With regard to the 500'000 bitcoins........these weren't necessarily real bitcoins, it could have been the BTC units within MtGox's own system....which suggests more was hacked then they are admitting.......which actually makes sense because they don't have a fucking clue anyway......hence the long delay while they get some kind of Sec infrastructure in place.
Since the sell off happened on mtgox's order books, the 500,000 coins could not have been real bitcoins. They were accounting units internal to their system.
I still haven't figured out why people think it was some sort of master wallet, or collective account that was involved. It was purely an internal representation, and this is obvious because only their internal representation can participate in their order matching.
Because MtGox officially stated it. And it is a massive bullshit, as you reasoned by yourself.
The thing is that they don't want to acknowledge that they were hacked. According to them, they weren't hacked
ever.
Here is the citation:
Huge Bitcoin sell off due to a compromised account - rollback
The bitcoin will be back to around 17.5$/BTC after we rollback all trades that have happened after the huge Bitcoin sale that happened on June 20th near 3:00am (JST).
One account with a lot of coins was compromised[/b][/color] and whoever stole it (using a HK based IP to login) first sold all the coins in there, to buy those again just after, and then tried to withdraw the coins. The $1000/day withdraw limit was active for this account and the hacker could only get out with $1000 worth of coins.
Apart from this no account was compromised, and nothing was lost. Due to the large impact this had on the Bitcoin market, we will rollback every trade which happened since the big sale, and ensure this account is secure before opening access again.
1st) The $17.5 it is arbitrary. That concerns me.
2nd) The One account story is being insisted by MtGox in several threads in the forum.
3rd) Rollback sounds like a game. There is no rollback in life. Shit happens, people lose, people win. Move on. Compensate for your mistakes, honor it.
Since this statement wasn't satisfying for the people who actually got a hold of the userbase with all the emails, usernames and passwords of all the users in MtGox.
So another statement was released:
[Update - 2:06 GMT] What we know and what is being done.- It appears that someone who performs audits on our system and had read-only access to our database had their computer compromised. This allowed for someone to pull our database. The site was not compromised with a SQL injection as many are reporting, so in effect the site was not hacked.
- Two months ago we migrated from MD5 hashing to freeBSD MD5 salted hashing. The unsalted user accounts in the wild are ones that haven't been accessed in over 2 months and are considered idle. Once we are back up we will have implemented SHA-512 multi-iteration salted hashing and all users will be required to update to a new strong password.
- We have been working with Google to ensure any gmail accounts associated with Mt.Gox user accounts have been locked and need to be reverified.
- Mt.Gox will continue to be offline as we continue our investigation, at this time we are pushing it to 8:00am GMT.
- When Mt.Gox comes back online, we will be putting all users through a new security measure to authenticate the users. This will be a mix of matching the last IP address that accessed the account, verifying their email address, account name and old password. Users will then be prompted to enter in a new strong password.
- Once Mt.Gox is back online, trades 218869~222470 will be reverted.
So here you see how they insist that they weren't hacked.
And Mark from MtGox keeps insisting:
We have evidence the problems found by phantomcircuit have never been exploited by anyone, and we have further evidence someone logged in on your account using your password. We cannot take liability for a case which is clearly not linked to any problems on our side.
Thanks,
Mark
MtGox.com Team
As you can see, by insisting the story of the "single user account hacked" they want to free themselves from all responsability, save their faces and blame
their incompetence to
the users.
There are stupid users with simple passwords (still cracking: more than 800 passwords already cracked) but someone with 500,000 BTC in a single account with a lame password doesn't seem to be probable (although it is totally possible).
Considering the reasons I detailed in my first post in the creation of this thread, I think everything is a lousy attempt of a cover up to hide their asses to not be held responsible.
This lie would save them money (from compensations) and somehow it would cause tranquility to some of their users since they would be relieved that "their systems weren't compromised", which I bet it is totally untrue.
We got all our usernames, passwords hashes and email addresses exposed. All of us are now in spammers' databases.
Most of us got really stressed out because we shared the same password in several accounts.
And some of us realized that their worst fears became true: they got victimized in other exchanges.
It doesn't matter if it was an external auditor, MtGox is trying to wash their hands from this.
They claim that the CSRF vulnerability discovered by phantomcircuit wasn't exploited because they checked their logs... this type of attack leaves no logs, and it's been confirmed from other users in the forum that it's been used before and after the fix.
This attitude from MtGox isn't acceptable.
It seriously makes me doubt about their moral integrity.
And as I said before: "trust takes a decade to build, and only one second to break"
MtGox, you better work hard to earn our trust again, all these lies/incompetence/negligence are simply not acceptable.