Post
Topic
Board Speculation
Re: bitstamp 18,000 bitcoins stolen? -confirmed
by
aztecminer
on 06/01/2015, 15:32:57 UTC
i suppose i had a lucky escape, i never saw reason to keep coins in the bitstamp exchange. i traded out of my bitstamp iou's on rippletrade when the prices went out of sync. i had to take a poor ask price in ripples but at least i got my money. the bitstamp gateway was open long after the initial announcement, and i thought i was being a little paranoid by bailing out with a haircut of about 2%.

now my ~bitstamp iou balance is nil, i had some dust in there. will be interesting to see if it comes back. anyone else see this?

Bitstamp has 200,000 BTC in reserves. Unlike Gox, they only lost a small percentage of total bitcoins during this hack so I think customers' deposits are safe. Poloniex suffered a similar hack which saw them lose 12.3 percent of their total BTC. They made it out fine.

Smells like fractional reserves...


Bitstamp was audited by Mike Hearn, a Bitcoin dev back in May 2014. He said that everything seemed OK and all the funds were fully backed in their cold storage wallets. This was just 8 months ago and I'd be surprised if the situation has changed since then.


from the sound of what the ceo said that they are moving the bitstamp environment to a more secure server location means that the physical servers were not so secured.
where do they keep their physical servers ?? in their moms basement ?? seems like bitstamp should at least be PCI compliant which means their servers need to be physically secured.
when they do an 'audit' then they need to do a security audit. if their stuff is not secure then they should not be in the business. hiring the engineer is expensive but cheaper than losing 5M a year.
from what i have read it sounds like someone walked in to their datacenter (or moms basement) and stuck a flash drive into the server and walked away with the wallet.dat file.
i not saying that is what happened but gathering what the ceo said and what i have read it sounds like maybe that what happened. whatever the case is they did not have sufficient security.