Fraud caused disappearance of 99% of Mt. Gox Bitcoins
the-japan-news.com
the-japan-news.com
Most likely, they had a hard time maintaining the right ratio of bitcoin/yen/USD to match the reality of their customer's deposits (through incompetency) and got hit hard when the "wrong" price fluctuations occurred... when this happened, and in which direction the fluctuation happened, I cannot say.
After that, they were deeply into a fractional reserve situation and thought "hey, we own a large part of the Bitcoin market, we can probably play the price a bit to make our customers whole again, without anyone knowing what had happened."
In this way, they gradually drifted from "cutting corners and doing the ugly things required to keep a business afloat" (aka mild, veiled fraud) into outright fraud.
How difficult is it to keep the right amount of bitcoin and USD in deposit? It seems pretty simple to me. Customer deposits $1.00, then I keep $1.00 in deposit in my business account. Customer deposits 1 bitcoin, I keep one bitcoin. The account for customer deposits will only ever be touched by automated systems processing these transactions.
If I'm charging fees as part of depositing/withdrawing/trading currencies or BTC, then those fees are immediately swept into a separate account, the entirety of which is revenue. Kept strictly separate from deposits. I'd regularly audit both accounts to confirm that the dollar amounts of each deposit/withdrawal, as well as total, match the records of actions in my systems.
Mt Gox only ever handled about 40 trades per second. Seems like you could keep everything balanced with a typical database, using transactions to implement atomic trades / deposits / withdrawals. Perhaps interfacing with money transmission systems is slightly more difficult, but once a transaction has reached the point of having probably-completed, you initiate the transaction to modify the customer's balance of bitcoin and currency.
So I guess I'm agreeing with you that if they failed in this way, they must have been incompetent.
P.S. I'm just making all this up. I've never worked in payments or accounting. I expect a good security or finance auditor could suggest much better controls. I'd pick up an "accounting for dummies" book and learn about the basic control principles used in accounting to prevent fraud. Perhaps I periodically download statements from my bank, print them out (or receive them in the mail) and audit those records against my own systems, by hand. Do the same electronically on a continuous basis. Set up an off-site write-only logging system to capture all transactions, and regularly audit to ensure that the system logs match bank transaction logs.
...but my best guess is their trading engine was so unstable that they ended up using one server to run a stripped-down clearance house algorithm for executing the trades as quickly as feasible, and a separate system that was the "source of truth" for how many physical assets in bitcoin/yen/USD were actually in possession by the company.
I'm guessing that there was absolutely nothing "atomic" about the system Marc Karpeles had built, their storage system was just an amalgam of disconnected, duct-taped databases living in different places, that were "kinda, sorta" in sync with each other, with lots of unpredictable, undefined behavior.
I bet Marc Karpeles had 5 people calling him at once that the trading engine was down again so THAT's where he put is efforts... He didn't get any calls from people saying "By the way, I hope you have robust auditing procedures."
Like some people live paycheck to paycheck, I'm betting the MtGox guys were living from critical bug report to critical bug report, without time for "luxuries" like "atomicity" or "database auditing"
(Let me say up front I am in no way intending for my comments to be a defense of the behavior of these criminals.)
[+] Unnamed employee of Tibanne, the parent company which supplied substantially all of 0-employee Mt. Gox's staffing: http://www.pcworld.com/article/2105920/lost-in-translation-t...
Maybe we don't block transactions on writing to the log, but whenever discrepancies are detected of more than a short time (transactions more than 60 seconds old not appearing), we page all founders and senior leaders. The trading engine stays up, but we draw much attention to the logging outage.
(I'd also want controls like offline wallets and accounts that would prevent an attacker from obliterating our assets in a single withdrawal)
You could call it the most total failure of accounting controls in history, if one had any reason to suspect that Mt. Gox possessed meaningful accounting controls. There was no reason to suspect this, but many people were willfully blind to that, because it appeared that Bitcoiners were making money hand-over-fist.
Edit to add: One reason Gox may not have done the math on the assets vs. liabilities is because they knew they were insolvent from some point in early to mid 2013, as a result of some combination of external events, including the since-reversed freezing of their US bank accounts. The clearest publicly available evidence of insolvency was persistent unwillingness to allow people to withdraw USD/etc and ludicrous excuses for why this was the case. (At one point, the CEO alleged that their daily wire volume had overwhelmed the second largest bank in Japan. This kind of claim is very useful because it is trivially falsifiable.)
Enron?
E.g. there's cheating on your general ledger (which at 50,000 feet might be the sort of thing Enron did), then there's not keeping a general ledger at all, which is being posited in this discussion.
Even I, who's never run a company, but did watch my parents run some while I was growing up, know how essential it is to keep a general ledger. Otherwise you have no real idea what your financial state is.
To be fair, you don't need a general ledger if you are setting up a website to trade playing cards. Say an Online eXchange for Magic the Gathering.
Every time an Mt Gox story comes up, the most incredulous thing to me is, why was anyone even expecting these guys to act like a bank? Why did anyone even consider trusting them with actual money?
Now, of course, at that level something as formal as a general ledger isn't quite required, but you still need to do the same things in e.g. watching the organization's bank balance.
I also suspect there were also more than a few people who trusted it implicitly because it wasn't a bank, they just assumed it worked because Bitcoin.
When you begin from the premise that the models followed by the financial world are at best obsolete and at worst a criminal facade, of course you might not bother referring to them if you start a business, or care to find out if an exchange follows the best practices of an industry you consider corrupt and useless.
I'm not saying this describes all bitcoin holders or Mt. Gox customers by any means, but the politics around Bitcoin do seem to lend themselves to an unwillingness to hold third parties up to any sort of standard.
In 2002, the firm voluntarily surrendered its licenses to practice as Certified Public Accountants in the United States after being found guilty of criminal charges relating to the firm's handling of the auditing of Enron, an energy corporation based in Texas, which had filed for bankruptcy in 2001 and later failed. The other national accounting and consulting firms bought most of the practices of Arthur Andersen. The verdict was subsequently overturned by the Supreme Court of the United States. The damage to its reputation, however, has prevented it from returning as a viable business, though it still nominally exists.
Mt. Gox had a financial control problem less complex than that faced by the typical supermarket. A supermarket has cash going in and out, multiple cash registers, multiple cashiers on different shifts, credit cards, checks, benefit cards, and automated checkout lanes. That's just the front side - there's a comparable operation at the back, where merchandise comes in and is accounted for. A big supermarket has a higher transaction rate than Mt. Gox did.
If a $10 bill goes missing in a supermarket, the management will know at the end of the day, and will probably be able to figure out where it went. This is routine cash control. It's a solved problem.
Mt. Gox had no financial controls; we know that from press reports. None. They don't even seem to have had a general ledger. This is rare in real businesses, but it's common in fraud schemes. Fraudsters don't want accounting controls, with everything they're stealing on the record.
Anyway, on Jan 3, we'll hear more. That this story came from the Tokyo Metropolitan Police is significant. The police haven't said anything until now, except that they were investigating. That silence has ended. Arrests may be announced. There's a good chance that Mark Karpeles is about to experience the standard 21-day interrogation used in Japan.
Not necessarily, differences are a daily part of working as a supermarket cashier. Most supermarkets have agreements with their employees (sometimes mandated by law), varying from full employee liability to full coverage by employer. It's actually quite common to have differences in your register, e.g. because customers let you keep small-ish returns or give "real" tips or you as cashier in a high-frequency environment make a mistake in sorting in a bill into the right compartment - or fraudsters trick you (http://www.weser-kurier.de/region/delmenhorster-kurier_artik...).
Of all their cashiers she had the highest "volatility", you might say, from day to day. That conceptually annoyed her superiors, but they loved her because she never made a big mistake, and her daily errors averaged out very nicely.
Even more fun fact: this is not the strongest statement one could make. The last number I remember citing for it was something on the order of two dozen not guilty verdicts, nationwide, out of about 125,000 prosecutions in a year, but don't quote me on that.
Does this answer your questions?
[+] I realize this sounds like the kind of story an Irish storyteller would make up to prove a point and feel that I must add "I swear by all the saints, by my hope of heaven and my fear of hell, this did literally happen."
That was good news, since it convinced a colleague he was overstepping his authority. I was released 5 minutes later, with an admonition to lock up my bike properly to avoid the scourge of foreign bike thieves plaguing Ogaki.
It should be as disquieting (or not disquieting) in Japan as it is in the US.
If it's absurdly high, or significantly higher than some comparable country, then you've got a problem - with a 99.9% conviction rate.
http://news.bbc.co.uk/2/hi/8290767.stm
Police can hold suspects for 23 days; those interrogations are private; Japan only recently re-introduced trial-by-jury (2009!); etc
Here's a nice 28 minite radio programme talking about the problems. http://www.bbc.co.uk/programmes/b01phktd
"Others have written with concern regarding the harsh secrecy provision in the statute which includes the risk of criminal penalties for those lay judges who would publicly share confidential deliberation room discussion even after trial proceedings are complete.:
I'm sure there's a lot more where that came from, plus of course as you note extreme deference would likely be paid to the professional judges. The above is from the end of https://en.wikipedia.org/wiki/Lay_judges_in_Japan
https://en.wikipedia.org/wiki/Yoshiyuki_Kouno
The investigation of the Tokyo sarin attacks, on the other hand, seems to have been carried out pretty much by the book and I'm not aware of anybody outside the tinfoil hat brigade who contests that they got the right people.
[1] http://www.nytimes.com/2007/05/11/world/asia/11japan.html?pa...
If I had a box, accepted apples and oranges, and would give them back to the owner if asked(taking some slices as payment fees, but at transaction) , at what point can things disappear? The only thing I can think of is race condition style things, but that's a single point of failure right?
Maybe I'm missing some complexity here
Karpelès having quite a trail of fraud and misconduct, I'm curious to learn the results of the Magic The Gathering Online Exchange investigation.
For those who don't know yet about the past of Karpelès, he started his career when over a disagreement with his employer he moved some of the company's clients' data over to his own servers, redirected a company domain towards one of his then resigned from the company. When the company confronted him, he refused to give back what he took and offered to buy the domain he stole, so the company went to court with Karpelès admitting he did it to the police but telling a different story on his blog [1]. With Karpelès not appearing at the audience because he had left the country he got sentenced in 2010 to 1 year of prison and 45 000€ in damage [2].
This is only part of a trail of lies, deception and fraud from Karpalès for his personal profit that has started to surface, we know have a blog he made in 2006 where he confessed of getting caught for a youth error of doing bad things with online payment systems for 2 years[3] or how he used lies to get money for a job he didn't do[4].
Of course that doesn't mean he did stole the coins, that's why I want to know about the investigation.
[1]: https://web.archive.org/web/20070630213730/http://www.magica...
[2]: https://www.documentcloud.org/documents/1238981-img-20140720...
[3]: http://web.archive.org/web/20140302234940/http://blog.magica...
[4]: https://www.cryptocoinsnews.com/exclusive-tibanne-co-ltd-sen...
I don't recall even the Mtgox haters bringing up any of the French backstory until not long before the end.
It's almost like there is a great irony in the fact that people who mistrusted government run banks sought an anonymous unregulated cryptocurrency and then immediately got ripped off because it's anonymous and unregulated.
What's one of these? It's the other way round - banks run governments.
I for one am just interested in its potential as a technology foremost; this isn't about mistrust of the government for me.