Bitcoin Forum
November 01, 2024, 01:06:35 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 [41] 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 ... 117 »
  Print  
Author Topic: [ANN - NEW EXCHANGE] | www.CoinMarket.io | OFFICIAL THREAD  (Read 143460 times)
Sparkzor
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
January 25, 2014, 06:52:59 PM
 #801



Here are the trades the hacker made in my account. He cleared out 90% of my coins in the space of a few minutes, these trades are very quick, looks automated to me. It is certainly not a pool password because I use a different password for pools and a unique password for each exchange.

Coinmarket.io, I have a friend who is a infosec specialist, can you contact me please with some info regarding site security so I can get him to audit it for me please? I REALLY don't think the vulnerability was my password here and that you may have a bigger problem.


I'm a sad trader today, all the coins I was holding nearly doubled and I am left with nothing Sad

Donations very welcome Cry
Yeah the exact same happened with me ^^
ibukovec
Newbie
*
Offline Offline

Activity: 25
Merit: 0


View Profile
January 25, 2014, 06:53:37 PM
 #802

It looks like I have either been hacked or the wrong account has been given to me.
Please contact me about this ASAP, thanks.
From looking at trade history it seems that someone has used my account to buy 50k doges at 900 satoshie each.
This wasn;t me, is there any way trade can be rolled back here? I have lost a lot of money here...

Unfortunately there is nothing we can do, your account (usename and password) are your responsibility.
We will attempt to reverse the trades with users that we are 100% sure are connected to that person.
Many people have got burnt by using the same user/password combination here and on some pools.
Pools get hacked, passwords leak. Semi-strong passwords get cracked by dictionary attacks.

There is no vulnerability server-side. Even it it were, we are not liable for any damages.

I used a strong, unique password with capital, lowercase and non-alphanumeric figures. I do not think it was brute forced of hacked from a pool.
I would seriously audit things server side if I were you.

Do you need any info from me regarding trade reversals?
Maybe the server is safe and maybe ppl use same username/psw for pool and market. But if your market worked the right way such trade should be possible at all. If you put in a rediculus high price the market should buy from best offers upwards and not right away with the wrong price. There lies your responsibility

The trade the hacker made for me:

Type   Timestamp   Amount   Price   Fee   Total
Buy   Sat Jan 25 13:14:10   3574.2394775 DOGE   0.00000689   0%   0.02462651 BTC
Giggety
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 25, 2014, 06:54:28 PM
 #803

When are you guys going to fix this:

Type   Timestamp   Amount   Price   Total
N/A   Sat Jan 25 19:52:37   1898.3 KDC   0.00020100   0.38155830 BTC


Type is always N/A
DarknessYY
Newbie
*
Offline Offline

Activity: 36
Merit: 0


View Profile
January 25, 2014, 06:56:55 PM
 #804

I recharge the 50Wdgb, but has not arrived, the wallet has been unrecognized state, Please tell me how to solve  THAKNS Cry
coinmarket.io (OP)
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 25, 2014, 06:57:18 PM
 #805

Go ahead and try to make an order with ridiculous price, see what happens.
DarknessYY
Newbie
*
Offline Offline

Activity: 36
Merit: 0


View Profile
January 25, 2014, 07:00:19 PM
 #806

Go ahead and try to make an order with ridiculous price, see what happens.
I recharge the 50Wdgb, but has not arrived, the wallet has been unrecognized state, Please tell me how to solve  thanks
coinmarket.io (OP)
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
January 25, 2014, 07:02:52 PM
 #807

Go ahead and try to make an order with ridiculous price, see what happens.
I recharge the 50Wdgb, but has not arrived, the wallet has been unrecognized state, Please tell me how to solve  thanks
Provide username and transaction ID.
BlueTunic
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
January 25, 2014, 07:03:58 PM
 #808

Hey, I signed up with you guys a while back and used a test e-mail on my account; it never actually asked me for e-mail confirmation, so when I went to actually do some trading, and withdraw coins, it sent the confirmation email to... you guessed it, the test account, which I don't have access to.

Is there any way I can get the withdrawl that I did reverted or get the confirmation e-mail sent to my actual e-mail address?

Give me your username, i'll confirm your withdrawal manually and you will crate an another account with the right details after that.

BlueTunic
incorrect
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 25, 2014, 07:05:10 PM
 #809

Could you do the same for me with the email? I can't get a verification either.
mrbildo
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
January 25, 2014, 07:05:37 PM
 #810

It looks very obvious to me that the exchange was hacked last night, what is the explanation for the downtime all night last night? How come your dev lost SSH access all night?
I do not think that this occurrence and the fact that users are finding their accounts hacked during the night is a complete coincidence.

Again, I request information on the security measures present on the exchange so that I can have them independently audit. I am 90% sure the vulnerability was not my password, it was non-dictionary, unique and had caps, lower case and non alphanumerics, not the type of password is is easy to crack in that small a time window.

The high order filling was a bug, and combined with possible breach to site security constitutes a working vulnerability. There was a 0.25btc bounty for this advertised a while back.
DarknessYY
Newbie
*
Offline Offline

Activity: 36
Merit: 0


View Profile
January 25, 2014, 07:08:16 PM
 #811

Go ahead and try to make an order with ridiculous price, see what happens.
I recharge the 50Wdgb, but has not arrived, the wallet has been unrecognized state, Please tell me how to solve  thanks
Provide username and transaction ID.
   username:yysqsd   transaction ID:5022decc8836924e94a7371c249d7dbaaee53c94455a92f08fd6abfdedb29dd4
 thanks Smiley
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
January 25, 2014, 07:10:31 PM
 #812

FFS. Coinmarket just went down as I requested a BTC withdrawal.

I'm going to throw a fit if that vanishes.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
podyx
Legendary
*
Offline Offline

Activity: 2338
Merit: 1035



View Profile
January 25, 2014, 07:10:38 PM
 #813

Site is down?
BlueTunic
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
January 25, 2014, 07:11:51 PM
 #814

Just want to say, Coinmarket handled my issue with no problems and the btc that I was transferring is now sitting pretty in my wallet. Thank you for your support, Coinmarket Smiley
mrbildo
Member
**
Offline Offline

Activity: 102
Merit: 10


View Profile
January 25, 2014, 07:12:32 PM
 #815

Site is down for me too. Maybe someone's password is being hacked again...
AdamT
Hero Member
*****
Offline Offline

Activity: 486
Merit: 500


View Profile
January 25, 2014, 07:13:42 PM
 #816

Could you do the same for me with the email? I can't get a verification either.

Me as well, user: deep

Withdrew 50k NOBL yesterday morning, no conf email. Please push through manually, much appreciated!
incorrect
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 25, 2014, 07:15:20 PM
 #817

Me as well, user: deep

Withdrew 50k NOBL yesterday morning, no conf email. Please push through manually, much appreciated!

Username: Near

I really hope we can sort this out soon I want to sleep knowing my coins are safe.  Wink
podyx
Legendary
*
Offline Offline

Activity: 2338
Merit: 1035



View Profile
January 25, 2014, 07:17:07 PM
 #818

My 80 KDC that I sent when site went down was duplicated lol

not alot of money but just letting you know, if you want them back or something
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
January 25, 2014, 07:19:49 PM
 #819

My 80 KDC that I sent when site went down was duplicated lol

not alot of money but just letting you know, if you want them back or something

If it was a glitch I doubt those coins actually exist. I wouldn't risk trying to sell them or you may end up with a negative balance.

FYI, my BTC withdrawal never went through when the site went down. Once it was back up I made the withdrawal and recieved the BTC instantly. Love how fast this site is. Hope they continue developing it.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
ibukovec
Newbie
*
Offline Offline

Activity: 25
Merit: 0


View Profile
January 25, 2014, 07:21:48 PM
 #820

Go ahead and try to make an order with ridiculous price, see what happens.

If it works right now it dosnt mean it did today when the hacker made the orders. If it worked then right then the thief is one of you or your server was hacked.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 [41] 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 ... 117 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!