6 ms·
Commentary from my part: Bitfinex uses BitGo for multi-signature (MultiSig) transactions. 2-of-3 signatures must be present for user funds to be released. Key
by mikecke 10y ago
Commentary from my part:
Bitfinex uses BitGo for multi-signature (MultiSig) transactions. 2-of-3 signatures must be present for user funds to be released.
Keys present:
- Offline key held by Bitfinex
- Online key held by Bitfinex to initiate user withdrawals
- Online key held by BitGo to confirm user withdrawals are within constrained limits in a set timeframe
zanetackett, Product Development of Bitfinex, confirmed that Bitfinex's offline key was not compromised. The attack was also not internal [1]. Another set of comments also suggested that BitGo limits were set in place by Bitfinex [2-3].
The automatic limits are designed to constrain BitGo from signing any transaction from Bitfinex that are irregular in volume or exceed a set amount in any rolling timeframe. Somehow they were bypassed. What we have currently suggests that the limits were too large or that BitGo was not enforcing the limits. BitGo and Bitfinex are also separate established entities, so that both of them being compromised for this attack is unlikely. An improper setup between Bitfinex and BitGo is more likely.
[1]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_security_breach_trading_will_be_halted/d61pc44 https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
[2]: https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_shows_movement_out_of_multisig_wallets/d61paqy https://www.reddit.com/r/Bitcoin/comments/4vupa6/p2shinfo_sh...
[3]: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_security_breach_trading_will_be_halted/d61qkll https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
- biggerfisch 10y agoHas it been verified that BitGo's key was not simply compromised? As unlikely as it may be that both online keys could be compromised, it certainly seems that it could have happened (perhaps while it was not internal to bitfinex, it could have been internal to BitGo?)
- mikecke 10y agoIf BitGo was compromised, 1 of the 2 remaining keys still must be used to sign the transaction. BitGo has no access without either of the 2 keys that Bitfinex controls.
- biggerfisch 10y agoSorry, wasn't clear. I assumed it was obvious that bitfinex's online key was also compromised, no matter what happened with BitGo, whether their key(s) were stolen or if their api was abused.
- berberous 10y ago>Who is to blame for this hack, finex, bitgo, users? >>>We're still investigating the hack to figure out exactly how we were compromised, but it does look like it's on us. Source: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_security_breach_trading_will_be_halted/d61p2kb https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...
- Eliezer 10y agoSomebody, one of these days, should design a cryptocurrency whose point is just to NOT get stolen.
- DennisP 10y agoHere's an article by some cryptocurrency researchers, about a proposed anti-theft extension to Bitcoin: http://hackingdistributed.com/2016/02/26/how-to-implement-secure-bitcoin-vaults/ http://hackingdistributed.com/2016/02/26/how-to-implement-se... The same scheme can be implemented as a one-page smart contract on Ethereum: http://www.blunderingcode.com/ether-vaults/ http://www.blunderingcode.com/ether-vaults/ Of course Ethereum had its own giant theft, but that was from a convoluted, poorly-written, and much larger contract. There are ways to avoid the sorts of vulnerabilities that were exploited there: http://www.blunderingcode.com/writing-secure-solidity/ http://www.blunderingcode.com/writing-secure-solidity/ Probably other vulnerabilities will be discovered. But I think simple contracts that secure ether with multiple keys, timelocking, and so on are a pretty good solution for anyone just storing and sending ether. They're also starting to incorporate formal verification of contracts; the online Solidity compiler includes it now, though it doesn't yet support all Solidity features.
- patio11 10y agoI can't believe I'm saying this but: this is not a Bitcoin problem, per se. This is a Bitcoin exchange problem. (Bitcoin has many security problems, in the same way that an overweight smoker has many health problems, but that doesn't mean that smoking caused the gunshot wound.) It's possible to have customer balances of $60 million and not lose them. Thousands of businesses manage this. They suffer $5+ million dollars of damages in less than 0.1% of business-years. (SWAG on a reasonable upper bound-- ask an actuary. This is an insurable risk.) Bitcoin exchanges with this level of deposits sustain $5+ million dollars of damages 20%+ of exchange-years. Running Bitcoin exchange probably requires $10 million a year in engineering and compliance costs, and consequential changes to the business model with an eye towards a) paying for the actual costs of running the business and b) compromising on other things that users/investors care about, like speed of withdraw, degree of engagement with the regulatory state, and growth rate. Instead of making that tradeoff, Bitcoin businesses continue trying to grow at 100%+ YOY on four, five, or six digit risk budgets. And this works... until it doesn't. "How do we not transfer substantially all of our assets to fraudsters?" would be an acceptable job interview question at the Medici bank in the early 15th century. It was a solved problem then.