• bitcoinBitcoin (BTC) $ 97,314.00
  • ethereumEthereum (ETH) $ 3,380.19
  • tetherTether (USDT) $ 0.998796
  • xrpXRP (XRP) $ 2.24
  • bnbBNB (BNB) $ 664.51
  • solanaSolana (SOL) $ 185.44
  • dogecoinDogecoin (DOGE) $ 0.325352
  • usd-coinUSDC (USDC) $ 0.999076
  • staked-etherLido Staked Ether (STETH) $ 3,373.55
  • cardanoCardano (ADA) $ 0.912680
  • tronTRON (TRX) $ 0.245417
  • avalanche-2Avalanche (AVAX) $ 38.32
  • chainlinkChainlink (LINK) $ 22.67
  • wrapped-stethWrapped stETH (WSTETH) $ 4,010.88
  • suiSui (SUI) $ 4.62
  • the-open-networkToncoin (TON) $ 5.32
  • shiba-inuShiba Inu (SHIB) $ 0.000022
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 97,149.00
  • stellarStellar (XLM) $ 0.360515
  • polkadotPolkadot (DOT) $ 7.08
  • hyperliquidHyperliquid (HYPE) $ 31.93
  • hedera-hashgraphHedera (HBAR) $ 0.255226
  • wethWETH (WETH) $ 3,383.53
  • bitcoin-cashBitcoin Cash (BCH) $ 455.54
  • leo-tokenLEO Token (LEO) $ 9.28
  • uniswapUniswap (UNI) $ 13.41
  • litecoinLitecoin (LTC) $ 100.50
  • pepePepe (PEPE) $ 0.000018
  • wrapped-eethWrapped eETH (WEETH) $ 3,566.31
  • nearNEAR Protocol (NEAR) $ 5.11
  • ethena-usdeEthena USDe (USDE) $ 0.998782
  • bitget-tokenBitget Token (BGB) $ 4.22
  • aptosAptos (APT) $ 9.78
  • usdsUSDS (USDS) $ 0.998862
  • internet-computerInternet Computer (ICP) $ 10.35
  • aaveAave (AAVE) $ 306.51
  • crypto-com-chainCronos (CRO) $ 0.161083
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.479393
  • mantleMantle (MNT) $ 1.19
  • ethereum-classicEthereum Classic (ETC) $ 26.34
  • render-tokenRender (RENDER) $ 7.26
  • vechainVeChain (VET) $ 0.046176
  • mantra-daoMANTRA (OM) $ 3.75
  • moneroMonero (XMR) $ 191.84
  • whitebitWhiteBIT Coin (WBT) $ 24.40
  • bittensorBittensor (TAO) $ 464.91
  • daiDai (DAI) $ 0.999534
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.28
  • arbitrumArbitrum (ARB) $ 0.759358
  • ethenaEthena (ENA) $ 1.07
  • filecoinFilecoin (FIL) $ 5.03
  • kaspaKaspa (KAS) $ 0.120749
  • fantomFantom (FTM) $ 1.02
  • algorandAlgorand (ALGO) $ 0.337318
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.70
  • okbOKB (OKB) $ 44.97
  • cosmosCosmos Hub (ATOM) $ 6.65
  • blockstackStacks (STX) $ 1.70
  • ondo-financeOndo (ONDO) $ 1.72
  • optimismOptimism (OP) $ 1.79
  • bonkBonk (BONK) $ 0.000031
  • immutable-xImmutable (IMX) $ 1.37
  • celestiaCelestia (TIA) $ 5.02
  • movementMovement (MOVE) $ 1.03
  • theta-tokenTheta Network (THETA) $ 2.18
  • injective-protocolInjective (INJ) $ 20.90
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 97,367.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,374.84
  • the-graphThe Graph (GRT) $ 0.210296
  • dogwifcoindogwifhat (WIF) $ 1.99
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030465
  • sei-networkSei (SEI) $ 0.430499
  • worldcoin-wldWorldcoin (WLD) $ 2.24
  • thorchainTHORChain (RUNE) $ 5.10
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,489.63
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998075
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,782.54
  • flokiFLOKI (FLOKI) $ 0.000171
  • jasmycoinJasmyCoin (JASMY) $ 0.033480
  • gatechain-tokenGate (GT) $ 12.90
  • quant-networkQuant (QNT) $ 111.16
  • tokenize-xchangeTokenize Xchange (TKX) $ 20.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,551.50
  • lido-daoLido DAO (LDO) $ 1.71
  • galaGALA (GALA) $ 0.035939
  • flare-networksFlare (FLR) $ 0.027418
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 97,357.00
  • makerMaker (MKR) $ 1,648.02
  • beam-2Beam (BEAM) $ 0.027460
  • fasttokenFasttoken (FTN) $ 3.32
  • usual-usdUsual USD (USD0) $ 0.998115
  • the-sandboxThe Sandbox (SAND) $ 0.573553
  • pyth-networkPyth Network (PYTH) $ 0.371167
  • kucoin-sharesKuCoin (KCS) $ 11.19
  • nexoNEXO (NEXO) $ 1.34
  • tezosTezos (XTZ) $ 1.30
  • kaiaKaia (KAIA) $ 0.223273
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 97,090.00
  • raydiumRaydium (RAY) $ 4.42
  • based-brettBrett (BRETT) $ 0.129224
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,477.81
  • eosEOS (EOS) $ 0.812718
  • heliumHelium (HNT) $ 6.89
  • binance-staked-solBinance Staked SOL (BNSOL) $ 189.24
  • ethereum-name-serviceEthereum Name Service (ENS) $ 35.17
  • aerodrome-financeAerodrome Finance (AERO) $ 1.61
  • xdce-crowd-saleXDC Network (XDC) $ 0.075995
  • jupiter-exchange-solanaJupiter (JUP) $ 0.836319
  • flowFlow (FLOW) $ 0.714072
  • starknetStarknet (STRK) $ 0.478265
  • bitcoin-svBitcoin SV (BSV) $ 54.06
  • arweaveArweave (AR) $ 16.23
  • coredaoorgCore (CORE) $ 1.14
  • aioz-networkAIOZ Network (AIOZ) $ 0.930658
  • iotaIOTA (IOTA) $ 0.296860
  • dydx-chaindYdX (DYDX) $ 1.47
  • bittorrentBitTorrent (BTT) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 231.55
  • curve-dao-tokenCurve DAO (CRV) $ 0.817278
  • neoNEO (NEO) $ 14.14
  • axie-infinityAxie Infinity (AXS) $ 6.26
  • elrond-erd-2MultiversX (EGLD) $ 34.65
  • matic-networkPolygon (MATIC) $ 0.479158
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 96,302.00
  • decentralandDecentraland (MANA) $ 0.480146
  • fartcoinFartcoin (FARTCOIN) $ 0.865835
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 96,840.00
  • pendlePendle (PENDLE) $ 5.13
  • zcashZcash (ZEC) $ 53.31
  • apecoinApeCoin (APE) $ 1.16
  • jito-governance-tokenJito (JTO) $ 2.97
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,377.29
  • mog-coinMog Coin (MOG) $ 0.000002
  • akash-networkAkash Network (AKT) $ 3.22
  • eigenlayerEigenlayer (EIGEN) $ 3.76
  • chilizChiliz (CHZ) $ 0.085540
  • ai16zai16z (AI16Z) $ 0.717922
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,385.65
  • wormholeWormhole (W) $ 0.270066
  • conflux-tokenConflux (CFX) $ 0.159190
  • usddUSDD (USDD) $ 0.997764
  • popcatPopcat (POPCAT) $ 0.743938
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 199.08
  • mina-protocolMina Protocol (MINA) $ 0.608875
  • compound-governance-tokenCompound (COMP) $ 81.38
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,380.18
  • spx6900SPX6900 (SPX) $ 0.764710
  • roninRonin (RON) $ 1.92
  • superfarmSuperVerse (SUPER) $ 1.57
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.40
  • ecasheCash (XEC) $ 0.000035
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.006824
  • havvenSynthetix Network (SNX) $ 2.02
  • gnosisGnosis (GNO) $ 263.98
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.325214
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 96,176.00
  • chiaChia (XCH) $ 20.88
  • axelarAxelar (AXL) $ 0.747886
  • dydxdYdX (ETHDYDX) $ 1.47
  • amp-tokenAmp (AMP) $ 0.007807
  • notcoinNotcoin (NOT) $ 0.006381
  • zksyncZKsync (ZK) $ 0.175776
  • fraxFrax (FRAX) $ 0.994636
  • tether-goldTether Gold (XAUT) $ 2,627.93
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.630994
  • layerzeroLayerZero (ZRO) $ 5.64
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,555.76
  • chex-tokenCHEX Token (CHEX) $ 0.617722
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000111
  • reserve-rights-tokenReserve Rights (RSR) $ 0.011237
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,662.22
  • grassGrass (GRASS) $ 2.45
  • turboTurbo (TURBO) $ 0.008482
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • vanaVana (VANA) $ 19.09
  • super-oethSuper OETH (SUPEROETHB) $ 3,391.91
  • safeSafe (SAFE) $ 1.09
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006363
  • ordinalsORDI (ORDI) $ 26.35
  • oasis-networkOasis (ROSE) $ 0.082355
  • echelon-primeEchelon Prime (PRIME) $ 10.76
  • blurBlur (BLUR) $ 0.261205
  • beldexBeldex (BDX) $ 0.078496
  • 1inch1inch (1INCH) $ 0.385862
  • usualUsual (USUAL) $ 1.16
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.28
  • susdssUSDS (SUSDS) $ 1.02
  • paypal-usdPayPal USD (PYUSD) $ 0.999537
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,345.00
  • pax-goldPAX Gold (PAXG) $ 2,621.52
  • dexeDeXe (DEXE) $ 9.07
  • livepeerLivepeer (LPT) $ 14.00
  • pumpbtcpumpBTC (PUMPBTC) $ 96,601.00
  • creditcoin-2Creditcoin (CTC) $ 1.25
  • apenftAPENFT (NFT) $ 0.00000052
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.503192
  • frax-etherFrax Ether (FRXETH) $ 3,378.93
  • gigachad-2Gigachad (GIGA) $ 0.051270
  • true-usdTrueUSD (TUSD) $ 1.00
  • arkhamArkham (ARKM) $ 1.48

‘Giancarlo’ keys managed poorly says post-hack Bitfinex security report

0 242

‘Giancarlo’ keys managed poorly says post-hack Bitfinex security report

The Organized Crime and Corruption Reporting Project (OCCRP) has reportedly obtained the security report created by Ledger Labs that was commissioned by Bitfinex after its 2016 hack. The report details numerous failures to follow industry best practice, failure to practice adequate logging, and failure to implement a whitelist.

The Bitfinex hack backstory

On August 2, 2016, Bitfinex was hacked in what was then the second-largest Bitcoins hack ever recorded. Indeed, 120,00 coins — then valued at around $70 million but today worth over $3 billion — were withdrawn from the platform forcing it to disable all deposits, trading, and withdrawals in response.

In the wake of the attack, Bitfinex announced that “We have arrived at the conclusion that losses must be generalized across all accounts and assets.” The company also claimed that every single account would receive a 36.067% haircut, and for each dollar that represented, users would receive a BFX token, valued at $1, that Bitfinex would try to repay.

Nathaniel Popper would later report that the haircut was not equally applied to all accounts and assets, insisting that Coinbase didn’t receive the same haircut.

They actually did pay, just not the 36%, and what they paid ended up being higher than if they just took the 36% haircut, got their BFX and sold it shortly thereafter.

— Zane Tackett (@tackettzane) January 20, 2022

Former Bitfinex Director Zane Tackett claimed that Coinbase did receive a haircut, but revealed that it was smaller than other clients, undercutting the previous Bitfinex claim that “losses must be generalized across all accounts and assets.”

A few days later on August 17, Bitfinex would announce that it had retained Ledger Labs “to determine exactly how the security breach occurred and to make our system’s design better going forward,” and “to perform an audit of our complete balance sheet for both cryptocurrency and fiat assets and liabilities.”

Several months later, Bitfinex announced that “Ledger Labs has not been engaged to perform a financial audit of Bitfinex.” Eventually, in May 2017, Bitfinex announced that it had hired Friedman LLP to perform an audit. No update has ever been provided on the status of that audit but Friedman was unable to provide an audit for sister company Tether.

After the hack, Bitfinex promised to provide details on how it occurred but this never happened. It also reiterated that everyone received the same haircut and detailed the steps that should be taken by unverified users who the system “mistakenly” believed were US-based.

The report

While Bitfinex never released the security report that had been commissioned by Ledger Labs, the reporting by OCCRP does provide more insight into how the hack occurred.

The report details how Bitfinex’s system, which was an implementation of BitGo’s multi-signature wallet, needed two of three keys in order to withdraw. The report claims that Bitfinex irresponsibly had both keys on the same device, and so by compromising that single device, hackers were able to immediately bypass the BitGo withdrawal limits and drain the wallet.

The keys were supposedly linked to two separate emails, one labeled “giancarlo” used by Bitfinex chief financial officer Giancarlo Devasini, and another “admin” email address.

The report also details lapses including the lack of a whitelist for withdrawals and an absence of server logging. The report also suggested that the hack occurred in Poland, based on an analysis of IP addresses.

Dutch and Razzlekhan

The Bitfinex hacker has never been arrested, but early last year Heather Morgan and Ilya Lichtenstein were arrested for allegedly trying to launder the bitcoins stolen in this hack.

Razzlekhan: These are ‘Bitcoin launderer’ Heather Morgan’s greatest hits

When they were arrested, authorities were able to seize the vast majority of the bitcoin that was originally hacked from Bitfinex, however, neither has been accused of the hack. Among their other possessions that were seized were a variety of burner phones and spreadsheets that detailed their efforts to successfully clean the coins.

Bitfinex hasn’t disclosed any additional breaches since 2016, but its sister company Tether was hacked in November 2017.

Bitfinex, in its statement to OCCRP, said that the Ledger Labs report was “incomplete” and “incorrect” but has so far failed to provide its own post-mortem explaining how the hack occurred. It is also yet to provide an update on the promised financial audit from over half a decade ago.

Source

Leave A Reply

Your email address will not be published.