Live data from Hacker News

Breaking open the Mt. Gox case, part 1

blog.wizsec.jp

51–60 of 99 posts

Re: Breaking open the Mt. Gox case, part 1

#51
post #29

> By mid 2013 [..] the thief had taken out about 630,000 BTC from MtGox. 630,000 BTC to USD = 1,560,069,000.00 US Dollars Crazy. $1.5 billion USD = 2.5% of Bitcoin's market cap ($40 billion) and someone stole it.

Around Mid 2013 Bitcoin supply was around 11.5M coins so 630K was more like 5.5% of total Bitcoin. Just using a different kind of math. There's more coins now so using todays market cap % makes it seem less then it actually was.

Re: Breaking open the Mt. Gox case, part 1

#52
post #51
post #29

> By mid 2013 [..] the thief had taken out about 630,000 BTC from MtGox. 630,000 BTC to USD = 1,560,069,000.00 US Dollars Crazy. $1.5 billion USD = 2.5% of Bitcoin's market cap ($40 billion) and someone stole it.

Around Mid 2013 Bitcoin supply was around 11.5M coins so 630K was more like 5.5% of total Bitcoin. Just using a different kind of math. There's more coins now so using todays market cap % makes it seem less then it actually was.

But mid 2013, the price of Bitcoin was ~$100.. So 630k was "only" $63 million. A much larger percentage of a much smaller asset.

Re: Breaking open the Mt. Gox case, part 1

#53
post #5
post #2

So according to the following, Vinnik was aware of the origin of bitcoins that were sold on BTC-e: > Some of the funds moved to BTC-e seem to have moved straight to internal storage rather than customer deposit addresses, hinting at a relationship between Vinnik and BTC-e. and he was stupid enough to deposit them back to his account on MtGox: > Moving coins back onto MtGox was what let us identify Vinnik, as the MtGo…

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Btc-e is currently under 'unplanned maintenance' [1], does anyone know if it has something to do with this?.

[1] https://btc-e.com/

Re: Breaking open the Mt. Gox case, part 1

#54

Earlier quoted context omitted.

I only hear about the hackers that empty addresses and wondered if they could be more effective by slowly draining. Well now know turns out the biggest one was doing just that

And even re-depositing it back!

At least I finally have comfort in my 2011 decisions not to buy bitcoin for $2 each with my little disposable cash:

"I'm not sending my living money to a sketchy exchange in Japan"

This is the exact sketchy kind of thing I imagined would be happening.

Re: Breaking open the Mt. Gox case, part 1

#55
post #53
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Btc-e is currently under 'unplanned maintenance' [1], does anyone know if it has something to do with this?. [1] https://btc-e.com/

Almost certainly. BTC-e always describes any and all issues as "maintenance".

Re: Breaking open the Mt. Gox case, part 1

#56
post #53
post #5

Earlier quoted context omitted.

>All in all, there a strong suggestion that he participated in money laundering and was involved in the whole scheme. Well duh, anyone involved in the Bitcoin community was very well aware of this. BTC-e has been flagrantly disregarding AML and KYC laws for it's entire existence.

Btc-e is currently under 'unplanned maintenance' [1], does anyone know if it has something to do with this?. [1] https://btc-e.com/

[deleted]

Re: Breaking open the Mt. Gox case, part 1

#57
post #4

This would have all been avoided if MtGox had transferred its coins to a new wallet after the 2011 breach. I guess they assumed that any attacker that got access to the private keys would have immediately emptied the wallet, and the fact that this hadn't happened proved that the private keys hadn't been compromised by the breach. I have to admit, that is a reasonable assumption. This may show the limits of the useful…

> I have to admit, that is a reasonable assumption. It costs dirt to move your coins. It's not remotely reasonable if you're in the Bitcoin world at all - if you have any reason to believe that an attacker had any access to your wallet the advice is always the same. Make a new wallet and transfer all the coins ASAP.

They said it's a reasonable assumption to believe your private keys likely weren't compromised. That's not the same as saying it's reasonable to not move the coins anyway.

Re: Breaking open the Mt. Gox case, part 1

#59
post #22

It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…

In trading environments we have a thing called drop copy that is a real-tine feed of what the street thinks the house's trades are. This is constantly compared to what tree house's own view is. This way trade breaks (discrepancies) are caught immediately.

The analogy would be scanning the block chain looking for tree firm's account numbers to verify all transactions are accounted for.

I don't know for the life of me why basic stuff like this isn't implemented. The crypto currency world is like a big joke.

Re: Breaking open the Mt. Gox case, part 1

#60
post #58

Unrelated to the actual topic at hand, but anybody know which software generated this svg? http://wizsec.jp/images/theft_flow.svg I like graphs like this. They remind me of Charles Joseph Minard's famous Napoleon graph: https://en.wikipedia.org/wiki/Charles_Joseph_Minard#/media/F...

D3: https://bost.ocks.org/mike/sankey/
Post reply on HN