Author

Topic: An automated attack on MtGox BTC deposits? (Read 1215 times)

newbie
Activity: 15
Merit: 0
October 19, 2013, 05:40:37 PM
#8
How do people send btc without a transaction fee?

Ive always wondered that question..

I use Bitcoin Armory and its quite simple - just set it to 0:

https://i.imgur.com/NGbONsg.png

the text is from help (blue questionmark).

I guess its even simpler programmatically ...
hero member
Activity: 798
Merit: 531
Crypto is King.
October 19, 2013, 05:35:26 PM
#7
... could only do it after seeing your transaction in the blockchain or memory pool.

So attack like this can be done by a mining pool?

My transaction is visible in memory pool, so the attacker creates satoshi-sized transaction and puts it in block whilst putting mine on backburner ...
If that block is then "solved" they have their transaction before mine.

I still don't know why someone would do it - maybe only for the lolz ... :?

But I also accept Foxpops answer as quite possible - it certainly explains why they go after addresses that have more than 100 BTC in them.
Just PM the owner of Just Dice and ask him if his automated advertisement program sent a Satoshi to your wallet.
newbie
Activity: 15
Merit: 0
October 19, 2013, 05:31:13 PM
#6
... could only do it after seeing your transaction in the blockchain or memory pool.

So attack like this can be done by a mining pool?

My transaction is visible in memory pool, so the attacker creates satoshi-sized transaction and puts it in block whilst putting mine on backburner ...
If that block is then "solved" they have their transaction before mine.

I still don't know why someone would do it - maybe only for the lolz ... :?

But I also accept Foxpops answer as quite possible - it certainly explains why they go after addresses that have more than 100 BTC in them.
legendary
Activity: 2072
Merit: 1049
┴puoʎǝq ʞool┴
October 19, 2013, 07:30:02 AM
#5
How do people send btc without a transaction fee?

Ive always wondered that question..
legendary
Activity: 1974
Merit: 1030
October 19, 2013, 07:03:01 AM
#4
Now, its not a problem for me, but it may be if the deposit address was at MtGox since they give you single usage address.
If that 0.00000001 comes to MtGox before my transaction, my funds get stuck in a limbo and don't get to my account - I'm the one that should contact MtGox support to clear this and a lot of non-needed work is done.

That couldn't happen since the address you're sending funds to isn't known to anyone except mtgox and you. Whoever send that satoshi could only do it after seeing your transaction in the blockchain or memory pool.
legendary
Activity: 4542
Merit: 3393
Vile Vixen and Miss Bitcointalk 2021-2023
October 19, 2013, 04:43:05 AM
#3
It's got nothing to do with Mt. Gox specifically. LetsDice periodically scans the blockchain for new addresses and send a satoshi to them as advertising (at least, I assume that's why they're doing it, otherwise I have no idea). They don't even have the courtesy to pay a decent transaction fee.
sr. member
Activity: 367
Merit: 250
Find me at Bitrated
October 19, 2013, 04:25:46 AM
#2
10 bitcoins says that the 0.00000001 would never arrive before the transaction, and it is only being added to your account by a watcher program that is attempting to keep track of what goes into the exchange.  Whether it is benign or malicious is difficult to say.
newbie
Activity: 15
Merit: 0
October 19, 2013, 03:59:47 AM
#1
A strange thing just happened.

I've executed a transaction of BTC to an exchange account (not MtGox)
https://blockchain.info/tx/447fcc52f767975c92df78352b844b19a17bad2c34e41992548dc469aa75ecc7

but then a couple of minutes later another transaction with 0.00000001 BTC to the same deposit address was executed (seemingly from letsdice?)
https://blockchain.info/tx/4d00f3f4fa64b061c794f3ea5463eeb8ecf84be64bed86fc318327e042719c98

Now, its not a problem for me, but it may be if the deposit address was at MtGox since they give you single usage address.
If that 0.00000001 comes to MtGox before my transaction, my funds get stuck in a limbo and don't get to my account - I'm the one that should contact MtGox support to clear this and a lot of non-needed work is done.

Its a simple automated DoS attack ...

Another scenario is that someone is tagging large transactions - if you look at other addresses with 0.00000001 transaction these are all some large transactions before it.

Thougts?
Jump to: