pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 20, 2017, 01:32:51 PM |
|
btc38 say: xcn bye bye
I don't think so: btc38 updated their wallet and opened withdrawals. I think they will open deposits soon. No, the deposit button says "please understand announcement" which you can find here http://www.btc38.com/news/2017/9/15418.html saying they will close all trading, means they won't allow deposit, only withdraw so people get their coins back and then will suspend it. Why is this coin not listed on YoBit? It's not so hard to get there, you need to look at the future and focus on other exchanges. Even dev thinks this coin will live because of Chineese investors like before, but understand that it won't be possible anymore due to this suspension. Correct me if I'm wrong. I don't know how this chinese thing will end up, but I can say we are in contact with bittrex and poloniex to have the coin listed there. Unfortunately they are both very busy, at least that's what they use to say.
|
|
|
|
dimafatality
Newbie
Offline
Activity: 23
Merit: 0
|
|
September 20, 2017, 01:42:10 PM |
|
Yobit: https://yobit.net/en/addcoin/To add a new coin to Yobit please you need to fill out the form below. Payment method: YobiCode Listing type: • Free - 0.00 btc - no guarantee • Premium - 0.1 btc - 4-7 business days (no guarantee in case of compilation issues) • Exclusive - 0.5 btc - 2-3 business days (no guarantee in case of compilation issues)
Let's donate to pallas btc address and buy premium for 0.1 btc. Worth a try.
|
|
|
|
_javi_
|
|
September 20, 2017, 01:44:28 PM |
|
Pallas.. something about the windows wallet: 1) it would be nice to be able to select the number of currency decimals to show. 10 digits for decimals makes no sense.. 2) settings-options-wallet.. i see "Expert" at the bottom of the window but its not clickeable.
|
|
|
|
arvin777
Member
Offline
Activity: 196
Merit: 15
|
|
September 21, 2017, 03:52:50 AM |
|
service staff 小丹: Hello! I'm sorry to have kept you waiting, this a few money can get a new integral reward money TAG, RIC, Riemann currency QRK quark currency, world coin WDC, makar currency MEC, ingots COINS YBC, kryptonite currency XCN, little money more than PPC and the earth EAC, energy currency HLB currencies will stop at 12 noon on September 21, trade, system will reserve currency time 7 days, on September 28, please will you digital assets held by the extract to the personal wallet or other platforms. We later will have partial stop trading of other currencies, estimated around October 31 all stop, details please check the announcement, http://www.btc38.com/news/2017/9/15477.htmlThank you for your support and wish you a happy life. (09-21 10:28) about this ticket, you feel: good | ordinary | bad
|
XCN wallet:
|
|
|
bitfreak!
Legendary
Offline
Activity: 1536
Merit: 1000
electronic [r]evolution
|
|
September 21, 2017, 08:08:09 AM Last edit: September 21, 2017, 09:58:11 AM by bitfreak! |
|
Ok guys now the main pool and many exchanges have updated to the new version I feel it's safe to release more information about exactly what happened. Unfortunately it looks like btc38 is going to remove XCN based on that announcement. Btc38 were the ones who first realized something was wrong because they had a suspiciously high number of XCN in their exchange wallet. They notified us there was something wrong a few days ago and I coded up a blockchain analyzer to look for anything suspicious. I discovered that an attacker found a way to create transactions with outputs larger than the inputs, allowing the attacker to essentially create free coins. The first example of the attack can be seen in this block: http://xcn-explorer.selektion21.de/?b=1007085They were able to generate a negative fee value because of an integer overflow bug, making it possible to have outputs larger than the input value. Obviously there were checks for integer overflows in place but some integers which should have been unsigned were left signed in the worst place possible, either intentionally or by simple mistake, by the original dev. It looks like the attacker spent most of the smaller outputs and left the massive outputs alone, the latest version should block those massive balances but I calculated they were able to get away with around 260 million XCN from the smaller outputs. We gave btc38 and other exchanges a list of the addresses used by the attacker so they may have been able to freeze some of the attackers funds, based on my analysis it doesn't seem like there's a whole lot of transactions stemming off from the bad transactions. I also want to make it clear this bug has nothing to do with the mini-blockchain technology, the bug in the code was pretty obvious and quite easy to fix just by making some signed integers unsigned. Look at the latest changes on pallas's github to see exactly what we did to prevent this happening again. In a few days I will release the source code for an XCN blockchain analyzer that I made to find the issue, it should also be useful for building an explorer that works efficiently. I will also release the javascript code I wrote some time ago for creating raw transactions and signing them, which I used to make sure our fix worked and should also be useful for creating a web wallet. Hopefully we can move past this even without too much issue, I was hoping our quick fix would be enough for btc38 not to drop XCN but I cannot blame them for being spooked by this, especially with the new laws in China. The following is a list of blocks where the exploit was detected: 1007085, 1009490, 1035837, 1044220, 1052967, 1073572, 1103770, 1119219, 1139944, 1171685, 1188258, 1232798, 1246249, 1255968, 1271558, 1274983, 1278864, 1279894, 1281781, 1284716, 1286093, 1288597, 1290084, 1291824, 1294633, 1297819, 1298379, 1300671, 1302547, 1320111, 1320830, 1322596, 1323220, 1350726, 1360510, 1363161, 1364581, 1366301, 1366351, 1367675, 1369704, 1371786, 1373205, 1375144, 1377644
|
XCN: CYsvPpb2YuyAib5ay9GJXU8j3nwohbttTz | BTC: 18MWPVJA9mFLPFT3zht5twuNQmZBDzHoWF Cryptonite - 1st mini-blockchain altcoin | BitShop - digital shop script Web Developer - PHP, SQL, JS, AJAX, JSON, XML, RSS, HTML, CSS
|
|
|
pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 21, 2017, 08:11:21 AM |
|
service staff 小丹: Hello! I'm sorry to have kept you waiting, this a few money can get a new integral reward money TAG, RIC, Riemann currency QRK quark currency, world coin WDC, makar currency MEC, ingots COINS YBC, kryptonite currency XCN, little money more than PPC and the earth EAC, energy currency HLB currencies will stop at 12 noon on September 21, trade, system will reserve currency time 7 days, on September 28, please will you digital assets held by the extract to the personal wallet or other platforms. We later will have partial stop trading of other currencies, estimated around October 31 all stop, details please check the announcement, http://www.btc38.com/news/2017/9/15477.htmlThank you for your support and wish you a happy life. (09-21 10:28) about this ticket, you feel: good | ordinary | bad effect of the new chinese regulation. we will just move to another exchange. you can already use novaexchange or you can wait for bittrex and/or poloniex (or any other that will come).
|
|
|
|
gnasirator
|
|
September 21, 2017, 08:35:13 AM |
|
Great work, bitfreak and pallas for fixing this! I think this is all part of the maturing process for the coin. We all know what we're up to and the end goal should be a stable, usable currency for the general public.
Sad too though, because we all also want to profit from the effort we all put into this coin in the long run. And this might scare off other people for the moment. Nevertheless, let's remember why we're all here: XCN has a unique set of features that makes it stand out. And that technology is still there, even better now.
Let's move forward and decide on how to deal with the unwanted coins that are now circulating the system. Are they any harm?
|
XCN: CJSECkHi7tTTTA1ze9qYRkkUCKfFiF8EEG
|
|
|
pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 21, 2017, 08:49:10 AM |
|
Great work, bitfreak and pallas for fixing this! I think this is all part of the maturing process for the coin. We all know what we're up to and the end goal should be a stable, usable currency for the general public.
Sad too though, because we all also want to profit from the effort we all put into this coin in the long run. And this might scare off other people for the moment. Nevertheless, let's remember why we're all here: XCN has a unique set of features that makes it stand out. And that technology is still there, even better now.
Let's move forward and decide on how to deal with the unwanted coins that are now circulating the system. Are they any harm?
Most of the hacked funds should be locked now, but a little part of them got into circulation and we can't do anything about them, because we would risk harming honest users. The final effect is a higher current supply: about 260M more, but it depends if the hacker will move those funds and if part of them got locked on the exchanges; probably accessible surplus is less.
|
|
|
|
cyborgx
Newbie
Offline
Activity: 23
Merit: 0
|
|
September 21, 2017, 11:17:10 AM |
|
Why is there no update on your website under Project Developer News since 2014 ?!
|
|
|
|
bitfreak!
Legendary
Offline
Activity: 1536
Merit: 1000
electronic [r]evolution
|
|
September 21, 2017, 11:45:26 AM |
|
Why is there no update on your website under Project Developer News since 2014 ?!
Most updates are made on this thread, Twitter, Slack, etc. I never really update the website except for the download page. I might just remove that page and a few others actually. I'm just very busy with several other projects which is why I'm not around much and why Pallas handles most Cryptonite stuff these days.
|
XCN: CYsvPpb2YuyAib5ay9GJXU8j3nwohbttTz | BTC: 18MWPVJA9mFLPFT3zht5twuNQmZBDzHoWF Cryptonite - 1st mini-blockchain altcoin | BitShop - digital shop script Web Developer - PHP, SQL, JS, AJAX, JSON, XML, RSS, HTML, CSS
|
|
|
abudfv2008
|
|
September 21, 2017, 12:01:22 PM |
|
1) It looks like the attacker spent most of the smaller outputs and left the massive outputs alone, the latest version should block those massive balances but I calculated they were able to get away with around 260 million XCN from the smaller outputs. 2) I also want to make it clear this bug has nothing to do with the mini-blockchain technology, the bug in the code was pretty obvious and quite easy to fix just by making some signed integers unsigned. Look at the latest changes on pallas's github to see exactly what we did to prevent this happening again.
1) 260ml is much. Even at 100satishi price. 2) It's not a good sign that "obvious" bugs are corrected with such price.
|
|
|
|
pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 21, 2017, 12:06:24 PM |
|
1) It looks like the attacker spent most of the smaller outputs and left the massive outputs alone, the latest version should block those massive balances but I calculated they were able to get away with around 260 million XCN from the smaller outputs. 2) I also want to make it clear this bug has nothing to do with the mini-blockchain technology, the bug in the code was pretty obvious and quite easy to fix just by making some signed integers unsigned. Look at the latest changes on pallas's github to see exactly what we did to prevent this happening again.
1) 260ml is much. Even at 100satishi price. 2) It's not a good sign that "obvious" bugs are corrected with such price. 1) as we said, that's the ceiling and we don't know how much of those funds are really accessible by the hacker, the real amount may be much less. 2) it's obvious when you know what it is :-) bitfreak had to create a blockchain analysis tool from scratch to detect the problematic blocks, then we had to find which bug in the code permitted such wrong blocks/transactions, then we had to fix it, then we had to make a tool to create raw transactions on testnet to see if the hole was in fact closed, etc. etc.
|
|
|
|
arvin777
Member
Offline
Activity: 196
Merit: 15
|
|
September 21, 2017, 02:05:16 PM |
|
Many of those 260m probably sold in btc38. That's explains dumps of past days. What you guys wanna do about that?
And any of you tried to withdraw xcn in btc38? I can't do that . When I press withdraw bottom page goes to btc withdraw not xcn.
|
XCN wallet:
|
|
|
pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 21, 2017, 02:17:18 PM |
|
Many of those 260m probably sold in btc38. That's explains dumps of past days. What you guys wanna do about that?
And any of you tried to withdraw xcn in btc38? I can't do that . When I press withdraw bottom page goes to btc withdraw not xcn.
We provided the exchanges with the offending addresses. What they do I don't know nor can force them to do anything.
|
|
|
|
Bilbo Bagacoins
Newbie
Offline
Activity: 40
Merit: 0
|
|
September 21, 2017, 05:37:10 PM |
|
Many of those 260m probably sold in btc38. That's explains dumps of past days. What you guys wanna do about that?
And any of you tried to withdraw xcn in btc38? I can't do that . When I press withdraw bottom page goes to btc withdraw not xcn.
We provided the exchanges with the offending addresses. What they do I don't know nor can force them to do anything. Could a burn address be created and get the exchanges to send locked coins to it? This address is still showing astronomical amounts of coins??? CVPaxGgsteGgucAnzmA7EeTj5hzaLCfb7o
|
|
|
|
pallas (OP)
Legendary
Offline
Activity: 2716
Merit: 1094
Black Belt Developer
|
|
September 21, 2017, 05:47:57 PM |
|
Many of those 260m probably sold in btc38. That's explains dumps of past days. What you guys wanna do about that?
And any of you tried to withdraw xcn in btc38? I can't do that . When I press withdraw bottom page goes to btc withdraw not xcn.
We provided the exchanges with the offending addresses. What they do I don't know nor can force them to do anything. Could a burn address be created and get the exchanges to send locked coins to it? This address is still showing astronomical amounts of coins??? CVPaxGgsteGgucAnzmA7EeTj5hzaLCfb7o That's btc38 address. We can't block it because it contains funds of honest users as well.
|
|
|
|
kabi123
|
|
September 21, 2017, 06:05:41 PM |
|
meeeh this coins is just done...if u wanna safe coin algorit, its bether to start with new coin and new hipe P. 2many problems with this coin...trust is just lost...
|
|
|
|
Bilbo Bagacoins
Newbie
Offline
Activity: 40
Merit: 0
|
|
September 21, 2017, 06:21:54 PM |
|
Many of those 260m probably sold in btc38. That's explains dumps of past days. What you guys wanna do about that?
And any of you tried to withdraw xcn in btc38? I can't do that . When I press withdraw bottom page goes to btc withdraw not xcn.
We provided the exchanges with the offending addresses. What they do I don't know nor can force them to do anything. Could a burn address be created and get the exchanges to send locked coins to it? This address is still showing astronomical amounts of coins??? CVPaxGgsteGgucAnzmA7EeTj5hzaLCfb7o That's btc38 address. We can't block it because it contains funds of honest users as well. Not block it, get them to send the known "fake / stolen " coins to a know burn address and take them out of circulation.
|
|
|
|
Bilbo Bagacoins
Newbie
Offline
Activity: 40
Merit: 0
|
|
September 21, 2017, 06:26:00 PM |
|
meeeh this coins is just done...if u wanna safe coin algorit, its bether to start with new coin and new hipe P. 2many problems with this coin...trust is just lost...
Valid point.
|
|
|
|
reb0rn21
Legendary
Offline
Activity: 1901
Merit: 1024
|
|
September 21, 2017, 06:34:04 PM |
|
Dumped whole month of mining at least have to pay electricity burned
|
|
|
|
|