Bitcoin Forum
November 19, 2024, 03:47:54 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 [6] 7 8 9 10 11 12 13 14 15 16 17 18 19 20 »  All
  Print  
Author Topic: BTC-E.COM NICE RECOVERY FROM THE HACK! =)  (Read 51047 times)
jwzguy
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1002



View Profile
July 31, 2012, 02:21:27 AM
 #101

While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?
Major doesn't mean secure. BTC-e always looked sketchy as hell to me.
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
July 31, 2012, 02:21:53 AM
 #102

I understand all that. What I was saying is that simply putting 50000 in the BTC balance box doesn't mean there is actually 500000 BTC there.

Well obviously the attacker can only withdraw the max in the hot wallet (or any per day limit unless compromised). 
That limit is the same regardless of if the attacker "fakes" BTC or "faked" USD to build up his BTC balance.

Say the hot wallet only had 10,000 BTC (hopefully it had a lot less) and the hacker was able to compromise the withdraw limit (by using multiple accounts).

"fake" 50,000 BTC you can only withdraw 10,000 BTC
"fake" $1M USD and buy 50,000 BTC you can still only withdraw 10,000 BTC.

Once the hot wallet is empty the hacker is "maxed out" regardless of what tricks he pulls.

Unless BTC-E is very stupid incoming deposits should go to the COLD WALLET thus not increase the amount stolen.

hazek
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003


View Profile
July 31, 2012, 02:22:41 AM
 #103

They wouldn't be able to withdraw any USD since it's fake. Saying you have 500000 fake BTC on BTC-e doesn't mean anything if you don't actually have the keys to those coins in an actual wallet. They used fake USD to buy real BTC then ride off into the sunset laughing.

Dude.  All exchanges use a pooled wallet.  There is no such things "your" BTC or "your BTC" wallet on BTC-E, MtGox or any other exchange.  The exchange simply has one (or more) hot and/or cold wallets.  Then they maintain a database of each user's balance, and trades change those balance.     One could withdraw "fake" BTC just as easily as selling "fake" USD for BTC and withdrawing that.

The likely reason for faking USD is simply because that is the exploit the hacker founds.  Hacker found a way to add USD to his USD balance.  Once had had that why try hacking any further.  Give yourself huge amounts of USD, buy BTC and remove them from the exchange.
If it was a SQL injection (extremely likely), it should have been just as easy to add BTC. I suspect the hacker may be intentionally messing with the exchange.

New theory: hacker emptied the BTC-e BTC wallet first and all that's happening now is him having some fun with the other users..

My personality type: INTJ - please forgive my weaknesses (Not naturally in tune with others feelings; may be insensitive at times, tend to respond to conflict with logic and reason, tend to believe I'm always right)

If however you enjoyed my post: 15j781DjuJeVsZgYbDVt2NZsGrWKRWFHpp
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
July 31, 2012, 02:22:58 AM
 #104

While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?

No.  Any "faking" of USD or BTC would be on BTC-E books.  The bad news is that the victims are now left with more coins & dollars on the books (BTC-e internal books) than actual coins.  No amount of hacking can produce BTC from nothing.  The attacker merely transfered the real wealth of victims with fake balances on BTC-e books.


The "good news" is hopefully BTC-e wasn't totally stupid and after Bitcoinica reduced the size of their hot wallet.   If the attacker cleaned out the hot wallet then the % that users will lose is the % that the hot wallet makes up of total funds. 

Example (numbers out of my ass):

Say prior to the hack BTC-e had
5,000 BTC in hot wallet
50,000 BTC in cold wallet (plus all new deposit going directly to cold wallet)
50,000 BTC equivelent in USD.

The 5,000 BTC may be gone but victims should still get $0.90 on the dollar of their combined BTC/USD balances.  Now if BTC-e ran one giant hot wallet with all incoming deposits going directly into the hot wallet then victims may have lost everything.


BkkCoins
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1009


firstbits:1MinerQ


View Profile WWW
July 31, 2012, 02:24:05 AM
 #105

Only 36 BTC left. Game over soon... who's selling the last 5 BTC @ 99 each?

Maybe they don't have a COLD wallet. Maybe any amount of BTC you can buy in your account can be transferred out immediately. Maybe later today we'll hear that everyone who sold their BTC for super high was in fact giving them away because there are no USD anywhere to be found.

Aggro
Donator
Sr. Member
*
Offline Offline

Activity: 296
Merit: 250



View Profile
July 31, 2012, 02:27:37 AM
 #106

This is probably not good news, but check on the spike on the picture, and the timing of it:



Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening.
JoelKatz
Legendary
*
Offline Offline

Activity: 1596
Merit: 1012


Democracy is vulnerable to a 51% attack.


View Profile WWW
July 31, 2012, 02:29:17 AM
 #107

New theory: hacker emptied the BTC-e BTC wallet first and all that's happening now is him having some fun with the other users..
Close. He's using the high price to induce others to refill it with real BTC deposits.

I am an employee of Ripple. Follow me on Twitter @JoelKatz
1Joe1Katzci1rFcsr9HH7SLuHVnDy2aihZ BM-NBM3FRExVJSJJamV9ccgyWvQfratUHgN
bitcool
Legendary
*
Offline Offline

Activity: 1441
Merit: 1000

Live and enjoy experiments


View Profile
July 31, 2012, 02:31:48 AM
 #108

While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?

No.  Any "faking" of USD or BTC would be on BTC-E books.  The bad news is that the victims are now left with more coins on the books (BTC-e internal books) than actual coins.  No amount of hacking can produce BTC from nothing.
book entries vs cash on hand.

Ironically over there at btc-e, because too much fake usd was injected into the system, no one wants dollar and everybody try to get some BTC or LTC. It's what to come in the future.

btc-e is just ahead of us.
ydenys
Member
**
Offline Offline

Activity: 96
Merit: 10


View Profile
July 31, 2012, 02:32:26 AM
 #109

While mildly exiting, it is actually no fun. Are you, guys, saying that someone can ‘inject’ fake btc into major exchange/service provider, then exchange between the currencies/withdraw and the surplus of the coins would be recorded into the blockchain?

No.  Any "faking" of USD or BTC would be on BTC-E books.  The bad news is that the victims are now left with more coins on the books (BTC-e internal books) than actual coins.  No amount of hacking can produce BTC from nothing.

Yep, thanks D&T, i was worried there for a while – late hour here, wine. So, basically, both owner's and user's accounts were promptly emptied by the hackers, and then some remaining users emptied each other's accounts out of pure greed, plus all who was awake withdrew all funds. No more BTC-e.

I guess their withdrawal limits were too high then.
EnergyVampire
Full Member
***
Offline Offline

Activity: 210
Merit: 100



View Profile
July 31, 2012, 02:33:11 AM
 #110

Assuming the chat image pasted earlier was the real hacker comments, then the entire database is going to get purged. So if BTC-e didn't back up regularly, this is going to burn a ton of people.

Edit: this post of the comments: https://bitcointalk.org/index.php?topic=96802.msg1066651#msg1066651

bitcool
Legendary
*
Offline Offline

Activity: 1441
Merit: 1000

Live and enjoy experiments


View Profile
July 31, 2012, 02:33:17 AM
 #111

This is probably not good news, but check on the spike on the picture, and the timing of it:



Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening.
Not really. I was able to withdraw from btce many minutes after the price spiked to 40s.
dree12
Legendary
*
Offline Offline

Activity: 1246
Merit: 1078



View Profile
July 31, 2012, 02:35:39 AM
 #112

Assuming the chat image pasted earlier was the real hacker comments, then the entire database is going to get purged. So if BTC-e didn't back up regularly, this is going to burn a ton of people.
They are probably not.

I believe this was a SQL injection. There are a few telltale signs:

  • The event was sudden.
  • The hacking was weak. If the hacker had access to the server, they may be able to empty the hot wallet directly. Instead, the hacker had to rely on BTC-E withdrawal.
  • The hacking seemed to involve a simple UPDATE of the USD value.
Shadow383
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250


View Profile
July 31, 2012, 02:36:06 AM
 #113

This is probably not good news, but check on the spike on the picture, and the timing of it:



Somebody is cleaning house I believe. I think those trying to deposit and speculate are in for a rude awakening.
Not really. I was able to withdraw from btce many minutes after the price spiked to 40s.
Suggesting that they probably don't have cold storage in place - sounds an awful lot like the maximum amount that can be withdrawn is everything on the exchange.

Are people still getting BTC out?
Does anyone there even still have any?  Cheesy
BkkCoins
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1009


firstbits:1MinerQ


View Profile WWW
July 31, 2012, 02:37:22 AM
 #114

Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly.
Anyone know who to call to wake them up and freeze the exchange?

dree12
Legendary
*
Offline Offline

Activity: 1246
Merit: 1078



View Profile
July 31, 2012, 02:37:56 AM
 #115

Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly.
Anyone know who to call to wake them up and freeze the exchange?
It is 6:37 in Moscow.
Herodes
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
July 31, 2012, 02:42:25 AM
 #116

Hmmm. Let's see. What's the time zone in Russia. I'm guessing about 4AM roughly.
Anyone know who to call to wake them up and freeze the exchange?
It is 6:37 in Moscow.


Time for the first vodka of the day then !  Grin
Bitcoin Oz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Wat


View Profile WWW
July 31, 2012, 02:43:17 AM
 #117

The hacker injected fake usd ? My money is on Ben Bernanke.

terrytibbs
Hero Member
*****
Offline Offline

Activity: 560
Merit: 501



View Profile
July 31, 2012, 02:45:01 AM
 #118

The hacker injected fake usd ? My money is on Ben Bernanke.
...or his Russian doppelgänger.
TTBit
Legendary
*
Offline Offline

Activity: 1137
Merit: 1001


View Profile
July 31, 2012, 02:45:28 AM
 #119

Um... no. 2.18 of it to: 12JGzgb7ezdp5UT4EoJN3Spcn3P8fyyFav
http://blockexplorer.com/address/12JGzgb7ezdp5UT4EoJN3Spcn3P8fyyFav
0BTC
Did you get any out successfully?

No, that is first few. Waiting for some confirms.

1 confirm on the withdraws. Still 20 bid for 13.45, but able to sleep now.

good judgment comes from experience, and experience comes from bad judgment
ThiagoCMC
Legendary
*
Offline Offline

Activity: 1204
Merit: 1000

฿itcoin: Currency of Resistance!


View Profile
July 31, 2012, 02:46:59 AM
 #120

OMG... I had 180 Bitcoins there... Jesus...

My latest withdraw at btc-e webpage says "confirmed", but nothing reached my wallet yet.

40 Bitcoins was "sold" there... And 140 Bitcoins are stucked at some point there... In Russia... Damn!

Jesus no, please no...

Please... no... Oh God...  lol

My documentation:

https://bitcointalk.org/index.php?topic=40889.msg1066779#msg1066779

I have screenshots... To remember...  Damn...  :-/
Pages: « 1 2 3 4 5 [6] 7 8 9 10 11 12 13 14 15 16 17 18 19 20 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!