27 ms·
100s of El Salvadorans Report Bitcoins Disappearing from Their Chivo Wallets
- emerged 5y agoThat’s the great thing about Bitcoin. You can defraud people at scale and completely get away with it. Hardly seems newsworthy at this point.
- almost 5y agoIt’s not a big it’s a feature :/
- vmception 5y agoJust like ACH fraud isn’t news so you only get news about bitcoin frauds
- woodruffw 5y agoACH fraud isn't news because the ACH network allows clawbacks.
- DaiPlusPlus 5y agoI thought ACH was negative-confirmation-only, and a "clawback" is really just a delayed "nope" message instead of revoking or undoing a previously issued "ok" message, simply because there is no "ok" message. How on earth was ACH's design approved in the first place? It violates practically every principle of good transactional system design.
- aaomidi 5y agoIt's decades old.
- woodruffw 5y ago> a "clawback" is really just a delayed "nope" message instead of revoking or undoing a previously issued "ok" message, simply because there is no "ok" message. That's actually not a clawback in ACH parlance: that's just a transaction rejection, which causes the original transaction to "bounce" and enter a remediation process. Clawbacks are done via "return records", which can be issued separately of any transaction records. Clawbacks, in turn, can be dishonored and countermanded by the RDFI. I wrote a short summary of the different rules here[1]. > How on earth was ACH's design approved in the first place? It violates practically every principle of good transactional system design. ACH's design comes from the 1960s. It was designed for a time when the average American used their physical checkbook to pay for everyday items, and there was no reliable (non-military) nationwide computer network. Its design looks bad because it's optimized for forces that are currently mostly irrelevant, but used to be common: tens of thousands of tellers filing physical paper, smudged checks, typos by secretaries, delays in the mail network, the cost of long-distance calls, &c. They probably didn't even have a sound notion of a "transaction" in the ACID sense, given that Jim Gray didn't develop that particular paradigm until the 1970s. ACH's flexibility and complexity make it look staid and antiquated compared to modern settlement systems, but it's all there for a good (historical) reason. [1]: https://blog.yossarian.net/2019/12/25/A-shallow-dive-into-the-American-banking-system https://blog.yossarian.net/2019/12/25/A-shallow-dive-into-th...
- DaiPlusPlus 5y agoBut why didn't they improve it at all during the past 50 years?
- woodruffw 5y agoThey've tried! ACH has been somewhat modernized over the decades, in the form of compliance and in-protocol changes (faster turnarounds, additional transaction codes for online transactions and different cardholder verification methods). The Fed has also been working on a modern replacement to ACH for at least a decade, and is planning on performing an initial release in 2023[1]. But as for why it's taken so long: banking in the US is, for various reasons, significantly more complicated than banking in most other countries. The US has thousands of FDIC-insured banks and credit unions, each of which operates under a patchwork of municipal, state, and federal regulations. Banks are (mostly) required to honor each other's checks and transactions which means that, in the worst case, there's a total graph of all ~10,000 banks and credit unions serving as both ODFIs and RDFIs[2]. Transaction failures between any two nodes in that graph are a possible compliance failure, so any common mechanism is both a lowest common denominator and resists any modernization or other changes than can cause disruption. [1]: https://www.federalreserve.gov/paymentsystems/fednow_about.htm https://www.federalreserve.gov/paymentsystems/fednow_about.h... [2]: It's actually simpler than this, since the ACH clearinghouses serve as a central resolution and dispatch service for all ODFIs and RDFIs. But each O/RDFI still has to interpret the ACH record(s) they receive, so there's still extraordinary inertia against any changes.
- vmception 5y agoBasically the defrauded doesnt notice it is occurring, at some interval, and the fraudster isnt keeping the money in the account and also using mules, and third they dont get caught most of the time banks provide a user experience that makes them pretend to get the money back, a crypto bank can pretend to do the same thing, hardly a one to one comparison
- woodruffw 5y agoAs of 2019 (the last year before just about every financial statistic goes sideways due to COVID), the ACH payment system has the lowest fraud rate by value of any settlement system in the US[1]. I'm not aware of similar statistics for any popular cryptocurrency, but I'm not optimistic about how any of them would compare. It's difficult to find statistics for the percentage of money recovered from fraudulent ACH transactions, but this industry survey[2] says that 92% of fraudulent transactions are discovered within two months (and 79% within one month). Given that NACHA allows clawbacks within 60 days, that offers a relatively bright prospect for funds recovery compared to an irreversible transaction. [1]: https://www.nacha.org/news/ach-payments-have-lowest-fraud-rate-fed-survey-finds https://www.nacha.org/news/ach-payments-have-lowest-fraud-ra... [2]: https://www.synovus.com/-/media/files/business/webinars/2021_paymentsfraudsurveyreport-3.pdf https://www.synovus.com/-/media/files/business/webinars/2021...
- vmception 5y agoThats a nice improvement for them Bitcoin would be calculated by value deemed as being defeauded from users onchain as payments and on exchanges, that year, and compared to a portion of its.. marketcap? or by quantity of non-fraudulent transactions? Since bitcoin is all one kind of payment method (well lightning would be different), it would have to be compared to the other kinds mentioned in the nacha article too, ACH + ATM + Card fraud For bitcoin I would say the data doesnt exist, but even with the headlines trying to break down just bitcoin for that year, it would be fairly low I’m thinking, even $1bn in fraudulent irrecoverable transactions would be a single digit. Percent or maybe down to a couple basis points as well just like NACHA brags about
- cpach 5y agoOTOH, ACH lets you actually pay for goods or services received, right? I never hear of people paying invoices with Bitcoin.
- codetrotter 5y agoI recently agreed with a client that they’d pay in Bitcoin for an invoice that I sent them :) I received half of it in Bitcoin and the other half via old fashioned bank transfer. It was a neat experiment, and I plan on accepting payment in crypto for some invoices that I send in the future as well.
- Griffinsauce 5y agoHow did you handle the fluctuation in value?
- codetrotter 5y agoWe agreed to use the average price from the most recent day in the past from the CoinMarketCap website price history page for Bitcoin, and I attached a note to the invoice stating the USD/BTC exchange rate that we would use when calculating how much they were to send me.
- dagenix 5y agoWhy? Couldn't you just take the whole payment via bank transfer and then go buy Bitcoin afterwards if you wanted to? This sounds like extra steps that I don't understand the point of.
- codetrotter 5y agoThey had Bitcoins, I wanted Bitcoins. It would have been more extra steps for me to first wait for bank transfer and then transfer money to an exchange, buy Bitcoins, and then transfer the Bitcoins to my wallet.
- 5y ago
- kevingadd 5y agoACH fraud is more trackable than Bitcoin fraud and in many cases you can get the money back. For example, the most recent time I ran into an ACH scam I was able to identify the bank + individual that owned the target account.
- vmception 5y agowho was likely a money mule, who likely got their account overdrafted by your bank because the actual fraudster already got away with the actual money, while you just got a user experience that has nothing to do with the recoverability of money just an illusion of it a financial institution custodying bitcoin can do that too
- mbesto 5y agoAnd $61T got transferred via ACH in 2020[0] with a 0.08% fraud rate[1] Completely different scale with an incredibly low fraud rate. Not to mention consumer protections put in place by banks (i.e. recoverability). This analog is disingenuous. [0] - https://www.nacha.org/content/ach-network-volume-and-value-statistics https://www.nacha.org/content/ach-network-volume-and-value-s... [1] - https://www.nacha.org/news/ach-payments-have-lowest-fraud-rate-fed-survey-finds https://www.nacha.org/news/ach-payments-have-lowest-fraud-ra...
- vmception 5y agoThe disingenuous part is that the weekly news isnt dominated by the large frequent thefts at all, if it was actually about awareness and questioning then an ACH fraud noticed would be on the news and would conventially not mention that its a tiny tiny fraction of a basis point of activity on the network
- mbesto 5y ago> that its a tiny tiny fraction of a basis point of activity on the network Hence why it's not in the news...I still don't understand your point?
- vmception 5y agoBecause thats the standard that should apply to bitcoin and crypto But instead no proportions are mentioned in a crypto fraud, just large dollar values paraded as if its unique It is intended to distort perception and its silly
- mbesto 5y agoHow much USD$ or equivalent is moved into cryptocoins and how much of that amount is considered fraudulent? Until you have numbers there, then I simply don't believe your premise.
- 5y ago
- deleted 5y ago[deleted]
- mitchdoogle 5y agoWhen someone is mugged and has $100 cash stolen, you don't disparage the idea of holding cash.
- lclarkmichalek 5y agoI mean, I do.
- jimkleiber 5y agoIt's hard to mug someone of their cash from the other side of the planet. That physical proximity limitation seems to provide a relative amount of safety.
- dragonwriter 5y ago> When someone is mugged and has $100 cash stolen, you don't disparage the idea of holding cash. Yes, you do, if you are using “cash” in the same sense in both places (physical currency). If you use cash to mean “fiat denominated depository accounts and investment instruments” in the second case, sure, you don't hear that, but that's equivocation as that's not something that gets stolen in a mugging.
- Griffinsauce 5y agoI don't carry cash partly for this reason so yes I do?
- zitterbewegung 5y agoActually I do. I only carry around less than $50 dollars of cash around with me. So I can pay someone who can't accept credit cards.
- davewritescode 5y agoBitcoin isn’t the $100 bill in your wallet, it’s your bank account. If my bank account can be completely drained in a way that the money can’t ever be recovered, that’s not a feature, it’s a bug.
- passwordreset 5y ago
- anotheraccount9 5y ago>"You can defraud people at scale and completely get away with it." That's possible with any fiat currency too.
- xxs 5y agoway way way harder than that.
- KiranRao0 5y agoWay way harder unless you're in an authoritarian regime with control over the banking sector.
- timeon 5y agoSo is this that decentralization? With Bitcoin authoritarian regime has no borders.
- AnthonyMouse 5y ago> way way way harder than that. Is it? https://www.forbes.com/sites/instituteforjustice/2021/10/25/new-proof-that-police-use-civil-forfeiture-to-take-from-those-who-cant-fight-back/ https://www.forbes.com/sites/instituteforjustice/2021/10/25/... https://fortune.com/2016/06/09/civil-forfeiture-erad/ https://fortune.com/2016/06/09/civil-forfeiture-erad/ At least with Bitcoin they need your passphrase.
- kspacewalk2 5y agoWith flat currency it is possible to have a well-designed banking system with mechanisms for boring human pen-and-paper recourse in case of fraud. El Salvador probably doesn't have one, but they can create one. With Bitcoin, they cannot, by design.
- davewritescode 5y agoNo it’s not. If my savings account gets drained by someone hacking my account, the bank gives me back my money up to 250k and they have mechanisms to claw back that money from other institutions. With crypto you can commit fraud at scale with little risk of long prison sentences due to the non violent nature of the crimes and victims are SOL.
- ekianjo 5y ago> You can defraud people at scale and completely get away with it Ever heard of fiat currency inflation?
- mrosett 5y agoYou're not wrong, but the USD has had ~6% inflation over the last year while Bitcoin has experienced ~15% inflation since the end of last motnh.
- AnthonyMouse 5y agoKind of cherry picking when over the same year as the 6%, Bitcoin has experienced ~45% deflation, isn't it?
- vorpalhex 5y agoStability is a feature. 6% is pretty rough, ~45% is atrocious world ending stuff.
- deleted 5y ago[deleted]
- AnthonyMouse 5y agoThe deflationary aspect of Bitcoin was a design flaw, but it's not inherent to cryptocurrencies generally. Nothing says there has to be a finite supply of coins as opposed to the supply scaling in proportion to how much the value of the currency exceeds the cost of hardware or electricity. And even with Bitcoin itself, think about what Wall Street and governments would do with securities derivatives and Bitcoin-denominated debt instruments. The supply of Bitcoin isn't actually limited by the supply of Bitcoin.
- ekianjo 5y ago> Stability is a feature so the USD going to the ground at 6% per year is a feature? Aren't currencies supposed to be store of value over the long term, you know, over dozens of years since you need hard cash to retire?
- vmception 5y agoSince this is lightning network, isnt this also possible that the users are subscribed to some payment? perhaps the subscription is malicious, or maybe its not
- trembonator 5y ago
- londons_explore 5y agoPresumably it would show as such in the app?
- 3np 5y agoCare to elaborate? Lightning doesn’t have a concept of pull-payments, it’s still all push. Or does their wallet software additionally contain functionality for automated subscriptions?
- vmception 5y agoI don’t know I heard subscriptions could be done but i havent checked in years
- woodruffw 5y agoThis is a question for any El Salvadorans browsing HN: are the funds stored in Chivo subject to the same financial rules and regulations as the rest of the El Salvadoran banking/financial sector? I'm asking regardless of practical enforcement of those regulations, because I want to understand the risk model here as people actually using the app perceive it. Are the people regularly using it under the impression that the government will help claw back or recover lost or stolen funds, or is there widespread understanding that it's irreversible?
- el-salvador 5y ago> This is a question for any El Salvadorans browsing HN: are the funds stored in Chivo subject to the same financial rules and regulations as the rest of the El Salvadoran banking/financial sector? No. > I'm asking regardless of practical enforcement of those regulations. From public information and press releases it doesn't seem like they do. - For starters the password is just a six digit number. So it doesn't follow the same account security recommendations required by the regulator for every other financial institution in El Salvador. - Every financial institution in El Salvador is required to publish their corporate information on their website, including their financial statements and board of directors. But their website doesn't even publish their address. - The app is not a member of the local deposit insurance scheme (IGD). But the app is the financial institution with the most clients in El Salvador. 3 million, compared to 1.5 from the rest of the financial sector > I want to understand the risk model here as people actually using the app perceive it > Are the people regularly using it under the impression that the government will help claw back or recover lost or stolen fund. I don't know. I mean, all other banks are required to publish customer service statistics, including how many credit card chargebacks they do and how many fraud complaints they receive. But the app doesn't do this as far as I know.
- woodruffw 5y agoThanks for the response, I appreciate it.
- deleted 5y ago[deleted]
- dreyfan 5y agoThey elected a crypto-bro as president.
- booleandilemma 5y agoAnd you're not even exaggerating, here's his Twitter profile: https://twitter.com/nayibbukele?s=20 https://twitter.com/nayibbukele?s=20
- kspacewalk2 5y agoBut he's so young and wears a baseball cap! Surely he cannot be like all the others.
- woodruffw 5y agoNot just a crypto-bro, but a failed sovereign[1]. [1]: https://www.latimes.com/world-nation/story/2021-12-09/el-salvador-government-negotiated-with-gangs-u-s-treasury-says https://www.latimes.com/world-nation/story/2021-12-09/el-sal...
- halpert 5y agoTheir only soure documents "over 50" cases, not hundreds.
- endisneigh 5y agoI'm curious - if someone was able to develop a new type of computing (or phishing) to get the private keys and simply took them, would that be stealing? Do people who own Bitcoin have any legal right to the coins? What if the person who "stole" them claimed they mined it themselves. How could you disprove this?
- zitterbewegung 5y agoIANAL but in the United States that would still be wire fraud because you interact with a network to move the bitcoin into a wallet you would control. You can disprove the other actions by looking at Bitcoin's distributed ledger but for certain transactions if they liquidate the coins it can be a great deal of work to figure out where the money went.
- endisneigh 5y agoHow would you distinguish this "bad" behavior from the good? It seems inherently intractable without centralization.
- anamexis 5y agoHow is it any different than determining if a credit card charge was fraudulent? Either way, someone "figured out a way" to extract funds.
- endisneigh 5y agoCredit cards are centralized and it's trivial because of that.
- anamexis 5y agoHow is it trivial to determine if a charge was fraudulent? Fraudulent charges are made in the exact same way as genuine ones.
- __MatrixMan__ 5y agoIncentivising users to associate real world identities with their crypto identities by paying them $30 isn't a terrible idea. That's more than you get when some advertising giant builds a profile for you based on your browser characteristics. But preloading wallets and saying "use this wallet with you government ID to claim the money" fails to scratch the itch in so many ways: - Users need to understand public/private keys so that the can rotate keys whenever necessary. They should have had users generate the wallets empty and then have them authenticate as a second step to get the payout. - Maybe you need government-authored software to carry out the business of government, but since the chain is public and the keys can be used for signing things other than transactions there's no need for that software to ever see your private key. You ought to be able to handle everything you need by sending signed messages to the government app or having the government app examine the chain. - Pairing an ID number with a photo of a face is not a valid authentication step. Neither of these things are secrets. You're going to need a government employee to look at the ID and the face before they accept the key, that way when skulduggery ensues, that employee can be found and questioned. Relying on non-secrets to do the job of secrets is a bad idea--as everybody who has a ssn knows.
- hericium 5y ago> Incentivising users to associate real world identities with their crypto identities by paying them $30 isn't a terrible idea. There's this project called Worldcoin which gives you "crypto of the future" for registering your retina and more "crypto of the future" for setting up "orb" devices to scan other's retinas.
- whelming_wave 5y agoAn inverted funnel of world coin, it seems.
- __MatrixMan__ 5y agoI've heard if it. I just don't think biometrics are ever going to be good enough to securely drive a key from. And even if they were, I'm not sure one-key-per-human is what you'd want. I think we ought to be able to generate pseudonyms which provably belong on to a taxpaying citizen, but which can't be traced to the specific one. For protecting whistleblowers and such.
- ArtTimeInvestor 5y agoIs the "Chivo Wallet" an actual lightning wallet? I have not found any confirmations so far, that People in El Salvador are actually using Bitcoin. For all I know it could be Government fiat that is denominated in Bitcoin. Does anybody here know more about it?
- neb_b 5y agoYes, you can send funds from Chivo wallet to any bitcoin wallet (or the other way around)
- ArtTimeInvestor 5y agoOk, but the same would hold true for any exchange app. But that does not make it a lightning app. The coins would be held by the exchange and the app only displays your balance.
- topranks 5y agoIt’s precisely like that.
- __MatrixMan__ 5y agoIf you're going to centralize the keys, why bother with Bitcoin? Isn't the whole point that you're insulated against untrustworthy governments? It's kind of sounding like decaf coffee ..
- ArtTimeInvestor 5y agoSo the Chiva Wallet is not a lightning app?
- topranks 5y agoThere’s been a few articles on it. Chivo -> Chivo transfers are not done with Lightning, or ok the blockchain itself. Govt is not obliged to back the amount of “Bitcoin” in all the wallets by any specific amount. There are, I believe, gateways to both LN and the BTC blockchain itself. So you can transfer funds to/from Chivo with a real Bitcoin transaction. But sending to another Chivo user is just handled by Chivo centrally.
- imtringued 5y agoWhat does state owned mean? Is it run like a centralized bank or is it just the official "lightning wallet"? The article is confusing because it mentions missing funds but not whether there are any transactions by hackers or scammers.
- kranke155 5y agoChivo Wallet is non custodial. It is managed by the government somehow. It’s pure evil what they did there. Afaik a government official could take it all.
- ethan77 5y ago
- anaganisk 5y agoSo basically someone just centralised a coin based the bitcoin lightning network and censored it. LoL. Waiting for crypto pedlers and Buteriks to shut the heck up about their ponzi schemes. They would defined come up now saying, bUT bUT uSeRS muSt knOw abOut prRiVate and PubLiC keYs. Dude in real world most of the people including software engineers don’t even understand basic password practices 2FA etc. Its time people start accepting bitcoin/ethereum is just a new problem for a solved problem, with a new database.