Paxos Identified as Fat Finger Entity in 20 BTC Fee Mistake

“Paxos overpaid the BTC network fee on Sept. 10, 2023. This only impacted Paxos corporate operations. Paxos clients and end users have not been affected and all customer funds are safe. This was due to a bug on a single transfer and it has been fixed. Paxos is in contact with the miner to recoup the funds,” a PayPal spokesperson told Bitcoin Magazine.The wallet was first identified by mononaut, who first attributed the mistake to PayPal.”The on-chain activity is consistent with automated processing of fiat-denominated withdrawals, and also closely matches the behavior of a now inactive wallet bc1qhs…kx4n, which is labelled as PayPal on http://oxt.me,” wrote mononaut.”All evidence now points to a software bug like this as the cause of the error. I really feel for the developer who wrote that code – it’s such an easy mistake to make, and it should have been caught in review,” he added.”More importantly, there should have been monitoring and sanity checks in place to prevent actual loss of funds. In reality, the system was apparently running *completely unmonitored*, since PayPal didn’t notice or halt withdrawals for almost 24 hours.””Single-address wallets are terrible for privacy. It was trivial to unravel PayPal’s entire wallet structure and payment history from one known tx,” mononaut added.”Big companies are way worse at it than you might expect.”In response to the reveal, F2Pool’s Chun Wang, who earlier said that F2Pool is willing to refund the sender if it’s claimed in 3 days, posted the following poll on X.

I was annoyed and regretted agreeing to refund that 20 BTC. Especially when I saw the person claiming it kept saying EST instead of EDT/UTC. Last time a Zcash guy did that, I blocked his entire company.

Ref:https://t.co/MQh0ijLR11https://t.co/lxtcFH9mq3

So what should I do?

— Chun (@satofishi) September 13, 2023

Full Thread
Bitcoin Magazine Article / Archive

Leave a Reply

Your email address will not be published. Required fields are marked *