Bitstamp is open for business
bitstamp.net
bitstamp.net
There's nothing really here about what happened or how they have mitigated it. Perhaps it's too early and they don't really know, but then isn't going back live fairly risky?
Aside from a persistent firmware threat, which has nothing to do with the attack vector, I don't see why "yay we're on AWS now" is any different unless they know the compromise was due to a specific piece of infra which is no longer present. Isn't it much more likely to be a bug in their software logic which would certainly not be fixed by restoring a backup...
The investigation continues in parallel. First priority was safety, which meant shutting everything down to prevent any additional issues or destruction of evidence. Second was giving people the ability to access their funds and to trade - a complete redeploy of the infrastructure which took us working 22/7 since Monday until just now.
An investigation is underway and we have some internal speculation from the first bits of information - the real statements will come after we aren't guessing. This is the first minute we've had to breathe this week.
i.e. why did you decide to restart when you haven't determined what caused the safety issue?
I'm confused - "an investigation is underway" - and investigation as to how they got in? or WHO did it?
I wish I knew more specifics about this situation but I'm starting to feel that you guys rushed the relaunch of the service post-intrusion.
The original presentation was given in 2010.
If a real stockbroker lost funds like that, and became insolvent (debts > assets), they would have to stop operations immediately. In some jurisdictions it is a felony for a broker to continue to accept funds once insolvent. They don't get to "fix it later". That's because, historically, the temptation to fix it by speculating with customer funds has been a big problem.
Bitstamp now needs a full audit by an outside auditing firm.
Their fees are roughly 0.4% on a transaction. But note, the fees are incurred twice per unit of volume. i.e. they pair a buyer and a seller, who both pay a fee, thus you get a 0.8% fee on any unit of volume.
So we end up with a very rough revenue of $20m a year. Of course there will be various costs, but I've seen most exchanges run with teams of 6 core people, with another 6 or so support staff. I wouldn't expect to see much larger teams than 20 at Bitstamp, and given their cost-center for development is in Slovenia, I doubt you'll see them average more than $150k, which would be $3m per year.
So, together with $10m in funding not so long ago, together with substantial revenues ($10-20m per year), and together with the fact it's quite likely we're talking about early adopters (Company was founded in 2011, the year of 30 cent bitcoins, 1000x cheaper) who likely could pay this out of their own pockets, do they have what it takes to cover $5m? I think so. On that last point, if they had $5k of bitcoin when they founded the company, that'd be worth $5m today, and over $15m a year ago, for perspective. It's not at all unlikely they're sitting on $30m, but rather build a company where they offload their entire risk and give up 30% of equity. Who knows.
Does that mean an audit isn't necessary, not at all. It should be standard practice. Just speculating here on whether I think an audit would show a positive result or not, I think it would.
The fact that they didn't do something like this and release it along with this statement makes me rather suspicious. It's not like they don't know that this is the first question on every single customer's mind.
[0] http://www.crunchbase.com/organization/bitstamp
[1] not a guaranteeThe Bitcoin exchange business has low commissions, and they're heavily discounted for big traders. Sometimes all the way to zero. It's hard for an exchange to raise prices. So exchanges tend to look for other ways to make money. Those ways usually aren't good for customers. Trading on one's own exchange and front-running are tempting. Mt. Gox probably did that; many users observed that, during busy periods, trades did not appear to be first in, first out.
That's why no major financial firm has entered the Bitcoin exchange business. It's not very profitable.
Their volume and bitcoin prices were crazy high a year ago, I estimate they made around $6-10M.
And the amount of bitcoin transactions has only grown since 2013. e.g. the record highest number happened just yesterday. Or compare wallets at the top bitcoin company right now which verifies users and bank accounts, Coinbase, which was at 700k wallets this time last year, now at roughly 2 million. Another 300 million of VC money was invested since 2013 into the bitcoin space.
I mostly agree on your larger point regardless, big traders get discounted (any source for that from any particular bitcoin exchange, btw?) and exchanges are definitely not gold mines right now. Look at Vault of Satoshi, just closed. It ran well but it just wasn't bringing in the type of revenue they could with the amount of expertise they had on board. They've switched focus to a Netflix app. But comparing 2012 Mt. Gox to 2014 says quite little, we're talking about a trainwreck of a company here in an industry that's seen 1, almost 2 orders of magnitude growth since 2012. If price is a good proxy (not really great, but sorta ok), the fiscal year in which Mt. Gox made the $1.3m revenue / $300k profit started with a bitcoin price of less than $5, for perspective. Things have grown somewhat since then.
Huh, what?
Deleted comment
I was also called a complete fool by someone on HN just before I lost my money. The comment made me angry. Me, a fool? Yet it was true, and I should have listened.
Run away, don't walk. They lost 5 million dollars. Let that sink in before deciding to trust them with any money you care about.
5 million dollars is about the same as a Series A round. They lost the equivalent of an entire company of programmers. You could employ 50 programmers for one year with that amount of cash. And it was precisely your money that they lost.
For all you know, this could now be a game of "musical chairs" where the last person to withdraw money from bitstamp will be left wanting. Don't let that be you. Guard yourself.
By the way, Mt. Gox lied through their teeth to me, all the way up until their service shut off. Leading up to the disaster, I was in constant communication with their support staff, and they were very reassuring. "No, of course no one will lose money. Withdraws will reopen soon." Too bad the support people were themselves being lied to by Mt. Gox management.
So, no, a statement by a bitcoin service isn't worth the weight of the paper it's printed on.
EDIT: It's distressing that HN downvoted the parent comment to the point where they felt like deleting it. Please try to downvote less in general. The parent comment was simply relaying Bitstamp's statement.
(And, no, they don't get to do "fractional reserve banking". They're not a bank, and they don't have loans as assets.)
I don't mean to suggest that they are not solvent; I am only pointing out that the language doesn't seem to perfectly answer the question.
Real talk.
Simply put, it's pretty much assumed based on volumes and fees that they make that much profit anyway, but there are also things such as recapitalization.
5 million is not a nail in a coffin for a Bitcoin exchange.
Lastly and honestly, if these assumptions are wrong then assuming Bitstamp wants to continue business it would be easy to raise the money on slightly less favorable terms given the distress/desperation (assuming the previous assumptions prove false).
Unless you're speaking as a founder in the field, I'm finding this hard to believe. Five million dollars is about an entire Series A round. Or at least half of one. And a Series A round is supposed to last multiple years. Or at least a whole year. It's not chump change.
And I've heard you're going to have no luck raising money at all if investors catch wind that you need it to survive. "Slightly less favorable terms" probably means the deal doesn't happen. See e.g. http://paulgraham.com/pinch.html
But I have no experience at that, so I admit I'm going off of hypotheticals and what other people say.
EDIT: Also, that's five million dollars at current BTC prices. Bitcoin has only recently fallen to $300/coin. It was $600/coin not to long ago.
I, for one, am glad to see a Bitcoin story turn out with a somewhat positive outcome, at least from the users' perspective.
That said, the article says a breach resulted in the loss of ~19,000 BTC, or around $5.6 million. If they're honoring all user funds, does that mean they are just eating that loss out of their own profits, and perhaps try to file an insurance claim? Or were they actually responsible enough to set enough profits aside in cold storage self-insure the total amount floating in the "hot" wallets? On that note, I wonder if profits and hot wallet demands scale proportionately or not, or if their margins are just at a scale where this is a non-issue?
Yup.
There will be lots of parties interested in that information.
tldr: back of the envelope calculations show that they must have made more in profit to-date.
What isn't mentioned often is that I suspect they're personally somewhat rich, too. i.e. they were two people into bitcoin in 2010, started the company in 2011. Even if they didn't invest in 2010 which they likely did, in 2011 the price was still in the pennies. A $5k investment then would've been worth $5m today, or $15m just a year ago. Between the two of them, I don't think it's unlikely they've got quite some millions stashed away. And given they've had a $10m investment not too long ago (with a valuation in the tens of millions at least. e.g. Coinbase and Bitpay both have $150m valuations at $30m invested) it's not unlikely they're burning VC money or their own money just to cover these issues and keep an otherwise potentially very valuable (long-term) company afloat.
Mix that with 2 years of not unsubstantial fee collecting and a cheap cost center in Slovenia for the vast majority of their development work, and I think it makes a lot of sense that they can pay this off.
Of course all of this is speculation. The crazy thing is that bitcoin is so young and nascent that we don't even have basic oversight. For all we know the two co-founders could have stolen $5m from their customers, said it was a hack, and continued happily knowing they don't have to work again for the rest of their lives if something happens. Of course this makes no sense seeing as they fronted the loss, but this notion that we are assured by that, rather than say an audit, oversight, blockchain analysis etc, is a reminder of how far bitcoin has to go still.
In addition to operational costs probably fraud is also a big cost, but it is very difficult to estimate how big it is for them.
And, they don't exactly need to take it from their profits, they can just do fractional reserve... They are a bank, as are any bitcoin services that hold money for the users.
Nine months ago it was sub 0.1%. Three months ago it was sub 1%. Today it's over 6% and growing rapidly.
Multi-signature is just one example of potentially radically improved security versus the single key methods we had before.
We've also seen in the past 6 months 3 companies come out with proper insurance. Circle, Xapo, Coinbase. All at a sub 1% cost. (Coinbase and Circle free, Xapo I think 0.12% annually). Combined with multi-sig vault products from Coinbase, which has done a lot of interesting security stuff. (the basic 2fa stuff of course, but I think also things like finterprinting devices to detect stolen credentials from users.)
And with that, we're also seeing enterprise-products come out which offer bitcoin management in a secure way. I wouldn't be surprised if such a company like BitGo starts marketing insured warm wallets to exchanges on a percentage cost basis, and let exchanges offer users to pay for the option of this insurance.
And we've seen more steps taken regarding the bitcoin ETF on the NASDAQ, which settles manually twice a day and allows (industrial) trading and liquidity but gets rid of the issue that Bitstamp and everyone else has: running a warm wallet on a server that automates transactions. The vast majority of Bitstamp's coins were in cold storage, but if you want to run automated transactions you can't do it on cold storage.
So this period has definitely been a turning point I think. Will be interesting to see things develop the next few years.
That's a nice way of saying "we're out five and a half million USD"...
http://www.coindesk.com/194993-btc-transaction-147m-mystery-...
If I understand it correctly it means money can not be withdrawn without both the account holder and bitstamp signing the transaction. This means that neither can the money be stolen by hackers, nor could bitstamp run off with it. There are actually some bitcoins in the real blockchain "with your name on it", as opposed to you just having a claim on bitstamp.
In addition, this would require the user to be online and actively sign transactions when a matching order is found.
I think that they most likely meant that they're using multisig internally to protect their funds, in a setup where all the keys are controlled by them.
Source: I am a Bitgo retail customer, but I don't have access to an enterprise account and cannot comment on their Bitstamp integration.
It sounds more like, it means it's possible given the necessary end-user configuration to enable multi-sig, not that all coins are already benefitting from that level of protection.
http://oi60.tinypic.com/20sj3b9.jpg
PS: Still wondering why they use Apache instead of Nginx which is more efficient/robust/secure
The difference is securing bitcoins in high-risk environments: live automated servers. But that only goes for a small minority of bitcoins as only about 0.5% of bitcoins are traded on a daily basis, the rest can be in what is called cold-storage which is way, way easier to secure than a bunch of physical money, gold, diamonds, whatever. The 0.5% is a bit like the security of wallets in people's pockets: not very good and not comparable to bank-grade security of those same people's savings in a bank. Or comparable to lone ATMs which can be raided.
Beyond that, bitcoins exist on an open ledger. While it may be hard to trace that now, we're seeing blockchain analysis tools develop all the time. Who knows what they might uncover later? I certainly wouldn't be excited as a criminal to leave a permanently recorded trace of every single transaction ever since the moment of the theft, with the prospect of decades of cheap supercomputers doing analysis of this open source data set which might reveal yourself. Bitcoin is great for pseudo-anonymity when buying por n online, but it probably won't stand the test of time in protecting you from every criminal investigation, a bit like a randomly generated pseudonymous email address gives a large extent of privacy, but not if you're a criminal.
1) Don't let anyone find the private key
2) Don't let yourself lose the private key
The more of 2 you do, the harder 1 gets and the more of 1 you do, the harder 2 gets. If you have only a single copy on paper, it's hard for anyone to find, but also easily damaged or lost. If you make a backup on a computer, a virus might find it, making the paper copy worthless.
Not only that, but from the moment you generate the key, you have to be completely confident about the security of the computer you're using. People recommend a clean install of OS from the original CD and never connecting to the internet. That's not impossible but not easy, furthermore you have to carefully destroy all record of it left on that computer. So unlike gold, not only do you have to keep it secure in the future, but you have to have made sure that it was always secure throughout the past. You can't transfer ownership to anyone else without them going through the same rigmarole too, unlike gold which you can physically give to someone and they can be confident it won't evaporate in front of their eyes one day.
I agree with you about blockchain analysis. Who knows what new techniques might be able to dig up. They might not have much certainty but perhaps enough to put suspicion on someone.
It would be interesting to watch where that money is moving and how the thief goes about anonymising it.
http://blog.cryptocrumb.com/2015/01/bitstamp-theft-bitcoins-...
BTW, in that title, the word 'spent' is used in the formal sense for blockchain transactions. It doesn't mean the money is gone or ''used up'. It really just means 'moved'.
After reading that, it looks like the person who stole this money is actually panicking and making a lot of dangerous mistakes. I guess they are in a state that's between terror and ecstasy. I doubt they had any sleep recently, and they're going to be looking over their shoulder for a very long time.