Hacker News new | ask | show | jobs
by biggerfisch 3612 days ago
Has it been verified that BitGo's key was not simply compromised? As unlikely as it may be that both online keys could be compromised, it certainly seems that it could have happened (perhaps while it was not internal to bitfinex, it could have been internal to BitGo?)
2 comments

>Who is to blame for this hack, finex, bitgo, users? >>>We're still investigating the hack to figure out exactly how we were compromised, but it does look like it's on us.

Source: https://www.reddit.com/r/Bitcoin/comments/4vtuxo/bitfinex_se...

If BitGo was compromised, 1 of the 2 remaining keys still must be used to sign the transaction. BitGo has no access without either of the 2 keys that Bitfinex controls.
Sorry, wasn't clear. I assumed it was obvious that bitfinex's online key was also compromised, no matter what happened with BitGo, whether their key(s) were stolen or if their api was abused.