[ad_1]
Bitfinex told OCCRP that the analysis was incomplete and incorrect and there was evidence of negligence by other counterparties that led to the hack. Bitgo declined to comment. Ledger Lab did not respond to a request for comment.
The hacker covered his tracks with a data destruction tool, used to permanently delete logs and other digital artifacts that could have identified the original entry point into Bitfinex systems, meaning it is unclear how they got into the trading systems, only the security weaknesses they took advantage of once inside. Transferring the more than 119,000 bitcoins from over 2,000 user accounts to wallets under the control of the thieves took just over three hours. The cryptocurrency sat there for months until, starting in January 2017, someone started sending small amounts zigzagging through other accounts. The money was eventually cashed out or used to make small online purchases.
Investigators managed to track the money and, six years after the hack, arrested the couple for laundering the stolen bitcoins. Cell phones, fake passports and USB drives containing the electronic security keys to the wallet containing $3.9 billion worth of bitcoins were found under the couple’s bed in their apartment in New York. Both have pleaded not guilty and are awaiting trial.
It is unclear whether the lessons of the Bitfinex hack led to changes in company procedures. The company told OCCRP that the report was incorrect and that there was evidence of negligence by other counterparties that led to the hack. Bitgo declined to comment.
Karen A. Greenaway, a former FBI agent and cryptocurrency expert, says she believed Bitfinex’s security vulnerabilities were due to her desire to complete more transactions faster and thus increase her profits. The fact that [Bitfinex] did not provide [public] The report accepting responsibility and fixing the security flaws that led to the hack says more than any admission or denial on their part, the agent said.
Security experts say the crypto industry in general is less vulnerable to the type of relatively simple hacking that was happening at the time of the Bitfinex breach, but the size and complexity of the industry has grown significantly since then. .
The surface area that needs to be protected for Web3 is much larger than you might expect, says Max Galka, founder and CEO of blockchain analytics firm Elementus. In some cases, what might appear to be a smart contract hack might actually have happened several degrees of separation away.
Just as bitcoin stolen from Bitfinex exploded in value, the crypto industry itself is now massive, but the companies that provide its infrastructure are often more focused on speed and executing new ideas.
Many crypto companies have great ideas but just don’t think about security, says Hugh Brooks, director of security operations at blockchain security firm CertiK. They continue building a Web3 application until it is hacked. Only a handful of apps pass even the most basic checks.
While there has been progress, Brooks says, crypto companies need to invest a lot more in security. If you get hacked or make a mistake, it’s not just usernames and passwords, it’s someone’s life savings or potentially a huge amount of funds, he says. When dealing with internet money, the stakes are that much higher.
This article was prepared in partnership with the Organized Crime and Corruption Reporting Project, an investigative reporting platform for a global network of independent media centers and journalists.
|
Sources 2/ https://www.wired.com/story/security-lapses-at-hacked-crypto-exchange-bitfinex/ The mention sources can contact us to remove/changing this article |
[ad_2]