Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Mt. Gox Chief Stole 100,000 Bitcoins, Hackers Claim

Cryptocurrency aficionados' ire stoked by leaked accounts showing 100,000 bitcoins remain missing.

Hackers seized control of the personal blog of Mark Karpeles, CEO of the bankrupt Mt. Gox Bitcoin exchange, on Sunday and posted a message accusing him of stealing 100,000 bitcoins (BTC).

"It's time that MTGOX got the bitcoin communities wrath instead of [the] Bitcoin Community getting Goxed," read the message, which hackers posted both to Karpeles's magicaltux.net site as well as to his Reddit page. "This release would have been sooner, but in [the] spirit of responsible disclosure and making sure all of [our] ducks were in a row, it took a few days longer than [we] would have liked to verify the data."

The data in question referred to a dump -- a.k.a. dox -- in the form of a 716-MB zip file, which hackers distributed via Karpeles's site, and which purportedly contained evidence of fraud. "Included in this download you will find relevant database dumps, CSV exports, specialized tools, and some highlighted summaries compiled from data. Keeping in line with [expletive] Gox alone, no user database dumps have been included." The zip file also includes an Excel spreadsheet listing about a million Mt. Gox trades, a screenshot of hackers' access to the systems of Mt. Gox's parent company, Tibanne Limited, a listing of Mark Karpeles's home addresses, as well as his CV, Forbes reported.

[Mt. Gox is not the only Bitcoin exchange with problems. See Bitcoin Heists Cause More Trouble.]

Also included -- and excerpted in a post to Pastebin -- were the exchange's alleged balances, in 18 different currencies, including a bitcoin balance of 951,116 BTC. Whoever hacked Karpeles's site cited that number as evidence that the Mt. Gox chief lied about the site going bankrupt, since he'd said that attackers appeared to have stolen 850,000 bitcoins. In other words, there appeared to be a discrepancy involving 100,000 BTC, which would have been worth about $62.4 million.

Some Bitcoin followers read that discrepancy as evidence that Karpeles still controlled a horde of bitcoins, no matter whether hackers had stolen the rest. Or in the words of one Reddit commenter: "We've been goxed!"

But other Bitcoin watchers said that the leaked data, while likely legitimate, didn't prove anything about the actual state of either Mt. Gox's coffers -- to say nothing of its accounting prowess. "It's legit data, but it's not proof of anything," said "PuffyHerb" on Reddit. "This is Mt. Gox's internal accounting. If there are problems with this, then it lines up with what they've been [saying] all along (i.e. they didn't know BTC was being siphoned off)."

While Karpeles appears to have blanked out his personal site after hackers began using it to distribute their dox, supposed copies of the data dump have been mirrored to other download sites and are also circulating via BitTorrent.

One caution for anyone who wants to analyze the leaked information: In a discussion on Bitcoin Forum, multiple people said that the text files in the download "are interesting and safe," but warned that executable files in the zip archive contain malware, and thus should only be analyzed using a virtual machine (VM). "One of the .exe files contains the wallet.dat stealer," said "oyvinds" in a comment. "Only run the .exe files in a throw-away VM if you are curious or on your normal Windows installation if you have too many Bitcoins and want to get rid of them." He noted that a PDF document included in the dump also included "evil JavaScript," suggesting that it was designed to steal bitcoins.

As the hackers' accusations suggest, many Bitcoin aficionados are fuming over Mt. Gox's meltdown, and don't mind taking revenge at the expense of other Mt. Gox -- or Bitcoin -- users. On a related note, as Forbes first reported, a Bitcoin Forum user called "nanashi___" on Friday posted a message offering to sell a 20-GB file of user information -- including passport scans -- allegedly stolen from Mt. Gox, for 100 bitcoins (about $62,000) to cover losses he incurred from the exchange's failure. "Selling it one or two times to make up personal loses from gox closure," according to the post, which has since been deleted by the forum's administrators. "Asking 100BTC for entire document. Willing to sell it in pieces, 10BTC for 2gb of data."

Revenge aside, fresh evidence that Mt. Gox's bitcoins were stolen by outside attackers surfaced Sunday, when The Japan News reported -- referencing multiple, unnamed sources -- that the exchange was being hammered by distributed denial-of-service (DDoS) attacks, peaking at 150,000 system access attempts per second. The attacks, which reportedly originated from systems in the United States and Europe, began on February 7, and apparently occurred at the same time as hackers were draining the company's bitcoin balance via transaction malleability attacks.

On February 10, Mt. Gox suspended all bitcoin withdrawals, before filing for bankruptcy protection on February 28.

While it's not clear whether Mt. Gox's bitcoin thieves also launched the DDoS attacks, criminals have regularly employed DDoS smokescreens to steal bitcoins. In November, for example, the Denmark-based Bitcoin Internet Payment System (BIPS) was hit by a DDoS attack at the same time that attackers hacked into the company's free online wallets and stole 1,295 bitcoins, worth nearly $1 million. According to Kris Henriksen, CEO of the Bitcoin payment processor, the attacks against his site appeared to emanate "from Russia and neighboring countries."

Cybercriminals wielding APTs have plenty of innovative techniques to evade network and endpoint defenses. It's scary stuff, and ignorance is definitely not bliss. How to fight back? Think security that's distributed, stratified, and adaptive. Read our Advanced Attacks Demand New Defenses report today. (Free registration required.)

Mathew Schwartz served as the InformationWeek information security reporter from 2010 until mid-2014. View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
3/30/2014 | 4:48:39 AM
Re: sigh
Way to go hackers! now with all that evidence provided.......... wait you mean now he can probally say that all his files were corrupted by hackers and blame them for what he did because they were stupid and trying to take vigialante justice/investigating?
User Rank: Ninja
3/12/2014 | 10:21:37 AM
Re: So much!
While I suspect not, it does make you wonder if we'll need to see a new generation of coin with a stronger backbone before a digital currency really becomes accepted.
Madhava verma dantuluri
Madhava verma dantuluri,
User Rank: Apprentice
3/11/2014 | 9:29:39 AM
So much!
With the Bitcoin, so much inner security leaks opened up and hope system should be rebust.
User Rank: Ninja
3/11/2014 | 8:22:11 AM
Re: sigh
There's two sides to that (bit) coin though. The benefits of bitcoin like: instantaneous transfer, lack of fees, no requirement of middlemen, anonymity, are features that simply cannot be found anywhere in the banking system outside of cash, which is gradually going away. 

While of course there are sturdier ways to invest your money than by buying up lots of bitcoins, it shows real promise as a way of eliminating antiquated practices of institutions and governments harassing money out of people simply because they're too small to do anything about it. 
Lorna Garey
Lorna Garey,
User Rank: Ninja
3/10/2014 | 1:55:26 PM
Re: sigh
This is true, but also, these people have a LOT of time on their hands.
User Rank: Apprentice
3/10/2014 | 1:50:38 PM
It's always fun watching Libertarians learn why governments and regulations exist.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can ...
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one....
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and ...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices f...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `outpu...