Post
Topic
Board Service Discussion
Re: MtGox and 2 Factor Authentication
by
acoindr
on 13/07/2012, 21:08:31 UTC
I am told API key was already revoked. Information seems to be conflicting and confusing.

The API key was used as a password to LastPass, which in turn had the password to log into Mt.Gox.

Is that a joke?

Oh wow. Thanks for bringing this to light.

We regret to inform you that there has been another huge breach of Bitcoinica. While all passwords were changed after the theft which occurred May 11th, the password for LastPass was not compromised and thus left unchanged. The breach today occured because the password for LastPass was in fact a duplicate password which had been compromised during the hack.

Unbeknownst to us, Tihan was using the mtgox api key as the password for a website called LastPass.