Bitcoin Forum
May 09, 2024, 05:44:39 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Double Spend on Pocket Dice  (Read 2704 times)
xetsr
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000


View Profile
July 22, 2015, 02:45:20 AM
 #21

The best way to avoid that problem is asking for 1 confirmation on all the depos, before any withdraw.  Wink

thats how the site works but the cheater is doing something to the coins when he was supposed to lost it all, double spending so the site wont recieve the lost coins like there is no deposit happened

No, you could start rolling with 0 confirmations, or did i miss something here? This is why almost EVERY dice site requires at least 1 confirmation before you can play.
In order to get the maximum amount of activity points possible, you just need to post once per day on average. Skipping days is OK as long as you maintain the average.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715233479
Hero Member
*
Offline Offline

Posts: 1715233479

View Profile Personal Message (Offline)

Ignore
1715233479
Reply with quote  #2

1715233479
Report to moderator
Derrike
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
July 22, 2015, 04:12:04 AM
 #22

I see there is also a mistake on the pocketdice side. Many bitcoin users know how to double spend zero confirmations with no fee transactions.
Pocket Dice (OP)
Sr. Member
****
Offline Offline

Activity: 342
Merit: 250



View Profile WWW
July 23, 2015, 12:23:15 PM
 #23

We're glad this thread appears to be so important and relevant for you. We appreciate all your feedbacks and solutions you've offered. Some of them were really helpful and effective. Right now we updated our system to make it more secure from any future attempts of hacking.

Of course we understand that the most effective way to fight double-spends is to require confirmation of EACH deposit. Though we always have to balance between providing world-class user experience on one side and security on another.

Once again, many thanks for your support!

arallmuus
Legendary
*
Offline Offline

Activity: 2534
Merit: 1404



View Profile WWW
July 23, 2015, 12:35:47 PM
 #24

-snip-

This issue and thread is pretty cloudy. Im not sure what you are trying to get in this thread since you put an example of yakuza attempted a double spend on your site and thus this thread was placed on scam accusation.

However no proof / data is presented about this and it appears you are more into looking for a suggestion on how this issue wont be repeated in the future ( if this is so then this thread should not be in scam accusation )
If truly yakuza attempted a double spend on your site then you should present the proof to back what you claimed ( this is a form of scamming as well since he supposed to lose the 71.38 BTC )

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
July 24, 2015, 05:38:15 AM
Last edit: July 24, 2015, 06:19:34 AM by Quickseller
 #25

Hello this morning I received a PM by BuyAreaCoins and he gave me this link https://www.reddit.com/r/Bitcoin/comments/3dygn9/double_spend_on_pocket_dice/.I was pretty shocked after reading it because who wouldn't when he is innocent.I am going to quote my self what I wrote on reddit.
Quote
Hello everyone, yakuza699 from bitcointalk.org here.I am going to be very straight forward and tell you that I was not involved with this at all.Why in the world would I choose same username on a site that I plan to attack?That just wouldn't make any sense.Though it is very interesting that he choose my username.Something special about it?Regarding trading or any kind of deals I don't really care if you trust me or not because I don't do a lot of trades and when I do I either use escrow or go first if I deal with trusted people.
Yakuza699 also tried sending a double-spend to repay his loan
Regarding that check this:
I would be weary about accept 0/unconfirmed transactions from this person.  
Not only with me but with everyone coins are not yours if they are unconfirmed.I knew(was not sure 100%) that that transaction will not confirm that is why I stated "If this tx doesn't confirm ask me to resend!" And that is what I just did.
https://blockchain.info/tx/162f89bbf6118bc06c2d26e6be5d1823b680f6f6c12b194bdaf3e568de2f3404
This time the transaction will confirmJust got confirmed. Sorry for all the inconvenience marco. I hope I don't have to take a loan ever again but if I do I will contact you.
It was an accident and I re-sent it.
Dude, it could not be more clear that you are behind this double spend attack. You should give back the BTC that you stole from pocket dice and give back the BTC that you stole from other casinos that similarly (stupidly) accept 0/unconfirmed deposits.

I have it on good authority that you were double spending against luckyb.it if you were not double spending against pocket dice. Furthermore there is a look of evidence that you were creating transactions designed to never confirm on their own.

Here you posted the address 12ZMT7Qn2rysM3XKxkSBrVfzdXXufoS13t and looking at the transaction history, you split up a single output of .4994BTC into over 90 outputs all to the same address, and all of roughly .0055BTC (in a single transaction with 0 fees attached to the transaction), and this would never have confirmed on it's own. You later consolidated these outputs to three outputs via 205d6967349a64d8f7c99deacfb5f37e733f5ec9a497f53d42afd03df48678c1 and then proceeded to make at least one bet with those new outputs that would never confirm on it's own. (there are other examples of this, however I think one should suffice)

In This thread, you were offering a 1 BTC bounty to pools who were willing to include transactions you give them in their found blocks. (this is somewhat circumstantial evidence against you, however it should certainly be taken info consideration). What you were asking for was essentially a way to be able to get double spend transactions confirmed and to get other low fee transactions confirmed when they shouldn't.

Here, you post about depositing 10 BTC to a site that accepts 0/unconfirmed deposits, gamble with that 10 BTC, and proceed to make over 4 BTC, all before the transaction confirms (you even say that it should confirm "in a few minutes" when you post that you will be withdrawing). People in that thread were suspicious of you, however there was little risk to you because if you lost then you would have simply double spent the transactions.

In this thread, you were told that creating a number of chained transactions will sometimes result in transactions that will be rejected by nodes other then blockchain.info (this is not exactly what you were doing above, however it did set the basis for your actions).

I have additional evidence against you, however I am going to keep that private for now.

tl;dr - do not accept a 0/unconfirmed transaction from yakuza699 and it is a bad idea to accept these kinds of transactions in general
DiamondCardz
Legendary
*
Offline Offline

Activity: 1134
Merit: 1112



View Profile WWW
July 24, 2015, 07:17:19 AM
 #26

Right now we updated our system to make it more secure from any future attempts of hacking.

No hacking took place here. Scamming - yeah, but no hacking took place. Yakuza exploited the ability to double-spend unconfirmed transactions and it hit you for a decent amount of money. I suggest you test double-spending against yourself so that you are 100% sure your system can't be double-spended against.

BA Computer Science, University of Oxford
Dissertation was about threat modelling on distributed ledgers.
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
October 04, 2015, 06:42:08 AM
 #27

It might be a good idea for others to be warned about both yakuza699 and amaclin who both have a history of executing double spend attacks on gambling websites.......
james.lent
Hero Member
*****
Offline Offline

Activity: 602
Merit: 501



View Profile
October 04, 2015, 07:39:19 AM
 #28

Probably the best thing to do (like most other casinos here) is to only allow deposit once it hits 1 confirmation.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!