Pages:
Author

Topic: crypsty hacked over 1.5 yrs ago. 13000 BTCs and 300,000 ltc - page 2. (Read 6205 times)

hero member
Activity: 532
Merit: 500
Offer escrow, receive negative trust
Florida

That explains everything.  Florida really needs to be either nuked, cut into an island and detached from the united states, or walled off.  It's like a completely different country down there; either something in the water or heat stroke is really messing with those folks.  Haven't met one person from florida (while living there) that I could trust; met many that resulted in personal losses of all sorts - just like people losing money to craptsy. 

What is it with people down there?  Runaway convicts hiding as south as possible? Results on a social level from Florida's pill mills (the source of the country's oxycontin problem & resulting heroin epidemic)?  There are so many reasons why they're fucked in the head, it's hard to choose one
legendary
Activity: 1588
Merit: 1000
Surely the limited liability shield is void in the face of so much totally criminal activity, lying etc?

This talk of a company going bankrupt seems off the mark, since a company is just a fiction that counts for nothing against criminal negligence malfeasance fraud theft and so on?

-MarkM-


This is definitely in criminal territory.

Calling Cryptsy a "fractional reserve" is lazy and apologia... since that's a legal way money is created by banks.

In contrast, Cryptsy was running a crude PONZI SCHEME and COMINGLING CUSTOMER FUNDS and 100 other offenses...
They kept running and lying for 2 years by using new deposits to pay off withdrawals = random delays.

Big Bern and the principals will definitely face Florida criminal justice. No place to hide now, baby.
full member
Activity: 224
Merit: 100
★YoBit.Net★ 350+ Coins Exchange & Dice
The sad point is:

Looking at all the scams in this lovely crypto world, we need to state: If people would put all their efforts and phantasy in useful tasks instead of ripping other users off, at least Bitcoin would meanwhile have reached mainstream...
legendary
Activity: 1946
Merit: 1005
My mule don't like people laughing
..and another one bites the dust.

Decentralized exchanges need to happen.  Instantdex or Etherex, whoever, hurry up

Bitshares and Next are working. The problem is how to trade our beloved altcoins on those exchanges?? I don't think anyone has figured that out yet. Even then there would have to be some sort of centralization for fiat on and off ramps.

legendary
Activity: 2492
Merit: 1473
LEALANA Bitcoin Grim Reaper
The claimed way the attack was supposedly done makes no sense, even without using virtual machines no coin daemon running as one user would be able to access another running as another user unless someone deliberately forced passwords into the ps or top type readouts by putting them on commandlines, so even incompetents could hardly be expected to make the proposed attack method workable unless they really went out of their way to ensure such an attack would work, such as by running untrustable shitcoins as the same user as a real valuable coin, and on the same machine, or by deliberately passing passwords on the commandline so other users could see them on top and ps and such.

Basically you'd have to deliberately go out of your way to circumvent all the usual procedures everyone is always instructed to use even for just small personal wallets.

Such deliberate setting up of a situation intended to enable some pathetic excuse like "oh one daemon had a trojan in it" is surely at best criminal negligence and far more likely conspiracy to defraud and steal?

It is a pity really that there are so many regulations around this kind of app because all the perceived/expected additional expense imposed by red tape kind of makes the whole idea of running an exchange at all look way too expensive to the kinds of folks who might be competent to run one, whereas script-kiddies just wanting to set up a nice hackable environment so they can claim they were hacked can do so much cheaper / easier...

...Also come to think of it an IRC command-and-control on a cold-wallet machine would never be able to be commanded and controlled because cold means not on the net, right? Hmm...

-MarkM-


Only way is if root was running the wallet and other wallets were in the same machine.

Yup amateur hour when it comes to security. They didn't even have the foresight to think perhaps something like this could happen and say split their pot of funds up into multiple wallets in different locations with multi-sig etc.

"no let's put it all in one place and then install random releases of new crapcoins on the same machine"...

wow just wow ^
legendary
Activity: 2492
Merit: 1473
LEALANA Bitcoin Grim Reaper
Guys, just let's be honest.
If Cryptsy was your exchange and you got hacked and lost a lot of coins.
If you were struggling to keep the exchange open and notice a lot of traders are leaving the exchange.
Would you start a Prepaid Debit Card Program?
Personally I can't believe this. Even if you know it's a sinking ship, keeping the exchange open isn't a criminal offense. It could be seen as damage control.
But actually selling a product of which you know you can't deliver... IMO that's a crime. Why would they risk this?
Hence, I personally doubt about their explaination (and ofcourse added the fact they say they didn't inform the authorities).
Let's see where it ends.  

Leaving the exchange open for people to deposit money to TRADE/EXCHANGE....is technically a product they were selling. Okay more like a service...but apples and oranges...its the same thing just looked at differently a bit in the eyes of "the law".
legendary
Activity: 2492
Merit: 1473
LEALANA Bitcoin Grim Reaper
This is a poor move by cryptsy. For over 1.5 years, they have kept it secretly. They would have suspended their operations immediately once they realize the missing coins from their wallets. They wouldn't have lost when they did it like that. Silence is the killing factor for cryptsy for now. If they did suspended their operations earlier, many people would have got the original value of the coins back. For the past months, people tried to convert btc to other altcoins for much loss to withdraw. This is isn't acceptable.

Not just that...

People who were DEPOSITING BTC and alts into crypsty for the 1.5 years....is essentially a huge liability on cryptsy's part.

As they were operating essentially a PONZI scheme by robbing PETER (depositor) to pay PAUL (withdrawer).

legendary
Activity: 2492
Merit: 1473
LEALANA Bitcoin Grim Reaper
cryptsy hacked themselfs over 1.5 yrs ago,  ••• missing 10M $



lol you should add GOXED in there somewhere too
legendary
Activity: 1498
Merit: 1117
Cryptsy has failed to explain why they aren't returning the millions of alts still stored in its cold-storage coffers.

Why not return those coins to the rightful owners?

thats exactly what i was thing about after i read the blogpost.

maybe they are selling this coins somewhere else because they never will come back live again. so nobody will ever have the possibility to withdraw these coins. they need money to start a new life. and by selling the rest they can make some money.


legendary
Activity: 2940
Merit: 1090
Only way is if root was running the wallet and other wallets were in the same machine.

There is no way any ordinary/available/typical kind of machine, even high powered ones, could run all the coins Cryptsy was running.

Try it!

So it makes even less sense that some pathetic scamcoin would even be on the same physical machine as top of the line actually-valuable well-established coins, let alone on the same username in the same virtual machine.

For a newly-remade trojan without a large team of well known developers with expensive reputations on the line all using verifiable compile processes to sign releases and so on to manage to get run on the same machine as e.g. bitcoin itself would pretty much require a deliberate intent to expose a specific, known number of bitcoins to attack by that new potential-trojan.

In other words, when you choose which physical machine to run a coin on, and which virtual machine on that machine, and which username on that virtual machine, you are specifically deciding how many of which other coins you want to give that new program the opportunity to "attack if it is going to", so you know how many of which coin you want to put at risk and why, such as for example to decide how much temptation you want to expose that program's developer to in order to test his or her integrity and the integrity of the code they have provided.

It is thus pretty much unbelievable that some scamcoin such as lucky7 would ever even be on the same hardware machine, let alone virtual machine, let alone username, as bitcoin...

...Unless you chose for example to test the integrity by putting a half a bitcoin, or a bitcoin, or whatever your chosen bounty is for discovering a trojan, into its reach to test whether despite all your efforts to inspect it it might still harbour some nastiness...

-MarkM-
legendary
Activity: 2044
Merit: 1005
The claimed way the attack was supposedly done makes no sense, even without using virtual machines no coin daemon running as one user would be able to access another running as another user unless someone deliberately forced passwords into the ps or top type readouts by putting them on commandlines, so even incompetents could hardly be expected to make the proposed attack method workable unless they really went out of their way to ensure such an attack would work, such as by running untrustable shitcoins as the same user as a real valuable coin, and on the same machine, or by deliberately passing passwords on the commandline so other users could see them on top and ps and such.

Basically you'd have to deliberately go out of your way to circumvent all the usual procedures everyone is always instructed to use even for just small personal wallets.

Such deliberate setting up of a situation intended to enable some pathetic excuse like "oh one daemon had a trojan in it" is surely at best criminal negligence and far more likely conspiracy to defraud and steal?

It is a pity really that there are so many regulations around this kind of app because all the perceived/expected additional expense imposed by red tape kind of makes the whole idea of running an exchange at all look way too expensive to the kinds of folks who might be competent to run one, whereas script-kiddies just wanting to set up a nice hackable environment so they can claim they were hacked can do so much cheaper / easier...

...Also come to think of it an IRC command-and-control on a cold-wallet machine would never be able to be commanded and controlled because cold means not on the net, right? Hmm...

-MarkM-


Only way is if root was running the wallet and other wallets were in the same machine.
legendary
Activity: 2730
Merit: 1068
Juicin' crypto
fuck that site and fuck most of alt/behind closed doors BS.
wow.  the shit never stops with the scammers/greed. wtf.
legendary
Activity: 1540
Merit: 1011
FUD Philanthropist™
Cryptsy topic in my SIG has 200+ pages of info..

A LOT has happened along the way last 4 months.

And this topic may get moved to service discussion guys..
legendary
Activity: 2380
Merit: 1085
Money often costs too much.
cryptsy hacked themselfs over 1.5 yrs ago,  ••• missing 10M $



 Cheesy Cheesy talented  Cheesy Cheesy
member
Activity: 69
Merit: 10
Floccinaucinihilipilification Specialist
I smell it...

BS
legendary
Activity: 1190
Merit: 1000
member
Activity: 105
Merit: 10
I'm so glad i switched from Crpsty to Nxt MultiGateway
legendary
Activity: 2940
Merit: 1090
If they intended to make good the losses they could have raked in 25 to 30 bitcoins per coin per day on some altcoins that had 100 bitcoins a day of volume and were much cheaper on other exchanges than on Cryptsy.

Part of what made them seem solid, over and above Vern's purported claims that they were not running on a fractional reserve, was the sheer amount of coin they could easily bring in per day just by doing arbitrage.

Now it is starting to seem more likely Vern and/or others who knew what was going on and could bypass withdrawal restrictions might have been doing arbitrage for personal gain not to rebuild the reserves, if they were doing any at all.

Seems pretty unlikely they won't be looking at some serious criminal charges?

And pretty stupid of they planned to make up the losses not to have been doing as much arbitrage as they could with all the bitcoins of their own they could muster.

Especially since by not reporting the theft right away they surely must have shattered any possibility of pretending the company is an entity apart from themselves, so that surely all their own personal wealth became as much at risk as the company? (Unlimited liability due to criminal culpability?)

-MarkM-
legendary
Activity: 1050
Merit: 1016
Can't say I'm too surprised to hear such news, the vultures have been circling for some time.

It seems that period of time was gaming season for thefts as it was around then I was hit also for a combined total of ~900 BTC of both project and personal funds, there were others shortly before me, and others after, including Cryptsy...brings me to the conclusion it might of even been a group of people, who knows.

Fact is it sucks, and I know full well the sickly stomach churning feeling these guys must of had upon realizing those funds had gone.  So I feel for them and anyone else that gets robbed for that matter, no matter how much it is.

However, I can't really sympathize with the act of covering it up for 18 months even though I understand why they did.

In the case of myself I took a bit of time to try and figure out exactly what had happened, build a contingency and figure out a plan.  I knew though that I had maybe 2 months max to report the news to the community before the tide would turn. I also knew there would be a run by those that had supported the project for their funds back, and there was, which cost me a great deal personally.

Its a tough choice, in the case of Cryptsy they thought they could recover via profits, but I think that was a bit naive.  You can't be sure as a business in this sector you'll be around next year, let alone 5-6 years down the line, which seems to be the time period for which they would need to recover all this via profits.  In 18 months they've reduced the deficit by 3k.

It would of been a better more to announce it then, assure everyone that efforts would be made to return funds over time and do just that, no matter what or how long it took.  People can be patient if you are seen to be doing the right thing.  It took me months to reorganize my finances to pay everyone back in my situation, I kept everyone in the loop constantly, everyone was happy to be patient and all that wanted their funds got them.   I suppose its fortunate that I had plenty of assets available to liquidate, perhaps that wasn't the case here hence this decision.

Either way, its a kick in the nuts, so you have my sympathy in that regard.  Hope you do the right thing from this point forward.
Pages:
Jump to: