2016 Crypto Hack: Bitfinex Hid a Report that Flagged Security Flaws: OCCRP
Cryptocurrency exchange Bitfinex never made public a confidential report that found its security lapses responsible for over 119,000 bitcoins stolen from the platform in August 2016, the Organized Crime and Corruption Re...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Cryptocurrency exchange Bitfinex never made public a confidential report that found its security lapses responsible for over 119,000 bitcoins stolen from the platform in August 2016, the Organized Crime and Corruption Reporting Project (OCCRP) reported on Thursday. The stolen BTCs, worth about $3.2 billion in today’s market, were priced at $71 million at the time.
OCCRP, a global network of investigative journalists, said it obtained a version of the secret report that says Bitfinex failed to execute operational, financial and technological controls recommended by its digital security partner Bitgo. The network said the report was commissioned by iFinex, the owner and operator of Bitfinex, and was produced by Canada-based blockchain services firm, Ledger Labs.
Giving further details, OCCRP said the report claims that Bitfinex deployed a security system that placed two of its three security keys with an administrator. The keys were required to conduct a significant operation on the exchange, including transferring bitcoins.
In addition, OCCRP noted that Bitfinex made the mistake of storing two of the three keys on a single device. However, it added that while it is not known if the device was compromised during the hack, access to it would give a hacker complete access to the crypto exchange’s internal system and ‘security tokens’.
"Other basic security measures were also absent, including the logging of server activity outside of the server itself," OCCRP wrote in its report, adding that the 'withdrawal whitelist', a security component that enables cryptocurrency transfers to verified addresses, was also unavailable.
Additionally, the journalism network said the confidential report suggested that the hack was probably organized from Poland, going by a detailed examination of the source Internet Protocol address.
Bitfinex Slams OCCRP Report
As reported, Bitfinex told OCCRP that Ledger Labs’ analysis in the report was “incomplete" and “incorrect.” On top of that, the network quoted Bitfinex as saying there was “evidence of negligence…on the part of other counterparties that led to the hack.”
In an undated statement published on its website, Bitfinex also reiterated these points, noting that “assertions made by the OCCRP are factually incorrect." Moreover, the crypto exchange criticised a report on the issue published by Wired whose journalist worked on the report with the OCCRP.
“Bitfinex refutes the findings of the OCCRP,” said the digital exchange operator. “As is well known, there is an investigation being conducted by authorities into the 2016 hack, with which Bitfinex has collaborated and shared information over many years.”
Also, Bitfinex said it will provide full details on the case when investigations are completed, noting that: “to make any comments before the investigation into the breach is concluded would be inappropriate.”
United States Charges Two Suspects
Meanwhile, while the Bitfinex hacker remains at large, US prosecutors in February last year charged an American couple for trying to launder roughly $4.5 billion in cryptocurrency linked to the 2016 hack. The US Department of Justice (DOJ) in a statement said the government seized more than 94,000 bitcoins connected to the attack from the couple, Ilya Lichtenstein and Heather Morgan. The bitcoins were worth over $3.6 billion at the time.
Furthermore, the prosecutor noted that the BTCs stolen from Bitfinex through over 2,000 unauthorized transactions were sent to a crypto wallet under Lichtenstein’s control. The OCCRP reported that the couple pleaded not guilty and is awaiting trial.
“Over the last five years, approximately 25,000 of those stolen bitcoins were transferred out of Lichtenstein’s wallet via a complicated money laundering process that ended with some of the stolen funds being deposited into financial accounts controlled by Lichtenstein and Morgan,” the DOJ explained. “The remainder of the stolen funds, comprising more than 94,000 bitcoins, remained in the wallet used to receive and store the illegal proceeds from the hack,” it added.
This article was written by Solomon Oladipupo at www.financemagnates.com.Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Finance MagnatesRelated market context
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...
Crypto Exchange Sign-Up Bonuses Explained: How to Get Free Bitcoin in 2026
A crypto sign-up bonus is a reward that a crypto exchange offers to new users for opening an account and completing certain tasks....
South Korea Ends 1M Won Crypto Travel Rule Limit in Major AML Crackdown
Key Takeaways: The Travel Rule will be adopted by South Korea for all transfers between registered VASPs. Amidst AML controls, ove...
Coinbase Unveils AiFi After $100M in x402 Transactions, Targeting AI Agent Payments
Key Takeaways: Coinbase has announced the launch of its financial infrastructure initiative, AiFi, centered on the new AI agent ec...
Record user activity and a collapse in whale selling should send XRP soaring, so why is it still pinned at $1?
XRP is back near $1 even as network activity rebounds, whale deposits to Binance collapse, and derivatives exposure builds near re...
Texas refuses to sell as its $10 million Bitcoin bet sinks to $6.6 million
Texas kept its 197,844-share position in BlackRock's iShares Bitcoin Trust (IBIT) unchanged during the second quarter even as the...