Skip to content

Instantly share code, notes, and snippets.

@magoo
Last active March 4, 2021 00:43
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save magoo/b64ecad5348767ac4195dabefa394a81 to your computer and use it in GitHub Desktop.
Save magoo/b64ecad5348767ac4195dabefa394a81 to your computer and use it in GitHub Desktop.
Bitpoint breach translation.
This is a Google Translation of the BitPoint PDF related to their breach.
https://contents.xj-storage.jp/xcontents/AS08938/8a8b8ec7/f5b1/445e/a543/eade0775d325/140120190716472191.pdf
Page 1
1July 16, 2019To everyonecompany nameRemixpoint Co., Ltd.Representative's namePresident and CEOGenki Oda(Code number: 3825)contact informationDirector CFOTakuya Hirose(TEL: 03-6303-0280)(Progress of disclosure items) Regarding illegal outflow of virtual currency at our subsidiaryNotice and apology (third report)BitPoint Japan Co., Ltd. (Headquarters: Minato-ku, Tokyo, Representative Director), which operates a virtual currency exchange business at our subsidiaryGenki Oda, hereinafter referred to as "BPJ". ), Dated July 12, 2019, "Cryptocurrency failure at our subsidiaryBPJ's virtual currency exchange as described in "Notice and Apology for Positive Outflow (First Report)" (hereinafter referred to as "First Report")Unauthorized outflow of virtual currency at the exchange (hereinafter referred to as "this case") has been revealed. Virtual communication in this caseRegarding the status of the investigation of the outflow amount of currency, the virtual currency deposited by customers, business continuity, etc., on July 14, 2019, "(Open)(Progress of indications) Notice and apology regarding the illegal outflow of virtual currency at our subsidiary (second report) "(hereinafter referred to as" the firstIt is called "two reports". ).On July 12, 2019, BPJ requested a report from the Financial Services Agency based on Article 63-15, Paragraph 1 of the Law Concerning Settlement of Funds.Since we received the decree, we told the Financial Services Agency today that the facts and damages related to this case and the spread of damages should be prevented.Up to now, we have found out about the measures to be taken, the work schedule, and the measures to be taken regarding the assets deposited by the customer.I reported the contents of the decision.We would like to inform you about the outline of the above report and future response policy as follows.1. 1. Facts and damages related to this case(1) Facts and background of response (outline)The details of the response from the occurrence and discovery of this incident to July 15, 2019 (Monday) are as follows. In addition, the bookThe case was also due to the theft and unauthorized use of the private key of the hot wallet managed by BPJ's wallet server.However, we are still investigating the cause and route.BPJ will hold a countermeasures meeting from 3:00 on July 12th with external experts including legal counsel.In addition, we have reported to the Board of Directors of the Company regarding this matter.In addition, there was some error in the time series in the content described in "2. Background" of the first report. I will correct itWe apologize for the inconvenience.Around 21:11 on July 11th, BPJ's monitoring system automatically detected a remittance error related to Ripple.Around 21:12, the BPJ Information Systems Department confirmed the alert regarding the above error and investigated it.And started support.At around 21:45, BPJ determined that an illegal outflow of Ripple had occurred and started responding.At around 22:39, BPJ started investigating whether there was an outflow of virtual currencies other than Ripple.At around 22:45, at BPJ, stealing the private key of BPJ's hot wallet, and after RippleJudging that there is a possibility of illegal outflow of external virtual currencies, hot woStarted to move virtual currency from let to cold wallet.
Page 2
2July 123:00An emergency response meeting was held by executive officers and employees at BPJ.Around 4:50 BPJ can illegally leak virtual currency from BPJ's cold walletMake sure it's low, and keep your balance in your cold wallet on a regular basisStart checking.6:30Suspension of virtual currency transfer service at BPJ.Around 7:30 At the BPJ countermeasures meeting, all services including opening a new account will be suspended.Decision.Around 10:26 Regarding the suspension of all services including virtual currency transactions and virtual currency remittancesThe news is posted on the BPJ homepage and BPJ trading site.10:30Stopped all services including over-the-counter virtual currency margin service at BPJ.At around 13:05, BPJ will announce the suspension of all services and receive (deposit) virtual currency.Start sending e-mails related to alerts to your e-mail address.13:30We carry out timely disclosure (first report) regarding this case.Information on illegal outflow of virtual currency is posted on the BPJ homepage.Around 15:20 Notice on the BPJ homepage regarding the suspension of acceptance of new applications for opening an accountPublished.15:30BPJ has stopped accepting new applications for opening an account.July 13At around 5:00 BPJ, all kinds of virtual currencies entrusted to customers (bitcoin, bitcoin key)5 brands of Jash, Ethereum, Litecoin, Ripple) and the total amountTherefore, the holding is completed by procuring virtual currency equivalent to the outflow.Around 21:13 BPJ is a general incorporated association of the Japan Cryptocurrency Exchange Association (hereinafter referred to as "JVCEA").Su. ), We request JVCEA members to cooperate in this matter.Request.Around 22:20, the JVCEA secretariat sent an email to JVCEA members regarding the above cooperation.At around 10:00 on July 14, the calculation of the outflow amount of virtual currency in this case was completed at BPJ.19:15We carry out timely disclosure (second report) regarding this case.July 15th 10:00Status report to the Company's outside directors and BPJ Audit & Supervisory Board Members and future response policyDescription.② Status of outflow of virtual currencyThe types, quantities and amounts of virtual currencies leaked in this case are as follows. In addition, cold walletNo illegal outflow has been confirmed for the virtual currency and legal tender managed by the company.Cryptocurrency brandOutflow quantityEvaluation amount (*)home,Customer deposithome,BPJ holdingsBitcoin1,225 BTC153 million yen1.28 billion yen250 million yenBitcoin cash1,985 BCH70 million yen40 million yen20 million yenEthereum11,169 ETH330 million yen240 million yen80 million yenLitecoin5,108 LTC50 million yen40 million yen0.0 billion yenRipple28,106,343 XRP102 million yen440 million yen580 million yentotal3.02 billion yen2.06 billion yen960 million yen(*) The above evaluation value is the daily publication rate of BPJ as of 16:00 on July 11, 2019, which is the date of occurrence of this incident.It is calculated using. In addition, the display unit is rounded down.
Page 3
32. 2. Immediate measures to prevent the spread of damage, etc.We are currently investigating the cause and route of this incident, but BPJ has a virtual currency trading system.Although various security measures were taken against the wallet, the wallet that manages the private key of the hot walletThere is a high possibility that the server has been illegally accessed, and the private key of the hot wallet has been stolen or misused.We believe.Therefore, we have taken the following measures to prevent the spread of damage.① Preventive measures related to wallets・ Transfer of all kinds and all virtual currencies managed by BPJ hot wallet to cold wallet・ Announcement of this incident to users and suspension of all services・ Caution to users not to send virtual currency to BPJ management account・ Transfer of virtual currency sent to BPJ management account to cold walletOn the other hand, no unauthorized outflow from the cold wallet has been confirmed so far, but it ensures the preservation of property.In order to make it, we are monitoring the amount of virtual currency on the cold wallet.② Measures for investigating the cause, etc.At BPJ, with the cooperation of external experts, in order to investigate the cause of this incident and seek a fundamental solution,We are implementing the following measures.・ Investigation and analysis of commercial system logs・ Vulnerability investigation on remote routes, etc.・ Forensic survey of wallet server・ Vulnerability investigation in hot wallet implementation・ Investigation and tracking of fraudulent outflow destinations③ OtherIn order to prevent the spread of damage, with the cooperation of JVCEA, BPJ told JVCEA members as follows.We are requesting cooperation.・ JVCEA that the virtual currency will not be sent to the BPJ management account until the situation is settled.Attention and dissemination to users of each member・ When virtual currency is received from an address that is considered to be an illegal outflow destination, it will be placed in the account.Request for suspension of deposit / withdrawal, trading and other services of virtual currency (account freeze)In addition, BPJ requires various cooperation with the Ripple Foundation and major overseas cryptocurrency exchange operators.We are making a contract.3. 3. Correspondence to customer's assetsAs announced in the second report, at BPJ, all types of virtual currencies deposited by customers (Bitcoin,Bitcoin Cash, Ethereum, Litecoin, Ripple) and the total amount equivalent to the outflowWe already have it by procuring virtual currency.Appropriate as soon as possible, such as refunding upon request, in line with the resumption of services at BPJWe will do our best to accommodate you.
Page 4
Four4. Plan from now onAs mentioned above, BPJ holds the amount equivalent to the outflow for all types and amounts of virtual currency entrusted by customers.However, even considering the damage amount of BPJ related to the illegal outflow due to this case and the cost of countermeasures for the time being, it is still unpredictable.As long as this situation does not occur, we have determined that there will be no problem with the financial condition of BPJ and the Company. Also, BPJRegarding the cash flow of the Group, including the above 3. Approximately 3 billion yen after securing virtual currency equivalent to the outflow ofWe have a balance of cash and deposits, and we judge that there will be no hindrance to business continuity.Continue to investigate the cause of this case, implement measures to prevent the spread of damage, consider and implement measures to prevent recurrence, and view the business management system.Taken by the customer on the premise of making repairs, etc. to ensure the safety of transactions and the protection of the customer's property.We will aim to resume the service as soon as possible in order to secure the opportunity to pull.5. OtherIn addition to the above, as announced in the second report, overseas virtual communication that BPJ provides an exchange systemThe outflow of virtual currency has been confirmed in some of the currency exchanges. The details of the situation are under investigationHowever, it is estimated to be about 250 million yen.We are currently continuing to scrutinize the impact of this case on our consolidated results, and as soon as the details become available, we will continue to scrutinize it.We will inform you as soon as possible.In the Group, including BPJ, from BPJ customers, shareholders of the Company, and other stakeholders.We will strive to restore credit.that's all
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment