The “Stolen” Mt.Gox Data Contained Malware That Robbed Users Of Bitcoin

Security researchers at Securelist have found that the data “stolen” from Mark Karpeles’ computer actually contained a BTC-stealing Trojan that masqueraded as a back-end app for managing Mt.Gox trades. The app searched user directories for Bitcoin-related files – wallet.dat and bitcoin.conf – and uploaded them to a server that is now defunct.

The app apparently ran on OS X and Windows.

The files appeared after Mark Karpeles’ website was hacked by unknown assailants. The documents contained mostly public information regarding Mt.Gox and the aforementioned payload.

Writes Kaspersky’s Sergey Lozhkin:

The malware creates and executes the TibanneSocket.exe binary and searches for the files bitcoin.conf and wallet.dat – the latter is a critical data file for a Bitcoin crypto-currency user: if it is kept unencrypted and is stolen, cybercriminals will gain access to all Bitcoins the user has in his possession for that specific account.

In short, delete that payload if you’ve downloaded it.

Illustration by Bryce Durbin

Techcrunch event

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

San Francisco | October 27-29, 2025

Topics

, , ,
Loading the next article
Error loading the next article