Bitcoin Forum

Bitcoin => Important Announcements => Topic started by: Maged on July 31, 2012, 02:03:52 PM



Title: BTC-e Exchange Compromised, trading halted (now resumed)
Post by: Maged on July 31, 2012, 02:03:52 PM
From https://btc-e.com/news/81:
Quote
Dear users of the Exchange Btc-e.com

The exchange is not going to close. We will refund all losses from our reserves.

Neither the servers nor the database were compromised. There were no SQL injections.

At 04:07 MSK (GMT+4) our LR API Secret Key was compromised. It's 16 uppercase, lowercase letters and digits. They may have bruteforced it for long.

Using the key the hacker imitated LR deposits from many accounts and bought up Bitcoins, Namecoins and Litecoins.

We lost our daily volume, approx. 4500 BTC. The attacker couldn't withdraw more
as most BTC were distributed over several offline wallets.

At 10:30 we restored the database to the state it was at 04:00, right before the attack. All trades after 4:00 are reverted.

People who attempted withdrawals before 04:00 MSK will get their funds withdrawn later today.

For people who deposited BTC, LTC and NMC after 04:00 MSK the funds will be put to their balances before market opens.
We are working on the scripts for this.

If you deposited USD after 04:00 MSK you should send us your login, amount and payment system used by email or PM.

Our plan:

1. The trade will be disabled until we restore the balances to the point before market crash.

2. After that, the trade and deposit/withdrawal will be back on, approx. within 1-2 days.

Icq - 610112128
Skype - btc-e.support
E-mail - support@btc-e.com
Most of the discussion on this can be found here:
https://bitcointalk.org/index.php?topic=96802.0
https://bitcointalk.org/index.php?topic=96831.0
https://bitcointalk.org/index.php?topic=96811.0


Title: Re: BTC-e Exchange Compromised, trading halted
Post by: Maged on July 31, 2012, 03:02:28 PM
[7/31/12 10:49:33 AM] btc-e.com: Started trading!

Since the attack started about 8pm Eastern last night, I have been awake until about now (11am EST) working with BTC-e on the investigation.

From the moment they woke up and I broke the news to them, until now they have handled it exeptionally well.

Within only a few hours they posted an update https://btc-e.com/news/81

It sounds like they also adopted good security practices and because of it only lost 4500 BTC.

Bitinstant will resume to work with BTC-E, however even though trading is resumed we will not be enabling deposits/withdrawals in and out of BTC-e to protect customers funds for the next few hours.

Thanks

-Charlie
https://bitcointalk.org/index.php?topic=96912.0


Title: Re: BTC-e Exchange Compromised, trading halted (now resumed)
Post by: John (John K.) on August 01, 2012, 07:57:20 AM
Update Bitinstant <--> BTC-E Enabled now

It sounds like they also adopted good security practices

Explaining the external use of their LR key with "brute forced" has me worried, I don't see how that's computationally possible: https://bitcointalk.org/index.php?topic=96831.msg1068030#msg1068030

What additional security practices are put in place in case the hackers are able to extract new replacement keys easily?



They are preparing a full write up for the community including screenshots, ect.