Bitcoin Forum
June 28, 2024, 04:49:11 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Network Attack on XVG / VERGE on: April 07, 2018, 10:48:01 PM
I wonder what the reason is behind not freezing / blacklisting the malicious wallets. Seems odd. Also, the Dev thinks this attack is costing the "hacker" a lot of money. I'm not convinced that mining low difficulty blocks is very hard, hence the low difficulty.
2  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Network Attack on XVG / VERGE on: April 05, 2018, 08:15:52 AM


Hello,


The XVG wallet address you mentionned is UniMining XVG wallet. UniMining is a public pool where the miners mine together on a pool. All earnings that are generated by pool are sent to miners.

Can you show me some proofs that I am the attacker ? I'd like to understand the issue to prevent any wrong use of UniMining.

I complained also about this issue so I don't think that I'd be using my public pool to do this:
https://bitcointalk.org/index.php?topic=3256693.msg33927153#msg33927153

Thank you for ocminer help on this problem/attack,

Best Regards,


phm87

It appears that idolism made that post right when the attack stopped and doesn't realize how to identify the malicious blocks. All of the time stamps to your address appear to be legit, at a quick glance.
3  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Network Attack on XVG / VERGE on: April 05, 2018, 02:23:10 AM
Exploit is being abused rapidly right now. Anyone can check the block explorer to verify.
4  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Network Attack on XVG / VERGE on: April 04, 2018, 11:02:10 PM
we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?
5  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] [XSH] TOR/i2p, Quantum proof, MN, PoS/PoW, Fully ano, SHIELD on: April 04, 2018, 10:17:00 PM
Quick question, does Xsh suffer from the same exploit currently affecting Xvg?
6  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Network Attack on XVG / VERGE on: April 04, 2018, 10:08:31 PM
nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

how can we verify the hardfork ?

just download an updated wallet which includes the "fix" - then download the blockchain snapshot and try to sync up to the latest block...it will get stuck at 2007364

Confirmed.    client stalls at block 2007364


yeah we removed that, and we're doing a full fork update with extra block verifications. will be ready by tmrw =]

So are you saying the exploit can be used for the rest of the day with no repercussions?
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!