Bitcoin Forum
May 28, 2015, 09:59:41 AM *
News: Latest stable version of Bitcoin Core: 0.10.2 [Torrent]
 
   Home   Help Search Donate Login Register  
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 »
  Print  
Author Topic: BTC Stolen from Poloniex  (Read 106789 times)
busoni
Sr. Member
****
Offline Offline

Activity: 350

Owner of Poloniex


View Profile

Ignore
March 04, 2014, 08:31:32 AM
 #1

All deposits, withdrawals, and markets are functioning normally. No further BTC will be deducted from anyone's balance.

On March 4th, 2014, about 12.3% of the BTC on Poloniex was stolen.

How Did It Happen?

The hacker found a vulnerability in the code that takes withdrawals. Here's what happens when you place a withdrawal:

1. Input validation.
2. Your balance is checked to see if you have enough funds.
3. If you do, your balance is deducted.
4. The withdrawal is inserted into the database.
5. The confirmation email is sent.
6. After you confirm the withdrawal, the withdrawal daemon picks it up and processes the withdrawal.

The hacker discovered that if you place several withdrawals all in practically the same instant, they will get processed at more or less the same time. This will result in a negative balance, but valid insertions into the database, which then get picked up by the withdrawal daemon.

What Did Poloniex Do Wrong?

The major problem here was that withdrawals should have been queued at every step of the way. This could not have happened if withdrawal requests were processed sequentially instead of simultaneously.

Additionally, auditing and security features were not explicitly looking for negative balances. They add deposits and withdrawals and check that accounts are in balance. If you have 2 BTC, withdraw 10 BTC, and are left with -8 BTC, the software would see that you deposited 2, withdrew 10, and have exactly what you should: -8.

What Did Poloniex Do Right?

The existing security features noticed unusual withdrawal activity and froze BTC. That is how the activity was discovered.

What Happens Now?

I take full responsibility for this and am committed to repaying the debt of BTC. The exchange funds are 12.3% short. Because there is not enough BTC to cover everyone's balances, all balances will temporarily be deducted by 12.3%. Please understand that this is an absolute necessity--if I did not make this adjustment, people would most likely withdraw all their BTC as soon as possible in order to make sure they weren't left in that remaining 12.3%. Aside from the obvious drawback of most of the BTC being taken out of the exchange, this would not be fair--some people would get all of their money right away, and a few would get none right away.

The amount deducted from everyone's balances will be recorded, and funds raised from exchange fees, as well as donations from my own pocket (which is not very deep, I'm afraid), will be distributed regularly to all users who have had BTC deducted. Exchange fees will be raised to expedite the recovery of the debt. 1.5% has been suggested by many people, but I will take input on this. Exchange fees will not be raised.

If I had the money to cover the entire debt right now, I would cover it in a heartbeat. I simply don't, and I can't just pull it out of thin air.

What Will Be Done to Prevent Further Exploits?

Withdrawals and order creation have been switched to a queued method, where the first step is to add the task to a global execution queue that is processed sequentially. Each step of critical database operations is verified before proceeding, and such operations are in the process of being converted to transactions. I have hired additional developers to help with tightening up security at Poloniex, as well as created a bug bounty.

-----

In conclusion...

I sincerely apologize for this, and I am very grateful to the many people who have already expressed their support and belief in my character. I take full responsibility; I will be donating some of my own money, and I will not be taking profit before the debt is paid.

I welcome your opinions on how to proceed, but please be constructive. I do not have the money to wave away the debt, so we'll need to work together.

Poloniex.com - Fast crypto exchange with margin trading, advanced charts, and stop-limit orders
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
★ BetChain Casino ★ 110% Welcome Bonus ✓ 197 Games ✓ 3,133 BTC Jackpot ★ PLAY NOW ★
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
1432807181
Hero Member
*
Offline Offline

Posts: 1432807181

View Profile Personal Message (Offline)

Ignore
1432807181
Reply with quote  #2

1432807181
Report to moderator
omahapoker
Hero Member
*****
Offline Offline

Activity: 532


The Powerful Licensed Exchange » https://bit-x.com


View Profile WWW

Ignore
March 04, 2014, 08:34:38 AM
 #2

at least your honest. thanks for the info and when we can trade again, CGA to the moon

BayAreaCoins
Hero Member
*****
Offline Offline

Activity: 700


I'm a "dot clammer"


View Profile WWW

Ignore
March 04, 2014, 08:35:22 AM
 #3

How many bitcoins is 12.3%?

BitQuick The best way to buy and sell Bitcoins with cash. (Worth a look) Click here
Do you have an account at the largest Bitcoin exchange? Futures, leverage, shorting, lending, loaning, margin trading and more.
Best Bitcoin sport book & casino!  If you owned BTC, LTC or DOGE on May 12, 2014 check out www.ClamcoinFaucets.com Pet Snails www.SnailsInTheMail.com
steeleminer
Jr. Member
*
Offline Offline

Activity: 49


View Profile

Ignore
March 04, 2014, 08:38:12 AM
 #4

Thank you for the detailed explanation. 

This is how a breech should be handled.
HashRent.com
Newbie
*
Offline Offline

Activity: 7


View Profile

Ignore
March 04, 2014, 08:38:18 AM
 #5

Address of the thief https://blockchain.info/address/1Ktq7TE3J5vZ3c99M5weqKfFcNkHQdqPrq
Total loss is around $50,000
Gordon Bleu
Sr. Member
****
Offline Offline

Activity: 308


verified ✔


View Profile WWW

Ignore
March 04, 2014, 08:39:23 AM
 #6

I'm OK with this-

GAWMiners http://gawminers.com/ Gridseed ASICS in stock in USA
ONE YEAR FREE HOSTING AND ELECTRICITY WITH PURCHASE!






AROUSR.COM The Adult Chat Community (21+) We now accept BTCitcoins Smiley               |
Connect with hot girls for chat, talk, trade pics and more!➠Visit http://arousr.com (21+)|
stevenb
Sr. Member
****
Offline Offline

Activity: 378


View Profile

Ignore
March 04, 2014, 08:39:45 AM
 #7

Keep it up Busoni, will continue to support your exchange.

ps: have you checked my pm? please process deposit too, there're no pending deposit in my account but it has over 6 confirmations.

BTC address: 147WCTMf94biQKCGZL39Lyr2oc3b6tj6We | LTC address: LYnpCWatYJyNKsWoNHGt4UBqVcBBP4CyGY
-reputation-
https://bitcointalk.org/index.php?topic=208061.0
sang
Sr. Member
****
Offline Offline

Activity: 274


View Profile

Ignore
March 04, 2014, 08:39:50 AM
 #8

Completely respect your openness and honesty. Best of luck to you.
jgivg
Newbie
*
Offline Offline

Activity: 24


View Profile

Ignore
March 04, 2014, 08:40:20 AM
 #9

Seems like you're handling this very well.
fairglu
Hero Member
*****
Offline Offline

Activity: 504


View Profile WWW

Ignore
March 04, 2014, 08:42:30 AM
 #10

Would you consider adding a shares systems like several other exchanges have?

Shares would pay dividends, and the sales of shares would help cover the debt. Obviously this may require some development work, but might allow swifter recovery.

RenegadeMind
Sr. Member
****
Offline Offline

Activity: 406


Tell me something you don't know...


View Profile WWW

Ignore
March 04, 2014, 08:44:17 AM
 #11

How will this affect orders? I have most BTC on orders right now.

HUC!
bookbuster
Newbie
*
Offline Offline

Activity: 10


View Profile

Ignore
March 04, 2014, 08:45:08 AM
 #12

I am sorry about the loss.  You can keep my business if you follow through with what you've said here.  You have my support


Is it just BTC balances that are affected?  What about alt balances?
uygar2580
Full Member
***
Offline Offline

Activity: 196


View Profile

Ignore
March 04, 2014, 08:45:37 AM
 #13

My all balance on orders. Thats my bad luck. I have  about %30 loss.
WaffleMaster
Sr. Member
****
Offline Offline

Activity: 294


Be wise.


View Profile

Ignore
March 04, 2014, 08:45:50 AM
 #14



A short muggle starting with the online handle josg21 to, allegedly, ■■■■■ about boob jobs (plastic surgeons) and poor service Mr Homero Garza has since changed to the handle GAWCEO. A while later after tainting the handle GAWCEO a change was made to MrCEO and minerorigin which exist in parallel. In order to, allegedly, attempt confusion over his real name Homero Joshua Garza uses his middle name and mixes up aliases so he is commonly known as Josh Garza or Joshua Garza. On several patents held with Mr. Stuart Fraser Vice Chairman of Cantor Fitzgerald, Garza uses H. Joshua Garza as opposed to H. Josh Garza. Various internet Trolls and FUDsters refer to him as Homero Garza or Homero Josh Garza or just Mr. Scam Muggle. Mr Garza, allegedly, started his entrepreneurship with Optima Computers LLC in Brattleborough Vermont (VT) where he then branched out into the, alleged, oversubscription of Broadband service with his company Great Awk Wireless also called GAW High Speed Internet and shortened to GAW HSI. Having claimed to make millions with this service or sale of the company or something, Mr Garza then went on to the cryptocurrency industry where he, allegedly, applied the same oversubscription techniques to ASIC Mining with his platforms ZenMiner and ZenCloud selling virtual products called the Hashlet and Hashtaker. Sometimes referred to as CashLets, CashTakers and Ponsi's. Through the purported success of said platforms under a conglomerate of companies called Geniuses at Work or GAW for short Mr Garza, allegedly, moved on from GAW Miners LLC to a new company which should have provided a clean slate. Business Technology for Cryptocurrency LLC or BTC LLC for short which matches the domain name BTC.com puportedly purchased for 1.1 Million USD, was born. This company launched several platforms such as PayBase at Paybase.com and paycoin known as XPY. The PayBase platform allegedly destroyed the products PayFlash (gyft) PaySave (zincsave) as well as others. The Paycoin "Currency" allegedly destroyed the concepts of HybridFlex, FundSafe, Huh. After much public scrutiny Mr Homero Joshua Garza married to Jessica Garza then set out to not own the platforms Coinstand at coinstand.com (which used an, allegedly, embezzled codebase called zincsave to purchase from Amazon violating the ToS) and mineral at mineral.com (which used an, allegedly, embezzled codebase called coin-swap). These new ventures were purportedly related to Hong-Kong, hong kong, while rumor persists of Dubai being the real location.

There once was a muggle from nantucket who wanted to go to the World Cup 2014, he was flying on Malaysian Airlines and researching Robin Williams on his iPhone 6. at one point during the trip he played Flappy Bird. The traveler did not know what رمضان‎ or رامز قرش البحر‎ meant though he knew they were important.

Mr. Stuart Fraser Vice Chairman Cantor Fitzgerald. cantor fitzgerald, cantor capital markets, cantor investment banking, cantor investment management, cantor global financial services: Cantor Fitzgerald is one of the premier capital markets investment banks. Cantor specializes in global financial services with many locations across the U.S and around the world.
GAWCEO, MrCEO, josg21, Homero Garza, Josh Garza, Homero Josh Garza, Homero Joshua Garza, H. Josh Garza, H. Joshua Garza, Fraud, Scam, Rippoff
Dave McLain, David McLain, Dave H McLain, David H McLain, David H. McLain serves as COO and General Counsel of Hat Trick Consultants, LLC as well as a principal in DHM Legal Services, LLC., Assistant General Manager of the Fort Worth Brahmas,

Crypto Private Investor Group is bigger than any one person. CPGI is a collaboration, made up of members from all over the world. Professional backgrounds of CPIG members include professors, scientists, engineers, technology experts and more. It's the combination of our talents that makes CPIG strong and able to positively impact the global crypto industry. Walnut, CA, cryptsy
RenegadeMind
Sr. Member
****
Offline Offline

Activity: 406


Tell me something you don't know...


View Profile WWW

Ignore
March 04, 2014, 08:46:04 AM
 #15

Would you consider adding a shares systems like several other exchanges have?

Shares would pay dividends, and the sales of shares would help cover the debt. Obviously this may require some development work, but might allow swifter recovery.

This sounds like a good idea. mcxNOW has mcxFEEs for this. Vircurex does something similar, but not to the degree that mcxNOW does.

I'd be interested in buying poloFEEs.

And +1 for the openness and honesty.

HUC!
SkillRoad
Member
**
Offline Offline

Activity: 112


View Profile

Ignore
March 04, 2014, 08:46:23 AM
 #16

Good that you have found a problem




_______________________________________________________________________________ _________________________________
Next Coin Lite - Fair Distribution
simonhard
Member
**
Offline Offline

Activity: 66


View Profile WWW

Ignore
March 04, 2014, 08:47:17 AM
 #17

Go on working that hard and good! Thanks for the info!
stereotype
Hero Member
*****
Offline Offline

Activity: 798



View Profile

Ignore
March 04, 2014, 08:47:24 AM
 #18

An absolute fine example of how these matters should be dealt with. Thats what i call customer care.

[what happened] - [why it happened] - [what the resolution is]

Thankyoumuch.

***Tired of trading stupid shitcoins? Use your BTC to trade Stocks, Forex, Indices, and Commodities, with up to x200 leverage.***
                                                https://1broker.com/m/r.php?i=2651
jaideep1000
Member
**
Offline Offline

Activity: 105


View Profile

Ignore
March 04, 2014, 08:47:33 AM
 #19

I have just made a btc deposit a few mins ago so will mine be deducted as well even if I'm using the site for the first time?
Aditya
Full Member
***
Offline Offline

Activity: 159

Selling Authentic Indonesian Products


View Profile WWW

Ignore
March 04, 2014, 08:50:27 AM
 #20

I wish Karpeles is just as honest & transparent as you do.

Bitrated user: adit.
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 »
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!