7 ms·
Czech bitcoin exchange Bitcash.cz hacked, up to 4,000 user wallets emptied
- antonius 13y agoFirst the Chinese exchange (GBL) and now this? Scammers have been hitting the exchanges hard recently.
- speeder 13y agoOf course, this is a prime time to get btc and sell it. Scammers probably are not expecting the price to climb much longer in short term.
- monsterix 13y agoOn the other hand I see this more like a concerted attempt to build mistrust against the virtual currency and its distribution network. Tinfoil hat anyone? [Edit: Thank you for your lame negative votes, sad people. You can go further and ask for more negative power to vote this down and then just die negatively voting right here.]
- samuellb 13y agoAlso, the Swedish exchange Kapiton is having problems with "delays" in payments and is currently not accepting deposits: https://kapiton.se/news/2 https://kapiton.se/news/2 https://kapiton.se/news/3 https://kapiton.se/news/3 (site in swedish language)
- alecsmart1 13y agoThis is the third story in two weeks. Either the hacking attempts are increasing or the site owners are cashing out. Either way it's bad news. Anyone with bitcoins must use an offline wallet.
- LukeWalsh 13y agoPlease. Please. For the love of god please. https://en.bitcoin.it/wiki/How_to_set_up_a_secure_offline_savings_wallet https://en.bitcoin.it/wiki/How_to_set_up_a_secure_offline_sa...
- aqme28 13y agoHow safe is this compared to using a brainwallet (https://en.bitcoin.it/wiki/Brainwallet https://en.bitcoin.it/wiki/Brainwallet) with sufficiently strong password (say, a hundred secure-randomly generated characters)? A brainwallet sounds far far simpler to set up, at least.
- broostoryco 13y ago> a hundred secure-randomly generated characters might as well just memorize the private key..
- GigabyteCoin 13y agoBrainwallets are never a good idea. See here: https://www.google.com/search?q=brainwallet+(stolen+OR+hacked) https://www.google.com/search?q=brainwallet+(stolen+OR+hacke...
- meowface 13y agoUh, no. Brainwallets with weak passphrases are a bad idea. Every case of a brainwallet theft has been due to users coming up with predictable passphrases to generate the key. Most brainwallet private keys are simply a SHA256 hash of a passphrase, which is fairly easy for a dedicated attacker to crack via bruteforce or dictionary attacks, yes. But if you use, say, a 12-word sentence with completely random words, like SHA256("fire pickle shipment lachrymose deity unwitting pernicious obstacle kitchen tumbleweed mannequin erudite"), and maybe some random letters or numbers at the end, it's infeasible that it'll ever be cracked. One common problem is that many people will pick song lyrics, book titles, or Bible quotes as their passphrase. Obviously attackers are going to scrape and add those to their dictionaries (which will then also be permutated in many ways), so it's critical that the words are picked arbitrarily and that there are enough of them. The idea itself isn't inherently insecure, except for the fact that SHA256 was probably a poor hash function to use since it's fast. I can guarantee that this will always be more secure than trusting any online service to store your wallet instead. The only risk is you forgetting one or more of the words, in which case you're in trouble.
- disdev 13y agoI'd love to say there's some more nefarious work going on, like governments trying to quash Bitcoin and executing these hacks... But my guess is it comes down to poor security.
- fembot__ 13y agoI couldn't agree more. I took a cool seminar in college about web security, in which a former senior security specialist for a government agency said that there is no such thing as full security, just varying levels of insecurity. Scary thought...
- BlackDeath3 13y ago>there is no such thing as full security, just varying levels of insecurity Six in one hand... But it is good to realize that there really no such thing as perfect security. If it can be accessed, it can be accessed nefariously.
- honzzz 13y agoIt might be interesting to note that someone in the discussion under the original article (an unregistered user going by the name 'The one who knows') claims that "the admin of bitcash.cz Carlos upset the czech hacker comunity SooM.cz and accordingly to Blockchain (https://blockchain.info/tx/44f66e60460926d1ac75667ce3060429000f7cbd30e9afe5a1f3af62cae7727f https://blockchain.info/tx/44f66e60460926d1ac75667ce30604290...) it looks like those hackers donated all the BTC that was on bitcash.cz to wikileaks".
- Retro 13y agoThat's not the bitcoin address listed on the wikileaks website. The only mention of the address was on bitcoin-charity.info where it was connected to wikileaks but that's now offline. Seems suspicious that only one website had that address listed. Edit: From the 'wikileaks' account listed on bitcoin-charity.info 150btc each were sent to 2 other addresses listed on that site. An african charity 'Amani Kinderdorf' and a 'Nonprofit Recycling and Exchange Network'. It seems like (though the charities are real) the bitcoin links are not related to them and bitcoin-charity.info was a scam site. (google cache: http://webcache.googleusercontent.com/search?q=cache:bitcoin-charity.info/charities.php http://webcache.googleusercontent.com/search?q=cache:bitcoin...)
- altero 13y agoIf all BTC are on single place, it could be possible to recover them. Seems like well documented case, both parties are in civilized countries and court could take it. Soom.cz is not very reliable source. Also Czech Linux community does not mention anything. But according to some users it did not even used SSL!!!
- saraid216 13y ago> But according to some users it did not even used SSL!!! It's never going to stop amusing me that Bitcoin's big selling point is how it's this amazing form of applied cryptography... and the people who actually try to do this kind of thing cheerfully neglect security concerns that seem rather basic. It's not hard to explain this phenomenon, but it's still amusing.
- cs702 13y agoEvery new day seems to bring another new Bitcoin scandal -- whether it's a hacked exchange, stolen wallets, frozen funds, collapsed Ponzi schemes, arrested illegal-market operators, or who knows what else. Yet, despite all this, Bitcoin keeps appreciating, recently reaching an all-time high.[1] -- [1] https://blockchain.info/charts/market-price?timespan=all https://blockchain.info/charts/market-price?timespan=all
- smtddr 13y agoThese stories of hacks & scandals and your link showing increasing-value only increases my desire to buy bitcoin. Also, this wild story[1] makes me want bitcoin too. What if I just want to buy $500 USD worth of bitcoin and just sit on it? Maybe 10 years from now it'll be worth close to a million, or maybe bitcoin will be shutdown and it'll be worth nothing. I think I can risk it. Who's trust-worthy these days if I want to make that purchase? 1. http://now.msn.com/kristoffer-koch-norwegian-man-buys-apartment-with-bitcoin-profit http://now.msn.com/kristoffer-koch-norwegian-man-buys-apartm...
- aianus 13y agoCoinbase.com is a YC company that's trustworthy and convenient if you have a US bank account
- zachlatta 13y agoEh, I wouldn't recommend Coinbase. They deemed one of my purchases from them as "high-risk" and have been holding my money hostage since. Support team has been taking 3-4 days to reply to each email in the thread.
- iancarroll 13y agoSometimes this happens. They deal with purchases every day and can't aid with money laundering.
- 13y ago
- kumarski 13y agoI think CoinMKT with its verification seems like the only solid place....
- iancarroll 13y agoI think Mt. Gox, the most reputable exchange, is the only solid place. This sounds like self advertising.
- mithras 13y agoSure if you like to wait 8 weeks for your money.
- etherael 13y agoI'm getting somewhat tired of these kinds of stories, the stories and the responses here both follow identical patterns. 1) Security is compromised at an entity that deals somehow with bitcoins. The security of the blockchain remains unimpacted, it is as relevant to the fundamentals of the currency as much as someone getting robbed is relevant to the fundamentals of the fiat currency they were robbed in. 2) Much whining and gnashing of teeth ensues as to how bitcoin is going to collapse any second now because clearly it is just some crazy snake oil and look at the rash of compromises as evidence, and by the way it also happens I disapprove of it because it goes against my views on what a currency needs to be. 3) People respond much along the lines I'm responding now. 4) It devolves into an ideological argument along the lines of the characteristics of the currency itself and the potential death of fiat money and its implications. Conclusion; Some people are fundamentally ideologically opposed to bitcoin and will use whatever they can to drag it through the mud at every opportunity. Compromising the blockchain or the fundamentals of bitcoin itself is news, even when it's overblown or exaggerated like the recent Cornell findings, some venture getting owned because they failed to adequately secure their place of business is par for the course and barely a footnote at this point in time. For the first time in normal everyday business history, security really matters now. You can't just put up a banner with the legal penalties for acting against corporate policy and actually expect to hold people accountable via the legal system for ignoring your banner, the new rules are that you need real security. Frankly I think that's a good thing and something that is far overdue, the swiss cheese state of general security practices coupled with the apathy and ignorance of general computer users has gone on for far too long, but because the individuals in question were never held personally to account there was never the motivation to really fix the problem. Now there is, people need to accept this new paradigm if they want to deal in this space.
- Nux 13y agoYou mean, they weren't insured?