Mintpal Exchange Exit Scam: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
No edit summary
(COMPLETE 30 minutes. Updated the opening description to describe what MintPal exchange is. Removing general template information. Prepared an initial prevention section filling in further. Added information from the blockchain for the MintPal wallet and final transactions. Integrated a lot more information on MintPal and the downfall from the CCN article. Filling in basic technical details of the incident.)
 
(3 intermediate revisions by the same user not shown)
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/mintpalexchangeexitscam.php}}
{{Case Study Under Construction}}{{Unattributed Sources}}
{{Unattributed Citations}}


[[File:Mintpal.jpg|thumb|MintPal]]After previously learning a valuable lesson in why funds shouldn't be stored online, Mintpal decided that they'd allow the new (non background-checked) manager Alex Green full access to customer funds, and not maintain full reserves.
[[File:Mintpal.jpg|thumb|MintPal Logo/Homepage]]MintPal was a cryptocurrency exchange based in the United Kingdom. After previously learning a valuable lesson in why funds shouldn't be stored online, Mintpal decided that they'd allow the new (non background-checked) manager Alex Green full access to customer funds, and not maintain full reserves.


This exchange or platform is based in United Kingdom, or the incident targeted people primarily in United Kingdom.
<ref name="newsdotbitcoin-14" /><ref name="kylegibson-86" /><ref name="bitcointalklist-87" /><ref name="bitcoinexchangeguide-218" /><ref name="slowmisthacked-1160" /><ref name="vice-3659" /><ref name="ledger-3639" /><ref name="ccn-4074" /><ref name="mintpalexchangetwitter-4075" /><ref name="mintpalexchangetwitter-4076" /><ref name="cointelegraph-3645" /><ref name="coindesk-3646" /><ref name="mintpalarchive-3649" /><ref name="mintpalarchive-3650" /><ref name="mintpalarchive-3651" /><ref name="reddit-4077" /><ref name="bitcoinist-4078" /><ref name="moolahblogarchive-4079" /><ref name="reddit-3648" /><ref name="cointelegraph-4080" /><ref name="foreignpolicy-7453" /><ref name="comparitech-10032" /><ref name=":0">[https://news.bitcoin.com/ryan-kennedy-rapist/ Infamous Crypto Scammer Ryan Kennedy Is Now a Convicted Rapist - Bitcoin News] (Accessed Nov 8, 2024)</ref><ref name=":1">[https://web.archive.org/web/20141021104046/https://www.cryptocoinsnews.com/mintpals-3700-stolen-bitcoin-likely-in-hands-of-alleged-scammer-alex-green/ MintPal’s 3700 Stolen Bitcoin Likely in Hands of Alleged Scammer Alex Green - CCN Archive October 21st, 2014 4:40:46 AM MDT] (Accessed Nov 15, 2024)</ref>
<ref name="newsdotbitcoin-7" /><ref name="newsdotbitcoin-14" /><ref name="kylegibson-86" /><ref name="bitcointalklist-87" /><ref name="bitcoinexchangeguide-218" /><ref name="slowmisthacked-1160" /><ref name="vice-3659" /><ref name="ledger-3639" /><ref name="ccn-4074" /><ref name="mintpalexchangetwitter-4075" /><ref name="mintpalexchangetwitter-4076" /><ref name="cointelegraph-3645" /><ref name="coindesk-3646" /><ref name="mintpalarchive-3649" /><ref name="mintpalarchive-3650" /><ref name="mintpalarchive-3651" /><ref name="reddit-4077" /><ref name="bitcoinist-4078" /><ref name="moolahblogarchive-4079" /><ref name="reddit-3648" /><ref name="cointelegraph-4080" /><ref name="foreignpolicy-7453" />


== About MintPal ==
== About MintPal ==
Line 20: Line 18:
"MintPal will not be responsible for any damages that you may suffer. MintPal makes no warranties of any kind, expressed or implied for services we provide. MintPal disclaims any warranty or merchantability or fitness for a particular purpose. This includes loss of data resulting from delays, non-deliveries, wrong delivery, and any and all service interruptions caused by MintPal and its employees."
"MintPal will not be responsible for any damages that you may suffer. MintPal makes no warranties of any kind, expressed or implied for services we provide. MintPal disclaims any warranty or merchantability or fitness for a particular purpose. This includes loss of data resulting from delays, non-deliveries, wrong delivery, and any and all service interruptions caused by MintPal and its employees."


"Moolah has recently picked up Mintpal." “The exchange was acquired by Moopay executive “Alex Green” who many believe was a shady scammer."
"At one time the cryptocurrency exchange Mintpal was one of the top trading platforms. Many traders used the service to exchange bitcoins and altcoins as the exchange processed large digital currency trading volumes."<ref name="newsdotbitcoin-7" />
 
=== Acquisition By Moolah ===
"Moolah has recently picked up Mintpal." "In the fall of 2014 customers were told Mintpal was going to have new ownership and rebrand as “Mintpal 2.0.”<ref name="newsdotbitcoin-7" />


"Our first action to take regarding MintPal, is to beef up the security, make a number of performance tweaks; do a formal audit and review of operational procedures. Once this is done, we will focus on introducing new features to both platforms. They already have a great platform, we just need to make sure that all the doors are locked, and that none of the windows are open."
"Our first action to take regarding MintPal, is to beef up the security, make a number of performance tweaks; do a formal audit and review of operational procedures. Once this is done, we will focus on introducing new features to both platforms. They already have a great platform, we just need to make sure that all the doors are locked, and that none of the windows are open."


“A total of 3,894 BTC was stolen from Mintpal customers and never returned. Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene. Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com”
=== Charitable and Random Giving ===
"Operating under the alias Alex Green, Kennedy gave away dogecoin on Reddit and other forums. He often tipped people hundreds and even thousands of dollars worth of dogecoin to strangers for no reason. He apparently gave liberally to the Dogecoin charity campaigns. Kennedy gave $2,450 worth of dogecoin to a cancer charity and $2,927 to support the Dogecoin branded NASCAR."<ref name=":0" />


"Thanks to all of you who have already donated, @CryptoCobain has sent the first 22 BTC raised directly to @Selachii_LLP to start proceedings"
"Kennedy then asked Dogecoin supporters to invest in Moolah. He offered investors a “slice of  pie” in his startup in exchange for dogecoins.
“How messy [the process] gets really depends on how cooperative Ryan is. The altcoins that didn't migrate to MintPal V2 – we estimate that to be around 1,000 BTC worth – we can return to users. The other missing amounts, including missing bitcoins, are still with Ryan and hopefully we can get him to cough up those as well. Then, we can return the bitcoins to customers and rebuild, rebrand from there.


This exchange or platform is based in United Kingdom, or the incident targeted people primarily in United Kingdom.
“Moolah’s sales pitch involved projected Doge dividends over the course of a couple years. They also claimed that the company was rapidly expanding and that their development team was working on a prototype Doge ATM,” one of Moolah’s investors  told ''Motherboard''. “Because the Dogecoin community was based so wholly on generosity, we were like sheep to the slaughter.”<ref name=":0" />


The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
== The Reality ==


Include:
"The exchange was acquired by Moopay executive “Alex Green” who many believe was a shady scammer."<ref name="newsdotbitcoin-7" />


* Known history of when and how the service was started.
"Luckily for some Mintpal users, the warning signs came early as the platform’s transformation to “Mintpal 2.0” was a complete disaster"<ref name="newsdotbitcoin-14" />
* What problems does the company or service claim to solve?
* What marketing materials were used by the firm or business?
* Audits performed, and excerpts that may have been included.
* Business registration documents shown (fake or legitimate).
* How were people recruited to participate?
* Public warnings and announcements prior to the event.
 
Don't Include:
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
 
== The Reality ==
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
 
* When the service was actually started (if different than the "official story").
* Who actually ran a service and their own personal history.
* How the service was structured behind the scenes. (For example, there was no "trading bot".)
* Details of what audits reported and how vulnerabilities were missed during auditing.


== What Happened ==
== What Happened ==
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
"A total of 3,894 BTC was stolen from Mintpal customers and never returned."<ref name="newsdotbitcoin-7" />
{| class="wikitable"
{| class="wikitable"
|+Key Event Timeline - Mintpal Exchange Exit Scam
|+Key Event Timeline - Mintpal Exchange Exit Scam
Line 65: Line 46:
!Description
!Description
|-
|-
|October 1st, 2014 12:00:35 AM
|October 13th, 2014 7:41:01 PM MDT
|Main Event
|Final Transaction On Cold Wallet
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.
|The final transaction on the wallet which is considered to be the cold storage wallet for MintPal<ref name=":2">[https://www.blockchain.com/explorer/addresses/btc/17ztgkcaZbs4VFrAswMQGvnNDEtn47rsmu MintPal Cold Storage Bitcoin Wallet - Blockchain.com] (Accessed Nov 15, 2024)</ref>.
|-
|-
|
|October 14th, 2014
|
|Abrupt Shutdown Of Exchange
|
|According to an article of incidents prepared by BitcoinTalk<ref name="bitcointalklist-87" />, this is the date when the MintPal exchange abruptly shut down with users funds officially unable to be withdrawn.
|-
|October 19th, 2014 1:21:00 AM MDT
|CNN Publishes News Article
|CCN (Crypto Coins News back then) publishes an article speculating that the missing 3,700 bitcoins are suspected to be in the hands of Alex Green<ref name=":1" />.
|-
|August 5th, 2016 2:51:20 PM MDT
|Ryan Kennedy Arrested
|The Moolah founder Ryan Kennedy/Alex Green is arrested based on unrelated charges<ref name=":0" />. "Kennedy worked as an office worker in Bristol at the time of his arrest in February."<ref name=":0" /> “The phrase ‘coercive control’ was coined to describe a situation where one person in a relationship, over a period of time, overshadows and eventually takes over control of the other person,” Judge Jamie Tabor QC said. “The premiere feature is that the victims are made to feel guilty if they don’t do as they are told.”<ref name=":0" />
|-
|February 3rd, 2017 10:00:04 AM MST
|Bitcoin News Article
|Mintpal is included in a data article by Bitcoin News<ref name="newsdotbitcoin-7" />. At this time, "Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene. Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com. The Moopay executive was not convicted for the Mintpal theft and has yet to claim responsibility."<ref name="newsdotbitcoin-7" />
|-
|October 20th, 2017 5:30:47 AM MDT
|UK Investigation Underway
|"[U]sers of the now-defunct cryptocurrency exchange Mintpal have received an email from the UK’s Avon and Somerset Economic Crime Team. The team’s detective constable, Charlotte Suter, has stated the police force is currently investigating the trading platform’s demise."<ref name="newsdotbitcoin-14" />
|}
|}
== Technical Details ==
On October 13th, the last transaction from the MintPal cold wallet was processed. Following that, no further withdrawals were able to take place for any user's bitcoin<ref name="bitcointalklist-87" /><ref name=":2" /><ref name=":3">[https://www.blockchain.com/explorer/transactions/btc/5305491c5228a6ca5045f8fb3014a08f039e079d58489d112b0aa17ef875fab3 Final Transaction From MintPal Wallet - Blockchain.com] (Accessed Nov 15, 2024)</ref>.
MintPal cold wallet account<ref name=":2" />. Final transaction<ref name=":3" />.


== Total Amount Lost ==
== Total Amount Lost ==
An article on BitcoinTalk provides a lower bound of 3894.49250000 BTC<ref name="bitcointalklist-87" />, which is translated to $3,208,412 USD<ref name="bitcointalklist-87" />.
An article by CCN (Crypto Coin News) shortly after the closure places the number at 3,700 bitcoin, which are worth $1.48m<ref name=":1" />.
"A total of 3,894 BTC was stolen from Mintpal customers and never returned."<ref name="newsdotbitcoin-7" />
The total amount lost has been estimated at $1,300,000 USD.
The total amount lost has been estimated at $1,300,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?


== Immediate Reactions ==
== Immediate Reactions ==
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Alex Green’s suspicious actions began when he announced Moopay’s bankruptcy and MintPal’s closure, offering vague excuses and delays regarding user withdrawals<ref name=":1" />. After the accusations surfaced, it was discovered that the stolen bitcoins were likely moved to a personal wallet linked to Ryan Kennedy, further implicating Green in a major cryptocurrency theft<ref name=":1" />.
 
== Ultimate Outcome ==
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?


== Total Amount Recovered ==
The case of MintPal’s stolen bitcoins points to Alex Green, the CEO of Moopay, who is accused of being a long-time Bitcoin scammer under the alias Ryan Kennedy<ref name=":1" />. MintPal, a popular Bitcoin exchange, shut down abruptly, trapping users' funds, including 3700 BTC (worth approximately $1.48 million)<ref name=":1" />. .
There do not appear to have been any funds recovered in this case.


What funds were recovered? What funds were reimbursed for those affected users?
"Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene."


== Ongoing Developments ==
== Ultimate Outcome ==
What parts of this case are still remaining to be concluded?
Alex Green claimed that Moopay had no control over MintPal, but later evidence suggested he was deeply involved in the exchange’s operations<ref name=":1" /> A former employee, Eoghan Hayes, revealed that the previous MintPal owners were also shocked to find Green in control of the exchange’s cold storage wallets<ref name=":1" />.


== Prevention Policies ==
"With partners fronting money, Kennedy purchased Mintpal, a crypto-currency exchange, but immediately it and Moolah had financial difficulties. Kennedy took Mintpal online citing a critical bug. Soon thereafter – as the internet began uncovering Kennedy’s darker side, which includes spying on women’s dressing rooms- users were out $2-$4 million in funds. Kennedy cited critical bugs. He then disappeared."<ref name=":0" />
Mintpal is one of those rare cases where all 3 prime causes of platform losses were present. Funds were stored online in the case of Vertcoin, there was no multi-sig employed, and full reserves were not maintained.


== References ==
In the aftermath, MintPal was delisted by CoinGecko, and many users reported that their Bitcoin withdrawals were never processed, while some received altcoins instead<ref name=":1" />.
<references><ref name="newsdotbitcoin-7">[https://news.bitcoin.com/bitcoin-exchange-thefts-forgotten/ The Bitcoin Exchange Thefts You May Have Forgotten | Featured Bitcoin News] (Jan 28, 2020)</ref>


<ref name="newsdotbitcoin-14">[https://news.bitcoin.com/uk-police-force-investigates-the-defunct-mintpal-exchange-and-owner/ UK Police Force Investigate the Defunct Mintpal Exchange and Owner | News Bitcoin News] (Feb 2, 2020)</ref>


<ref name="kylegibson-86">[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents] (Jan 25, 2020)</ref>
“A total of 3,894 BTC was stolen from Mintpal customers and never returned. Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene. Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com”


<ref name="bitcointalklist-87">[https://bitcointalk.org/index.php?topic=576337 List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses] (Feb 15, 2020)</ref>
"Thanks to all of you who have already donated, @CryptoCobain has sent the first 22 BTC raised directly to @Selachii_LLP to start proceedings"
“How messy [the process] gets really depends on how cooperative Ryan is. The altcoins that didn't migrate to MintPal V2 – we estimate that to be around 1,000 BTC worth – we can return to users. The other missing amounts, including missing bitcoins, are still with Ryan and hopefully we can get him to cough up those as well. Then, we can return the bitcoins to customers and rebuild, rebrand from there.”


<ref name="bitcoinexchangeguide-218">[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 5, 2020)</ref>
=== Arrest Of Alex Green/Ryan Kennedy ===
"Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com. The Moopay executive was not convicted for the Mintpal theft and has yet to claim responsibility."<ref name="newsdotbitcoin-7" />


<ref name="slowmisthacked-1160">[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 25, 2021)</ref>
=== Investigation By UK Authorities ===
“Operation Sparrow is an ongoing UK fraud investigation into the activities of Moolah and its former CEO Ryan Kennedy, also known as Alex Green,” explains the email’s author, detective constable Charlotte Suter. “The investigation focuses on Kennedy’s acquisition of Mintpal in 2014 and the subsequent disappearance and dispersal of customers’ funds from the exchange. Kennedy has been charged with a number of fraud offenses in relation to these matters and is due to face trial at Bristol Crown Court.”<ref name="newsdotbitcoin-14" /> Affected users were provided with a survey to gather data<ref name="newsdotbitcoin-14" />.


<ref name="vice-3659">[https://www.vice.com/en/article/78xqxb/the-guy-who-ruined-dogecoin The Guy Who Ruined Dogecoin] (Oct 3, 2021)</ref>
The situation is compared to the infamous Mt. Gox collapse, and the hope now is that law enforcement agencies like the US Department of Justice or SEC will investigate Green, whose whereabouts are currently unknown<ref name=":1" />.


<ref name="ledger-3639">[https://www.ledger.com/remembering-the-mintpal-hack Remembering the Mintpal Hack - October 2014 $3.500.000 Loss in Crypto Assets | Ledger] (Oct 1, 2021)</ref>
== Total Amount Recovered ==
There do not appear to have been any funds recovered in this case<ref name="newsdotbitcoin-7" />.


<ref name="ccn-4074">[https://www.ccn.com/alleged-moolah-fraudster-ryan-kennedy-faces-first-court-hearing/ https://www.ccn.com/alleged-moolah-fraudster-ryan-kennedy-faces-first-court-hearing/] (Oct 1, 2021)</ref>
== Ongoing Developments ==
What parts of this case are still remaining to be concluded?
== Individual Prevention Policies ==
Individuals must exercise caution when selecting any platform to use for their funds.


<ref name="mintpalexchangetwitter-4075">[https://twitter.com/MintPalExchange/status/538097296370843648 @MintPalExchange Twitter] (Oct 1, 2021)</ref>
{{Prevention:Individuals:Avoid Third Party Custodians}}


<ref name="mintpalexchangetwitter-4076">[https://twitter.com/MintPalExchange/status/530760612125892608 @MintPalExchange Twitter] (Oct 1, 2021)</ref>
{{Prevention:Individuals:Store Funds Offline}}


<ref name="cointelegraph-3645">[https://cointelegraph.com/news/mintpal-hacked-considerable-amount-of-vericoin-stolen Mintpal Hacked 'Considerable Amount' Of VeriCoin Stolen] (Oct 1, 2021)</ref>
{{Prevention:Individuals:End}}


<ref name="coindesk-3646">[https://www.coindesk.com/business/2014/10/30/mintpal-vows-to-fight-former-moolah-ceo-in-court/ CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data] (Oct 2, 2021)</ref>
== Platform Prevention Policies ==
Mintpal is one of those rare cases where all 3 prime causes of platform losses were present. Funds were stored online in the case of Vertcoin, there was no multi-sig employed, and full reserves were not maintained.


<ref name="mintpalarchive-3649">[https://web.archive.org/web/20140625072438/https://www.mintpal.com/ MintPal] (Oct 2, 2021)</ref>
{{Prevention:Platforms:Implement Multi-Signature}}


<ref name="mintpalarchive-3650">[https://web.archive.org/web/20140626165710/https://www.mintpal.com/about MintPal] (Oct 2, 2021)</ref>
{{Prevention:Platforms:Regular Audit Procedures}}


<ref name="mintpalarchive-3651">[https://web.archive.org/web/20140626161118/https://www.mintpal.com/security MintPal] (Oct 2, 2021)</ref>
{{Prevention:Platforms:Establish Industry Insurance Fund}}


<ref name="reddit-4077">[https://www.reddit.com/r/Bitcoin/comments/77f2gt/mintpal_operation_sparrow/ MintPal - Operation Sparrow : Bitcoin] (Nov 12, 2021)</ref>
{{Prevention:Platforms:End}}


<ref name="bitcoinist-4078">[https://bitcoinist.com/mintpal-is-acquired-by-moolah-io/ Mintpal is acquired by Moolah.io – Bitcoinist.com] (Nov 12, 2021)</ref>
== Regulatory Prevention Policies ==
{{Prevention:Regulators:Platform Security Assessments}}


<ref name="moolahblogarchive-4079">[https://web.archive.org/web/20140731001237/https://blog.moolah.io/2014/07/28/were-taking-over-mintpal-heres-what-you-need-to-know/ We’re taking over MintPal, here’s what you need to know. | Moolah] (Nov 12, 2021)</ref>
{{Prevention:Regulators:Establish Industry Insurance Fund}}


<ref name="reddit-3648">[https://www.reddit.com/r/reddCoin/comments/2ankyk/vericoins_solution_to_mintpal_hack_a_dangerous/ VeriCoin's 'solution' to Mintpal hack - a dangerous precedent? : reddCoin] (Oct 2, 2021)</ref>
{{Prevention:Regulators:End}}


== References ==
<references>
<ref name="newsdotbitcoin-7">[https://news.bitcoin.com/bitcoin-exchange-thefts-forgotten/ The Bitcoin Exchange Thefts You May Have Forgotten - Bitcoin News] (Accessed Jan 29, 2020)</ref>
<ref name="newsdotbitcoin-14">[https://news.bitcoin.com/uk-police-force-investigates-the-defunct-mintpal-exchange-and-owner/ UK Police Force Investigate the Defunct Mintpal Exchange and Owner - Bitcoin News] (Accessed Feb 3, 2020)</ref>
<ref name="kylegibson-86">[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents] (Jan 25, 2020)</ref>
<ref name="bitcointalklist-87">[https://bitcointalk.org/index.php?topic=576337 List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses - BitcoinTalk] (Accessed Feb 15, 2020)</ref>
<ref name="bitcoinexchangeguide-218">[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 5, 2020)</ref>
<ref name="slowmisthacked-1160">[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 26, 2021)</ref>
<ref name="vice-3659">[https://www.vice.com/en/article/78xqxb/the-guy-who-ruined-dogecoin The Guy Who Ruined Dogecoin] (Oct 4, 2021)</ref>
<ref name="ledger-3639">[https://www.ledger.com/remembering-the-mintpal-hack Remembering the Mintpal Hack - October 2014 $3.500.000 Loss in Crypto Assets | Ledger] (Oct 2, 2021)</ref>
<ref name="ccn-4074">https://www.ccn.com/alleged-moolah-fraudster-ryan-kennedy-faces-first-court-hearing/ (Oct 2, 2021)</ref>
<ref name="mintpalexchangetwitter-4075">[https://twitter.com/MintPalExchange/status/538097296370843648 @MintPalExchange Twitter] (Oct 2, 2021)</ref>
<ref name="mintpalexchangetwitter-4076">[https://twitter.com/MintPalExchange/status/530760612125892608 @MintPalExchange Twitter] (Oct 2, 2021)</ref>
<ref name="cointelegraph-3645">[https://cointelegraph.com/news/mintpal-hacked-considerable-amount-of-vericoin-stolen Mintpal Hacked 'Considerable Amount' Of VeriCoin Stolen] (Oct 2, 2021)</ref>
<ref name="coindesk-3646">[https://www.coindesk.com/business/2014/10/30/mintpal-vows-to-fight-former-moolah-ceo-in-court/ CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data] (Oct 3, 2021)</ref>
<ref name="mintpalarchive-3649">[https://web.archive.org/web/20140625072438/https://www.mintpal.com/ MintPal] (Oct 3, 2021)</ref>
<ref name="mintpalarchive-3650">[https://web.archive.org/web/20140626165710/https://www.mintpal.com/about MintPal] (Oct 3, 2021)</ref>
<ref name="mintpalarchive-3651">[https://web.archive.org/web/20140626161118/https://www.mintpal.com/security MintPal] (Oct 3, 2021)</ref>
<ref name="reddit-4077">[https://www.reddit.com/r/Bitcoin/comments/77f2gt/mintpal_operation_sparrow/ MintPal - Operation Sparrow : Bitcoin] (Nov 13, 2021)</ref>
<ref name="bitcoinist-4078">[https://bitcoinist.com/mintpal-is-acquired-by-moolah-io/ Mintpal is acquired by Moolah.io – Bitcoinist.com] (Nov 13, 2021)</ref>
<ref name="moolahblogarchive-4079">[https://web.archive.org/web/20140731001237/https://blog.moolah.io/2014/07/28/were-taking-over-mintpal-heres-what-you-need-to-know/ We’re taking over MintPal, here’s what you need to know. | Moolah] (Nov 13, 2021)</ref>
<ref name="reddit-3648">[https://www.reddit.com/r/reddCoin/comments/2ankyk/vericoins_solution_to_mintpal_hack_a_dangerous/ VeriCoin's 'solution' to Mintpal hack - a dangerous precedent? : reddCoin] (Oct 3, 2021)</ref>
<ref name="cointelegraph-4080">[https://cointelegraph.com/news/blockchain-aids-investigators-as-ex-mintpal-ceo-arrested-in-the-uk Blockchain Aids Investigators as Ex-Mintpal CEO Arrested in the UK] (Nov 29, 2021)</ref>
<ref name="cointelegraph-4080">[https://cointelegraph.com/news/blockchain-aids-investigators-as-ex-mintpal-ceo-arrested-in-the-uk Blockchain Aids Investigators as Ex-Mintpal CEO Arrested in the UK] (Nov 29, 2021)</ref>
 
<ref name="foreignpolicy-7453">[https://foreignpolicy.com/2021/02/11/dogecoin-how-does-it-work-elon-musk-cryptocurrency/ Dogecoin Started as a Joke and Became a Scam] (Mar 26, 2022)</ref>
<ref name="foreignpolicy-7453">[https://foreignpolicy.com/2021/02/11/dogecoin-how-does-it-work-elon-musk-cryptocurrency/ Dogecoin Started as a Joke and Became a Scam] (Mar 26, 2022)</ref></references>
<ref name="comparitech-10032">[https://www.comparitech.com/crypto/cryptocurrency-scams/ Worldwide crypto & NFT rug pulls and scams tracker - Comparitech] (Dec 15, 2022)</ref>
</references>

Latest revision as of 16:16, 15 November 2024

Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

MintPal Logo/Homepage

MintPal was a cryptocurrency exchange based in the United Kingdom. After previously learning a valuable lesson in why funds shouldn't be stored online, Mintpal decided that they'd allow the new (non background-checked) manager Alex Green full access to customer funds, and not maintain full reserves.

[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21][22][23][24]

About MintPal

"The fast, efficient and secure cryptocurrency exchange." "MintPal Limited is a UK based private company (registered UK company #09009856) that focuses on the exchanging of cryptocurrencies. Launched in early 2014, we aim to provide the best user experience matched with quick support times." "Our team is made up of talented developers and network engineers who know how to build a fast, efficient and secure system that takes advantage of the latest web technologies. Check out our security page to find out more about the security precautions we have in place."

"Our beautiful interface allows you to trade in real-time with live updating prices so you never miss the action. At just 0.15% per trade for both BUY and SELL orders, we have some of the lowest trading fees in the industry. MintPal has been built with strong security principles in mind. We utilise COLD storage and strict firewalls. Our support team handle customer queries throughout the day, never will you experience a long wait for a reply."

"A secure and reliable trading environment. A fast matching engine that executes trades within milliseconds. The latest market data available to all users as fast as possible. A highly scalable architecture that can handle spikes of activity. An appealing and responsive user interface that is easy to use. Fast support responses, typically within 24 hours. Full DDoS protection with a leading provider. CDN Caching for all static content. Distributed wallets and Hot/Cold wallets. Tiered design from day 1 to improve scalability. Push instead of pull to deliver all market updates as fast as possible. 2 Factor Authentication as standard for all staff."

"We store the majority of our customer's funds in a secure offline wallet, with only a portion available in a 'hot' wallet for instant withdrawals. This method vastly improves security at a minor expense of large withdrawals requiring manual processing. We utilize a leading DDoS provider for all public facing content and cache all static content on a CDN to provide the fastest possible load times. All website components are logically separated and protected by physical firewalls for increased security. All employees are required to connect to a secure VPN before gaining access to any systems. All interaction with the website is required over HTTPS so all communication is encrypted via SSL. Customers can set up two-factor authentication for accounts with Google Authenticator to provide an extra layer of security. We use an industry recognised PCI (credit card provisioning compliance) scanning service to routinely scan the website to aid in locating any potential security issues. We use industry standard methods for preventing SQL Injection & XSS attacks on our website. In additional, all passwords & sensitive data are encrypted along with a static & random salt."

"[T]he cryptocurrency exchange gaining a lot of publicity recently for events such as the attack with Vericoin, requiring it to fork." "MintPal accepts no liability for any loss however so arising suffered as a result of any failure or fault in the service provided by MintPal. Any compensation shall be at the discretion of MintPal."

"MintPal will not be responsible for any damages that you may suffer. MintPal makes no warranties of any kind, expressed or implied for services we provide. MintPal disclaims any warranty or merchantability or fitness for a particular purpose. This includes loss of data resulting from delays, non-deliveries, wrong delivery, and any and all service interruptions caused by MintPal and its employees."

"At one time the cryptocurrency exchange Mintpal was one of the top trading platforms. Many traders used the service to exchange bitcoins and altcoins as the exchange processed large digital currency trading volumes."[25]

Acquisition By Moolah

"Moolah has recently picked up Mintpal." "In the fall of 2014 customers were told Mintpal was going to have new ownership and rebrand as “Mintpal 2.0.”[25]

"Our first action to take regarding MintPal, is to beef up the security, make a number of performance tweaks; do a formal audit and review of operational procedures. Once this is done, we will focus on introducing new features to both platforms. They already have a great platform, we just need to make sure that all the doors are locked, and that none of the windows are open."

Charitable and Random Giving

"Operating under the alias Alex Green, Kennedy gave away dogecoin on Reddit and other forums. He often tipped people hundreds and even thousands of dollars worth of dogecoin to strangers for no reason. He apparently gave liberally to the Dogecoin charity campaigns. Kennedy gave $2,450 worth of dogecoin to a cancer charity and $2,927 to support the Dogecoin branded NASCAR."[23]

"Kennedy then asked Dogecoin supporters to invest in Moolah. He offered investors a “slice of  pie” in his startup in exchange for dogecoins.

“Moolah’s sales pitch involved projected Doge dividends over the course of a couple years. They also claimed that the company was rapidly expanding and that their development team was working on a prototype Doge ATM,” one of Moolah’s investors  told Motherboard. “Because the Dogecoin community was based so wholly on generosity, we were like sheep to the slaughter.”[23]

The Reality

"The exchange was acquired by Moopay executive “Alex Green” who many believe was a shady scammer."[25]

"Luckily for some Mintpal users, the warning signs came early as the platform’s transformation to “Mintpal 2.0” was a complete disaster"[1]

What Happened

"A total of 3,894 BTC was stolen from Mintpal customers and never returned."[25]

Key Event Timeline - Mintpal Exchange Exit Scam
Date Event Description
October 13th, 2014 7:41:01 PM MDT Final Transaction On Cold Wallet The final transaction on the wallet which is considered to be the cold storage wallet for MintPal[26].
October 14th, 2014 Abrupt Shutdown Of Exchange According to an article of incidents prepared by BitcoinTalk[3], this is the date when the MintPal exchange abruptly shut down with users funds officially unable to be withdrawn.
October 19th, 2014 1:21:00 AM MDT CNN Publishes News Article CCN (Crypto Coins News back then) publishes an article speculating that the missing 3,700 bitcoins are suspected to be in the hands of Alex Green[24].
August 5th, 2016 2:51:20 PM MDT Ryan Kennedy Arrested The Moolah founder Ryan Kennedy/Alex Green is arrested based on unrelated charges[23]. "Kennedy worked as an office worker in Bristol at the time of his arrest in February."[23] “The phrase ‘coercive control’ was coined to describe a situation where one person in a relationship, over a period of time, overshadows and eventually takes over control of the other person,” Judge Jamie Tabor QC said. “The premiere feature is that the victims are made to feel guilty if they don’t do as they are told.”[23]
February 3rd, 2017 10:00:04 AM MST Bitcoin News Article Mintpal is included in a data article by Bitcoin News[25]. At this time, "Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene. Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com. The Moopay executive was not convicted for the Mintpal theft and has yet to claim responsibility."[25]
October 20th, 2017 5:30:47 AM MDT UK Investigation Underway "[U]sers of the now-defunct cryptocurrency exchange Mintpal have received an email from the UK’s Avon and Somerset Economic Crime Team. The team’s detective constable, Charlotte Suter, has stated the police force is currently investigating the trading platform’s demise."[1]

Technical Details

On October 13th, the last transaction from the MintPal cold wallet was processed. Following that, no further withdrawals were able to take place for any user's bitcoin[3][26][27].

MintPal cold wallet account[26]. Final transaction[27].

Total Amount Lost

An article on BitcoinTalk provides a lower bound of 3894.49250000 BTC[3], which is translated to $3,208,412 USD[3].

An article by CCN (Crypto Coin News) shortly after the closure places the number at 3,700 bitcoin, which are worth $1.48m[24].

"A total of 3,894 BTC was stolen from Mintpal customers and never returned."[25]

The total amount lost has been estimated at $1,300,000 USD.

Immediate Reactions

Alex Green’s suspicious actions began when he announced Moopay’s bankruptcy and MintPal’s closure, offering vague excuses and delays regarding user withdrawals[24]. After the accusations surfaced, it was discovered that the stolen bitcoins were likely moved to a personal wallet linked to Ryan Kennedy, further implicating Green in a major cryptocurrency theft[24].

The case of MintPal’s stolen bitcoins points to Alex Green, the CEO of Moopay, who is accused of being a long-time Bitcoin scammer under the alias Ryan Kennedy[24]. MintPal, a popular Bitcoin exchange, shut down abruptly, trapping users' funds, including 3700 BTC (worth approximately $1.48 million)[24]. .

"Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene."

Ultimate Outcome

Alex Green claimed that Moopay had no control over MintPal, but later evidence suggested he was deeply involved in the exchange’s operations[24] A former employee, Eoghan Hayes, revealed that the previous MintPal owners were also shocked to find Green in control of the exchange’s cold storage wallets[24].

"With partners fronting money, Kennedy purchased Mintpal, a crypto-currency exchange, but immediately it and Moolah had financial difficulties. Kennedy took Mintpal online citing a critical bug. Soon thereafter – as the internet began uncovering Kennedy’s darker side, which includes spying on women’s dressing rooms- users were out $2-$4 million in funds. Kennedy cited critical bugs. He then disappeared."[23]

In the aftermath, MintPal was delisted by CoinGecko, and many users reported that their Bitcoin withdrawals were never processed, while some received altcoins instead[24].


“A total of 3,894 BTC was stolen from Mintpal customers and never returned. Alex Green (also known by another alias, Ryan Kennedy) had fled the cryptocurrency scene. Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com”

"Thanks to all of you who have already donated, @CryptoCobain has sent the first 22 BTC raised directly to @Selachii_LLP to start proceedings"

“How messy [the process] gets really depends on how cooperative Ryan is. The altcoins that didn't migrate to MintPal V2 – we estimate that to be around 1,000 BTC worth – we can return to users. The other missing amounts, including missing bitcoins, are still with Ryan and hopefully we can get him to cough up those as well. Then, we can return the bitcoins to customers and rebuild, rebrand from there.”

Arrest Of Alex Green/Ryan Kennedy

"Green has since been arrested by the authorities, but for rape charges, as reported by Bitcoin.com. The Moopay executive was not convicted for the Mintpal theft and has yet to claim responsibility."[25]

Investigation By UK Authorities

“Operation Sparrow is an ongoing UK fraud investigation into the activities of Moolah and its former CEO Ryan Kennedy, also known as Alex Green,” explains the email’s author, detective constable Charlotte Suter. “The investigation focuses on Kennedy’s acquisition of Mintpal in 2014 and the subsequent disappearance and dispersal of customers’ funds from the exchange. Kennedy has been charged with a number of fraud offenses in relation to these matters and is due to face trial at Bristol Crown Court.”[1] Affected users were provided with a survey to gather data[1].

The situation is compared to the infamous Mt. Gox collapse, and the hope now is that law enforcement agencies like the US Department of Justice or SEC will investigate Green, whose whereabouts are currently unknown[24].

Total Amount Recovered

There do not appear to have been any funds recovered in this case[25].

Ongoing Developments

What parts of this case are still remaining to be concluded?

Individual Prevention Policies

Individuals must exercise caution when selecting any platform to use for their funds.

When using any third party custodial platform (such as for trading), it is important to verify that the platform has a full backing of all assets, and that assets have been secured in a proper multi-signature wallet held by several trusted and trained individuals. If this can't be validated, then users should avoid using that platform. Unfortunately, most centralized platforms today still do not provide the level of transparency and third party validation which would be necessary to ensure that assets have been kept secure and properly backed. Therefore, the most effective strategy at present remains to learn proper self custody practices and avoid using any third party custodial platforms whenever possible.

Store the majority of funds offline. By offline, it means that the private key and/or seed phrase is exclusively held by you and not connected to any networked device. Examples of offline storage include paper wallets (seed phrase or key written down and deleted from all electronic media), hardware wallets, steel wallet devices, etc...

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Mintpal is one of those rare cases where all 3 prime causes of platform losses were present. Funds were stored online in the case of Vertcoin, there was no multi-sig employed, and full reserves were not maintained.

All wallets, minting functions, and critical infrastructure should be implemented with a multi-signature requirement, with a recommended minimum of 3 signatures required. This means that making important changes or approving spending will require the keys held by at least 3 separate individuals within the organization to approve. The multi-signature should be implemented at the lowest layer possible, all key holders should have security training, and all key holders should be empowered and encouraged to exercise diligence.

All aspects of any platform should undergo a regular validation/inspection by experts. This validation should include a security audit of any smart contracts, reporting any risks to the backing (of any customer assets, ensuring treasuries or minting functions are properly secured under the control of a multi-signature wallet, and finding any inadequacies in the level of training or integrity of the team. The recommended interval is twice prior to launch or significant system upgrade, once after 3 months, and every 6 months thereafter. It is recommended that the third party performing the inspection not be repeated within a 14 month period.

Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

All platforms should undergo published security and risk assessments by independent third parties. Two assessments are required at founding or major upgrade, one after 3 months, and one every 6 months thereafter. The third parties must not repeat within the past 14 months. A risk assessment needs to include what assets back customer deposits and the risk of default from any third parties being lent to. The security assessment must include ensuring a proper multi-signature wallet, and that all signatories are properly trained. Assessments must be performed on social media, databases, and DNS security.

Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. 1.0 1.1 1.2 1.3 1.4 UK Police Force Investigate the Defunct Mintpal Exchange and Owner - Bitcoin News (Accessed Feb 3, 2020)
  2. 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents (Jan 25, 2020)
  3. 3.0 3.1 3.2 3.3 3.4 List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses - BitcoinTalk (Accessed Feb 15, 2020)
  4. Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com (Mar 5, 2020)
  5. SlowMist Hacked - SlowMist Zone (Jun 26, 2021)
  6. The Guy Who Ruined Dogecoin (Oct 4, 2021)
  7. Remembering the Mintpal Hack - October 2014 $3.500.000 Loss in Crypto Assets | Ledger (Oct 2, 2021)
  8. https://www.ccn.com/alleged-moolah-fraudster-ryan-kennedy-faces-first-court-hearing/ (Oct 2, 2021)
  9. @MintPalExchange Twitter (Oct 2, 2021)
  10. @MintPalExchange Twitter (Oct 2, 2021)
  11. Mintpal Hacked 'Considerable Amount' Of VeriCoin Stolen (Oct 2, 2021)
  12. CoinDesk: Bitcoin, Ethereum, Crypto News and Price Data (Oct 3, 2021)
  13. MintPal (Oct 3, 2021)
  14. MintPal (Oct 3, 2021)
  15. MintPal (Oct 3, 2021)
  16. MintPal - Operation Sparrow : Bitcoin (Nov 13, 2021)
  17. Mintpal is acquired by Moolah.io – Bitcoinist.com (Nov 13, 2021)
  18. We’re taking over MintPal, here’s what you need to know. | Moolah (Nov 13, 2021)
  19. VeriCoin's 'solution' to Mintpal hack - a dangerous precedent? : reddCoin (Oct 3, 2021)
  20. Blockchain Aids Investigators as Ex-Mintpal CEO Arrested in the UK (Nov 29, 2021)
  21. Dogecoin Started as a Joke and Became a Scam (Mar 26, 2022)
  22. Worldwide crypto & NFT rug pulls and scams tracker - Comparitech (Dec 15, 2022)
  23. 23.0 23.1 23.2 23.3 23.4 23.5 23.6 Infamous Crypto Scammer Ryan Kennedy Is Now a Convicted Rapist - Bitcoin News (Accessed Nov 8, 2024)
  24. 24.00 24.01 24.02 24.03 24.04 24.05 24.06 24.07 24.08 24.09 24.10 MintPal’s 3700 Stolen Bitcoin Likely in Hands of Alleged Scammer Alex Green - CCN Archive October 21st, 2014 4:40:46 AM MDT (Accessed Nov 15, 2024)
  25. 25.0 25.1 25.2 25.3 25.4 25.5 25.6 25.7 25.8 The Bitcoin Exchange Thefts You May Have Forgotten - Bitcoin News (Accessed Jan 29, 2020)
  26. 26.0 26.1 26.2 MintPal Cold Storage Bitcoin Wallet - Blockchain.com (Accessed Nov 15, 2024)
  27. 27.0 27.1 Final Transaction From MintPal Wallet - Blockchain.com (Accessed Nov 15, 2024)