Bitcoin Forum
November 15, 2024, 01:33:08 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: CEX.IO "hacked"........?  (Read 5429 times)
IYFTech (OP)
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


WANTED: Active dev to fix & re-write p2pool in C


View Profile
December 09, 2013, 11:07:07 PM
 #1

Thought I'd copy this over from the cex.io official thread so everyone could read it, seeing as nobody looks at their thread anyway - especially cex.io......


-- Smiley  Thank you for smoking  Smiley --  If you paid VAT to dogie for items you should read this thread:  https://bitcointalk.org/index.php?topic=1018906.0
PatMan
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1000


Watch out for the "Neg-Rep-Dogie-Police".....


View Profile WWW
December 10, 2013, 03:36:11 AM
 #2

****GONE****

EDIT: More on it here.......

http://narrock.com/threads/my-cex-io-just-got-hacked.130/#post-790

Apparently cex allow multiple logins........how wonderfully secure  Roll Eyes

"When one person is deluded it is called insanity - when many people are deluded it is called religion" - Robert M. Pirsig.  I don't want your coins, I want change.
Amazon UK BTC payment service - https://bitcointalk.org/index.php?topic=301229.0 - with FREE delivery!
http://www.ae911truth.org/ - http://rethink911.org/ - http://rememberbuilding7.org/
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
December 10, 2013, 04:43:28 AM
 #3

Apart from the volatility of bitcoin, I see "hacking" as the number thing that could cause it to fail.

Barely a week goes by without another "several thousand" bitcoins going missing because a site has been "hacked".

I put "hacked" in quotes because in 90% of these "hacking" cases, I don't believe for a minute the site has really been hacked. Its just a convenient excuse for the site owner to run off with the coins.

Tip: never leave any more bitcoins that you have to on *any* bitcoin website. There are too many greedy people about. Keep your bitcoins offline.
HellDiverUK
Hero Member
*****
Offline Offline

Activity: 1246
Merit: 501



View Profile
December 10, 2013, 08:24:31 AM
 #4

Huh, glad I emptied out my BTC from there yesterday.  Still have a tiny amount of cloud hashing going on there (mostly to keep the referral freebies running).
helmax
Sr. Member
****
Offline Offline

Activity: 440
Merit: 250



View Profile
December 10, 2013, 12:32:19 PM
 #5

i am new in this pool
where is thread official for doughts ?

how i can put my address wallet in pool for withdrawn

looking job
Mitchell
Staff
Legendary
*
Offline Offline

Activity: 4116
Merit: 2320


Verified awesomeness ✔


View Profile WWW
December 10, 2013, 12:33:43 PM
 #6

Quote
Apart from the volatility of bitcoin, I see "hacking" as the number thing that could cause it to fail.
It's the same with every other online banking account. It takes a while to build up good security and people just have to be careful with their stuff.

.
Duelbits
            ▄████▄▄
          ▄█████████▄
        ▄█████████████▄
     ▄██████████████████▄
   ▄████▄▄▄█████████▄▄▄███▄
 ▄████▐▀▄▄▀▌████▐▀▄▄▀▌██

 ██████▀▀▀▀███████▀▀▀▀█████

▐████████████■▄▄▄■██████████▀
▐██████████████████████████▀
██████████████████████████▀
▀███████████████████████▀
  ▀███████████████████▀
    ▀███████████████▀
.
         ▄ ▄▄▀▀▀▀▄▄
         ▄▀▀▄      █
         █   ▀▄     █
       ▄█▄     ▀▄   █
      ▄▀ ▀▄      ▀█▀
    ▄▀     ▀█▄▄▄▀▀ ▀
  ▄▀  ▄▀  ▄▀

Live Games

   ▄▄▀▀▀▀▀▀▀▄▄
 ▄▀ ▄▄▀▀▀▀▀▄▄ ▀▄
▄▀ █ ▄  █  ▄ █ ▀▄
█ █   ▀   ▀   █ █  ▄▄▄
█ ▀▀▀▀▀▀▀▀▀▀▀▀▀ █ █   █
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█  █▄█
█ ▀▀█  ▀▀█  ▀▀█ █  █▄█

Slots
.
        ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄
        █         ▄▄  █
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄       █
█  ▄▄         █       █
█             █       █
█   ▄▀▀▄▀▀▄   █       █
█   ▀▄   ▄▀   █       █

Blackjack
|█▀▀▀▀▀█▄▄▄
       ▀████▄▄
         ██████▄
▄▄▄▄▄▄▄▄█▀    ▀▀█
████████▄        █
█████████▄        █
██████████▄     ▄██
█████████▀▀▀█▄▄████
▀▀███▀▀       ████
   █          ███
   █          █▀
▄█████▄▄▄ ▄▄▀▀
███████▀▀▀
.
                 NEW!                  
SPORTS BETTING 
|||
[ Đ ][ Ł ]
AVAILABLE NOW

Advertisements are not endorsed by me.
PatMan
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1000


Watch out for the "Neg-Rep-Dogie-Police".....


View Profile WWW
December 10, 2013, 01:22:31 PM
 #7

Cex aren't happy about the posting - but have neither confirmed or denied it happened. I've asked them to clarify the situation on their official thread so as to assure their users that their system is safe, here:

https://bitcointalk.org/index.php?topic=318010.msg3905148#msg3905148

"When one person is deluded it is called insanity - when many people are deluded it is called religion" - Robert M. Pirsig.  I don't want your coins, I want change.
Amazon UK BTC payment service - https://bitcointalk.org/index.php?topic=301229.0 - with FREE delivery!
http://www.ae911truth.org/ - http://rethink911.org/ - http://rememberbuilding7.org/
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
December 11, 2013, 01:18:02 AM
 #8

Quote
Apart from the volatility of bitcoin, I see "hacking" as the number thing that could cause it to fail.
It's the same with every other online banking account. It takes a while to build up good security and people just have to be careful with their stuff.

Umm ..... how many stories have we heard from banks recently saying "oh sorry, we've got hacked, and all your money has gone".

No, I'm not defending banks for a minute, just pointing out that you can have all the "good security" in the world but if the website owner decides to steal the coins, he can do so in 5 mins.

Greed does funny things to people. Inputs.io claimed the most amazing levels of security, yet they claim they were hacked and had all their coins stolen. Make your own mind up  Undecided
bkpduke
Full Member
***
Offline Offline

Activity: 158
Merit: 100



View Profile WWW
December 11, 2013, 01:59:27 PM
 #9

If the user had setup two-factor authentication, this would not have happened.

I put more blame on the user here than CEX.  Sorry, you just don't leave large sums of BTC unprotected.
siameze
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000



View Profile
December 11, 2013, 05:12:57 PM
 #10

"Jeffrey Smith" who replies to all cex.io correspondance is aparently a TradeFortress clone: http://mentaso.com/bitcoin-news/cex-part-2-the-hacked-account-and-children-playing-grownups.html

This sort of thing is becoming far too commonplace. While I like the premise of cex.io, I wish there was a more stable and secure platform like it and not the constant dodgy behavior Mr. Smith seems to exhibit.


                     ▀▀█████████▀████████████████▄
                        ████▄      ▄████████████████
                     ▄██████▀  ▄  ███████████████████
                  ▄█████████▄████▄███████████████████
                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀████████
                                               ▀▀███▀
    ▄█▀█       ▄▀  ▄▀▀█  ▄▀   █████████████████▄ ██▀         ▄▀█
   ▄█ ▄▀      ▀█▀ █▀ █▀ ▀█▀  ███████████████████ █▀ ▀▀      ▄▀▄▀
  ▄█    ▄███  █     █   █   ████████████████████  ▄█     ▄▀▀██▀ ▄███
███▄▄▄  █▄▄▄ █▄▄ ▄▄▀   █▄▄ ██████████████████▀▀   █▄▄ ▄▄ █▄▄█▄▄▄█▄▄▄
                           ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                            ▀▀█████████████▄
                                █████████████▄
                                  █████████████▄
                                    ▀███████▀▀▀▀▀
                                      ▀████▀
                                        ▀█▀
LetItRideINNOVATIVE ▬▬▬
DICE GAME
                        ▄███████████▄
                       ██  ██████████▄
                     ▄█████████████  ██▄
            ▄▄▀█▄▄▄▄▄████████████████████▄
        ▄▄█▀   ███████████  █████  ████  █
    ▄██████ ▄▄███████████████████████████▀
 ▄▀▀ ██████████████████████████  ████  █
█  ▄███████████▀▀▀█████████████████████
██████████████    ████████▀▀██████  █▀
██████████████▄▄▄██████████   ▀▀▀▀▀▀▀
███▀ ▀██████████████████████
██    ███████████████████████
██▄▄██████████████████████████
██████████████▀   ██████████
  █████████████   ▄██████▀▀
     ▀▀██████████████▀▀
         ▀▀██████▀▀
PROVABLY
F A I R
▄█████████████▀ ▄█
██            ▄█▀
██          ▄██ ▄█
██ ▄█▄    ▄███  ██
██ ▀███▄ ▄███   ██
██  ▀███████    ██
██    █████     ██
██     ███      ██
██      ▀       ██
██              ██
▀████████████████▀
BUY  BACK
PLANS
[BTC]
IYFTech (OP)
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


WANTED: Active dev to fix & re-write p2pool in C


View Profile
December 11, 2013, 07:31:11 PM
 #11

 http://mentaso.com/bitcoin-news/cex-part-2-the-hacked-account-and-children-playing-grownups.html

+100!

Gotta love those 3 questions..... Cheesy Cheesy Cheesy

TBH, cex.io are dodgy full stop. They've even accused me of getting paid to criticize them..... Cheesy Cheesy Cheesy Cheesy

It's all gonna end in tears.

-- Smiley  Thank you for smoking  Smiley --  If you paid VAT to dogie for items you should read this thread:  https://bitcointalk.org/index.php?topic=1018906.0
siameze
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000



View Profile
December 11, 2013, 10:32:30 PM
 #12

http://mentaso.com/bitcoin-news/cex-part-2-the-hacked-account-and-children-playing-grownups.html

+100!

Gotta love those 3 questions..... Cheesy Cheesy Cheesy

TBH, cex.io are dodgy full stop. They've even accused me of getting paid to criticize them..... Cheesy Cheesy Cheesy Cheesy

It's all gonna end in tears.

My criticism is free lol. Cheesy


                     ▀▀█████████▀████████████████▄
                        ████▄      ▄████████████████
                     ▄██████▀  ▄  ███████████████████
                  ▄█████████▄████▄███████████████████
                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀████████
                                               ▀▀███▀
    ▄█▀█       ▄▀  ▄▀▀█  ▄▀   █████████████████▄ ██▀         ▄▀█
   ▄█ ▄▀      ▀█▀ █▀ █▀ ▀█▀  ███████████████████ █▀ ▀▀      ▄▀▄▀
  ▄█    ▄███  █     █   █   ████████████████████  ▄█     ▄▀▀██▀ ▄███
███▄▄▄  █▄▄▄ █▄▄ ▄▄▀   █▄▄ ██████████████████▀▀   █▄▄ ▄▄ █▄▄█▄▄▄█▄▄▄
                           ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                            ▀▀█████████████▄
                                █████████████▄
                                  █████████████▄
                                    ▀███████▀▀▀▀▀
                                      ▀████▀
                                        ▀█▀
LetItRideINNOVATIVE ▬▬▬
DICE GAME
                        ▄███████████▄
                       ██  ██████████▄
                     ▄█████████████  ██▄
            ▄▄▀█▄▄▄▄▄████████████████████▄
        ▄▄█▀   ███████████  █████  ████  █
    ▄██████ ▄▄███████████████████████████▀
 ▄▀▀ ██████████████████████████  ████  █
█  ▄███████████▀▀▀█████████████████████
██████████████    ████████▀▀██████  █▀
██████████████▄▄▄██████████   ▀▀▀▀▀▀▀
███▀ ▀██████████████████████
██    ███████████████████████
██▄▄██████████████████████████
██████████████▀   ██████████
  █████████████   ▄██████▀▀
     ▀▀██████████████▀▀
         ▀▀██████▀▀
PROVABLY
F A I R
▄█████████████▀ ▄█
██            ▄█▀
██          ▄██ ▄█
██ ▄█▄    ▄███  ██
██ ▀███▄ ▄███   ██
██  ▀███████    ██
██    █████     ██
██     ███      ██
██      ▀       ██
██              ██
▀████████████████▀
BUY  BACK
PLANS
[BTC]
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
December 12, 2013, 01:02:46 AM
 #13

"Jeffrey Smith" who replies to all cex.io correspondance is aparently a TradeFortress clone: http://mentaso.com/bitcoin-news/cex-part-2-the-hacked-account-and-children-playing-grownups.html

This sort of thing is becoming far too commonplace. While I like the premise of cex.io, I wish there was a more stable and secure platform like it and not the constant dodgy behavior Mr. Smith seems to exhibit.

Seriously? That explains all then .............

Nobody going to investigate him, the police I mean.

This is giving a bad name to the .io domain space  Wink

Re: 2 factor authentication "solving all", it didn't stop all the coins disappearing from inputs.io, owned by "Mr" TradeFortress. he was unfortunately (cough cough) "hacked", even though he claimed the best security of any online wallet. Make your own mind up.
johningreece
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile
January 05, 2014, 03:35:12 PM
 #14

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??
Mitchell
Staff
Legendary
*
Offline Offline

Activity: 4116
Merit: 2320


Verified awesomeness ✔


View Profile WWW
January 05, 2014, 04:12:51 PM
 #15

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??
If it was their fault, they should. If you fucked up, they don't have to.

.
Duelbits
            ▄████▄▄
          ▄█████████▄
        ▄█████████████▄
     ▄██████████████████▄
   ▄████▄▄▄█████████▄▄▄███▄
 ▄████▐▀▄▄▀▌████▐▀▄▄▀▌██

 ██████▀▀▀▀███████▀▀▀▀█████

▐████████████■▄▄▄■██████████▀
▐██████████████████████████▀
██████████████████████████▀
▀███████████████████████▀
  ▀███████████████████▀
    ▀███████████████▀
.
         ▄ ▄▄▀▀▀▀▄▄
         ▄▀▀▄      █
         █   ▀▄     █
       ▄█▄     ▀▄   █
      ▄▀ ▀▄      ▀█▀
    ▄▀     ▀█▄▄▄▀▀ ▀
  ▄▀  ▄▀  ▄▀

Live Games

   ▄▄▀▀▀▀▀▀▀▄▄
 ▄▀ ▄▄▀▀▀▀▀▄▄ ▀▄
▄▀ █ ▄  █  ▄ █ ▀▄
█ █   ▀   ▀   █ █  ▄▄▄
█ ▀▀▀▀▀▀▀▀▀▀▀▀▀ █ █   █
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█  █▄█
█ ▀▀█  ▀▀█  ▀▀█ █  █▄█

Slots
.
        ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄
        █         ▄▄  █
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄       █
█  ▄▄         █       █
█             █       █
█   ▄▀▀▄▀▀▄   █       █
█   ▀▄   ▄▀   █       █

Blackjack
|█▀▀▀▀▀█▄▄▄
       ▀████▄▄
         ██████▄
▄▄▄▄▄▄▄▄█▀    ▀▀█
████████▄        █
█████████▄        █
██████████▄     ▄██
█████████▀▀▀█▄▄████
▀▀███▀▀       ████
   █          ███
   █          █▀
▄█████▄▄▄ ▄▄▀▀
███████▀▀▀
.
                 NEW!                  
SPORTS BETTING 
|||
[ Đ ][ Ł ]
AVAILABLE NOW

Advertisements are not endorsed by me.
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 06, 2014, 03:12:39 AM
 #16

Earlier today my cex.io account was hacked and also my email. The hacker sold the GHS I had and withdrew the funds. I had deposited 10 btc into my cex account. My cex account is now frozen by cex and they are investigating - whatever that means. Does not cex have the obligation to make this right??
If it was their fault, they should. If you fucked up, they don't have to.

Several reports of lost funds from cex.io these last few days. Hope its not another .io site getting "hacked".
johningreece
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile
January 08, 2014, 07:08:33 AM
 #17

Cex.io said "sorry for your loss"
rammy2k2
Legendary
*
Offline Offline

Activity: 1974
Merit: 1003



View Profile
January 08, 2014, 12:08:39 PM
 #18

i doubt cex.io is hacked ... i bet users have fallen for phising sites or keyloggers
empoweoqwj
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
January 08, 2014, 01:45:59 PM
 #19

i doubt cex.io is hacked ... i bet users have fallen for phising sites or keyloggers

You can't possibly know that. I haven't heard of of any cex.io phishing emails going around, but I have heard of several cex.io accounts being emptied recently .........
streetlogics
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile WWW
January 16, 2014, 09:06:36 PM
 #20

Was just logged in to cex.io chat and got 2 javascript alerts minutes apart with simply the text "1".

I logged back in a few minutes later to investigate, and discovered this in the "russian" tab of their chat window:

Code:
z66 : 20:25
“><img src="#" onerror="alert(1)"
Ramirez : 20:26
><img src="#" onerror="alert(1)"
Ramirez : 20:26
doesnt work
kickbit : 20:27
xe2x80x9c><img src="#" onerror="alert(1)"
Ramirez : 20:28
-->
Ramirez : 20:29
->

They have been alerted via twitter by others that noticed the problem too:
https://twitter.com/chrisfarms/status/423913046512128001
https://twitter.com/vvedma/status/423920180750610432

As a professional web developer, this is deeply concerning.

I am not sure that this is necessarily related to people having their accounts cleaned out, but it is certainly something to consider regardless as a "possibility".  Anyone who has studied computer information security knows how serious the potential for an XSS attack is, and it certainly should not be taken lightly.

You are free to draw your own conclusions, but personally I withdrew all my BTC from there a while ago.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!