CustodyStress
Archive › Documentation absent
Part of the CustodyStress archive of observed Bitcoin custody incidents
CS-00295

Neither Bitfinex nor BitGo published a full forensic report.

Constrained
Case description
The Bitfinex post-hack investigation never produced a definitive public account of how the attacker obtained Bitfinex's co-signing key or circumvented BitGo's transaction-level security policies. Bitfinex stated that BitGo's API had been called legitimately by the attacker using valid credentials. Neither Bitfinex nor BitGo published a full forensic report. The mechanism remained officially unexplained as of the end of 2016.
Custody context
Stress conditionDocumentation absent
Custody systemExchange custody
OutcomeConstrained
DocumentationUnknown
Year observed2016
CountryHong Kong
Structural dependencies observed
Undocumented procedure
What this illustrates
Nobody had written down how to get back in. That knowledge existed only in the owner's head. Whether full access was ultimately possible is unclear, but significant delay or outside intervention was involved.
Outcome interpretation
Access remained possible, but only with delay, dependence, or significant difficulty.
Source
Publicly Reported
Evidence type
News article
Related cases involving documentation absent
193 cases involve documentation absent 512 cases involve exchange custody View archive statistics →
This archive documents observed custody survivability failures. It does not attempt to document all Bitcoin losses or security incidents. Submit a case
← All cases
Framework references
Terms guide
Survives
Access remained possible under the reported conditions.
Constrained
Access remained possible, but only with delay, dependence, or significant difficulty.
Blocked
Access was not possible under the reported conditions.
Indeterminate
There was not enough information to determine the outcome.
Single-person knowledge
Recovery depended on information or capability held by one individual who was unavailable.
Institutional dependence
Recovery depended on a third-party institution or service that was inaccessible or uncooperative.
Documentation gap
Recovery depended on instructions that were missing, incomplete, or unclear.
Authority mismatch
The person with legal authority to act did not have operational access, or vice versa.
Original text
Rate this translation
Your feedback will be used to help improve Google Translate