Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: HELP.org on August 27, 2013, 01:31:17 PM



Title: Someone sending out MilliBits
Post by: HELP.org on August 27, 2013, 01:31:17 PM
..


Title: Re: Someone sending out MilliBits
Post by: Taras on August 28, 2013, 06:03:16 AM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6 (https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6)
I wonder why they're giving to random addresses like this.


Title: Re: Someone sending out MilliBits
Post by: willphase on August 28, 2013, 10:05:20 AM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6
I wonder why they're giving to random addresses like this.

They are trying to entice the addresses to consolidate the funds, thus proving linkages between addresses in order to defeat pseudonymity.

Before the RNG bug was well known, some people were also using this technique to trying to entice spends from addresses from devices with weak RNG so they can perform a private key disclosure.

Will


Title: Re: Someone sending out MilliBits
Post by: coastermonger on August 28, 2013, 09:11:58 PM
So what you're saying is, if you suspect someone is enticing you to consolidate funds, you should probably move the funds to an exchange and cash them out and buy back in, or move your bitcoins through a coin mixer before moving them again? 


Title: Re: Someone sending out MilliBits
Post by: willphase on August 28, 2013, 09:32:14 PM
So what you're saying is, if you suspect someone is enticing you to consolidate funds, you should probably move the funds to an exchange and cash them out and buy back in, or move your bitcoins through a coin mixer before moving them again? 

or just leave the extra bitcoins in there until you actually want to spend the bitcoins.

Will


Title: Re: Someone sending out MilliBits
Post by: Kluge on August 28, 2013, 09:42:03 PM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6
I wonder why they're giving to random addresses like this.

They are trying to entice the addresses to consolidate the funds, thus proving linkages between addresses in order to defeat pseudonymity.

Before the RNG bug was well known, some people were also using this technique to trying to entice spends from addresses from devices with weak RNG so they can perform a private key disclosure.

Will
This behavior has been happening since almost the beginning of Bitcoin. This is the conclusion arrived at last time I saw a discussion on it (though it wasn't related to RNG flaw). It's difficult to really determine why it happens, though. AFAIK, they haven't been connected to thefts of coins from people who've ever received them. Other theories are more tin-foil-y.  :)


Title: Re: Someone sending out MilliBits
Post by: Ente on November 10, 2013, 04:46:29 PM
..that person is on it again.
Check this out:
https://blockchain.info/address/1FFirnLctcZxVx5otnLNZ4dDGUkMBM4vNr

The outputs are totally random - even satoshidice and deepbit are on the list. Several thousands there, it seems.
Well, thanks for the 10c. Good luck with messing with my vanitygen address. *shrugs*

Ente


Title: Re: Someone sending out MilliBits
Post by: vandeam on November 10, 2013, 07:43:33 PM
sorry can this be simplified for me  ???


Title: Re: Someone sending out MilliBits
Post by: Mike Christ on November 10, 2013, 08:36:27 PM
sorry can this be simplified for me  ???

Tiny amounts of Bitcoin are potentially being used to track who owns which addresses.


Title: Re: Someone sending out MilliBits
Post by: Ente on November 11, 2013, 11:15:55 AM
Also, one scenario could be that people receive (milli)bitcoins and go on send them elsewhere. When you send a transaction out, you publish your (real) public key (which is something different to your public bitcoin address). If the privat+public key pair was created insecurely, the attacker ow knows the public key and might be able to steal all funds from that address.

BUT: Why the heck does the attacker here send millibits to addresses which already did transactions? Where the public key is already published and known?
So, this can't really be the reason.

Analyzing who owns which addresses? Doesn't really make sense, with just a handfull he scraped from bitcointalk and similar.

So, my guess is it's something with tainting other coins.

Ente


Title: Re: Someone sending out MilliBits
Post by: gmaxwell on November 11, 2013, 01:46:54 PM
So, my guess is it's something with tainting other coins.
Users of bitcoind / bitcoin-qt can fight back against this by using Peter Todd's (retep on BCT) dust-b-gone script (https://github.com/petertodd/dust-b-gone/) which will CoinJoin (https://bitcointalk.org/index.php?topic=279249.0) away the dust in your wallet, both cleaning up the blockchain and thwarting any tainting efforts.


Title: Re: Someone sending out MilliBits
Post by: auzaar on November 12, 2013, 01:45:17 AM
Just putting the source address so that it comes up in search
1FFirnLctcZxVx5otnLNZ4dDGUkMBM4vNr


Title: Re: Someone sending out MilliBits
Post by: dddbtc on November 12, 2013, 01:54:39 AM
Quote from: rjs
That's generous of you to offer an exchange, but I think they're fine.

Here's the address of the coin with extra BTC on it: https://blockchain.info/address/13EboHof8EoyB3xW4tssrsufhQtaQmymhS - address 1FFirnLctcZxVx5otnLNZ4dDGUkMBM4vNr is being a Bitcoin fairy and sending Bitcoins to a bunch of addresses. That same address previously sent a whole bunch of 1BTC to many, many addresses and then 100BTC to two addresses and 25BTC to one address. My first thought was that was Casascius loading his coins and then doing... something sending a little extra. But spot-checking the 1BTC addresses doesn't show what I would expect in this case, which would be that all those addresses just had one (or two) transactions to them, and they all hold a nice round 1BTC (or 1.001BTC), but that's not really what I'm seeing. A mystery!


Title: Re: Someone sending out MilliBits
Post by: Lauda on November 12, 2013, 06:01:45 AM
This is mysterious.  :o


Title: Re: Someone sending out MilliBits
Post by: allthingsluxury on November 12, 2013, 06:08:03 AM
Very strange.


Title: Re: Someone sending out MilliBits
Post by: itod on November 12, 2013, 11:38:17 AM
Also, one scenario could be that people receive (milli)bitcoins and go on send them elsewhere. When you send a transaction out, you publish your (real) public key (which is something different to your public bitcoin address). If the privat+public key pair was created insecurely, the attacker ow knows the public key and might be able to steal all funds from that address.

BUT: Why the heck does the attacker here send millibits to addresses which already did transactions? Where the public key is already published and known?
So, this can't really be the reason.

Analyzing who owns which addresses? Doesn't really make sense, with just a handfull he scraped from bitcointalk and similar.

So, my guess is it's something with tainting other coins.

Ente

Maybe it's not just the public key, if the receiver sends this dust out to consolidate the wallet he may reveal his real IP address if his peer is listening, getting info for potential attack on the wallet later. I wonder if those addresses that receive dust have:
a) above average amount of BTC in them, meaning not particular BTC address but the wallet that holds that BTC address.
b) local wallet, not web wallet


Title: Re: Someone sending out MilliBits
Post by: int03h on January 07, 2014, 08:45:26 PM
https://blockchain.info/tx/cf2d7091de839cead9d677d6fb050d4278f17bfca3e74cf80198197346ba4a3d

Another round it seems. Thanks Who-Ever-You-Are.


Title: Re: Someone sending out MilliBits
Post by: crazy_rabbit on January 07, 2014, 09:05:17 PM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6
I wonder why they're giving to random addresses like this.

They are trying to entice the addresses to consolidate the funds, thus proving linkages between addresses in order to defeat pseudonymity.

Before the RNG bug was well known, some people were also using this technique to trying to entice spends from addresses from devices with weak RNG so they can perform a private key disclosure.

Will

Exactly. If you keep track of where coins start, and where they end up, you can 'color' the entire transaction tree. Think of a river that runs backwards from the sea. You dump dye in the water at the delta, the mouth, and watch is flow back up track all the estuaries. Not an elegant example, but you get the point. You could track water back to the smallest creek.

Thats whats happening here.


Title: Re: Someone sending out MilliBits
Post by: quone17 on January 07, 2014, 09:35:08 PM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6
I wonder why they're giving to random addresses like this.

They are trying to entice the addresses to consolidate the funds, thus proving linkages between addresses in order to defeat pseudonymity.

Before the RNG bug was well known, some people were also using this technique to trying to entice spends from addresses from devices with weak RNG so they can perform a private key disclosure.

Will

Exactly. If you keep track of where coins start, and where they end up, you can 'color' the entire transaction tree. Think of a river that runs backwards from the sea. You dump dye in the water at the delta, the mouth, and watch is flow back up track all the estuaries. Not an elegant example, but you get the point. You could track water back to the smallest creek.

Thats whats happening here.

God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.


Title: Re: Someone sending out MilliBits
Post by: Ente on January 07, 2014, 10:09:54 PM
https://blockchain.info/tx/90087eef265335c807ae2559793913e57321765462a2abcb58027e6751eb58e6
I wonder why they're giving to random addresses like this.

They are trying to entice the addresses to consolidate the funds, thus proving linkages between addresses in order to defeat pseudonymity.

Before the RNG bug was well known, some people were also using this technique to trying to entice spends from addresses from devices with weak RNG so they can perform a private key disclosure.

Will

Exactly. If you keep track of where coins start, and where they end up, you can 'color' the entire transaction tree. Think of a river that runs backwards from the sea. You dump dye in the water at the delta, the mouth, and watch is flow back up track all the estuaries. Not an elegant example, but you get the point. You could track water back to the smallest creek.

Thats whats happening here.

God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Well, Bitcoin isn't anonymous. It is, however, pseudonymous. That means you can distinguish individual payments, amounts and addresses, just just don't know which address belongs to whom.
With this technique (sending out tiny amounts), as well as a few others, one can figure out which individual addresses belong to the same user and/or wallet. For example, if you receive one dust amount to an "anonymous" address of your wallet, and spend it together with funds from an address you have written in your signature, everyone (who cares to look) knows that the first, "anonymous" address belongs to the user quone.

Not more, not less.

But yes, the public opinion on one hand, and the technical facts on the other hand about anonymity/pseudonymity are a reason to become nervous ;-)

Ente


Title: Re: Someone sending out MilliBits
Post by: itod on January 07, 2014, 10:38:18 PM
God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Don't know which risk you are talking about. Bitcoin addresses which send and receive coins are in permanent public record. There are also connected to their inputs and outputs. You have to understand there are no "coins" like in the physical world, each coin is permanently destroyed when it completely becomes an input for another coin, but the record of it's previous existence remains forever. Two inputs of a new coin become tied to each other in that new coin, until that coin's output become's input to yet another one.

All those inputs and outputs have not only BTC amounts, but also sending address of the output and receiving address of the input in the blockchain record.

Keep in mind that sum of inputs and the outputs of each transaction have to be equal, and since there's a slim chance you have the exact amount in one "coin" you wan't to send to another address, in majority of cases your output have to be tied to your another coin's output to make enough for a transaction, and the change of the transaction goes to your new "coin" as it's input. This eternal multiple inputs/multiple outputs game is the reason for this dust to be sent, as a sender hopes to trace it's outputs for a long time until he figures out where it eventually ended.

There is in no way to connect a BTC address to a personal identity, but i'ts enough that you have leaked a single tie of some address to your identity, and this dust's output to become a new coin owned by an address in the same wallet as this leaked address, these old coins will also be tied to that leaked identity.

Also, keep in mind that your IP address is somewhere in the private record of you ISP provider. Each time your provider assigns a dynamic IP address to your home router, or static IP address to your business, it logs which IP address went to which customer. Those logs can be obtained in all countries with the court order, and in some countries even without the court order. The reason why I'm mentioning this is a possibility that your peers, when you send a BTC transaction, my log the IP which sent them the transaction. In most cases you are not connected to a peer who does such a thing, but even if you are, those "nasty" peers my get the IP of the peer that relayed the transaction, not the peer that originated it, so they can never be sure if they got the IP address of the originator right. You can make sure that your IP will never be logged, but it's far from easy, and the guys that need such a things know how to do it.

When you know these facts you are safe and there is no risk in using Bitcoin, just behave appropriately. There are recommended polices you should stick to, start with never reusing the BTC address without the great need to do so. This policy was recommended for a whole another reason (not to expose the public key, just a hash of it instead), but is very useful for keeping your transactions and addresses harder to tie together. This forum post is not adequate for all of these policies, but you can find them all over this forum.


Title: Re: Someone sending out MilliBits
Post by: Cassius on February 12, 2014, 05:04:08 PM
Another theory. I'm not sure about this: just want to run it up the flagpole and see who salutes it.
If you look at brainwallets, you'll see that they can be incredibly insecure. A lot of people treat them like email and use bad passwords. It makes them vulnerable to people guessing them.
What if you used a dictionary to generate private keys and addresses, then sent a small amount of bitcoins - say 0.0000546 - to each address. A week later you run the same script and hoover up your coins, plus any others that happen to be sitting in an address you have 'guessed' right.
I don't know why you'd do it this way. Maybe you're a lazy coder, or something. But that appears to be what someone has done. Do a brainwallet address search for speculator, speculating, spectator, spectacles, etc, and you'll see what I mean. 0.0000546 bitcoins goes into the account, a week later out it goes. Looks like someone is running dictionary attacks with words over a certain length.
(Just so we're clear, I found this out through research into brainwallets and general curiosity, not to steal bitcoins from badly-secured wallets. I can't prove this but suffice to say I probably wouldn't post this warning if I was. :) )

*** People who have received dust payments: are you using a brainwallet? If so, consider it insecure and move your coins ASAP. ***

Like I said, not sure whether this is right or not. But something weird is going on with dictionary-generated brainwallet addresses.
Alternatively, I'd love to know any other theories as to why someone would send 0.0000546 bitcoins to a bunch of dictionary addresses.... any answers?


Title: Re: Someone sending out MilliBits
Post by: Ente on February 12, 2014, 05:23:34 PM
Another theory. I'm not sure about this: just want to run it up the flagpole and see who salutes it.
If you look at brainwallets, you'll see that they can be incredibly insecure. A lot of people treat them like email and use bad passwords. It makes them vulnerable to people guessing them.
What if you used a dictionary to generate private keys and addresses, then sent a small amount of bitcoins - say 0.0000546 - to each address. A week later you run the same script and hoover up your coins, plus any others that happen to be sitting in an address you have 'guessed' right.
I don't know why you'd do it this way. Maybe you're a lazy coder, or something. But that appears to be what someone has done. Do a brainwallet address search for speculator, speculating, spectator, spectacles, etc, and you'll see what I mean. 0.0000546 bitcoins goes into the account, a week later out it goes. Looks like someone is running dictionary attacks with words over a certain length.
(Just so we're clear, I found this out through research into brainwallets and general curiosity, not to steal bitcoins from badly-secured wallets. I can't prove this but suffice to say I probably wouldn't post this warning if I was. :) )

*** People who have received dust payments: are you using a brainwallet? If so, consider it insecure and move your coins ASAP. ***

Like I said, not sure whether this is right or not. But something weird is going on with dictionary-generated brainwallet addresses.
Alternatively, I'd love to know any other theories as to why someone would send 0.0000546 bitcoins to a bunch of dictionary addresses.... any answers?

Good theory - but unprobable because of two things:

1) you can, as a "brainwallet harvester", create random private keys, calculate the public address to this, and look up on the blockchain if there is any money on that. If yes - sweep it away immediately. All public addresses with funds on them would be in a huge database, everything would be done completely offline.

2) because of this, more generally speaking:

http://cynic.me/wp-content/uploads/2013/11/bitcoin-laws-of-the-universe.jpg

3) bonus: I received dust, it was on an address I published somewhere, on the forums or something like that. Unrelated: I did a test and sent a small amount to a brainwallet address with a weak passphrase. It was sweeped like some hours later.

Ente


Title: Re: Someone sending out MilliBits
Post by: Cassius on February 12, 2014, 05:51:19 PM
Thanks for the reply. That's good to know (I'm assuming your address that got dust was not generated from a brainwallet, or has a very strong password.)
However, at the time of the dust payments, someone did send 0.000546 btc to a bunch of *dictionary-generated* brainwallet addresses (not random) and swept them back a week later - take a look at the addresses generated by those words, "speculat-", that I mention, and plenty of others. That's weird. Like I say, I don't know why you'd do it that way - sweeping the funds straightaway if the address has anything in it, as you describe, makes more sense - but that's apparently what happened. That looks a lot like something sinister to me. If it was routine bot sweeping, they wouldn't have put btc in and they wouldn't all have come out the same week. The amount was also roughly (exactly?) 1c at those prices, which may or may not be coincidence.
One alternative is some kind of DoS attack. Around half the addresses on the blockchain (1.2 million) that have any funds in have only dust, which dates back to c. 2011. At the time the amounts would have been tiny; they're much more now (and I imagine the perpetrator would like them back). I wonder whether it was something similar?


Title: Re: Someone sending out MilliBits
Post by: Cassius on February 12, 2014, 05:55:57 PM
Ok: more suspiciously, 1SochiWwFFySPjQoi2biVftXn8NRPCSQC has just sent me 1 satoshi. Literally just now.
That probably means someone is screwing around, probably on this forum: saw my post and sent it almost straightaway.
Come on, people. If you're going to prank someone at least make it 0.1 bitcoins.


Title: Re: Someone sending out MilliBits
Post by: Mowcore on February 12, 2014, 06:17:16 PM
Now I've just been sochi/ enjoy 'd , cxnts!

Thought i'd got away from this bs..


Title: Re: Someone sending out MilliBits
Post by: hilariousandco on February 12, 2014, 06:20:07 PM
Ok: more suspiciously, 1SochiWwFFySPjQoi2biVftXn8NRPCSQC has just sent me 1 satoshi. Literally just now.
That probably means someone is screwing around, probably on this forum: saw my post and sent it almost straightaway.
Come on, people. If you're going to prank someone at least make it 0.1 bitcoins.

That happened to somebody else on here about ten minutes after they posted in one of the threads haha. Maybe just coincidence?


Title: Re: Someone sending out MilliBits
Post by: Voodah on February 13, 2014, 08:28:43 PM
I got 1Enjoy and 1Sochi today on my address posted on my sig (which I now removed) so they are definitely scraping from here, though probably not here alone.

Solution to not get tagged:

Quote
If you don't want some anonymous actor to know which addresses you control, it's best to get rid of those keys or move those dust transactions out of your wallet.

One way to do that is by using Dust-B-Gone. A script written by Peter Todd, one of the bitcoin core developers. It takes those transactions and sends them to his server where they are all combined and spent in a transaction with a 0btc output, effectively giving the dust to the miners.

If you are weary of connecting to his server directly, it has the option of connecting through TOR.

Dust-B-Gone can be found here: https://github.com/petertodd/dust-b-gone

I've used it myself not too long ago and works like a charm. You may have to set the dust limit to 0.001 BTC for it to find the transaction(s). You can run it initially as a dry run by specifying --dry-run and it'll show you a raw dump of the transaction it'll send out.

More information can be found here: https://bitcointalk.org/index.php?topic=317233.msg3413785#msg3413785


Title: Re: Someone sending out MilliBits
Post by: Ente on February 13, 2014, 10:58:42 PM
I got 1Enjoy and 1Sochi today on my address posted on my sig (which I now removed) so they are definitely scraping from here, though probably not here alone.

Solution to not get tagged:

Quote
If you don't want some anonymous actor to know which addresses you control, it's best to get rid of those keys or move those dust transactions out of your wallet.

One way to do that is by using Dust-B-Gone. A script written by Peter Todd, one of the bitcoin core developers. It takes those transactions and sends them to his server where they are all combined and spent in a transaction with a 0btc output, effectively giving the dust to the miners.

If you are weary of connecting to his server directly, it has the option of connecting through TOR.

Dust-B-Gone can be found here: https://github.com/petertodd/dust-b-gone

I've used it myself not too long ago and works like a charm. You may have to set the dust limit to 0.001 BTC for it to find the transaction(s). You can run it initially as a dry run by specifying --dry-run and it'll show you a raw dump of the transaction it'll send out.

More information can be found here: https://bitcointalk.org/index.php?topic=317233.msg3413785#msg3413785


Aww, I like this!
He didn't send the dust to himself, or back to the owner, or to a black hole, he send it to the miners!
Yep, I like this guy!

Ente


Title: Re: Someone sending out MilliBits
Post by: Hyena on February 18, 2014, 10:30:05 AM
My address received this strange transaction lately. However, that address has not been written anywhere so the attacker had to just discover it from the block chain I suspect. Another theory is that this is some kind of bitcoin terrorism. People who have nice round balances in their cold storage get them ruined.

There are some interesting public notes there:
Public Note: Hey, give me back my 20 Bitcoin

Public Note: If you are reading this, please take some time to remember those who died 12 years ago today in the WTC attacks

Public Note: Whoever you are, you're epic.

edit:
there's some more suspicious activity, look this address: https://blockchain.info/address/1AgesqfafUHHpAWnmjj9g6TVqBGXk4ixxg

A lot of coins are sent to all possible addresses that start with 1Ag

According to Mendelejev's table, silver is Ag.

ONE MORE THEORY:
What if the attacker has targeted just one address? However, to make it less threatening it has added a bunch of other random addresses to the formula? Then people such as myself who get disturbed by this activity start making posts to this thread and are immediately connected to their address by the forum user.

and one more:
Some of the destination addresses have spent their input except this suspicious input. Maybe the attacker tries to pin point automated wallets? So if the suspicious input remains unspent but other balance is spent then there could be some automation in place which could be abused with the transaction malleability vulnerability.


Title: Re: Someone sending out MilliBits
Post by: salstimda on February 18, 2014, 12:10:07 PM

omg thanks for the laugh :)


Title: Re: Someone sending out MilliBits
Post by: miragecash on February 18, 2014, 01:15:08 PM


God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Errr... whoever told you bitcoin is anonymous was joking, because that's funny. It may be anonymous to regular folks, but it is NOT anonymous to governments with really powerful computers. Your spending patterns are as unique to you as your fingerprints. Human beings are creatures of habit. Let's say that you hypothetically enjoy delivery Chinese food with expensive liquor while watching heavyweight championship boxing. Prior to getting involved with bitcoin, your credit card transactions show that these are your preferences. Now, you are trying to stay hidden and use "anonymous" bitcoins to make your purchases instead. There is going to be a world heavyweight boxing match tonight so you run out to the local liquor store and buy a bottle of Dom Perignon, go home, and then order some delivery Chinese food, all with bitcoin. Your government's computers pick up this spending pattern on the blockchain, hack into Mr. Wok's servers and BAM! They've just located you. Most merchants have their wallets with coinbase or bitpay to isolate themselves from exchange rate risk and messy tax filings. That's how the government gets their hands on most merchant's bitcoin wallet addresses.

Or you like French food, expensive liquor, and buy a lotto ticket every Friday night at your local convenience store. All they'd have to do to catch you is wait for you at the local convenience store on Friday night.

Or... you get the picture.

If you were religious, I'd say that bitcoin is the mark of the beast!


Title: Re: Someone sending out MilliBits
Post by: deeplink on February 18, 2014, 01:51:27 PM


God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Errr... whoever told you bitcoin is anonymous was joking, because that's funny. It may be anonymous to regular folks, but it is NOT anonymous to governments with really powerful computers. Your spending patterns are as unique to you as your fingerprints. Human beings are creatures of habit. Let's say that you hypothetically enjoy delivery Chinese food with expensive liquor while watching heavyweight championship boxing. Prior to getting involved with bitcoin, your credit card transactions show that these are your preferences. Now, you are trying to stay hidden and use "anonymous" bitcoins to make your purchases instead. There is going to be a world heavyweight boxing match tonight so you run out to the local liquor store and buy a bottle of Dom Perignon, go home, and then order some delivery Chinese food, all with bitcoin. Your government's computers pick up this spending pattern on the blockchain, hack into Mr. Wok's servers and BAM! They've just located you. Most merchants have their wallets with coinbase or bitpay to isolate themselves from exchange rate risk and messy tax filings. That's how the government gets their hands on most merchant's bitcoin wallet addresses.

Or you like French food, expensive liquor, and buy a lotto ticket every Friday night at your local convenience store. All they'd have to do to catch you is wait for you at the local convenience store on Friday night.

Or... you get the picture.

If you were religious, I'd say that bitcoin is the mark of the beast!


You're funny, thx for the laugh


Title: Re: Someone sending out MilliBits
Post by: citysin on June 04, 2014, 05:40:34 AM
Generate as many address/key pairs as you can, continuously, using any method you think someone else might employ to generate their future wallet. Flit some coins in and out to get it's address showing up in your coind. Set up a script to watch your wallets. You'll need a farm of them. There is going to be some bumps with millions of accounts in 1 wallet. Each wallet gets a daemon to track the balance of the wallet, if it increases, withdraw the funds. Script the creation of new wallet nodes, deploy, expand. wait. Maybe you get lucky, maybe you waste a few thousand a year on hosting and electricity for generating endless keypairs. As more people create/move/transact, more addresses get used, the likelihood of success with this type of method increases as the coin becomes more adopted, which likely would increase it's value. If you hit a lucky address, it would be quite worth the effort. You probably never will, but again, with rpc calls, image deployment, cheap plug computers and botnets and ever decreasing hosted compute/cheaper arms coming along, there's very little investment in just creating endless keypairs and hoping for a rich twin one day. People bet on long shots all the time. On occasion they get lucky.

Just my random thought.

I should probably add the point of my mind exercise was not to advise you to actually do this, but to encourage not using a 'method' in building something that should provide security based on obscurity. It might also encourage more people to investigate multisig addresses.


Title: Re: Someone sending out MilliBits
Post by: lewisg on June 04, 2014, 06:56:27 AM
Most newcomers can't mine because the bar is set too high but faucets pay in MilliBits.


Title: Re: Someone sending out MilliBits
Post by: Ente on June 04, 2014, 07:37:49 AM
Generate as many address/key pairs as you can, continuously, using any method you think someone else might employ to generate their future wallet. Flit some coins in and out to get it's address showing up in your coind. Set up a script to watch your wallets. You'll need a farm of them. There is going to be some bumps with millions of accounts in 1 wallet. Each wallet gets a daemon to track the balance of the wallet, if it increases, withdraw the funds. Script the creation of new wallet nodes, deploy, expand. wait. Maybe you get lucky, maybe you waste a few thousand a year on hosting and electricity for generating endless keypairs. As more people create/move/transact, more addresses get used, the likelihood of success with this type of method increases as the coin becomes more adopted, which likely would increase it's value. If you hit a lucky address, it would be quite worth the effort. You probably never will, but again, with rpc calls, image deployment, cheap plug computers and botnets and ever decreasing hosted compute/cheaper arms coming along, there's very little investment in just creating endless keypairs and hoping for a rich twin one day. People bet on long shots all the time. On occasion they get lucky.

Just my random thought.

I should probably add the point of my mind exercise was not to advise you to actually do this, but to encourage not using a 'method' in building something that should provide security based on obscurity. It might also encourage more people to investigate multisig addresses.

Possible, but not be best way.
1) It would be more efficient to hunt for already used addresses, as the older addresses have more coins than the addresses in the future.
2) You don't need to actually send funds to an address to "watch" it. You generate billions of addresses, and check in the blockchain if any of those has funds on.
3) It is completely senseless to "mine" for random addresses. It makes more sense to hunt for weak brainwallets.

The address space is 256 bit. This is what that means, practically:

http://www.bitcointrading.com/img/bitcoinwallpaper1.jpg

Ente


Title: Re: Someone sending out MilliBits
Post by: elrapido on July 12, 2014, 02:14:28 PM
Just got some on a few addresses, some even twice...has this mystery been solved yet?


Title: Re: Someone sending out MilliBits
Post by: Marty N. Gale on July 12, 2014, 02:17:42 PM
i'd like some more transactions from awesome addresses like 1Enjoy... and 1Sochi...
maybe something along the lines of 1Enjoy... 1Worldcup...  :D


Title: Re: Someone sending out MilliBits
Post by: Taras on July 13, 2014, 02:01:00 AM
I wonder why they're giving to random addresses like this.
I'd like to get some more millibits ;D


Title: Re: Someone sending out MilliBits
Post by: TheIrishman on July 13, 2014, 12:06:35 PM
I wonder why they're giving to random addresses like this.
I'd like to get some more millibits ;D

Totally agree. Man up and send me a few whole bitcoins already! :D


Title: Re: Someone sending out MilliBits
Post by: Fragan on July 13, 2014, 05:47:01 PM
topic is closed ?


Title: Re: Someone sending out MilliBits
Post by: Ente on July 13, 2014, 07:24:41 PM
topic is closed ?

https://c1.staticflickr.com/3/2727/4206982954_dc00d5e010.jpg

Ente


Title: Re: Someone sending out MilliBits
Post by: Skele on July 13, 2014, 08:36:33 PM
This is mysterious.  :o

And what stuff about Bitcoin isn't so mysterious ? Boom prices speculation oh yes...


Title: Re: Someone sending out MilliBits
Post by: AliceWonder on July 13, 2014, 08:48:15 PM
3) It is completely senseless to "mine" for random addresses. It makes more sense to hunt for weak brainwallets.

Maybe.

I have a theory that a lot of private addresses are created by taking sha256 sum repeatedly without additional salts.
I've seen that tactic used a lot with website password hashes - they salt the initial hash but then do X additional hashes without salting.
That's probably fine for passwords, because brute forcing the last hash to be hashed doesn't get you the password.

But with bitcoin if that is done, that means the final hash (all that matters) is done from a limited set of characters of known length.

So generating a random sha256 sum and then doing repeated rinse and repeats *may* boost your odds of a collission.

And while finding a weak brain-wallet might still be higher odds, weak brain-wallet is not likely to have much coins because there are lots of people constantly looking for them to empty. So a lot of the collisions will have 0 balance when you check.


Title: Re: Someone sending out MilliBits
Post by: Ente on July 14, 2014, 12:35:59 PM
..for me, that's just another brainwallet :-)
You take some human-compatible input and create a 254bit string from it. Most will use a simple sha256() for this, but a somewhat advanced harvesting-bot would also try several sha256(), reversing the string, doubling the dtring and hashing again, etc.
Regular brute-force alteration.

The lesson should be: "you only have as many bits in your final result as the complexity of the input and the algorithm". Just because the final string is 256bit long, doesn't mean much.

Ente


Title: Re: Someone sending out MilliBits
Post by: TimS on July 14, 2014, 02:44:55 PM
But with bitcoin if that is done, that means the final hash (all that matters) is done from a limited set of characters of known length.

So generating a random sha256 sum and then doing repeated rinse and repeats *may* boost your odds of a collission.
2^256 is a really, really big number, though. I really doubt this constitutes a feasible attack.

Let's make up some numbers to show you what I mean: let's say that people typically repeat their hash 1 million times, and there are a million such addresses in use. 1 million * 1 million ~= 2^40. This means there are 2^40 random sha256 hashes that, if you repeatedly hash them up to 1 million times, will result in you spending someone else's money. Unfortunately, there are 2^256-2^40 (or roughly 2^256) sha256 hashes that do not result in anything useful.


Title: Re: Someone sending out MilliBits
Post by: Ente on July 14, 2014, 03:43:27 PM
Big numbers, I like.

http://miguelmoreno.net/wp-content/uploads/2013/05/fYFBsqp.jpg

Ente


Title: Re: Someone sending out MilliBits
Post by: Zepher on September 21, 2014, 12:51:47 PM
My address received this strange transaction lately. However, that address has not been written anywhere so the attacker had to just discover it from the block chain I suspect. Another theory is that this is some kind of bitcoin terrorism. People who have nice round balances in their cold storage get them ruined.

There are some interesting public notes there:
Public Note: Hey, give me back my 20 Bitcoin

Public Note: If you are reading this, please take some time to remember those who died 12 years ago today in the WTC attacks

Public Note: Whoever you are, you're epic.

edit:
there's some more suspicious activity, look this address: https://blockchain.info/address/1AgesqfafUHHpAWnmjj9g6TVqBGXk4ixxg

A lot of coins are sent to all possible addresses that start with 1Ag

According to Mendelejev's table, silver is Ag.

ONE MORE THEORY:
What if the attacker has targeted just one address? However, to make it less threatening it has added a bunch of other random addresses to the formula? Then people such as myself who get disturbed by this activity start making posts to this thread and are immediately connected to their address by the forum user.

and one more:
Some of the destination addresses have spent their input except this suspicious input. Maybe the attacker tries to pin point automated wallets? So if the suspicious input remains unspent but other balance is spent then there could be some automation in place which could be abused with the transaction malleability vulnerability.

All those addresses that start with 1Ag are Casascius Silver 1BTC Coins.
I own a Casascius Silver/Gold 1BTC: 1Ag5rhfvXE1KYGypZQAujxt3aL2Dy15hUN, which also has dust ( 1 satoshi... ) on it from 1Sochi... No harm publishing the address now that it has already been messed with.
I also have a Titan Tenth 0.1BTC which had 0.00006BTC sent to it just 4 days after it was funded by Titan, sent from 1Enjoy. Now don't get me wrong, free BTC is nice, but it really pisses me off that these are on physical coins, hence I have absolutely no way to remove said dust to get it back to a nice round balance again. Frustrating  >:( If it had been sent to a wallet that I actually have 'access' to, then I'd laugh and remove the dust, and send it to the miners.

Anyone know if this will somehow devalue physical coins like Casascius/Titan/Lealana etc? Or whether it doesn't really make any difference?


Title: Re: Someone sending out MilliBits
Post by: Velkro on September 21, 2014, 01:30:41 PM
that spam is annoying but well.... what to do


Title: Re: Someone sending out MilliBits
Post by: bradleyb5155 on September 21, 2014, 03:30:15 PM
mmmm id love a MILlibit!!  ;D
1Cg2eGH1mAxoP6dNK6zt5MhPKBJGm5n9hv


Title: Re: Someone sending out MilliBits
Post by: mustang77 on September 21, 2014, 04:18:28 PM
Im getting a lot of trades of 0.00000001 or something from "fair cargo" or something like that . Weird


Title: Re: Someone sending out MilliBits
Post by: snappa4ever on September 22, 2014, 03:49:04 AM
mmmm id love a MILlibit!!  ;D
1Cg2eGH1mAxoP6dNK6zt5MhPKBJGm5n9hv
As much as this looks like spam at first glance, it is actually very well possible that this person would actually receive some amount of bitcoin to this address from laxo. I have google searched several "random" addresses that have had these transactions sent to and they all (that I have searched) have results that point back to this forum on the first or second result. As a result I would conclude that the addresses are being "mined" from posts on this forum