Results 1 to 4 of 4

Thread: Unconfirmed Report Details $5 Million Bitstamp Bitcoin Exchange Hack

  1. #1

    Unconfirmed Report Details $5 Million Bitstamp Bitcoin Exchange Hack

    http://www.coindesk.com/unconfirmed-...coin-exchange/

    Six employees of Bitstamp were targeted in a weeks-long phishing attempt leading up to the theft of roughly $5m in bitcoin in January, according to an incident report said to be drafted internally by the bitcoin exchange.

    The confidential document, posted to Reddit by a single-purpose account, offers an in-depth look into what is believed to be the inside story of the hack, which resulted in the loss of just under 19,000 BTC earlier this year. Since then, the company has offered scant details on what took place behind the scenes, citing confidentiality regarding the investigation into the lost funds.

    The report’s findings are notable as they illustrate the risks facing bitcoin exchanges, including social engineering attacks in which personal information is used to trick victims into providing a means of access to sensitive materials.

    In the case of Bitstamp, those behind the attack used Skype and email to communicate with employees and attempt to distribute files containing malware by appealing to their personal histories and interests. Bitstamp’s system became compromised after systems administrator Luka Kodric downloaded a file that he believed had been sent by a representative for an organization that was seeking his membership.

    The report, attributed to Bitstamp general counsel George Frost, explained:

    “On 11th December, as part of this offer, the attacker sent a number of attachments. One of these, UPE_application_form.doc, contained obfuscated malicious VBA script. When opened, this script ran automatically and pulled down a malicious file from IP address 185.31.209.145, thereby compromising the machine.”
    Ultimately, the attackers were able to access two servers containing the wallet.dat file for Bitstamp’s hot wallet and the passphrase for that file.
    more at link.



  2. Remove this section of ads by registering.
  3. #2
    A sys admin opening a doc file from a stranger, in a manner that allowed scripting to run automatically, on a machine used for work? I hope he's not still employed as a sys admin.
    “…let us teach them that all who draw breath are of equal worth, and that those who seek to press heel upon the throat of liberty, will fall to the cry of FREEDOM!!!” – Spartacus, War of the Damned

    BTC: 1AFbCLYU3G1dkbsSJnk3spWeEwpqYVC2Pq

  4. #3
    Quote Originally Posted by kpitcher View Post
    A sys admin opening a doc file from a stranger, in a manner that allowed scripting to run automatically, on a machine used for work? I hope he's not still employed as a sys admin.
    I'll admit, I didn't like reading that report. All those top guys with hot wallet access from their laptops without multi-sig. I hope they are at least using noscript when surfing on porn sites using company laptops for personal use.

  5. #4
    That news is scarey. I hope Coinbase isn't the next target.



Similar Threads

  1. Replies: 13
    Last Post: 04-14-2014, 10:49 AM
  2. Replies: 0
    Last Post: 02-11-2014, 03:42 PM
  3. Bitcoin to Bitcoin currency exchange?
    By AlexAmore in forum Bitcoin / Cryptocurrencies
    Replies: 7
    Last Post: 01-10-2014, 04:00 AM
  4. Replies: 4
    Last Post: 11-11-2013, 08:39 AM
  5. Saudi King Abdullah Has Died (Unconfirmed Report)
    By wildfirepower in forum U.S. Political News
    Replies: 2
    Last Post: 02-10-2011, 05:35 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •