Ian Balina, a popular cryptocurrency evangelist, was in the midst of a standard livestream on his YouTube channel on Sunday night when a viewer asked, "Ian, did you know that somebody transferred all your tokens from your account?" With $US2 million ($2.6 million) worth of cryptocurrency gone from his wallet, Balina claims he was hacked. But the strangeness of the situation has the community questioning his story.
Screenshot: Ian Balina
Balina was reviewing an initial coin offering for his 116,000 YouTube subscribers when the comment was posted and he either didn't notice it or shrugged it off. After about 20 minutes, the livestream cut off. A couple of hours later, Balina returned to finish his review and blamed a power outage for his sudden disappearance. During the second stream, he said he'd discovered that he was mysteriously signed out of his Google Sheets profile where he tracks his cryptocurrency holdings.
Later, on his Telegram channel, Balina put out a call for help. "Hey Crypto Family, I need you now more than ever," he wrote. "I had to end today's live stream abruptly because I am being hacked." He then listed three Ether wallet addresses that he was trying to track.
It's not unusual for individuals or exchanges to get their cryptocurrency stolen by a malicious actor, but Balina's reaction has been odd in this case. "I'm not worried about the money at this point," he wrote on Telegram, and he insisted that going forward he's just concerned about catching the hacker.
A now-deleted message explained Balian's theory on how he was hacked:
This is how I think I got hacked. My college email was listed as a recovery email to my Gmail. I remember getting an email about it being compromised, and tried to follow up with my college security to get it resolved, but wasn't able to get it handled in fast manner and gave up on it thinking it was just an old email.
I kept text versions of my private keys stored in my Evernote, as encrypted text files with passwords. I think they hacked my email using my college email, and then hacked my Evernote.
It's unclear what he means when he says having his recovery email hacked provided the attacker with access to his encrypted Evernote files. Evernote's system requires that a user remember their passphrase, and it can't be reset through a recovery email. Maybe he's saying a hacker got his old email password and it was the same as his Evernote encryption phrase?
This is all very odd. As far as cryptocurrency gurus go, Balina is fairly prominent. Some in the community say that he's a paid shill for ICOs, but he has a large following and is featured as a regular expert by mainstream news outlets. It's strange that a guy with millions in crypto wouldn't follow basic security practices.
Coindesk, a popular cryptocurrency publication, gave Balina an honorable mention on its list of the top 10 token traders and analysts of 2017. The entry stipulated that his inclusion was "not because of his holdings or trades per say (though the author and self-promoter is doing well), but because of his habit of sharing a screenshot of his portfolio every day". And as the alleged hack became apparent, one YouTube commenter wrote, "That is exactly why you don't brag about your wealth online."
Many other online observers in his comments, on Twitter, and on Reddit think the timing and some transactions are fishy. Charlie Schrem, one of the earliest Bitcoiners, replied to Balina's tweet, asking incredulously, "So he moved all the tokens and ether into 1 account last week and that's the account that got hacked?" With US taxes due tomorrow, the overwhelming theory is that this is all an elaborate scheme to get out of paying taxes. Others say that theory is complicated because Balina is based in the UK where taxes were due on April 5.
We're not sure what to think, but Balina certainly seems chill for a man who just lost millions while he was publicly giving crypto advice. We've reached out to the man himself with numerous clarifying questions but had not received a reply at time of writing.