Bitcoin Forum
May 24, 2024, 05:46:05 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 [31] 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 »
  Print  
Author Topic: Inputs.io | Instant Payments, Offchain API, Secure Wallet, 235k+ BTC transferred  (Read 158087 times)
niktitan132
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000



View Profile
November 05, 2013, 03:17:24 PM
 #601

just want to ask all reimbursed  or what is policy about this I lost 0.127 btc and its in my account for last 1 month

I lost 0.2445 BTC  Sad
mintmoney
Newbie
*
Offline Offline

Activity: 22
Merit: 0



View Profile
November 05, 2013, 04:25:49 PM
 #602

weird, I had an api-key enabled and no issues...

I hope you guys aren't setting your api key & pin variables directly in the code
(like in the callback example here: https://inputs.io/api#callbackexample )

hopefully TF gets the API back online soon  Huh  Grin

-Minty
californiablue
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
November 05, 2013, 08:46:34 PM
 #603

A full update will be posted soon, don't panic. Only people with the API key enabled was compromised (and will be reimbursed), passwords are securely stored one way in the database.

Security is obviously the most important thing to a Bitcoin wallet, and it's unfortunate that a compromise occurred, and we're learning a lot from it (things that pentests won't catch).

There will be a full update soon, but this compromise was not through a fault of the code but rather like a 'side channel' attack.

The attacker was able to empty the balance on accounts with the API key enabled. The issue is being actively looked upon. API access has been disabled.

Everyone who has lost money will be fully reimbursed.

Thank you TF. You're the best.  Cool Cool Cool Cool
harningt
Member
**
Offline Offline

Activity: 63
Merit: 10



View Profile
November 05, 2013, 09:01:58 PM
 #604

CoinLenders should probably have it's withdraw disabled - I withdrew and found nothing shows up in my Inputs.IO wallet... then I come and look and the API is disabled. (which is probably why the deposit part didn't take effect)

CoinLenders should probably have caught some sort of error and not deducted my balance... hopefully this item is easy to fix and get balances right!

My luck is not too good these days - lose some BTC to an "auto-refund" by Coinbase and now to API key for CoinLenders...
flmbg
Member
**
Offline Offline

Activity: 81
Merit: 10


View Profile
November 06, 2013, 01:02:53 AM
 #605

CoinLenders should probably have it's withdraw disabled - I withdrew and found nothing shows up in my Inputs.IO wallet... then I come and look and the API is disabled. (which is probably why the deposit part didn't take effect)

CoinLenders should probably have caught some sort of error and not deducted my balance... hopefully this item is easy to fix and get balances right!

My luck is not too good these days - lose some BTC to an "auto-refund" by Coinbase and now to API key for CoinLenders...

I agree with your suggestion. I withdraw 5 BTC yesterday from Coinlenders and they never show up in inputs. I've sending email to TF and not receive any reply for this. This might be a serious problem for all of us.
marketorder
Sr. Member
****
Offline Offline

Activity: 375
Merit: 250


View Profile
November 06, 2013, 01:33:26 AM
 #606

Has anyone got any updates yet? I've moved my money to cold storage until this is resolved. I'm confident TF will fix everything 
Financisto
Hero Member
*****
Offline Offline

Activity: 632
Merit: 768

BTC⇆⚡⇄BTC


View Profile WWW
November 06, 2013, 02:36:48 AM
 #607

Why is my "hotpocket empty"?

Same happened here.

Have all (or most of) funds from "hot wallets" been removed to cold storage?

LIST • ESCROW providers • Ranking & Scores available!LIST • FOSS BrainwalletsBTC ⇆⚡⇄ BTCBTC aka BTC: 16MBvhaJoRBxW3Vk6apnvz3UYT9HAgraVS ⚡ PGP: 2680207AA9A1B69FE7A033D80DE0F221074384C4 ⚡ If you think freedom matters, please support the development of these privacy projects→DONATE some sats: TailsQubes OSWhonixVeraCryptPicocryptKryptorSimpleX Chat
bitcoindigi
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
November 06, 2013, 09:10:15 AM
 #608

Why is my "hotpocket empty"?

Same happened here.

Have all (or most of) funds from "hot wallets" been removed to cold storage?

First: it's not your hot pocket, it's inputs'.

I guess TF moved all coins to a secure cold wallet until he fixed the security breaches.

So calm down and use electrum to keep huge amounts next time Smiley
cozie
Sr. Member
****
Offline Offline

Activity: 261
Merit: 250


View Profile
November 06, 2013, 11:33:53 AM
Last edit: November 06, 2013, 11:50:56 AM by cozie
 #609

i try to withdraw 0.5 btc, inputs.io say "Sent!" but he is not, trxid generated not exist and ofc my balance is now with -0.5005 btc Angry

[edit]
all ok, transaction show up after some time
[/edit]
btcton
Legendary
*
Offline Offline

Activity: 1288
Merit: 1007


View Profile
November 06, 2013, 11:51:05 AM
 #610

Yeah, you really have to calm down. Leaving all your BTC in the same wallet isn't a very good idea. Anyway, I'm sure TF is working harder than you may think to solve this.

The signature campaign posters adding useless redundant fluff to their posts to reach their minimum word count are lowering my IQ.
pinovero
Member
**
Offline Offline

Activity: 176
Merit: 10

The World’s First Blockchain Core


View Profile
November 06, 2013, 12:06:13 PM
 #611

I suspect that this could be a faucet code issue and not a inputs.io problem

This hacker may be targeting sites that surely would have had an input.io account with API enabled, looking for vulnerability, trying to obtain read privileges of the config.php in which almost all current faucet keep it in plain API key and pin codes

I've also found a strange activity on my site and services overflow attempts, but without any success

▄▄▄▄▄▄▄▄▄▄▄ ▄ ■        SKYNET        ■ ▄ ▄▄▄▄▄▄▄▄▄▄▄
▐▬▬▬▬▬▬▬▬▬▬     PRIVATE SALE is LIVE     ▬▬▬▬▬▬▬▬▬▬▌
Whitepaper   Bounty   Bitcointalk  ■  Facebook   Twitter   Telegram
js1985
Full Member
***
Offline Offline

Activity: 229
Merit: 101


View Profile
November 06, 2013, 12:26:21 PM
 #612

Why is my "hotpocket empty"?

Same happened here.

Have all (or most of) funds from "hot wallets" been removed to cold storage?

First: it's not your hot pocket, it's inputs'.

I guess TF moved all coins to a secure cold wallet until he fixed the security breaches.

So calm down and use electrum to keep huge amounts next time Smiley

Any news from TF?
JohnHarmer
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile WWW
November 06, 2013, 01:09:27 PM
 #613

Why is my "hotpocket empty"?

Same happened here.

Have all (or most of) funds from "hot wallets" been removed to cold storage?

First: it's not your hot pocket, it's inputs'.

I guess TF moved all coins to a secure cold wallet until he fixed the security breaches.

So calm down and use electrum to keep huge amounts next time Smiley

Any news from TF?

No, and when i withdraw from input.io, got "hotpocket empty"

TradeFortress|吴泽岳's profile:www.wuzeyue.org
吴泽岳要钱要命你自己选,不信你就等着
gaston909
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250



View Profile
November 06, 2013, 02:21:55 PM
 #614

Yes, calm is the only way here. If you can't be calm, don't trust external sites with you btc.

Take care of them yourself.
JohnHarmer
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile WWW
November 06, 2013, 03:00:08 PM
 #615

Googled "side channel", it is said its Xen's hole.
input.io use aws, and aws is base on Xen.

so , maybe TF is busing moving input.io from aws to some physical machine.
That's why it took so long.


TradeFortress|吴泽岳's profile:www.wuzeyue.org
吴泽岳要钱要命你自己选,不信你就等着
devthedev
Legendary
*
Offline Offline

Activity: 1050
Merit: 1004



View Profile
November 06, 2013, 03:21:05 PM
 #616

I suspect that this could be a faucet code issue and not a inputs.io problem

This hacker may be targeting sites that surely would have had an input.io account with API enabled, looking for vulnerability, trying to obtain read privileges of the config.php in which almost all current faucet keep it in plain API key and pin codes

I've also found a strange activity on my site and services overflow attempts, but without any success

Yep, makes sense.

christmas
Newbie
*
Offline Offline

Activity: 45
Merit: 0


View Profile
November 06, 2013, 03:31:25 PM
 #617

Googled "side channel", it is said its Xen's hole.
input.io use aws, and aws is base on Xen.

so , maybe TF is busing moving input.io from aws to some physical machine.
That's why it took so long.




hope so
high110
Sr. Member
****
Offline Offline

Activity: 728
Merit: 253


A Blockchain Mobile Operator With Token Rewards


View Profile
November 06, 2013, 04:00:06 PM
 #618

I haven't lost any money - but I just need to move some around.  If you can let me know the soonest when I can do this...thanks! Just 2 BTC...

              ███
             █████
            ███████
           █████████
          ███████████
         █████████████
        ███████ ███████
       ███████   ███████
      ███████     ███████
     ███████       ███████
    ███████         ███████
   ███████           ███████
  ███████             ███████
 █████████████████████████████
███████████████████████████████
.
M!RACLE TELE
BRINGING MAGIC
TO THE TELECOM INDUSTRY

██
██
██
██
██
██
██
██
██
██
40% Biweekly Rewards
▬▬▬   Calls at €0.2   ▬▬▬
Traffic from €0.01 worldwide

██
██
██
██
██
██
██
██
██
██
      ██         ██     
        ▀▌     ▐▀       
       ▄██▄▄▄▄▄██▄      
     ▄█████████████     
   ▄█████████████████▄   
  ██████▄██████▄██████  
 ▐█████████████████████▌
  ██████▀███████▀██████ 
  █████   █████   █████  
  █████████████████████  
  █████████████████    
    ███████████████    
 ▀██▄ ████████████  ▄██▀
      ▀██▀   ▀██▀   
       ▄█       █▄
ANN
Lightpaper
Bounty
Facebook
Twitter
Telegram
knowitnothing
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
November 06, 2013, 04:22:47 PM
 #619

Googled "side channel", it is said its Xen's hole.
input.io use aws, and aws is base on Xen.

This is very misleading. Side channel attack is a whole group of attacks, but this term is commonly used when talking about cryptography (please see https://en.wikipedia.org/wiki/Side_channel_attack, and in the rare event that you are really into it http://www.sidechannelattacks.com/a.aspx).

I can't think of any reason why someone would say this was a side channel attack (actually, sic: "like a 'side channel' attack"), except to disguise the shame of the actual bug(s) found that won't be properly disclosed. It's time to get honest and drop the text about "most secure wallet ever created".
Injust
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
November 07, 2013, 12:33:06 AM
 #620

This doesn't look good, https://inputs.io shows this message.

Quote
404 BTC not found

Two hacks have left Inputs unable to pay

Woah, this admittedly IS looking bad now Sad TradeFortress, please give us an update?
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 [31] 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!