{"id":79530,"date":"2023-05-29T19:45:25","date_gmt":"2023-05-29T16:45:25","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=79530"},"modified":"2025-09-11T11:34:25","modified_gmt":"2025-09-11T08:34:25","slug":"journalists-reveal-details-of-bitfinex-hack-report","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/journalists-reveal-details-of-bitfinex-hack-report\/","title":{"rendered":"Journalists reveal details of Bitfinex hack report"},"content":{"rendered":"<p>The bitcoin exchange Bitfinex failed to implement &#8216;operational, financial and technological controls&#8217;, which made the 2016 hack possible. The report, <a href=\"https:\/\/www.occrp.org\/en\/blog\/17670-confidential-report-flags-bitfinex-security-lapses-in-huge-2016-hack\">as stated<\/a> on the OCCRP website.<\/p>\n<p>OCCRP brings together media outlets and investigative reporters conducting journalism in Eastern Europe, Central Asia, Latin America and Africa. The main funding comes from <span data-descr=\"U.S. Agency for International Development\" class=\"old_tooltip\">USAID<\/span>.<\/p>\n<p>The centre claims to have obtained access to a confidential incident-investigation report. It was prepared by the Canadian firm Ledger Labs at the request of iFinex, the parent company of Bitfinex.<\/p>\n<p>According to the document, the trading platform did not implement the measures proposed by its partner BitGo. The investigation states that Bitfinex used a system that requires an administrator to hold two of three security keys to execute any major operation. The company &#8216;made a critical error&#8217; by keeping two keys on a single device.<\/p>\n<p>The document also states that the exchange lacked other basic security measures, including server activity logging and a &#8216;withdrawal whitelist&#8217;.<\/p>\n<p>Journalists stressed that they could not independently verify the report&#8217;s findings. According to them, Bitfinex did not challenge the document&#8217;s veracity, and its author Michael Perklin cited a non-disclosure agreement.<\/p>\n<p>Meanwhile, representatives of the exchange told OCCRP that Ledger Labs&#8217; analysis was &#8216;incomplete&#8217; and &#8216;incorrect&#8217;. They said there was &#8216;evidence of negligence&#8217; by other counterparties that led to the hack.<\/p>\n<p>Ledger Labs did not respond to journalists&#8217; requests. BitGo declined to comment, but did not dispute the existence of the document.<\/p>\n<p>As a result of the hack in early August 2016, Bitfinex lost nearly 120,000 BTC (about $71.8 million at the time, over $3.3 billion at current prices) and suspended trading for a time.<\/p>\n<p>In May 2020, unknown actors moved 30.667192 BTC to anonymous addresses. Later, <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-again-move-bitcoins-stolen-from-bitfinex\">4571 BTC and 473.3183 BTC<\/a> moved. <\/p>\n<p>In August 2020, <a href=\"https:\/\/u1f987.com\/en\/news\/bitfinex-offers-up-to-400m-for-return-of-2016-stolen-btc\">Bitfinex announced a $400 million reward<\/a> for help in recovering the stolen funds. In October, the attackers moved bitcoins worth <a href=\"https:\/\/u1f987.com\/en\/news\/bitfinex-hacked-bitcoins-move-again\">more than $30 million<\/a>, and in December \u2014 in total <a href=\"https:\/\/u1f987.com\/en\/news\/bitfinex-stolen-bitcoins-move-again\">7,045.48 BTC<\/a>.<\/p>\n<p>On February 1, 2022, <a href=\"https:\/\/u1f987.com\/en\/news\/over-90000-btc-moved-from-bitfinex-hack\">94,643 BTC moved<\/a>. In the same month, U.S. authorities <a href=\"https:\/\/u1f987.com\/en\/news\/u-s-authorities-confiscated-3-6-billion-in-bitcoin-stolen-from-bitfinex\">arrested<\/a> 34-year-old Ilya Lichtenstein and 31-year-old Heather Morgan on charges of laundering 119,754 BTC stolen from Bitfinex.<\/p>\n<p>Representatives of the U.S. Department of Justice also announced the largest seizure of digital assets in the department&#8217;s history \u2014 94,636 BTC ($3.6 billion at the time).<\/p>\n<p>Morgan <a href=\"https:\/\/u1f987.com\/en\/news\/heather-morgan-linked-to-bitfinex-hacked-assets-released-on-3-million-bond\">was released on $3 million bail<\/a>. The court found that there was no substantial evidence against her beyond the assertion that she allegedly received funds related to the case.<\/p>\n<p>The streaming service <a href=\"https:\/\/u1f987.com\/en\/news\/netflix-announces-series-about-those-involved-in-bitfinex-stolen-assets\">Netflix<\/a> announced a documentary series about Morgan and Lichtenstein.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The bitcoin exchange Bitfinex failed to implement &#8216;operational, financial and technological controls&#8217;, which made the 2016 hack possible.<\/p>\n","protected":false},"author":1,"featured_media":79531,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[95,1154,1323],"class_list":["post-79530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-bitfinex","tag-crimes","tag-investigations"],"aioseo_notices":[],"amp_enabled":true,"views":"82","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=79530"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79530\/revisions"}],"predecessor-version":[{"id":79532,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/79530\/revisions\/79532"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/79531"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=79530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=79530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=79530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}