earlier comment.
I learned something today.
Madoff isn't dead, but he is in prison.
Beyond that, CEO's of large companies are generally under guard when the crap hits the fan, and Madoff was protected by police.
I wouldn't be surprised if the "CEO" of Mt. Gox soon finds out what a tire iron tastes like.
Madoff swindled the rich iirc.
The rational interest of a criminal here wouldn't be revenge. It would be reputation maintenance. The reason mafia loan sharks are known for breaking kneecaps isn't that they're personally upset, or that they can't afford the loss. It's that they can't afford anybody else thinking that their loans are something they can walk away from.
"The government provides protections" != I can completely trust my contracts to work because of it".
Though the idea of making a pile of hard drives and setting that on fire sort of intrigues me...
"In April 2006, fugitive Mafia boss Bernardo Provenzano was captured in Sicily partly because some of his messages, written in a variation of the Caesar cipher, were broken. Provenzano's cipher used numbers, so that "A" would be written as "4", "B" as "5", and so on.[11]"
http://en.wikipedia.org/wiki/Caesar_cipher
And this wasn't just some bozo, but a Mafia boss who was certainly into a lot of different "lines of business":
So your biggest crooked customer has a balance of 10% of your net liabilities. And someone steals 1/3 your net worth so you're basically outta business and the biggest crook on the planet just took a 1/3 haircut, which he's not going to be too happy about.
You tell the biggest baddest gangster of a customer, you can more than triple his current balance at the mere cost of guaranteeing your personal safety in perpetuity and having a crony of his and a crony of yours re-enact the 1/3 theft. After all, you just figured out what happened, and its not going to be too hard to arrange for it again two more times.
So that leaves the biggest crook in the world in debt to you, a fat bank account, and lifetime guarantee of protection from said crook.
Do some deals with the crooks competitors to make sure they know he gave you his word, so if he ever goes back on it they'll never trust him again. Or run the same scheme three times and make sure the top three crooks know that the enemies of the guy who kills you off are going to split your fortune if you croak.
Or lets say you make "all" the BTC disappear but you actually have enough control to reimburse every player big enough and criminal enough to actually hurt you, with millions left over for yourself.
Your biggest customer is about to get powned as a money launderer by the DEA/IRS and his only legal hope is to make your records look untrustworthy. Would any court of law trust MtGox's records after today? I guess there's no proof anymore that some bad guy was about to get powned. Well, there's an easy way and a hard way to do that, at least WRT collateral damage to the execs family members. And if you still tangentially somehow have control of the "lost" money, nobody important need actually hold a grudge.
I'm not saying any of this is true or even possible, although it could be the plot of GTA:7 or similar. These are better hollywood movie plots than the formulaic dreck we're forced to endure.
I'd watch this movie(s).
It reminds me of something out of Heinlein's Friday.
You might want to wait for something resembling actual violence before applying such an ugly characterization. A bunch of people saying mean things is not a "lynch mob".
I'm not being hyperbolic.
Personally, I put my coins in BTC-e, Virtuex, and CoinBase (and thank god I did). Even though BTC-e and Virtuex seemed fairly sketchy they still allowed me to withdrawal my coins with no issue.
For an organisation which is insolvent they must have invested a fairly significant sum on a 3 letter .com domain. This happened yesterday! What's going on here?
"Should" based on the assumption that they are profit-maximizing entity, or "should" based on the assumption that they are a moral actor? Because, you know, the answers are quite different.
I didn't have bitcoins in the system, but I did have a couple hundred dollars. Completely negligible amount and it doesn't really affect me to lose it, but it would be convenient to get it back.
This message is likely worse than staying silent.
You may be right that they are incompetent and it shows, but it doesn't necessarily follow that the answer is to right now immediately hire a new team and let them handle it.
This statement inspires absolutely zero confidence and trust at a time when both those things are necessary at some level.
Yes, but they cared about their user's bits.
Maybe there is a faint glimmer of hope for gox... (I personally doubt it)
Turns out I was too smart for my own good. Almost every ponzi scheme can be exploited _if_ you get on board early enough.
At the current stage of bitcoin only suckers are left holding the bag. Of course no one will see it, because "Mistakes Were Made (But Not by Me)" (its a book, read it).
You're misusing the term "Ponzi scheme". A speculative system that relies on volatility and wishful thinking isn't necessarily a Ponzi scheme (might be but not necessarily).
A classic Ponzi scheme has layers or levels that are treated differently. Ordinary speculation about a volatile entity doesn't have this property.
http://en.wikipedia.org/wiki/Ponzi_scheme
Quote: "Typically, extraordinary returns are promised on the original investment[5] and vague verbal constructions such as "hedge futures trading", "high-yield investment programs", or "offshore investment" might be used. The promoter sells shares to investors by taking advantage of a lack of investor knowledge or competence, or using claims of a proprietary investment strategy which must be kept secret to ensure a competitive edge."
That's the price of anarchism.
Of which recent news reports are they talking about?
Perhaps the leak was fake, so gox shut down to prevent people panic selling