It's time to put all information to one place:
1. What happened 23/02/14?We developed new system to make withdrawals more secure by confirming it by e-mail. But there was made unforgivable mistake in code allowing to customer to increase it's coins amount by clicking confirmation link again and again in case of withdrawal failure (reason could be wrong wallet address). That mistake was quickly fixed, all security revised but harm was made by one of our customers with user name "Mairusu" displayed in chat as "Darkman" with e-mail address "
[email protected]" and IP address "23.29.119.226". He made our BTC hot wallet empty. When I saw it is empty - I just thought that it's just normal withdrawals and put cold wallet's BTC to hot wallet - it was withdrawed in seconds. That was second mistake. In 2 days "Darkman" responded to my e-mail and promiced to refund all he has by the moment. He indeed made some refunds. In total it was: DRK:14380, 15000,08999991 Total: 29380,08999991 / MINT: 2500000, 22516984,55385500, 4999999,99, Total: 30016984,543855 / 0.40072620 BTC. He also promiced to refund 76 BTC but it never happens.
2. What we had to do.We had to create special account "BTC on hold" to memorize customer's BTC amount for future refund and put BTC. We also reversed all DRK to BTC transactions only made with "Darkman". We credited DRK to users's accounts and substracted BTC. But there was another one mistake: we did not prohibit users to withdraw BTC and DRK when we put their BTC to negative because of reversed transactions. Almost everybody withdrew DRK + BTC not giving us back BTC. That made additional harm to us.
3. What we do now.We work hard to pick-up trade volumes we lost, making exchange better every day. We pay very big attention to security, check, verify everything every several hours.
4. How we will refund customers and how long it takes?We owe 149 BTC to 96 our customers. (11.21068002 refunded by Apr, 2015) Yes, we already refunded about 500 customers, but the total amount was about 3 BTC. (they all had <0.1 balance in BTC). We are going to refund everybody, but we need time. Aproximately up to 3 months. But it depends on how good we will work - I hope it happens faster.
5. Why we continue to work after such hard accident?I personally beleive c-cex will become Big exhange. We get much of positive feedback and people continue to trust us their funds by increasing the total ammount of exchange's wallets every day. By the day of accident we had lot's of customer's funds in altcoins. Everybody start to withdraw - and they withdraw to about 10% of the balance we had on wallets before accident. We let them do it with no problem because it is their funds an we respect it. We learned hard lesson by that mistake in withdrawals about development culture in implementing new features. We also made full revision of our security procedures, made additional checks, verifications. We had noting bad happened after accident and continue to work good.
I personally apologizes to our customers because of this accident.