2016 Bitfinex Hack
   HOME

TheInfoList



OR:

The
Bitfinex Bitfinex is a cryptocurrency exchange owned and operated by iFinex Inc registered in the British Virgin Islands. Their customers' money has been stolen or lost in several incidents, and they have been unable to secure normal banking relationshi ...
cryptocurrency exchange A cryptocurrency exchange, or a digital currency exchange (DCE), is a business that allows customers to trade cryptocurrencies or digital currencies for other assets, such as conventional fiat money or other digital currencies. Exchanges may acce ...
was hacked in August 2016. 119,756
bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
, worth about million at the time, were stolen. In February 2022, the US government recovered and seized a portion of the stolen bitcoin, then worth billion, by decrypting a file owned by Ilya Lichtenstein that contained addresses and private keys associated with the stolen funds. Lichtenstein and his wife, Heather R. Morgan, were charged with conspiracy to launder money.


Hack

In August 2016, the
Bitfinex Bitfinex is a cryptocurrency exchange owned and operated by iFinex Inc registered in the British Virgin Islands. Their customers' money has been stolen or lost in several incidents, and they have been unable to secure normal banking relationshi ...
cryptocurrency exchange A cryptocurrency exchange, or a digital currency exchange (DCE), is a business that allows customers to trade cryptocurrencies or digital currencies for other assets, such as conventional fiat money or other digital currencies. Exchanges may acce ...
, based in
Hong Kong Hong Kong ( (US) or (UK); , ), officially the Hong Kong Special Administrative Region of the People's Republic of China ( abbr. Hong Kong SAR or HKSAR), is a city and special administrative region of China on the eastern Pearl River Delt ...
, announced it had suffered a security breach. Around 2,000 approved transactions were sent to a single
wallet A wallet is a flat case or pouch often used to carry small personal items such as paper currency, credit cards; identification documents such as driver's license, identification card, club card; photographs, transit pass, business cards and oth ...
from users' segregated wallets. Immediately thereafter,
Bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
's trading price plunged by 20%, causing the value of the stolen Bitcoin to dip to million. After learning of the breach, Bitfinex halted all Bitcoin withdrawals and trading and said it was tracking down the hack. Exchange customers, even those whose accounts had not been broken into, had their account balance reduced by 36% and received BFX tokens in proportion to their losses. The exchange's access to U.S. dollar payments and withdrawals was then curtailed. The hack happened even though Bitfinex was securing the funds with BitGo, which uses multiple-signature security.


Laundering

Small amounts of money began to move out of the single wallet in early 2017 through the marketplace
AlphaBay AlphaBay is a darknet market operating both as an onion service on the Tor network and as an I2P node on I2P. After it was shut down in July 2017 following law enforcement action in the United States, Canada, and Thailand as part of Operation ...
to launder it. After AlphaBay was shuttered by international law enforcement led by the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and its principal Federal law enforcement in the United States, federal law enforcement age ...
, the money was rerouted to the Russian marketplace Hydra. The shutdown of AlphaBay may have given law enforcement access to the service's internal transaction logs to connect pieces together. In February 2022, a New York couple, Ilya Lichtenstein (age 34) and his wife Heather R. Morgan (age 31), were charged by US federal authorities with conspiring to launder the bitcoin, which was then worth billion. If found guilty, each of the pair faces a maximum sentence of 20 years in prison for the alleged conspiracy to launder money, and a maximum sentence of five years for the alleged
conspiracy to defraud the United States Conspiracy against the United States, or conspiracy to defraud the United States,§ 92318 U.S.C. § 371—Conspiracy to Defraud the United States U.S. Department of Justice's ''United States Attorneys' Manual''. is a federal offense in the United ...
. Neither were accused of perpetrating the hack. Law enforcement were able to acquire a
search warrant A search warrant is a court order that a magistrate or judge issues to authorize law enforcement officers to conduct a search of a person, location, or vehicle for evidence of a crime and to confiscate any evidence they find. In most countries, ...
for a
cloud storage service A file-hosting service, cloud-storage service, online file-storage provider, or cyberlocker is an internet hosting service specifically designed to host user files. It allows users to upload files that could be accessed over the internet afte ...
used by Lichtenstein, obtaining a spreadsheet of wallet addresses linked to the hack, and their passwords. One of the wallets had around 94,000 Bitcoin. Due to the openness and transparency of the
blockchain A blockchain is a type of distributed ledger technology (DLT) that consists of growing lists of records, called ''blocks'', that are securely linked together using cryptography. Each block contains a cryptographic hash of the previous block, a ...
, law enforcement was able to track the money; and obtaining the passwords allowed them to seize it. Some of the funds were moved towards more traditional financial accounts and used on gold,
NFTs The National Film and Television School (NFTS) is a film, television and games school established in 1971 and based at Beaconsfield Studios in Beaconsfield, Buckinghamshire, England. It is featured in the 2021 ranking by ''The Hollywood Repor ...
, and a
Walmart Walmart Inc. (; formerly Wal-Mart Stores, Inc.) is an American multinational retail corporation that operates a chain of hypermarkets (also called supercenters), discount department stores, and grocery stores from the United States, headquarter ...
gift card spent on
Uber Uber Technologies, Inc. (Uber), based in San Francisco, provides mobility as a service, ride-hailing (allowing users to book a car and driver to transport them in a way similar to a taxi), food delivery (Uber Eats and Postmates), package ...
rides and a
PlayStation is a video gaming brand that consists of five home video game consoles, two handhelds, a media center, and a smartphone, as well as an online service and multiple magazines. The brand is produced by Sony Interactive Entertainment, a divisi ...
. Though hundreds of millions of dollars were converted to fiat currency, 80% of the Bitcoin were still in the original wallet at the center of the hack. Shortly after the couple's arrest, Netflix ordered a documentary series that will cover the story of Lichtenstein's and Morgan's alleged crimes.


See also

* History of bitcoin


References

{{Hacking in the 2010s Cryptocurrency theft Money laundering Robberies in the United States Hacking in the 2010s Bitfinex hack Bitfinex hack