Good news, everyone!
The hacker (a bit of a misnomer, as he has pointed out) returned 50 BTC, and I have just distributed it to affected users. Looks like the other 65 will be sent, too.
Busoni
Once you get back all 115 BTC and you have distributed them to the affected account holders, the situation will hopefully be completely remedied. I understand that the withdrawn 7000 XCP have been mitigated by the 12 BTC you received from the developers.
The commission of 2.5% that you have levied to raise 115 btc should ideally go to the bugs and security bounties now. You should have had a volume of at least 200 BTC since you raised the commission so I am guessing approximately 10 btc raised so far. Will you please consider donating these to the bounty?
I thank the person returning all the coins back to you and I hope the devs are able to involve him as an external security auditor as originally intended by them before he went AWOL
Last I heard the 12 BTC were meant for the hacker, as well as a "security consultant" position. I do agree additional money from donations and whatnot since then should also go to the security bounty, which should be paid at the dev's discretion.
As described in the
chatlog, steps to implement stricter validation are always appreciated, given especially the use of multisig. Similar validation will also have to be done when OP_RETURN is finally implemented, as that has only been on testnet so far.
They were meant for the hacker but because of lack of response from the hacker it was given to Busoni. I thought I read something along those lines.