Bitcoin Forum
November 03, 2024, 03:43:19 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 [11] 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
Author Topic: Reused R values again  (Read 121270 times)
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 14, 2014, 08:48:46 PM
 #201


I feel like Sisyphos.  You think you swiped everything but in the mean time someone else sends you new money...



Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3710
Merit: 10429


#1 VIP Crypto Casino


View Profile
December 14, 2014, 08:50:07 PM
 #202

Reddit talking about johoe today.

http://www.reddit.com/r/Bitcoin/comments/2p9zv2/300_more_btc_swept_from_insecure_wallets_by_johoe/

█████████████████████████
███████████▄█████████████
██████▀░▀█▀░▀█▀░▀████████
███████▄███▄███▄█████████
████▀██▀██▀░▀████▀░▀█████
███████████░███▀██▄██████
████▀██▀██░░░█░░░████████
███████████░███▄█▀░▀█████
████▀██▀██▄░▄███▄░░░▄████
███████▀███▀███▀██▄██████
██████▄░▄█▄░▄█▄░▄████████
███████████▀█████████████
█████████████████████████
 
.Bitcasino.io.
 
.BTC  ✦  Where winners play  BTC.
.
..
.
    ..





████
████
░░▄████▄████████████▄███▄▄
░███████▄██▄▄▄▄▄▄█████████▄
███████████████████████████
▀████████████████████████▀
░░▀▀████████████████████
██████████████████▄█████████
██
▐███████▀███████▀██▄██████
███████▄██▄█▀████▀████████
░░██████▀▀▀▄▄▄████▀▀████
██▐██████████▀███▀█████████████    ████
███
████████████
███████████████    ████
█████▀████████████████▀
███████▀▀▀█████████▀▀
..
....
 
 ..✦ Play now... 
.
..
itod
Legendary
*
Offline Offline

Activity: 1974
Merit: 1077


^ Will code for Bitcoins


View Profile
December 14, 2014, 09:11:55 PM
 #203


I feel like Sisyphos.  You think you swiped everything but in the mean time someone else sends you new money...

You need Bitcoin forwarder service, upload private keys and it forwards funds the moment it sees them on the blockchain. Since it doesn't exist, you'll have to write your own Wink
BlindMayorBitcorn
Legendary
*
Offline Offline

Activity: 1260
Merit: 1116



View Profile
December 14, 2014, 09:13:05 PM
Last edit: December 14, 2014, 09:35:10 PM by BlindMayorBitcorn
 #204


I feel like Sisyphos.  You think you swiped everything but in the mean time someone else sends you new money...




Keep rollin' that big Bitcoin up that hill, brother. We have need of you up there Wink

Forgive my petulance and oft-times, I fear, ill-founded criticisms, and forgive me that I have, by this time, made your eyes and head ache with my long letter. But I cannot forgo hastily the pleasure and pride of thus conversing with you.
johoe (OP)
Full Member
***
Offline Offline

Activity: 217
Merit: 259


View Profile
December 14, 2014, 11:06:02 PM
 #205

Another 500 keys cracked  Grin

I have computed more random values, but still have not captured all.
Unfortunately my ssh session timed out and took my script with it  Angry
Have to run it again, it will probably find some more keys.



Donations to 1CF62UFWXiKqFUmgQMUby9DpEW5LXjypU3
goosoodude
Hero Member
*****
Offline Offline

Activity: 584
Merit: 500



View Profile
December 14, 2014, 11:20:02 PM
 #206

Seems to me that johoe can do that nobody else can on this planet.
https://blockchain.info/address/1HuqM18GMVaLxTRGdmSgytzVYnhRzu7U68
awesome!
(he just saved/swept more ~300 btc)

  Grin

the answer is in the post directly above yours (by bcearl).


You, sir, are a true hero! Thanks for saving the day again.

What surprises me is that no hacker tried to use this in the meantime to steal.






██████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████▄▄▄███████████████████████
███████████████████████████████████████████████████████████████████████▀▀▀████████████████████████
██████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████





...INTRODUCING WAVES........
...ULTIMATE ASSET/CUSTOM TOKEN BLOCKCHAIN PLATFORM...






HospitalDonations
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
December 14, 2014, 11:23:54 PM
 #207

Ok this for help us continue  Kiss
we be wait more your details and informations   Roll Eyes


P.S

You very popular in tv show
guy robin hod
make 200.000$ victms you big boy in bitcoins scene

also thanx for any your donations we accept in our scene litle more
i am very love you!
sumantso
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000



View Profile
December 14, 2014, 11:34:15 PM
 #208

Another 500 keys cracked  Grin

I have computed more random values, but still have not captured all.
Unfortunately my ssh session timed out and took my script with it  Angry
Have to run it again, it will probably find some more keys.


This is going on and on with no end in sight Shocked

Keep up the good work, johoe.

LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3710
Merit: 10429


#1 VIP Crypto Casino


View Profile
December 14, 2014, 11:43:16 PM
 #209

I think it'd be a good idea not to explain in any detail no matter how minor the process that allows you to get these private keys etc.

People with different intentions are going to learn how to do it.

█████████████████████████
███████████▄█████████████
██████▀░▀█▀░▀█▀░▀████████
███████▄███▄███▄█████████
████▀██▀██▀░▀████▀░▀█████
███████████░███▀██▄██████
████▀██▀██░░░█░░░████████
███████████░███▄█▀░▀█████
████▀██▀██▄░▄███▄░░░▄████
███████▀███▀███▀██▄██████
██████▄░▄█▄░▄█▄░▄████████
███████████▀█████████████
█████████████████████████
 
.Bitcasino.io.
 
.BTC  ✦  Where winners play  BTC.
.
..
.
    ..





████
████
░░▄████▄████████████▄███▄▄
░███████▄██▄▄▄▄▄▄█████████▄
███████████████████████████
▀████████████████████████▀
░░▀▀████████████████████
██████████████████▄█████████
██
▐███████▀███████▀██▄██████
███████▄██▄█▀████▀████████
░░██████▀▀▀▄▄▄████▀▀████
██▐██████████▀███▀█████████████    ████
███
████████████
███████████████    ████
█████▀████████████████▀
███████▀▀▀█████████▀▀
..
....
 
 ..✦ Play now... 
.
..
JorgeStolfi
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1003



View Profile
December 14, 2014, 11:49:11 PM
 #210

I feel like Sisyphos.  You think you swiped everything but in the mean time someone else sends you new money...
You need Bitcoin forwarder service, upload private keys and it forwards funds the moment it sees them on the blockchain. Since it doesn't exist, you'll have to write your own Wink

If there was a forwarding option in the protocol, the first thing a black hat hacker would do is to sweep the coins, the second thing would be to set up forwarding to his address (and set it again every time the original owner tries to reset it).

Academic interest in bitcoin only. Not owner, not trader, very skeptical of its longterm success.
ProfMac
Legendary
*
Offline Offline

Activity: 1246
Merit: 1002



View Profile
December 15, 2014, 12:23:01 AM
 #211

Do I have to use bitcoin-cli listtransactions and then dump each transaction to check which output was spent?

The wallet operations on bitcoind are so slow when you have 1400 private keys imported.

As I understand there's a new feature which will be introduced into bitcoind 0.10.0 to work with addresses without importing private keys (watch-only):
https://github.com/bitcoin/bitcoin/pull/4045
It should give you what you want with 'listtransactions', and should be working already in 0.10 branch in github, if you feel like working with it.


I'm confused here.

I have been using the reference (Satoshi) client, both the graphic version and the daemon version.  I did not check before posting, but I am pretty sure that I have used watch only addresses for a year or two.


I try to be respectful and informed.
bitcoinaliens
Sr. Member
****
Offline Offline

Activity: 337
Merit: 250



View Profile WWW
December 15, 2014, 01:18:24 AM
 #212

As always I plan to return it to bc.i and you can contact their support to get your refund.

I've had 1+btc "sweeped" into your account, and have requested to get it returned from Blockchain.info - this is their response:
    
Quote
Mandrik (Blockchain)
Dec 14 20:11

Thank you for this information. We require further investigation into this matter, which means we need to verify that this address was generated in your wallet. Unfortunately we can only do this with the wallet identifier + password. Please provide this information along with the total amount removed from the other address.

Be sure to *NEVER* use the compromised bitcoin address again. You should also generate a new wallet at https://www.blockchain.info/wallet/new, and never use the other wallet again, since you'll be sharing the password information with us.

This looks like the stupidest idea ever to me - to send them my identifier and password over email (I have other bitcoin in other wallets inside that account... not for long..)

I'm pretty shocked that this is their approach to helping me to SECURE my bitcoin? Is this even allowed / legit?

Bitcoin Banner Advertising - CoinAd, the world's largest bitcoin focused ads network.
DalienGames.com - Earn bitcoin while you play FREE online flash games.
Tubers.tv - Earn bitcoin while you watch ANY video online.
Blockchain Stats - Earn bitcoin while you check the bitcoin and altcoin prices.
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
December 15, 2014, 03:23:20 AM
 #213

As always I plan to return it to bc.i and you can contact their support to get your refund.

I've had 1+btc "sweeped" into your account, and have requested to get it returned from Blockchain.info - this is their response:
    
Quote
Mandrik (Blockchain)
Dec 14 20:11

Thank you for this information. We require further investigation into this matter, which means we need to verify that this address was generated in your wallet. Unfortunately we can only do this with the wallet identifier + password. Please provide this information along with the total amount removed from the other address.

Be sure to *NEVER* use the compromised bitcoin address again. You should also generate a new wallet at https://www.blockchain.info/wallet/new, and never use the other wallet again, since you'll be sharing the password information with us.

This looks like the stupidest idea ever to me - to send them my identifier and password over email (I have other bitcoin in other wallets inside that account... not for long..)

I'm pretty shocked that this is their approach to helping me to SECURE my bitcoin? Is this even allowed / legit?

Are you sure this was sent by blockchain.info not some other scammer?
FinanceUS
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
December 15, 2014, 03:55:12 AM
 #214

As always I plan to return it to bc.i and you can contact their support to get your refund.

I've had 1+btc "sweeped" into your account, and have requested to get it returned from Blockchain.info - this is their response:
    
Quote
Mandrik (Blockchain)
Dec 14 20:11

Thank you for this information. We require further investigation into this matter, which means we need to verify that this address was generated in your wallet. Unfortunately we can only do this with the wallet identifier + password. Please provide this information along with the total amount removed from the other address.

Be sure to *NEVER* use the compromised bitcoin address again. You should also generate a new wallet at https://www.blockchain.info/wallet/new, and never use the other wallet again, since you'll be sharing the password information with us.

This looks like the stupidest idea ever to me - to send them my identifier and password over email (I have other bitcoin in other wallets inside that account... not for long..)

I'm pretty shocked that this is their approach to helping me to SECURE my bitcoin? Is this even allowed / legit?



I guess you'd move your funds away from all other addresses generated in this wallet first. You will have to abandon this account anyway.

If you're still afraid of signing transactions with blockchain.info, you may sign these transactions offline with other clients like Electrum.
smoothie
Legendary
*
Offline Offline

Activity: 2492
Merit: 1474


LEALANA Bitcoin Grim Reaper


View Profile
December 15, 2014, 04:10:33 AM
 #215

@johoe,

I'll send you one of my brass coins (unloaded) to you for free.

PM me or email me your shipping information and I'll send it your way.

smoothie@lealana.com

thanks for being honest! It is refreshing to have that around here.  Smiley

███████████████████████████████████████

            ,╓p@@███████@╗╖,           
        ,p████████████████████N,       
      d█████████████████████████b     
    d██████████████████████████████æ   
  ,████²█████████████████████████████, 
 ,█████  ╙████████████████████╨  █████y
 ██████    `████████████████`    ██████
║██████       Ñ███████████`      ███████
███████         ╩██████Ñ         ███████
███████    ▐▄     ²██╩     a▌    ███████
╢██████    ▐▓█▄          ▄█▓▌    ███████
 ██████    ▐▓▓▓▓▌,     ▄█▓▓▓▌    ██████─
           ▐▓▓▓▓▓▓█,,▄▓▓▓▓▓▓▌          
           ▐▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▌          
    ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓─  
     ²▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓╩    
        ▀▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀       
           ²▀▀▓▓▓▓▓▓▓▓▓▓▓▓▀▀`          
                   ²²²                 
███████████████████████████████████████

. ★☆ WWW.LEALANA.COM        My PGP fingerprint is A764D833.                  History of Monero development Visualization ★☆ .
LEALANA BITCOIN GRIM REAPER SILVER COINS.
 
smoothie
Legendary
*
Offline Offline

Activity: 2492
Merit: 1474


LEALANA Bitcoin Grim Reaper


View Profile
December 15, 2014, 04:13:02 AM
 #216

I think it'd be a good idea not to explain in any detail no matter how minor the process that allows you to get these private keys etc.

People with different intentions are going to learn how to do it.

True. A fix needs to be implemented soon so that other malicious bystanders do not gain access to his method(s) and wreak havoc.

███████████████████████████████████████

            ,╓p@@███████@╗╖,           
        ,p████████████████████N,       
      d█████████████████████████b     
    d██████████████████████████████æ   
  ,████²█████████████████████████████, 
 ,█████  ╙████████████████████╨  █████y
 ██████    `████████████████`    ██████
║██████       Ñ███████████`      ███████
███████         ╩██████Ñ         ███████
███████    ▐▄     ²██╩     a▌    ███████
╢██████    ▐▓█▄          ▄█▓▌    ███████
 ██████    ▐▓▓▓▓▌,     ▄█▓▓▓▌    ██████─
           ▐▓▓▓▓▓▓█,,▄▓▓▓▓▓▓▌          
           ▐▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▌          
    ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓─  
     ²▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓╩    
        ▀▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀       
           ²▀▀▓▓▓▓▓▓▓▓▓▓▓▓▀▀`          
                   ²²²                 
███████████████████████████████████████

. ★☆ WWW.LEALANA.COM        My PGP fingerprint is A764D833.                  History of Monero development Visualization ★☆ .
LEALANA BITCOIN GRIM REAPER SILVER COINS.
 
wantrepreneur
Full Member
***
Offline Offline

Activity: 147
Merit: 100


View Profile
December 15, 2014, 04:35:48 AM
 #217

Johoe, you just swept my keys!!!

Thank god your doing the right thing, you are my f*cking hero.

(will PM my address for further verification)
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
December 15, 2014, 06:53:13 AM
 #218

Another 500 keys cracked  Grin

I have computed more random values, but still have not captured all.
Unfortunately my ssh session timed out and took my script with it  Angry
Have to run it again, it will probably find some more keys.

try 'screen' command (gnu screen)

keeps your shit running even if you connection goes down. You can connect again with 'screen -x'

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
russokai
Full Member
***
Offline Offline

Activity: 130
Merit: 100


View Profile
December 15, 2014, 07:07:02 AM
 #219

Johoe, you just swept my keys!!!

Thank god your doing the right thing, you are my f*cking hero.

(will PM my address for further verification)

Yes he swept mine too and just emailed blockchain about it.  But yes Johoe is a great guy...tough to find those in this world most of the time.
dserrano5
Legendary
*
Offline Offline

Activity: 1974
Merit: 1029



View Profile
December 15, 2014, 08:28:39 AM
 #220

Unfortunately my ssh session timed out and took my script with it  Angry

try 'screen' command (gnu screen)

keeps your shit running even if you connection goes down.

Then try mosh. Your connection won't go down. Even if your IP changes.
Pages: « 1 2 3 4 5 6 7 8 9 10 [11] 12 13 14 15 16 17 18 19 20 21 22 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!