Bitcoin Forum
November 12, 2024, 02:07:37 AM *
News: Check out the artwork 1Dq created to commemorate this forum's 15th anniversary
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
Author Topic: Instawallet/Bitcoin-Central Security Breach  (Read 85336 times)
uuidman
Full Member
***
Offline Offline

Activity: 121
Merit: 100


View Profile
April 01, 2013, 08:09:30 PM
 #41

I might be confusing people, but isn't davout behind both instawallet and bitcoin-central, who also "detected a security breach"? https://bitcointalk.org/index.php?topic=164132.0


yep, and instawire.org which disappeared
for a while it was showing an error page with a list of all their directories. saw a lot of ruby gems there not good, anybody remember the insecure gems fiasco a few months ago?

No, I only remember that rails had problems and a lot of sites want quick enough, bad processes really. Is that what you referring to ? Or was is something else and bitcoin-related and I missed it.
Merralea
Full Member
***
Offline Offline

Activity: 126
Merit: 100



View Profile
April 01, 2013, 08:10:46 PM
 #42

Bitcoin users that trust nobody not affected.
Bitcoin users that trust nobody, but chose to move funds around at the worst time humanly possible, very much affected.
SgtSpike
Legendary
*
Offline Offline

Activity: 1400
Merit: 1005



View Profile
April 01, 2013, 08:11:57 PM
 #43

Well, this is interesting...
the founder
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
April 01, 2013, 08:12:16 PM
 #44

There might be good news to this,  the fact that they had bitcoins in cold storage in the first place to help repopulate what they lost might be a good sign.


Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
moni3z
Hero Member
*****
Offline Offline

Activity: 899
Merit: 1002



View Profile
April 01, 2013, 08:12:31 PM
 #45

Quote
I find it strange that the two big transactions at http://blockchain.info/address/1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy are still unconfirmed.  Any reason for this besides someone trying to spend coin that isn't there?

maybe the theif was too cheap to pay txn fees Smiley
beala
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
April 01, 2013, 08:13:04 PM
 #46

Someone on HN pointed out that the transfer happened an hour or two before the site went down. Can anyone confirm this? It looks like the transfer happened about an hour before *this thread* appeared, but did this thread start immediately after the site came down?

https://news.ycombinator.com/item?id=5475389
Nick
Jr. Member
*
Offline Offline

Activity: 57
Merit: 1


View Profile
April 01, 2013, 08:13:52 PM
 #47

Quote
I find it strange that the two big transactions at http://blockchain.info/address/1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy are still unconfirmed.  Any reason for this besides someone trying to spend coin that isn't there?

maybe the theif was too cheap to pay txn fees Smiley
Actually the tx fees are 0.10 BTC each. 10 USD!
keverw
Member
**
Offline Offline

Activity: 75
Merit: 10



View Profile WWW
April 01, 2013, 08:15:45 PM
 #48

Maybe the cold storage or some wallet got compromise, and they are moving it to a new wallet... Or maybe the owners of the site are pretending they were hacked, then cash out then go live on an island somewhere... Hard to tell really. Guess time will tell. I didn't use Instawallet but I have a feeling lots of newbies used it since its convenience.

Go open a whole new world with Visa Prepaid Bitcoin. More people go with, Visa Bitcoin.
Donate - BTC: 1giYNSkexV3vtqUPQZvGf9Nu1dfQ73VMZ
gbl08ma
Sr. Member
****
Offline Offline

Activity: 306
Merit: 250


Donations: http://tny.im/nx


View Profile WWW
April 01, 2013, 08:18:00 PM
 #49

You're supposed to cut+paste the bitcoin address your URL leads to so you can watch it with the blockchain.

That will do nothing but make users panic when they see value moving out of that address. The address Instawallet associates/associated with a certain URL is used only for depositing, increasing your balance in Instawallet's internal DB. Then once the money is throwed into the Instawallet system, it can be taken from these deposit addresses without the having the user send money out of the wallet. In other words, the balance of a Instawallet wallet is unrelated to the balance, verifiable with the blockchain, of the deposit address for that wallet.

Also, before Instawallet and Bitcoin Central went down, users had trouble sending money out - https://bitcointalk.org/index.php?topic=163918.0 . I already said this in another thread about this Instawallet security breach, but now I found the link to that thread. I think this has something to do with the hot wallet being empty - now who or what caused it to empty is another story... what do you think?

molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
April 01, 2013, 08:31:01 PM
 #50

Quote
I find it strange that the two big transactions at http://blockchain.info/address/1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy are still unconfirmed.  Any reason for this besides someone trying to spend coin that isn't there?

maybe the theif was too cheap to pay txn fees Smiley
Actually the tx fees are 0.10 BTC each. 10 USD!

hm, blockexplorer doesn't know about the large transactions: http://blockexplorer.com/address/1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
d5000
Legendary
*
Offline Offline

Activity: 4088
Merit: 7555


Decentralization Maximalist


View Profile
April 01, 2013, 08:34:33 PM
 #51

[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.

The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.

We thank you for your patience and will provide updates exclusively on this page as they come in. We are committed to resuming service as soon as possible. Expect normal service to resume within 48 hours.


----

Deep breath ...

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
the founder
Sr. Member
****
Offline Offline

Activity: 448
Merit: 251


Bitcoin


View Profile WWW
April 01, 2013, 08:40:25 PM
 #52

They failed to mention instawallet ?   Why?

Bitcoin RSS App / Bitcoin Android App / Bitcoin Webapp http://www.ounce.me  Say thank you here:  1HByHZQ44LUCxxpnqtXDuJVmrSdrGK6Q2f
steelboy
Hero Member
*****
Offline Offline

Activity: 756
Merit: 1000



View Profile
April 01, 2013, 08:40:55 PM
 #53

Does that include instawallet?

And is this user reliable?

twolifeinexile
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
April 01, 2013, 08:41:33 PM
 #54

[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.

The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.

We thank you for your patience and will provide updates exclusively on this page as they come in. We are committed to resuming service as soon as possible. Expect normal service to resume within 48 hours.


----

Deep breath ...
The wording "exclusive control" is also odd to me, sounds like someone steals it (internal employee?) and they discovered and force the guy give back the key?
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
April 01, 2013, 08:43:08 PM
 #55

I locked my thread https://bitcointalk.org/index.php?topic=164132.msg1717292#msg1717292 (about Bitcoin-Cetnral security breach) and told people to come here.

Injust, can you please change thread title to include "bitcoin central"?

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
pof
Full Member
***
Offline Offline

Activity: 204
Merit: 100


View Profile
April 01, 2013, 08:44:04 PM
 #56

[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.

The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.

We thank you for your patience and will provide updates exclusively on this page as they come in. We are committed to resuming service as soon as possible. Expect normal service to resume within 48 hours.


----

Deep breath ...

What's the site?

mccorvic
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500



View Profile
April 01, 2013, 08:44:22 PM
 #57

twolifeinexile, nahh it just means that they and only they control it. Could just as well say "it is our address".


But exclusive control sounds so much COOLER.

Offering Video/Audio Editing Services since 2011 - https://bitcointalk.org/index.php?topic=77932.0
Joost
Member
**
Offline Offline

Activity: 68
Merit: 10



View Profile
April 01, 2013, 08:44:51 PM
 #58

They sure kept us in a state of panic for a while there! Glad to see it's all working out fine Smiley

[Apr-1 10:30 CET] Bitcoin-Central and Paytunia update: Our customer's bitcoins and euros are safe and will not be affected by the security breach. We have taken the websites off-line for proper investigation.

The address 1LrPYjto3hsLzWJNstghuwdrQXB96KbrCy is under our exclusive control.

We thank you for your patience and will provide updates exclusively on this page as they come in. We are committed to resuming service as soon as possible. Expect normal service to resume within 48 hours.


----

Deep breath ...

What's the site?

It's showing up on https://bitcoin-central.net/

So far it hasn't appeared on Paytunia and Instawallet yet, but as the Instawallet transaction was to the same address I can only assume that those funds are safe as well.
lucb1e
Newbie
*
Offline Offline

Activity: 47
Merit: 0


View Profile WWW
April 01, 2013, 08:47:38 PM
 #59

either way the lesson will be "trust no one to hold your coins".
Seconded
uhoh
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


Circle gets the Square


View Profile
April 01, 2013, 08:49:37 PM
 #60

Glad this one has panned out OK (or will do once that transaction actually confirms)

As the value of bitcoin goes up, so does the amount (and the combined skillset) of hackers wanting to relieve people and business of coins. There is only so well prepared these companies can be, as seen by the social-engineering hack on BitInstant.
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!