OAK — OnChain Attack Knowledge

Worked example · 2014-03

Flexcoin Bitcoin bank closure after hot-wallet hack — Bitcoin — 2014-03-02 to 2014-03-04

Loss
896 BTC stolen from Flexcoin's hot wallet. At the March 2014 Bitcoin price of approximately $600–$650/BTC, the loss equated to approximately $550,000–$600,000. All customer funds stored in the hot wallet were drained; cold-storage funds were reportedly unaffected but were not distributed to customers. Flexcoin closed permanently on March 4, 2014.
Recovery
zero on-chain recovery. Flexcoin's terms of service stated the operator was not responsible for losses, and the operator closed the platform rather than attempting to make customers whole. No law-enforcement recovery action was ever publicly disclosed.
OAK Techniques observed
OAK-T11.001 (Third-Party Signing-Vendor Compromise — broadly construed; Flexcoin operated as a custodial "Bitcoin bank" where customer funds were held in operator-controlled hot wallets. The hot-wallet compromise drained customer-deposited funds. The structural shape is exchange-custody compromise: operator-controlled wallet drained by external attacker, customer funds lost, operator closed without making customers whole). OAK-T6.007 (Trust-Substrate Shift / Vendor-Promise Revocation — Flexcoin's permanent closure on March 4, 2014, with the statement "Flexcoin has been hacked and all funds have been stolen," revoked the trust-substrate claim that the Bitcoin bank was a safe custody destination. The closure-without-reimbursement pattern established the "Bitcoin bank closes after hack, customers bear the loss" template that would recur at Cryptsy (2014), MintPal (2014), and later custodial failures). OAK-T15.003 (Operator Endpoint/Infrastructure Compromise — the technical entry vector was the compromise of Flexcoin's hot-wallet server infrastructure).
Attribution
unattributed for the technical compromise. The attacker(s) who drained the Flexcoin hot wallet have never been publicly identified. No law-enforcement disposition names any individual or group in connection with the Flexcoin hack.
Key teaching point
Flexcoin is the earliest documented case of a "Bitcoin bank" permanently closing after a hack, with customers bearing the full loss — the canonical pre-2015 anchor for the "custody-compromise → operator-closes → customers-bear-loss" failure pattern. The structural shape — hot-wallet compromise drains customer funds, operator invokes terms-of-service disclaimers, operator permanently closes, customers receive no recovery — recurred across the 2013-2016 altcoin exchange cohort (Cryptsy, MintPal, BTER) and established the pre-regulatory-era template that modern exchange licensing, proof-of-reserves, and mandatory capital-reserve frameworks were retro-engineered against.

Summary

Flexcoin was a small, early Bitcoin "bank" that launched in 2011 and operated a custodial wallet service where users could deposit Bitcoin for safekeeping. The service branded itself as a "Bitcoin bank" — a predecessor to the custodial-wallet and centralized-exchange custody models that would dominate later years. Flexcoin stored customer deposits in two wallet tiers: a hot wallet for day-to-day withdrawals (connected to the internet) and a cold-storage wallet for long-term holdings (offline).

On March 2, 2014, an attacker compromised Flexcoin's hot-wallet server and drained 896 BTC — all funds stored in the hot wallet — to an attacker-controlled address. Flexcoin's operator detected the breach, disabled deposits and withdrawals, and posted a notice on the Flexcoin website on March 3-4, 2014: "Flexcoin has been hacked and all funds have been stolen." The operator stated that cold-storage funds were unaffected but did not distribute them to affected hot-wallet customers. Flexcoin closed permanently on March 4, 2014.

The operator's response — "we were hacked, we're closing, terms of service say we're not responsible" — was widely criticized in the Bitcoin community at the time as an abdication of custodial responsibility. The incident became the canonical example of "why you shouldn't store your Bitcoin with an unregulated, uninsured Bitcoin bank." The structural failure pattern — unregulated custodian with no capital reserves, no insurance, and terms-of-service disclaimers absorbs a hot-wallet compromise and passes the full loss to customers — directly motivated the post-2014 push for exchange licensing, mandatory proof-of-reserves, and capital-reserve requirements.

Timeline (UTC unless noted)

When Event OAK ref
2011–2014 Flexcoin operates as a custodial "Bitcoin bank" with hot-wallet and cold-storage tiers; customer funds stored in operator-controlled wallets (standing T11.001 surface)
2014-03-02 Attacker compromises Flexcoin hot-wallet server; 896 BTC drained from hot wallet to attacker-controlled address T11.001 (custody compromise) + T15.003 (endpoint compromise)
2014-03-03 Flexcoin operator detects breach; disables deposits and withdrawals (incident response — containment)
2014-03-04 Flexcoin posts closure notice: "Flexcoin has been hacked and all funds have been stolen"; platform closes permanently T6.007 (trust-substrate shift — platform-permanent-closure)
2014-03 onward Affected customers receive no recovery; cold-storage funds reportedly not distributed; no law-enforcement action publicly disclosed (recovery — failed; no law-enforcement disposition)

Realised extraction

Full loss of hot-wallet funds (896 BTC, ~$550K–$600K at March 2014 prices). All customers with funds in the hot wallet lost their deposits. Cold-storage funds were reportedly unaffected by the hack but were not distributed to offset hot-wallet customer losses. No recovery has ever been realized. The attacker(s) remain unidentified.

What defenders observed

  • Pre-event: Flexcoin operated as an unregulated, uninsured custodial service — a "Bitcoin bank" with no banking license, no capital reserves, and terms of service that explicitly disclaimed responsibility for losses. The OAK lesson is that "unregulated custodian with no-loss-responsibility terms of service" was the dominant pre-2015 custodial model for Bitcoin services, and the Flexcoin closure is the canonical illustration of why this model failed customers.
  • At-event: the hot-wallet compromise drained 896 BTC — a relatively small amount compared to later exchange hacks, but sufficient to permanently close the platform. The attacker's entry vector (server compromise) was never publicly detailed. The OAK lesson is that a small unregulated custodian with no capital reserves has zero loss-absorption capacity — any hot-wallet compromise that exceeds the operator's personal assets is a platform-ending event.
  • Post-event: the operator's decision to close permanently rather than attempt to reimburse customers from cold-storage funds or personal assets established the "operator closes, customers bear loss" template. The OAK lesson is that unregulated custodians have a structural incentive to close after a compromise rather than to attempt remediation — the remediation path costs the operator money; the closure path costs the operator nothing (protected by terms-of-service disclaimers).
  • Post-event (paradigm): the Flexcoin closure, combined with the Mt. Gox collapse (February 2014, one month earlier), created a concentrated Q1 2014 custodial-crisis window that permanently transformed the Bitcoin community's attitude toward unregulated custodians. The "Mt. Gox + Flexcoin" two-month window — February-March 2014 — established the dual failure templates (exchange-scale insolvency and small-custodian hot-wallet-compromise closure) that motivated the post-2014 push for exchange licensing, proof-of-reserves, and insurance.

What this example tells contributors writing future Technique pages

  • Flexcoin is the canonical small-custodian anchor for T11.001. While Mt. Gox is the exchange-scale anchor, Flexcoin is the small-custodian-scale anchor — the case that established that unregulated custodians of any size face the same structural failure shape (compromise → insolvency → closure → customer-loss) and that smaller custodians are actually more fragile because they lack any loss-absorption capacity.
  • The Q1 2014 custodial-crisis window is a concentrated historical-reference window. Mt. Gox (February 2014) + Flexcoin (March 2014) created a two-month window that established both exchange-scale and small-custodian-scale custodial-failure templates. Contributors writing historical-reference sections on custodial-failure evolution should treat the two incidents as paired anchors for the pre-regulatory era.
  • Terms-of-service disclaimers as a risk indicator is a standing defender lesson. Flexcoin's terms of service — "we are not responsible for losses" — was the structural warning that customers lacked legal recourse in the event of a compromise. The OAK lesson is that terms-of-service disclaimers of custodial responsibility are a first-order risk indicator for any custodial service. This lesson recurs across the 2014-2016 exchange cohort and remains relevant through the OAK v0.1 cutoff.

Public references

  • [flexcoinclosure2014] — Flexcoin. "Flexcoin has been hacked and all funds have been stolen." Flexcoin website closure notice, March 4, 2014. Primary-source operator disclosure (website now defunct; archived via BitcoinTalk and contemporaneous press coverage).
  • [coindeskflexcoin2014] — CoinDesk. "Bitcoin Bank Flexcoin Closes After Hack, Customers Lose Everything." March 4, 2014. Contemporaneous press coverage of the closure.
  • [bitcointalkflexcoin2014] — BitcoinTalk forum. Flexcoin closure discussion threads, March 2014. Contemporaneous community response and victim reports.
  • [forbesflexcoin2014] — Forbes. "Bitcoin Bank Flexcoin Shuts Down After Theft." March 2014. Mainstream financial press coverage of the incident.

Discussion

Flexcoin March 2014 is the canonical small-custodian anchor in the OAK record for the "custody-compromise → operator-closes → customers-bear-loss" failure pattern. The case is structurally paired with Mt. Gox (February 2014, one month earlier) as the dual-exchange-scale-and-small-custodian-scale anchors that established the pre-regulatory-era custodial-failure template. The Q1 2014 concentrated custodial-crisis window permanently transformed the Bitcoin community's attitude toward unregulated custodians and motivated the post-2014 push for exchange licensing, proof-of-reserves, and insurance — structural reforms that were retro-engineered against precisely the Mt. Gox + Flexcoin failure shapes.

The case is small in dollar terms compared to later custodial failures (Mt. Gox ~$450M, Cryptsy ~$5M+, QuadrigaCX ~$190M, FTX ~$8B), but its structural value to the OAK corpus is as the small-custodian-scale anchor — the case that established that unregulated small custodians are actually more fragile than large ones because they lack any loss-absorption capacity. The operator's terms-of-service disclaimer ("we are not responsible for losses") was the structural warning sign that modern exchange-due-diligence practices (checking for regulatory licensing, proof-of-reserves, insurance, and loss-reimbursement track records) were retro-engineered to detect.

Techniques demonstrated (3)