Here is a more complete rundown of what happened with the baron account.
Person A had their mtgox account compromised by Person B.
Day1: Person B sent ~3000BTC (the mtgox $1000 a day limit at the time) from person A's account to an address owned by baron.
Day2: Person B sent ~3000BTC (the mtgox $1000 a day limit at the time) from person A's account to an address owned by baron.
Day3: Person B sent ~3000BTC (the mtgox $1000 a day limit at the time) from person A's account to an address owned by baron.
Day4: Person A logs into their account and notices the missing BTC. They change their password and contact me about the theft.
DayX: Person B finds an exploit in my LR code and manages to send himself a good deal of LR from the site.
DayY: Person B steals money from 2 other mtgox accounts after compromising them with a dictionary attack. This is discussed elsewhere.
I have talked to Person A on the phone extensively both before and after the theft. He had much more in his account than what was stolen.
baron claims that he bought the BTC in question from someone on IRC with Liberty Reserve (LR). He hasnt been able to provide any evidence of this transfer. I see nothing even close in the IRC logs of bitcoin-otc about this transfer.
To believe barons story we have to believe:
1) A thief would trust a random person on IRC they have never met before and no one else on the channel knows to send them $3000.
2) The thief would transfer directly from mtgox to the buyer before knowing how much BTC they would end up stealing from mtgox.
3) baron cant remember his nick, the thiefs nick, or the IRC channel that was used for the trade.
4) baron can no longer find the record of the LR transaction.
5) baron is unable to talk to me on the phone because according to him he is mute.
baron also refuses to provide proof of who he is or where he lives.
We are left having to assume that baron is in fact person B. barons account on mtgox holds less than the sum of theft by person B.
----
As I have said previously we dont want to be the bitcoin police and this will hopefully not be necessary in the future since we have fixed these security issues that allowed Person B to steal from us and other users in the first place.