Bitcoin Forum
November 12, 2024, 02:39:35 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Someone sending out MilliBits  (Read 16401 times)
itod
Legendary
*
Offline Offline

Activity: 1974
Merit: 1077


^ Will code for Bitcoins


View Profile
January 07, 2014, 10:38:18 PM
 #21

God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Don't know which risk you are talking about. Bitcoin addresses which send and receive coins are in permanent public record. There are also connected to their inputs and outputs. You have to understand there are no "coins" like in the physical world, each coin is permanently destroyed when it completely becomes an input for another coin, but the record of it's previous existence remains forever. Two inputs of a new coin become tied to each other in that new coin, until that coin's output become's input to yet another one.

All those inputs and outputs have not only BTC amounts, but also sending address of the output and receiving address of the input in the blockchain record.

Keep in mind that sum of inputs and the outputs of each transaction have to be equal, and since there's a slim chance you have the exact amount in one "coin" you wan't to send to another address, in majority of cases your output have to be tied to your another coin's output to make enough for a transaction, and the change of the transaction goes to your new "coin" as it's input. This eternal multiple inputs/multiple outputs game is the reason for this dust to be sent, as a sender hopes to trace it's outputs for a long time until he figures out where it eventually ended.

There is in no way to connect a BTC address to a personal identity, but i'ts enough that you have leaked a single tie of some address to your identity, and this dust's output to become a new coin owned by an address in the same wallet as this leaked address, these old coins will also be tied to that leaked identity.

Also, keep in mind that your IP address is somewhere in the private record of you ISP provider. Each time your provider assigns a dynamic IP address to your home router, or static IP address to your business, it logs which IP address went to which customer. Those logs can be obtained in all countries with the court order, and in some countries even without the court order. The reason why I'm mentioning this is a possibility that your peers, when you send a BTC transaction, my log the IP which sent them the transaction. In most cases you are not connected to a peer who does such a thing, but even if you are, those "nasty" peers my get the IP of the peer that relayed the transaction, not the peer that originated it, so they can never be sure if they got the IP address of the originator right. You can make sure that your IP will never be logged, but it's far from easy, and the guys that need such a things know how to do it.

When you know these facts you are safe and there is no risk in using Bitcoin, just behave appropriately. There are recommended polices you should stick to, start with never reusing the BTC address without the great need to do so. This policy was recommended for a whole another reason (not to expose the public key, just a hash of it instead), but is very useful for keeping your transactions and addresses harder to tie together. This forum post is not adequate for all of these policies, but you can find them all over this forum.
Cassius
Legendary
*
Offline Offline

Activity: 1764
Merit: 1031


View Profile WWW
February 12, 2014, 05:04:08 PM
 #22

Another theory. I'm not sure about this: just want to run it up the flagpole and see who salutes it.
If you look at brainwallets, you'll see that they can be incredibly insecure. A lot of people treat them like email and use bad passwords. It makes them vulnerable to people guessing them.
What if you used a dictionary to generate private keys and addresses, then sent a small amount of bitcoins - say 0.0000546 - to each address. A week later you run the same script and hoover up your coins, plus any others that happen to be sitting in an address you have 'guessed' right.
I don't know why you'd do it this way. Maybe you're a lazy coder, or something. But that appears to be what someone has done. Do a brainwallet address search for speculator, speculating, spectator, spectacles, etc, and you'll see what I mean. 0.0000546 bitcoins goes into the account, a week later out it goes. Looks like someone is running dictionary attacks with words over a certain length.
(Just so we're clear, I found this out through research into brainwallets and general curiosity, not to steal bitcoins from badly-secured wallets. I can't prove this but suffice to say I probably wouldn't post this warning if I was. Smiley )

*** People who have received dust payments: are you using a brainwallet? If so, consider it insecure and move your coins ASAP. ***

Like I said, not sure whether this is right or not. But something weird is going on with dictionary-generated brainwallet addresses.
Alternatively, I'd love to know any other theories as to why someone would send 0.0000546 bitcoins to a bunch of dictionary addresses.... any answers?
Ente
Legendary
*
Offline Offline

Activity: 2126
Merit: 1001



View Profile
February 12, 2014, 05:23:34 PM
 #23

Another theory. I'm not sure about this: just want to run it up the flagpole and see who salutes it.
If you look at brainwallets, you'll see that they can be incredibly insecure. A lot of people treat them like email and use bad passwords. It makes them vulnerable to people guessing them.
What if you used a dictionary to generate private keys and addresses, then sent a small amount of bitcoins - say 0.0000546 - to each address. A week later you run the same script and hoover up your coins, plus any others that happen to be sitting in an address you have 'guessed' right.
I don't know why you'd do it this way. Maybe you're a lazy coder, or something. But that appears to be what someone has done. Do a brainwallet address search for speculator, speculating, spectator, spectacles, etc, and you'll see what I mean. 0.0000546 bitcoins goes into the account, a week later out it goes. Looks like someone is running dictionary attacks with words over a certain length.
(Just so we're clear, I found this out through research into brainwallets and general curiosity, not to steal bitcoins from badly-secured wallets. I can't prove this but suffice to say I probably wouldn't post this warning if I was. Smiley )

*** People who have received dust payments: are you using a brainwallet? If so, consider it insecure and move your coins ASAP. ***

Like I said, not sure whether this is right or not. But something weird is going on with dictionary-generated brainwallet addresses.
Alternatively, I'd love to know any other theories as to why someone would send 0.0000546 bitcoins to a bunch of dictionary addresses.... any answers?

Good theory - but unprobable because of two things:

1) you can, as a "brainwallet harvester", create random private keys, calculate the public address to this, and look up on the blockchain if there is any money on that. If yes - sweep it away immediately. All public addresses with funds on them would be in a huge database, everything would be done completely offline.

2) because of this, more generally speaking:



3) bonus: I received dust, it was on an address I published somewhere, on the forums or something like that. Unrelated: I did a test and sent a small amount to a brainwallet address with a weak passphrase. It was sweeped like some hours later.

Ente
Cassius
Legendary
*
Offline Offline

Activity: 1764
Merit: 1031


View Profile WWW
February 12, 2014, 05:51:19 PM
 #24

Thanks for the reply. That's good to know (I'm assuming your address that got dust was not generated from a brainwallet, or has a very strong password.)
However, at the time of the dust payments, someone did send 0.000546 btc to a bunch of *dictionary-generated* brainwallet addresses (not random) and swept them back a week later - take a look at the addresses generated by those words, "speculat-", that I mention, and plenty of others. That's weird. Like I say, I don't know why you'd do it that way - sweeping the funds straightaway if the address has anything in it, as you describe, makes more sense - but that's apparently what happened. That looks a lot like something sinister to me. If it was routine bot sweeping, they wouldn't have put btc in and they wouldn't all have come out the same week. The amount was also roughly (exactly?) 1c at those prices, which may or may not be coincidence.
One alternative is some kind of DoS attack. Around half the addresses on the blockchain (1.2 million) that have any funds in have only dust, which dates back to c. 2011. At the time the amounts would have been tiny; they're much more now (and I imagine the perpetrator would like them back). I wonder whether it was something similar?
Cassius
Legendary
*
Offline Offline

Activity: 1764
Merit: 1031


View Profile WWW
February 12, 2014, 05:55:57 PM
 #25

Ok: more suspiciously, 1SochiWwFFySPjQoi2biVftXn8NRPCSQC has just sent me 1 satoshi. Literally just now.
That probably means someone is screwing around, probably on this forum: saw my post and sent it almost straightaway.
Come on, people. If you're going to prank someone at least make it 0.1 bitcoins.
Mowcore
Hero Member
*****
Offline Offline

Activity: 592
Merit: 500



View Profile
February 12, 2014, 06:17:16 PM
Last edit: February 12, 2014, 07:50:16 PM by Mowcore
 #26

Now I've just been sochi/ enjoy 'd , cxnts!

Thought i'd got away from this bs..

Humble Weekly Bundle.Pay What You Want. Redeem on Steam. Support charity. Pay with BTCitcoin now!--> Paypal Sad
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3990
Merit: 2713


Join the world-leading crypto sportsbook NOW!


View Profile
February 12, 2014, 06:20:07 PM
 #27

Ok: more suspiciously, 1SochiWwFFySPjQoi2biVftXn8NRPCSQC has just sent me 1 satoshi. Literally just now.
That probably means someone is screwing around, probably on this forum: saw my post and sent it almost straightaway.
Come on, people. If you're going to prank someone at least make it 0.1 bitcoins.

That happened to somebody else on here about ten minutes after they posted in one of the threads haha. Maybe just coincidence?

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Voodah
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
February 13, 2014, 08:28:43 PM
 #28

I got 1Enjoy and 1Sochi today on my address posted on my sig (which I now removed) so they are definitely scraping from here, though probably not here alone.

Solution to not get tagged:

Quote
If you don't want some anonymous actor to know which addresses you control, it's best to get rid of those keys or move those dust transactions out of your wallet.

One way to do that is by using Dust-B-Gone. A script written by Peter Todd, one of the bitcoin core developers. It takes those transactions and sends them to his server where they are all combined and spent in a transaction with a 0btc output, effectively giving the dust to the miners.

If you are weary of connecting to his server directly, it has the option of connecting through TOR.

Dust-B-Gone can be found here: https://github.com/petertodd/dust-b-gone

I've used it myself not too long ago and works like a charm. You may have to set the dust limit to 0.001 BTC for it to find the transaction(s). You can run it initially as a dry run by specifying --dry-run and it'll show you a raw dump of the transaction it'll send out.

More information can be found here: https://bitcointalk.org/index.php?topic=317233.msg3413785#msg3413785
Ente
Legendary
*
Offline Offline

Activity: 2126
Merit: 1001



View Profile
February 13, 2014, 10:58:42 PM
 #29

I got 1Enjoy and 1Sochi today on my address posted on my sig (which I now removed) so they are definitely scraping from here, though probably not here alone.

Solution to not get tagged:

Quote
If you don't want some anonymous actor to know which addresses you control, it's best to get rid of those keys or move those dust transactions out of your wallet.

One way to do that is by using Dust-B-Gone. A script written by Peter Todd, one of the bitcoin core developers. It takes those transactions and sends them to his server where they are all combined and spent in a transaction with a 0btc output, effectively giving the dust to the miners.

If you are weary of connecting to his server directly, it has the option of connecting through TOR.

Dust-B-Gone can be found here: https://github.com/petertodd/dust-b-gone

I've used it myself not too long ago and works like a charm. You may have to set the dust limit to 0.001 BTC for it to find the transaction(s). You can run it initially as a dry run by specifying --dry-run and it'll show you a raw dump of the transaction it'll send out.

More information can be found here: https://bitcointalk.org/index.php?topic=317233.msg3413785#msg3413785


Aww, I like this!
He didn't send the dust to himself, or back to the owner, or to a black hole, he send it to the miners!
Yep, I like this guy!

Ente
Hyena
Legendary
*
Offline Offline

Activity: 2114
Merit: 1015



View Profile WWW
February 18, 2014, 10:30:05 AM
Last edit: February 18, 2014, 11:21:47 AM by Hyena
 #30

My address received this strange transaction lately. However, that address has not been written anywhere so the attacker had to just discover it from the block chain I suspect. Another theory is that this is some kind of bitcoin terrorism. People who have nice round balances in their cold storage get them ruined.

There are some interesting public notes there:
Public Note: Hey, give me back my 20 Bitcoin

Public Note: If you are reading this, please take some time to remember those who died 12 years ago today in the WTC attacks

Public Note: Whoever you are, you're epic.

edit:
there's some more suspicious activity, look this address: https://blockchain.info/address/1AgesqfafUHHpAWnmjj9g6TVqBGXk4ixxg

A lot of coins are sent to all possible addresses that start with 1Ag

According to Mendelejev's table, silver is Ag.

ONE MORE THEORY:
What if the attacker has targeted just one address? However, to make it less threatening it has added a bunch of other random addresses to the formula? Then people such as myself who get disturbed by this activity start making posts to this thread and are immediately connected to their address by the forum user.

and one more:
Some of the destination addresses have spent their input except this suspicious input. Maybe the attacker tries to pin point automated wallets? So if the suspicious input remains unspent but other balance is spent then there could be some automation in place which could be abused with the transaction malleability vulnerability.

★★★ CryptoGraffiti.info ★★★ Hidden Messages Found from the Block Chain (Thread)
salstimda
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
February 18, 2014, 12:10:07 PM
 #31

2) because of this, more generally speaking:




omg thanks for the laugh Smiley
miragecash
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
February 18, 2014, 01:15:08 PM
 #32



God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Errr... whoever told you bitcoin is anonymous was joking, because that's funny. It may be anonymous to regular folks, but it is NOT anonymous to governments with really powerful computers. Your spending patterns are as unique to you as your fingerprints. Human beings are creatures of habit. Let's say that you hypothetically enjoy delivery Chinese food with expensive liquor while watching heavyweight championship boxing. Prior to getting involved with bitcoin, your credit card transactions show that these are your preferences. Now, you are trying to stay hidden and use "anonymous" bitcoins to make your purchases instead. There is going to be a world heavyweight boxing match tonight so you run out to the local liquor store and buy a bottle of Dom Perignon, go home, and then order some delivery Chinese food, all with bitcoin. Your government's computers pick up this spending pattern on the blockchain, hack into Mr. Wok's servers and BAM! They've just located you. Most merchants have their wallets with coinbase or bitpay to isolate themselves from exchange rate risk and messy tax filings. That's how the government gets their hands on most merchant's bitcoin wallet addresses.

Or you like French food, expensive liquor, and buy a lotto ticket every Friday night at your local convenience store. All they'd have to do to catch you is wait for you at the local convenience store on Friday night.

Or... you get the picture.

If you were religious, I'd say that bitcoin is the mark of the beast!
deeplink
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


In cryptography we trust


View Profile
February 18, 2014, 01:51:27 PM
 #33



God bless you for understanding this, because I sure as heck don't.  I thought BTC was anonymous, and I didn't think I was putting myself and my BTC address at risk by sending BTC to another address.  If that's what you're saying, I'm nervous.

Errr... whoever told you bitcoin is anonymous was joking, because that's funny. It may be anonymous to regular folks, but it is NOT anonymous to governments with really powerful computers. Your spending patterns are as unique to you as your fingerprints. Human beings are creatures of habit. Let's say that you hypothetically enjoy delivery Chinese food with expensive liquor while watching heavyweight championship boxing. Prior to getting involved with bitcoin, your credit card transactions show that these are your preferences. Now, you are trying to stay hidden and use "anonymous" bitcoins to make your purchases instead. There is going to be a world heavyweight boxing match tonight so you run out to the local liquor store and buy a bottle of Dom Perignon, go home, and then order some delivery Chinese food, all with bitcoin. Your government's computers pick up this spending pattern on the blockchain, hack into Mr. Wok's servers and BAM! They've just located you. Most merchants have their wallets with coinbase or bitpay to isolate themselves from exchange rate risk and messy tax filings. That's how the government gets their hands on most merchant's bitcoin wallet addresses.

Or you like French food, expensive liquor, and buy a lotto ticket every Friday night at your local convenience store. All they'd have to do to catch you is wait for you at the local convenience store on Friday night.

Or... you get the picture.

If you were religious, I'd say that bitcoin is the mark of the beast!


You're funny, thx for the laugh
citysin
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
June 04, 2014, 05:40:34 AM
Last edit: June 04, 2014, 05:59:51 AM by citysin
 #34

Generate as many address/key pairs as you can, continuously, using any method you think someone else might employ to generate their future wallet. Flit some coins in and out to get it's address showing up in your coind. Set up a script to watch your wallets. You'll need a farm of them. There is going to be some bumps with millions of accounts in 1 wallet. Each wallet gets a daemon to track the balance of the wallet, if it increases, withdraw the funds. Script the creation of new wallet nodes, deploy, expand. wait. Maybe you get lucky, maybe you waste a few thousand a year on hosting and electricity for generating endless keypairs. As more people create/move/transact, more addresses get used, the likelihood of success with this type of method increases as the coin becomes more adopted, which likely would increase it's value. If you hit a lucky address, it would be quite worth the effort. You probably never will, but again, with rpc calls, image deployment, cheap plug computers and botnets and ever decreasing hosted compute/cheaper arms coming along, there's very little investment in just creating endless keypairs and hoping for a rich twin one day. People bet on long shots all the time. On occasion they get lucky.

Just my random thought.

I should probably add the point of my mind exercise was not to advise you to actually do this, but to encourage not using a 'method' in building something that should provide security based on obscurity. It might also encourage more people to investigate multisig addresses.
lewisg
Sr. Member
****
Offline Offline

Activity: 281
Merit: 250


View Profile
June 04, 2014, 06:56:27 AM
 #35

Most newcomers can't mine because the bar is set too high but faucets pay in MilliBits.

Ente
Legendary
*
Offline Offline

Activity: 2126
Merit: 1001



View Profile
June 04, 2014, 07:37:49 AM
 #36

Generate as many address/key pairs as you can, continuously, using any method you think someone else might employ to generate their future wallet. Flit some coins in and out to get it's address showing up in your coind. Set up a script to watch your wallets. You'll need a farm of them. There is going to be some bumps with millions of accounts in 1 wallet. Each wallet gets a daemon to track the balance of the wallet, if it increases, withdraw the funds. Script the creation of new wallet nodes, deploy, expand. wait. Maybe you get lucky, maybe you waste a few thousand a year on hosting and electricity for generating endless keypairs. As more people create/move/transact, more addresses get used, the likelihood of success with this type of method increases as the coin becomes more adopted, which likely would increase it's value. If you hit a lucky address, it would be quite worth the effort. You probably never will, but again, with rpc calls, image deployment, cheap plug computers and botnets and ever decreasing hosted compute/cheaper arms coming along, there's very little investment in just creating endless keypairs and hoping for a rich twin one day. People bet on long shots all the time. On occasion they get lucky.

Just my random thought.

I should probably add the point of my mind exercise was not to advise you to actually do this, but to encourage not using a 'method' in building something that should provide security based on obscurity. It might also encourage more people to investigate multisig addresses.

Possible, but not be best way.
1) It would be more efficient to hunt for already used addresses, as the older addresses have more coins than the addresses in the future.
2) You don't need to actually send funds to an address to "watch" it. You generate billions of addresses, and check in the blockchain if any of those has funds on.
3) It is completely senseless to "mine" for random addresses. It makes more sense to hunt for weak brainwallets.

The address space is 256 bit. This is what that means, practically:



Ente
elrapido
Newbie
*
Offline Offline

Activity: 57
Merit: 0


View Profile
July 12, 2014, 02:14:28 PM
 #37

Just got some on a few addresses, some even twice...has this mystery been solved yet?
Marty N. Gale
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
July 12, 2014, 02:17:42 PM
 #38

i'd like some more transactions from awesome addresses like 1Enjoy... and 1Sochi...
maybe something along the lines of 1Enjoy... 1Worldcup...  Cheesy
Taras
Legendary
*
Offline Offline

Activity: 1386
Merit: 1053


Please do not PM me loan requests!


View Profile WWW
July 13, 2014, 02:01:00 AM
 #39

I wonder why they're giving to random addresses like this.
I'd like to get some more millibits Grin
TheIrishman
Legendary
*
Offline Offline

Activity: 1049
Merit: 1006


View Profile
July 13, 2014, 12:06:35 PM
 #40

I wonder why they're giving to random addresses like this.
I'd like to get some more millibits Grin

Totally agree. Man up and send me a few whole bitcoins already! Cheesy
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!