Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

11–20 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#13
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

> That crosses the line and goes deep into "willful negligence" territory, in my view.

Er, that's the thing that pushed you over the line? Not all the fraud and crime?

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#14
While this is flatout insane, it does not speak toward crypto's security directly. If you personally decide that you want a company to hold your crypto that's your decision and a poor one at that. You have the ability to create your own wallet and hold your funds in it securely. Some exchanges like Coinbase even have wallet apps so the transition is super easy to make.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#15
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

Yet FTX wasn’t hacked. Their own irresponsible bets lost it all instead.

I mean FTX had over 300 million dollars moved out of company funds, without company authorization, by parties unknown, and with insufficient monitoring to even know it happened until third parties let them know. So kind of depends on your definition of hacked, I guess.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#16
> The Forbes survey also revealed that FTX did not have a SOC audit and was hoping to get these certificates in Q4 2022 or Q1 2023 from Prescient Assurance LLC, but given the firm’s collapse in November, it is unlikely they got them or will do so.

https://www.forbes.com/sites/javierpaz/2022/12/02/crypto-exc...

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#17
post #2

Wait, what ? Private keys were stored in unprotected plaintext files regularly opened by multiple people at the company? WTF? That crosses the line and goes deep into "willful negligence" territory, in my view. The physical equivalent would be stacking customer assets like dollar bills and gold bars in big piles inside a heavily trafficked room that has no lock. The term "irresponsible" doesn't quite do justice to it…

Yet FTX wasn’t hacked. Their own irresponsible bets lost it all instead.

Why not both? https://www.bbc.com/news/business-64313624

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#18

> The Forbes survey also revealed that FTX did not have a SOC audit and was hoping to get these certificates in Q4 2022 or Q1 2023 from Prescient Assurance LLC, but given the firm’s collapse in November, it is unlikely they got them or will do so. https://www.forbes.com/sites/javierpaz/2022/12/02/crypto-exc...

Prescient Audits never gone well

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#20

Earlier quoted context omitted.

Yet FTX wasn’t hacked. Their own irresponsible bets lost it all instead.

I mean FTX had over 300 million dollars moved out of company funds, without company authorization, by parties unknown, and with insufficient monitoring to even know it happened until third parties let them know. So kind of depends on your definition of hacked, I guess.

Sounds like really nice plausible deniability for whomever came up with such a blatant wrong way of storing secrets/value
Post reply on HN