Bitcoin Forum
June 20, 2024, 06:39:06 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Bitaddress.org bug?? private key mismatch  (Read 2259 times)
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
November 27, 2014, 08:59:30 AM
 #21

@ArpFlush could you post an image with the key pair? It is not useful for you, isn't it? I would like to see it by myself.
Sure: (sorry for the upside/down)

fixed that for you:



Edit:

private key: 5KaDTTWPxdwxrFYboxQPJiXgqwua9SULLCvLFEBuGkbeQnSLAoG
results in address: 16obDHVzXx1YevqkAkDyN5Vbqw4V8iauGf
according to brainwallet homepage [1].


[1] https://brainwallet.github.io/

Im not really here, its just your imagination.
ArpFlush (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500


View Profile
November 27, 2014, 09:05:15 AM
 #22

Well then it's serious. What browser do you use?

Any response from the bitaddress team?

They should take down the site until they have identified and solved the error.

ya.ya.yo!

No response yet. I used Chrome on a Win7.

"Panic Selling is not an Investment Strategy"
ArpFlush (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500


View Profile
November 27, 2014, 09:06:49 AM
 #23

fixed that for you:
Edit:

private key: 5KaDTTWPxdwxrFYboxQPJiXgqwua9SULLCvLFEBuGkbeQnSLAoG
results in address: 16obDHVzXx1YevqkAkDyN5Vbqw4V8iauGf
according to brainwallet homepage [1].

[1] https://brainwallet.github.io/
thanks, and your result isthe same as mine  Wink

"Panic Selling is not an Investment Strategy"
pointbiz
Sr. Member
****
Offline Offline

Activity: 437
Merit: 415

1ninja


View Profile
November 27, 2014, 01:09:51 PM
 #24

I just dropped by to say I've read this thread.

The code has been around a long time and no one has made this type of claim. The code has unit tests to ensure accuracy. Also, in testing we have used the bulk wallet in the past to generate 10,000+ addresses and tested them against other bitcoin software to ensure only good matching pairs are being generated.

Even in this claim the generated address and private key match because the address is passed into the function that creates the QR code for the bitcoin address. Meaning the complex bitcoin part of the code worked fine. So, the behavior that is claimed to be affected would be the simple code that is updating the HTML.

As a sanity check I would ask the OP to run the unit tests by placing a query string at the end of the page, please do this with the offline version you presumably downloaded.
https://www.bitaddress.org/bitaddress.org-v2.9.3-SHA1-7d47ab312789b7b3c1792e4abdb8f2d95b726d64.html?unittests=true

OP was your browser or system misbehaving in any way you could detect? Was your system low on memory or anything that might shed light on this? My questions are just speculatings.

At this moment it seems more plausible you have encountered some new malware. Easier for malware to change the text in the HTML then to swap out the QR code. PLUS the wrong bitcoin address shown in your screenshot has money on it meaning that someone else controls that key. If this were a legitimate code failure it would not produce an existing bitcoin address because a collision like that is theoretically impossible.

Coder of: https://www.bitaddress.org      Thread
Open Source JavaScript Client-Side Bitcoin Wallet Generator
Donations: 1NiNja1bUmhSoTXozBRBEtR8LeF9TGbZBN   PGP
pointbiz
Sr. Member
****
Offline Offline

Activity: 437
Merit: 415

1ninja


View Profile
November 27, 2014, 01:10:34 PM
 #25

Another question to OP. Did you check the SHA1?

Coder of: https://www.bitaddress.org      Thread
Open Source JavaScript Client-Side Bitcoin Wallet Generator
Donations: 1NiNja1bUmhSoTXozBRBEtR8LeF9TGbZBN   PGP
DannyHamilton
Legendary
*
Offline Offline

Activity: 3430
Merit: 4669



View Profile
November 27, 2014, 01:52:08 PM
Last edit: November 27, 2014, 02:07:18 PM by DannyHamilton
 #26

Remember way back in the beginning of this thread when I said that it was far more likely that you have malware on your computer that changed the bitcoin address?

Guess what.

I did about 3 seconds of research with a Google search now that you finally posted the address, and it seems pretty clear that you have malware on your computer that changed the bitcoin address:

*** MALWARE WARNING ***

We want to inform you a MALWARE about dangerous TheTrollBox Chrome Extensions at https://bitcointalk.org/index.php?topic=424686.0
http://pastie.org/pastes/9096889
http://www.reddit.com/r/dogecoin/comments/23jr02/google_chrome_extension_live_ticker_steals_your/

Please be careful and do not use this chrome extension.
It replaces addresses with his own addresses to steal your money.
One of our members lost 1 BTC.

Please retweet to help inform more people about TheTrollBox Chrome Extensions.
https://twitter.com/Coinano/status/458184780069494784

Kind Regards.

If anyone is interested, here are the BTC addresses and various other altcoin addresses in this browser extension that they are stealing BTC to:
- snip -
"1CoEtBCwmy6BBCka1mxYieX7dtkwLSy88F",
- snip -

Security Inform
Quote
- snip -
1CoEtBCwmy6BBCka1mxYieX7dtkwLSy88F is one of the receiving addresses replaced by this malicious extension
- snip -
lontivero
Full Member
***
Offline Offline

Activity: 164
Merit: 128

Amazing times are coming


View Profile
November 27, 2014, 01:59:08 PM
 #27

Remember way back in the beginning of this thread when I said that it was far more likely that you have malware on your computer that changed the bitcoin address?

Guess what.

I did about 3 seconds of research with a Google search now that you finally posted the address, and it seems pretty clear that you have malware on your computer that changed the bitcoin address:

*** MALWARE WARNING ***

We want to inform you a MALWARE about dangerous TheTrollBox Chrome Extensions at https://bitcointalk.org/index.php?topic=424686.0
http://pastie.org/pastes/9096889
http://www.reddit.com/r/dogecoin/comments/23jr02/google_chrome_extension_live_ticker_steals_your/

Please be careful and do not use this chrome extension.
It replaces addresses with his own addresses to steal your money.
One of our members lost 1 BTC.

Please retweet to help inform more people about TheTrollBox Chrome Extensions.
https://twitter.com/Coinano/status/458184780069494784

Kind Regards.

If anyone is interested, here are the BTC addresses and various other altcoin addresses in this browser extension that they are stealing BTC to:
- snip -
"1CoEtBCwmy6BBCka1mxYieX7dtkwLSy88F",
- snip -

Security Inform
Quote
- snip -
1CoEtBCwmy6BBCka1mxYieX7dtkwLSy88F is one of the receiving addresses replaced by this malicious extension
- snip -

Yes, thats the address! Good catch.
Chrome extensions are a big security problem, no just for bitcoins. 
ArpFlush (OP)
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500


View Profile
November 28, 2014, 10:28:20 AM
Last edit: November 29, 2014, 08:31:42 PM by ArpFlush
 #28

Wow, I didn't know this existed. It's not on my Chrome now (unless I installed & unstalled it months ago).
Antivirus check = negative, but as usual there were some trackers and stuff (that I deleted too)

Thanks for the update!

Edit: So I think this problem is solved. Bitaddress.org is safe to use  Wink

"Panic Selling is not an Investment Strategy"
yayayo
Legendary
*
Offline Offline

Activity: 1806
Merit: 1024



View Profile
November 29, 2014, 06:22:27 PM
 #29

Remember way back in the beginning of this thread when I said that it was far more likely that you have malware on your computer that changed the bitcoin address?

Guess what.

I did about 3 seconds of research with a Google search now that you finally posted the address, and it seems pretty clear that you have malware on your computer that changed the bitcoin address:

Thank you for resolving this!

Good to know that bitaddress.org is free of errors.

However it is disturbing to see all these kinds of malware targeting Bitcoin-related services... it makes you feel unsafe executing any script... Well at least the criminals agree, that Bitcoin has value... Wink

ya.ya.yo!

.
..1xBit.com   Super Six..
▄█████████████▄
████████████▀▀▀
█████████████▄
█████████▌▀████
██████████  ▀██
██████████▌   ▀
████████████▄▄
███████████████
███████████████
███████████████
███████████████
███████████████
▀██████████████
███████████████
█████████████▀
█████▀▀       
███▀ ▄███     ▄
██▄▄████▌    ▄█
████████       
████████▌     
█████████    ▐█
██████████   ▐█
███████▀▀   ▄██
███▀   ▄▄▄█████
███ ▄██████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████████
███████████▀▀▀█
██████████     
███████████▄▄▄█
███████████████
███████████████
███████████████
███████████████
███████████████
         ▄█████
        ▄██████
       ▄███████
      ▄████████
     ▄█████████
    ▄███████
   ▄███████████
  ▄████████████
 ▄█████████████
▄██████████████
  ▀▀███████████
      ▀▀███
████
          ▀▀
          ▄▄██▌
      ▄▄███████
     █████████▀

 ▄██▄▄▀▀██▀▀
▄██████     ▄▄▄
███████   ▄█▄ ▄
▀██████   █  ▀█
 ▀▀▀
    ▀▄▄█▀
▄▄█████▄    ▀▀▀
 ▀████████
   ▀█████▀ ████
      ▀▀▀ █████
          █████
       ▄  █▄▄ █ ▄
     ▀▄██▀▀▀▀▀▀▀▀
      ▀ ▄▄█████▄█▄▄
    ▄ ▄███▀    ▀▀ ▀▀▄
  ▄██▄███▄ ▀▀▀▀▄  ▄▄
  ▄████████▄▄▄▄▄█▄▄▄██
 ████████████▀▀    █ ▐█
██████████████▄ ▄▄▀██▄██
 ▐██████████████    ▄███
  ████▀████████████▄███▀
  ▀█▀  ▐█████████████▀
       ▐████████████▀
       ▀█████▀▀▀ █▀
.
Premier League
LaLiga
Serie A
.
Bundesliga
Ligue 1
Primeira Liga
.
..TAKE PART..
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!