6 ms·
I Just Lost 1,400 BTC (2020)
- TekMol 5y agoIn times of banking apps, why does this not happen to old fashioned bank accounts? What keeps hackers from taking over someones phone and sending their dollar/euro holdings somewhere?
- relax88 5y agoA vast system of fraud detection and limits on what can be done to accounts, especially on a mobile app. If you try and move large amounts of money via your mobile banking app you won’t get very far before you have to show up in person at a branch.
- TekMol 5y agoIs that true? What would be maximum amount someone can transfer from their bank account in a given day via the banking app / website?
- pjc50 5y agoMy bank says the faster payment limit is £25k. They do require phone code confirmation, but that can be hacked.
- Causality1 5y agoAs an example, someone once had to write me a check for $10,000. The bank transferred the amount incrementally to give the originator time to object. The first day it transferred $100, then $200, $500, $1000, $3000 and so on until the full amount had been paid.
- relax88 5y agoDepends on the bank, account type, and the destination for the funds. My bank requires in-person to send a wire transfer, meaning in person identification at a bank branch with photo ID and PIN. You can only transfer money on the app within your own accounts or to payees that are in the system (e.g your utility company, insurance company, etc.) or by using interac e-transfers with a limit of ~$1500. Even if you’re trying to pay your taxes to the Canada Revenue Agency the bill payment system has a limit that I have hit. You can bet that a review process is triggered when that happens as well. Any deposit of >$10000 from a wire transfer usually triggers a phone call as well where someone will politely ask you if you were expecting the transfer.
- syntheticnature 5y agoThis page has further examples that appear to vary for ACH transactions (one of the more common means for app/website transfers), indicating that for would-be thieves it would be a guessing game, and the limits are generally pretty low: https://www.mybanktracker.com/news/ach-transfer-limits https://www.mybanktracker.com/news/ach-transfer-limits
- renegadus 5y agoBecause banking transactions are far more traceable and can often be reversed if found to be fraudulent.
- TekMol 5y ago"Often" indicates that there are ways to send funds in a way that is not reversible. Wouldn't a thief make use of such a way?
- radres 5y ago"Often" word is used because it also covers the case of small transactions. As transactions get bigger, systems get slower. I have had personal phone calls from bank to ensure I wanted to send big sum of money.
- eh9 5y agoI guess this is my disconnect or naïveté, but I thought the whole point of crypto is that it’s fairly traceable - obviously, there’s no decentralized way to address fraud, but couldn’t we have a decentralized report system that can warn people before sending tokens to known malicious actors?
- pjc50 5y agoThis does happen. Then they're tracked down and prosecuted and the money returned - sometimes. But the regular banks also put a bit more effort into authentication. And amounts over certain figures attract more scrutiny. Two specific design decisions of crypto - irreversibility and pseudonymity - make this much harder for crypto.
- ronsor 5y agoBanks usually have transfer limits to prevent you from losing 10 million dollars at once.
- dustinmoris 5y agoJust a few from the top if my head: - Banks limit the amount per single transaction - Limit on total daily amount one can transfer - If a limit has to be exceeded for a large purchase they have a 24/7 hotline to authenticate and authorise such a one off transaction - Additional checks on source of funds when someone pays in a lot of money - Need for multiple extra factors of authentication when making a transfer to a new payee - Extra checks including money laundering checks when making transfers abroad - … and much more
- diegocg 5y agoBank transactions are reversible.
- exporectomy 5y agoI don't know why people keep saying this. They're often not. There was a case in my country of someone receiving a pile of money by mistake and he withdrew or transferred it quickly and fled the country. I also know someone overseas whose dad lost his life savings through a phishing scam that asked for his password and 2FA token via text message. The bank could only tell them where the money went (multiple accounts in other banks) but not get it back. Elder abuse often happens by the abuser using the victim's bank card and PIN to buy groceries/etc. then also taking money for themselves. The banks blame the victim who broke the rules by giving away their PIN and the abuser says it was a genuine payment for services or rent or whatever. If your bank's app has a vulnerability that you lose money through, they bank will probably compensate you out of their own pocket even if they can't reverse the transaction.
- fspacef 5y agoThat’s a bummer
- spraveenitpro 5y agoSmall sacrifice for the benefit of the rest of the HODLers
- exdsq 5y agoOr $68,387,200 USD as of today
- lucb1e 5y agoSo how do we prevent this? Not everyone can cryptographically verify software updates, like I can't expect my mom to do that, and that is assuming you can reliably determine which key to use for verification in the first place, and that you trust whoever owns that key, and that this signer properly checked all commits or trusts the people that did. Perhaps a start would be not to keep more than, say, a fifth of your cryptocurrency in a single place if you have many millions' worth?
- morpheos137 5y agoI good start would be to write security critical software right the first time and not require frequent updates if at all. Every time an update happens it imposes a time cost and security risk on users. No other engineering discipline has the concept of updates to an in use product. When Toyota sells you a car if it has a "bug" in a control arm that results in it breaking and you losing control on the highway there is no software update. There is an NHTSA investigation and a recall.
- yashap 5y agoI’m far, far from an expert, but it seems to me that the unforgiving “software is the law, nothing can be reversed” nature of crypto means that all sorts of vulnerabilities and/or mistakes can instantly lead to you losing all your money. It feels inherent to the system - the core reasons behind these weaknesses are also the core strengths of crypto. You can patch individual vulnerabilities, and try not to make mistakes, but it seems it’ll always be the case that if all your money gets stolen, nothing can really be done.
- relax88 5y agoThis is correct, and why the average end consumer will never actually use Bitcoin for anything. It may have some utility as an asset class but the crypto fan boys seem to ignore that it is largely incompatible with our current financial and legal system. I’ll happily agree with anyone that Bitcoin is an interesting and novel invention but I fail to see how it does anything useful for me other than as a speculative investment. Now that crypto markets are a parody of wildcat banks in the 1800s I won’t even touch it with a 10 foot pole.
- nyolfen 5y agoif i had a huge fucking pot of crypto i would probably also announce to the world that i had lost it
- Nextgrid 5y agoI don't understand the point - are you suggesting that he earlier on leaked the fact that he had lots of crypto and faked losing it to no longer be a target? If so he seems to be posting from a throwaway account which defeats the purpose.
- deleted 5y ago[deleted]
- nyolfen 5y agoperhaps he can provably point to it in the future if the government comes knocking. mainly i am remembering the guy in the uk that made a big show of looking for his old hard drive in a landfill, my immediate suspicion was that it was a ruse.
- pinkybanana 5y agoIt would be good way to avoid taxes, as you can write it as a loss and then go enjoy your BTC stash to some other country tax-free. The problem is though that the BTC will still be traced to you...
- nyolfen 5y agochaumian coinjoin, atomic swap for monero or zcash, or even just cashing out off the books
- tomxor 5y agoOr £49,673,410 GBP as of today
- morpheos137 5y agoIf I recall correctly the issue was something like electrum permitted any full bitcoin node to broadcast any message and a nefarious node (since anybody can run a node anonymously) broadcast a message to users to update their electrum client to a trojan client. Just goes to show that "security" is amatuerish in much of the bitcoin community. Bitcoin may be cryptographically secure but how people use it often is not. On top of all this around the same time I was trying to access some small amount of bitcoin in an older electrum wallet. It was no longer supported so I would have been forced to upgrade while there was this trojan variant going around. Any way what the lesson should be is when writing security critical software do it right the first time, don't force users to upgrade frequently, don't allow messages from anybody to be broadcast to users, don't break existing secure installations forcing users to upgrade unnecessarily. Keep it simple and secure. KISS.
- crtasm 5y ago> It was no longer supported so I would have been forced to upgrade while there was this trojan variant going around. Safely done by downloading a new version from the official website (which wasn't compromised) + verifying its signature. I agree that allowing nodes to pop up messages was a huge error.
- draw_down 5y agoThere should be some kind of institution that you can trust to hold your currency for you. Oh well, maybe one day!
- nonameiguess 5y agoIt seems like crypto has created a whole lot of people who are now rich but don't know how to be rich. People with normal assets can't transfer ownership of those assets by clicking on a popup link downloaded from the Internet. They have teams of accountants, bankers, brokers, lawyers, who sure, slow things down, take a cut, require that they know who you are and what you're buying, but they also keep you from accidentally giving $68 million to criminals.
- birdyrooster 5y agoAnd those same financial services companies will end up managing these in the end game for crypto. This is just early adopter syndrome. Risk and reward, freedom and responsibility.
- pinkybanana 5y agoThere are already Bitcoin ETFs and other stock-market tradable products in many jurisdictions (not US though). These are very straightforward for casual user, I don't see how it would be any more insecure than buying for example Gold ETF.
- robjan 5y agoIt's harder to permanently steal gold from an institution than crypto.
- birdyrooster 5y agoBitcoin (let alone a Bitcoin ETF) doesn't scratch the surface of all of the financial services that can be implemented with Smart Contracts. I agree though that is certainly going to be a piece of the overall landscape. Beyond financial services are things like Smart Trusts.
- pinkybanana 5y agoThe people have been always there, it is just that now they have the tools. I personally have no problem, bitcoin should be for adults who can manage their own risks. You can always opt out and not use it. This whole thing has been repeated since the early Bitcoin times ad infinitum and shouldn't be a surprise. This issue has been fixed in Electrum a long time ago already. However the problem is that no one can prevent people from running older versions. This kind of problems are to be expected in crypto in the future as well, so always stay cautious.
- Igelau 5y agoOr 574,718,687 Turkish Lira today
- Meekro 5y agoHere's the discussion of this Electrum vulnerability from back when it happened: https://news.ycombinator.com/item?id=18770577 https://news.ycombinator.com/item?id=18770577 Looks like this guy installed an old and vulnerable version. Electrum has a history of severe security bugs. If you want to store crypto safely, I recommend a Trezor hardware wallet. If you want crypto exposure in your portfolio without the technical/security headaches, I recommend Grayscale's investment products. GBTC, for example, is backed by Bitcoin and you can buy it through any investment account.
- Pxtl 5y agoOnce again: Crypto currency is about tearing down the old rules and institutions of banking and finding out one failure at a time why each rule and institution exists.
- Comevius 5y agoThe hippie problem. South Park described it accurately. Man 2: Right now we're proving we don't need corporations. We don't need money. This can become a commune where everyone just helps each other. Man 1: Yeah, we'll have one guy who like, who like, makes bread. A-and one guy who like, l-looks out for other people's safety. Stan: You mean like a baker and a cop? Man 2: No no, can't you imagine a place where people live together and like, provide services for each other in exchange for their services? Kyle: Yeah, it's called a town.
- deleted 5y ago[deleted]
- pinkybanana 5y agoHowever crypto has made lots of people millionaires and that kind of hippie stuff doesn't. It is not like reinventing old institutions, Bitcoin has features that central banking based systems are fundamentally unable to offer (such as limited supply).
- Gadiguibou 5y agoI understand that often, we think something new will solve all our problems, but it only changes how they look and the old solution ends up being good enough already. However, isn't it kind of pessimistic to think that there's nothing new to learn from rebuilding existing institutions from the ground up based on new knowledge? I'm by no mean a crypto apologist. I think it's important to discuss why those new ideas fail and what we can learn from them in the future rather than mock them for trying to reinvent the wheel.
- pinkybanana 5y ago> I understand that often, we think something new will solve all our problems New things fix some old problems, but also introduce new ones that we hadn't before. The value of solving the old problems is greater than the total cost of the new problems, why we stay with new things even when they add problems to our lives.
- KingMachiavelli 5y agoWow. The desktop application allowed random nodes to trigger popup alerts that could just say anything they wanted. It sounds like that was a super old version? It's a bit unclear which version of Electrum was the last to have that issue. It's pretty crazy the number of people who bought Bitcoin/crypto at such an early stage (e.g spending >$1000 on something nearly worthless and very obscure) yet are very bad at the security of this. You would think the first step to recovering >$10M plus would involve a Google search or two.
- DSMan195276 5y agoYeah I'm glad I'm not the only one who finds this a bit shocking, and their initial response doesn't really impress me that much. I don't expect a desktop app to be displaying random unverified messages to me in the same way my email or phone might, and especially so if it's not made that clear where the message is from. It's certainly true that this guy shouldn't have made this mistake anyway, but there are plenty of steps Electrum could do to make it clear whether a message should be trusted or not, and to their credit it does at least sound like they did make changes in this area in later versions. Of course, to clarify I have not actually tried this thing, I'm just basing that on their description of changes they made such as no longer displaying RTF and/or arbitrary messages.
- zarzavat 5y agoWhat can they do about old versions? Yes clearly it is an exploit but patching only fixes it in new versions. If someone insists on using an old version with that bug, they are on their own.
- DSMan195276 5y agoI agree with that, I was just objecting a bit to the tone of the original comment. IMO it's a bit of a hard sell to me to say "we're sorry, there's nothing we can do" after listing a bunch of things they did to fix this in later versions. Rather than going on and on about how it's an unfixable problem, they could have just said they have made steps to address the issue in later versions but there isn't a way to fix existing versions.
- floatingatoll 5y agoWhat is interesting or unusual about this GitHub issues link? Someone had coin stolen and they’re complaining about it. What makes this worth being on the front page?
- rvz 5y agoIf you have this amount of BTC, why put it in a software wallet? Does this wallet even have a single security audit?
- simonblack 5y agoBitcoin and others are just numbers. As such they are not backed by anything material. They have no intrinsic worth. You can't touch them or hold them. When the electricity stops they don't exist. Your choice as to whether you entrust your assets to a scheme like that. I prefer something solid like real physical assets that I can hold or touch and that doesn't rely on a source of energy for its existence.
- ryandvm 5y agoLike paper.
- xiphias2 5y agoI wish it would be easier to use Bitcoin Core with multisig hardware wallets, as it's much more thorowly reviewed as other wallets. Partially signed transactions were a huge step forward, but there's still a lot to go to get rid of other software for managing large amounts of Bitcoins.
- Koiwai 5y agoWhy the f*ck would I care? how is this news?
- JanDietch 5y agoGet in touch with coinwalletrecoup . com to help you recover all your scammed funds. I got in touch with them when i was scammed by Tradestation to be precise, having deposited over $75,000 but still couldn’t withdraw any funds. They kept on telling me to deposit more to reach a certain amount but still couldn’t withdraw then it dawned on me that these people were playing games with my money. Within a week of contact, Coinwalletrecoup . com did the impossible, they recovered everything and also my ROI for the agreed duration of investment. Dont hesitate to contact them if you need any help. They’re the Best out there.