LuBian’s Bitcoin Theft: Key Custody Risks and On-Chain Response
Summary
This account describes the December 2020 theft from LuBian, a Chinese mining pool, and its implications for crypto custody. It attributes the breach to weaknesses in private-key generation that enabled brute-force attacks, reporting that 127,426 BTC were taken and that more than 90% of the pool’s holdings were lost. It also says additional funds were stolen from an Omni Layer address two days later.
The article follows the stolen coins’ limited movement, including a July 2024 wallet consolidation, and describes LuBian’s attempt to contact the thief through OP_RETURN messages. It frames the incident as a case for stronger key generation, monitoring, and timely disclosure. However, the account provides no technical forensic evidence for its attribution, and its asset valuations vary with Bitcoin’s price. Its claims about the breach and its scale should therefore be treated as reported claims rather than an independently demonstrated security analysis.
Key ideas
- The article attributes the theft to flaws in LuBian’s private-key generation process.
- It reports that most of the pool’s Bitcoin was stolen, including funds from an Omni Layer address.
- LuBian reportedly used OP_RETURN transactions to appeal for the stolen funds’ return.
- Limited subsequent movement and a 2024 consolidation are presented as signs of continued control by the thief.
- The case highlights custody security and incident disclosure concerns, though the article supplies little forensic evidence.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.