Bitcoin Forum
April 26, 2024, 06:54:03 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 ... 71 »
  Print  
Author Topic: BTER.com hacked| 7170 BTC stolen | DON'T KEEP YOUR MONEY ON AN EXCHANGE |  (Read 119637 times)
stdset
Hero Member
*****
Offline Offline

Activity: 572
Merit: 506



View Profile
February 16, 2015, 10:41:37 AM
 #141

As I said earlier, I had problems withdrawing bitcoins two days prior the hack (had to wait for two hours until my withdrawal request got finally processed), so it may well mean that their cold storage turned into hot wallet... Roll Eyes
There were no outgoing transactions from 1M2bv around Feb 12th.
Edit: Could you check your incoming transaction, where from the funds were sent?

I'm afraid not, at least right now, since I had been transferring funds from Bter to Bittrex, and there I can only see the date and sum of the deposit (and it was on the 14th actually, 12:13:55 AM, I just checked). If you give me an address of some blockchain explorer, I would try to find the transaction... Cool

Update: here's the transaction
Your transaction was sent from one of their hot wallet change addresses.

1714114443
Hero Member
*
Offline Offline

Posts: 1714114443

View Profile Personal Message (Offline)

Ignore
1714114443
Reply with quote  #2

1714114443
Report to moderator
1714114443
Hero Member
*
Offline Offline

Posts: 1714114443

View Profile Personal Message (Offline)

Ignore
1714114443
Reply with quote  #2

1714114443
Report to moderator
Transactions must be included in a block to be properly completed. When you send a transaction, it is broadcast to miners. Miners can then optionally include it in their next blocks. Miners will be more inclined to include your transaction if it has a higher transaction fee.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714114443
Hero Member
*
Offline Offline

Posts: 1714114443

View Profile Personal Message (Offline)

Ignore
1714114443
Reply with quote  #2

1714114443
Report to moderator
1714114443
Hero Member
*
Offline Offline

Posts: 1714114443

View Profile Personal Message (Offline)

Ignore
1714114443
Reply with quote  #2

1714114443
Report to moderator
1714114443
Hero Member
*
Offline Offline

Posts: 1714114443

View Profile Personal Message (Offline)

Ignore
1714114443
Reply with quote  #2

1714114443
Report to moderator
deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 10:47:58 AM
 #142

Did anyone try to decipher those cryptic messages in the transactions? Cool

dagi
Sr. Member
****
Offline Offline

Activity: 374
Merit: 250



View Profile WWW
February 16, 2015, 10:55:35 AM
 #143

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?
deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 10:59:56 AM
 #144

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?

Here, though they may be irrelevant (or are from Bter trying to get in touch with the thief himself)... Cool

Also note one of the thief addresses (1Muse5NL7nDPPHVreF2Gkq5wv5XLbC2Qtz)

dagi
Sr. Member
****
Offline Offline

Activity: 374
Merit: 250



View Profile WWW
February 16, 2015, 11:10:23 AM
 #145

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?

Here, though they may be irrelevant... Cool

Also note one of the thief addresses (1Muse5NL7nDPPHVreF2Gkq5wv5XLbC2Qtz)

thx
Muse can be just from random key-address generator
and message .... i don't know ... just someone send message for the theft
deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 11:20:42 AM
 #146

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?

Here, though they may be irrelevant... Cool

Also note one of the thief addresses (1Muse5NL7nDPPHVreF2Gkq5wv5XLbC2Qtz)

thx
Muse can be just from random key-address generator
and message .... i don't know ... just someone send message for the theft

Yes, but it was sent to all 7 (seven) addresses... Bter hand? Cool

dagi
Sr. Member
****
Offline Offline

Activity: 374
Merit: 250



View Profile WWW
February 16, 2015, 11:27:28 AM
 #147

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?

Here, though they may be irrelevant... Cool

Also note one of the thief addresses (1Muse5NL7nDPPHVreF2Gkq5wv5XLbC2Qtz)

thx
Muse can be just from random key-address generator
and message .... i don't know ... just someone send message for the theft

Yes, but it was sent to all 7 (seven) addresses... Bter hand? Cool
probably yes
I can't decode these Chinese characters :-(

deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 11:34:03 AM
 #148

Did anyone try to decipher those cryptic messages in the transactions? Cool
cryptic messages? where?

Here, though they may be irrelevant... Cool

Also note one of the thief addresses (1Muse5NL7nDPPHVreF2Gkq5wv5XLbC2Qtz)

thx
Muse can be just from random key-address generator
and message .... i don't know ... just someone send message for the theft

Yes, but it was sent to all 7 (seven) addresses... Bter hand? Cool
probably yes
I can't decode these Chinese characters :-(

If these symbols represent the message in Chinese, then the recipient should be able to decipher them, which leaves us with an inference that they know (or think to know) who the thief is. Thus more weight to an inside job assumption... Cool

stdset
Hero Member
*****
Offline Offline

Activity: 572
Merit: 506



View Profile
February 16, 2015, 11:35:52 AM
 #149

The hack transaction emptyed not only 1M2bv6sypZSp6uAEC9U4Gzvgp6jd29F87e, but several other addresses too:
1CZ6jGQ9TPBjixtRkNZ21PNR8gQe7YNydE, 13sswj3bpfyFQby1oJbpjCUe18ZxUygKZt, 1Ni8z1MbaF4ri8GGE67BWtLu66YnXj2BuW, 1AeRVukQNG3qhd3i31pwFa7Z8qc6JnkYEs - the first 3 are all change addresses of their cold wallet, but the last one looks strange. There were no outgoing transactions from this address before the hack, only incoming ones, after the hack there were several incoming and outgoing transactions operating mostly with dust outputs.

deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 11:45:00 AM
 #150

The hack transaction emptyed not only 1M2bv6sypZSp6uAEC9U4Gzvgp6jd29F87e, but several other addresses too:
1CZ6jGQ9TPBjixtRkNZ21PNR8gQe7YNydE, 13sswj3bpfyFQby1oJbpjCUe18ZxUygKZt, 1Ni8z1MbaF4ri8GGE67BWtLu66YnXj2BuW, 1AeRVukQNG3qhd3i31pwFa7Z8qc6JnkYEs - the first 3 are all change addresses of their cold wallet, but the last one looks strange. There were no outgoing transactions from this address before the hack, only incoming ones, after the hack there were several incoming and outgoing transactions operating mostly with dust outputs.

Probably, Bter had to pay someone no matter what and what amount (we see escrowed transactions)... Cool

Also, how do you know that these addresses (except for 1M2bv, indeed) belong to Bter at all?

Bitcoin_Mafia_Me
Sr. Member
****
Offline Offline

Activity: 560
Merit: 252

BitcoinerX.com - PM for Ad Info


View Profile WWW
February 16, 2015, 11:59:09 AM
 #151

This stinks. I liked Bter. The daily interest aspect was cool and their support people were always quick to respond
to emails. I really hope that this was a hack and not another mtgox fiasco. Over 7k bitcoin is a LOT of money.

I only had 1.5 BTC on their myself - not a lot compared to most, but it was what I was saving to pay for my kid's
college textbooks next term. Hopefully I'll be able to pick up an extra web dev or SEO gig to cover the loss.

dagi
Sr. Member
****
Offline Offline

Activity: 374
Merit: 250



View Profile WWW
February 16, 2015, 11:59:15 AM
 #152

1CZ6jGQ9TPBjixtRkNZ21PNR8gQe7YNydE, 13sswj3bpfyFQby1oJbpjCUe18ZxUygKZt, 1Ni8z1MbaF4ri8GGE67BWtLu66YnXj2BuW, 1AeRVukQNG3qhd3i31pwFa7Z8qc6JnkYEs
all are bter cold wallet

http://www.walletexplorer.com/wallet/Bter.com-cold?from_address=1CZ6jGQ9TPBjixtRkNZ21PNR8gQe7YNydE
http://www.walletexplorer.com/wallet/Bter.com-cold?from_address=13sswj3bpfyFQby1oJbpjCUe18ZxUygKZt
http://www.walletexplorer.com/wallet/Bter.com-cold?from_address=1Ni8z1MbaF4ri8GGE67BWtLu66YnXj2BuW
http://www.walletexplorer.com/wallet/Bter.com-cold?from_address=1AeRVukQNG3qhd3i31pwFa7Z8qc6JnkYEs
abyrnes81
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500



View Profile
February 16, 2015, 12:01:45 PM
 #153

No  Sad , I lost 3,4 bitcoin. Now what should I do ?
stdset
Hero Member
*****
Offline Offline

Activity: 572
Merit: 506



View Profile
February 16, 2015, 12:02:09 PM
 #154

Probably, Bter had to pay someone no matter what and what amount (we see escrowed transactions)... Cool

Also, how do you know that these addresses (except for 1M2bv, indeed) belong to Bter at all?
The first 3 got their balances in hot wallet replenishing transactions, when bter takes 7 of their standard 15 BTC outputs and sends exactly 100 BTC to their hot wallet, the change minus transaction fee goes to one of those addresses.
The last address, I'm not sure that it belongs to bter, but it's strange to combine your own funds (or funds of two different victims) in a single hack transaction.

Sarthak
Hero Member
*****
Offline Offline

Activity: 518
Merit: 501

Error 404: there seems to be nothing here.


View Profile
February 16, 2015, 12:03:56 PM
 #155

I guess I had 0.002 BTC left to withdraw from there!
RIP 0.002  Cry (Just kidding! But I really have 2 mbtc left there Tongue)
Anyways, I hope the hacker sends back the money and enjoy the bounty!

alexrossi
Legendary
*
Offline Offline

Activity: 3724
Merit: 1739


Join the world-leading crypto sportsbook NOW!


View Profile
February 16, 2015, 12:17:46 PM
 #156

I'm starting to think that bter cold wallet wasn't so cold. Still, in 2015, should an exchange learn in the worst way how to setup a true cold wallet?

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
deisik
Legendary
*
Offline Offline

Activity: 3444
Merit: 1280


English ⬄ Russian Translation Services


View Profile WWW
February 16, 2015, 12:21:01 PM
 #157

Probably, Bter had to pay someone no matter what and what amount (we see escrowed transactions)... Cool

Also, how do you know that these addresses (except for 1M2bv, indeed) belong to Bter at all?
The first 3 got their balances in hot wallet replenishing transactions, when bter takes 7 of their standard 15 BTC outputs and sends exactly 100 BTC to their hot wallet, the change minus transaction fee goes to one of those addresses.
The last address, I'm not sure that it belongs to bter, but it's strange to combine your own funds (or funds of two different victims) in a single hack transaction.

Now this question seems to be cleared (as to whom belongs 1AeRVukQNG3qhd3i31pwFa7Z8qc6JnkYEs). We see that the last transaction from that address was done at 18:19:12, but the cryptic messages to all seven hacker's addresses were sent at 20:17:08 (assuming they were sent by Bter), i.e. 2 hours later. Is it possible that Bter learned about the thievery only after 18:19:12? As far as I remember, the site stopped operating just about that time... Cool

powersup
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250


View Profile
February 16, 2015, 01:01:09 PM
 #158

I'm starting to think that bter cold wallet wasn't so cold. Still, in 2015, should an exchange learn in the worst way how to setup a true cold wallet?

Leading up to the hack the "cold wallet" was online almost daily.  In fact the whole IO from the wallet looks completely automated.  If that was the case perhaps the attacker didn't have direct access to the device holding the cold wallet, but instead a computer which controlled the cold wallet through API commands?

Also does anyone know what the small output associated to the larger output is?  This small value seems to be transferred to a fresh wallet and slowly diminishes over time.  looks like it is in part covering the TX fee.
stdset
Hero Member
*****
Offline Offline

Activity: 572
Merit: 506



View Profile
February 16, 2015, 01:04:25 PM
 #159

Leading up to the hack the "cold wallet" was online almost daily.
What makes you think that it was online almost dayly?

powersup
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250


View Profile
February 16, 2015, 01:11:30 PM
 #160

Leading up to the hack the "cold wallet" was online almost daily.
What makes you think that it was online almost dayly?

Sorry daily was a bit of an exaggeration, but there is a number of outputs from the wallet in January.
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 ... 71 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!