MyBitcoin Exchange Hack/Fraud

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Revision as of 17:38, 30 January 2023 by Azoundria (talk | contribs)
Jump to navigation Jump to search

MyBitcoin was a popular wallet service for new users of bitcoin. The exact origins and founding of the service are not fully known.

About MyBitcoin

MyBitcoin was a wallet platform catering primarily to cryptocurrency newbies interested in buying bitcoin for the first time. The exact founding date of MyBitcoin is not fully known. One source reports that "MYBITCOIN has been in business since [the] middle of 2009"9, while domain name WHOIS reports that the domain first existed on April 25th, 201010. Actual content was first reported on the site by Internet Archive on February 11th, 201111, although prior versions of the site may have loaded content if the user installed "CACert's security certificate"12.

This website showed the name MyBitcoin LLC5,11 while domain name WHOIS entries showed the mailing address to be a post office box in Nevis5,13, part of the Caribbean island nation of St. Kitts and Nevis16. It is not known if this truly is an LLC and if so, where the organization was located5. Domain name WHOIS showed that the founder was someone named Tom Williams13.

MyBitcoin built its reputation by providing a free, user-friendly service targeted at newbie Bitcoin buyers. An excerpt from the first version of the website mentioned it as "[a]n intuitive web-interface for Bitcoin" with "[n]o software to download, install, or configure", with easy integration for merchants to send and receive funds in bitcoin11.

MyBitcoin sports an easy to use interface with large navigation buttons. It is suitable for those who are just trying Bitcoin out, or for those who want to use Bitcoin for commerce now, and without delay.

Downloading and installing the Bitcoin software isn't a requirement to trade with MyBitcoin. Of course, you can still use the Bitcoin software in conjunction with MyBitcoin. The choice is entirely yours!

Just like many other popular payment systems; you can easily generate and paste HTML code onto your website to accept Bitcoin payments! No more messy programming, or other headaches. You'll have your website accepting Bitcoin in minutes!

Price the goods and services on your website in any national currency, and have our SCI convert the prices into Bitcoins as each purchase is made.

You can have every single incoming payment forward to another Bitcoin address. Great for those who want to keep their coins on their desktop PC, or all in one place, but still want to use our shopping cart interface and merchant tools.

MyBitcoin is completely free. We are supported by selling small text ads that are in our login area. We are also planning on selling support packages in the near future.

Dozens of users flocked to the platform in its early days, and it reportedly had more deposits than the third largest exchange at the time, Bitomat.pl14. One of the more prominent users was Bitcoin evangelist and host of The Bitcoin Show Bruce Wagner.17

We have a lot of bitcoin there..... ( as has already been reported in the press )...    Many -- perhaps most -- non-technical people... and businesses, I know and associate with,....  rely on MyBitcoin.com      Most of my friends and family and associates.... all have all their bitcoin there too.

  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

Is is unclear whether Tom Williams is the real name of the individual who founded MyBitcoin.2,7 As described by BitcoinTalk user iamzill:13

That seems like a dead end to me. It's just a PO Box. There are thousands of "Tom Williams" in the world, not to mention it's most likely a pseudonym since that's acceptable in a Nevis LLC.

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - MyBitcoin Exchange Hack/Fraud
Date Event Description
July 29, 2011, 3:41:36 PM MST Site Reported Down The MyBitcoin website is reported to be down for the first time on the BitcoinTalk forums.13

Total Amount Lost

The losses from the event were reported as 78739.58205388 BTC2,7 on BitcoinTalk, and estimated to be equivalent to either $1,072,570 USD7 or $1,110,544 USD2. BuyBitcoinsWorldWide lists a price of $13.49 USD on July 29th, 2011, which would give a total loss of $1,062,196.96 USD15. Averaging these estimates gives a value of $1,081,770.32 USD.

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

BitcoinTalk user lettucebee said:13

"Quite a lot has been said about this "service" already. I'm surprised anyone is still using it for anything."

BitcoinTalk user "done" was more optimistic:13

"[T]hey should be back up in 24[.]"

However, when the service never resumed, talk began about tracking down the operator.13

Lets track him down then, it shouldn't be that impossible. If anyone wanna buy me a flight ticket to Nevis[,] I'd be glad to help[.]

BitcoinTalk mrbashfo describes his experiences:13

[Y]eah, I am new to this[. A]fter investing in hardware to mine bitcoins I deposited my earnings into mybitcoin =( [I didn't] know either[.] I read from somewhere that it was a good place to have my wallet... guess not. I mean I didn[']t los[e] alot but darn =( 5bitcoins so it hurts considering I just started!

BitcoinTalk user julz says this was to be expected:13

Security and business processes across most Bitcoin start-ups are likely to be immature.

This sort of thing is disappointing, but shouldn't be a complete surprise.

It's only made worse by the fact that it's such an adversarial environment to operate in.

Not only are there competing services, but the systems effectively hold 'cash' on their hard drives, which of course attracts the cyber bandits.

Ultimate Outcome

Information was quickly investigated on the domain name registration and leased server which was set up.


A summary can be found on BitcoinTalk:

Little information was released about the MyBitcoin theft, however, many argue that Tom Williams ran it as a scam (and was not a theft per se). In terms of both dollars and bitcoins, this was by far the largest theft, however, it is possible it was simply a scam. Although MyBitcoin offered to release its code as a gift to the community, it failed to follow through on that promise. In the months ensuing, some evidence has been uncovered supporting mortgage broker Bruce Wagner; however, any evidence is inconclusive. The theft resulted in the closure of MyBitcoin, which was once a successful Bitcoin company in Bitcoin's early days.

It does not appear that any prosecution was ever undertaken in this case.

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Prevention Policies

This is a case where simply knowing who's holding the funds and storing them properly offline with multiple signatures would have avoided the issues.

It seems like they never reached any agreement on who was behind the service. The official stories about what happened do not appear to hold together. There was nobody held to account in the end. Simple public registration of exchanges would prevent this. Some sources report that the exchange went into receivership and half of the funds were ultimately recovered, though I was not able to confirm this.

References

  1. Infographic: An Overview of Compromised Bitcoin Exchange Events (Jan 30, 2020)
  2. List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses [Old] (Jan 28, 2020)
  3. MyBitcoin Spokesman Finally Comes Forward: “What Did You Think We Did After the Hack? We Got Shitfaced” | Observer (Feb 4, 2020)
  4. The biggest scams in Bitcoin history (Feb 15, 2020)
  5. MyBitcoin - Bitcoin Wiki (Apr 12, 2020)
  6. 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents (Jan 25, 2020)
  7. List of Major Bitcoin Heists, Thefts, Hacks, Scams, and Losses (Feb 15, 2020)
  8. Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com (Mar 5, 2020)
  9. Full text of "MyBitCoin" - Archived FBI Report From August 17th, 2011 (Jan 30, 2023)
  10. e wallet - When was MyBitcoin created? - Bitcoin Stack Exchange (Jan 30, 2023)
  11. MyBitcoin - A simple web-based Bitcoin wallet (Original Site) - Internet Archive (Jan 30, 2023)
  12. MyBitcoin - A simple web-based Bitcoin wallet (CaCert Notice) - Internet Archive (Jan 30, 2023)
  13. mybitcoin down or just me? - BitcoinTalk Forum (Jan 30, 2023)
  14. MyBitcoin.com Is Back: A Week After Vanishing With at Least $250 K. Worth of BTC, Site Claims It Was Hacked | Observer (Jan 30, 2023)
  15. BuyBitcoinsWorldwide Historic Bitcoin Price Chart (Jan 30, 2023)
  16. Nevis - Wikipedia (Jan 30, 2023)
  17. Bruce Wagner On Use of MyBitcoin - BitcoinTalk (Jan 30, 2023)