Bitcoin Forum
May 01, 2024, 01:14:49 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Hack bug duplicate transaction  (Read 98 times)
GeneralTulsa (OP)
Member
**
Offline Offline

Activity: 98
Merit: 14


View Profile
April 15, 2023, 11:21:09 AM
 #1

Hack bug duplicate transaction


If a vulnerability occurs in the system, where you buy eth and the exchange due to some bug doubles the purchase, and you manage to withdraw it to your wallet twice, what would be your responsibility in this bug?
Could the exchange charge you (has kyc) in the future for this "hack"?
Or should you take advantage of this flaw and create infinite money? Do you think it would be a police case?
1714526089
Hero Member
*
Offline Offline

Posts: 1714526089

View Profile Personal Message (Offline)

Ignore
1714526089
Reply with quote  #2

1714526089
Report to moderator
1714526089
Hero Member
*
Offline Offline

Posts: 1714526089

View Profile Personal Message (Offline)

Ignore
1714526089
Reply with quote  #2

1714526089
Report to moderator
Once a transaction has 6 confirmations, it is extremely unlikely that an attacker without at least 50% of the network's computation power would be able to reverse it.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
OmegaStarScream
Staff
Legendary
*
Offline Offline

Activity: 3458
Merit: 6105



View Profile
April 15, 2023, 11:28:39 AM
Last edit: April 15, 2023, 11:58:12 AM by OmegaStarScream
Merited by vapourminer (1)
 #2

You can't create infinite money because the exchange have a limited supply.

And yes, they can and will sue you. There was a few similar cases[1][2] in the past where people got more money (not necessarily by exploiting a bug) and the exchange sued them (or at least threatened to).

[1] https://decrypt.co/108586/crypto-com-sues-woman-10-million-mistake
[2] https://www.coindesk.com/business/2022/10/17/coinbase-threatens-to-sue-crypto-traders-who-profited-from-pricing-glitch/

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
BitMaxz
Legendary
*
Offline Offline

Activity: 3234
Merit: 2955


Block halving is coming.


View Profile WWW
April 15, 2023, 12:09:32 PM
 #3

Or should you take advantage of this flaw and create infinite money?

I'm sure later after you withdraw some money from the exchange due to hack/bugs police will seize you.


If I were you if you found bugs or holes that are vulnerable for attacks then since most exchanges have a bug bounty program reporting it is the best because they will also give you rewards.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
GeneralTulsa (OP)
Member
**
Offline Offline

Activity: 98
Merit: 14


View Profile
April 15, 2023, 12:55:43 PM
 #4

What is the best way for me to report this failure to the exchange?
Potato Chips
Hero Member
*****
Offline Offline

Activity: 2744
Merit: 893


yesssir! 🫡


View Profile
April 15, 2023, 01:22:34 PM
Merited by vapourminer (2)
 #5

What is the best way for me to report this failure to the exchange?

A way to reach their support can be found on the exchange's website, look into the website's footer/on their help center/for a message symbol on the bottom right or on their menu bar.

Some exchange's also has a separate page for bug bounties which can be typically found on the footer as well, you may do a "Ctrl+F" command to save time.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
BitMaxz
Legendary
*
Offline Offline

Activity: 3234
Merit: 2955


Block halving is coming.


View Profile WWW
April 15, 2023, 01:24:26 PM
 #6

What is the best way for me to report this failure to the exchange?

All exchanges have their own way or a guide on how to report bugs/security vulnerabilities sample Kucoin they have a guide on how to report these from this link below

- https://www.kucoin.com/news/en-kucoin-bug-bounty-program-launched

And you will be rewarded depending on how critical it is.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
pawanjain
Hero Member
*****
Offline Offline

Activity: 2660
Merit: 713


Nothing lasts forever


View Profile
April 15, 2023, 03:00:04 PM
 #7

Hack bug duplicate transaction


If a vulnerability occurs in the system, where you buy eth and the exchange due to some bug doubles the purchase, and you manage to withdraw it to your wallet twice, what would be your responsibility in this bug?
Could the exchange charge you (has kyc) in the future for this "hack"?
Or should you take advantage of this flaw and create infinite money? Do you think it would be a police case?

The exchange will surely track you for this thing and may be freeze your account and threaten you.
But would you withdraw the money at first place ? Would you be able to live with the fact that you stole someone's money.
It is definitely similar to stealing someone's money and so may be yes there might be a police case as well.
Does your morals support you for this action. There are things which we should avoid to live a peaceful life and this is definitely one of it.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Coyster
Legendary
*
Offline Offline

Activity: 2002
Merit: 1236


Cashback 15%


View Profile
April 15, 2023, 03:56:54 PM
 #8

If a vulnerability occurs in the system, where you buy eth and the exchange due to some bug doubles the purchase, and you manage to withdraw it to your wallet twice, what would be your responsibility in this bug?
Your responsibility if you discover this kind of bug should be to return it back to the exchange, it would be foolhardy to try and go on the run with this money when the exchange knows about you through your KYC documents, it might take sometime but the fact still remains that the exchange would come after you and would drag you to court, especially if the sum of money is quite substantial.
Or should you take advantage of this flaw and create infinite money? Do you think it would be a police case?
You can't create infinite money for one obvious reason already mentioned earlier in this thread, and also because it usually does not take long before the exchange would detect what's going on and immediately lock your account.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
noorman0
Hero Member
*****
Offline Offline

Activity: 1764
Merit: 694


[Nope]No hype delivers more than hope


View Profile WWW
April 15, 2023, 04:01:58 PM
 #9

-snip-
Or should you take advantage of this flaw and create infinite money?

You can leverage bugs to earn money (not infinity) by reporting them to support. Indeed, in the past there have been some disappointing endings for unpaid bug hunters even at extreme vulnerability levels (for example). I think you should first withdraw a large amount as a "collateral" bounty before reporting it. lol

This space for rent.
Available in mid January 2024 - PM me
Little Mouse
Legendary
*
Offline Offline

Activity: 2030
Merit: 1979


Marketing Campaign Manager |Telegram ID- @LT_Mouse


View Profile WWW
April 15, 2023, 05:26:22 PM
 #10

Could the exchange charge you (has kyc) in the future for this "hack"?
Or should you take advantage of this flaw and create infinite money? Do you think it would be a police case?
Regardless of what an exchange will do to recover their fund, why would someone take advantage? You are being dishonest here. Don't you think it's something unethical? You must return the sum back to the exchange by contacting their support.
Coincidently, I got $50 worth of BDT today from a user of Binance P2P. I have sold $50 through Binance P2P today and the guy sent me a worth of BDT twice. I instantly called the number from which I have been sent the money but he didn't pick up the call. Later, I PMed him in the Binance P2P chat and got no response. I kept calling him and finally, he picked up the call. Note that he had nothing to do as according to the order, I have released the USDT. Also, for $50 worth of BDT, I think no one will sue you here because it requires valid proof. Well, cryptocurrency is illegal here and he can't claim the money legally because he will also face legal issues because of transacting cryptocurrency. Anyway, I asked him for his Binance pay id and paid him $50 one more time. It's ethics, you shouldn't be unethical.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
GeneralTulsa (OP)
Member
**
Offline Offline

Activity: 98
Merit: 14


View Profile
April 15, 2023, 08:18:00 PM
 #11

I contacted chat support and they asked me to send an email.  I will send the email reporting about everything that happened and how the duplicity is done. Peace.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!