Bitcoin Forum
January 22, 2019, 01:39:04 AM *
News: Latest Bitcoin Core release: 0.17.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 ... 88 »
  Print  
Author Topic: Network Attack on XVG / VERGE  (Read 28311 times)
LinuxDude
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
April 04, 2018, 10:59:46 PM
 #141

nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

how can we verify the hardfork ?

just download an updated wallet which includes the "fix" - then download the blockchain snapshot and try to sync up to the latest block...it will get stuck at 2007364

Confirmed.    client stalls at block 2007364


yeah we removed that, and we're doing a full fork update with extra block verifications. will be ready by tmrw =]

So are you saying the exploit can be used for the rest of the day with no repercussions?

Sounds great! Cheesy - That screams for exploit and rollback afterwards.

Downloaded latest Wallet, installed blockchain files from 4/3/18 and I got past block 2007364 and it's still syncing for me.

1548121144
Hero Member
*
Offline Offline

Posts: 1548121144

View Profile Personal Message (Offline)

Ignore
1548121144
Reply with quote  #2

1548121144
Report to moderator
1548121144
Hero Member
*
Offline Offline

Posts: 1548121144

View Profile Personal Message (Offline)

Ignore
1548121144
Reply with quote  #2

1548121144
Report to moderator
1548121144
Hero Member
*
Offline Offline

Posts: 1548121144

View Profile Personal Message (Offline)

Ignore
1548121144
Reply with quote  #2

1548121144
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1548121144
Hero Member
*
Offline Offline

Posts: 1548121144

View Profile Personal Message (Offline)

Ignore
1548121144
Reply with quote  #2

1548121144
Report to moderator
1548121144
Hero Member
*
Offline Offline

Posts: 1548121144

View Profile Personal Message (Offline)

Ignore
1548121144
Reply with quote  #2

1548121144
Report to moderator
bluejeanballa
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
April 04, 2018, 11:02:10 PM
 #142

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?
Dogedarkdev
Legendary
*
Online Online

Activity: 1344
Merit: 1005


$XVG - The Standard in Privacy Based Crypto


View Profile WWW
April 04, 2018, 11:04:22 PM
 #143

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?

nothing, until we release the updated wallets. the way i see it, is this attack has a cost, and will end when we push the update. you aren't invested in verge though, so why are you so concerned?

_///// [XVG] ★★★★★WE ARE ON  THE VERGE ★★★★★ [MULTI-ALGO] /////_
_///// TOR // I2P // LINUX . WINDOWS . MAC . ANDROID . ELECTRUM . WEBWALLET . GITHUB // WEBSITE // RADIO // IRC /////_
Dogedarkdev
Legendary
*
Online Online

Activity: 1344
Merit: 1005


$XVG - The Standard in Privacy Based Crypto


View Profile WWW
April 04, 2018, 11:06:41 PM
 #144

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.

Sorry this is not true, the attack started on block  2007365 and ended on block 2010039 = 2674 blocks, okay lets say 2500 blocks...

One Block makes about 1560 coins, so you have 2500 * 1560 = 3.900.000 "extra" coins generated (at least!) ....

I've listed a few of the attackers addresses in the first post.. Just check them, check the balance and if you're curious, just go through all the blocks during that timespan and sum them up.. It's actually easy when you have a blockexplorer database running.. You can do it via SQL query.


not all blocks during that time were mined by them, i checked. it was much less than half from what i saw across the other pools.

edit: although it is still vulnerable until tmrw, most blocks are being found by valid pools.

_///// [XVG] ★★★★★WE ARE ON  THE VERGE ★★★★★ [MULTI-ALGO] /////_
_///// TOR // I2P // LINUX . WINDOWS . MAC . ANDROID . ELECTRUM . WEBWALLET . GITHUB // WEBSITE // RADIO // IRC /////_
ocminer
Legendary
*
Offline Offline

Activity: 2310
Merit: 1229



View Profile WWW
April 04, 2018, 11:12:54 PM
 #145

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.

Sorry this is not true, the attack started on block  2007365 and ended on block 2010039 = 2674 blocks, okay lets say 2500 blocks...

One Block makes about 1560 coins, so you have 2500 * 1560 = 3.900.000 "extra" coins generated (at least!) ....

I've listed a few of the attackers addresses in the first post.. Just check them, check the balance and if you're curious, just go through all the blocks during that timespan and sum them up.. It's actually easy when you have a blockexplorer database running.. You can do it via SQL query.


not all blocks during that time were mined by them, i checked. it was much less than half from what i saw across the other pools.

Well.. I checked it as well, in fact I've got the logfiles and started working through them but I have other things todo instead of going through logfiles.. From what I see 95% of the blocks during that time went to "them".. And i'm pretty certain about that..

Okay, lets say they STILL don't have ALL of the blocks (which is wrong), there were STILL almost 3000 blocks generated during a very short time, so over 3.900.000 coins (at least) were extra-generated... Where did they go ? I don't see those blocks on the "big" pools...

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
miserymachine
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
April 04, 2018, 11:13:57 PM
 #146

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?

nothing, until we release the updated wallets. the way i see it, is this attack has a cost, and will end when we push the update. you aren't invested in verge though, so why are you so concerned?
So you're saying that the exploit is still unresolved, correct? Also, there are lots of other people who ARE invested in your coin, that is why people are concerned.
ChekaZ
Legendary
*
Offline Offline

Activity: 1823
Merit: 1005



View Profile
April 04, 2018, 11:14:24 PM
 #147

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.

Sorry this is not true, the attack started on block  2007365 and ended on block 2010039 = 2674 blocks, okay lets say 2500 blocks...

One Block makes about 1560 coins, so you have 2500 * 1560 = 3.900.000 "extra" coins generated (at least!) ....

I've listed a few of the attackers addresses in the first post.. Just check them, check the balance and if you're curious, just go through all the blocks during that timespan and sum them up.. It's actually easy when you have a blockexplorer database running.. You can do it via SQL query.


not all blocks during that time were mined by them, i checked. it was much less than half from what i saw across the other pools.

Well.. I checked it as well, in fact I've got the logfiles and started working through them but I have other things todo instead of going through logfiles.. From what I see 95% of the blocks during that time went to "them".. And i'm pretty certain about that..

Okay, lets say they STILL don't have ALL of the blocks (which is wrong), there were STILL almost 3000 blocks generated during a very short time, so over 3.900.000 coins (at least) were extra-generated... Where did they go ? I don't see those blocks on the "big" pools...

You may need to explain him what a blockexplorer is that he can verify it himself  Roll Eyes

BTC: 1Ges1taJ69W7eEMbQLcmNGnUZenBkCnn45
FTC: 6sxjM96KMZ7t4AmDTUKDZdq82Nj931VQvY
5o5kY
Jr. Member
*
Offline Offline

Activity: 252
Merit: 1


View Profile WWW
April 04, 2018, 11:35:47 PM
 #148

@ChekaZ

You're more toxic then a radioactive piece of shit. Why? How does that help you? Tron fan or...?

Toqqn.com ● Crypto Mining Is Now Social
▬▬ ● ● Blockchain Based, Powered by People ● ● ▬▬ (https://toqqn.com)
LinuxDude
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
April 04, 2018, 11:37:18 PM
 #149

My wallet synced just fine and didnt get stuck on any blocks. I also sent coins from Binance to my Wallet and were confirmed on the XVG blockchain. They arrived within 1-2 mins.
ocminer
Legendary
*
Offline Offline

Activity: 2310
Merit: 1229



View Profile WWW
April 04, 2018, 11:43:39 PM
 #150

My wallet synced just fine and didnt get stuck on any blocks. I also sent coins from Binance to my Wallet and were confirmed on the XVG blockchain. They arrived within 1-2 mins.

They rolled back the "fix" and hopefully fork it correctly this time..

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
whisperitplease
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 04, 2018, 11:44:46 PM
 #151

My wallet synced just fine and didnt get stuck on any blocks. I also sent coins from Binance to my Wallet and were confirmed on the XVG blockchain. They arrived within 1-2 mins.

My wallet has only synced once since the initial attack.  Yiimp shows a transaction from 50 minutes ago, but it hasn't hit my wallet.  
siege3967
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
April 04, 2018, 11:48:50 PM
 #152

I just came here to say that the verge team is still full on trying to act like this is no big deal. They're acting like the issue is resolved on telegram and are banning anyone who point people to this thread. The exploit is being exploited right now...
khaled0111
Full Member
***
Offline Offline

Activity: 588
Merit: 227

Take it Easy


View Profile
April 04, 2018, 11:50:15 PM
 #153

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?

nothing, until we release the updated wallets. the way i see it, is this attack has a cost, and will end when we push the update. you aren't invested in verge though, so why are you so concerned?

I hope you will release the update as soon as possible and stop the hackers attacks.
Even if he didn't invest with you, he still have the right to share his thoughts (respectfully), you have to consider him or any one else as a potential investor.

CHIEF56
Jr. Member
*
Offline Offline

Activity: 126
Merit: 2


View Profile
April 04, 2018, 11:53:11 PM
 #154

I just came here to say that the verge team is still full on trying to act like this is no big deal. They're acting like the issue is resolved on telegram and are banning anyone who point people to this thread. The exploit is being exploited right now...

Meanwhile, I'm watching millions in USD being siphoned off. RIP
AnabolicRampage
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
April 04, 2018, 11:53:51 PM
 #155

I'm just here for the drama, I have my popcorn ready.
Mcoinzy
Newbie
*
Offline Offline

Activity: 15
Merit: 0


View Profile
April 04, 2018, 11:54:41 PM
 #156

we are not doing a rollback and we are preparing a fork to patch this up.

Sorry to mess up this thread and topic a bit, but after i do not get for hours an answer on twitter, neither does the email function on the Verge homepage work, nor does someone respond on the Verge Bitcoin thread i have to try my luck here.

I visited some hours ago the official Verge Twitter profil to read the news about the hash hack. While reading the tweed i noticed several messages offering a compensation for the attack by Verge. Send x Eth and you get some bonus back. Sounded legit to me as it was affilated to the hash attack and i suffered from it as well having had some hours only orphaned blocks on all my baikals, hence i fall victim to this damn scam on the official twitter page.

Now, while i have myself for sure some vault for this i'am seriously angry about how on the official verge twitter page 100s of scams and fake messages that say they got the ETH back are tolerated and nobody cares about it?!?! How is this possible. After i realized i got scammed i even made a post in this tweet that its a scam and to remove it asap, nothing happened and people still fall after that scam. Only on that scam by now 12+ Eth have been transfered the last hours. .

Damn, i'am not a twitter guy and very rarely use it, but from an official Verge twitter profil i personal await its clean and at very least if this for some reason is not possible that there are warning messages about these scams!!!! But no, nothing, the whole official Verge Twitter profil is FULL of scams that are tolerated and people like me, fall victims to it. Fine, i lost some 1.8 ETH, but hourly these scams seems to collect a huge amount of ETH that way and nobody there at Verge cares?

Seriously, so far i wondered about the twitter decision to ban crypto, but i begin to understand the decision. They must get shitload of complains from victims like me.....

And what makes me even more angry ... no response:
- Messaged some hours ago verge on twitter .... nothing, scams are staying and getting more and more
- Put a tweet on the Verge tweet to remove the scams .... nothing, scams are just staying there
- posted in the official bitcointalk Verge thread, nothing ......
- tried to email Verge about the ongoing scams .... email function on the homepage isn't even working, it just loads forever. And after 5 attempts to load it still loads after 2 hours, lol.

I'am writting this as a XVG miner and lover, but this all makes me really sad and angry .....

Sorry to say, but this has been a huge problem for some time. Bots post on every single crypto profile with the same exact scam, people probably ignored you because they thought you were joking about it, since people literally joke about getting ripped off by these scammers,,, because we have seen it literally every post for months. Im very sorry for your loss sir, but you cant go placeing blame on others
siege3967
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
April 04, 2018, 11:56:26 PM
 #157

we're putting out an update, and it will fix it. that's what we can do. it's the best we can do. no, they did not 13 hours of coins. it was some blocks during a 3 hour period.

something around ~250k coins, and the attack probably cost alot more than that, luckily.

we are glad this was brought to our attention, and we are already working on a sophisticated block verification routine.


Looking at the block explorer some of the new blocks are still out of order according to the time stamps. Doesn't that suggest the exploit is still being used? I'm just having a hard time trying to figure out why you believe it only happened for 3 hours. What's to stop the exploit from being used for the rest of the night, therefore stealing more than 250k coins?

nothing, until we release the updated wallets. the way i see it, is this attack has a cost, and will end when we push the update. you aren't invested in verge though, so why are you so concerned?

I hope you will release the update as soon as possible and stop the hackers attacks.
Even if he didn't invest with you, he still have the right to share his thoughts (respectfully), you have to consider him or any one else as a potential investor.

The dev has always been nonchalant about stuff like this. Almost acts like it's not his fault.
mvd
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile
April 04, 2018, 11:57:34 PM
 #158

I just came here to say that the verge team is still full on trying to act like this is no big deal. They're acting like the issue is resolved on telegram and are banning anyone who point people to this thread. The exploit is being exploited right now...

Based on what I see from the dev postings here it's apparent that if ocminer had never brought this to everyone's attention, the XVG team would have never admitted to or disclosed what happened.

Trying to downplay and being flippant about the severity here is just pissing on the XVG faithful.
LinuxDude
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
April 05, 2018, 12:00:44 AM
 #159

I just came here to say that the verge team is still full on trying to act like this is no big deal. They're acting like the issue is resolved on telegram and are banning anyone who point people to this thread. The exploit is being exploited right now...

Sounds to me like you're fudding to try to drive the price down.
siege3967
Jr. Member
*
Offline Offline

Activity: 42
Merit: 1


View Profile
April 05, 2018, 12:03:00 AM
 #160

I just came here to say that the verge team is still full on trying to act like this is no big deal. They're acting like the issue is resolved on telegram and are banning anyone who point people to this thread. The exploit is being exploited right now...

Sounds to me like you're fudding to try to drive the price down.

FUD- fear, uncertainty and doubt. There's nothing uncertain or doubtful about this. You xvg fanboys use acronyms you don't know the meaning of a lot.
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 ... 88 »
  Print  
 
Jump to:  

Bitcointalk.org is not available or authorized for sale. Do not believe any fake listings.
Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!