jwzguy
|
|
July 31, 2012, 02:21:27 AM |
|
While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?
Major doesn't mean secure. BTC-e always looked sketchy as hell to me.
|
|
|
|
DeathAndTaxes
Donator
Legendary
Offline
Activity: 1218
Merit: 1079
Gerald Davis
|
|
July 31, 2012, 02:21:53 AM |
|
I understand all that. What I was saying is that simply putting 50000 in the BTC balance box doesn't mean there is actually 500000 BTC there.
Well obviously the attacker can only withdraw the max in the hot wallet (or any per day limit unless compromised). That limit is the same regardless of if the attacker "fakes" BTC or "faked" USD to build up his BTC balance. Say the hot wallet only had 10,000 BTC (hopefully it had a lot less) and the hacker was able to compromise the withdraw limit (by using multiple accounts). "fake" 50,000 BTC you can only withdraw 10,000 BTC "fake" $1M USD and buy 50,000 BTC you can still only withdraw 10,000 BTC. Once the hot wallet is empty the hacker is "maxed out" regardless of what tricks he pulls. Unless BTC-E is very stupid incoming deposits should go to the COLD WALLET thus not increase the amount stolen.
|
|
|
|
hazek
Legendary
Offline
Activity: 1078
Merit: 1003
|
|
July 31, 2012, 02:22:41 AM |
|
They wouldn't be able to withdraw any USD since it's fake. Saying you have 500000 fake BTC on BTC-e doesn't mean anything if you don't actually have the keys to those coins in an actual wallet. They used fake USD to buy real BTC then ride off into the sunset laughing.
Dude. All exchanges use a pooled wallet. There is no such things "your" BTC or "your BTC" wallet on BTC-E, MtGox or any other exchange. The exchange simply has one (or more) hot and/or cold wallets. Then they maintain a database of each user's balance, and trades change those balance. One could withdraw "fake" BTC just as easily as selling "fake" USD for BTC and withdrawing that. The likely reason for faking USD is simply because that is the exploit the hacker founds. Hacker found a way to add USD to his USD balance. Once had had that why try hacking any further. Give yourself huge amounts of USD, buy BTC and remove them from the exchange. If it was a SQL injection (extremely likely), it should have been just as easy to add BTC. I suspect the hacker may be intentionally messing with the exchange. New theory: hacker emptied the BTC-e BTC wallet first and all that's happening now is him having some fun with the other users..
|
My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)
If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
|
|
|
DeathAndTaxes
Donator
Legendary
Offline
Activity: 1218
Merit: 1079
Gerald Davis
|
|
July 31, 2012, 02:22:58 AM |
|
While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?
No. Any "faking" of USD or BTC would be on BTC-E books. The bad news is that the victims are now left with more coins & dollars on the books (BTC-e internal books) than actual coins. No amount of hacking can produce BTC from nothing. The attacker merely transfered the real wealth of victims with fake balances on BTC-e books. The "good news" is hopefully BTC-e wasn't totally stupid and after Bitcoinica reduced the size of their hot wallet. If the attacker cleaned out the hot wallet then the % that users will lose is the % that the hot wallet makes up of total funds. Example (numbers out of my ass): Say prior to the hack BTC-e had 5,000 BTC in hot wallet 50,000 BTC in cold wallet (plus all new deposit going directly to cold wallet) 50,000 BTC equivelent in USD. The 5,000 BTC may be gone but victims should still get $0.90 on the dollar of their combined BTC/USD balances. Now if BTC-e ran one giant hot wallet with all incoming deposits going directly into the hot wallet then victims may have lost everything.
|
|
|
|
BkkCoins
|
|
July 31, 2012, 02:24:05 AM |
|
Only 36 BTC left. Game over soon... who's selling the last 5 BTC @ 99 each?
Maybe they don't have a COLD wallet. Maybe any amount of BTC you can buy in your account can be transferred out immediately. Maybe later today we'll hear that everyone who sold their BTC for super high was in fact giving them away because there are no USD anywhere to be found.
|
|
|
|
Aggro
Donator
Sr. Member
Offline
Activity: 296
Merit: 250
|
|
July 31, 2012, 02:27:37 AM |
|
This is probably not good news, but check on the spike on the picture, and the timing of it: Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening.
|
|
|
|
JoelKatz
Legendary
Offline
Activity: 1596
Merit: 1012
Democracy is vulnerable to a 51% attack.
|
|
July 31, 2012, 02:29:17 AM |
|
New theory: hacker emptied the BTC-e BTC wallet first and all that's happening now is him having some fun with the other users..
Close. He's using the high price to induce others to refill it with real BTC deposits.
|
I am an employee of Ripple. Follow me on Twitter @JoelKatz 1Joe1Katzci1rFcsr9HH7SLuHVnDy2aihZ BM-NBM3FRExVJSJJamV9ccgyWvQfratUHgN
|
|
|
bitcool
Legendary
Offline
Activity: 1441
Merit: 1000
Live and enjoy experiments
|
|
July 31, 2012, 02:31:48 AM |
|
While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?
No. Any "faking" of USD or BTC would be on BTC-E books. The bad news is that the victims are now left with more coins on the books (BTC-e internal books) than actual coins. No amount of hacking can produce BTC from nothing. book entries vs cash on hand. Ironically over there at btc-e, because too much fake usd was injected into the system, no one wants dollar and everybody try to get some BTC or LTC. It's what to come in the future. btc-e is just ahead of us.
|
|
|
|
ydenys
Member
Offline
Activity: 96
Merit: 10
|
|
July 31, 2012, 02:32:26 AM |
|
While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?
No. Any "faking" of USD or BTC would be on BTC-E books. The bad news is that the victims are now left with more coins on the books (BTC-e internal books) than actual coins. No amount of hacking can produce BTC from nothing. Yep, thanks D&T, i was worried there for a while – late hour here, wine. So, basically, both owner's and user's accounts were promptly emptied by the hackers, and then some remaining users emptied each other's accounts out of pure greed, plus all who was awake withdrew all funds. No more BTC-e. I guess their withdrawal limits were too high then.
|
|
|
|
|
bitcool
Legendary
Offline
Activity: 1441
Merit: 1000
Live and enjoy experiments
|
|
July 31, 2012, 02:33:17 AM |
|
This is probably not good news, but check on the spike on the picture, and the timing of it: Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening. Not really. I was able to withdraw from btce many minutes after the price spiked to 40s.
|
|
|
|
dree12
Legendary
Offline
Activity: 1246
Merit: 1078
|
|
July 31, 2012, 02:35:39 AM |
|
Assuming the chat image pasted earlier was the real hacker comments, then the entire database is going to get purged. So if BTC-e didn't back up regularly, this is going to burn a ton of people.
They are probably not. I believe this was a SQL injection. There are a few telltale signs: - The event was sudden.
- The hacking was weak. If the hacker had access to the server, they may be able to empty the hot wallet directly. Instead, the hacker had to rely on BTC-E withdrawal.
- The hacking seemed to involve a simple UPDATE of the USD value.
|
|
|
|
Shadow383
|
|
July 31, 2012, 02:36:06 AM |
|
This is probably not good news, but check on the spike on the picture, and the timing of it: Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening. Not really. I was able to withdraw from btce many minutes after the price spiked to 40s. Suggesting that they probably don't have cold storage in place - sounds an awful lot like the maximum amount that can be withdrawn is everything on the exchange. Are people still getting BTC out? Does anyone there even still have any?
|
|
|
|
BkkCoins
|
|
July 31, 2012, 02:37:22 AM |
|
Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly. Anyone know who to call to wake them up and freeze the exchange?
|
|
|
|
dree12
Legendary
Offline
Activity: 1246
Merit: 1078
|
|
July 31, 2012, 02:37:56 AM |
|
Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly. Anyone know who to call to wake them up and freeze the exchange?
It is 6:37 in Moscow.
|
|
|
|
Herodes
|
|
July 31, 2012, 02:42:25 AM |
|
Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly. Anyone know who to call to wake them up and freeze the exchange?
It is 6:37 in Moscow. Time for the first vodka of the day then !
|
|
|
|
Bitcoin Oz
|
|
July 31, 2012, 02:43:17 AM |
|
The hacker injected fake usd ? My money is on Ben Bernanke.
|
|
|
|
terrytibbs
|
|
July 31, 2012, 02:45:01 AM |
|
The hacker injected fake usd ? My money is on Ben Bernanke.
...or his Russian doppelgänger.
|
|
|
|
TTBit
Legendary
Offline
Activity: 1137
Merit: 1001
|
|
July 31, 2012, 02:45:28 AM |
|
No, that is first few. Waiting for some confirms. 1 confirm on the withdraws. Still 20 bid for 13.45, but able to sleep now.
|
good judgment comes from experience, and experience comes from bad judgment
|
|
|
ThiagoCMC
Legendary
Offline
Activity: 1204
Merit: 1000
฿itcoin: Currency of Resistance!
|
|
July 31, 2012, 02:46:59 AM |
|
OMG... I had 180 Bitcoins there... Jesus...
My latest withdraw at btc-e webpage says "confirmed", but nothing reached my wallet yet.
40 Bitcoins was "sold" there... And 140 Bitcoins are stucked at some point there... In Russia... Damn!
Jesus no, please no... Please... no... Oh God... lol My documentation: https://bitcointalk.org/index.php?topic=40889.msg1066779#msg1066779I have screenshots... To remember... Damn... :-/
|
|
|
|
|