Bitcoin Forum
August 15, 2024, 02:22:51 PM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 »  All
  Print  
Author Topic: RarityCheck VIBGYOR gilded #12 swept yesterday.  (Read 2792 times)
MoparMiningLLC
aka Stryfe
Legendary
*
Online Online

Activity: 2170
Merit: 2330


EIN: 82-3893490


View Profile WWW
August 08, 2024, 01:42:43 PM
 #161

I also created a thread on how I generate my keys as well.

   https://bitcointalk.org/index.php?topic=5416519.0

   For those people who do not trust software download off of the internet or do not own a mycelium entropy...there is another way that I suggest.

   Simply....buy a Trezor...generate a new seed and place the 12 word seed instead of a private key.

    You can use it this method as many times as you wish simply by resetting the Trezor. And yes of course you have to trust Trezor as well. If not then use a hardware wallet of your choice. Coldard is also another one I would trust especially the latest Q wallet which is all done air gapped!

     Or simply roll the dice. Lol

I believe you had one already - maybe several - as you have walked thru your process very clearly and meticulously several times.

as a note - many have peeled all their RC coins. When a coin maker has been compromised, one must assume all works are compromised.

we really need to hear about your key generation process and how it was different for the affected coins vs the ones you claim are safe.

and then a very detailed post on how exactly you generated keys for each project.

yes. We will provide details.
But Mopar this thread is for helping those who are impacted.

As this is a widespread issue(not only for VIBGYOR coins). This is an issue beyond our collectibles.
Please let’s use the other thread for root causing and keep this for helping those impacted.

and by widespread you mean what? if there is some larger issue, you need to state it now vs later - the sooner the better.

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
DaveF
Legendary
*
Offline Offline

Activity: 3570
Merit: 6489


Crypto Swap Exchange


View Profile WWW
August 08, 2024, 02:09:56 PM
 #162

We didn’t say our wallets were impacted.
I literally quoted the post in which you said that.

I believe they were referring to the fact that the bad keygen software used has resulted in BTC from other, non-collectibles wallets potentially held by normal, regular users who have nothing to do with this forum, being moved and stolen.

I'm baffled as to why they don't share the software at this stage, given that it could save other folks.


Many people who tried using a vanity gen software have been compromised. You should have stuck with your original software that worked on your first coins.

   I know you didn't end up using the vangen part but you still used their software. Did the swept funds go to any exchange? Perhaps you can reach out to them to freeze the funds. Always stick with what works. And in your case the first key generation code looks like it was solid.

   Also please post where you got that software so others do not fall in the same trap. And perhaps take legal action as well

Yes and yes, there are 2 well known pieces of vanity address generating software.

VanitySearch: https://bitcointalk.org/index.php?topic=5112311.0
And the older Vanitygen: https://bitcointalk.org/index.php?topic=25804

They are well known and people have been using them for YEARS with no issues.

Heck in 8 minutes on my old work laptop with NO GPU I got 3 keys for an address starting with "1V1BG" with a decent video card it should take no time at all.

Without a lot more detail we are all just guessing what happened here.

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Eclipse33
Copper Member
Sr. Member
****
Offline Offline

Activity: 1038
Merit: 451


Eclipse™ Experimental Cryptographic Technology


View Profile WWW
August 08, 2024, 04:32:12 PM
Last edit: August 08, 2024, 04:45:40 PM by Eclipse33
 #163

RC needs to dox the key-gen software.

I suspect it's backdoored with pregenerated rolling codes or pregenerated private keys.

It's not vanitygen or vanitysearch.

Prob some small-time dinky key-gen.

Why he has not doxxed it yet is beyond me. A real headscratcher.


███
███
███
███
███
███
███
███

███

███

███

███

███
.
Eclipse
)███
███
███
███
███
███
███
███

███

███

███

███

███
.
   MARKETPLACE
▀   TELEGRAM
   TWITTER
▀   INSTAGRAM
███
███
███
███
███
███
███
███

███

███

███

███

███
███▄▄███████▄▄
▄█████▀█▀█████▄
▄███████████████▄
█████████████████
███████████▀█████▄▄
██████████████████████▄
▀████████████████████▀██
██████▄█▄██████████▀█████
███▀▀████████▀█▀███████
██████████████▄███▄██████
████████████████▄███████
██████████▀███████████▀
████████████▀▀█████▀▀
| BTC |
| XMR |
ACCEPTED
███
███
███
███
███
███
███
███

███

███

███

███

███
[/quote]
Amax16
Jr. Member
*
Offline Offline

Activity: 255
Merit: 1


View Profile
August 08, 2024, 04:48:36 PM
 #164

RC refunded me .001 btc for the swiped silver #49 for the record.
rsincognito
Copper Member
Member
**
Offline Offline

Activity: 560
Merit: 78


View Profile
August 08, 2024, 04:57:32 PM
Last edit: August 08, 2024, 05:34:46 PM by rsincognito
Merited by DaveF (2), LoyceV (2)
 #165

RC needs to dox the key-gen software.

I suspect it's backdoored with pregenerated rolling codes or pregenerated private keys.

It's not vanitygen or vanitysearch.

Prob some small-time dinky key-gen.

Why he has not doxxed it yet is beyond me. A real headscratcher.



makes me feel he's not doing it because he know something else happened that wasn't the software, but the longer he takes the more shady it looks. there is ZERO reasons not to share the name of the software for some of the professionals  on here to investigate further, news flash:  you don't have to say its was the softwares fault or even figure out if its secure or not for you to be able to take the time to share the softwares name and URL.    
raghavsood
Copper Member
Sr. Member
****
Online Online

Activity: 322
Merit: 342

Track Burns @ burned.money


View Profile WWW
August 08, 2024, 05:34:51 PM
 #166

An update from James @ S&B: All upcoming/ongoing Rarity Check lots have been withdrawn.

As before, the affected lots are:

https://auctions.stacksbowers.com/lots/view/3-1BAYV9/unfunded-2022-rarity-check-lost-coin-0001-bitcoin-serial-no-079-zinc-alloy-proof-68-deep-cameo-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYX2/unfunded-2022-rarity-check-diy-lost-coin-0001-bitcoin-zinc-alloy-proof-69-deep-cameo-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYAN/2022-rarity-check-lost-coin-0001-bitcoin-loaded-serial-no-100-zinc-alloy-ms-68-pl-icg
https://auctions.stacksbowers.com/lots/view/3-1BAYWK/unfunded-2022-rarity-check-diy-lost-coin-0001-bitcoin-zinc-alloy-proof-69-deep-cameo-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYVO/unfunded-2022-rarity-check-diy-lost-coin-001-bitcoin-silver-proof-69-deep-cameo-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYW5/unfunded-2022-rarity-check-diy-lost-coin-001-bitcoin-silver-proof-69-deep-cameo-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYUE/unfunded-2022-rarity-check-vibgyor-0001-bitcoin-serial-no-8-orange-variety-silver-ms-70-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYTX/unfunded-2022-rarity-check-vibgyor-001-bitcoin-serial-no-8-orange-variety-gilt-silver-ms-70-pcgs
https://auctions.stacksbowers.com/lots/view/3-1BAYUU/unfunded-2022-rarity-check-lost-coin-001-bitcoin-serial-no-79-silver-proof-69-deep-cameo-pcgs

Track burns @ burned.money | Track Collectibles @ collectible.money | Track Value @ isbtc1m.com
MoparMiningLLC
aka Stryfe
Legendary
*
Online Online

Activity: 2170
Merit: 2330


EIN: 82-3893490


View Profile WWW
August 08, 2024, 06:00:11 PM
 #167

maybe he had yogg create them for him...

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
tweetious
Sr. Member
****
Offline Offline

Activity: 2007
Merit: 392


Cryptoshi Blockomoto


View Profile
August 08, 2024, 08:09:02 PM
Merited by LoyceV (4)
 #168

Hi raghav

We will not pull the eBay listing.
If someone orders we will send them coins with new holos and new keys.

We understand that not just other coins but our wallets are impacted but even we are trying to root cause it.
We are not 100% sure how this has happened.
But we think the key gen software we used is compromised.
Rest ensured as soon as we know we will provide details.

Since you "are not 100% sure how this has happened", how are you 100% certain that the newly generated keys will be 100% safe? (even if you use a different key generation method for creating the key pairs)
raghavsood
Copper Member
Sr. Member
****
Online Online

Activity: 322
Merit: 342

Track Burns @ burned.money


View Profile WWW
August 08, 2024, 08:13:22 PM
 #169

✂️

We still posses all the hardware used.
We will share exact details of what we think has happened.
None of the used hardware has ever been connected to the internet.
And the computers  used are also wiped out.

As this is a widespread issue(beyond our collectibles) this means this is an issue with the private key generator we used for VIBGYOR.

We will share the details at 9 pm UK time today.

✂️

raritycheck team: It is imperative that you share how the keys for the VIBGYOR series were generated in as much detail as possible - software used, people involved, computer used, printer used, and everything else that is available. This does appear to be a more widespread attack and funds for many others people outside of collectibles may be at risk.


I see no reason why there should be any more delays on sharing the keygen software and process.

I'm sure everyone appreciates raritycheck's efforts to compensate affected users, but without more concrete information the community is still being asked to take the fact that other series are not impacted on faith.

Additionally, given the on-chain evidence highlighted by Eclipse33 and myself previously in the thread, actively withholding the software and process involved is putting other Bitcoin users at risk.

I've reached out to the raritycheck team multiple times over PM to offer help in analyzing this situation (I have a long, long background in building and operating custody systems), and have had no material response.

I'm hopeful raritycheck sticks to their promise of a details update and posts it soon - in the mean time, if anyone has been provided any additional information
 on the keygen process not in this thread by the team, I would encourage you to share it.

Track burns @ burned.money | Track Collectibles @ collectible.money | Track Value @ isbtc1m.com
raritycheck
Copper Member
Full Member
***
Offline Offline

Activity: 658
Merit: 178


View Profile WWW
August 08, 2024, 08:48:34 PM
Last edit: August 08, 2024, 09:05:57 PM by raritycheck
 #170

Hey guys

Just finished analysing everything we could from our side.

raritycheck
Copper Member
Full Member
***
Offline Offline

Activity: 658
Merit: 178


View Profile WWW
August 08, 2024, 09:01:26 PM
 #171

We made a mistake. We have been doing lots of digging since morning on how this could have happened. We knew this isn't a hardware issue as we never connect any of our hardware to internet. Plus, we have no backups so this isn't a  personnel issue.

Issue is with the keygen software we used.

In full transparency, for the first version of vigilante series, and for the hole coins we have used https://github.com/bitaddress/bitaddress.org to create keys on an airgap computer.

For VIBGYOR orange we used https://github.com/walletgeneratornet/WalletGenerator.net again on an airgap computer.
Unfortunately, since morning we started digging into looks like walletgeneratornet is actually compromised.

We have learned from our mistake and we can only look forward from here. We have been refunding the clients (still few to go).

For next generation of our coins, we will use better keygens + also, print and post sample private keys before using those for the coins.

We appreciate all support from the forum members.




 

Kazkaz27
Copper Member
Member
**
Offline Offline

Activity: 91
Merit: 35

"Virtual Physical Bitcoins"


View Profile WWW
August 08, 2024, 09:09:51 PM
 #172

My coin was unfortunately part of this debacle… hoping to be made whole. No way I was able to recoup any funds as this unfolded.. my coin is still in a icg slab and in my safe 1000 miles away from me currently. .001 lost, which isn’t huge but the principle of it matters.

̿ ̿̿̿̿ ̿ ̿’̿’\̵͇̿̿\=(•̪●)=/̵͇̿̿/’̿̿ ̿ ̿ ̿  - Buy a Virtual Physical Bitcoin   https://ordzaar.com/marketplace/collections/virtualphysicalbitcoins/mints
Steeley
Sr. Member
****
Offline Offline

Activity: 1153
Merit: 266


Byzantine Generals' Problem solved,Prosperity Next


View Profile
August 08, 2024, 09:10:29 PM
 #173

Rarity Check:

I really hate that this happened to you and your team. I appreciate the ways you are responding to help owners of these coins and I wish you the best moving forward.

Steeley

Beware of scammers. I will never discuss the sale of Collectibles on Telegram or any other messaging client outside the forum.
raritycheck
Copper Member
Full Member
***
Offline Offline

Activity: 658
Merit: 178


View Profile WWW
August 08, 2024, 09:12:06 PM
 #174

My coin was unfortunately part of this debacle… hoping to be made whole. No way I was able to recoup any funds as this unfolded.. my coin is still in a icg slab and in my safe 1000 miles away from me currently. .001 lost, which isn’t huge but the principle of it matters.

Please pm us an address for refund.

2stout
Hero Member
*****
Offline Offline

Activity: 2450
Merit: 603


View Profile
August 08, 2024, 09:13:46 PM
 #175

We made a mistake. We have been doing lots of digging since morning on how this could have happened. We knew this isn't a hardware issue as we never connect any of our hardware to internet. Plus, we have no backups so this isn't a  personnel issue.

Issue is with the keygen software we used.

In full transparency, for the first version of vigilante series, and for the hole coins we have used https://github.com/bitaddress/bitaddress.org to create keys on an airgap computer.

For VIBGYOR orange we used https://github.com/walletgeneratornet/WalletGenerator.net again on an airgap computer.
Unfortunately, since morning we started digging into looks like walletgeneratornet is actually compromised.

We have learned from our mistake and we can only look forward from here. We have been refunding the clients (still few to go).

For next generation of our coins, we will use better keygens + also, print and post sample private keys before using those for the coins.

We appreciate all support from the forum members.




 


Which keygen software did you use for LCS- v1?

Disregard as you already answered.
raritycheck
Copper Member
Full Member
***
Offline Offline

Activity: 658
Merit: 178


View Profile WWW
August 08, 2024, 09:14:34 PM
 #176

Rarity Check:

I really hate that this happened to you and your team. I appreciate the ways you are responding to help owners of these coins and I wish you the best moving forward.

Steeley

Thank you! 🙏  your wishes mean a lot. Very difficult times for us and our customers.
We are trying to help as much as possible.

krogoth
Full Member
***
Offline Offline

Activity: 1291
Merit: 175


Krogothmanhattan alt account


View Profile WWW
August 08, 2024, 09:22:57 PM
 #177

 Have you reported this to GitHub? They should take it down if it is compromised.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>CIPHER BILLS-CIPHER BONDS-CIPHER STAMPS * www.CYPHERHODL.com * COLD STORAGE BITCOIN CERTIFICATES <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
raritycheck
Copper Member
Full Member
***
Offline Offline

Activity: 658
Merit: 178


View Profile WWW
August 08, 2024, 09:32:41 PM
 #178

Have you reported this to GitHub? They should take it down if it is compromised.

https://github.com/walletgeneratornet/WalletGenerator.net/issues/293

hybridsole
Hero Member
*****
Offline Offline

Activity: 960
Merit: 799


View Profile
August 08, 2024, 09:34:03 PM
Merited by LoyceV (4)
 #179

Walletgenerator.net has had known vulnerabilities since at least 2019: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

But one other issue is that walletgenerator does not support the creation of Vanity keys...so I'm confused why you even switched to using this software from bitaddress?
krogoth
Full Member
***
Offline Offline

Activity: 1291
Merit: 175


Krogothmanhattan alt account


View Profile WWW
August 08, 2024, 09:34:21 PM
 #180

Have you reported this to GitHub? They should take it down if it is compromised.

https://github.com/walletgeneratornet/WalletGenerator.net/issues/293

    Good man.  Will they now pull it off the site? I hope nobody else downloads it

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>CIPHER BILLS-CIPHER BONDS-CIPHER STAMPS * www.CYPHERHODL.com * COLD STORAGE BITCOIN CERTIFICATES <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 13 14 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!