Mt. Gox Halts Trade Over Major Hack: Difference between revisions
(Another 30 minutes complete. About section spread around. Adding timeline. Added information on Karpeles conviction. Adding some sources on transaction malleability.) |
(COMPLETE Another 30 minutes. All sources sorted through. Lists moved to ultimate outcome, down to 12 sources left to be integrated. Andrei Jikh video and CryptoPotato article integrated.) |
||
| Line 3: | Line 3: | ||
[[File:Mtgox.jpg|thumb|Mt. Gox]]The most famous incident that everyone has heard of. Lack of secure storage for funds, a CEO who had his focus elsewhere, and the hacks apparently went undetected for months. There is still an ongoing bankruptcy. Luckily, at least one of the cold wallets escaped capture and can be used for disbursement. While victims have massive losses in bitcoin terms, due to the time that has passed they will most likely have minimal losses in fiat terms. | [[File:Mtgox.jpg|thumb|Mt. Gox]]The most famous incident that everyone has heard of. Lack of secure storage for funds, a CEO who had his focus elsewhere, and the hacks apparently went undetected for months. There is still an ongoing bankruptcy. Luckily, at least one of the cold wallets escaped capture and can be used for disbursement. While victims have massive losses in bitcoin terms, due to the time that has passed they will most likely have minimal losses in fiat terms. | ||
This exchange or platform is based in Japan, or the incident targeted people primarily in Japan. | This exchange or platform is based in Japan, or the incident targeted people primarily in Japan.<ref name="fintechnews-164" /><ref name="cointelegraph-197" /><ref name="coinsutra-202" /><ref name="darknetdiaries-1157" /><ref name="coindesk-4125" /><ref name="wallstreetjournal-4129" /><ref name="japantimes-4130" /><ref name="slashdotyro-7523" /><ref name="ceodotca-7527" /><ref name="bitcointalk-4667" /><ref name="youtube-8527" /> | ||
== About Mt. Gox == | == About Mt. Gox == | ||
<ref name="mtgoxarchive-4128" /> | |||
Mt. Gox launched with a very simple interface<ref name="mtgoxarchive1-4126" />. At the time Mt. Gox was established, there were very few other major trading platforms for cryptocurrencies. Mt. Gox was thus able to obtain over 80% of the global trading volume for bitcoin<ref name="mtgoxarchive2-4127" />.<blockquote>"Mt.Gox is the world's most established Bitcoin exchange. You can quickly and securely trade bitcoins with other people around the world with your local currency!" | Mt. Gox launched with a very simple interface<ref name="mtgoxarchive1-4126" />. At the time Mt. Gox was established, there were very few other major trading platforms for cryptocurrencies. Mt. Gox was thus able to obtain over 80% of the global trading volume for bitcoin<ref name="mtgoxarchive2-4127" />.<blockquote>"Mt.Gox is the world's most established Bitcoin exchange. You can quickly and securely trade bitcoins with other people around the world with your local currency!" | ||
| Line 24: | Line 27: | ||
3. Buy or Sell Bitcoins. | 3. Buy or Sell Bitcoins. | ||
4. Withdraw your converted funds."</blockquote>Basic features like SSL were provided for account security and 24/7 uptime was advertised as a selling point<ref name="mtgoxarchive2-4127" />. The Mt. Gox platform featured a "Norton Secured" seal<ref name="mtgoxarchive2-4127" />.<blockquote>"Mt.Gox is protected by Prolexic and certified by VeriSign, which means all communications with our servers are encrypted with SSL technology." "We're always on. Buy and sell Bitcoin 24/7/365 with the world's most sophisticated trading platform."</blockquote> | 4. Withdraw your converted funds."</blockquote>Basic features like SSL were provided for account security and 24/7 uptime was advertised as a selling point<ref name="mtgoxarchive2-4127" />. The Mt. Gox platform featured a "Norton Secured" seal<ref name="mtgoxarchive2-4127" />.<blockquote>"Mt.Gox is protected by Prolexic and certified by VeriSign, which means all communications with our servers are encrypted with SSL technology." "We're always on. Buy and sell Bitcoin 24/7/365 with the world's most sophisticated trading platform."</blockquote>At the time, Mt. Gox was the leading cryptocurrency exchange, handling over 70% of Bitcoin transactions<ref name="cryptopotato-161" />. | ||
== The Reality == | == The Reality == | ||
Unfortunately the Mt. Gox platform had a vulnerability which would allow repeated withdrawals of the same bitcoin from the platform. | Unfortunately the Mt. Gox platform had a vulnerability which would allow repeated withdrawals of the same bitcoin from the platform. | ||
| Line 38: | Line 42: | ||
|February 7th, 2014 | |February 7th, 2014 | ||
|Exchange Withdrawals Halted | |Exchange Withdrawals Halted | ||
|Mt. Gox halts all withdrawals from the exchange platform, citing a transaction malleability bug in the bitcoin core software. | |Mt. Gox halts all withdrawals from the exchange platform, citing a transaction malleability bug in the bitcoin core software<ref name="cryptopotato-161" />. | ||
|- | |- | ||
|February 24th, 2014 | |February 24th, 2014 | ||
|Mt. Gox Exchange Shuts Down | |Mt. Gox Exchange Shuts Down | ||
|The Mt. Gox exchange platform completely shuts down and returns a blank page. No trading is possible on the platform after this point. Also at this point, leaks start to surface of 744,408 bitcoin being missing. | |The Mt. Gox exchange platform completely shuts down and returns a blank page. No trading is possible on the platform after this point. Also at this point, leaks start to surface of 744,408 bitcoin being missing<ref name="cryptopotato-161" />. | ||
|- | |- | ||
|February 28th, 2014 | |February 28th, 2014 | ||
|Mt. Gox Files For Bankruptcy | |Mt. Gox Files For Bankruptcy | ||
|Mt. Gox files for bankruptcy. | |Mt. Gox files for bankruptcy. The exchange declared bankruptcy on February 28, 2014, attributing the success of the attackers to storing most of the stolen cryptocurrency in a web-based hot wallet, which had a vulnerability exploited by the hackers<ref name="cryptopotato-161" />. | ||
|- | |- | ||
|August 2015 | |August 2015 | ||
| Line 59: | Line 63: | ||
|Alexander Vinnik Arrested | |Alexander Vinnik Arrested | ||
|US authorities traced the bulk of the theft to a Russian named Alexander Vinnik, who is subsequently arrested in Greece. | |US authorities traced the bulk of the theft to a Russian named Alexander Vinnik, who is subsequently arrested in Greece. | ||
|- | |||
|November 9th, 2018 1:00:52 PM MST | |||
|CryptoPotato Lessons Learned | |||
|CryptoPotato published a "Lessons Learned from the Biggest Crypto Hacks in History" in which Mt. Gox is listed at number 2. The article discusses the Mt. Gox hack having a substantial impact on the cryptocurrency industry. The article emphasizes the need for heightened security in the crypto industry and advises users to be cautious about where they store their funds, suggesting the use of wallets offering cold storage, conducting due diligence on services, and prioritizing security. | |||
|- | |- | ||
|March 15th, 2019 | |March 15th, 2019 | ||
| Line 67: | Line 75: | ||
|Civil Rehabilitation | |Civil Rehabilitation | ||
|"In May [2021], the trustee presiding over the Mt. Gox civil rehabilitation case opened the voting on how to partially reimburse victims who lost money to the in hacks dating back nearly a decade." | |"In May [2021], the trustee presiding over the Mt. Gox civil rehabilitation case opened the voting on how to partially reimburse victims who lost money to the in hacks dating back nearly a decade." | ||
|- | |||
|November 16th, 2021 | |||
|Rehabilitation Plan Put Together | |||
|Courts start to put together a rehabilitation plan to pay back creditors<ref name="youtube-8527" />. | |||
|- | |||
|July 11th, 2022 4:30:18 PM MDT | |||
|Andrei Jikh Video | |||
|Andrei Jikh releases a video about "arguably one of biggest events in all of bitcoin's history which is the release of Mt. Gox's bitcoins". The release of the Mt. Gox bitcoins is next month in August. 137,890 bitcoin (worth 3 billion dollars are about to flood the market<ref name="youtube-8527" />. | |||
|} | |} | ||
| Line 72: | Line 88: | ||
=== Transaction Malleability Bug === | === Transaction Malleability Bug === | ||
Withdrawal failure, email customer service and ask for withdrawal to be retried. | |||
https://en.wikipedia.org/wiki/Transaction_malleability_problem | https://en.wikipedia.org/wiki/Transaction_malleability_problem | ||
| Line 79: | Line 97: | ||
== Total Amount Lost == | == Total Amount Lost == | ||
The hack resulted in the loss of 744,408 Bitcoins from customers and 100,000 BTC belonging to the company, with the total stolen amount valued at approximately $473 million<ref name="cryptopotato-161" />. | |||
The total amount lost has been estimated at $300,000,000 USD. | The total amount lost has been estimated at $300,000,000 USD. | ||
== Immediate Reactions == | |||
On February 7, 2014, Mt. Gox temporarily halted all BTC withdrawals, extending to all trading activities on February 24, and eventually going offline<ref name="cryptopotato-161" />. | |||
"On February 7th, MtGox halted all BTC withdrawals from the exchange, citing a transaction malleability bug in the core Bitcoin software. When withdrawals had still not resumed after 2 weeks, users began to suspect that MtGox may not be able to pay its customers. | "On February 7th, MtGox halted all BTC withdrawals from the exchange, citing a transaction malleability bug in the core Bitcoin software. When withdrawals had still not resumed after 2 weeks, users began to suspect that MtGox may not be able to pay its customers. | ||
| Line 95: | Line 115: | ||
== Ultimate Outcome == | == Ultimate Outcome == | ||
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done? | What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done? | ||
=== Case Listed Everywhere === | |||
As Mt. Gox was the largest exchange at the time, the situation was highly notable. The My. Gox situation was included in almost every list of cryptocurrency exchange hacks including Bitcoin Magazine<ref name="bitcoinmagazine-6" />, Kyle Gibson<ref name="kylegibson-86" />, a list published on BitcoinTalk<ref name="bitcointalklist-87" />, SlowMist<ref name="slowmisthacked-1160" />, and BitcoinExchangeGuide<ref name="bitcoinexchangeguide-218" /> (TBD Fix link). | |||
=== Insolvency Filing === | === Insolvency Filing === | ||
| Line 168: | Line 191: | ||
== References == | == References == | ||
<references> | <references> | ||
<ref name="bitcoinmagazine-6">[https://bitcoinmagazine.com/articles/infographic-overview-compromised-bitcoin-exchange-events Infographic: An Overview of Compromised Bitcoin Exchange Events] (Jan 30, 2020)</ref> | <ref name="bitcoinmagazine-6">[https://bitcoinmagazine.com/articles/infographic-overview-compromised-bitcoin-exchange-events Infographic: An Overview of Compromised Bitcoin Exchange Events - Bitcoin Magazine] (Jan 30, 2020)</ref> | ||
<ref name="kylegibson-86">[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents] (Jan 25, 2020)</ref> | <ref name="kylegibson-86">[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents - Kyle Gibson] (Jan 25, 2020)</ref> | ||
<ref name="bitcointalklist-87">[https://bitcointalk.org/index.php?topic=576337 List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses] (Feb 15, 2020)</ref> | <ref name="bitcointalklist-87">[https://bitcointalk.org/index.php?topic=576337 List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses - BitcoinTalk] (Feb 15, 2020)</ref> | ||
<ref name="cryptopotato-161">[https://cryptopotato.com/lessons-learned-from-the-biggest-crypto-hacks-in-history/ Lessons Learned from the Biggest Crypto Hacks in History] (Feb 26, 2020)</ref> | <ref name="cryptopotato-161">[https://cryptopotato.com/lessons-learned-from-the-biggest-crypto-hacks-in-history/ Lessons Learned from the Biggest Crypto Hacks in History - CryptoPotato] (Feb 26, 2020)</ref> | ||
<ref name="fintechnews-164">[https://fintechnews.sg/23594/blockchain/cryptocurrency-hack-binance/ A Look Back on Some of the Most Devastating Crypto Hacks | <ref name="fintechnews-164">[https://fintechnews.sg/23594/blockchain/cryptocurrency-hack-binance/ A Look Back on Some of the Most Devastating Crypto Hacks - Fintech Singapore] (Feb 27, 2020)</ref> | ||
<ref name="cointelegraph-197">[https://cointelegraph.com/news/crypto-exchange-hacks-in-review-proactive-steps-and-expert-advice Crypto Exchange Hacks in Review: Proactive Steps and Expert Advice] (Mar 2, 2020)</ref> | <ref name="cointelegraph-197">[https://cointelegraph.com/news/crypto-exchange-hacks-in-review-proactive-steps-and-expert-advice Crypto Exchange Hacks in Review: Proactive Steps and Expert Advice - CoinTelegraph] (Mar 2, 2020)</ref> | ||
<ref name="coinsutra-202">[https://coinsutra.com/biggest-bitcoin-hacks/ Top 6 Biggest Bitcoin Hacks Ever] (Mar 2, 2020)</ref> | <ref name="coinsutra-202">[https://coinsutra.com/biggest-bitcoin-hacks/ Top 6 Biggest Bitcoin Hacks Ever - CoinSutra] (Mar 2, 2020)</ref> | ||
<ref name="bitcoinexchangeguide-218">[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 5, 2020)</ref> | <ref name="bitcoinexchangeguide-218">[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 5, 2020)</ref> | ||
<ref name="darknetdiaries-1157">[https://darknetdiaries.com/episode/9/ The Rise and Fall of Mt. Gox – Darknet Diaries] (Jun 25, 2021)</ref> | <ref name="darknetdiaries-1157">[https://darknetdiaries.com/episode/9/ The Rise and Fall of Mt. Gox – Darknet Diaries] (Jun 25, 2021)</ref> | ||
<ref name="slowmisthacked-1160">[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 26, 2021)</ref> | <ref name="slowmisthacked-1160">[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 26, 2021)</ref> | ||
<ref name="coindesk-4125">[https://www.coindesk.com/business/2021/10/06/mt-gox-civil-rehabilitation-voting-deadline-ends-friday/ Mt. Gox Civil Rehabilitation Voting Deadline Ends Friday] (Oct 10, 2021)</ref> | <ref name="coindesk-4125">[https://www.coindesk.com/business/2021/10/06/mt-gox-civil-rehabilitation-voting-deadline-ends-friday/ Mt. Gox Civil Rehabilitation Voting Deadline Ends Friday - CoinDesk] (Oct 10, 2021)</ref> | ||
<ref name="mtgoxarchive1-4126">[https://web.archive.org/web/20110203031942/http://mtgox.com/ Mt Gox - Bitcoin Exchange - February 3rd, 2011 - Internet Archive] (Oct 12, 2021)</ref> | <ref name="mtgoxarchive1-4126">[https://web.archive.org/web/20110203031942/http://mtgox.com/ Mt Gox - Bitcoin Exchange - February 3rd, 2011 - Internet Archive] (Oct 12, 2021)</ref> | ||
<ref name="mtgoxarchive2-4127">[https://web.archive.org/web/20120112024603/https://mtgox.com/ Mt.Gox - Bitcoin Exchange - January 12th, 2012 - Internet Archive] (Oct 12, 2021)</ref> | <ref name="mtgoxarchive2-4127">[https://web.archive.org/web/20120112024603/https://mtgox.com/ Mt.Gox - Bitcoin Exchange - January 12th, 2012 - Internet Archive] (Oct 12, 2021)</ref> | ||
<ref name="mtgoxarchive-4128">[https://web.archive.org/web/20140318154627/https://www.mtgox.com/ MtGox.com] (Oct 13, 2021)</ref> | <ref name="mtgoxarchive-4128">[https://web.archive.org/web/20140318154627/https://www.mtgox.com/ MtGox.com] (Oct 13, 2021)</ref> | ||
<ref name="wallstreetjournal-4129">[https://www.wsj.com/articles/SB10001424052702304899704579388483531937144 Mt. Gox Shows Bitcoin's Growing Pains - WSJ] (Oct 14, 2021)</ref> | <ref name="wallstreetjournal-4129">[https://www.wsj.com/articles/SB10001424052702304899704579388483531937144 Mt. Gox Shows Bitcoin's Growing Pains - WSJ] (Oct 14, 2021)</ref> | ||
<ref name="japantimes-4130">[https://www.japantimes.co.jp/news/2019/04/06/national/media-national/solving-worlds-largest-bitcoin-heist/ Solving the world's largest bitcoin heist | <ref name="japantimes-4130">[https://www.japantimes.co.jp/news/2019/04/06/national/media-national/solving-worlds-largest-bitcoin-heist/ Solving the world's largest bitcoin heist - The Japan Times] (Oct 14, 2021)</ref> | ||
<ref name="slashdotyro-7523">[https://yro.slashdot.org/story/14/03/10/0733213/hackers-allege-mt-gox-still-controls-stolen-bitcoins Hackers Allege Mt. Gox Still Controls "Stolen" Bitcoins - Slashdot] (Apr 10, 2022)</ref> | <ref name="slashdotyro-7523">[https://yro.slashdot.org/story/14/03/10/0733213/hackers-allege-mt-gox-still-controls-stolen-bitcoins Hackers Allege Mt. Gox Still Controls "Stolen" Bitcoins - Slashdot] (Apr 10, 2022)</ref> | ||
<ref name="ceodotca-7527">[https://ceo.ca/@currencyfrontier/theone-simple-reason-why-bitcoin-went-down-againoverthe-weekend The One Simple Reason Why Bitcoin Went Down (Again) Over the Weekend] (Apr 10, 2022)</ref> | <ref name="ceodotca-7527">[https://ceo.ca/@currencyfrontier/theone-simple-reason-why-bitcoin-went-down-againoverthe-weekend The One Simple Reason Why Bitcoin Went Down (Again) Over the Weekend - Ceo.ca] (Apr 10, 2022)</ref> | ||
<ref name="bitcointalk-4667">[https://bitcointalk.org/index.php?topic=4412667.0 Bitcointalk history of MtGox and how a Bitcointalk post caught the MtGox hacker.] (Dec 22, 2021)</ref> | <ref name="bitcointalk-4667">[https://bitcointalk.org/index.php?topic=4412667.0 Bitcointalk history of MtGox and how a Bitcointalk post caught the MtGox hacker. - BitcoinTalk] (Dec 22, 2021)</ref> | ||
<ref name="youtube-8527">[https://www.youtube.com/watch?v=rgpfGsLW7II The Wealth Transfer Just Started | <ref name="youtube-8527">[https://www.youtube.com/watch?v=rgpfGsLW7II Andrei Jikh - The Wealth Transfer Just Started - YouTube] (Jul 16, 2022)</ref> | ||
</references> | </references> | ||
Revision as of 12:03, 26 January 2024
Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
The most famous incident that everyone has heard of. Lack of secure storage for funds, a CEO who had his focus elsewhere, and the hacks apparently went undetected for months. There is still an ongoing bankruptcy. Luckily, at least one of the cold wallets escaped capture and can be used for disbursement. While victims have massive losses in bitcoin terms, due to the time that has passed they will most likely have minimal losses in fiat terms.
This exchange or platform is based in Japan, or the incident targeted people primarily in Japan.[1][2][3][4][5][6][7][8][9][10][11]
About Mt. Gox
Mt. Gox launched with a very simple interface[13]. At the time Mt. Gox was established, there were very few other major trading platforms for cryptocurrencies. Mt. Gox was thus able to obtain over 80% of the global trading volume for bitcoin[14].
"Mt.Gox is the world's most established Bitcoin exchange. You can quickly and securely trade bitcoins with other people around the world with your local currency!"
"It allows you to trade US Dollars (USD) for Bitcoins (BTC) or Bitcoins for US Dollars with other Mt Gox users. You set the price you want to buy or sell your BTC for."
"Buy Bitcoins at market rates with your credit card or many other payment methods." "Automate your trading with our Trading API" "Dark pools allow you to trade large quantities without moving the market."
"Fully automated, always available, 24 hours a day, Safe and Easy."
"The only multi-currency Bitcoin trading platform where you can trade with the entire world in your local currency."
Users could trade on Mt. Gox using a wide range of world currencies[14]. Mt. Gox achieved a wide popularity due to the ease with which users could sign up for services there[13].
"Buying and selling Bitcoin doesn't have to be complicated! Get trading in a few simple steps."
"4 Easy Steps:
1. Make an Account.
2. Add some funds.
3. Buy or Sell Bitcoins.
4. Withdraw your converted funds."
Basic features like SSL were provided for account security and 24/7 uptime was advertised as a selling point[14]. The Mt. Gox platform featured a "Norton Secured" seal[14].
"Mt.Gox is protected by Prolexic and certified by VeriSign, which means all communications with our servers are encrypted with SSL technology." "We're always on. Buy and sell Bitcoin 24/7/365 with the world's most sophisticated trading platform."
At the time, Mt. Gox was the leading cryptocurrency exchange, handling over 70% of Bitcoin transactions[15].
The Reality
Unfortunately the Mt. Gox platform had a vulnerability which would allow repeated withdrawals of the same bitcoin from the platform.
What Happened
"On February 7th, MtGox halted all BTC withdrawals from the exchange, citing a transaction malleability bug in the core Bitcoin software."
| Date | Event | Description |
|---|---|---|
| February 7th, 2014 | Exchange Withdrawals Halted | Mt. Gox halts all withdrawals from the exchange platform, citing a transaction malleability bug in the bitcoin core software[15]. |
| February 24th, 2014 | Mt. Gox Exchange Shuts Down | The Mt. Gox exchange platform completely shuts down and returns a blank page. No trading is possible on the platform after this point. Also at this point, leaks start to surface of 744,408 bitcoin being missing[15]. |
| February 28th, 2014 | Mt. Gox Files For Bankruptcy | Mt. Gox files for bankruptcy. The exchange declared bankruptcy on February 28, 2014, attributing the success of the attackers to storing most of the stolen cryptocurrency in a web-based hot wallet, which had a vulnerability exploited by the hackers[15]. |
| August 2015 | Karpeles Arrest Imminent | After cooperating with authorities, Karpeles appears poised for an arrest. Karpeles spent 11 months in detention before bail was granted. “I was interrogated for eight hours each day,” Karpeles recalls. “I was asked about the missing bitcoins. I was even asked if I was Satoshi Nakamoto, the creator of Bitcoin. I was asked to sign confessions and statements in Japanese. Sometimes, the prosecutor would have pre-written statements for me in the morning they wanted signed.” |
| September 2016 | US Authorities Get Mt. Gox Database | "In September 2016, U.S. authorities received a copy of the Mt. Gox database and used it to track the stolen bitcoins." |
| July 25th, 2017 | Alexander Vinnik Arrested | US authorities traced the bulk of the theft to a Russian named Alexander Vinnik, who is subsequently arrested in Greece. |
| November 9th, 2018 1:00:52 PM MST | CryptoPotato Lessons Learned | CryptoPotato published a "Lessons Learned from the Biggest Crypto Hacks in History" in which Mt. Gox is listed at number 2. The article discusses the Mt. Gox hack having a substantial impact on the cryptocurrency industry. The article emphasizes the need for heightened security in the crypto industry and advises users to be cautious about where they store their funds, suggesting the use of wallets offering cold storage, conducting due diligence on services, and prioritizing security. |
| March 15th, 2019 | Karpeles Prosecution | On March 15th, 2019, Karpeles was found guilty of data manipulation[16]. He is also found innocent of embezzlement and breach of trust charges. The Tokyo District Court sentenced Karpeles to a suspended term of two years and six months, contingent on maintaining a clean record for the next four years. |
| May 2021 | Civil Rehabilitation | "In May [2021], the trustee presiding over the Mt. Gox civil rehabilitation case opened the voting on how to partially reimburse victims who lost money to the in hacks dating back nearly a decade." |
| November 16th, 2021 | Rehabilitation Plan Put Together | Courts start to put together a rehabilitation plan to pay back creditors[11]. |
| July 11th, 2022 4:30:18 PM MDT | Andrei Jikh Video | Andrei Jikh releases a video about "arguably one of biggest events in all of bitcoin's history which is the release of Mt. Gox's bitcoins". The release of the Mt. Gox bitcoins is next month in August. 137,890 bitcoin (worth 3 billion dollars are about to flood the market[11]. |
Technical Details
Transaction Malleability Bug
Withdrawal failure, email customer service and ask for withdrawal to be retried.
https://en.wikipedia.org/wiki/Transaction_malleability_problem
https://www.doubloin.com/learn/bitcoin-transaction-malleability
Total Amount Lost
The hack resulted in the loss of 744,408 Bitcoins from customers and 100,000 BTC belonging to the company, with the total stolen amount valued at approximately $473 million[15].
The total amount lost has been estimated at $300,000,000 USD.
Immediate Reactions
On February 7, 2014, Mt. Gox temporarily halted all BTC withdrawals, extending to all trading activities on February 24, and eventually going offline[15].
"On February 7th, MtGox halted all BTC withdrawals from the exchange, citing a transaction malleability bug in the core Bitcoin software. When withdrawals had still not resumed after 2 weeks, users began to suspect that MtGox may not be able to pay its customers.
On February 24th, Mt. Gox suspended all trading, then went offline completely, returning a blank page. News outlets reported on a leaked “crisis strategy draft” plan, which declared MtGox’s insolvency after losing 744,408 BTC of customer funds (valued at over $2 billion USD at today’s prices) as well as 100,000 of its own bitcoins."
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Case Listed Everywhere
As Mt. Gox was the largest exchange at the time, the situation was highly notable. The My. Gox situation was included in almost every list of cryptocurrency exchange hacks including Bitcoin Magazine[17], Kyle Gibson[18], a list published on BitcoinTalk[19], SlowMist[20], and BitcoinExchangeGuide[21] (TBD Fix link).
Insolvency Filing
"It didn’t take long for the information to become public, with Mt. Gox eventually filing for bankruptcy on Feb. 28."
"At a news conference, Karpeles claimed the exchange had been hacked. He apologized and promised to recover the missing cryptocurrency. The cybercrimes unit of the Metropolitan Police Department launched an investigation into the matter and Karpeles offered to cooperate with the inquiry."
"Naturally, those following the news have always wondered whether or not Mt. Gox had been hacked in the first place? Given the complexity of the issue, it was always going to be a difficult question to answer."
Investigations Through 2015
"In 2015, agents from the U.S. Treasury Department and Federal Bureau of Investigation, as well as members of Japan’s National Police Agency, met with Karpeles in Tokyo. They asked for Karpeles’ cooperation in an ongoing investigation involving an international hacker suspected of hacking several cryptocurrency exchanges, including Bitcoinica in 2012."
"By August 2015, many assumed the police were going to arrest Karpeles for some reason or another. The special investigation unit that deals mainly with white-collar offenses had taken control of the case, suggesting that the Frenchman would be arrested in order to extract some kind of confession."
"Karpeles, however, didn’t confess. The police subsequently arrested him on two other charges, with none of the indictments having any direct connection to hacking. Karpeles spent 11 months in detention before bail was granted."
“I was interrogated for eight hours each day,” Karpeles recalls. “I was asked about the missing bitcoins. I was even asked if I was Satoshi Nakamoto, the creator of Bitcoin. I was asked to sign confessions and statements in Japanese. Sometimes, the prosecutor would have pre-written statements for me in the morning they wanted signed.”
"Kim Nilsson, a Swedish engineer who had lost 12 bitcoins in the collapse of Mt. Gox, began sharing information with federal authorities in the United States while Karpeles was in detention. They specifically analyzed the block chain, the public ledger of all bitcoin transactions."
Tracing To Alexander Vinnik
"In September 2016, U.S. authorities received a copy of the Mt. Gox database and used it to track the stolen bitcoins."
"Tigran “Blockchain Wizard” Gambaryan, an agent in the Internal Revenue Service who has extensive experience in cryptocurrency crime, led a joint task force that looked into the case."
"The task force concluded that Mt. Gox had been hacked by an outsider who had siphoned off more than 600,000 bitcoins in a period between 2011 and late 2013. It was able to trace the bulk of stolen bitcoins to one individual, a Russian bitcoin exchange operator named Alexander Vinnik."
Alexander Vinnik Arrest
"On July 25, 2017, U.S. authorities had Vinnik detained in Greece. He was indicted on 21 counts of money laundering and several other charges, some relating to Mt. Gox."
"During Karpeles’ trial in the Tokyo District Court, Ogata argued that Karpeles had only been detained because the police had hoped to extract a confession from him. When Ogata tried to enter Vinnik’s indictment into evidence, prosecutors objected, claiming the Russian should be presumed innocent until proven guilty. The fallacy of such an argument was not lost on the panel of judges, who specifically referred to the indictment in their ruling."
"Vinnik is expected to be extradited to France. And so it seems the man behind the Mt. Gox theft may have finally been identified. It’s a shame the domestic investigation into the case failed to add much to the end result."
Karpeles Criminal Prosecution
"On March 15, [2019,] the court found Karpeles guilty of data manipulation and handed out a suspended prison sentence of 2½ years. He was found not guilty on a separate charge of embezzling millions of dollars through customer accounts. It’s perhaps just worth noting that the odds of a partial not guilty verdict in Japan after indictment are less than 1 percent."
"The Nikkei Shimbun noted the indictments had nothing to do with the initial investigation of the hacking. “The Metropolitan Police Department investigation into the missing bitcoins has, in fact, been terminated,” the paper said."
Former Mt. Gox CEO Mark Karpeles has been found guilty of manipulating exchange data in a Tokyo court, but innocent of embezzlement and breach of trust charges. The Tokyo District Court sentenced Karpeles to a suspended term of two years and six months, contingent on maintaining a clean record for the next four years. While prosecutors sought a 10-year sentence for embezzlement, the defense argued that Mt. Gox's collapse was not due to Karpeles' wrongdoing but claimed he worked to prevent it. Karpeles has consistently maintained his innocence and apologized for the impact on those involved[16].
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Civil Rehabilitation
In 2018, the case was moved to civic rehabilitation, allowing creditors to potentially receive their bitcoin in its original form[16]. "In May [2021], the trustee presiding over the Mt. Gox civil rehabilitation case opened the voting on how to partially reimburse victims who lost money to the in hacks dating back nearly a decade."
"Those who don’t vote are deemed to have voted against the proposal, according to the trustee. A minimum threshold of 50% of votes is required in order for the proposal to pass, so there is a chance the proposal could fail even if the majority of votes actively cast vote in favor of acceptance."
General Prevention Policies
Mt. Gox could have been avoided through smaller hot wallets. Using a multi-sig for cold fund storage and having accountability to ensure all funds are fully backed would also have significantly reduced the damage.
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ A Look Back on Some of the Most Devastating Crypto Hacks - Fintech Singapore (Feb 27, 2020)
- ↑ Crypto Exchange Hacks in Review: Proactive Steps and Expert Advice - CoinTelegraph (Mar 2, 2020)
- ↑ Top 6 Biggest Bitcoin Hacks Ever - CoinSutra (Mar 2, 2020)
- ↑ The Rise and Fall of Mt. Gox – Darknet Diaries (Jun 25, 2021)
- ↑ Mt. Gox Civil Rehabilitation Voting Deadline Ends Friday - CoinDesk (Oct 10, 2021)
- ↑ Mt. Gox Shows Bitcoin's Growing Pains - WSJ (Oct 14, 2021)
- ↑ Solving the world's largest bitcoin heist - The Japan Times (Oct 14, 2021)
- ↑ Hackers Allege Mt. Gox Still Controls "Stolen" Bitcoins - Slashdot (Apr 10, 2022)
- ↑ The One Simple Reason Why Bitcoin Went Down (Again) Over the Weekend - Ceo.ca (Apr 10, 2022)
- ↑ Bitcointalk history of MtGox and how a Bitcointalk post caught the MtGox hacker. - BitcoinTalk (Dec 22, 2021)
- ↑ 11.0 11.1 11.2 Andrei Jikh - The Wealth Transfer Just Started - YouTube (Jul 16, 2022)
- ↑ MtGox.com (Oct 13, 2021)
- ↑ 13.0 13.1 Mt Gox - Bitcoin Exchange - February 3rd, 2011 - Internet Archive (Oct 12, 2021)
- ↑ 14.0 14.1 14.2 14.3 Mt.Gox - Bitcoin Exchange - January 12th, 2012 - Internet Archive (Oct 12, 2021)
- ↑ 15.0 15.1 15.2 15.3 15.4 15.5 Lessons Learned from the Biggest Crypto Hacks in History - CryptoPotato (Feb 26, 2020)
- ↑ 16.0 16.1 16.2 Mt. Gox’s Mark Karpeles Found Guilty Over Data Manipulation in Tokyo Court - CoinDesk (Jan 4, 2024)
- ↑ Infographic: An Overview of Compromised Bitcoin Exchange Events - Bitcoin Magazine (Jan 30, 2020)
- ↑ 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents - Kyle Gibson (Jan 25, 2020)
- ↑ List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses - BitcoinTalk (Feb 15, 2020)
- ↑ SlowMist Hacked - SlowMist Zone (Jun 26, 2021)
- ↑ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com (Mar 5, 2020)