22 ms·
BitFinex down due to Bitcoin security breach - 120k BTC stolen
- f_allwein 10y agoOh dear - this should be interesting. Seems like it is good advice not to invest more in Bitcoin than you can comfortably lose...
- ryanlol 10y ago>Seems like it is good advice not to invest more in Bitcoin than you can comfortably lose... Not losing bitcoin isn't any harder than not losing cash. Problem here is people storing their coins with unqualified third parties.
- mikeash 10y agoI'd say it's a little harder than not losing cash. If you put cash in a safe, you can be confident that an attacker can't take the cash without getting into the safe. If you put bitcoin in a safe, an attacker can take it without ever getting into the safe if you happened to forget about a copy of your private key somewhere else.
- ryanlol 10y agoSurely you would generate a new key to put in the safe if you had to worry about that. And anyway, robbing safes is easy. But try emptying a bitcoin wallet encrypted with a good password, it's very easy to make impossible.
- russelluresti 10y agoNothing is impossible in the digital realm. And the bad guys are ALWAYS better than the good guys.
- mikeash 10y agoSurely, but that requires more knowledge and care than securing cash.
- ryanlol 10y agoProducing a long random string to use as a password? Not particularly.
- mikeash 10y agoMost people have no idea what a long random string would even look like.
- ryanlol 10y agoI think you're seriously underestimating most people. "Long random string [of letters and numbers]" is rather self-explanatory.
- mikeash 10y agoI think you're seriously overestimating most people's ability to think when presented with anything remotely computerish.
- bdcravens 10y agoDealing with nondevelopers, never say "string". Did that once and the person on the other end of the phone was obviously confused. After 2 seconds, realized how bizarre it sounded.
- bdcravens 10y ago> a bitcoin wallet encrypted with a good password, it's very easy to make impossible There's the problem with adoption. "SFYL you should have been smarter" means there will always be a % of the population who should never use it.
- russelluresti 10y agoNot quite true. If you're talking physical cash, a person would have to get to the physical location to take it (as opposed to being available to everyone in the world with an internet connection). If you're talking digital cash in a bank, most banks have a form of insurance that will cover your losses (for example, most US banks are FDIC insured and cover up to $250,000 USD in losses). Stock assets may be the closest comparison, as brokerage firms aren't backed by an independent agency, and losses that occur from cyber-theft would only be reimbursed if the firm wanted to.
- jzwinck 10y agoStock trading accounts in the US are backed by the SIPC up to $500k (even for non-US persons). This protects you from an all-out insolvency of the institution, which would happen if somehow they had all their money stolen by hackers. But it does not protect you from hacking of your individual account. If someone tricks your broker/custodian into selling your stocks and wiring them the money, SIPC (perhaps surprisingly) will not save you. See: http://www.reuters.com/article/us-investing-hackedaccounts-idUSTRE8151UN20120206 http://www.reuters.com/article/us-investing-hackedaccounts-i...
- Lerc 10y agoHow does one determine a qualified third party? Obviously you can't go with "You can trust us, we know what we're doing" You could find a party that is endorsed by someone going "You can trust them, They know what they are doing, Trust us on this, we know what we're doing" But that just moves the point of concern. Is there yet any "You can trust them, if we are wrong about that we will cover your losses" insurance. (even then how can you be certain they will follow through)
- sixhobbits 10y ago"quis custodiet ipse custodies" (who guards the guards themselves) by Juvenal in the first century seems to be the root cause of so many modern issues - from finance, to politics, to automatic server monitoring.
- ryanlol 10y ago>How does one determine a qualified third party? Surely you wouldn't store your cash in a bitcoin exchange? It's not a bank. With bitcoin you don't even necessarily need a third party, a hardware wallet could do just fine. That can be stored in a safety deposit box if you feel like it. >Is there yet any "You can trust them, if we are wrong about that we will cover your losses" insurance. (even then how can you be certain they will follow through) While you can certainly insure anything if you pay enough, I don't think there's anyone publicly offering that in the crypto space. But then there doesn't seem to exist a similar mechanism for USD accounts of any significant size either.
- viraptor 10y agoIt is good advice not to invest more in anything than you can comfortably lose.
- flashman 10y agoSeriously, even gamers playing Eve Online know this.
- mrb 10y agoMore details: https://steemit.com/bitcoin/@pseudonymwriter/bitfinex-hacked-here-s-what-we-know-so-far https://steemit.com/bitcoin/@pseudonymwriter/bitfinex-hacked...
- deleted 10y ago[deleted]
- abstractbeliefs 10y agoAs much as the joke about bitcoins "take the money and run" exchange business model is bandied about, how do people actually suggest securing exchange wallets? I'm sure it's talked about, but I've never really found a straightforward explanation of how it should be done - is there even an agreed upon set of best practices? If so, why are these supposedly sophisticated exchanges not able to successfully apply them?
- ikeboy 10y ago1. Have a cold wallet on an airgapped computer with 99% of your funds. 2. Have a warm wallet on a computer with a firewall that only connects to 3, with 1% of your funds 3. Have a web-facing server that sends back commands to 2 when it needs to send money. 2 alerts someone when it needs more money, who then goes to the cold wallet and transfers some, creating the transaction offline and using a new USB key to transfer it to a computer with internet. The last step can also require multiple people if desired.
- robryk 10y agoWhen that person goes to the cold storage wallet, the only trustworthy information they have (assuming compomise of the online system) is how much money they are transferring. This means that this arrangement succeeds at making a trustworthy rate limit and nothing more. If I wanted to make a trustworthy rate limit, I'd have the machine from (1) not airgapped, but connected by a serial (unidirectional) line to the machine from (2) along which it would periodically send signed transactions sending some of the money from "lukewarm" storage to hot storage, and sending change back to the very same "lukewarm" storage address. The machine from (1) can then implement a rate limit.
- ikeboy 10y agoBut then a compromise of 2 and a zero day remote attack can exploit 1. 1 is offline so no attack not involving insiders can affect it. Edit: actually nvm, didn't get the part about unidirectional. I don't deal with networking but I assume that's possible physically and there's no way to reverse the flow?
- Artlav 10y agoTime to buy. :) Seriously, there is a curious coincidence with the BTC-driven pump and dump currently going on at the Etherium's dead chain. Another curious coincidence is that the price started falling before the closure, as if someone did some insider trading.
- Kinnard 10y agoSources?
- mountaineer22 10y agoYour comment reminds me of this: https://en.wikipedia.org/wiki/Dow_theory https://en.wikipedia.org/wiki/Dow_theory
- sushid 10y agoTo be fair, the price of BTC has been falling this week because of the BTC miners' meeting about possibly increasing the block size (yet again).
- deleted 10y ago[deleted]
- mikecke 10y agoCommentary from my part: Bitfinex uses BitGo for multi-signature (MultiSig) transactions. 2-of-3 signatures must be present for user funds to be released. Keys present: - Offline key held by Bitfinex - Online key held by Bitfinex to initiate user withdrawals - Online key held by BitGo to confirm user withdrawals are within constrained limits in a set timeframe zanetackett, Product Development of Bitfinex, confirmed that Bitfinex's offline key was not compromised. The attack was also not internal [1]. Another set of comments also suggested that BitGo limits were set in place by Bitfinex [2-3]. The automatic limits are designed to constrain BitGo from signing any transaction from Bitfinex that are irregular in volume or exceed a set amount in any rolling timeframe. Somehow they were bypassed. What we have currently suggests that the limits were too large or that BitGo was not enforcing the limits. BitGo and Bitfinex are also separate established entities, so that both of them being compromised for this attack is unlikely. An improper setup between Bitfinex and BitGo is more likely. [1]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_security_breach_trading_will_be_halted/d61pc44 https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se... [2]: https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_shows_movement_out_of_multisig_wallets/d61paqy https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_sh... [3]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_security_breach_trading_will_be_halted/d61qkll https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
- biggerfisch 10y agoHas it been verified that BitGo's key was not simply compromised? As unlikely as it may be that both online keys could be compromised, it certainly seems that it could have happened (perhaps while it was not internal to bitfinex, it could have been internal to BitGo?)
- mikecke 10y agoIf BitGo was compromised, 1 of the 2 remaining keys still must be used to sign the transaction. BitGo has no access without either of the 2 keys that Bitfinex controls.
- 10y ago
- obilgic 10y agoSounds like 1870s for bitcoin. https://en.wikipedia.org/wiki/Train_robbery https://en.wikipedia.org/wiki/Train_robbery
- 0x0 10y agoThat's a sizeable chunk of the 21m BTC total that can ever be in existence...! Are the destination wallet addresses for the heist visible in any block chain explorers? Would it even be possible to mix those coins or will they be impossible to spend as tainted?
- cloudjacker 10y agoyeah sure it is possible to spend that amount of tainted coins, and yes everyone knows where they are. you can't send the tainted coins to an exchange or a bank, because they risk getting seized and your identity compromised you can give someone the private key on a flash drive for goods, services, or an army. you can move varying amounts to different addresses each for a different flash drive, to exchange for goods, services, or an army. physical transfers wouldn't show up on the blockchain. you can also mix them over time for whatever amount you need. $50,000 a day wouldn't be impractical. and you can also build up your own bitcoin infrastructure yourself, start another bitcoin casino and all the players get paid out in your otherwise tainted coins do an ICO for a new project and fund it with all your tainted coins, and others. most crowdsales - like Ethereum's - have one or two large investors amongst the little amounts everyone else contributes. honestly all the transparency perks of the blockchain is just to rosy it up to regulators. but it undermines any and every capital control in existence.
- hyh1048576 10y agoThat's a very nice remark by someone who clearly have a deep understanding of the BTC ecosystem. (no sarcasm here, I totally agree that's what the ecosystem is like.) > you can give someone the private key on a flash drive for goods, services, or an army. But for this part, what if the one who gives out the private key moves the coins later? That's not a finalized transaction at all if both side have the private key.
- cloudjacker 10y agoYes that is a problem and it does involve trust. Conceptually It can be alleviated with having the coins in multisig address where a third party creates one of the signing keys and the original thief retained one, and ideally the second recipient also had a third signing key. Still have the problem of getting the third signing key generated in a way that required no trust, in advance
- biggerfisch 10y agoIf it turns out that BitGo did not properly enforce limits (as opposed to being hacked or ???), would they be liable for the losses?
- deleted 10y ago[deleted]
- Scirra_Tom 10y agoI mean, liable for that much loss is going to be pretty meaningless at the end of the day because none of the actors would be able to cover the liability.
- lossolo 10y agoThis is how modern heist look like. You do not need guns anymore. Get keyboard, access to internet, learn, learn, learn and then get ~60 mil euros in one evening without going out of home stealing somebodies bitcoins.
- jonahx 10y agoAccording to google, that's $62,129,412.80 US Dollar
- llamataboot 10y agoTime for a hard fork ;)
- jeffmcjunkin 10y agoWhoa. A core BitCoin dev (maaku7) just suggested blacklisting those transactions in miners[0]. More to come, I'm sure. [0] https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_shows_movement_out_of_multisig_wallets/d61oe33 https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_sh... Yes, that's a scary precedent.
- zik 10y agoBecause it worked so well for Etherium...
- Kinnard 10y agoI don't see a problem with (a lot) individual miners makings such choices. Not quite the same as concerted forking to reverse a bug in proprietary system that you don't like that others see as a feature.
- detaro 10y agoIsn't Bitcoin mining quite centralized, with a few chinese operators controlling a large majority?
- abstractbeliefs 10y agoThere really are two issues here: 1) in actual fact, very few votes were cast for ETH. Although many people ran the clients that supported a fork, most of them simply did so because it was the only option for their chosen client - there was no non-fork client option easily available to them. Very few people explicitly chose the clients to support the fork. 2) "Will of the people" defeats the point of ETHs smart contracts. If everyone in the pool decided to buy in on a bet of a digital coin toss, and the bet ends up 51% heads and 49% tails, is it ok for the heads bettors to simply consensus the bet out of the chain and reclaim their money in the event that tails wins?
- natrius 10y agoBlockchains require the will of the people. You can't force people to acknowledge numbers just because they're written down somewhere unless you point a gun at them. If the people you want to interact with start looking at a different source of truth, you can't stop them. Despite this fundamental truth, blockchains are extremely useful.
- ben_jones 10y agoPart of the beauty of start-ups is that anyone can start one. You don't have to have a 20 year vetted resume, a college degree, or extreme wealth. However this is a boom-a-rang that comes around full force when people expect financial and medical services being offered by start-ups to have the same quality as those created by people with 20 year vetted resumes, college degrees, and extreme wealth.
- roywiggins 10y agoHonestly after the 2008 crash those highly résuméd old people start to look as untrustworthy as anyone, given a bunch of Respected Financial Institutions appear to have accidentally tanked the global economy.
- deleted 10y ago[deleted]
- pmorici 10y agoStill less than was stolen from the Federal Reserve recently. http://www.cnbc.com/2016/06/06/ny-fed-first-rejected-cyberheist-transfers.html http://www.cnbc.com/2016/06/06/ny-fed-first-rejected-cyberhe...
- bdcravens 10y agoYes, but impact of Bitfinex far, far greater. It represents about 0.75% of all Bitcoins. If you include only paper currency, there's almost $1 trillion in circulation (about 4x that if you include coins). I assume amount on deposit is much higher. However, being the most generous with the numbers, the Fed hack represents 0.002%.
- tedunangst 10y agoBut that money wasn't really stolen from the fed. It was stolen from somebody who had a fed account. We know exactly who lost money, and the answer isn't everybody.
- imaginenore 10y agoProphetic comments about BitFinex from 11 months ago: https://www.reddit.com/r/Bitcoin/comments/3igv0r/bitfinex_pretty_sure_we_are_dealing_with_amateurs/ https://www.reddit.com/r/Bitcoin/comments/3igv0r/bitfinex_pr...
- 0x0 10y agoIf the accusations about how the entire exchange was built on a stolen ruby-on-rails source code leak is true..! Let's just say this is the money quote in that thread: > "There is a good story here, waiting to be written by some investigative journalist. Perhaps we will have to wait for some catastrophe before that happens."
- yborg 10y agoI have no skin at all in this game, but at this point I have to wonder why anybody is still investing in this, it's been one scam after another every six months for as long as BitCoin had been around. Is it all just the greater fool theory?
- em3rgent0rdr 10y agoShows the importance of server security. And a reminder that no need to store your bitcoins online.
- kalleboo 10y agoThe NSA and Department of Defence have has documents leaked. Major retailers leak tens of thousands of credit card numbers. Banks routinely have embarrassing security holes. The very building blocks these systems are built on have bugs that laid dormant for years (OpenSSL, Secure Transport) Why does anyone still believe computer security is anything but an illusion?
- spdustin 10y agoThe thing with the greater fool is: they get the fuck out when the investment goes cold. They're not interested in calm, orderly profit, they're interested in action. By definition, they're irrational. Leaving aside the fact that (what I call) the semi-intrinsic value of BTC is designed to increase over time, when the end is in sight either because of security snafus or actual source exhaustion, the greater fool will go elsewhere, leaving the lesser fools holding the bag. Nobody seems to be handling BTC correctly, and nobody seems to agree on the correct way to handle it. That leads me to my own thesis: if a currency is so convoluted to handle that consensus can't be reached on proper handling of escrow funds or deposit balances, it's not a currency, it's just a long-running argument.
- exo762 10y agoI think it's time to give BitSquare a go. Distributed exchange, FLOSS, no single point of failure. Not suitable for fast trading due to transfer of real money on every trade, but totally fine if you just want to buy or sell cryptocurrency.
- dschiptsov 10y agoLet me guess - PHP?
- rofflez 10y agoBitcoin exchanges blowing up and and the "smart" guys patio and eliezer making once again ignorant comments about bitcoin. Oh well, nothing new under the sun.
- jbmorgado 10y agoFor me the question is very clear: 1 - A monetary system without any regulation accessible online (i.e. Bitcoin) needs perfect security. 2 - There is no such thing as "perfect security". Therefore: A monetary system without any regulation accessible online (i.e. Bitcoin) is deemed to fail.
- PaulHoule 10y agoWoo I trust these guys so much more than the Federal Reserve.