Bitcoin Forum
April 25, 2024, 04:48:31 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: [RESOLVED] Bitherium.cc not a full decentralized exchange - PrivKey leaks  (Read 577 times)
Mallyx (OP)
Hero Member
*****
Offline Offline

Activity: 1138
Merit: 574



View Profile
February 26, 2020, 03:56:03 PM
Last edit: March 03, 2020, 10:55:41 AM by Mallyx
Merited by nutildah (3), notblox1 (1), CucakRowo (1)
 #1

Resolved here: https://bitcointalk.org/index.php?topic=5228661.msg53954607#msg53954607
Archive of that thread: http://web.archive.org/web/20200303104953/https://bitcointalk.org/index.php?topic=5228661.0&all=
Archive of the official thread: http://web.archive.org/web/20200303105444/https://bitcointalk.org/index.php?topic=5226563.0&all=

tldr;
1. I accused them to send the users privatekeys to the server.
2. They goes to maintenance mode, then back online.
3. It seem they resolved the issue.




Accusation:
Bitherium claim to be a full decentralized exchange, but your private key and password are sent plaintext to the server.


Proof:
You can try by yourself, but here a screenshot of the XHR POST request when you create an account:






And when you want to unlock your wallet:






Obliviously, everything is managed server-side. A token is bind to you. It mean that your private key remain on the server somehow:




Other red flags:
  • Hidden team.
  • Very hard to verify the Seychelles Certificate of Incorporation.
  • Many low accounts are enjoying Bitherium on the main thread.
  • Hidden WHOIS.


Official thread: https://bitcointalk.org/index.php?topic=5226563.0
1714020511
Hero Member
*
Offline Offline

Posts: 1714020511

View Profile Personal Message (Offline)

Ignore
1714020511
Reply with quote  #2

1714020511
Report to moderator
"The nature of Bitcoin is such that once version 0.1 was released, the core design was set in stone for the rest of its lifetime." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714020511
Hero Member
*
Offline Offline

Posts: 1714020511

View Profile Personal Message (Offline)

Ignore
1714020511
Reply with quote  #2

1714020511
Report to moderator
1714020511
Hero Member
*
Offline Offline

Posts: 1714020511

View Profile Personal Message (Offline)

Ignore
1714020511
Reply with quote  #2

1714020511
Report to moderator
Jawhead999
Legendary
*
Offline Offline

Activity: 1638
Merit: 1155



View Profile
February 26, 2020, 04:54:28 PM
 #2

Domain : bitherium.cc
Registrar : DYNADOT, LLC
Registered On : 2019-04-05
Expires On : 2020-04-05
Updated On : 2020-02-25
Status : clientTransferProhibited
Name Servers : liv.ns.cloudflare.com
                        mario.ns.cloudflare.com

I using this site to find the WHOIS https://www.whois.com/whois/bitherium.cc



I also don't understand about his invest plan, it's like a certain level to earn more profit. Maybe a ponzi? But I'm not sure.. just my suspicion

.freebitcoin.       ▄▄▄█▀▀██▄▄▄
   ▄▄██████▄▄█  █▀▀█▄▄
  ███  █▀▀███████▄▄██▀
   ▀▀▀██▄▄█  ████▀▀  ▄██
▄███▄▄  ▀▀▀▀▀▀▀  ▄▄██████
██▀▀█████▄     ▄██▀█ ▀▀██
██▄▄███▀▀██   ███▀ ▄▄  ▀█
███████▄▄███ ███▄▄ ▀▀▄  █
██▀▀████████ █████  █▀▄██
 █▄▄████████ █████   ███
  ▀████  ███ ████▄▄███▀
     ▀▀████   ████▀▀
BITCOIN
DICE
EVENT
BETTING
WIN A LAMBO !

.
            ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
▄▄▄▄▄██████████████████████████████████▄▄▄▄
▀██████████████████████████████████████████████▄▄▄
▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
  ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
       ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.PLAY NOW.
matejbilahora
Sr. Member
****
Offline Offline

Activity: 1414
Merit: 275

Community built, Privacy driven


View Profile
February 27, 2020, 09:30:55 AM
 #3

Well this is going to be interesting. I knew it is scam from the first moment I have seen it. Too much nice talk about it and not much proof about who is who. That paper from Seychelles Certificate of Incorporation can be faked.
notblox1
Legendary
*
Offline Offline

Activity: 2044
Merit: 1263


Logo Designer ⛨ BSFL Division1


View Profile WWW
February 27, 2020, 11:01:32 AM
 #4

Great work OP
This is multiple way scam.
Now I expect to see their clown account to come here and write a bunch of stupid things

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
watergold
Sr. Member
****
Offline Offline

Activity: 1218
Merit: 251



View Profile
February 27, 2020, 03:41:51 PM
 #5

It turns out that there are still many scamers who continue to commit fraud and that is the average claiming to be a fully decentralized exchange, even though they want to find users by importing their private that has been saved by scamer. This is an extraordinary catch in my opinion.

         ▄▄▄███████▄▄▄
     ▄▀█▀█ █████████████▄▄
   ▄██ █ █▄████████████████▄
  ██ █ ██▀█ █████████████████
 █▀█▄█▄▀█▄██▄█████████████████
██ █ ██ ██ ██▄▀████████████████
███▀█▀██ ███▀███▀██████████████
███▄██ ██▄▀██▄███▄█████████████
 ███▄▀██▀██▄▀██▄▀██▄▀▀████████
  █████▀█▄█▀█▄▀▀██▄▀▀██▄▄▀█▀█
   ▀████▄███▄█▀█▄▄▀▀▀█▄▄█▀█▀
     ▀▀████▄▀██▄▄█▀▀█▄▄▄▀▀
         ▀▀▀██▄▄███▀▀▀
.
1xBit.com BENEFIT SEASON
       ▄▄███████████▄▄
    ▄███████████████████▄
  ▄██████████████████████▄
 █████████████████████████
██████████████████████████▌
████████████████████████████▄▄
███████████████████████████████
        █    █▄   █
        ▀▀▄    ▀▀▀█▀▀▀█▀▀▀▀▀▀▀█
           ▀▀▄    ▀▀▄▄█      ▄▀
              ▀▀▄     █▀▀▄▄  █
                 ▀▀▄  █   ▄█▀
                    ▀▀█▄▀▀
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
.
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
.
PLAY NOW
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
bitherium.cc
Copper Member
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 27, 2020, 05:08:44 PM
 #6

Hello Bitcointalk,


It took a little longer because we had to reconstruct and evaluate things first.

To the allegations

We never have and will never collect or keep private keys from wallets.

Some users seem to be trying hard to spread fud, thanks for that.
However, we do not accept any dubious offers from you to receive positive fake posts here in Bitcointalk. We are a hard working project. We do not need this and will not respond to your offers.

If we were Scammers, we wouldn't program Dex. We would also not be transparent in our external communication. All accusations are nothing more than accusations and defamations

We are completely in the development phase. Deposits and withdrawals are deactivated.

Here you can see that we are working on the development of our smart contract (which is not yet finished): https://ropsten.etherscan.io/address/0x8b1c480428038e93f9e99fc9e34194a5f4c1fc60#code

The accusations that the privatekey is read by users completely invented. This screenshot only shows that the user can see his own private key in his own browser session!

Here is a report from our developer team:





The consequences:

We will immediately end the ability to create wallets directly about our exchange. We will add a link to MyEtherWallet with a note on creating a Keystore wallet.

Now we are on the next topic
We immediately end the possibility that the user can log in to us with his private key. It only works with the metamask, Keystore file and we will work on it to connect to the general ledger.

Thanks a lot for this organized, negative campaign it made sure that we will make bitherium even safer.
notblox1
Legendary
*
Offline Offline

Activity: 2044
Merit: 1263


Logo Designer ⛨ BSFL Division1


View Profile WWW
February 27, 2020, 06:05:47 PM
 #7

Here he is with his feelings hurt now....oh poor little clown worried about imagined evil 'campaign' against their circus.
It would also be good to learn proper English language when you write, but it will not help you.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
bitherium.cc
Copper Member
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 27, 2020, 06:49:22 PM
 #8

Here he is with his feelings hurt now....oh poor little clown worried about imagined evil 'campaign' against their circus.
It would also be good to learn proper English language when you write, but it will not help you.

Thank you very much for your non constructive and totally useless post. Your words are saying much more about you now.
notblox1
Legendary
*
Offline Offline

Activity: 2044
Merit: 1263


Logo Designer ⛨ BSFL Division1


View Profile WWW
February 27, 2020, 08:19:15 PM
Last edit: February 27, 2020, 08:33:54 PM by notblox1
 #9

Thank you very much for your non constructive and totally useless post. Your words are saying much more about you now.

Your actions and lies say much more about you.


You can use your private key, keystore file, metamask  to log into our exchange, just like every decentralized exchange offers this login, similar to myetherwallet.
We can't collecting or saving anything from this details.

Our hired developer company got questions about security and we will inform you as soon as possible. If dev company have created any security issues we will publish their name immediately. For now it looking like the users can see their own private keys only in their own web browser and the exchange only authorize them.

We never have and will never collect or keep private keys from wallets.

Some users seem to be trying hard to spread fud, thanks for that.
However, we do not accept any dubious offers from you to receive positive fake posts here in Bitcointalk. We are a hard working project. We do not need this and will not respond to your offers.

If we were Scammers, we wouldn't program Dex. We would also not be transparent in our external communication. All accusations are nothing more than accusations and defamations

The accusations that the privatekey is read by users completely invented.

We immediately end the possibility that the user can log in to us with his private key. It only works with the metamask, Keystore file and we will work on it to connect to the general ledger.

Why did you stop your shit if everything is 'invented' ?

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
Mallyx (OP)
Hero Member
*****
Offline Offline

Activity: 1138
Merit: 574



View Profile
February 27, 2020, 08:33:48 PM
Last edit: February 27, 2020, 08:49:27 PM by Mallyx
 #10

The screens are only showing the XHR request with all the data, that was sent to the server. The data contain your private key, password.
On most browsers it's easy to track the network activities.

Not even technicaly speaking, a real DEX just don't need your private key. It only need your sign to commit an action to the blockchain. The smartcontract do the job.

1. You send the private key to the server.
2. Then you identify the user though a token to commit an order (like buying), which mean that the private key is stored server-side.

It's not how work a DEX.



 Wink
criticalknow
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
February 27, 2020, 09:10:04 PM
 #11

they're both stupid or just retarded, or both  Huh Huh Huh

They both got too little love ?

He has stated that the exchange is currently development phase
and a decentralized smart contract is in development progress

Don't you understand what that statement means?


that it was a hybrid exchange before and everything went well

they make themselves completely ridiculous

 Roll Eyes Roll Eyes Roll Eyes Roll Eyes Roll Eyes Grin
Mallyx (OP)
Hero Member
*****
Offline Offline

Activity: 1138
Merit: 574



View Profile
February 28, 2020, 07:45:57 AM
 #12

I can understand that the platform is in a beta stage.

No DEX wallet needs anyway to send your private keys to the server, even for a check. That's a major failure, or a scam attempt.
Plenty libs exists to handle that client side though Javascript (eg. https://github.com/nakov/client-side-ethereum-wallet).

If you show honesty and fix that issue, I'll remove my complaint.
criticalknow
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
February 28, 2020, 10:45:34 AM
Last edit: February 28, 2020, 10:56:05 AM by criticalknow
 #13

Now among adults and developers,

Have you ever tried to contact this project?
to find out if this company actually wants to cheat

or whether there was a technical problem or whether there was a problem at all?

A company works for this project
they are in the process of optimizing some things.

Privatekey login is completely deactivated. Not because of the Exchange but because it is a danger for the user to have the Prvatekey on the computer.

This Guys have also completely outsourced the creation of wallets.
You are wrong if you say there is a scam.

Think about it before you say these things and it would have been professional to contact the project first, they are fighting for the same thing as you 1

notblox1
Legendary
*
Offline Offline

Activity: 2044
Merit: 1263


Logo Designer ⛨ BSFL Division1


View Profile WWW
February 28, 2020, 11:38:29 AM
Last edit: February 28, 2020, 12:04:38 PM by notblox1
 #14

You are insulting people here,
and the way you are speaking it is obvious you are same person as your other account bitherium.cc

registered yesterday  Roll Eyes

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
bitherium.cc
Copper Member
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 28, 2020, 07:24:22 PM
 #15

I can understand that the platform is in a beta stage.

No DEX wallet needs anyway to send your private keys to the server, even for a check. That's a major failure, or a scam attempt.
Plenty libs exists to handle that client side though Javascript (eg. https://github.com/nakov/client-side-ethereum-wallet).

If you show honesty and fix that issue, I'll remove my complaint.

Hello Mallyx,

As we told you before, our exchange is in the test phase. Some things have not been checked yet or implemented. The fact is that you could see your own private key but only in your own browser - in your session. You were just faster than we were. Now we implemented encryption.

The other thing is that you accused us of collecting / storing private keys. There is a difference between checking in in the backend or frontend and saving a private key. A private keys was never stored. We can assure you of that. We evaluated all bitcointalk feedback in the past few days and our developers had to answer questions and provide evidence. I would also like to thank you for your indirect help. Based on your campaign, we checked again if the availability of log in with private keys makes sense for users. And after lot of talks we decided to turn it off regardless of whether the validation in the front end is carried out via web3.js and thus externally. Instead of that option we are working to ensure that the user can soon log in with their Ledger hardware wallet.

For security reasons, we also decided that the users be only able to create their wallets externally, to dispel any doubts. Another note for you. Before we open our exchange for trading, the code will be checked by 2 independent companies.

If you have any further comments or concerns, please let us know at info@bitherium.cc or join our telegram channel and we can talk more about the project.

-The Bitherium team



TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6971



View Profile WWW
February 28, 2020, 07:33:45 PM
Merited by Mallyx (5)
 #16

As we told you before, our exchange is in the test phase. Some things have not been checked yet or implemented. The fact is that you could see your own private key but only in your own browser - in your session. You were just faster than we were. Now we implemented encryption.
That's a lie. The page was sending a POST request with the private-key and its password in plain-text to your server.

If you saved the private-key or not, that's something we can not confirm since it was handled by your server, and we do not have access to it. But saving it was as simple as taking the body data from the request and saving them anywhere you wanted. So it was definitely possible. Do not lie saying this data was handled in the client, on his own browser, because it was NOT.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
bitherium.cc
Copper Member
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 28, 2020, 07:58:31 PM
 #17

As we told you before, our exchange is in the test phase. Some things have not been checked yet or implemented. The fact is that you could see your own private key but only in your own browser - in your session. You were just faster than we were. Now we implemented encryption.
That's a lie. The page was sending a POST request with the private-key and its password in plain-text to your server.

If you saved the private-key or not, that's something we can not confirm since it was handled by your server, and we do not have access to it. But saving it was as simple as taking the body data from the request and saving them anywhere you wanted. So it was definitely possible. Do not lie saying this data was handled in the client, on his own browser, because it was NOT.

We will explain it once more now. In our test phase we sent the private key to the backend to check it (through web3.js) if is valid or not. And because we had no encryption at the time, this event occurred. We presented everything transparently and above all we changed all what you wanted.
TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6971



View Profile WWW
February 28, 2020, 08:03:27 PM
 #18

We will explain it once more now. In our test phase we sent the private key to the backend to check it (through web3.js) if is valid or not. And because we had no encryption at the time, this event occurred. We presented everything transparently and above all we changed all what you wanted.
Exactly. You were sending it to your backend. Like I said, if you were only checking if its valid or saving them, it's not up for me to say. A DEX would not need any of these to reach the backend after all.

But your answer was:
The fact is that you could see your own private key but only in your own browser - in your session. You were just faster than we were. Now we implemented encryption.
The accusations that the privatekey is read by users completely invented. This screenshot only shows that the user can see his own private key in his own browser session!
The bolded part is a lie. If it reached your backend, you could supposedly have seen it all and saved them. If you admitted it was sent to the backend, then how is it only on the browser session? Again, if you saved or not, we can't know. But you COULD have been saving them. That's the point of OP's thread.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
criticalknow
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
February 28, 2020, 08:14:13 PM
Last edit: February 28, 2020, 08:32:13 PM by criticalknow
 #19

Don't answer anymore.
You did everything you could.


It looks like these people are not about security, but just portraying you as a scam to get attention


forget it

 Roll Eyes Roll Eyes Roll Eyes Roll Eyes

Honest

A blind man sees that there is no fraud here

If this project wanted to scam, they would have implemented encryption beforehand

and not afterwards, really hard to read

bitherium.cc
Copper Member
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
February 28, 2020, 08:23:43 PM
 #20

We will explain it once more now. In our test phase we sent the private key to the backend to check it (through web3.js) if is valid or not. And because we had no encryption at the time, this event occurred. We presented everything transparently and above all we changed all what you wanted.
Exactly. You were sending it to your backend. Like I said, if you were only checking if its valid or saving them, it's not up for me to say. A DEX would not need any of these to reach the backend after all.

But your answer was:
The fact is that you could see your own private key but only in your own browser - in your session. You were just faster than we were. Now we implemented encryption.
The accusations that the privatekey is read by users completely invented. This screenshot only shows that the user can see his own private key in his own browser session!
The bolded part is a lie. If it reached your backend, you could supposedly have seen it all and saved them. If you admitted it was sent to the backend, then how is it only on the browser session? Again, if you saved or not, we can't know. But you COULD have been saving them. That's the point of OP's thread.

We would not say "lie" but "not true". Yes, that was the first reaction (of social media manager) we thought is right, we should have examine it at first.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!