OAK — OnChain Attack Knowledge

Worked example · 2018-02

BitGrail exchange compromise — Nano (XRB / NANO) — 2017-10 to 2018-02-08 (disclosure)

Loss
approximately 17,000,000 XRB / NANO (~$170M USD at the at-time NANO peak of early February 2018; far less at later prices, but the at-time figure is the load-bearing one for the OAK record because it is the figure on which Italian civil and criminal proceedings rest). The drain was not a single concentrated event; per the Florence Court of First Instance's 2019-01-22 decree (the BitGrail bankruptcy / "fallimento" decree) and the subsequent civil-court findings, the operator-side records show a sustained drain across late-2017 through early-February-2018, with the public disclosure on 2018-02-08 occurring after the cumulative gap was no longer concealable through internal-accounting deflection.
Recovery
structurally unique on the public record. (1) Civil track: Florence Court of First Instance ruled on 2019-01-21 / 2019-01-22 that BitGrail operator Francesco "The Bomber" Firano was personally liable for restoring the missing balances to BitGrail customers — the case is one of the earliest European-court precedents for personal-liability of an exchange operator for customer cryptocurrency losses. (2) Bankruptcy track: Florence Court declared BitGrail S.r.l. bankrupt 2019-01-22; the bankruptcy proceedings ran from 2019 through 2024 with court-supervised distributions to verified creditors, and the proceedings continued past the OAK v0.1 cutoff. (3) Criminal track: Italian criminal proceedings (Guardia di Finanza, Florence Public Prosecutor's Office) on charges including computer fraud (frode informatica), bankruptcy fraud (bancarotta fraudolenta), and money-laundering (riciclaggio); criminal proceedings continuing across 2018–2024+.
OAK Techniques observed
OAK-T11 broadly construed (custody-side compromise) with a suspected operator-complicity / insider dimension that distinguishes the case from the canonical 2017–2018 G01 cohort. The proximate technical mechanism per public-record analysis was sustained drain of BitGrail's hot wallet balances driven by a Nano-protocol-specific re-push / replay condition (the so-called "NANO re-push exploit") in which BitGrail's internal balance-tracking failed to reconcile correctly against the on-chain ledger across re-pushed transactions. Adjacent: OAK-T5.002 (slow-and-low extraction) framing for the multi-month sustained-drain shape.
Attribution
confirmed by Florence civil court (operator personal liability of Francesco Firano, 2019-01-21) — distinct from the OAK-G01 / Lazarus-cluster cases of the same era. The criminal-track proceedings were continuing past the OAK v0.1 cutoff and have not produced a final criminal disposition naming any external attacker.
Key teaching point
the BitGrail case is the OAK record's canonical illustration of how a protocol-specific reconciliation gap (a Nano-protocol-specific re-push / replay condition where exchange-side balance accounting failed to reconcile against the on-chain ledger across re-pushed transactions) becomes an exchange-scale loss when combined with absent-or-compromised operator-side detection. The case is also the canonical illustration of the operator-complicity attribution-axis surface — distinct from the external-attacker / G01-cluster cases of the same era — where a sustained drain produces a court finding of operator personal liability rather than an external-attacker indictment.

Summary

BitGrail S.r.l. was an Italian cryptocurrency exchange headquartered in Florence, operated by Francesco Firano (publicly known as "The Bomber"), and was the dominant trading venue for Nano (originally RaiBlocks, ticker XRB; rebranded to NANO in late January 2018) in the run-up to NANO's late-2017 / early-2018 price run. On 2018-02-08 BitGrail publicly disclosed a loss of approximately 17 million NANO from its hot-wallet balances — a balance approximately equal to BitGrail's total NANO customer-deposit obligations at the time, valued at ~$170M USD at the at-time NANO peak. BitGrail simultaneously announced trading suspension and engaged Italian law enforcement (Guardia di Finanza), opening the civil and criminal proceedings that would run across the next six-plus years.

The case is operationally distinctive along three axes that distinguish it from the canonical 2017–2018 OAK-G01 cohort. First, the proximate technical mechanism was not a generic hot-wallet key compromise but a Nano-protocol-specific reconciliation gap — the so-called "re-push" / replay condition — in which BitGrail's internal balance-tracking failed to reconcile correctly against the on-chain Nano ledger across re-pushed transactions, allowing repeated debits against single on-chain deposit credits. Whether this gap was discovered-and-exploited by an external party using the BitGrail withdrawal API, exploited-and-concealed by the operator over an extended window, or some combination of the two, has been the central contested question across the civil and criminal proceedings.

Second, the attribution surface is the operator-complicity surface rather than the external-attacker surface. The Florence Court of First Instance's 2019-01-21 / 2019-01-22 ruling found Francesco Firano personally liable for restoring the missing balances to BitGrail customers — one of the earliest European-court precedents for personal liability of an exchange operator for customer cryptocurrency losses. Italian criminal proceedings on charges including computer fraud, bankruptcy fraud, and money-laundering were continuing past the OAK v0.1 cutoff. The case sits cleanly outside the OAK-G01 cohort and is the canonical OAK-record illustration of the operator-complicity attribution-axis position for the 2017–2018 era.

Third, the recovery shape is multi-track and protracted. Civil-court personal-liability ruling against the operator (2019-01-21); bankruptcy declaration against the operating entity (2019-01-22) with court-supervised distributions across multi-year proceedings; criminal proceedings on multiple charges continuing across 2018–2024+. No other case in the OAK examples set has this exact multi-track recovery shape, and contributors writing future operator-complicity-attributed worked examples should treat BitGrail as the canonical reference for what the multi-track recovery shape produces when operator personal liability is on the public-record table.

Timeline (UTC unless noted)

When Event OAK ref
2014-12 BitGrail S.r.l. founded; Francesco Firano begins operating the exchange. Florence-based; Italian-jurisdiction operating entity. (pre-event)
2017-Q3–Q4 NANO (then XRB / RaiBlocks) appreciates substantially in price; BitGrail emerges as the dominant trading venue for the asset, with NANO trading volume on BitGrail exceeding all other venues combined for extended periods. (pre-event — operational scale-up)
2017-10 (estimated, per operator-side records cited in Florence Court proceedings) Sustained drain of NANO hot-wallet balances begins. Per the Florence Court's 2019-01-21 / 2019-01-22 decree and subsequent civil-court findings, the operator-side records show a drain across late-2017 through early-February-2018; the proximate technical mechanism per public-record analysis is a Nano-protocol-specific re-push / replay condition in which BitGrail's internal balance-tracking failed to reconcile correctly against the on-chain ledger across re-pushed transactions. T11 entry — sustained drain via protocol-specific reconciliation gap
2017-10 → 2018-02-07 Sustained drain continues across approximately 4 months; cumulative gap reaches ~17M NANO. Whether the gap was concealed by internal-accounting deflection, simply not detected by operator-side controls, or actively exploited by the operator has been contested across civil and criminal proceedings. Sustained extraction across multi-month window
2018-01-31 RaiBlocks rebrands to Nano (NANO ticker); BitGrail trading volume continues at high levels through the rebrand window. (asset-side context)
2018-02-08 BitGrail publicly discloses a loss of 17M NANO ($170M USD at the at-time NANO peak). Trading suspension announced. Italian law enforcement (Guardia di Finanza) engaged. Operator disclosure
2018-02-09 onward Public dispute between Francesco Firano and the Nano core team over responsibility for the loss; Nano core team publicly states that the protocol itself was not exploited and that the proximate mechanism was an exchange-side reconciliation gap, not a Nano-protocol-level vulnerability. (operator-vs-protocol attribution dispute)
2018-Q1–Q2 Italian Guardia di Finanza criminal investigation continues; Florence Public Prosecutor's Office opens criminal proceedings on charges including computer fraud (frode informatica), bankruptcy fraud (bancarotta fraudolenta), and money-laundering (riciclaggio). (criminal-track engagement)
2018-Q2–Q4 Civil claims by BitGrail customers consolidate in Florence courts; class-action-style proceedings on operator personal liability advance. (civil-track engagement)
2019-01-21 Florence Court of First Instance rules Francesco Firano personally liable for restoring the missing balances to BitGrail customers. One of the earliest European-court precedents for personal liability of an exchange operator for customer cryptocurrency losses. Civil-track personal-liability ruling — confirmed-by-court
2019-01-22 Florence Court declares BitGrail S.r.l. bankrupt ("fallimento"); bankruptcy proceedings initiated with court-appointed trustee. Bankruptcy declared
2019 → 2024 Bankruptcy proceedings continue with court-supervised verification of creditor claims and partial distributions; proceedings continuing past the OAK v0.1 cutoff. Italian criminal proceedings on computer fraud, bankruptcy fraud, and money-laundering charges continue in parallel. Recovery — multi-year, court-supervised, partial

What defenders observed and learned

  • Pre-event: the load-bearing failure was that BitGrail's internal balance-tracking did not reconcile correctly against the on-chain Nano ledger across re-pushed transactions, allowing repeated debits against single on-chain deposit credits across an extended window. A defender writing an exchange-custody runbook should treat protocol-specific reconciliation gaps between exchange-side internal accounting and the on-chain ledger as a primary control surface to verify, particularly for assets with non-traditional transaction-confirmation semantics (Nano's block-lattice with re-pushed-transaction handling is a paradigmatic example). The post-2020 industry baseline of continuous cryptographic-balance reconciliation between hot-wallet on-chain state and exchange-side internal accounting — verified at minutes-scale rather than at end-of-day batch granularity — is retro-engineered against precisely this failure shape.
  • At-event (detection): detection occurred only when the cumulative gap was no longer concealable through internal-accounting deflection — meaning across approximately 4 months. There is no public-record indication that any continuous-reconciliation control was operational at BitGrail; the detection signal that ultimately fired was the operator's inability to honour customer NANO withdrawal requests at scale. The defender lesson is the same one Cryptopia 2019 illustrates from a different angle: aggregate-balance-decay anomaly detection across the population of monitored hot-wallet addresses, rather than per-transaction anomaly detection on individual withdrawals, is the load-bearing detection layer for sustained-drain extractions, and the same applies even when the proximate mechanism is a protocol-specific reconciliation gap rather than an external-attacker-driven authorised withdrawal.
  • At-event (operator complicity): the question of whether the drain was external-attacker-driven, operator-driven, or some combination of the two is the case's central contested question, and the OAK record should not pretend it has been resolved. The Florence Court of First Instance found Francesco Firano personally liable on civil grounds (2019-01-21); criminal proceedings on multiple charges including computer fraud and bankruptcy fraud were continuing past the OAK v0.1 cutoff. Defenders writing operator-accountability or law-enforcement-cooperation analyses should treat this case as the canonical illustration of the operator-complicity attribution-axis surface for the 2017–2018 era, and should preserve the confirmed-by-court (civil personal-liability) + suspected (criminal track ongoing) notation rather than over-claiming a final criminal disposition.
  • Post-event (recovery — multi-track): the case produced one of the earliest European-court precedents for personal liability of an exchange operator for customer cryptocurrency losses (Florence Court 2019-01-21), one of the earliest Italian-jurisdiction bankruptcy proceedings against a cryptocurrency-exchange operating entity (Florence Court 2019-01-22), and continuing criminal proceedings on multiple charges across the multi-year window. Defenders writing jurisdiction-of-incorporation analyses for exchanges, custodians, or DAO treasuries should treat the Italian precedent as a real and case-tested option for ensuring operator personal liability through civil and criminal proceedings, alongside the New Zealand precedent (Ruscoe v Cryptopia 2020) for property-status of customer cryptocurrency holdings in insolvency.

What this example tells contributors writing future Technique pages

  • BitGrail 2018 is the canonical OAK-record illustration of the operator-complicity attribution-axis surface for the 2017–2018 era. Most 2017–2018 exchange-hack worked examples in the OAK corpus document external-attacker-driven losses with attribution surfaces in the inferred-strong (NiceHash 2017, Coincheck 2018, Bithumb 2017/2018, Coinrail 2018, Zaif 2018, Upbit 2019) or confirmed (Bitfinex 2016 → 2022 disposition) ranges. BitGrail 2018 documents an exchange-scale loss where the proximate operator-complicity question is on the public-record table and was the subject of a civil-court personal-liability ruling. Contributors writing future operator-accountability worked examples or attribution-axis material should preserve the confirmed-by-court (civil personal-liability) + suspected (criminal ongoing) notation as a distinct attribution-strength position, not collapsible to either external-attacker confirmed or pseudonymous-unattributed.
  • Protocol-specific reconciliation gaps deserve their own M-axis treatment. The Nano re-push / replay condition that BitGrail failed to handle is not a Nano-protocol-level vulnerability; it is an exchange-side reconciliation gap. But the broader pattern — exchange-side internal accounting failing to reconcile correctly against the on-chain ledger across protocol-specific transaction semantics that the exchange's stack was not designed for — is a general technique-and-mitigation surface that recurs across OAK incidents involving non-traditional protocol transaction-confirmation semantics. Contributors writing M-axis pages should treat continuous cryptographic-balance reconciliation between exchange-side internal accounting and the on-chain ledger, verified at minutes-scale and protocol-aware as a distinct mitigation class, with BitGrail 2018 as the canonical reference for the 2017–2018 era.
  • The Italian-court precedent on operator personal liability deserves its own line in any jurisdiction-comparison material. The Florence Court 2019-01-21 ruling is one of the earliest European-court precedents for personal liability of an exchange operator for customer cryptocurrency losses; contributors writing jurisdiction-comparison pages or recovery-mechanism pages should reference it as the Italian pillar of the case-tested precedent set (alongside Mt. Gox / Japan civil-rehabilitation, Cryptopia / New Zealand property-status, FTX / Delaware Chapter 11, and other jurisdiction-specific precedents).
  • confirmed-by-court (civil) is a distinct attribution-strength notation that deserves preservation in OAK convention. OAK's attribution-strength axis — confirmed, inferred-strong, inferred, suspected, pseudonymous-unattributed — should accommodate cases where the public-record attribution is a civil-court finding of operator personal liability rather than a criminal indictment. BitGrail 2018 is the cleanest available reference for this position; contributors writing future attribution-axis material should preserve the notation rather than collapsing it to either confirmed (which implies criminal disposition) or inferred-strong (which understates the load-bearing court finding).

Public references

  • [bitgrailpress2018] — BitGrail S.r.l. / Francesco Firano. Public statement on the 2018-02-08 incident and trading suspension. 2018-02-08 onward; primary-source operator disclosure across the breach response window.
  • [nanoteamresponse2018] — Nano Foundation / Nano core team. Public response to BitGrail 2018-02 disclosure. 2018-02; primary-source asset-team statement that the proximate mechanism was an exchange-side reconciliation gap, not a Nano-protocol-level vulnerability.
  • [florencecourtbitgrail2019civil] — Tribunale di Firenze [Florence Court of First Instance]. Civil ruling on Francesco Firano personal liability, BitGrail S.r.l. customer claims. 2019-01-21; Italian-court civil judgment finding the operator personally liable for restoring the missing balances to customers.
  • [florencecourtbitgrail2019fallimento] — Tribunale di Firenze [Florence Court of First Instance]. Decreto di fallimento BitGrail S.r.l. 2019-01-22; Italian-court bankruptcy declaration against the operating entity.
  • [guardiafinanzabitgrail2018] — Guardia di Finanza / Procura della Repubblica di Firenze. Criminal investigation, BitGrail / Francesco Firano on charges including computer fraud, bankruptcy fraud, and money-laundering. 2018 onward; primary-source Italian criminal-track engagement.
  • [coindeskbitgrail2018] — CoinDesk. BitGrail Says $170 Million in Nano Cryptocurrency Lost in Hack. 2018-02; contemporaneous press coverage of the breach disclosure.
  • [coindeskbitgrail2019liability] — CoinDesk. Italian Court Rules BitGrail Founder Liable for $170M Crypto Hack. 2019-01; press coverage of the Florence civil-court personal-liability ruling.
  • [reutersbitgrail2018] — Reuters. Italian crypto exchange BitGrail says it lost $170 million in Nano cryptocurrency. 2018-02; contemporaneous press coverage of the breach disclosure.
  • [ellipticnano2018] — Elliptic / industry-forensic analysis of the BitGrail laundering cluster and the proximate mechanism (Nano re-push / replay reconciliation gap); cross-reference for the on-chain forensic surface.

Discussion

BitGrail 2018 is the OAK record's canonical illustration of the operator-complicity attribution-axis surface for the 2017–2018 era. The case is structurally distinct from the canonical 2017–2018 G01 cohort along the attribution axis — Florence civil-court personal-liability ruling against the operator (2019-01-21), Italian bankruptcy declaration against the operating entity (2019-01-22), continuing criminal proceedings on multiple charges across 2018–2024+ — and contributors writing operator-accountability or attribution-axis material should preserve the confirmed-by-court (civil personal-liability) + suspected (criminal ongoing) notation as a distinct attribution-strength position.

The proximate technical mechanism deserves to be flagged carefully. The "NANO re-push exploit" framing is widely-used in contemporaneous press coverage but is misleading if it implies a Nano-protocol-level vulnerability; the Nano core team's public position (corroborated by subsequent independent analysis) is that the protocol was not exploited and that the proximate mechanism was an exchange-side reconciliation gap in BitGrail's internal balance-tracking against the on-chain Nano ledger across re-pushed transactions. Contributors writing the case should preserve this distinction: the case is an exchange-side reconciliation-gap failure exploited (or self-exploited, depending on the criminal-track outcome) across an extended window, not a Nano-protocol-level vulnerability. The mitigation lesson is exchange-side — continuous cryptographic-balance reconciliation between exchange-internal accounting and the on-chain ledger, verified at minutes-scale and protocol-aware — rather than Nano-protocol-side.

The Italian-court precedent on operator personal liability is the single most structurally significant outcome of the case for OAK's jurisdiction-comparison material. The Florence Court 2019-01-21 ruling — finding Francesco Firano personally liable for restoring the missing balances to BitGrail customers — is one of the earliest European-court precedents for personal liability of an exchange operator for customer cryptocurrency losses, and the case is the cleanest available reference for the Italian pillar of the case-tested precedent set on operator-accountability through civil proceedings. Defenders writing jurisdiction-of-incorporation analyses for exchanges, custodians, or DAO treasuries should treat the Italian precedent as a real and case-tested option, alongside the Japanese, New Zealand, and US-Delaware precedents on adjacent recovery-mechanism axes.

Finally, the multi-track recovery shape — civil personal-liability ruling, bankruptcy declaration, criminal proceedings — is unusual on the OAK record at the 2018-era loss magnitude and worth preserving as the canonical reference for what the operator-complicity attribution-axis surface produces when it runs through Italian-jurisdiction civil and criminal courts in parallel. No other v0.1 worked example has this exact multi-track recovery shape; contributors writing future operator-complicity-attributed worked examples should treat BitGrail as the load-bearing reference.

Techniques demonstrated (2)