Live data from Hacker News

Inputs.io hacked – 4100 BTC stolen

inputs.io

151–160 of 193 posts

Re: Inputs.io hacked – 4100 BTC stolen

#151

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

I have better question:

If all transactions are public, in theory you could trace user, who has your bitcoin now. Than you could sue him to get your stolen stuff back.

Re: Inputs.io hacked – 4100 BTC stolen

#153
post #106

Earlier quoted context omitted.

> Also, Bitcoin can be confiscated by the government Not if you specifically want to prevent this. A bitcoin private key is 256-bit ECDSA, which provides 128 bits of security. If you can remember a 10 word randomly generated diceware phrase[1], you can securely store bitcoins in your brain. [1] calculating the private key as a SHA256(phrase) for example

A $5 wrench or a jail cell will deal with your encryption.

You are wrong and overly pessimistic. Look at DPR. The govt confiscated 174k BTC, but he supposedly has another (encrypted) ~500k BTC wallet, and he is NOT/will NOT be tortured to reveal the key.

Re: Inputs.io hacked – 4100 BTC stolen

#154
post #2

4100 BTC = 1.1 mil USD at current prices. These Bitcoins were stolen from website's "hot wallet" (every shared wallet has to operate one to process current withdrawals). This hot wallet was probably too hot though, as it seems that they had most of their coins online, and only about one third offline (other services claim to store 80-90% offline). According to postings on Bitcointalk.org forums people are getting bac…

I see what you did there[3] ;-) Also, it's a shame that this kind of breach happens, but it seems like it's been a while since a "$COMPANY hacked X BTC stolen" headline was out there[1]. There seem to have been more of those in the past and they appear with less frequency, which is a good thing, I guess. [1] Silk Road doesn't count toward this recollection, since it falls under the "Bitcoin $COMPANY busted by the fed…

You're right. I think the last few big online wallet breaches were Instawallet, and MyBitcoin.

For anyone who wants to get their missing BTC out of inputs.io (who doesn't), I've written a blog post here: http://bitcoinreviewer.com/inputs-io-hacked-refund/

Re: Inputs.io hacked – 4100 BTC stolen

#155

Earlier quoted context omitted.

Problem is that the coins can be traced, so they need to spend them anonymously.

Couldn't they tumble the coins and cash out?

Even if they do, the mixing service must be anonymous too. The blockchain provides irrefutable evidence, and you need at least one step to make the coins anonymous.

Re: Inputs.io hacked – 4100 BTC stolen

#156
post #138

Earlier quoted context omitted.

You can track the individual transactions. So if I have some tainted coins and I really do not like you. I know your main wallet and transfer 1$ worth of tainted coins to you. You can just transfer the tainted coins out of the wallet and that is it - the rest of the coins in your wallet are perfectly fine. That said, tainting is not a path we want to go down. The potential for abuse is enormous, and rendering more an…

Except bitcoins are completely fungible. Once the bitcoin is transferred in the wallet, you can no longer make any difference with the other bitcoins in the wallet ; it has no distinct identity anymore. Think transaction into a bank account : you cannot separate the money that was transfered in from what was already there. We can taint accounts, but not individual coins.

You know exactly what input transactions contains tainted coins, so you know the amount, and thus how many untainted coins there are.

Re: Inputs.io hacked – 4100 BTC stolen

#157
post #151

Is there anything to stop the community from creating a database of known-stolen Bitcoins which participants can choose to reject? I guess all it takes is one non-participating exchange, but it seems like you could make it much less convenient to cash out.

I have better question: If all transactions are public, in theory you could trace user, who has your bitcoin now. Than you could sue him to get your stolen stuff back.

Is it clear that you have any kind of legal property when you "own" a bitcoin? I mean, it's just some numbers in a distributed database (and not one with legal backing the way the banking system has).

Re: Inputs.io hacked – 4100 BTC stolen

#158

I don't know what you expected, Bitcoin enthusiasts. You bought into a system where coins could be permanently lost because you forgot a password. You bought into a system where the government cheerfully gained control of a large share of the market by simple confiscation. You have recreated money . But you aren't even good at it! You still think that simple cryptography will excuse you from the fact that you're gree…

Nobody is forcing you to use it OR help its development. Why do you even care?

I care because the stories are spamming up HN. You can't downvote stories, and flagging them would probably be considered inappropriate.

Re: Inputs.io hacked – 4100 BTC stolen

#159
post #46

Earlier quoted context omitted.

Banks losing $1 million to hackers are not exactly science fiction. Typical outcomes including authorities not catching the thief, insurance paying out or the bank self-insuring, reiterating NDAs to employees who became aware of the theft, and absolutely no media coverage. [Edit to add: For avoidance of ambiguity, I'm really, really, REALLY not suggesting that "Since banks are equally insecure, bitcoins are a great i…

> I'm really, really, REALLY not suggesting that "Since banks are equally insecure That's just as well, because otherwise I'd have to mock you. Banks are not equally insecure. I work for one, and we typically spend 10-20% of the cost of development for apps on security reviews and testing, and not from numptys from accounting firms, but actual, well-known, well-respected white hats who review our designs and run hack…

Serious question, not trying to be rude.

If banks are full of competent programmers, why are their customer-facing online banking websites so utterly, utterly terrible?

Re: Inputs.io hacked – 4100 BTC stolen

#160
post #2

4100 BTC = 1.1 mil USD at current prices. These Bitcoins were stolen from website's "hot wallet" (every shared wallet has to operate one to process current withdrawals). This hot wallet was probably too hot though, as it seems that they had most of their coins online, and only about one third offline (other services claim to store 80-90% offline). According to postings on Bitcointalk.org forums people are getting bac…

> I know this doesn't mean much, but I'm sorry, and saying that I'm very sad that this happened is an understatement. Um....I don't see how anyone is okay with this answer.

Because bitcoin! Way of the future man!

No thanks, I'll stick with insured deposits. Imagine if your bank called you up and said "Your money is gone, but we're reeeeeally sorry."

Post reply on HN