Worked example · 2013-10
Inputs.io web-wallet hack — Bitcoin — 2013-10
Summary
Inputs.io operated as a Bitcoin web-wallet service from approximately mid-2013, allowing users to deposit Bitcoin into wallets controlled by the platform. The service was operated by a pseudonymous individual under the online handle "TradeFortress," who had built a reputation in the Bitcoin Talk forum community as a developer of Bitcoin-related services and as the operator of an associated Bitcoin dice-game site.
In late October 2013, an attacker gained access to Inputs.io's hosting infrastructure and compromised the server environment where the platform's Bitcoin wallet private keys were stored. The attacker drained approximately 4,100 BTC — representing nearly the entirety of user deposits held by the platform — to attacker-controlled Bitcoin addresses. The operator "TradeFortress" publicly disclosed the breach on Bitcoin Talk and through community channels, acknowledging that the hosting-infrastructure compromise had enabled the attacker to access the wallet's private-key material and drain the balances. The operator stated that no user funds remained and that the platform would not be able to reimburse affected users.
The Inputs.io case is significant as the earliest cleanly-documented instance of the wallet-service compromise class where both the operator and the attacker were pseudonymous, the loss was total (no funds remained in the operator's control), and the attack vector was a hosting-infrastructure compromise rather than a social-engineering or phishing entry. The structural shape — pseudonymous operator, total-loss hosting-compromise, no reimbursement, no law-enforcement disposition — recurs across multiple subsequent wallet-service compromise incidents in the 2013-2017 record and is the canonical early-instance reference for the T11.001 + T15.003 chain in the web-wallet context.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2013 mid | Inputs.io launches as a Bitcoin web-wallet service operated by pseudonymous "TradeFortress" | (platform stand-up) |
| 2013-07 to 2013-10 | Users deposit ~4,100 BTC into Inputs.io platform-controlled wallets | T11.001 (wallet-service custody accumulation) |
| 2013-10-23 to 2013-10-25 | Attacker compromises Inputs.io hosting infrastructure; gains access to server environment storing wallet private keys | T15.003 (operator infrastructure compromise) |
| 2013-10-25 to 2013-10-26 | Attacker drains ~4,100 BTC from Inputs.io wallets to attacker-controlled addresses | T11.001 (wallet-service signing-infrastructure compromise) |
| 2013-10-26 to 2013-10-28 | "TradeFortress" publicly discloses the breach on Bitcoin Talk; states no user funds remain and no reimbursement will be possible | (operator disclosure) |
| Post-2013-10 | No material on-chain recovery; no law-enforcement disposition; attacker and operator both remain pseudonymous | (outcome) |
Realised extraction
Approximately 4,100 BTC (~$530K-$820K at 2013-10 prices). No material on-chain recovery; no user reimbursement; no law-enforcement seizure.
Public references
- "TradeFortress" Bitcoin Talk forum disclosure thread (October 2013) — primary-source operator disclosure of the Inputs.io compromise
[coindeskinputsio2013]— CoinDesk. Inputs.io Hacked: 4,100 BTC Stolen from Bitcoin Web Wallet Service. October 2013; contemporaneous English-language press coverage- Bitcoin Talk forum community discussion threads on the Inputs.io compromise and the operator's post-breach statements (October-November 2013)
[githubinputsio2013]— TradeFortress GitHub repository and Inputs.io operational-archive materials (2013)