Bitcoin Forum
November 03, 2024, 12:35:20 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 »
  Print  
Author Topic: Hufflepuff Making 2k BTC On PrimeDice Nov 2014. March 2015 Update: He Cheated  (Read 50019 times)
WhatTheGox (OP)
Legendary
*
Offline Offline

Activity: 812
Merit: 1000



View Profile
November 02, 2014, 12:07:32 PM
Last edit: June 29, 2015, 08:22:40 AM by WhatTheGox
 #1

Hufflepuff crossing 1000 Bitcoin profit on PrimeDice, watched it live and recorded the moment (vid below), so sick.

https://www.youtube.com/watch?v=uALj-u-BvOc&list=UUYT9hwCLb2qhv8wnCGWmw9w

Part 2: Hufflepuff Continues And Makes 2000 Bitcoin Profit

https://www.youtube.com/watch?v=lSLXv5Tz1ZY&list=UUYT9hwCLb2qhv8wnCGWmw9w&index=1


March 2015 Update:

Hufflepuff cheated & managed to run off with the coins according to reports from primedice


------------------------

June 2015 Update:  https://medium.com/@Stunna/breaking-the-house-63f1021a3e6d

How it was done:

Quote
This is the story of how we lost around $1 million worth of bitcoin to a hacker who exploited our online casino’s RNG system. This happened last year, but we’ve decided to share our experience for transparency and so that others can learn from our mistakes.

August 2014

Shortly after the launch of the third version of Primedice, our team faced an adversary that challenged the existence of our website. Our team had nearly two years of experience building bitcoin gaming sites, however I personally had pretty limited coding experience. We were under heavy pressure to avoid further delays and released after a short week of closed beta testing.

The heist began immediately after launch with two unusual players, Nappa & Kane. We noticed unusual betting patterns from both those accounts. Kane was automatically cashed out, we reviewed Nappa’s bets and thought they were highly unusual but could find no wrong-doing and cashed him out after a delay and a brief email exchange

September 2014

After getting spooked by his delayed cashout on Nappa, the exploiter waited a few weeks and created a new account named “Hufflepuff”. Hufflepuff was the largest bettor Primedice had ever seen, he was often seen betting upwards of $8000 worth of bitcoin every second for hours on end. Our entire team was shocked that Hufflepuff continued to beat the house edge (1%) and stack up more and more profit over time.

We were highly skeptical of his winnings and were forced to hold his cashouts time and time again to investigate and each time our developers could not find any wrong-doing. We couldn’t justify greatly delaying his withdrawals when there was no evidence he was cheating. There was also strong incentive for us to promptly pay him, so he’d keep playing. We heavily explored what we thought was every possibility, ran simulations and did the math and came to the conclusion that he was just incredibly lucky.

The Discovery

About two days after sending his final withdrawal placing him above 2037 profit on the Hufflepuff account alone, our main developer detected the exploit after we found a handful of accounts sharing the same server seed.

To understand how Hufflepuff beat our system, one must understand how our provably fair system (RNG) works. A user is shown an encrypted random value (the server seed) before they bet and they must also submit their own random value (the client seed). These two random values are combined and used to determine win or lose. The random encrypted random value used for the bet then is shown to the user after the bet so that they can be guaranteed that their bet is not rigged. You can find the detailed and in-depth explanations of provably fair here:

https://primedice.com/verify and http://dicesites.com/provably-fair

Part of the functionality of our site is that we have to give out decrypted server seeds (to assure users no bet manipulation has occurred) and put a new random seed in place, essentially trashing the old revealed seed. Hufflepuff found a way to “confuse” our server, and made it give out a decrypted server seed that was also an active seed. This was done by sending it more requests than it could handle in a small time period, think hundreds of requests in under a second. The result of this is that he knew all the information required to corroborate the outcomes of his bets. He knew whether if he would win or lose, and could wager accordingly.

We figured this out after frantically checking our servers after a eureka moment. We suspected something could have been going on and eventually realized the possibility of a timing attack described above. Our database had seeds that were both inactive and in use at the same time all connected to Hufflepuff. Along these “Schrödinger” seeds existed many seemingly unused seeds connected to the same accounts, indicative of the rapid fire of requests needed to obtain these.

Déjà vu

Unfortunately we detected this exploit after cashing out Hufflepuff and his handful of accounts 2400+ coins (roughly $1M at the time). Given the nature of Bitcoin there wasn’t much we could do but take it on the chin. We reached out to Hufflepuff via his bitcointalk forum account and demanded the return of the coins, however this backfired unbelievably hard. It turned out that our developer had improperly patched the glitch. In response to our message, Hufflepuff created a new account named Robbinhood and proceeded to rapidly win 2000+ additional bitcoins using a work-around to the patch. He was unable to cashout more than 50 or 60 coins this time around as our site hot-wallet was drained.

Shortly after he privately sent us this message which was preceded with the dox of a primedice employee:

    “Your offer is declined. Your demands are laughable. I’m happy to walk away and leave you be, but if you’re going to take this further, then so will I. I don’t think you want this to go further. I actually enjoy this shit. Your move.
    Oh, and by the way, there are some pending withdrawals that you need to process.”

And that was the day the house didn’t win…
Evidence for transparency and investigative purposes

Hufflepuff’s deposit address: https://blockchain.info/address/1BiPXmDrHm7VXZnWy6NnW1ZbPc4dcpfkH5

His primary withdrawal address: https://blockchain.info/address/14iS2UvcLK33xkC1K1qL1dhEbp49aiNfNp

Email: hufflepuff@anonymousspeech.com

RobbinHood withdrawals:

https://blockchain.info/address/14HQ67ZhmATviHi9RdYhbUriAGSFmJpYoB

— Note — : Nappa/Kane were two other usernames used early on, amongst many others.

Kane’s Withdrawal address: https://blockchain.info/address/18dMBap634aESPTeD3FGcAgJ2S9n4qtBTZ

Nappa Deposit address: https://blockchain.info/address/16h9ggSzUWdvagEJdNvWVYiUkytw6SJgiB

Nappa email: kritonian@outlook.com

Some IP’s used between accounts: 184.75.221.106, 184.75.223.34 , 151.224.50.156 , 76.179.22.16

Any information that leads to the return of the coins from this incident will be greatly rewarded. We invite you to analyze the above bitcoin addresses and find out where the bulk of the coins ended up if you have the skills.

It’s also important to note that this incident is proof of the strength of our integrity and provably fair system. If at any point we attempted to rig Hufflepuff’s bets (skip nonces etc) we would have instantly realized he was cheating and we would have 2400+ more bitcoins. Hufflepuff only took a brief break from playing after we halved our max bet, I believe he would have cleaned us had we never discovered what was going on. We fund our own bankroll so no users were negatively impacted as a result of this.

Sorry for the long read,

Stunna & Primedice


Contact: Stunna@primedice.com


bitcasino
Sr. Member
****
Offline Offline

Activity: 342
Merit: 250



View Profile
November 02, 2014, 12:30:07 PM
 #2

Great video!
How much did he win at the end? And withdraw?  Smiley
Nobitcoin
Legendary
*
Offline Offline

Activity: 966
Merit: 1000


In holiday we trust


View Profile
November 02, 2014, 12:32:05 PM
 #3

With the video looked like he just about got even... What privileges do you get betting that much on PD?
Splatters
Legendary
*
Offline Offline

Activity: 1232
Merit: 1000


★YoBit.Net★ 1400+ Coins Exchange


View Profile
November 02, 2014, 12:44:54 PM
 #4

crazy! Whit how many BTC he started?

I know why your pray will never be answered!
omahapoker
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000



View Profile
November 02, 2014, 12:47:49 PM
 #5

With the video looked like he just about got even... What privileges do you get betting that much on PD?



ah never again have to work and deal with a boss
finlon
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


View Profile
November 02, 2014, 01:07:11 PM
 #6

crazy! Whit how many BTC he started?
That is crazy. He has wagered over 27 thousand coins and is at a profit of 885 right now. Is he the biggest winner yet?

FanEagle
Legendary
*
Offline Offline

Activity: 3038
Merit: 1129


View Profile
November 02, 2014, 01:08:12 PM
 #7

I wish he would like to giveaway some.
sandykho47
Sr. Member
****
Offline Offline

Activity: 252
Merit: 251

Knowledge its everything


View Profile
November 02, 2014, 01:14:23 PM
 #8

Yeah, that's true
I have seen him while i open primedice.com

I bet stunna is sad
And maybe some people trying to do exactly same as Hufflepuff do

Kemampuanku Tidak semua orang memiliki dan dapat melakukannya . Tidak memakan kaum sendiri . dan mempunyai kode etik yang tidak masuk akal.
niaz
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
November 02, 2014, 01:22:18 PM
 #9

its a big loss for PD & i thinks best win on any gambling site here...
Joca97
Legendary
*
Offline Offline

Activity: 3794
Merit: 1030

The Best Tipster on the Forum!!


View Profile
November 02, 2014, 01:36:24 PM
 #10

i have seen his betting

it was really sick!

Best betting Tipster on the forum by far!!  Join my telegram channel for free https://t.me/joca97freepicks and checkout the free predictions daily!!
Splatters
Legendary
*
Offline Offline

Activity: 1232
Merit: 1000


★YoBit.Net★ 1400+ Coins Exchange


View Profile
November 02, 2014, 01:59:32 PM
 #11

I can lose 1000 BTC and I probably can win 0.01. Try me!

I know why your pray will never be answered!
galbros
Legendary
*
Offline Offline

Activity: 1022
Merit: 1000


View Profile
November 02, 2014, 02:00:36 PM
 #12

That must have been a heck of a comeback.  When I was on he was hovering in the 470 to 520 profit range.  Good for him, did he come into the chat to talk about it or was he too afraid of excessive rain begging?
Shogen
Legendary
*
Offline Offline

Activity: 966
Merit: 1001



View Profile
November 02, 2014, 02:08:15 PM
 #13

That is really an amazing run, and it is fun to see a high rollers bot "spamming" in chat lol. Cheesy

marcotheminer
Legendary
*
Offline Offline

Activity: 2072
Merit: 1049


┴puoʎǝq ʞool┴


View Profile
November 02, 2014, 02:32:21 PM
 #14

With the video looked like he just about got even... What privileges do you get betting that much on PD?
ah never again have to work and deal with a boss

For now yes! If he comes back to try his luck again then a new boss will most likely come too Wink
Minnlo
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000



View Profile
November 02, 2014, 02:46:01 PM
 #15

Hufflepuff crossing 1000 Bitcoin profit on PrimeDice, watched it live and recorded the moment (vid below), so sick.

https://www.youtube.com/watch?v=uALj-u-BvOc&

At the end of the video, Huff has wagered a total of 24290 bitcoin. At 1% edge, Stunna was expecting to win 243 btc from him, but instead Stunna has to pay him 1030 btc lol. It must be a bad day for Stunna and the greatest day for Huff. Smiley

allcoinminer
Hero Member
*****
Offline Offline

Activity: 784
Merit: 504


View Profile
November 02, 2014, 02:53:54 PM
 #16

Hufflepuff crossing 1000 Bitcoin profit on PrimeDice, watched it live and recorded the moment (vid below), so sick.

https://www.youtube.com/watch?v=uALj-u-BvOc&

At the end of the video, Huff has wagered a total of 24290 bitcoin. At 1% edge, Stunna was expecting to win 243 btc from him, but instead Stunna has to pay him 1030 btc lol. It must be a bad day for Stunna and the greatest day for Huff. Smiley

Loss to Stunna is not possible.
There might be inner games in this.
Cyrax89721
Sr. Member
****
Offline Offline

Activity: 321
Merit: 250



View Profile
November 02, 2014, 03:06:09 PM
 #17

Figures there'd be techno music backing it.  Roll Eyes
TYT
Member
**
Offline Offline

Activity: 78
Merit: 10


View Profile
November 02, 2014, 03:53:07 PM
 #18

He won 1000 bitcoins in one session or is that the total he's up?

Figures there'd be techno music backing it.  Roll Eyes

Lol, what did you expect? Death metal?
rammy2k2
Legendary
*
Offline Offline

Activity: 1974
Merit: 1003



View Profile
November 02, 2014, 04:00:40 PM
 #19

well played sir  Cool
kantongajaib
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
November 02, 2014, 04:07:43 PM
 #20

it's just a number

you can also do it  Grin
Pages: [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!