Molly White (@molly0xFFF) on X

7 min read Original article ↗

user avatar

The debtors reiterate the stunning lack of recordkeeping and controls at FTX: "Normally... there are readily identifiable records, data sources, and processes that can be used to identify and safeguard assets of the estate. Not so with the FTX Group."

user avatar

"Upon assuming control, the Debtors found a pervasive lack of records and other evidence at the FTX Group of where or how fiat currency and digital assets could be found or accessed, and extensive commingling of assets."

user avatar

FTX executives "stifled dissent, commingled and misused corporate and customer funds, lied to third parties about their business, [and] joked internally about their tendency to lose track of millions of dollars in assets"

Despite the public image it sought to create of a responsible business, the FTX Group was tightly controlled by a small group of individuals who showed little interest in instituting an appropriate oversight or control framework. These individuals stifled dissent, commingled and misused corporate and customer funds, lied to third parties about their business, joked internally about their tendency to lose track of millions of dollars in assets, and thereby caused the FTX Group to collapse as swiftly as it had grown. In this regard, while the FTX Group’s failure is novel in the unprecedented scale of harm it caused in a nascent industry, many of its root causes are familiar: hubris, incompetence, and greed.

user avatar

Debtors are having to cobble together financial records from what they're able to find in QuickBooks and Slack records 💀

The Debtors have also reviewed and analyzed the FTX Group’s available financial records. These include QuickBooks, which certain entities in the FTX Group used as their general ledgers; certain bank statements; financial statements; tax returns; promissory notes evidencing intercompany loans; spreadsheets recording real estate transactions, political and charitable contributions, and venture investments; and Slack channels devoted to expense reimbursements and related matters.

user avatar

It sounds like the debtors are limited somewhat by the fact that laptops belonging to SBF and other high-level insiders are currently in the hands of the Bahamian Joint Provisional Liquidators, who've been less than cooperative (according to the US team, at least).

Finally, the Debtors have analyzed a small set of laptops and other electronic devices of certain employees of the FTX Group, and continue to collect such devices. The set of electronic devices in the Debtors’ possession does not include those known to have belonged to Bankman-Fried and other key insiders that are currently in the possession of the Bahamian Joint Provisional Liquidators (“JPLs”) and are the subject of ongoing discussion between the Debtors and the JPLs.

user avatar

Nishad Singh, Gary Wang, and Caroline Ellison have all pled guilty and are cooperating with the DOJ, making it infeasible for the debtors to interview them for bankruptcy purposes until after the criminal trial is over. They have interviewed others, though.

C. Witnesses To date, the Debtors have conducted interviews of 19 employees of the FTX Group, and received substantial information through counsel for five others. These include interviews of employees who worked in Policy and Regulatory Strategy, Information Technology, Controllers, Administration, Legal, Compliance, and Data Science and Engineering, among others. The Debtors continue to identify, interview, and collect information from potentially relevant witnesses. While Singh, Wang, and Ellison have pleaded guilty pursuant to cooperation agreements with the Justice Department, it is generally not feasible for the Debtors to interview them on key subjects until after the ongoing criminal prosecution of Bankman-Fried has concluded. Wang has provided discrete assistance to the Debtors’ financial and technical advisors.

user avatar

FTX had "an environment in which a handful of employees had, among them, virtually limitless power to direct transfers of fiat currency and crypto assets and to hire and fire employees, with no effective oversight or controls to act as checks on how they exercised those powers."

user avatar

"The FTX Group lacked independent or experienced finance, accounting, human resources, information security, or cybersecurity personnel or leadership, and lacked any internal audit function whatsoever. Board oversight, moreover, was also effectively non-existent."

1. FTX Group Management and Governance The management and governance of the FTX Group was largely limited to Bankman-Fried, Singh, and Wang. Among them, Bankman-Fried was viewed as having the final voice in all significant decisions, and Singh and Wang largely deferred to him.10 These three individuals, not long out of college and with no experience in risk management or running a business, controlled nearly every significant aspect of the FTX Group. With isolated exceptions, including for FTX.US Derivatives (“LedgerX”), a non-Debtor entity it acquired in late 2021, FTX Japan, a Debtor acquired in 2022, and Embed Clearing LLC, a non-Debtor acquired in 2022, the FTX Group lacked independent or experienced finance, accounting, human resources, information security, or cybersecurity personnel or leadership, and lacked any internal audit function whatsoever. Board oversight, moreover, was also effectively non-existent. Most major decision-making and authority sat with Bankman-Fried, Singh,

user avatar

"If Nishad [Singh] got hit by a bus, the whole company would be done. Same issue with Gary [Wang]." (see also en.wikipedia.org/wiki/Bus_factor, for those unfamiliar with the grim hypothetical)

user avatar

Some new context on the sudden resignation of

@brettharrison

in Sept. 2022: he "resigned following a protracted disagreement", after which his bonus was drastically reduced.

Efforts to clarify corporate responsibilities and enhance compliance were not welcome and resulted in backlash. For example, the President of FTX.US resigned following a protracted disagreement with Bankman-Fried and Singh over the lack of appropriate delegation of authority, formal management structure, and key hires at FTX.US; after raising these issues directly with them, his bonus was drastically reduced and senior internal counsel instructed him to apologize to Bankman-Fried for raising the concerns, which he refused to do.

user avatar

In a separate instance, a lawyer who was hired only three months prior, who learned about the North Dimension bank accounts, was "summarily terminated after expressing concerns about Alameda’s lack of corporate controls, capable leadership, and risk management."

Similarly, less than three months after being hired, and shortly after learning about Alameda’s use of a North Dimension bank account to send money to customers of the FTX exchanges, a lawyer within the FTX Group was summarily terminated after expressing concerns about Alameda’s lack of corporate controls, capable leadership, and risk management.

user avatar

"At the time of the bankruptcy filing, the FTX Group did not even have current and complete lists of who its employees were."

user avatar

"As a general matter, policies and procedures relating to accounting, financial reporting, treasury management, and risk management did not exist, were incomplete, or were highly generic and not appropriate for a firm handling substantial financial assets."

user avatar

The small accounting firm used by FTX entities for most accounting "appears to have a small number of employees and no specialized knowledge relating to cryptocurrencies or international financial markets".

user avatar

More QuickBooks shade. "35 FTX Group entities used QuickBooks as their accounting system and relied on a hodgepodge of Google documents, Slack communications, shared drives, and Excel spreadsheets and other non-enterprise solutions to manage their assets and liabilities"

 2. Lack of Appropriate Accounting Systems Companies with operations as large and complex as those of the FTX Group normally employ either an advanced off-the-shelf Enterprise Resource Planning (“ERP”) system (e.g., Oracle Fusion Cloud ERP, SAP S/4HANA Cloud) or a sophisticated proprietary system tailored to the accounting needs of the business such as, for a crypto exchange or trading business, a system tailored to the crypto assets in which the business transacted. Any appropriate accounting system should be capable of handling large volumes of data to accurately record, process, and report financial statement information (balance sheet/income statement) as well as operational information (actual versus budgeted spending), and to store key supporting materials. To minimize the risk of data integrity errors and the need for manual processing of transactions, data should flow automatically into the accounting system from core systems of the business, with transactions recorded based on

user avatar

"Fifty-six entities within the FTX Group did not produce financial statements of any kind."

user avatar

"Approximately 80,000 transactions were simply left as unprocessed accounting entries in catch-all QuickBooks accounts titled 'Ask My Accountant.'"

As a result of the FTX Group’s poor controls, and the inherent limitations of QuickBooks software for use in a large and complex business, the FTX Group did not employ QuickBooks in a manner that would allow it to maintain accurate financial records. For example, QuickBooks did not interface directly with the FTX Group’s core systems. Data had to be transported from the FTX Group systems into QuickBooks manually, generally by outside accountants who did not have access to the source data to validate that they had completely and accurately transferred the data into QuickBooks. Furthermore, because they processed large volumes of data only manually, a great deal of transaction detail (e.g., the purpose of a transaction) was either populated en masse, or omitted entirely. Substantial accounts and positions went untracked in QuickBooks. Digital asset transactions were tracked in QuickBooks using the generic entry “investments in cryptocurrency,” but detailed recordkeeping reflecting what t

user avatar

Sam Bankman-Fried: "Alameda is unauditable... we are only able to ballpark what its balances are, let alone something like a comprehensive transaction history. We sometimes find $50m of assets lying around that we lost track of; such is life"

Alameda often had difficulty understanding what its positions were, let alone hedging or accounting for them. For the vast majority of assets, Alameda’s recordkeeping was so poor that it is difficult to determine how positions were marked. A June 2022 “Portfolio summary” purporting to model cryptocurrency positions held by Alameda stated, with respect to valuation inputs for certain tokens, that Alameda personnel should “come up with some numbers? idk.” In an internal communication, Bankman-Fried described Alameda as “hilariously beyond any threshold of any auditor being able to even get partially through an audit,” adding: Alameda is unauditable. I don’t mean this in the sense of “a major accounting firm will have reservations about auditing it”; I mean this in the sense of “we are only able to ballpark what its balances are, let alone something like a comprehensive transaction history.” We sometimes find $50m of assets lying around that we lost track of; such is life. Bankman-Fried’

user avatar

"Thousands of deposit checks were collected from the FTX Group’s offices, some stale-dated for months, due to the failure of personnel to deposit checks in the ordinary course; instead, deposit checks collected like junk mail."

user avatar

Transfers in the tens of millions of dollars were approved via Slack emoji, or discussed in disappearing Signal or Telegram chats.

Although the FTX Group consisted of many, separate entities, transfers of funds among those entities were not properly documented, rendering tracing of funds extremely challenging. To make matters worse, Slack, Signal, and other informal methods of communication were frequently used to document approvals. Signal and Telegram were at times utilized in communications with both internal and external parties with “disappearing messages” enabled, rendering any historical review impossible. Expenses and invoices of the FTX Group were submitted on Slack and were approved by “emoji.” These informal, ephemeral messaging systems were used to procure approvals for transfers in the tens of millions of dollars, leaving only informal records of such transfers, or no records at all.

user avatar

"Only four months after the real estate purchase had closed did the employee enter into a promissory note with Alameda in which he undertook to repay the funds used to purchase the property. Other insiders received purported loans from Alameda for which no promissory notes exist"

Numerous loans were executed between former insiders and Alameda without contemporaneous documentation, and funds were disbursed pursuant to those purported loans with no clear record of their purpose. In one instance, an insider entered into an agreement to purchase a piece of real estate. The funds used to purchase that property, however, were wired directly from Alameda and FTX Digital Markets Ltd. (“FTX DM”), a Bahamas-based entity which was owned by, and had obtained the funds from, FTX Trading Ltd. Only four months after the real estate purchase had closed did the employee enter into a promissory note with Alameda in which he undertook to repay the funds used to purchase the property. Other insiders received purported loans from Alameda for which no promissory notes exist.

user avatar

Accounts were opened using names and email addresses that were not obviously linked to FTX, using pseudonymous email addresses, in the names of shell companies created for these purposes, or in the names of individuals (including individuals with no direct connection FTX)

4. Trading Records from Other Exchanges While the FTX Group maintained over a thousand accounts on external digital asset trading platforms in jurisdictions around the world, many of which held significant assets at various points in time, it had no comprehensive, centralized source of information reflecting the purpose of these accounts, or the credentials to access them. Many of these accounts were opened using names and email addresses that were not obviously linked to any of the FTX Group entities. Other accounts were opened using pseudonymous email addresses, in the names of shell companies created for these purposes, or in the names of individuals (including individuals with no direct connection to the FTX Group).

user avatar

"Alameda also transferred funds to insiders to fund personal investments, political contributions, and other expenditures—some of which were nominally “papered” as personal loans with below-market interest rates and a balloon payment due years in the future."

5. Intercompany Transactions The FTX Group did not observe any discernable corporate formalities when it came to intercompany transactions. Assets and liabilities were routinely shuffled among the FTX Group entities and insiders without proper process or documentation. Alameda routinely provided funding for corporate expenditures (e.g., paying salaries and other business expenses) whether for Alameda, for various other Debtors, or for FTX DM, and for venture investments or acquisitions whether for Alameda or for various other Debtors. Alameda also transferred funds to insiders to fund personal investments, political contributions, and other expenditures—some of which were nominally “papered” as personal loans with below-market interest rates and a balloon payment due years in the future. Intercompany and insider transfers were often recorded on the QuickBooks general ledgers in a manner that was inconsistent with the apparent purpose of the transfers. For example, an Alameda bank accou

user avatar

The document reiterates previous allegations about Alameda's "unique ability to trade and withdraw virtually unlimited assets [on FTX], regardless of the size of its account balance and without risk of its positions being liquidated."

user avatar

The FTX group had no cybersecurity staff whatsoever.

1. Lack of Key Personnel, Departments, and Policies While the FTX Group employed software developers and a single dedicated IT professional, it had no dedicated personnel in cybersecurity, a specialized discipline that generally acts as a “check” to mitigate risks posed by business pressure for technology to operate as fast and easily as possible. The FTX Group had no independent Chief Information Security Officer, no employee with appropriate training or experience tasked with fulfilling the responsibilities of such a role, and no established processes for assessing cyber risk, implementing security controls, or responding to cyber incidents in real time. Instead, its security was largely managed by Singh and Wang, neither of whom had the training or experience to handle the FTX Group’s cybersecurity needs, and both of whom had responsibilities for the speed, efficiency, and continuing development of the FTX Group’s technology, which are business needs that generally run counter to th

user avatar

FTX stored private keys to its crypto wallets in AWS 🫠

The FTX Group stored the private keys to its crypto assets in its cloud computing environment, which included over one thousand servers and related system architecture, services, and databases that it leased from Amazon Web Services (the “AWS account”). AWS’s cloud computing platform offers businesses a range of infrastructure-as-a-service (IaaS), platform-as-a- service (PaaS), and software-as-a-service (SaaS) capabilities, and through it, like other businesses, the FTX Group customized, configured, and controlled its own cloud environment.

user avatar

"[FTX] kept virtually all crypto assets in hot wallets... [FTX] undoubtedly recognized how a prudent crypto exchange should operate, because when asked by third parties to describe the extent to which it used cold storage, it lied."

First, the FTX Group kept virtually all crypto assets in hot wallets, which are far more susceptible to hacking, theft, misappropriation, and inadvertent loss than cold wallets because hot wallets are internet-connected. Prudently-operated crypto exchanges keep the vast majority of crypto assets in cold wallets, which are not connected to the internet, and maintain in hot wallets only the limited amount necessary for daily operation, trading, and anticipated customer withdrawals.24 Relatedly, prudently-operated crypto exchanges implement strict processes and controls to minimize the security risks (for example, the risk of hacking, theft or loss) inherent in the transfer of crypto assets between hot and cold wallets. The FTX Group undoubtedly recognized how a prudent crypto exchange should operate, because when asked by third parties to describe the extent to which it used cold storage, it lied. For example, in 2019, Bankman-Fried falsely responded to a customer question on Twitter by

user avatar

An employee was "instructed that this information was not to be shared with regulators unless it was specifically requested. Another FTX Group employee responded that if the question was being posed by 'non-regulators,' then 'we say 10% in hot wallet, and 90% in cold wallet'"

user avatar

FTX generally didn't use multisigs. When they did, they stored all of the keys together in one place, thus defeating the purpose.

Second, the FTX Group failed to employ multi-signature capabilities or Multi-Party Computation (“MPC”) controls (together, “multi-signature/MPC controls”) that are widely used throughout the crypto industry to protect crypto assets. These controls require the cooperation of multiple individuals using unique keys or key fragments to effectuate a transaction. As a result, the controls significantly reduce the risk of fraud, theft, misuse, or  errors either by any single individual or in the event any single individual’s key or key fragment is compromised. These controls are widely understood to be crucial for crypto exchanges to ensure that unauthorized transactions do not occur, for many reasons: exchanges are regularly targeted by hackers; exchanges custody assets provided by others, heightening the need for security; exchanges engage in a high volume of transactions, increasing the likelihood that errors will occur; and, as noted above, compounding all of these issues, crypto assets m

user avatar

Debtors give multiple examples of irresponsible key storage. Keys to >$100M stored in unencrypted plaintext, for example, or in tools unsuitable for the job. Keys were often accessible by many employees with no auditing. Keys were poorly labeled, with names like "use this".

Despite the well-understood risks, private keys and seed phrases28 used by FTX.com, FTX.US, and Alameda were stored in various locations throughout the FTX Group’s computing environment in a disorganized fashion, using a variety of insecure methods and without any uniform or documented procedure. Among other examples: • The Debtors identified private keys to over $100 million in Ethereum assets stored in plain text and without encryption on an FTX Group server. • The Debtors identified private keys, as well as credentials to third-party exchanges, that enabled access to tens of millions of dollars in crypto assets that were stored in plain text and without encryption across multiple servers from which they could be accessed by many other servers and users in many locations. • Single-signature-based private keys to billions of dollars in crypto assets were stored in AWS Secrets Manager (a cloud-based tool used to manage sensitive information), and/or a password vault (a tool for secure

user avatar

swear to god my palms just started sweating reading that lol

user avatar

"Passwords for encrypting the private keys of wallet nodes were stored in plain text, committed to the code repository (where they could be viewed by many and were vulnerable to compromise), and reused across different wallet nodes"

Fourth, the FTX Group failed to appropriately implement controls to manage “wallet nodes,” which are software programs that operate on servers running the software of the blockchain network and help to implement and propagate transactions and maintain the security and integrity of the blockchain. A wallet node that holds private keys for a specific wallet is responsible for managing that wallet’s assets and communicating with the blockchain network to process transactions. As a result, the security of the associated wallet’s assets depends in large part on the security of the server on which the node is running. Crypto exchanges typically use trusted wallet nodes to broadcast transactions and query the blockchain to reconcile exchange ledger data with blockchain data. The FTX exchanges and Alameda maintained servers that ran wallet nodes for blockchains, including Bitcoin, Litecoin, and Dogecoin, among others; these nodes acted as hot wallets that held hundreds of millions of dollars’

user avatar

"Over a dozen people had direct or indirect access to the FTX​.com and FTX​.US central omnibus wallets, which held billions of dollars in crypto assets"

user avatar

FTX didn't enforce use of multi-factor authentication for Google Workspace or 1Password, which the debtors note is ironic given tweets like this:

user avatar

Daily reminder: use 2FA! 90% of crypto security is making sure you've done the basics. Ideally you should: a) use the 6-digit 2FA codes, NOT SMS b) use withdrawal passwords or IP-whitelisting for withdrawals etc. c) don't re-use passwords from hacked accounts

user avatar

FTX "failed by any measure" to perform basic cybersecurity practices including "creation and collection of logs that record and reflect activity within the computing environment, and systems to alert designated personnel to suspicious activity."

user avatar

"Due to the lack of such controls, the FTX Group did not learn of the November 2022 Breach until the Debtors’ restructuring advisor alerted employees after observing, via Twitter and other public sources, that suspicious transfers appeared to have occurred"

Among many examples of its control deficiencies in this area, the FTX Group did not have any mechanism to identify promptly if someone accessed the private keys of central exchange wallets holding hundreds of millions or billions of dollars in crypto assets, and it did not fully enable even the basic features offered by AWS to assist with cyber threat detection and response.36 In fact, due to the lack of such controls, the FTX Group did not learn of the November 2022 Breach until the Debtors’ restructuring advisor alerted employees after observing, via Twitter and other public sources, that suspicious transfers appeared to have occurred from FTX Group crypto wallets. The FTX Group similarly failed to institute any basic mechanism to be alerted to any “root” login to its AWS account, the cloud computing environment where it operated the FTX exchanges and stored keys to billions of dollars in crypto assets, even though such access would provide virtually complete access to the environmen

user avatar

Unsurprisingly given their lack of attention to cybersecurity, FTX didn't use any endpoint protection and failed to patch their software — in one case running software nearly 4 years out of date.

Third, the FTX Group did not implement controls sufficient to protect its network endpoints, such as laptops and desktops, from potential security threats. The FTX Group had no commonly used technical controls to ensure that employees used their corporate laptops, leaving employees free to use personal devices devoid of corporate security controls. The FTX Group also lacked any endpoint protection tool to monitor cloud-hosted servers for threats, and several of its critical services did not have the latest security updates installed. For example, to manage inbound internet traffic on a key server, the FTX Group used a version of software that was nearly four years out of date, leaving the server exposed to known vulnerabilities that had been addressed in updated versions of the software. This practice flouted industry standards by which software flaws and vulnerabilities should be remediated in a timely manner.37

user avatar

Nishad Singh was supposed to be in charge of cybersecurity, but wouldn't even provide the IT person with ID information of the corporate devices he was using.

Fourth, the FTX Group had no comprehensive record from which it could even identify critical assets and services, including employee workstations, software application servers, business data, and third-party cloud and other services it relied upon, leaving it with little to no visibility into what it needed to secure, let alone how to best secure it.38 Indeed, to understand and gain necessary access to the full scope of services that the FTX Group used, the Debtors had to analyze financial records such as bills paid to vendors, and search through employees’ email and chat messages. Although the FTX Group’s designated IT professional began creating an inventory of electronic devices issued to employees, and stressed to Singh (who was supposedly in charge of the FTX’s Group’s cybersecurity) the importance for security purposes of having Singh and other FTX Group senior management identify in the inventory the electronic devices they were using, neither Singh nor other senior management p

user avatar

FTX was "highly vulnerable" to supply chain attacks and "did not review, test, or otherwise deploy its code in a manner that sufficiently ensured that it was functioning as expected and free of vulnerabilities that might be leveraged by malicious actors."

Second, the FTX Group failed to adopt certain standard controls in order to ensure the integrity of its code.42 For example, there was no effective process for securely introducing, updating, or patching software, and no procedures, such as scanning, to continually ensure the integrity of the code running on FTX Group servers. Thus, among many other harms, the FTX Group was highly vulnerable to software “supply chain” attacks in which malicious actors insert vulnerabilities into third-party software in order to compromise any organization that uses the software.43 Furthermore, with only minimal code review and testing procedures in place, and no focus on continuous security testing, the FTX Group did not review, test, or otherwise deploy its code in a manner that sufficiently ensured that it was functioning as expected and free of vulnerabilities that might be leveraged by malicious actors.

user avatar

While outlining some of the difficulties they faced in identifying and securing crypto assets, the debtors say they "had to engineer technological pathways to transfer ... assets ... to cold storage" because FTX had never even written the code to make that possible.

user avatar

The report concludes by stating that the debtors have recovered and secured more than $1.4 billion in crypto assets, and have identified another $1.7 billion they're working to recover.