Live data from Hacker News

Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

reuters.com

101–110 of 312 posts

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#101

Bitcoin and other cryptocurrencies remain in technological infancy relative to the absurd amount of investor interest they hold. Hacks of this scale will likely continue to occur for the forseeable future, until exchanges develop and deploy techniques to limit potential lossage to hacks (e.g. minimal networked wallets), and will require several more years to provide a secure track record. In the interim, the convenie…

This seems to be exchange incompetence, their only wallet as a hot wallet. Disclaimer: I hold some XEM, have contributed to source, etc.

IIRC the only thing remotely close to breaking a crypto we've seen is the DAO hack; otherwise, it's generally incompetency somewhere along the chain, so that's not at all surprising to hear.

Rather astonishing in magnitude (a single hot wallet?), but such is tech.

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#102
post #33

As someone who knows very little about the blockchain, I was wondering if the Bitcoins are "known"? Like, they have a hash or something? Can't they be then blacklisted from use somehow? I thought the whole point of the blockchain was that all the transactions were all known?

[deleted]

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#103
post #50

A lot of people take for granted of a bank guarantees from govt. In a bank you are protected if the bank burns down or gets robbed empty. Unlike the Wild West here

Kind of an incorrect analogy. Exchanges aren't banks, they're more like open bazaars.

Your own cold wallet is the bank. Once you take the money to the bazaar, it becomes possible to be pick pocketed.

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#104
post #57

The 0x protocol will allow for decentralized exchanges, so hacks like this would be a thing of the past if it gains adoption. https://0xproject.com/

Lol, hope it isn't made using Solidity

Care to elaborate on these hopes? And the underlying humour…

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#105
post #95

Earlier quoted context omitted.

Uh. Wasn't the whole goddamn point of blockchains "censorship resistance"? Now people are saying that we can just ban transactions from certain addresses?

You can't ban them, but you could put together a "blacklist" on tokens from a particular origin that exchanges could agree to honour. It wouldn't stop anyone from trying to sell their coins in other ways.

That's basically forming a government. Who decides what goes in the list? Who ensures they'll keep honest? Who watches the watchers? What recourse does a user have against arbitrary measures?

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#106
post #58

Earlier quoted context omitted.

The coins stolen are XEM ( https://nem.io/ ) not Bitcoin. They're currently tracking the stolen coins to ensure they are not sold. Preliminary evidence suggests that it was a private key stolen and not a network problem. Disclaimer: Am somewhat associated with the team, and I hold a small amount of XEM. Feel free to ask questions.

Interesting. So is the implication here that it was probably an "inside job"? Were the private keys held in cold storage?

More information... looks like they only kept their Bitcoin in cold storage. Their altcoins were not. Dear god, the stupidity: https://bitpinas.com/news/coincheck-press-conference-japanes...

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#107

Earlier quoted context omitted.

https://api.gdax.com/products/BTC-USD/candles?granularity=60

Thanks. Is there a page that explains how to read that data?

https://docs.gdax.com/#get-historic-rates

There are more APIs there, publically accessible, small rate limit, have fun.

GDAX == Coinbase API. Trading on Coinbase makes, AFAIK, a market buy/sell through GDAX.

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#108
post #3

Conclusion: If you keep any cryptocurrency on an exchange or online service that can or is capable of controlling your private keys - MOVE all your cryptos to your own deterministic wallet YESTERDAY!

The possibility of an exchange getting hacked is much lower than the possibility of users losing founds by transferring them to their own wallet. I run a cryptocurrency forum and in 99% of reported cases users lost their founds by moving money from an exchange to a local wallet or even a hardware wallet. I always recommend everyone to keep it on an exchange.

Honest question. How is this possible? Isn't it as simple as copy and pasting the public address?

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#109

Posting this as a top level comment as well (probably a better idea): The coins stolen are XEM ( https://nem.io/ ) not Bitcoin. They're currently tracking the stolen coins to ensure they are not sold. Preliminary evidence suggests that it was a private key stolen and not a network problem. Disclaimer: Am somewhat associated with the team, and I hold a small amount of XEM. Feel free to ask questions.

'Am somewhat associated with the team' Can you please be more specific? It was almost not worth saying unless you'll be more specific IMHO.

Sorry, I'll clarify. I'm in the chat group quite a bit and have contributed to the wallet source code. I said partially as I'm not involved as an "official" capacity.

Re: Tokyo-based cryptocurrency exchange hacked, losing $530M: NHK

#110
post #33

As someone who knows very little about the blockchain, I was wondering if the Bitcoins are "known"? Like, they have a hash or something? Can't they be then blacklisted from use somehow? I thought the whole point of the blockchain was that all the transactions were all known?

The accounts on the NEM network (XEM was stolen, not Bitcoin) can be marked with a non-transferable asset. That was just automated and all known hacker addresses are now tainted.

Interesting - I'm unfamiliar with XEM, I presume the non-transferable mosaic (that were used to mark the accounts to which the stolen funds were transferred) is signed in some manner such that a copy couldn't be spoofed onto an arbitrary account?
Post reply on HN