After A $65m Hack, Is Bitcoin Really Safe & Secure?

It seemed bitcoin exchange Bitfinex was doing all the right things. In the end, that didn’t stop hackers from stealing $65 million.

The latest in a long list of attacks on the digital currency since its birth in 2009 has been particularly vexing for the bitcoin community. Not only was Bitfinex the largest exchange for US dollar transactions, but the hack highlights that the industry hasn’t figured out critical security, despite years of learning from mistakes and making improvements to its infrastructure.

Even as the incident has triggered calls for audits in certain parts of the industry, experts don’t anticipate the investigations will unearth new ways of radically strengthening protection. What’s more telling, they say, is that the community’s willingness to vilify targets while shrugging off the need for industry-wide solutions is a sign it’s doomed to happen again.

“There is a long tradition of blaming the victim in the bitcoin community,” said Emin Gun Sirer, a Cornell University computer science professor who researches the currency. “But when you have a six-year long history of near-continuous key theft, at some point, we have to stop shirking off the responsibility.”

The fallout has been widespread. Bitfinex imposed a levy on customers to cover the lost $65 million, taking 36 percent of everyone’s assets whether they had been hit by the hackers or not.

The price of bitcoin also plunged on news of the hack, slashing the value of the digital currency well beyond Bitfinex. Collectively, investors have lost about $1.2 billion since the attack, according data from Coindesk.

That’s not to say bitcoin security hasn’t come far, through the efforts of thousands who work and volunteer to improve the digital currency. Since Mt. Gox, at one time the world’s largest exchange, was hacked for $450 million in early 2014, most venues have adopted tough security measures, including segregated client accounts, external audits of systems and two-factor authentication for securing logins.

Another step forward has been multi-signature security, which essentially splits the private keys attached to every bitcoin into several copies and hides them in multiple locations. The technology requires a sign-off from a majority of the copies (for example, two out of three) before the bitcoin can be moved again. That forces hackers to breach multiple systems before they can get access to funds.

Bitfinex made use of the technology and, as suggested by security experts, stored copies offline and with a third party, its security partner BitGo Inc. When it was implemented in June 2015, confidence was so high that BitGo’s chief executive officer boasted the system made “breaches such as those of Mt. Gox impossible.”

Bitfinex hasn't disclosed details of how hackers managed to compromise that system, saying the investigation is still pending. It did suspend its use of BitGo's technology and said hackers had increased withdrawal limits without BitGo realizing it.

BitGo has said its software functioned properly and denied its systems were breached. “Securing tiny electronic files from leaking - keys - pushes the bounds of known computer science,” Jeff Garzik, one of bitcoin’s earliest developers and founder of blockchain startup Bloq Inc., wrote in an e-mail. “Multi-sig raises that bar considerably, but nothing is perfect.”

After a hack thought ‘impossible’ just a year ago, bitcoin proponents are scrambling for solutions. Some argue that existing technology is strong enough to keep out hackers, but implementation has to be better. Individuals, for example, can protect themselves by storing bitcoin in individual wallets rather than at exchanges, which remain targets for attack.

“When users choose to store their bitcoin in a custodial wallet or exchange, they are giving the provider control over their bitcoins,” said Peter Smith, chief executive officer of Blockchain, which provides bitcoin wallets to individuals. “As a result, customers are not only subjected to the possibility that they will lose their funds via cybertheft but also that the provider can impose a tax to cover the loss of other clients, as Bitfinex is doing here.”

A more radical solution is to use technology to punish thieves. This summer, hackers siphoned off about $60 millions of Ethereum, the world’s second most-popular digital currency behind bitcoin. The community reacted by adopting a so-called hard fork, which effectively migrated users to a new version of Ethereum in which the theft never occurred.

The decision triggered a rebellion from a significant chunk of the community, who argued that nullifying the theft was a violation of Ethereum’s free market ethos. Given such extreme steps, some say the time has come for the bitcoin community to consider a form of regulation, either self-imposed or with the assistance of governments. The key, they say, will be educating regulators so that they don’t slow down innovation in the name of protecting consumers.

Some, including BitGo, have begun work with auditors like Deloitte LLP to standardize security requirements for the industry, although how and who would enforce the guidelines is unclear.

“Even bitcoin enthusiasts are slowly realizing that regulation is necessary,” said Trond Undheim, a former senior lecturer at Massachusetts Institute of Technology’s Sloan School of Management. “That’s the only way it will survive. That’s also the key to its wider adoption.”

Investors want solutions. Kay Van-Petersen, a strategist at Saxo Capital Markets, avoided Bitfinex but still saw a tenth of his bitcoin investment wiped out as prices dropped after the attack. “Every time an exchange gets hacked, it just looks bad on everybody,” he said.

Information-Management:

 

« Snowden: NSA Hacking Tools Leak Is ‘a warning’
The 3 Biggest Mistakes in Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Varonis

Varonis

Varonis provide a security software platform to let organizations track, visualize, analyze and protect their unstructured data.

techUK

techUK

techUK represents companies operating in the tech sector in the UK. Focus areas cover all aspects of ICT including cyber security.

Cloudmark

Cloudmark

Cloudmark is a trusted leader in intelligent threat protection against known and future attacks, safeguarding 12 percent of the world’s inboxes from wide-scale and targeted email threats.

Compumatica

Compumatica

Compumatica is a leading European ICT security manufacturer for cybersecurity and encryption products. Solutions include network security, SCADA/ICS security, Mobile/BYOD and email encryption.

_cyel

_cyel

_cyel is introducing a new cybersecurity strategy: not a new generation of patches and firewalls, but moving target security – we take away the targets. Without replacing your existing system.

Secure Code Warrior

Secure Code Warrior

Secure your code from the start with gamified, scalable online secure coding training for software developers.

Capsule8

Capsule8

Capsule8 is the only company providing high-performance attack protection for Linux production environments.

Quantum Generation

Quantum Generation

Quantum Cyber Security for a new age of communications. We are developing the largest decentralized orbital, and ground quantum mesh network based on blockchain technology.

Cambridge Cybercrime Centre

Cambridge Cybercrime Centre

The Cambridge Cybercrime Centre is a multi-disciplinary initiative combining expertise from the Department of Computer Science and Technology, Institute of Criminology and Faculty of Law.

Digital Magics

Digital Magics

Digital Magics is an incubator for innovative startups which offer content and services with high technological value. Areas of focus include IoT, Enterprise Software, AI, Industry 4.0 and Blockchain.

Calyptix Security

Calyptix Security

Calyptix Security helps small and medium offices secure their networks so they can raise profits, protect investments, and control technology.

Emagined Security

Emagined Security

Emagined Security is a leading provider of professional services for Information Security and Compliance solutions.

Evanssion

Evanssion

Evanssion is a value added distributor specialized in Cloud Native & Cyber Security across Middle East & Africa.

Kralos

Kralos

Kralos are an experienced team of Software and IT experts, specialized in the development of innovative cybersecurity solutions.

Google Safety Engineering Center (GSEC)

Google Safety Engineering Center (GSEC)

GSEC Málaga is an international cybersecurity hub where Google experts work to understand the cyber threat landscape and to create tools that keep users around the world safer online.

SPIE Switzerland

SPIE Switzerland

SPIE Switzerland AG, a subsidiary of the SPIE Group, is a Swiss full-service provider of ICT, multi-technical and integral facility services.