Bitcoin Forum
May 13, 2024, 11:26:09 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: The issue of BC.i was not only the repeated-R (others may have the same issue)  (Read 1110 times)
bithernet (OP)
Hero Member
*****
Offline Offline

Activity: 661
Merit: 503

A simple and secure Bitcoin wallet!


View Profile WWW
December 13, 2014, 04:12:33 AM
Last edit: December 20, 2014, 01:24:45 PM by bithernet
 #1

The issue of blockchain.info (Dec. 8th) was not only the repeated-R. Although it showed out as repeated-R, and people could analyze repeated r values to find out the vulnerable addresses.

Since the day before yesterday, Bitcoin users in China asked our team about blockchain.info's problem.
So we started digging into the issue and found out:
It was not only the repeated-R, and there were more users affected by this event.

Some bitcoins on these vulnerable addresses that we found were collected to here: 1PGfLgFtRHgdgvPNvmHMjtsWwF4fyG1jvh

Currently we are continuing to evaluate the consequences.
After we finish all analysis, we will post more details here and try to return these bitcoins to correct users.

Johoe did a great job for saving peoples bitcoins. But we should notice more BC.i users, because we found out that "1xy......"/"1aa......" are still collecting repeated-r bitcoins.

UPDATE 20141220:
send bitcoins to blockchain.info Contact Blockchain Support:
Address : https://blockchain.info/address/1PLn3ru1n7wERPP1BLVV9oAEGGuXUP1eoC
Transaction : https://blockchain.info/tx/540c6fb44bb6f008260b88b104bbb1f577d81b79a4393837179b2290a67f4b3d

http://Bither.net
Bither - a simple and secure Bitcoin wallet!
1BsTwoMaX3aYx9Nc8GdgHZzzAGmG669bC3
1715642769
Hero Member
*
Offline Offline

Posts: 1715642769

View Profile Personal Message (Offline)

Ignore
1715642769
Reply with quote  #2

1715642769
Report to moderator
1715642769
Hero Member
*
Offline Offline

Posts: 1715642769

View Profile Personal Message (Offline)

Ignore
1715642769
Reply with quote  #2

1715642769
Report to moderator
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715642769
Hero Member
*
Offline Offline

Posts: 1715642769

View Profile Personal Message (Offline)

Ignore
1715642769
Reply with quote  #2

1715642769
Report to moderator
bithernet (OP)
Hero Member
*****
Offline Offline

Activity: 661
Merit: 503

A simple and secure Bitcoin wallet!


View Profile WWW
December 15, 2014, 06:32:57 AM
 #2

There are other vulnerable addresses related to this issue. It seems not only the blockchain.info but also other online wallet services are affected (although their users are much fewer than BC.i).

We have collected those weak bitcoins to another address : 1824bso2XgKTm7XThA75A2gdMpt3jSxW5M

http://Bither.net
Bither - a simple and secure Bitcoin wallet!
1BsTwoMaX3aYx9Nc8GdgHZzzAGmG669bC3
Fernandez
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
December 15, 2014, 06:35:48 AM
 #3

The issue of blockchain.info (Dec. 8th) was not only the repeated-R. Although it showed out as repeated-R, and people could analyze repeated r values to find out the vulnerable addresses.

------------
------------

But we should notice more BC.i users, because we found out that "1xy......"/"1aa......" are still collecting repeated-r bitcoins.

Says not only repeated R and then proceeds to find the same only Roll Eyes

What is the vulnerability, then?






██████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████▄▄▄███████████████████████
███████████████████████████████████████████████████████████████████████▀▀▀████████████████████████
██████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████





...INTRODUCING WAVES........
...ULTIMATE ASSET/CUSTOM TOKEN BLOCKCHAIN PLATFORM...






bithernet (OP)
Hero Member
*****
Offline Offline

Activity: 661
Merit: 503

A simple and secure Bitcoin wallet!


View Profile WWW
December 15, 2014, 07:18:41 AM
 #4

Says not only repeated R and then proceeds to find the same only Roll Eyes

What is the vulnerability, then?

You can look into the two addresses that we provided for more details.

After all the analysis, we will post more infos here.

http://Bither.net
Bither - a simple and secure Bitcoin wallet!
1BsTwoMaX3aYx9Nc8GdgHZzzAGmG669bC3
bithernet (OP)
Hero Member
*****
Offline Offline

Activity: 661
Merit: 503

A simple and secure Bitcoin wallet!


View Profile WWW
December 15, 2014, 09:24:16 AM
Last edit: December 15, 2014, 01:30:13 PM by bithernet
 #5

Until today, these vulnerable addresses (currently they are not monitored by 1xy/1aa) are still receiving bitcoins. So please tell users (especially miners) to check their wallet ASAP.
Also new txs with problem r-value are still showing.





http://Bither.net
Bither - a simple and secure Bitcoin wallet!
1BsTwoMaX3aYx9Nc8GdgHZzzAGmG669bC3
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!