The same bug that has plagued several of the biggest players in the Bitcoin economy may have just bitten the Silk Road: On Thursday, one of the recently-reincarnated drug-selling black market site's administrators posted a long announcement to the Silk Road 2.0 forums admitting that the site had been hacked by one of its sellers, and its reserve of Bitcoins belonging to both the users and the site itself stolen. The admin, who goes by the name "Defcon," blamed the same “transaction malleability” bug in the Bitcoin protocol that led to several of the cryptocurrency's exchanges halting withdrawals in the previous week.
"I am sweating as I write this… I must utter words all too familiar to this scarred community: We have been hacked," Defcon wrote. "Our initial investigations indicate that a vendor exploited a recently discovered vulnerability in the Bitcoin protocol known as 'transaction malleability' to repeatedly withdraw coins from our system until it was completely empty."
Just how many bitcoins were stolen wasn't included in the post, although it listed a series of Bitcoin addresses that the Silk Road administrators believe to have been involved in the heist. Those transactions seem to point to a single Bitcoin address that contains 58,800 coins, worth more than $36.1 million at current exchange rates. But tracing Bitcoin's pseudonymous transactions is always tricky–other estimates range from 41,200 by a Silk Road user and 88,000 by the Bitcoin news site.
Update: Nicholas Weaver, a researcher at the International Computer Science Institute, estimates the total theft of Silk Road's bitcoins at a much lower number: just 4,400 or so coins, worth around $2.6 million.