It sounds like MtGox must have had no auditing of their wallets, or completely ineffective auditing. How did they not at least perform a simple sum of coins held by their wallets and compare it against the amount expected by their databases? Or is the attack more sophisticated than this would detect? If I were building a system like this, I'd want to run an auditing system continuously that looks for discrepancies, a…
In trading environments we have a thing called drop copy that is a real-tine feed of what the street thinks the house's trades are. This is constantly compared to what tree house's own view is. This way trade breaks (discrepancies) are caught immediately. The analogy would be scanning the block chain looking for tree firm's account numbers to verify all transactions are accounted for. I don't know for the life of me…
There were one or two exchanges that did things "right" (e.g. TradeHill) and were immediately driven out of business by their own high costs.