Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

141–150 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#141
post #2

4100 BTC = 1.1 mil USD at current prices. These Bitcoins were stolen from website's "hot wallet" (every shared wallet has to operate one to process current withdrawals). This hot wallet was probably too hot though, as it seems that they had most of their coins online, and only about one third offline (other services claim to store 80-90% offline). According to postings on Bitcointalk.org forums people are getting bac…

When you're hacked, I hope someone posts a self-serving expose here.

Re: Inputs.io hacked – 4100 BTC stolen

#142
post #22
post #14

Earlier quoted context omitted.

You can still use a "mixing" service, which takes many coins from many sources and mixes it in a way that you can't tell anymore what is the source of Bitcoins you received. Blockchain.info operates one of these.

Interesting thought. Could there be "shunned" Bitcoins where, if they held certain blacklisted wallets in their history, businesses and users would choose not to accept them? One could imagine people still choosing to trade in these Bitcoins, but that such a penalty would forevermore reduce their value next to "unshunned" coins. Could legit businesses and people using Bitcoin collectively reduce the value of stolen B…

that would never work due to a simple reason -- there would never be a 100% way of telling if the "shunned" flag is legit.

Re: Inputs.io hacked – 4100 BTC stolen

#143
"Please don't store Bitcoins on an internet connected device, regardless of it is your own or a service's."

Best advice I've read so far about bitcoins. All these services that's started up around keeping bitcoins for you, wallets, banks, they are all dodgy and no matter how well their marketing seems or how nice their webpages look, I think in the end - I'd like to keep my own money.

Re: Inputs.io hacked – 4100 BTC stolen

#144
post #112

Earlier quoted context omitted.

A $5 wrench or a jail cell will deal with your encryption.

I don't think the US is at the point where they torture citizens for private keys. And they'd only be able to use jail as leverage by offering a reduced sentence. Even then, you might refuse if, for example, you'd rather stay in prison and leave the money to your family.

Be careful with your first sentence. For example, the US would not hesitate to torture Snowden for his key if they even had the slightest way to get their hands on him.

Just declare this person an enemy of the state/terrorist and there you go - to you and your encryption.

Re: Inputs.io hacked – 4100 BTC stolen

#145
post #62

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

Many members of the community have reacted quite loudly and negatively to the suggestion that a central authority should be able to declare certain bitcoins tainted. This effectively introduces an external-to-the-blockchain way to essentially remove their bitcoins from their control, which they (currently) believe is impossible in bitcoin, and which they believe would devalue their bitcoins if it were known to be pos…

I gather that it would be straightforward for individual bitcoin users to refuse to handle known-stolen bitcoins.

Perhaps this is illegal already - under local handling of stolen goods laws. People would likely be inclined to take up this policy were there a single case of legal enforcement.

I believe this would lead to a stable situation where those known-stolen bitcoins were worth far less than regular bitcoins.

The present loud reaction would become irrelevant. What's more, I believe it would benefit bitcoin to remove some of the danger of (irreversible) theft.

Re: Inputs.io hacked – 4100 BTC stolen

#146
They seem to be using Google Apps for the e-mail. And they claim:

    > The attacker was able to bypass 2FA due to a flaw on the server host side
Which flaw is this? Is it a known issue for Google? I would like to know more details.

Re: Inputs.io hacked – 4100 BTC stolen

#147
post #129
post #108

Earlier quoted context omitted.

If that guy did not have some kind of insurance like banks do, how can he refund anyone? ( that's a question ). And would insurances insure this kind of business ? Now are bitcoin wallets banks ? and are they subject to the same regulations ? Is that guy a US citizen ? can he be sued by his clients ?

> If that guy did not have some kind of insurance like banks do, how can he refund anyone? Bitcoin is a relatively new thing, would not be surprised to start seeing bitcoin insurance for these types of services. > Is that guy a US citizen ? can he be sued by his clients ? I think it would depend if his clients have contracts, otherwise its a caveat emptor deal, especially when dealing with bitcoin.

There was actually a Bitcoin "insurance" provider for a while. Like everything else in the Bitcoin economy, it was entirely unregulated, basically a scam, and ran with everyone's money.

Re: Inputs.io hacked – 4100 BTC stolen

#148

I had hundreds of Bitcoin on Coinlenders up until very recently when they switched to a "demo" legal-workaround that was legally terrible and childish. Coinlenders is a sister site to Inputs that share the same wallets. Coinlenders funds are being re-distributed to Inputs wallets. I obviously made a good decision to leave Coinlenders when I did as Coinlenders users are going to get perhaps 40% of their invested amoun…

I don't know, $1.1M is a lot of money. If someone stole a million dollars from my company, I don't know if I'd be rushing to reimburse it with personal funds (assuming I even could), however bad I felt for the users. That said, if I recall correctly, one case where the corporate veil can potentially be pierced in a lawsuit is negligence. IANAL, but maybe users would have a legitimate case against personal funds, assu…

Well, the site owner apparently promised to reimburse any deposit losses with his own funds back when he was trying to convince people to deposit money on the site: https://bitcointalk.org/index.php?topic=283756.msg3505423#ms...

Re: Inputs.io hacked – 4100 BTC stolen

#149
post #121

These coins were stored on a VPS? On Linode? All it took to steal 1 million USD was to hack an email account ? Insanity.

This needs to be upvoted more. How can someone have a hosting provider whilst claiming to be the most secure BANK out there? This should have been pointed out long ago. It's a terrible thing that people get away with this. Arrogant developers who think they can do without sysadmin skills when building crucial software.

> This should have been pointed out long ago.

It was. The creator smugly relied that it wasn't going to be an issue.

Re: Inputs.io hacked – 4100 BTC stolen

#150
post #139
post #89

Earlier quoted context omitted.

Wait a few years for the Bitcoin ecosystem to mature, and all the security mechanisms developed by banks (and more advanced ones that are just inapplicable to cash) will appear and be applied to Bitcoin: theft insurances, properly secured web wallets (HSM, userbased multi-sig, cold wallets, etc), tamper-proof hardware wallets, etc.

And at which point we'll be back to seeing 0.3+2.9% on every transaction to cover the costs of such...

Which will be fine. Even with such fees, Bitcoin would remain superior to existing currencies/payement networks: instant transfers across the world, censorship resistance, etc.
Post reply on HN