Live data from Hacker News

Breaking open the Mt. Gox case, part 1

blog.wizsec.jp

41–50 of 99 posts

Re: Breaking open the Mt. Gox case, part 1

#41
post #36

Earlier quoted context omitted.

>Can't wait to get my refund :) I had like 0.000001 BTC in mtgox and it was worth it for the cute sticky unfoldy postcard thing I got from the Japanese court.

When did you get that? I never received such a card.

Years ago, it stated I was a creditor and was owed some comically tiny amount of BTC I had left in my account. Cool form factor, a sorta sticky postcard sized accordian you would pull apart, japanese on one side, english on the other.

Re: Breaking open the Mt. Gox case, part 1

#42
post #25
post #2

So according to the following, Vinnik was aware of the origin of bitcoins that were sold on BTC-e: > Some of the funds moved to BTC-e seem to have moved straight to internal storage rather than customer deposit addresses, hinting at a relationship between Vinnik and BTC-e. and he was stupid enough to deposit them back to his account on MtGox: > Moving coins back onto MtGox was what let us identify Vinnik, as the MtGo…

> All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. I don't see how this proves he had direct involvement in the scheme instead of just running a laundering service for people. This blog post mentioned he was connected to other thefts as well: >> The stolen MtGox coins were not the only stolen coins handled by Vinnik; coins stolen from Bitcoinica, Bit…

In the archived BitcoinTalk post (http://archive.is/6cFcY) he makes several references to that he is working and handling the frozen funds for a "client". (He also happens to reveal his full legal name.) Supports him working as a money launder or front man for someone else.

Re: Breaking open the Mt. Gox case, part 1

#43
post #18

Can't wait to get my refund :) It's still insane to me that MtGox never moved coins to a wallet or acknowledged the breach until long after it was too late. You would think if you have billions of dollars sitting somewhere and you realize someone is starting to take them you would, you know, do something .

> Can't wait to get my refund :) There's no chance of that, right? (Hence ":)") At the time of the MtGox implosion I was bummed to have lost a few hundred $ worth of BTC. Now I'd be very interested in recovering that balance ... in BTC.

I had a decent chunk of BTC. I would be shocked if I ever saw any of it.

Re: Breaking open the Mt. Gox case, part 1

#44
post #28
post #22

It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

IIRC the site was written in PHP and it was a miracle it didn't get hacked earlier (or, now it seems, it did, but the hackers kept the site running to maximize the heist).

https://gist.github.com/alainmeier/9319451

Re: Breaking open the Mt. Gox case, part 1

#45
post #28
post #22

It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

It really bothers me how often people repeat it like it means anything in this case. Like they forget Amazon was just selling books. Also no idea if it still uses any of the old code or just the name itself.

Re: Breaking open the Mt. Gox case, part 1

#46
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

I only hear about the hackers that empty addresses and wondered if they could be more effective by slowly draining. Well now know turns out the biggest one was doing just that

And even re-depositing it back!

Re: Breaking open the Mt. Gox case, part 1

#47
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Lots of people in Bitcoin hate KYC and AML laws, and consider them invasive. I am one of these people. In itself, it's not an indicator of wrongdoing.

Breaking the law is an indicator of criminal behavior, whether you like the law or not.

Re: Breaking open the Mt. Gox case, part 1

#48
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Lots of people in Bitcoin hate KYC and AML laws, and consider them invasive. I am one of these people. In itself, it's not an indicator of wrongdoing.

Hating KYC/AML law may not be a strong indicator of legal wrongdoing; breaking it, OTOH, is not merely an indicator of legal wrongdoing, but is itself such wrongdoing.

Re: Breaking open the Mt. Gox case, part 1

#49
post #28

Earlier quoted context omitted.

The site was originally made for trading Magic The Gathering Online cards by one guy who later got bored and then got into Bitcoin but I have no idea and wikipedia doesn't mention if they reused any code or just the domain name itself. It's a fun piece of trivia one crypto currency guy told me and it seems to be true.

IIRC the site was written in PHP and it was a miracle it didn't get hacked earlier (or, now it seems, it did, but the hackers kept the site running to maximize the heist). https://gist.github.com/alainmeier/9319451

"PHP can do anything, what about some ssh?" -Mark Karpelès

ಠ_ಠ

https://web.archive.org/web/20100701145902/http://blog.magic...

Re: Breaking open the Mt. Gox case, part 1

#50
post #25
post #2

So according to the following, Vinnik was aware of the origin of bitcoins that were sold on BTC-e: > Some of the funds moved to BTC-e seem to have moved straight to internal storage rather than customer deposit addresses, hinting at a relationship between Vinnik and BTC-e. and he was stupid enough to deposit them back to his account on MtGox: > Moving coins back onto MtGox was what let us identify Vinnik, as the MtGo…

> All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. I don't see how this proves he had direct involvement in the scheme instead of just running a laundering service for people. This blog post mentioned he was connected to other thefts as well: >> The stolen MtGox coins were not the only stolen coins handled by Vinnik; coins stolen from Bitcoinica, Bit…

If he ran BTC-e and some of the stolen Mt Gox coins were transferred directly from the Gox wallet to BTC-e's internal wallet (bypassing the BTC-e customer deposit wallets), doesn't that necessarily mean he was involved?
Post reply on HN