Live data from Hacker News

Bitcoin Sinks After Hackers Steal $65M from Exchange

bloomberg.com

41–50 of 56 posts

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#41

Earlier quoted context omitted.

Real world banks are backed by the federal government, both in terms of the FDIC, and the FBI and broader DOJ. Robbing a bank is a federal offense, and that is frankly why "big heists" tends to be such great fiction. Mostly.

I'm pretty sure that stealing hundreds of thousands of dollars worth of a "thing", regardless of what that "thing" is, is a federal offense thanks to CFAA, if nothing else.

It depends. By design (for plausible deniability) the key is not a password, it's a mathematical fact which can be independently discovered.

If you generated weak keys then it's not theft for me to guess/calculate them and allocate those coins to myself.

This is why BTC is described as proving the strength of hash functions, etc. If it was easy to cheat, someone would claim the public bug bounty by giving themselves all the coins. Because they haven't, we have a fairly good minimum bound on the difficulty.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#42

Earlier quoted context omitted.

I'm pretty sure that stealing hundreds of thousands of dollars worth of a "thing", regardless of what that "thing" is, is a federal offense thanks to CFAA, if nothing else.

It depends. By design (for plausible deniability) the key is not a password, it's a mathematical fact which can be independently discovered. If you generated weak keys then it's not theft for me to guess/calculate them and allocate those coins to myself. This is why BTC is described as proving the strength of hash functions, etc. If it was easy to cheat, someone would claim the public bug bounty by giving themselves…

> If it was easy to cheat, someone would claim the public bug bounty by giving themselves all the coins.

But giving yourself all the coins means demonstrates that the system doesn't work conclusively, and guarantees that no one will accept the coins for goods and services, so while giving yourself "all the coins" destroys a lot of value, it doesn't actually capture any value. So, if you wanted to profit from an exploit you developed, you would not do that (if you wanted to discredit bitcoin and had developed the exploit, you would do that.)

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#43

> Bitcoin slumped 5.5 percent against the dollar as of 2:30 p.m. on Wednesday in Tokyo, bringing its two-day drop to 13 percent. Prices also sank 6.2 percent on Monday, although it was not clear if that initial move was related to the hack. The price has actually been dropping consistently since the 31st of July. Granted, this hack has caused a the drop to be bigger, but attributing the entire drop to it makes no sen…

> Bitcoin is artificially blocked from accepting more customers and grow.

There's no such thing as a bitcoin customer. And by growth, the only obstacle is number of transactions/block which is limited by design.

But there's no tps limit that we wouldn't blow through in a day if it were free. Building a distributed DB? Nah, just dump it all in the blockchain and make the world hold it for you. Without a limit, and the prices that come from approaching that limit, the system would never reach a balance.

The goal is that transaction costs pay miners. That only works if blocks are small enough to reasonably process and scarce enough to justify paying for.

For everything else, build a sidechain and do your micropayments on it - link to BTC every now and then for larger fund transfers.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#44

Earlier quoted context omitted.

It depends. By design (for plausible deniability) the key is not a password, it's a mathematical fact which can be independently discovered. If you generated weak keys then it's not theft for me to guess/calculate them and allocate those coins to myself. This is why BTC is described as proving the strength of hash functions, etc. If it was easy to cheat, someone would claim the public bug bounty by giving themselves…

> If it was easy to cheat, someone would claim the public bug bounty by giving themselves all the coins. But giving yourself all the coins means demonstrates that the system doesn't work conclusively, and guarantees that no one will accept the coins for goods and services, so while giving yourself "all the coins" destroys a lot of value, it doesn't actually capture any value. So, if you wanted to profit from an explo…

Right, they'd trickle them in to keep it secret. But that doesn't change the bug-bounty nature.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#45

In the long run, I think this is good for Bitcoin. It's supposed to be a decentralized currency. Centralizing Bitcoin in an exchange makes the exchange a big target. This disincentivizes centralization and limits how much centralization can actually happen when people are foolish enough to try. For individuals who lose Bitcoin because of exchanges getting hacked, it's because they leave Bitcoin in the exchange. This…

> this is good for Bitcoin ... The answer is, don't do that ... Make cold storage paper wallets and keep your Bitcoin there. Only in bitcoin land is theft considered good for the ecosystem. Only in bitcoin land does it make sense to blame laypeople for storing their money with financial institutions. Only in bitcoin land is it a best practice to secure your money using a password written on a piece of paper. Only in…

> Only in bitcoin land does it make sense to blame laypeople for storing their money with financial institutions.

Uh, yeah. That's the entire point of Bitcoin.

> Only in bitcoin land is it a best practice to secure your money using a password written on a piece of paper.

God no, at least not a password intended for human consumption. That's not what a cold wallet should be. It should be a key.

> Only in bitcoin land is it reasonable to expect consumers to do a better job of keeping their money secure than corporations with on staff security experts.

No, non-expert consumers should be using off-the-shelf security solutions made by a staff of security experts that they can use locally (i.e. physical Bitcoin wallets). It's just that not many people are working on that stuff, because most of the companies making Bitcoin stuff are catering to speculators trying to get rich quick.

There are a lot of really smart people working on creating centralized Bitcoin solutions, but frankly, that's just a bad idea, as evidenced by almost every centralized Bitcoin solution having been hacked at least once. A centralized system has too wide an attack surface and too high an incentive for attackers, and defeats most of the benefits of Bitcoin anyway.

Sure, it makes Bitcoin a poor choice for speculators looking to get rich quick, but I don't care in the least. They're outsiders who don't understand the tool and aren't on board with the philosophy of why Bitcoin is important.

If you don't understand decentralization and you try to be in Bitcoin, you're going to have a bad time.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#46

Earlier quoted context omitted.

> If it was easy to cheat, someone would claim the public bug bounty by giving themselves all the coins. But giving yourself all the coins means demonstrates that the system doesn't work conclusively, and guarantees that no one will accept the coins for goods and services, so while giving yourself "all the coins" destroys a lot of value, it doesn't actually capture any value. So, if you wanted to profit from an explo…

Right, they'd trickle them in to keep it secret. But that doesn't change the bug-bounty nature.

It changes the (paraphrased) "we can tell its secure because no one has visibly compromised for profit it the way they would if they could" nature you suggested uphtread, because, for profit, you would avoid visibly compromising it.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#47
post #23

Interesting: the thief is currently attempting to launder a fraction (1000 BTC, worth ~$550k) through a giveaway: https://www.reddit.com/r/Bitcoin/comments/4vykkr/1000_btc_gi... https://bitcointalk.org/index.php?topic=1574127.0 He is sending the coins as we speak: https://blockchain.info/address/1BfxSuxJqXuizBbTcP238JZY9DT4... As a contingency, to plan for his possible arrest/death/etc, he signed a NLOCKTIME transact…

I don't understand why every hacker tries to come up with a novel way of laundering bitcoins or tries to launder them all at once.

Is there something urgent they need to spend thousands of bitcoins on right now that they can't just launder a hundred bitcoins a day through tumblers over the next few years?

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#48
post #25

Earlier quoted context omitted.

Bitfinex was required by US regulators to switch from cold storage to segregated per-user wallets. Something to do with margin requirements for commodities exchanges.

Correct. Here is the source: "CFTC Regulation Prevented Bitfinex From Using Cold Storage" http://imgur.com/O46UNix

Actually it is incorrect. Source - Zane Tackett (Director of Community and Product Development at Bitfinex): https://np.reddit.com/r/BitcoinMarkets/comments/4vtv1m/bitfi...

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#49
post #23

Interesting: the thief is currently attempting to launder a fraction (1000 BTC, worth ~$550k) through a giveaway: https://www.reddit.com/r/Bitcoin/comments/4vykkr/1000_btc_gi... https://bitcointalk.org/index.php?topic=1574127.0 He is sending the coins as we speak: https://blockchain.info/address/1BfxSuxJqXuizBbTcP238JZY9DT4... As a contingency, to plan for his possible arrest/death/etc, he signed a NLOCKTIME transact…

I don't understand why every hacker tries to come up with a novel way of laundering bitcoins or tries to launder them all at once. Is there something urgent they need to spend thousands of bitcoins on right now that they can't just launder a hundred bitcoins a day through tumblers over the next few years?

You're assuming that they have a vested interest in holding their Bitcoins for some greater good.

Re: Bitcoin Sinks After Hackers Steal $65M from Exchange

#50

Earlier quoted context omitted.

Sure, I think I understand that, and I appreciate your answer. My question is why do you need any bitcoins at all in hot storage? What's wrong with netting until the end of the day and then put the required amount of coins in a hot wallet to do settlement say 24 hours after a trade? Wouldn't this cooling off period give software and risk managers a chance to find invalid transactions and keep funds from being stolen…

Bitfinex was required by US regulators to switch from cold storage to segregated per-user wallets. Something to do with margin requirements for commodities exchanges.

This reminds me of when Mt. Gox was hacked and it was later found out that US Homeland Security officers (who were undercover) stole coins and laundered them through another exchange. Seems like someone in the CFTC wanted some coins for themselves..
Post reply on HN