Bitcoin Forum
June 22, 2024, 09:26:01 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 »  All
  Print  
Author Topic: BIPS Wallet security breach  (Read 11458 times)
Dadio202
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
November 22, 2013, 04:14:26 PM
 #21

I chose BIPS because of their reputation and the services they could provide. I am a company director and entrusted them with 4.8 bitcoins and  transfered £..... To purchase more just before the ddos. I am very dissapointed at their lack of response to my emails and their apparent lack of concern about what has happened. For them to mention in their latest announcement that the wallets were a free service means nothing. To say they are passing details on to the authorities sounds like they are taking the first steps to absolve themselves of any responsibility. If BIPS wants to be a large respected company in the future, the should stand up now and be counted. Offer all those that lost coins compensation.
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 22, 2013, 04:36:58 PM
 #22

https://bitcointalk.org/index.php?topic=252308.80

"It is imperative to understand that everything was wiped out from our servers and getting functionality back is priority #1.
The wallet part of BIPS was a free service to make payments easier for users.
Web Wallets are like a regular wallet that you carry cash in and not meant to keep large amounts in.
Hence we offered a paper wallet as a cold storage alternative for those who wanted a safe storage solution.
We will be contacting all affected users as already proclaimed.
We will need their consent to hand over information to the authorities for further investigation, which hopefully can assist in catching the thief.
Those who were not affected and have a bitcoin balance will also be contacted.
Most balances left are minuscule, but if you had more than a few satoshi’s in your wallet you are affected, and will be contacted.

Another priority is doing forensics data recovery to be able to investigate and assist authorities in finding the attacker.
Technical information will not be disclosed for security reasons.

Stolen coins have been isolated and server logs have been retrieved from data recovery:
https://blockchain.info/address/1LuG91tcSQxKj32BsCoRkX7yQLfj9LtkCs

Please be advised that attacks are not isolated to us and if you are storing larger amounts of coins with any third party you may want to find alternative storage solutions as soon as possible, preferably cold storage if you do not need immediate access to those coins:
www.coindesk.com/hacker-attack-polands-bitcoin-exchange/
www.coindesk.com/czech-bitcoin-exchange-bitcash-cz-hacked-4000-user-wallets-emptied/"


From Kris at bips... not a great way to start my Friday...
ghengis34
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
November 22, 2013, 05:26:33 PM
 #23

OK people. I'm one of the unlucky "whales" who stored a lot of bitcoins with bips.me.  I lost about 90 bitcoins. They haven't contacted me yet, but from what I glean from these forums, my bitcoins have already gone and been spent on Russian hookers.

So. I'm willing to accept that I will never get these bitcoins back, but I'm not willing to accept that bips.me will continue on to glory, handling bitcoin transactions for merchants, getting (more?) venture funding, etc. 

In my mind, it's 'either or' - either I get my bitcoins back, or bips.me takes their website down and opens up under a completely new name. But not both.

With this in mind, I'm seeking out other 'whales' - people who lost significant numbers of bitcoin on bips.me.  If there's enough of us, what we do is get together and hire a lawyer in Denmark, and start from there. It will be worth it.

Here is a signup form:

https://docs.google.com/forms/d/1v8AL3scMErzSLPRSOhGuGXn9pzHjWNTrSE2YWEQIpxs/viewform

I am the first person to sign up, with my 90 missing bitcoins.

If nobody else signs up, or if the total number of signups doesn't add up to more than 250 bitcoins, I'll give up.

Also. I very much doubt that this was an 'inside job' or some kind of fraud. Danish people don't do those sorts of things. They just don't. However, that doesn't mean that these guys shouldn't have to start from scratch again.
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 22, 2013, 05:40:30 PM
 #24

Not a "whale" but I consider the potiential value of 3 coins to be very significant...  90 coins.. I'd be crying literialy.... Cry
philipma1957
Legendary
*
Offline Offline

Activity: 4158
Merit: 8051


'The right to privacy matters'


View Profile WWW
November 22, 2013, 05:52:03 PM
 #25

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf

My guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 22, 2013, 06:37:15 PM
 #26

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf

My guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34


How are you able to look this info up?  I have the BIPS address I used to deposit the coins a few days prior to the heist...
BitcoinFr34k
Hero Member
*****
Offline Offline

Activity: 504
Merit: 500




View Profile
November 22, 2013, 06:41:42 PM
 #27

I hope everyone gets their money back.
dantes
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
November 22, 2013, 07:50:28 PM
 #28

ghenghis - I have signed up to your list.  As I suspected it is all gone.  As BIPS is listed as one of the 'preferred' web wallet options in bitcoin.org (alongside Blockchain and Coinbase) I would have thought they were a little better prepared - they are not exactly a newly established exchange in E Europe. And what are they doing with their site up?  They don't seriously expect to continue in the merchanting business after this do they?
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 22, 2013, 08:50:47 PM
 #29

what are they doing with their site up?  They don't seriously expect to continue in the merchanting business after this do they?

Oh they certainly do...
dominicwin
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
November 22, 2013, 08:54:12 PM
 #30

Count those bitcoins lost forever unfortunately especially considering BIPS response to it.

CUBAN CIGARS for Sale - Full Boxes and Individual Cigars https://bitcointalk.org/index.php?topic=299151.0
Austrian GOLD 1oz PHILHARMONICS -  https://bitcointalk.org/index.php?topic=330401.0
BUYING BTC HERE https://bitcointalk.org/index.php?topic=334920.0
philipma1957
Legendary
*
Offline Offline

Activity: 4158
Merit: 8051


'The right to privacy matters'


View Profile WWW
November 22, 2013, 08:58:47 PM
 #31

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf

My guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34

    

How are you able to look this info up?  I have the BIPS address I used to deposit the coins a few days prior to the heist...


go to www.blockchain.info   in the middle of the page is a search engine put your  btc address  and you will see the info.

If the coins were pulled on the 20th like mine you are most likely okay.  if they where pulled on the 16th-18th   you are less likely okay.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 22, 2013, 09:10:06 PM
 #32

Would the address I used on MTGOX to transfer the funds to BIPS be the address I enter to view it?  I don't kno what the other address is (private address?) since I can't view it when I log into BIPS
assortmentofsorts
Member
**
Offline Offline

Activity: 91
Merit: 10



View Profile
November 23, 2013, 12:50:27 AM
 #33

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf

My guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34

    

How are you able to look this info up?  I have the BIPS address I used to deposit the coins a few days prior to the heist...


go to www.blockchain.info   in the middle of the page is a search engine put your  btc address  and you will see the info.

If the coins were pulled on the 20th like mine you are most likely okay.  if they where pulled on the 16th-18th   you are less likely okay.

Hey my address is this: https://blockchain.info/address/1PGXTsbbrnXBnTgEdssRCH8Ukc57DvapcP

I don't see any coins pulled after the 31st of October. So are my coins safe then?

If you want to tip: BTC 1KbjTUEfcziwMv7BMXcjmvNAKEpTJbZCsF
assortmentofsorts
Member
**
Offline Offline

Activity: 91
Merit: 10



View Profile
November 23, 2013, 12:51:46 AM
 #34

OK people. I'm one of the unlucky "whales" who stored a lot of bitcoins with bips.me.  I lost about 90 bitcoins. They haven't contacted me yet, but from what I glean from these forums, my bitcoins have already gone and been spent on Russian hookers.

So. I'm willing to accept that I will never get these bitcoins back, but I'm not willing to accept that bips.me will continue on to glory, handling bitcoin transactions for merchants, getting (more?) venture funding, etc. 

In my mind, it's 'either or' - either I get my bitcoins back, or bips.me takes their website down and opens up under a completely new name. But not both.

With this in mind, I'm seeking out other 'whales' - people who lost significant numbers of bitcoin on bips.me.  If there's enough of us, what we do is get together and hire a lawyer in Denmark, and start from there. It will be worth it.

Here is a signup form:

https://docs.google.com/forms/d/1v8AL3scMErzSLPRSOhGuGXn9pzHjWNTrSE2YWEQIpxs/viewform

I am the first person to sign up, with my 90 missing bitcoins.

If nobody else signs up, or if the total number of signups doesn't add up to more than 250 bitcoins, I'll give up.

Also. I very much doubt that this was an 'inside job' or some kind of fraud. Danish people don't do those sorts of things. They just don't. However, that doesn't mean that these guys shouldn't have to start from scratch again.

damn 90 bitcoins?  Shocked

If you want to tip: BTC 1KbjTUEfcziwMv7BMXcjmvNAKEpTJbZCsF
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 23, 2013, 01:48:22 AM
 #35

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

httMy guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34

     

How are you able to look this info up?  I have the BIPS address I used to deposit the coins a few days prior to the heist...
ps://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf



go to www.blockchain.info   in the middle of the page is a search engine put your  btc address  and you will see the info.

If the coins were pulled on the 20th like mine you are most likely okay.  if they where pulled on the 16th-18th   you are less likely okay.

Hey my address is this: https://blockchain.info/address/1PGXTsbbrnXBnTgEdssRCH8Ukc57DvapcP

I don't see any coins pulled after the 31st of October. So are my coins safe then?


I also don't see any activity on my address from what I can tell since they were deposited on 11/8
philipma1957
Legendary
*
Offline Offline

Activity: 4158
Merit: 8051


'The right to privacy matters'


View Profile WWW
November 23, 2013, 01:53:01 AM
 #36

no that is not good.  what bips does is transfer from your deposit address  to a second address.  since your monies were moved way before the breach you do not know what happened to them in the holding wallet.  my timing was the .4 btc   was put in about 1 hour to 10 hours before the breach and then moved  3 days after the breach was found it is easy to trace the history.

 I need to study the address you gave me.  maybe I can figure the moves made after you put the coins in.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
cubicdissection
Member
**
Offline Offline

Activity: 231
Merit: 10


View Profile WWW
November 23, 2013, 03:55:01 AM
 #37

In my mind, it's 'either or' - either I get my bitcoins back, or bips.me takes their website down and opens up under a completely new name. But not both.

With this in mind, I'm seeking out other 'whales' - people who lost significant numbers of bitcoin on bips.me.  If there's enough of us, what we do is get together and hire a lawyer in Denmark, and start from there. It will be worth it.

Here is a signup form:

https://docs.google.com/forms/d/1v8AL3scMErzSLPRSOhGuGXn9pzHjWNTrSE2YWEQIpxs/viewform

I am the first person to sign up, with my 90 missing bitcoins.

If nobody else signs up, or if the total number of signups doesn't add up to more than 250 bitcoins, I'll give up.

Also. I very much doubt that this was an 'inside job' or some kind of fraud. Danish people don't do those sorts of things. They just don't.

Goddamn right.  Even if they actually did get hacked (which I'm not willing to accept without proof), the security of their site was nothing like they advertised.  I'd bet they won't give technical details on the hack because it would reveal negligence.
 

Also. I very much doubt that this was an 'inside job' or some kind of fraud. Danish people don't do those sorts of things. They just don't. However, that doesn't mean that these guys shouldn't have to start from scratch again.

May be doubtful, but I'm not willing to walk away from my BTC on the strength of a cultural stereotype.  Prove it or I'm assuming they stole it.  No offence, but I think any other affected users would be foolish to take any other stance.
allincoin (OP)
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 23, 2013, 06:23:56 AM
 #38

There needs to be a way to reverse transactions when things like this happen.  It doesn't need to be  like what Visa/ mastercard or paypal does..  Just some form of recourse built into the system.   
philipma1957
Legendary
*
Offline Offline

Activity: 4158
Merit: 8051


'The right to privacy matters'


View Profile WWW
November 23, 2013, 06:44:59 AM
 #39

I am out about .39 btc  but my money was in the address up to the 20th and was not pulled out until later then the crash.  my money was pulled out at about 23:39 pm the 20th of nov Greenwich time.


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp

https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf

My guess is the money above was saved by bips  if you look at it the amounts were tiny

the highest was 1.2 btc the lowest was under .1 btc


What annoys me is not the .39   but I have an account with cloudhasher  and they are going to continue to put money into that address over the next 9 months.  I am really fucking annoyed.  But my losses may only be .7 or .8 btc when all is said and done.

  Now for someone with 90 coins oh that hurts.  good luck to you ghengis34

    

How are you able to look this info up?  I have the BIPS address I used to deposit the coins a few days prior to the heist...


go to www.blockchain.info   in the middle of the page is a search engine put your  btc address  and you will see the info.

If the coins were pulled on the 20th like mine you are most likely okay.  if they where pulled on the 16th-18th   you are less likely okay.

Hey my address is this: https://blockchain.info/address/1PGXTsbbrnXBnTgEdssRCH8Ukc57DvapcP

I don't see any coins pulled after the 31st of October. So are my coins safe then?



OKAY your btc has been flagged    it was put here on the  the 31st of oct.

https://blockchain.info/address/1PGXTsbbrnXBnTgEdssRCH8Ukc57DvapcP  the address you gave us.  it was moved on the 31st of oct to this address


https://blockchain.info/address/14xMNNgzDtkmrPhkEZohGg3nHkPFw96hDz    then moved on the same day to a flagged address that has 'easycoin scam' marked on it.


tx ids  go   in this order :

1)https://blockchain.info/tx/37b7e6df916b32113e9dda776d6127c0566106fcca89a750537ad27ccab11462  incoming

2)https://blockchain.info/tx/fcd34fecf7898c2420e7a5b36a8ffd34d5583c1a73428f63d6d64eb7639af06a  out to a bips.me holding address common practice normal for online wallets to pool deposits

3)https://blockchain.info/address/14xMNNgzDtkmrPhkEZohGg3nHkPFw96hDz   out to an un known address with a tag (easycoin (scam?)   I am thinking this is a flag from bips  marking a problem transfer.

my address does this


https://blockchain.info/address/1AyWHY6kCMi4F221J7aPheiYdAvkDbcdPp


1)           https://blockchain.info/tx/e56f87a67251525aa3bc69118bccb19335db90b10305b10366b81fe74630be56          my .39345 btc came in on the 17 of nov

2)  17 to the 20 shit hit the fan my coins were frozen

3)https://blockchain.info/tx/4d6bc489bdb2f32d397eb2aa3844f2e6711b934399af5f62b11c9ded8c84edbf  my coins where moved here late nov 20th.

and all coins moved here  at this address

https://blockchain.info/address/1PhABsySjnnjMigE6YSBtaQAqZAwaX9h64    that was done late  nov 20th    more moves done since then  but I am thinking these are still in control of by bips.me 

 my coins were clearly moved after the shut down   when they claimed the system was partially restored.    all in all it is a fucking mess for a lot of people.


▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
dave5698225
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
November 23, 2013, 07:10:41 AM
 #40

Wow, I'm a Zen Cart ecommerce designer and after looking at all Zen Cart/Bitcoin plugins I chose BIPS - YESTERDAY! I had no issue creating a new account and installing the software on demo site. I can't believe there were no warning or announcements anywhere to be seen, if It wasn't for this post I would not have known of any breach. Luckily I had yet to transfer BTC's to test their plugin - whew!

Sorry to hear the losses on here, I hope you find restitution quickly.

Dave Ward
Kitchener, ON, Canada
Pages: « 1 [2] 3 4 5 6 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!