Bitcoin Forum
May 09, 2024, 01:14:49 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
Author Topic: Reused R values again  (Read 121127 times)
dimsler
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
December 08, 2014, 06:58:54 PM
 #41

Hello,

there were a large bunch of new broken addresses today (several 100s in one day).  I took the liberty of saving some funds before they got swiped by others.  If you can convince me that they belong to you (signing a message with the address is obviously not enough; the private key is already known),  I will send the funds back.

Look into the file http://johoe.mooo.com/bitcoin/broken.txt, to see whether your address was broken.








One of these address' is mine, can you place contact me, I can provide proof with screen shots or teamview.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715260489
Hero Member
*
Offline Offline

Posts: 1715260489

View Profile Personal Message (Offline)

Ignore
1715260489
Reply with quote  #2

1715260489
Report to moderator
1715260489
Hero Member
*
Offline Offline

Posts: 1715260489

View Profile Personal Message (Offline)

Ignore
1715260489
Reply with quote  #2

1715260489
Report to moderator
1715260489
Hero Member
*
Offline Offline

Posts: 1715260489

View Profile Personal Message (Offline)

Ignore
1715260489
Reply with quote  #2

1715260489
Report to moderator
BenTuras
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1001



View Profile
December 08, 2014, 07:11:46 PM
 #42

...
Look into the file http://johoe.mooo.com/bitcoin/broken.txt, to see whether your address was broken.
I created a little procedure to check if your address is at risk just in case you are using bitcoin-qt.

1. activate "enable coin control features" in options, wallet
2. go to the send tab and click inputs. A list of addresses is shown, sort it by clicking on the heading(the word Addresses)
3. copy/paste each address in this tab to a text file(right click on an address and select copy to put it in the clipboard)
4. save this text file and call it myadrs.txt
5. save the file linked above in the file adr1.txt
6. compare the two files by using the *ux command
    sdiff myadrs.txt adr1.txt | grep -v "|"|grep -v "<"|grep -v ">"
7. if an address is shown(twice), that address of yours is on the list

You can repeat the procedure above for the two files mentioned in https://bitcointalk.org/index.php?topic=581411.msg9711303#msg9711303

If you are running Windows, you can install cygwin to get *ix like commands.

There might be faster procedures to check your addresses, this one worked for me.

I am selling in stock OneStringMiner boards, based on the Bitfury chips. Have a look here: https://bitcointalk.org/index.php?topic=495536.0
buddhamangler
Member
**
Offline Offline

Activity: 74
Merit: 10


View Profile
December 08, 2014, 07:12:42 PM
 #43

Hello,

there were a large bunch of new broken addresses today (several 100s in one day).  I took the liberty of saving some funds before they got swiped by others.  If you can convince me that they belong to you (signing a message with the address is obviously not enough; the private key is already known),  I will send the funds back.

Look into the file http://johoe.mooo.com/bitcoin/broken.txt, to see whether your address was broken.


Hey johoe,

I'm sure you are aware this was a blockchain.info screwup.  See here http://www.reddit.com/r/Bitcoin/comments/2onm5r/blockchaininfo_security_disclosure/

If you are willing, as you have stated, please contact blockchain and work with them as they have the info to prove ownership.  I'm certain you would be rewarded.
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
December 08, 2014, 07:18:00 PM
 #44

Perhaps blockchain.info (if people still trusts them) can create new addresses for the affected users, post the old-new map, and the "good samaritan" can then transfer the amounts there.

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
buddhamangler
Member
**
Offline Offline

Activity: 74
Merit: 10


View Profile
December 08, 2014, 07:24:12 PM
 #45

Perhaps blockchain.info (if people still trusts them) can create new addresses for the affected users, post the old-new map, and the "good samaritan" can then transfer the amounts there.

Bottom line, if this guy didn't do it, then someone else would have.  So the fact he revealed it was him is a good samaritan without quotes in my book.  Your idea has merit, blockchain should contact this person and figure out a way.
MadZ
Hero Member
*****
Offline Offline

Activity: 908
Merit: 657


View Profile
December 08, 2014, 08:02:15 PM
 #46

I'm pretty sure blockchain will reimburse users, since blockchain is clearly at fault and have admitted to it. Returning the funds won't change whether these people get paid back, although it would help blockchain if you actually care about that fact.
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4172
Merit: 8419



View Profile WWW
December 08, 2014, 08:42:57 PM
 #47

Perhaps blockchain.info (if people still trusts them) can create new addresses for the affected users, post the old-new map, and the "good samaritan" can then transfer the amounts there.
The non-random rng would have also resulted in giving unrelated users the same keys. It didn't just effect signing.
tencentcoin
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
December 08, 2014, 09:06:01 PM
 #48

https://blockchain.info/address/1Ha7DNXbiUi5DozhZjtDDveciamb6uQZbR

wha's wrong with my wallet? how to find back my coin?

JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
December 08, 2014, 09:30:52 PM
 #49

The Good Samaritan collected ~216 BTC from some 200--250 compromised Blockchain.info addresses, the last one ~4 hours ago:

https://blockchain.info/address/1Ha7DNXbiUi5DozhZjtDDveciamb6uQZbR

Are those the only ones? (I saw a claim on reddit, without any evidence, that the total losses were higher. Any source for that?)


Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
mizzle
Newbie
*
Offline Offline

Activity: 23
Merit: 0


View Profile
December 08, 2014, 09:38:04 PM
 #50

i am fucking livid right now. over 3.6 btc stolen from my wallet. password changed and i can't get back in. has anyone else had issues with the passwords being changed ? i don't understand why because the wallet is empty.

if i didnt have my wallet as a watch only" address on my phone this would have gone unnoticed. sent a message to blockchain but no reply yet.

anyone else have this problem ? I'm so distraught and upset, this sucks.

https://blockchain.info/address/18VfH6NCktwZ835z4zp52wmvpWEGCSenuf
tencentcoin
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
December 08, 2014, 09:41:40 PM
 #51

i am fucking livid right now. over 3.6 btc stolen from my wallet. password changed and i can't get back in. has anyone else had issues with the passwords being changed ? i don't understand why because the wallet is empty.

if i didnt have my wallet as a watch only" address on my phone this would have gone unnoticed. sent a message to blockchain but no reply yet.

anyone else have this problem ? I'm so distraught and upset, this sucks.

https://blockchain.info/address/18VfH6NCktwZ835z4zp52wmvpWEGCSenuf

my 0.382bitcoin was gone   Embarrassed  that was all of my assets
 
blockchain.info please  Compensation for me   
https://blockchain.info/address/1Ha7DNXbiUi5DozhZjtDDveciamb6uQZbR

JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
December 08, 2014, 09:45:31 PM
 #52

i am fucking livid right now. over 3.6 btc stolen from my wallet. password changed and i can't get back in. has anyone else had issues with the passwords being changed ? i don't understand why because the wallet is empty.

if i didnt have my wallet as a watch only" address on my phone this would have gone unnoticed. sent a message to blockchain but no reply yet.

anyone else have this problem ? I'm so distraught and upset, this sucks.

https://blockchain.info/address/18VfH6NCktwZ835z4zp52wmvpWEGCSenuf

Your address seems to be one of those colected by the "Good Samaritan" and moved here
https://blockchain.info/address/1Ha7DNXbiUi5DozhZjtDDveciamb6uQZbR
He promised to give them back as soon as the owners can prove tha they are theirs.
Check previous messages in this thread.

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
tencentcoin
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
December 08, 2014, 09:46:33 PM
 #53

Address:
1Ha7DNXbiUi5DozhZjtDDveciamb6uQZbR

Message  i am tenecntcoin

Signature:
GzTGNPLtIU659u5sVN+s+0HaVfq9gFAaM5dqgpDogTjDAhEQ8f869TrOth1ARjnGcU+w6fC6Og97mpXFbjgC3a4=

please return my bitcoin to the address 1CjDsHkuhsS4AyueugoV5dMWEUd35r9QZM

yakuza699
Hero Member
*****
Offline Offline

Activity: 935
Merit: 1002


View Profile
December 08, 2014, 09:47:13 PM
 #54

Oh just noticed that someone else just started to swipe the coins(not me still didn't figured out how to do it) https://blockchain.info/address/15g7xSy7j9vMRc9d6Vgn4ugfn2LiV67eaR most of the inputs were from the list so I am 100% sure that someone else is wiping the last coins which is at leas another 10BTC.

▄▄▄▄▄▄▄▄
▄▄▄▄▄▄
▄▄▄▄
BTC BitDice.me 
.
arnuschky
Hero Member
*****
Offline Offline

Activity: 517
Merit: 501


View Profile
December 08, 2014, 09:47:49 PM
 #55


Guys just contact blockchain.info support in case you haven't received an email from them:
http://blog.blockchain.com/2014/12/08/blockchain-info-security-disclosure/
mizzle
Newbie
*
Offline Offline

Activity: 23
Merit: 0


View Profile
December 08, 2014, 09:48:25 PM
 #56

How do I prove they were mine ? Who is the good samartian, why did he do this ?
yakuza699
Hero Member
*****
Offline Offline

Activity: 935
Merit: 1002


View Profile
December 08, 2014, 09:50:19 PM
 #57

How do I prove they were mine ?
You got to figure this out yourself.
Who is the good samartian.
johoe is the good Samaritan.
why did he do this ?
Because he is a very good person which guarded most of the coins from people who would have stolen it.

▄▄▄▄▄▄▄▄
▄▄▄▄▄▄
▄▄▄▄
BTC BitDice.me 
.
mizzle
Newbie
*
Offline Offline

Activity: 23
Merit: 0


View Profile
December 08, 2014, 09:53:33 PM
 #58

I don't think that he is a good samaritan unless he eventually gives me the coins he stole back. I also sent an email to blockchain so hopefully I can get refunded or something...this is retarded.
tencentcoin
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
December 08, 2014, 09:58:16 PM
 #59

i also have send him pm , i wish my coin come back, that is all my btc

please do not cruel to me  Embarrassed

JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
December 08, 2014, 10:05:51 PM
 #60

Here is one BCI user who claims to have lost 99 BTC which were not moved to the Good Samaritan's address:

http://www.reddit.com/r/Bitcoin/comments/2oo72b/victim_100_bitcoins_stolen_from_blockchaininfo/

The destination address got two other inputs; perhaps other ursers?
https://blockchain.info/address/1M77fUCzQrmY8jHRRgpzDVPAK5eQ31bwxZ


Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
Pages: « 1 2 [3] 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!