Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

61–70 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#61
post #15

Do bit coins have identity and hence be flagged as stolen somewhere ?.

In theory, each coin (called transaction output in bitcoin lingo) can be traced through a chain of transactions to its originating block. In practice, this is useless because there is no correspondence between bitcoin addresses and individuals (except in certain points like exchanges that require your ID)

In other words, each time a coin changes addresses there is a plausible deniability for the owner of the receiving address that s/he received the coin as a result of a legitimate transaction (sale of goods/services, donation, whatever)

Re: Inputs.io hacked – 4100 BTC stolen

#62

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

Many members of the community have reacted quite loudly and negatively to the suggestion that a central authority should be able to declare certain bitcoins tainted. This effectively introduces an external-to-the-blockchain way to essentially remove their bitcoins from their control, which they (currently) believe is impossible in bitcoin, and which they believe would devalue their bitcoins if it were known to be possible.

Re: Inputs.io hacked – 4100 BTC stolen

#64
post #2

4100 BTC = 1.1 mil USD at current prices. These Bitcoins were stolen from website's "hot wallet" (every shared wallet has to operate one to process current withdrawals). This hot wallet was probably too hot though, as it seems that they had most of their coins online, and only about one third offline (other services claim to store 80-90% offline). According to postings on Bitcointalk.org forums people are getting bac…

[deleted]

Re: Inputs.io hacked – 4100 BTC stolen

#65

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

But they can always just run them through mixing services.

Re: Inputs.io hacked – 4100 BTC stolen

#66

I had hundreds of Bitcoin on Coinlenders up until very recently when they switched to a "demo" legal-workaround that was legally terrible and childish. Coinlenders is a sister site to Inputs that share the same wallets. Coinlenders funds are being re-distributed to Inputs wallets. I obviously made a good decision to leave Coinlenders when I did as Coinlenders users are going to get perhaps 40% of their invested amoun…

I don't know, $1.1M is a lot of money. If someone stole a million dollars from my company, I don't know if I'd be rushing to reimburse it with personal funds (assuming I even could), however bad I felt for the users.

That said, if I recall correctly, one case where the corporate veil can potentially be pierced in a lawsuit is negligence. IANAL, but maybe users would have a legitimate case against personal funds, assuming keeping a large percentage of deposits online was found to be negligent. It'd obviously be an incredibly complicated and expensive class action suit if it were to happen though. Also it would probably mean trying to bankrupt a guy who just got hacked and lost his company...

Re: Inputs.io hacked – 4100 BTC stolen

#67
post #17

How do we know it's not the owner of input.io cashing out?

Here is his proof that it is not an inside job: https://bitcointalk.org/index.php?topic=283756.msg3505394#ms...

I'm curious, how would someone go about proving this wasn't an inside job. Is that possible?

Re: Inputs.io hacked – 4100 BTC stolen

#68

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

Well, one attack that I can come up with immediately is to just create a new wallet, transfer the bitcoins from the flagged wallet, then cash out from the new wallet. Your obvious retort would then be "Aha! But how about we just track any transactions from the flagged wallet and flag those wallets too!", sure, but then you open up for an alternative attack where you could get your wallet flagged and then send a minimal amount of bitcoins to some prominent wallet to have it automatically flagged (say the hot wallet of a major exchange), extortion anyone? To solve this we would need whitelists and the arms race goes on and on...

Re: Inputs.io hacked – 4100 BTC stolen

#69

Earlier quoted context omitted.

I think you might be able to just start and end with the laundry cleaners. Blockchain.info could just decide that they won't wash coins that they know were from a high profile hack like this.

They could, but there will always be people willing to accept the coins anyway. Without protocol support, it's not particularly meaningful.

I don't think it needs to be binary. Anyone today can choose to accept stolen or blood money. But I think you could create a distributed dye pack. It could just be an API that you query with a coin and receive a signed answer. Your Bitcoin client can report saying e.g. 'Blockchain.info thinks that this coin may be stolen. Accept anyway? Y/N' and leave it up to the user to decide. The downside is that the next person you try to give the coin to could decide that they trust Blockchain.info and not accept your money.

It's a democracy. If the masses decide that Blockchain.info is blocking coins that weren't stolen for some nefarious reason, they can just ignore their warning.

The question is: do the majority of bitcoin users even care if they are using stolen coins?

Re: Inputs.io hacked – 4100 BTC stolen

#70

I don't know what you expected, Bitcoin enthusiasts. You bought into a system where coins could be permanently lost because you forgot a password. You bought into a system where the government cheerfully gained control of a large share of the market by simple confiscation. You have recreated money . But you aren't even good at it! You still think that simple cryptography will excuse you from the fact that you're gree…

You fail to point out that cash has all the same drawbacks:

You can permanently lose cash if destroyed in a fire.

Your cash or bank account can be confiscated easily by the government.

Etc.

Of course, unlike cash, Bitcoin has advantages because it offers the option to prevent these losses: you can back up a Bitcoin wallet. You can avoid government confiscation (password-protected wallet). Etc.

Post reply on HN