I may have my facts wrong on some of this, so (those who actually know) please feel free to correct me?
1. Why did the hacker make a cash withdrawal? This supposedly gives Mt. Gox the account details of where the money was sent? If he/she were smart, they'd surely try to buy up as much bitcoin as possible then transfer the lot out of Mt. Gox and into an outside bitcoin address? Surely its worth maintaining anonimity and reducing the risk of being caught for the sake of not being able to take the whole $40k?
2. Keyrings like LastPass are great for fools who refuse to take responsibility for their own data/account security. But for a programmer or system administrator to provide one attack vector (externally sourced, no less!) that gives access to all parts of the system isn't just negligent, its deliberate and wilful.
3. Understanding that the API key was used as a password temporarily by someone who isn't normally involved in such matters, may be forgivable. However, this being brought to the attention of those in charge of technical operations and it not being resolved immediately is laughable.
In relation to 2 and 3; either the person/people responsible are clearly without the faculties to run such an operation, or they do have the technical sense to know that these flaws were critical and were either complicit or wilfully negligent.
Its clear from reading the
email transcripts that competition with other exchanges and profitability were driving factors in whatever arrangements were being made regarding ownership. Regardless of this strong incentive not to suspend Bitcoinica's operation, those in charge should have done so as soon as they discovered these open barn doors and worked on shutting them before resuming.
What I find most troubling is that despite (according to the
email transcripts) the Intersango / Bitcoin Consultancy trio knowing about these issues before they were exploited and therefore being absolutely culpable, people still seem to trust them enough to be trading on Intersango still?! If they were willing to leave holes unfilled for the sake of profit continuity at Bitcoinica, how can it be concluded that the same isn't true for Intersango?
My honest feeling is that the bitcoin community is blessed with technical talent. Unfortunately many appear to be straying far from their own skill sets and wasting other people's money while they learn new ones.
BB.