I read all this shit with both delectation (because of the thriller 2.0 spirit) and sadness for the victims.
A contradiction i didn't saw anywhere ( or just missed ) is the 100btc back from the theft to zhou "philanthropist refunding" account. it is strange to me because somewhere else zhou stated that his "ex-assosiate - cb-Frauder - theft" doesn't speak english.
am i missing anything here?
I noticed this too. He didn't say that he doesn't speak english, just that he's not proficient (probably well enough for basic reading). What's curious about it is that even after the 100BTC went to Zhou's donation address, he was still insisting that the culprit isn't reading the forum/threads. That one aurumxchange ticket would not be enough to be "sure", but then Zhou seems to take a lot of things at face value without much apparent evidence (ie the culprit's real name, the culprit being a millionaire, etc.)
I have located a suspect, his name is 陈建海(Chen Jianhai). He's NOT my friend and we have never met in person. He was one of my previous business associates because he's very familiar with credit card fraud and he advised me a lot (in terms of fraud prevention, of course) when I built my virtual goods payment processor in late 2010.
He has knowledge of my secret gmail address and I have once re-used the password in his web shop
His English is not very proficient and I'm sure that he's not reading this forum at the moment. I'm giving him a call now to persuade him to admit his wrong-doing and return the funds.
I'll post another thread soon.
Another issue I've noticed is the seemingly conflicting statements about the LastPass password and account:
On ycombinator zhoutong claims he didn't set the LastPass password:
http://news.ycombinator.com/item?id=4240408Well I do agree with you that Bitcoinica was not 100% secure. This hack really has nothing to do with the app or its infrastructure.
- I didn't set the password. - I didn't have the power to change the password. - I shouldn't have access to the account.
The root cause is LastPass account being stolen.
My version of the story is, Tihan selected a password from one of the Mt. Gox API keys and we face-to-face agreed to use that. There was no plan to release the source code ever (and if I did it myself, I would at least remove the credentials). The password has never been changed for 5 months, despite the transfer of ownership.
I didn't expect to be able to log in to LastPass after Bitcoinica Consultancy took over. So I didn't try.
I still don't think zhoutong was responsible, and I hope he can explain the source of the LR funds for his "friend" (said to be $100k in one place and quoted as "unlimited" in another).