Bitcoin Forum
June 15, 2024, 02:51:10 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Technical analysis of the EliteCoin heist  (Read 2820 times)
ocminer (OP)
Legendary
*
Offline Offline

Activity: 2660
Merit: 1240



View Profile WWW
July 26, 2014, 04:47:02 PM
 #21


Wow thanks czveda ! You made my day, I totally overlooked that "ly" variable there.. I saw that +1 at the block height and already thought that no checks were performed for block 1 but I missed "ly" totally.

Thank you very much, that explains it pretty much !

np. I was looking at it last night and couldn't figure out initially, it is so easy to misread that "ly" variable. I am not sure that the dev would be caught if he named that variable differently, I doubt that anyone was checking moneysupply function and its output before the dump happened. 

I am usually checking moneysupply before adding if the dev says "NO PREMINE", but I think I'll add a Coinexplorer @ Suprnova to every coin I add a few minutes or hours after launch now too .. there seems to be no decent other way around such things...

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
Dimitry
Hero Member
*****
Offline Offline

Activity: 896
Merit: 501



View Profile
July 26, 2014, 04:47:33 PM
 #22

Noob question how is it possible the explorer from the dev was showing another amount?
ocminer (OP)
Legendary
*
Offline Offline

Activity: 2660
Merit: 1240



View Profile WWW
July 26, 2014, 04:51:20 PM
 #23

Noob question how is it possible the explorer from the dev was showing another amount?

Did the coin actually have an explorer ? Wow it was actually SO good organized ? Woooow :-)

I did not notice that..

But the OP of a explorer can fake everything.. I can enter any value you want in my explorer there, I've got access to database behind it..

You'll have to trust a explorer from legit source i.e. only on a domain you know.. I think ssdpool provides explorers too.. I'll add a extra domain for that probably too

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 04:59:07 PM
 #24

well guys I am'not coder but it were words of dev:
_______________________________________________________________________________ __________________________________________________
Also, about the POW phase, 2 weeks is not a long time. If everybody got used to coins with pow phases of 24~72 hours, it's not our problem. And those kind of coins die in 2 days.

It's been only 3 days, and anything could happen. But we're still here answering all questions, and we're active.
About the dump, NO ONE can control that! People will eventually dump a lot of coins for cheap. Now that the price is stable again, the only way to rise it is holding the coins or buying a big volume at a higher price.

We'll be also buying our own coins, since we started mining like everybody else, yesterday.
_______________________________________________________________________________ __________________________________________________

dev begin to mining 24th and dump was 25th, at this point he sell a lot in dump , but he could to buy all again just now, elite could be very valuable in time
because devs dont delete posts, they only lock this, this a signal that coins will continue in a time give to be development by others or even same devs,so
nobody lost nothing only if holder sell,I think that for this reason devs are vanished in launching...........    they are very very smart guys......., anyway they
have control due to they buy again very very cheap......I understand game now..........
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 05:07:14 PM
 #25

In other words my wallet in bittrex now have value like to shit if sell now,   but  what about in next years??? I mean I buy expensive shit  it drop
nearly to 1 sat, but tomorrow?Huh
ocminer (OP)
Legendary
*
Offline Offline

Activity: 2660
Merit: 1240



View Profile WWW
July 26, 2014, 05:16:23 PM
 #26

In other words my wallet in bittrex now have value like to shit if sell now,   but  what about in next years??? I mean I buy expensive shit  it drop
nearly to 1 sat, but tomorrow?Huh

Keep it.. Maybe someday there will "Scam Busters" which are collecting coins from good scams ^^

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 05:22:59 PM
 #27

In other words my wallet in bittrex now have value like to shit if sell now,   but  what about in next years??? I mean I buy expensive shit  it drop
nearly to 1 sat, but tomorrow?Huh

Keep it.. Maybe someday there will "Scam Busters" which are collecting coins from good scams ^^

 Cheesy     all is possible at this point,  what about "Scammers biggest of Crypto"   many peoples only will delete this wallets but only a few will keep it
Dimitry
Hero Member
*****
Offline Offline

Activity: 896
Merit: 501



View Profile
July 26, 2014, 05:24:59 PM
 #28

No consider your investment lost! Better make your own coin, name it Elite you will have more succes then waiting for this to recover! Because that just aint possible
paradigmflux
Sr. Member
****
Offline Offline

Activity: 378
Merit: 254

small fry


View Profile WWW
July 26, 2014, 05:26:34 PM
 #29

OCMiner, I run a couple multipools - let me know if you'd like to share any of the VPS cost for hosting the block explorers or anything.   Or perhaps we could both host each of the coins explorers and link to one another's explorers to prove that the data is untampered with?

---
NXT Multipool! Mine Scrypt, SHA, Keccak or X11 for NXT! http://hashrate.org
http://hashrate.org/getting_started for port info!
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 05:35:20 PM
 #30

No consider your investment lost! Better make your own coin, name it Elite you will have more succes then waiting for this to recover! Because that just aint possible

If I think about  clone a coin and launch it, it will be forked in a second.......... like to old scrypt........  Cheesy Cheesy Cheesy
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 05:45:08 PM
 #31

Anyway Elite keep in crypto I think, only need change slogan ¨20000 Elites + a little premine hidden of Dev¨    Devs need money to travel and make his things   Grin
cassius69
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
July 26, 2014, 05:46:43 PM
 #32

quit supporting new coin launches by newbie devs.

its the easiest way to solve this problem.

ocminer (OP)
Legendary
*
Offline Offline

Activity: 2660
Merit: 1240



View Profile WWW
July 26, 2014, 05:47:39 PM
 #33

OCMiner, I run a couple multipools - let me know if you'd like to share any of the VPS cost for hosting the block explorers or anything.   Or perhaps we could both host each of the coins explorers and link to one another's explorers to prove that the data is untampered with?

Good idea, I'll get in touch with you soon !

suprnova pools - reliable mining pools - #suprnova on freenet
https://www.suprnova.cc - FOLLOW us @ Twitter ! twitter.com/SuprnovaPools
bit1
Legendary
*
Offline Offline

Activity: 938
Merit: 1000



View Profile
July 26, 2014, 05:50:47 PM
 #34

quit supporting new coin launches by newbie devs.

its the easiest way to solve this problem.

+1
damiano
Legendary
*
Offline Offline

Activity: 1246
Merit: 1000


103 days, 21 hours and 10 minutes.


View Profile
July 26, 2014, 05:56:24 PM
 #35

I'm sorta glad this happened. 

This will make things more strict on Bittrex.  If you lost that's just to bad, you all knew what you were getting into with all these shitcoins coming out daily.  This isn't Bittrex's fault, it's your own. 

Moving forward Bittrex shouldn't even acknowledge newbie dev's. 
Wulfcastle
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile WWW
July 26, 2014, 06:00:02 PM
 #36

Could someone post a TL;DR version of what happened with Elite? Was it a scam or did an attack take place against it that caused double spends?
tylerderden
Copper Member
Legendary
*
Offline Offline

Activity: 1162
Merit: 1025



View Profile
July 26, 2014, 06:00:17 PM
 #37

Hey guys,

since nobody is replying in the Thread concerning my questions, I'm starting a new thread here.

Usually I'm checking coins b4 adding them to suprnova, at least i'm doing some preliminary checks (no virus, "bad" code, no code where the first block is like 500.000 coins while the coinsupply is only 50.000 .. etc). I tried to do that on Elite too, but the "usual" places where moved into other files, so I skipped it and since I saw other "big" pools on it I did not think anything bad as they're also supposed to do checks, don't they ? Smiley (no, i will not do that again, don't worry Smiley)

However, the next morning I saw coinsupply tripled and on bittrex coins were dumped for about 20 BTC which made me look again and its weird..

I've set up an Block Explorer on a old machine as I could not find any online (its hell slow, please bear with me Smiley):
http://blocks.suprnova.cc:2750/

The source is here:
https://github.com/dimecoinco/elitecoin (thx to rikkejohn)

The first block pays out 20.000 to one address:
http://blocks.suprnova.cc:2750/block/00000ef54a645ff81b0d06b5fa10c2e0c4cbfd1af6448cc8747978fae96e6722

But this 20.000 payout is not reflected in the money supply, can someone point me to the place in the code where this is surpressed ?

When we take a closer look at some suspicious blocks, you see this address again:
http://blocks.suprnova.cc:2750/address/dMFkHRK1WRFVQLBvozBeKYAWfaAFQUsy1y

Especially Block 3448 and 4338 (which straaaange numbers Smiley) pay 20.000 AGAIN to the dev's address  .. The source is ALSO the dev's address so this is basically a double spent (or a double generation?):

http://blocks.suprnova.cc:2750/block/000000000025fe115ebd4ca762e1525c9889b3b9dbff29c6bb3c685bf953323a

(I dont know why 1000 coins go to the other address)

At block 4338 these coins get moved (probably to bittrex or so):
http://blocks.suprnova.cc:2750/address/dLvQf3686DgCPZBuHCixK9DBi8CMoeHCDe


Anyone got an idea how actually that worked ?


For that double generation/spend you usually also need a decent pool with large hashrate for this...


Thx !


PS: Oh and stop that shit and fud about bittrex please, you cannot blame the cardealer when you let your car repair by some strange workshop and then your brakes do not work - the only mistake they made - they did add it even though there was no block explorer available, which I hope they won't in the future..
Thanks for setting up the block explorer.
I did some analysis on my own. I don't think that 3448 involved double spending, it was just 1k transfer to another address, one can see 20k out and 19k in to the same premine address
In block 1 premine happened because of this:
https://github.com/dimecoinco/elitecoin/blob/394f19b04a49bf79368c29b7a3b617999f95acb5/src/main.cpp#L1567
i.e. for block 1 checking of coinbase reward was skipped so the dev could mine anything.  
Regarding moneysupply, the "dev" first defined the variable ly:
https://github.com/dimecoinco/elitecoin/blob/394f19b04a49bf79368c29b7a3b617999f95acb5/src/rpcwallet.cpp#L47
and then subtracted it from the actual money supply:
https://github.com/dimecoinco/elitecoin/blob/394f19b04a49bf79368c29b7a3b617999f95acb5/src/rpcwallet.cpp#L94


Wow thanks czveda ! You made my day, I totally overlooked that "ly" variable there.. I saw that +1 at the block height and already thought that no checks were performed for block 1 but I missed "ly" totally.

Thank you very much, that explains it pretty much !



there was a post a few weeks ago by a guy showing exactly how people are doing this, my guess the "dev" saw this post and tried it for himself and it worked apparently.
Dimitry
Hero Member
*****
Offline Offline

Activity: 896
Merit: 501



View Profile
July 26, 2014, 06:39:21 PM
 #38

I'm sorta glad this happened.  

This will make things more strict on Bittrex.  If you lost that's just to bad, you all knew what you were getting into with all these shitcoins coming out daily.  This isn't Bittrex's fault, it's your own.  

Moving forward Bittrex shouldn't even acknowledge newbie dev's.  

I'm glad this happend to. Bittrex shows true colors and it will be a short term exchange that has no vision for future, happy I found it out now!
damiano
Legendary
*
Offline Offline

Activity: 1246
Merit: 1000


103 days, 21 hours and 10 minutes.


View Profile
July 26, 2014, 06:55:18 PM
 #39

I'm sorta glad this happened.  

This will make things more strict on Bittrex.  If you lost that's just to bad, you all knew what you were getting into with all these shitcoins coming out daily.  This isn't Bittrex's fault, it's your own.  

Moving forward Bittrex shouldn't even acknowledge newbie dev's.  

I'm glad this happend to. Bittrex shows true colors and it will be a short term exchange that has no vision for future, happy I found it out now!

I doubt this will effect its business.

Mintpal is dead and Poloniex isn't that popular.

Bter is just alright

When you buy a shitcoin you are taking a risk
Dimitry
Hero Member
*****
Offline Offline

Activity: 896
Merit: 501



View Profile
July 26, 2014, 07:00:56 PM
 #40

Mintpal was big few months ago had little problem with hack and are left for dead. Bittrex is walking the same path diff route.
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!