Bitcoin Forum
November 06, 2024, 01:31:38 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 [175] 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 ... 661 »
  Print  
Author Topic: [ANN][XCP] Counterparty - Pioneering Peer-to-Peer Finance - Official Thread  (Read 1276760 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
TheMightyX
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250

Vires in Numeris


View Profile
February 19, 2014, 05:06:05 PM
 #3481

Holy shit. I wake up to this  Huh

People... for the love of god don't panic until we know all the facts. Don't mindlessly dump your XCP at the first opportunity (or do, as long as it's into my hands).
busoni
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250

Owner of Poloniex


View Profile
February 19, 2014, 05:06:25 PM
 #3482

I don't see any evidence that Poloniex was hacked. The guy who dumped messaged me and said that the XCP protocol is not safe. It appears he is correct--there seems to be a major issue with XCP. People noticed that 35,000 XCP were withdrawn as soon as it was deposited--but this was not done using Poloniex's withdrawal system. I've asked the guy for more details. He says he has no intention of keeping the money he made off with.

I don't understand.
Busoni if what you are saying is right than all users XCP and BTC are safe?



He said "the XCP protocol is not safe, as anyone can spend any XCP present." And the evidence on Poloniex is that this is true. He made a legitimate deposit to get a balance on Poloniex, then took the XCP without using Poloniex's withdrawal system, so his balance was not subtracted. If he had hacked Poloniex and gotten privileges to cover up a withdrawal, there would be no need for the legit deposit. The actions are consistent with him having some way of whisking the XCP out of the central wallet. And unless this is a vulnerability with XCP, the only way to do that would be to have total access to the wallet server, and as I said, he didn't take anything else.

He expressed a desire to work the problem out. It seems to have been a demonstration rather than a theft.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
savithau68
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
February 19, 2014, 05:09:03 PM
 #3483

I don't see any evidence that Poloniex was hacked. The guy who dumped messaged me and said that the XCP protocol is not safe. It appears he is correct--there seems to be a major issue with XCP. People noticed that 35,000 XCP were withdrawn as soon as it was deposited--but this was not done using Poloniex's withdrawal system. I've asked the guy for more details. He says he has no intention of keeping the money he made off with.

I don't understand.
Busoni if what you are saying is right than all users XCP and BTC are safe?



He said "the XCP protocol is not safe, as anyone can spend any XCP present." And the evidence on Poloniex is that this is true. He made a legitimate deposit to get a balance on Poloniex, then took the XCP without using Poloniex's withdrawal system, so his balance was not subtracted. If he had hacked Poloniex and gotten privileges to cover up a withdrawal, there would be no need for the legit deposit. The actions are consistent with him having some way of whisking the XCP out of the central wallet. And unless this is a vulnerability with XCP, the only way to do that would be to have total access to the wallet server, and as I said, he didn't take anything else.

He expressed a desire to work the problem out. It seems to have been a demonstration rather than a theft.

We also want to work on this. Please give more details
Patel
Legendary
*
Offline Offline

Activity: 1321
Merit: 1007



View Profile WWW
February 19, 2014, 05:11:06 PM
Last edit: February 19, 2014, 05:30:08 PM by Patel
 #3484

The original 35000 withdrawal from 15vA2MJ4ESG3Rt1PVQ79D1LFMBBNtcSz1f (Poloniex address) was signed by that private key to complete the withdrawal/send. The attacker somehow got access to process the transaction from Poloniex account. If he didn't, that means there is a huge flaw in Bitcoin.

 https://blockchain.info/tx/17d02a863919b7338e892d7a7da05f6e6529e5b97e3391d700a802b175978915
lonsharim
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
February 19, 2014, 05:11:32 PM
 #3485

newbie question here,

If I don't have the counterparty/XCP wallet program installed yet, but I want to withdraw my XCP from Poloniex (assuming I can!), can I just send it to a bitcoin address that I control? And then later, import that bitcoin address into the XCP wallet program?

(In other words, am I right in understanding that my XCP address is just a bitcoin address I own?)  How would I later "import" it into XCP?

You assumptions are correct. As long as you can control your private key you will be able to control the XCP associated with it and where ever you want to import it.
sixteendigits
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
February 19, 2014, 05:12:43 PM
 #3486

I don't see any evidence that Poloniex was hacked. The guy who dumped messaged me and said that the XCP protocol is not safe. It appears he is correct--there seems to be a major issue with XCP. People noticed that 35,000 XCP were withdrawn as soon as it was deposited--but this was not done using Poloniex's withdrawal system. I've asked the guy for more details. He says he has no intention of keeping the money he made off with.

I don't understand.
Busoni if what you are saying is right than all users XCP and BTC are safe?



He said "the XCP protocol is not safe, as anyone can spend any XCP present." And the evidence on Poloniex is that this is true. He made a legitimate deposit to get a balance on Poloniex, then took the XCP without using Poloniex's withdrawal system, so his balance was not subtracted. If he had hacked Poloniex and gotten privileges to cover up a withdrawal, there would be no need for the legit deposit. The actions are consistent with him having some way of whisking the XCP out of the central wallet. And unless this is a vulnerability with XCP, the only way to do that would be to have total access to the wallet server, and as I said, he didn't take anything else.

He expressed a desire to work the problem out. It seems to have been a demonstration rather than a theft.

We also want to work on this. Please give more details

Uhhhhhhh..............no.  Please do not give more details.  If it is a fault with XCP the only people he should be sharing details with are the devs.
busoni
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250

Owner of Poloniex


View Profile
February 19, 2014, 05:13:09 PM
 #3487

The stolen 35,000 XCP was sent to 1HMoHdzaHm9cHR8FjekGRtkkydoHfgaC8S.

I just checked the Poloniex BTC wallet's transaction history, and nothing was ever sent to 1HMoHdzaHm9cHR8FjekGRtkkydoHfgaC8S.

To me, that says he sent it without hacking Poloniex.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
busoni
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250

Owner of Poloniex


View Profile
February 19, 2014, 05:15:02 PM
 #3488

XCP is not at fault here. Its Poloniex.

The original 35000 withdrawal from 15vA2MJ4ESG3Rt1PVQ79D1LFMBBNtcSz1f (Poloniex address) was signed by that private key to complete the withdrawal/send. The attacker somehow got access to process the transaction from Poloniex account. If he didn't, that means there is a huge flaw in Bitcoin. Which I highly doubt. I think Busoni is lying, and this whole thing was staged. But that's just my opinion. I never used Poloniex, and don't plan on it.

 https://blockchain.info/tx/17d02a863919b7338e892d7a7da05f6e6529e5b97e3391d700a802b175978915

Those are internal Poloniex addresses, that is the XCP being moved into the main wallet.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
TheMightyX
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250

Vires in Numeris


View Profile
February 19, 2014, 05:16:04 PM
 #3489

I don't see any evidence that Poloniex was hacked. The guy who dumped messaged me and said that the XCP protocol is not safe. It appears he is correct--there seems to be a major issue with XCP. People noticed that 35,000 XCP were withdrawn as soon as it was deposited--but this was not done using Poloniex's withdrawal system. I've asked the guy for more details. He says he has no intention of keeping the money he made off with.

I don't understand.
Busoni if what you are saying is right than all users XCP and BTC are safe?



He said "the XCP protocol is not safe, as anyone can spend any XCP present." And the evidence on Poloniex is that this is true. He made a legitimate deposit to get a balance on Poloniex, then took the XCP without using Poloniex's withdrawal system, so his balance was not subtracted. If he had hacked Poloniex and gotten privileges to cover up a withdrawal, there would be no need for the legit deposit. The actions are consistent with him having some way of whisking the XCP out of the central wallet. And unless this is a vulnerability with XCP, the only way to do that would be to have total access to the wallet server, and as I said, he didn't take anything else.

He expressed a desire to work the problem out. It seems to have been a demonstration rather than a theft.

I feel like you are making grand show out of pointing out a potential flaw in a very public manner.

"Ya i've heard satoshi built a kill-switch into the genesis block of bitcoin and can tank it at any time".
See what I did there? Who the fuck knows? but talking about it out in the open is only going to frighten the lesser informed individuals.

This is something that should be discussed with the developers directly. Not tossed about on the forums for weak hands to see.
TheMightyX
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250

Vires in Numeris


View Profile
February 19, 2014, 05:19:26 PM
 #3490

The important matter is did the attacker withdraw the btc he received from dumping the XCP?
If not, the orders can be reversed and the private keys can be changed.
vivinamie
Member
**
Offline Offline

Activity: 206
Merit: 10


View Profile
February 19, 2014, 05:22:40 PM
 #3491

busoni,my xcp balance will back to poloniex account
and can withdraw?
lonsharim
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
February 19, 2014, 05:25:00 PM
 #3492

The important matter is did the attacker withdraw the btc he received from dumping the XCP?
If not, the orders can be reversed and the private keys can be changed.
According to busoni attacker didn't withdraw all his btc ergo some was left behind and some was withdrawn. How much he has withdrawn has not specified.
busoni
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250

Owner of Poloniex


View Profile
February 19, 2014, 05:25:22 PM
 #3493

Got a response from the guy, he explained the vulnerability. I am now contacting the devs privately.

Poloniex was not hacked.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
peled1986
Legendary
*
Offline Offline

Activity: 882
Merit: 1002


View Profile
February 19, 2014, 05:26:42 PM
 #3494

busoni please answer how many BTC the attacker still has in his account?
and if all users BTC are safe? (I am no talking about the btc the attacker got from the 35,000 xcp sell and withdraw)
ddink7
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000



View Profile
February 19, 2014, 05:28:19 PM
 #3495

Guys, why don't we reserve judgement on Poloniex and Busoni until we hear back one way or the other from the devs. Until we hear from them, everything is just speculation.

Busoni says he explained the vulnerability, now we wait.

Dash - Digital Cash
https://www.dash.org/
busoni
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250

Owner of Poloniex


View Profile
February 19, 2014, 05:29:36 PM
 #3496

I messaged PhantomPhreak, but if any XCP developers are online right now, please message me right away.

The attacked left 35BTC in his account. He has been very cooperative so far and has asked for an address to return the BTC he took. I'll keep you all updated.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
ginko-B
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile
February 19, 2014, 05:29:55 PM
 #3497

This is as good a time as any to make a plug for the DEX.

Let's fix the issue with trolling orders so we don't have to worry about centralized points of failure ever again.

+1

Why would a hacker wanting to make a demonstration have done the deed on Poloniex and not the DEX?  If he really wanted to show a problem with the protocol he would have hacked the DEX.
lemfuture
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


View Profile
February 19, 2014, 05:30:10 PM
 #3498

trouble in paradise  Roll Eyes

1ADLcfwTofFXb95pKhebpeRkJ4WTWsvQXB
SyRenity
Hero Member
*****
Offline Offline

Activity: 756
Merit: 502


View Profile
February 19, 2014, 05:32:28 PM
 #3499

Wow, that disappointing...
That said, I'm happy that it happened so early, before XCP has spread to other exchanges.

Also, seems that it will boost the Dex (as it should), as it seems to be much safer (or so I hope!).
SyRenity
Hero Member
*****
Offline Offline

Activity: 756
Merit: 502


View Profile
February 19, 2014, 05:33:15 PM
 #3500

Ok I think I see the vulnerability as well. I am inclined to believe busoni now. Hopefully the devs will get right on it.

The good news is if our benevolent attacker friend didn't withdraw his BTC everything can just be rolled back.

Clever attack.

Will you explain it after it was plugged?
Pages: « 1 ... 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 [175] 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 ... 661 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!