12 ms·
MtGox wrote their own Bitcoin wallet software. MtGox had a bug in the wallet software that caused it to lose track of outgoing Bitcoin transactions. People ex
by Xdes 13y ago
MtGox wrote their own Bitcoin wallet software.
MtGox had a bug in the wallet software that caused it to lose track of outgoing Bitcoin transactions.
People exploited that bug to take out more Bitcoin than they had in their MtGox account.
MtGox shut down Bitcoin withdrawals to fix the bug.
MtGox has not fixed the bug three weeks later and a lot of their customers are anxious.
- 3pt14159 13y agoAnd then MtGox blamed their own bug on the open source developers calling the actual protocol a bug. (Although malleable transactions were a pretty stupid idea.)
- cperciva 13y agoAlthough malleable transactions were a pretty stupid idea I'd say that malleable transactions are a bug in the protocol.
- pikachu_is_cool 13y agoI wouldn't say a bug... more like a flaw in design. AKA a bug.
- ak39 13y agoAgreed. For those interested in finding out what transaction malleability is: http://www.coindesk.com/bitcoin-bug-guide-transaction-malleability/ http://www.coindesk.com/bitcoin-bug-guide-transaction-mallea... <quote> What is transaction malleability? It’s an attack that lets someone change the unique ID of a bitcoin transaction before it is confirmed on the bitcoin network. The change makes it possible for someone to pretend that a transaction didn’t happen, if all the right conditions are in place. </quote> This is a fatal design flaw in any TPS system. From any sound accounting principles point of view, no journal entry is to be manipulated after insertion - only through compensating transactions (referencing the original).
- VMG 13y agoTo be clear here: when broadcasting your transaction to the network, somebody can reissue your transaction with a different ID, but they cannot change the inputs and outputs. There are other ways to track transactions other than the txid, for example by tracking a unique output address. A normalized hash routine has been added recently: https://github.com/bitcoin/bitcoin/pull/3656#issuecomment-35055553 https://github.com/bitcoin/bitcoin/pull/3656#issuecomment-35...
- ak39 13y agoThanks. Just a naive suggestion (will this work?): Why not introduce some sort of a 2-phase commit with the original transaction and the newly inserted one on the block-chain? So, before the block-chain transaction is committed, check the two transaction id hashes, if they are different for the request, fail the transaction. Edit: Of course, the eavesdropper could just as well pass the expected hash back to the originator anyways. :-( Hmmm
- VMG 13y agoThat's not necessary. A transaction with a modified id is not a problem unless you falsely rely on the id for payment verification instead of tracking the inputs and outputs by a custom hash. The biggest flaw here is probably the name "transaction id", because it suggests that a transaction can only have one valid id. The normalized id fixes this issue for most transaction types.
- baddox 13y agoNot the same thing in common usage. Most people use "bug" to refer to unintended behavior. Wikipedia also includes "incorrect behavior" in its definition, but that's extremely broad, since "incorrect" could be used to describe anything from an underperforming call to action on a landing page to creating software in the wrong market (e.g. "My software had a bug: I created a food delivery app when I should have created a social network app"). In fact, it's hard to even call this a flaw in design, because your intentions and hopes for Bitcoin might be very different than those of the Bitcoin developers.
- dllthomas 13y agoI've often heard "design bug".
- maaku 13y agoWell, there are many sources of malleability which could be eliminated. Certainly I would consider each of those a bug. However it is not yet known whether malleability can be eliminated entirely (e.g. algebraic manipulations of ECDSA signatures).
- Danieru 13y agoEven if transactions were not malleable, or if you use unchangeable signatures, you would still hit a race condition using them like Mt. Gox does. The proper way to resend a transaction is to re-use an input which was used in the original transaction. It does not need to be all the same inputs, just at least one. This way it is not possible for the two transactions to both succeed. If the original transaction succeeds then the second will be rejected as a double spend. In general Mt. Gox's software appears to not be paying attention to little details about inputs. For a while now if a miner sends the block find award to their Mt. Gox address then Mt. Gox will use the inputs resulting from that block find before the inputs are valid. This causes any transaction with said input to be ignored. The proper solution is to wait the ~100 confirms before using the new btc. Note that this is a separate problem from the duplicated transactions. The point is: Mt. Gox is not tracking their bitcoin at the correct granularity. They appear to have written the software like we might use the bitcoin rpc api, without paying close attention to the details.
- deleted 13y ago[deleted]
- sharkweek 13y agoSo people with money frozen by MtGox are w/o recourse while the funds crash? Yikes... Kind of reminds me of that online poker company that got in trouble with the law and people were trading "[name of company, I forgot] dollars" for below value in an attempt to recoup some of their funds.
- teraflop 13y agoThe exact same thing is happening with MtGox: https://www.bitcoinbuilder.com/ https://www.bitcoinbuilder.com/ Looks like Gox bitcoins are currently available for roughly a 60% discount.
- SwellJoe 13y agoYes, there are Mt Gox BTC, trading for about half of a real world BTC: https://bitcoinbuilder.com/ https://bitcoinbuilder.com/ There is some fear that funds may have been lost on a large scale, due to this bug, and that Mt Gox simply won't be able to make good on their accounts. Some have suggested that Gox is buying BTC at the current deflated price to try to cover the gap. All of this is hearsay, and I don't know how much of it I would believe. It's difficult to take the Gox folks at their word, however, given their reticence about providing details of what they're up to, and the slowness of a return to normalcy.
- StavrosK 13y agoI don't understand how that works. I had $1000 in my account, say, and it was worth 1 BTC. Now it's worth 10. Isn't that much more expensive for Gox to return?
- shawabawa3 13y agoYou aren't buying directly from Gox, it's an exchange. You can buy 10x more bitcoins with your money, but you're buying from people who have lost confidence in the exchange and believe they are more likely to get their USD out than their bitcoins. MtGox should be full reserve, that is, they should be holding 100% of all user's bitcoins and fiat deposits, only skimming off the exchange fees.
- dscrd 13y agoExcept for the last bit, also Bitstamp (a slightly more reputable site) had the same story. They fixed it in a few days, though.
- rmc 13y agoDidn't other BitCoin excahnges suffer the same problem with "losing transactions"?
- aestra 13y agoOther exchanges were DDoSed but never lost any coins or got hit with double spends. http://www.wired.com/wiredenterprise/2014/02/bitcoin-ddos/ http://www.wired.com/wiredenterprise/2014/02/bitcoin-ddos/
- kzrdude 13y agoIs there any evidence in the blockchain of this being exploited? Can you see if there are occurences of MtGox paying out twice?
- dobbsbob 13y agoMtGox had plenty of problems before their php hot wallet was emptied like multiple civil suits, their US accounts being frozen with millions seized, and their Dwolla account was also seized full of funds. And of course all that downtime for denial of service attacks which was their own fault. MagicalTux slammed BlackLotus, Prolexic and Cloudflare as garbage before somebody pointed out they left a bunch of open ports which is why they were still getting DDoS'd. That whole exchange is a joke from day 1.