How hackers broke the crypto code and stole $500 mn in digital currency

Crime raises questions about security of cryptocurrencies around the world, as affected exchange admits to security lapse

Hacking
.
Pavel Alpeyev & Yuji Nakamura | Bloomberg
Last Updated : Jan 29 2018 | 3:08 PM IST
Early Friday morning in Tokyo, hackers broke into a cryptocurrency exchange called Coincheck Inc. and made off with nearly $500 million in digital tokens. It’s one of the biggest heists in history, with the exchange losing more than 500 million of the somewhat obscure NEM coins. The hack has raised questions about security of cryptocurrencies around the world.

Q: How did the hackers pull it off?

A: Coincheck hasn’t disclosed how their system was breached beyond saying that it wasn’t an inside job. The company did own up to a security lapse that allowed the thief to seize such a large sum: It kept customer assets in what’s known as a hot wallet, which is connected to external networks. Exchanges generally try to keep a majority of customer deposits in cold wallets, which aren’t connected to the outside world and thus are less vulnerable to hacks. Coincheck also lacked multi-signature security, a measure requiring multiple sign-offs before funds can be moved.

Q: Where did the stolen coins go?

A: That’s one of the stranger aspects of these heists. Because transactions for Bitcoin and the like are all public, it’s easy to see where the NEM coins are -- even though they’re stolen. Coincheck has identified and published 11 addresses where all 523 million of the stolen coins ended up. You can see for yourself online. Trouble is, no one knows who owns the accounts. Each one has been labeled with a tag that reads "coincheck_stolen_funds_do_not_accept_trades : owner_of_this_account_is_hacker." NEM developers created a tracking tool that would allow exchanges to automatically reject stolen funds.

Q: Does that mean the hackers won’t be able to cash in?

A: Not necessarily. The thief may be able to shake off surveillance by going through a “tumbler,” a service like ShapeShift that offers cryptocurrency trading without collecting personal data. Converting NEM coins into a more anonymized currency, like Monero, could conceivably launder them. But the huge total amount of money stolen presents a challenge. NEM trading was disabled on ShapeShift as of Monday.

Q: What else can NEM developers do to fix this?

A: Developers could change the NEM blockchain by rolling back the record to a point before the attack. The so-called hard fork would create two versions of NEM, one that has never been hacked and another containing the stolen funds. While this approach worked for Ethereum in 2015, NEM Foundation Vice President Jeff McDonald said a fork is not an option.

Q: For all the talk about crypto being the future of currency, these exchanges seem to be getting hacked a lot.

A: You’ve noticed? Yes, there’s a long history of thefts at cryptocurrency exchanges and wallets, dating back to the infamous robbery of Tokyo-based Mt. Gox in 2014. As prices of digital assets have soared, the platforms have become increasingly juicy targets for hackers. North Korean leader Kim Jong Un has allegedly sent his hackers out to swipe digital coins as his country faces tightening trade sanctions. One researcher estimates that more than 14 percent of Bitcoin and rival currency Ether has been stolen.

Q: So what can an individual do to keep crypto-assets safe?

A: The lesson for crypto-enthusiasts is that exchanges are prime targets for hackers and no place to store your coins. One alternative is to keep the assets in software wallets, which come in online, mobile and desktop varieties. Hardware wallets are dedicated devices that offer an additional layer of security. For the extra paranoid, there is always the analog option: printing out the private keys for your coins on paper.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Next Story