Block Journal
No Result
View All Result
  • Login
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
Magazine
Newsletter
  • Trending Now
  • Bitcoin
  • Altcoin
  • Ethereum
  • Analysis
  • Blockchain
  • Metaverse
  • NFT
  • DeFi
  • Web3
  • GameFi
  • ICO
  • Legal
  • Security
Block Journal
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
No Result
View All Result
Block Journal
No Result
View All Result
  • News
  • Crypto
  • Markets
  • Investing
  • Videos
  • Charts
Home Crypto Security

‘Giancarlo’ keys managed poorly says post-hack Bitfinex security report

News Room by News Room
May 26, 2023
in Security
Reading Time: 4 mins read
0 0
A A
0

The Organized Crime and Corruption Reporting Project (OCCRP) has reportedly obtained the security report created by Ledger Labs that was commissioned by Bitfinex after its 2016 hack. The report details numerous failures to follow industry best practice, failure to practice adequate logging, and failure to implement a whitelist.

The Bitfinex hack backstory

On August 2, 2016, Bitfinex was hacked in what was then the second-largest Bitcoins hack ever recorded. Indeed, 120,00 coins — then valued at around $70 million but today worth over $3 billion — were withdrawn from the platform forcing it to disable all deposits, trading, and withdrawals in response.

In the wake of the attack, Bitfinex announced that “We have arrived at the conclusion that losses must be generalized across all accounts and assets.” The company also claimed that every single account would receive a 36.067% haircut, and for each dollar that represented, users would receive a BFX token, valued at $1, that Bitfinex would try to repay.

Nathaniel Popper would later report that the haircut was not equally applied to all accounts and assets, insisting that Coinbase didn’t receive the same haircut.

They actually did pay, just not the 36%, and what they paid ended up being higher than if they just took the 36% haircut, got their BFX and sold it shortly thereafter.

— Zane Tackett (@tackettzane) January 20, 2022

Read more: ‘Bitcoin Willy Wonka’ Max Keiser now works for El Salvador gov’t

Former Bitfinex Director Zane Tackett claimed that Coinbase did receive a haircut, but revealed that it was smaller than other clients, undercutting the previous Bitfinex claim that “losses must be generalized across all accounts and assets.”

A few days later on August 17, Bitfinex would announce that it had retained Ledger Labs “to determine exactly how the security breach occurred and to make our system’s design better going forward,” and “to perform an audit of our complete balance sheet for both cryptocurrency and fiat assets and liabilities.”

Several months later, Bitfinex announced that “Ledger Labs has not been engaged to perform a financial audit of Bitfinex.” Eventually, in May 2017, Bitfinex announced that it had hired Friedman LLP to perform an audit. No update has ever been provided on the status of that audit but Friedman was unable to provide an audit for sister company Tether.

After the hack, Bitfinex promised to provide details on how it occurred but this never happened. It also reiterated that everyone received the same haircut and detailed the steps that should be taken by unverified users who the system “mistakenly” believed were US-based.

The report

While Bitfinex never released the security report that had been commissioned by Ledger Labs, the reporting by OCCRP does provide more insight into how the hack occurred.

The report details how Bitfinex’s system, which was an implementation of BitGo’s multi-signature wallet, needed two of three keys in order to withdraw. The report claims that Bitfinex irresponsibly had both keys on the same device, and so by compromising that single device, hackers were able to immediately bypass the BitGo withdrawal limits and drain the wallet.

The keys were supposedly linked to two separate emails, one labeled “giancarlo” used by Bitfinex chief financial officer Giancarlo Devasini, and another “admin” email address.

The report also details lapses including the lack of a whitelist for withdrawals and an absence of server logging. The report also suggested that the hack occurred in Poland, based on an analysis of IP addresses.

Dutch and Razzlekhan

The Bitfinex hacker has never been arrested, but early last year Heather Morgan and Ilya Lichtenstein were arrested for allegedly trying to launder the bitcoins stolen in this hack.

Razzlekhan: These are ‘Bitcoin launderer’ Heather Morgan’s greatest hits

Read more: Crypto rapper Razzlekhan lands new job despite facing 25 years in prison

When they were arrested, authorities were able to seize the vast majority of the bitcoin that was originally hacked from Bitfinex, however, neither has been accused of the hack. Among their other possessions that were seized were a variety of burner phones and spreadsheets that detailed their efforts to successfully clean the coins.

Bitfinex hasn’t disclosed any additional breaches since 2016, but its sister company Tether was hacked in November 2017.

Bitfinex, in its statement to OCCRP, said that the Ledger Labs report was “incomplete” and “incorrect” but has so far failed to provide its own post-mortem explaining how the hack occurred. It is also yet to provide an update on the promised financial audit from over half a decade ago.

Read the full article here

ShareTweetSharePinShareShareSend

Related News

Nigerian Crypto Firm Patricia Halts Withdrawal Post Exploit
Security

Nigerian Crypto Firm Patricia Halts Withdrawal Post Exploit

May 28, 2023
Arbitrum-Based Liquidity Protocol Exploited For $7.5M
Security

Arbitrum-Based Liquidity Protocol Exploited For $7.5M

May 28, 2023
Exchange CEO – The Lack of KYC and AML is BRC-20’s Biggest Risk
Security

Exchange CEO – The Lack of KYC and AML is BRC-20’s Biggest Risk

May 28, 2023
Tornado Cash DAO passes attacker’s proposal to hand back control
Security

Tornado Cash DAO passes attacker’s proposal to hand back control

May 27, 2023
Tornado Cash Attackers Surrender Governance Privileges After Stealing $1.5 Million
Security

Tornado Cash Attackers Surrender Governance Privileges After Stealing $1.5 Million

May 27, 2023
Crypto CEO falls victim to latest Twitter hack
Security

Crypto CEO falls victim to latest Twitter hack

May 27, 2023
The Sandbox Co-founder’s Twitter Account Was Hacked With Scam Airdrop
Security

The Sandbox Co-founder’s Twitter Account Was Hacked With Scam Airdrop

May 26, 2023
Hardware Wallet Provider Trezor Sees 900% Jump in Sales amid Ledger Controversy
Security

Hardware Wallet Provider Trezor Sees 900% Jump in Sales amid Ledger Controversy

May 26, 2023
iEarn Hacker Continues To Launder $11.6M Loot Through Tornado Cash
Security

iEarn Hacker Continues To Launder $11.6M Loot Through Tornado Cash

May 26, 2023

Discussion about this post

Latest News

GBP/USD bulls step in on US Dollar weakness

GBP/JPY eases from fresh seven-year high towards 173.00 amid market’s consolidation on UK holiday

May 29, 2023
US watching developments at First Republic, other banks – White House

AMP names Blair Vernon as CFO, dissolves Australian wealth management structure

May 29, 2023
Is the Stock Market Open Today? Here Are the Hours for Memorial Day 2023.

Is the Stock Market Open Today? Here Are the Hours for Memorial Day 2023.

May 29, 2023
Bitcoin Price Struggles To Catch Up With Ethereum But Eyes More Upsides

Bitcoin Price Prints Bullish Technical Pattern, Why Close Above $28,500 Is Critical

May 29, 2023
Ethereum’s Block Size Surges To 1-Month High – What This Means For ETH

Ethereum’s Block Size Surges To 1-Month High – What This Means For ETH

May 29, 2023
ADVERTISEMENT

Popular

  • EU states back ban on destruction of unsold clothing

    EU states back ban on destruction of unsold clothing

    0 shares
    Share 0 Tweet 0
  • Why the PBA Is Putting Bowling Awards On-Chain With Avalanche NFTs

    0 shares
    Share 0 Tweet 0
  • Bitcoin Climbs Past $27.4K but Remains in Holding Pattern as Investors Continue Their Debt Limit Vigil

    0 shares
    Share 0 Tweet 0
  • Blockchain Essential for Democratizing AI, Says SingularityNET COO 

    0 shares
    Share 0 Tweet 0
  • Crude Oil Futures: Further upside in the pipeline near term

    0 shares
    Share 0 Tweet 0
Block Journal

Block Journal is the world’s leading source in blockchain news and updates. Follow us to stay up-to-date with all you need to know in web3.

LEARN MORE »

Recent Posts

  • GBP/JPY eases from fresh seven-year high towards 173.00 amid market’s consolidation on UK holiday
  • AMP names Blair Vernon as CFO, dissolves Australian wealth management structure
  • Is the Stock Market Open Today? Here Are the Hours for Memorial Day 2023.

Trending Topics

Altcoin Analysis Bitcoin Blockchain Commodities Crypto DeFi Ethereum Forex Futures GameFi ICO Investing Legal Markets Metaverse News NFT Security Stocks Uncategorized Videos Web3

Get Informed

The most important crypto and finance news and events of the day

Be the first to know latest important news & events directly to your inbox.

By signing up, I agree to our TOS and Privacy Policy.

  • About
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Copyright © 2023 Block Journal - Created by Sawah Solutions.

No Result
View All Result
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine

Copyright © 2023 Block Journal - Created by Sawah Solutions.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.