LoyceV
Legendary
Offline
Activity: 3710
Merit: 19117
Thick-Skinned Gang Leader and Golden Feather 2021
|
This website is known to steal Bitcoins for almost as long as I can remember! That's not just a rookie mistake, it's plain negligence. A simple forum search would have brought you to Disclosure: Key generation vulnerability found on WalletGenerator.net (in 2019). Using compromised software offline doesn't make it safe. We didn’t realize walletgenerator has an issue. That can only mean you didn't even search for it, otherwise you'd have found many warnings signs. From that medium article you posted in (2019): 'At this time, the code on GitHub is not malicious nor vulnerable, nor has it been malicious or vulnerable previously.' Last checkin for that code on github appears to be 7 years ago.
Even if that code was compromised, if it was on an air gapped system theres no way it could have communicated the keys back to the malicious actors. Something doesnt smell right here. There's another paper wallet website that turned into stealing Bitcoins after the site was sold, and even offline it produces compromised keys. See this post. There's no need to use potentially compromised software, there's more than enough legit software out there.
Coin refunds should absolutely unequivocally be above just load value, anything less is a slap in the face and bullshit, period. I'm not into collectibles (for privacy, and for "verify, don't trust"), but as far as I know the value of collectibles comes from scarcity, and age. Buyers pay more than just the Bitcoin value when they buy them, which means refunding just the Bitcoin amount is less than the damage done when it got compromised. Even replacing it with a new one removes the "age" of the coin, so doesn't fully fix the value. And that's even ignoring the fact that being compromised even once makes all future coins lose their credibility.
So yes we were incompetent. Yes we have made a mistake. ~ Please stay a little supportive and positive. In my country, we have these sayings: - Trust comes on foot and goes on horseback
- A donkey doesn't hit the same stone twice
This post is my Reference link for neutral feedback.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
Mitchell
Staff
Legendary
Offline
Activity: 4326
Merit: 2431
Verified awesomeness ✔
|
 |
August 09, 2024, 08:54:02 AM |
|
Removed my negative for now, but I cannot wrap my head around why you would use some online wallet generator? Even if the source code wasn't compromised (which it must have been, otherwise, how are we here), why would you ever choose that over actual (airgappable) wallets. 
|
|
|
|
| . betpanda.io | │ |
ANONYMOUS & INSTANT .......ONLINE CASINO....... | │ | ▄███████████████████████▄ █████████████████████████ █████████████████████████ ████████▀▀▀▀▀▀███████████ ████▀▀▀█░▀▀░░░░░░▄███████ ████░▄▄█▄▄▀█▄░░░█▄░▄█████ ████▀██▀░▄█▀░░░█▀░░██████ ██████░░▄▀░░░░▐░░░▐█▄████ ██████▄▄█░▀▀░░░█▄▄▄██████ █████████████████████████ █████████████████████████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀░░░▀██████████ █████████░░░░░░░█████████ ████████░░░░░░░░░████████ ████████░░░░░░░░░████████ █████████▄░░░░░▄█████████ ███████▀▀▀█▄▄▄█▀▀▀███████ ██████░░░░▄░▄░▄░░░░██████ ██████░░░░█▀█▀█░░░░██████ ██████░░░░░░░░░░░░░██████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀▀▀▀▀▀█████████ ███████▀▀░░░░░░░░░███████ ██████▀░░░░░░░░░░░░▀█████ ██████░░░░░░░░░░░░░░▀████ ██████▄░░░░░░▄▄░░░░░░████ ████▀▀▀▀▀░░░█░░█░░░░░████ ████░▀░▀░░░░░▀▀░░░░░█████ ████░▀░▀▄░░░░░░▄▄▄▄██████ █████░▀░█████████████████ █████████████████████████ ▀███████████████████████▀ | .
SLOT GAMES ....SPORTS.... LIVE CASINO | │ | ▄░░▄█▄░░▄ ▀█▀░▄▀▄░▀█▀ ▄▄▄▄▄▄▄▄▄▄▄ █████████████ █░░░░░░░░░░░█ █████████████ ▄▀▄██▀▄▄▄▄▄███▄▀▄ ▄▀▄██▄███▄█▄██▄▀▄ ▄▀▄█▐▐▌███▐▐▌█▄▀▄ ▄▀▄██▀█████▀██▄▀▄ ▄▀▄█████▀▄████▄▀▄ ▀▄▀▄▀█████▀▄▀▄▀ ▀▀▀▄█▀█▄▀▄▀▀ | Regional Sponsor of the Argentina National Team |
Advertisements are not endorsed by me.
|
|
|
tweetious
Sr. Member
  
Offline
Activity: 2271
Merit: 428
Cryptoshi Blockomoto
|
 |
August 09, 2024, 11:02:56 AM |
|
We made a mistake. We have been doing lots of digging since morning on how this could have happened. We knew this isn't a hardware issue as we never connect any of our hardware to internet. Plus, we have no backups so this isn't a personnel issue.
How we created the keys were we connected the computer via lab cable to the internet to download the client side side site from walletgenerator and the disconnected the cable No hardware (printer) was connected to wifi.
First of all, we are not judging you here. We are not asking questions to understand if you made a small or a big mistake, to convict/"crucify" you later on. We are all making mistakes. Being here answering questions & trying to find solutions is really appreciated. What is important here, is that we need to understand exactly how this leak happened. Was it a mistake by your side (ie you used a compromised key gen and mistakenly the airgap computer was connected to the internet and the generated key pairs were leaked) OR you actually use the key gen in a proper way -airgap computer, compiled the key gen from github source code in you airgap computer etc. etc.- and still the priv keys were leaked? If it was the first case, then fair enough. However, if it is the second case, we REALLY need to know all the details to protect others from creating compromised key pairs. I am not technical enough (there are many highly technical individuals here, hence please correct me if I am wrong), however the only way I can think of -in the second case- that the priv keys could be leaked from an airgap computer, is if the entropy used for generating the key pair was not random. Hence, if someone knows the exact entropy used, they could probably generate the same key pairs. My question here is: Did you compile the key gen (on the air gaped computer) from the github source code OR you used a pre-compiled file (from the github or eleswere). If the second, could you please indicate what exactly you used? Again, we are not asking questions to turn the answers against you. Since (as you are saying too) this has probably affected many others - even outside of the collectibles community- we just want to protect others from falling into the same mistake. And in order to protect them, we need to work out exactly how the priv keys were leaked. (and your collaboration on that would be of crucial importance) Lastly (and here my above quotes apply) if I understand this correctly the term "airgap" refers to hardware never connected to the internet. Hence if you connected the hardware to the internet (even for 1 second) then the term "airgap" might not still apply. I am just trying to help here, no negativity whatsoever
|
|
|
|
raghavsood
|
 |
August 09, 2024, 11:19:06 AM |
|
We made a mistake. We have been doing lots of digging since morning on how this could have happened. We knew this isn't a hardware issue as we never connect any of our hardware to internet. Plus, we have no backups so this isn't a personnel issue.
How we created the keys were we connected the computer via lab cable to the internet to download the client side side site from walletgenerator and the disconnected the cable No hardware (printer) was connected to wifi.
First of all, we are not judging you here. We are not asking questions to understand if you made a small or a big mistake, to convict/"crucify" you later on. We are all making mistakes. Being here answering questions & trying to find solutions is really appreciated. What is important here, is that we need to understand exactly how this leak happened. Was it a mistake by your side (ie you used a compromised key gen and mistakenly the airgap computer was connected to the internet and the generated key pairs were leaked) OR you actually use the key gen in a proper way -airgap computer, compiled the key gen from github source code in you airgap computer etc. etc.- and still the priv keys were leaked? If it was the first case, then fair enough. However, if it is the second case, we REALLY need to know all the details to protect others from creating compromised key pairs. I am not technical enough (there are many highly technical individuals here, hence please correct me if I am wrong), however the only way I can think of -in the second case- that the priv keys could be leaked from an airgap computer, is if the entropy used for generating the key pair was not random. Hence, if someone knows the exact entropy used, they could probably generate the same key pairs. My question here is: Did you compile the key gen (on the air gaped computer) from the github source code OR you used a pre-compiled file (from the github or eleswere). If the second, could you please indicate what exactly you used? Again, we are not asking questions to turn the answers against you. Since (as you are saying too) this has probably affected many others - even outside of the collectibles community- we just want to protect others from falling into the same mistake. And in order to protect them, we need to work out exactly how the priv keys were leaked. (and your collaboration on that would be of crucial importance) Lastly (and here my above quotes apply) if I understand this correctly the term "airgap" refers to hardware never connected to the internet. Hence if you connected the hardware to the internet (even for 1 second) then the term "airgap" might not still apply. I am just trying to help here, no negativity whatsoever Based on a discussion I had with the team separately earlier today, they opened the website on the computer, before removing the internet connection and generating the keys. It does not appear that the tool was built from source. Unfortunately, that does make it extremely hard to validate anything more - even with a date range to work with, past investigations into walletgenerator knock-offs and scams have shown some degree of sophistication in serving "Good" generators to some IPs, and bad seeds to others. Without the original page used by the team to generate the keys being saved and available, it isn't really possible to look futher. Presumably, the backdoor took the same form as the one described in the previously linked reports in this thread - the page was seeded with bad random data which was saved by the attackers, and they've simply been biding their time for a few years before sweeping to let the pot grow. This matches the on-chain evidence as well.
|
|
|
|
MoparMiningLLC
aka Stryfe
Legendary
Online
Activity: 2478
Merit: 2743
EIN: 82-3893490
|
 |
August 09, 2024, 12:47:05 PM Last edit: August 09, 2024, 02:24:49 PM by MoparMiningLLC |
|
based on the quality of the paper and ink used - I recommend peeling all of RC coins - many of them have ink that is bleeding which will only get worse over time.
This is not true. During the printing itself it looks some hole coins might have not properly printed paper but we have used waterdrop water proof paper and the ink does NOT bleed. Please don’t spread lies. not spreading lies - I have shown the keys to multiple people - Polymerbit and Minerjones - both agreed they ink was bleeding. We used waterdrop waterproof paper. How can the ink be leaking ? We are asking so we make sure this doesn’t happen again. I will share the pics tomorrow, I am in bed just on my phone so not on PC with the pictures. The first and last images are of rarity check coins, the first from one of the lost series. The last from VIBGYOR. The second and third images are of a key I generated. Here is the one that best represents what I am referencing as appearing to have the ink bleeding.  and before you can say it is because it is being zoomed in so much. here is a key I made almost 2 years ago with 2 pt sized font - first image is showing how small it is and the second image is me zooming in on the same. It has no ink bleeding.   and here is a key from VIBGYOR that I would not say is "crystal clear"  update images replaced.
|
|
|
|
SwissCrab
Copper Member
Member

Offline
Activity: 236
Merit: 18
|
 |
August 09, 2024, 03:16:49 PM |
|
My guess the hardware was not actually airgrapped.
But out of curiosity :
Which browser have you used ?
I had a quick look at securerandom.js (I did not inspect it throughly) :
It relies on the Web Crypto API (which is supported in all modern versions of browser), but if it is not supported it will fallback to Math.random() and/or ArcFour. Both are not cryptographically secure - it is non-cryptographic pseudo-random number generator (PRNG). I believe there is even a comment in the code about PRNG.
|
1 sat/vB 4ever
|
|
|
raritycheck
Copper Member
Full Member
 
Offline
Activity: 720
Merit: 182
|
 |
August 09, 2024, 03:34:15 PM |
|
My guess the hardware was not actually airgrapped.
But out of curiosity :
Which browser have you used ?
I had a quick look at securerandom.js (I did not inspect it throughly) :
It relies on the Web Crypto API (which is supported in all modern versions of browser), but if it is not supported it will fallback to Math.random() and/or ArcFour. Both are not cryptographically secure - it is non-cryptographic pseudo-random number generator (PRNG). I believe there is even a comment in the code about PRNG.
Google Chrome.
|
|
|
|
hybridsole
|
Based on a discussion I had with the team separately earlier today, they opened the website on the computer, before removing the internet connection and generating the keys.
I went ahead and removed my negative trust, because I feel bad for you, and you have had to pay dearly for this mistake. But this sentence right here proves you should never, ever make any private keys for anyone ever again. Full stop. You don't need a "team" to generate keys, that's the first fuck up. If it wasn't the well known malware you used, it would have been someone in this "team" to save the keys for later. There was so much wrong with how you went about this, that to think you can salvage your brand and make more products is astounding. Let this thread be an example for anyone who wants to make their own coins. Don't. There is zero margin for error in this business. And without calling out this level of incompetency, we are only encouraging others to follow in your footsteps.
|
|
|
|
raritycheck
Copper Member
Full Member
 
Offline
Activity: 720
Merit: 182
|
 |
August 09, 2024, 08:24:43 PM |
|
Based on a discussion I had with the team separately earlier today, they opened the website on the computer, before removing the internet connection and generating the keys.
I went ahead and removed my negative trust, because I feel bad for you, and you have had to pay dearly for this mistake. But this sentence right here proves you should never, ever make any private keys for anyone ever again. Full stop. You don't need a "team" to generate keys, that's the first fuck up. If it wasn't the well known malware you used, it would have been someone in this "team" to save the keys for later. There was so much wrong with how you went about this, that to think you can salvage your brand and make more products is astounding. Let this thread be an example for anyone who wants to make their own coins. Don't. There is zero margin for error in this business. And without calling out this level of incompetency, we are only encouraging others to follow in your footsteps. Thank you
|
|
|
|
raritycheck
Copper Member
Full Member
 
Offline
Activity: 720
Merit: 182
|
 |
August 09, 2024, 08:35:31 PM |
|
Guys!
We also want to remind all that last year when the Yogg debacle happened, we volunteered to help everyone impacted by giving RC coins to each impacted forum member. Every single one impacted. We didn't say not to anyone and helped everyone.
And when something went wrong, most of the forum members rushed to immediately provide negative feedback and when we asked 12 hours of time, people were already concluding bad stuff about us on this forum. It hurts so much. That's all.
|
|
|
|
LoyceV
Legendary
Offline
Activity: 3710
Merit: 19117
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
August 09, 2024, 08:41:03 PM |
|
And when something went wrong, most of the forum members rushed to immediately provide negative feedback and when we asked 12 hours of time, people were already concluding bad stuff about us on this forum. It hurts so much. That's all. You're wrong here: from what I've seen, people are very conservative with negative feedback. I've seen only 2 negative tags on your account, and the warning was justified. It's also easy to remove later. We also want to remind all that last year when the Yogg debacle happened, we volunteered to help everyone impacted by giving RC coins to each impacted forum member. Every single one impacted. We didn't say not to anyone and helped everyone. I think most people here agree that your heart is at the right place. But that's just not enough to create secure funded coins.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
seavodin
Member

Offline
Activity: 180
Merit: 17
|
 |
August 09, 2024, 09:43:19 PM |
|
We are not hiding anything. We are sorry if something doesn’t make sense. When we were creating keys for VIBGYOR we were (don’t remember what other soft gen) but we were looking to generate 1O (1Orange) for the first coins in the series. That’s all we remember the real reason For change of key gen solution. And moved from bitaddess to walletgenerator. That’s what we meant that we unluckily changed software. We took. Sometime because it was 1 am last night until we were responding to messages. Then we woke and went to work(day job) Then we came back and checked as much history as possible and we researched as much as possible and researched only to realized that walletgenerator is compromised.
But we are not hiding anything.
We didn’t answer because weren’t sure how this happened but as soon as possible we had time we responded.
Seavodin you have bough few coins from Is, what does your heart say? Did we really do something intentionally ? What does your interactions with us say? Will we hide somehting or makeup somehting ? Do you not think we are always helpful and caring as much as possible We are humans and yes a mistake is made for VIBGYOR series.
I dont think anyone here truly thinks you did this maliciously- you would be financially hurting yourself and your brand. It wouldnt make any sense and you would have just ghosted out of the community. But when any sort of a security leak happens, the person or entity involved typically tries to spin things in a way to take as little accountability as possible, and preserve as much trust from society as possible (it could happen to anyone right? just bad luck). This is why the sharing of information immediately is so vital, so your customers within this community can do an independent sort of 'audit' as opposed to you just investigating yourself. As mentioned by other members, there are quite a few engineers/programmers/technically savvy people on the board who can not only assist but verify claims. This is good for you and good for the community. When information isn't provided immediately, my first reaction is that the person/entity is playing for time and trying to spin the facts. I'm not saying that that was what you were necessarily doing here, but your actions up to that point seemed to indicate it. I appreciate your longer form responses later on, as it lets people understand a bit more about what was going on as opposed to having to speculate, like I did. Perhaps part of this is a language barrier thing, or a PR response kind of issue. I think Raghavsood provided the missing information here, which clears up how this occurred: Based on a discussion I had with the team separately earlier today, they opened the website on the computer, before removing the internet connection and generating the keys.
It does not appear that the tool was built from source.
Unfortunately, that does make it extremely hard to validate anything more - even with a date range to work with, past investigations into walletgenerator knock-offs and scams have shown some degree of sophistication in serving "Good" generators to some IPs, and bad seeds to others. Without the original page used by the team to generate the keys being saved and available, it isn't really possible to look futher.
Presumably, the backdoor took the same form as the one described in the previously linked reports in this thread - the page was seeded with bad random data which was saved by the attackers, and they've simply been biding their time for a few years before sweeping to let the pot grow. This matches the on-chain evidence as well.
If this is accurate, then the breach occurred because: - Using a computer that was not air gapped (was connected to the internet which allowed loading of the malicious website) - Getting the software supplied by this .net website, and not downloading it from github - Removing the internet connection did not secure key generation, as the website had already served up code that had an entropy seed value known to the attackers This contradicts some of the information supplied earlier, but makes sense how this attack occurred. The original explanations did not make sense in how the attack was perpetrated, and that was what I was trying to clear up. Without a clear root cause on the issue, not only could you fall into this trap again (or more likely a variation of it)- but others could as well. I would like to say that I am a fan of RC's designs and own several coins. I do not benefit from attacking his team, as it lowers the value of my collectibles and potentially stops a newer maker from creating new coins: something i support. I've supported this in the past by pre-ordering RC's LC V2 coins prior to this event occurring.
|
|
|
|
transvestite lamb
Member

Offline
Activity: 153
Merit: 31
|
 |
August 09, 2024, 11:08:46 PM |
|
|
Get Paid, Get Laid!
|
|
|
HouseOfBAMF
Member

Offline
Activity: 89
Merit: 10
|
 |
August 09, 2024, 11:10:05 PM |
|
RC,
You addressed this promptly with communication in these threads. Payment was received. I appreciate the ownership y’all are taking with this breach. to me, it says a lot about your character and customer service. I have no bad feelings on this. mistakes happen, I understand you have learned from them and look forward to what you do in the future.
Always a pleasure.
|
|
|
|
raritycheck
Copper Member
Full Member
 
Offline
Activity: 720
Merit: 182
|
 |
August 09, 2024, 11:21:24 PM |
|
RC,
You addressed this promptly with communication in these threads. Payment was received. I appreciate the ownership y’all are taking with this breach. to me, it says a lot about your character and customer service. I have no bad feelings on this. mistakes happen, I understand you have learned from them and look forward to what you do in the future.
Always a pleasure.
Thank you.
|
|
|
|
LoyceV
Legendary
Offline
Activity: 3710
Merit: 19117
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
August 10, 2024, 08:14:28 AM |
|
That "sign" applies to any new coin maker who sells funded collectibles. And you could just as well apply it to every old coin maker.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
transvestite lamb
Member

Offline
Activity: 153
Merit: 31
|
 |
August 10, 2024, 10:53:07 AM Merited by DaveF (2), klaaas (1) |
|
That "sign" applies to any new coin maker who sells funded collectibles. And you could just as well apply it to every old coin maker. They were asking very basic questions on how to generate private keys. That does not apply to every new maker, was unique to this one
|
Get Paid, Get Laid!
|
|
|
DaveF
Legendary
Offline
Activity: 3864
Merit: 6838
Wheel of Whales 🐳
|
 |
August 10, 2024, 12:52:46 PM |
|
At the moment the other negative tags on RC have been changed to neutral, going to leave mine as a warning for the moment. Let's be honest its not going to matter since I don't think anyone is going to be buying anything funded or even with keys they generated for a while.
Once it looks like the majority of the people who lost their funds are paid back at least what they lost I will change it. But for now between the 1) Mistake with the key generation 2) The poor quality of the private keys 3) The admission that more then 1 person had access to the machine that generated / printed the keys
There are too many things that are just not done to the way things should be done to take off the negative in my opinion.
HOWEVER, once it looks like everyone has had their swept coins refunded I will update to a neutral.
raritycheck --> Have you attempted to reach out to the people who have not contacted you yet about this who have the coins? Email / PMs / even a letter though the post office if you have no other way of contacting them since you did ship them a coin you should have their address?
-Dave
|
|
|
|
pinky1234
|
 |
August 10, 2024, 03:55:24 PM |
|
At the moment the other negative tags on RC have been changed to neutral, going to leave mine as a warning for the moment. Let's be honest its not going to matter since I don't think anyone is going to be buying anything funded or even with keys they generated for a while.
Once it looks like the majority of the people who lost their funds are paid back at least what they lost I will change it. But for now between the 1) Mistake with the key generation 2) The poor quality of the private keys 3) The admission that more then 1 person had access to the machine that generated / printed the keys
There are too many things that are just not done to the way things should be done to take off the negative in my opinion.
HOWEVER, once it looks like everyone has had their swept coins refunded I will update to a neutral.
raritycheck --> Have you attempted to reach out to the people who have not contacted you yet about this who have the coins? Email / PMs / even a letter though the post office if you have no other way of contacting them since you did ship them a coin you should have their address?
-Dave
2) The poor quality of the private keys you have not seen MR HOLD private key . 
|
|
|
|
21MilBTC
Jr. Member
Offline
Activity: 52
Merit: 5
|
 |
August 10, 2024, 05:05:02 PM |
|
Maybe another member mentioned this already...But if I'm *RC* I'm turning a negative situation into a positive....
If I'm *RC* I'd design a different *New coin from scratch* and every person that purchased a VIBGYOR coin would now get one of the new designed coin for free....
Here's the kicker......The newly designed coin SHOULD NEVER GO ON SALE.....NEVER EVER......They should only go to the people who purchased a coin in this series...Now *RC* has actually created a new collectible for the people affected...Those who purchased funded get one funded...Those who purchased unfunded get one unfunded....What the people do with the coins once they get them...well that's up to them....
Probably a stupid idea on my part....I don't know....Anyways....it looks like everything the bloke can do he is doing...
Props to *RC* but I'm sure others on here may not see it that way....
|
|
|
|
|