I'm reflexively sympathetic to the small, scrappy startup. But...
...man this is not a sympathetic story. You're running a gambling site (morally shady and an obvious magnet for abuse), using bitcoins (another huge abuse magnet), you had very supicious gambling patterns (a massive red flag that no real casino would accept), and you just let the guy keep playing? That's not how you're supposed to do that.
And as for the whole "we had a timing bug in our code, and we couldn't find it even with hard proof that it existed, and then we finally thought we'd fixed it, and then we asked the guy for the million dollars back (??!?), and then it turned out we hadn't fixed it at all, and he hit us up for another few thousand"? Like, that just sounds screaming amateurish.
If you can't be trusted to write secure code, or at least fix the bugs you find in it, maybe online bitcoin casinos aren't for you? And if you think asking people nicely to give you your money back works in casinos, maybe you don't understand the industry?
Edit: I'm not trying to be a dick, but I feel like the proper blogpost to write would be a grovelling "hey guys, I know it's super obvious, but if you're doing an online gambling website, monitor your transactions for specific patterns. Know what a real punter looks like, and aggressively throttle anyone who doesn't behave like one. Otherwise you'll be stupid idiots who lose a million dollars over a stupid bug, and then have to write a magnanimous letter congratulating the guy who exploited you for winning so much money (man that was painful to write)." You made some huge mistakes, and it doesn't sound like you really learned from them, or even identified them. Hint: Your core mistake was not a timing bug that emerged when your system was under heavy load.
Comments
I'm reflexively sympathetic to the small, scrappy startup. But...
...man this is not a sympathetic story. You're running a gambling site (morally shady and an obvious magnet for abuse), using bitcoins (another huge abuse magnet), you had very supicious gambling patterns (a massive red flag that no real casino would accept), and you just let the guy keep playing? That's not how you're supposed to do that.
And as for the whole "we had a timing bug in our code, and we couldn't find it even with hard proof that it existed, and then we finally thought we'd fixed it, and then we asked the guy for the million dollars back (??!?), and then it turned out we hadn't fixed it at all, and he hit us up for another few thousand"? Like, that just sounds screaming amateurish.
If you can't be trusted to write secure code, or at least fix the bugs you find in it, maybe online bitcoin casinos aren't for you? And if you think asking people nicely to give you your money back works in casinos, maybe you don't understand the industry?
Edit: I'm not trying to be a dick, but I feel like the proper blogpost to write would be a grovelling "hey guys, I know it's super obvious, but if you're doing an online gambling website, monitor your transactions for specific patterns. Know what a real punter looks like, and aggressively throttle anyone who doesn't behave like one. Otherwise you'll be stupid idiots who lose a million dollars over a stupid bug, and then have to write a magnanimous letter congratulating the guy who exploited you for winning so much money (man that was painful to write)." You made some huge mistakes, and it doesn't sound like you really learned from them, or even identified them. Hint: Your core mistake was not a timing bug that emerged when your system was under heavy load.