Status updateIn last 7 days there were
two reported issues of customer visiting .com and receiving
non ChipMixer deposit address. In both cases - after deposit transaction deposit address displayed in browser changed into ChipMixer deposit address.
In last 7 days there were
three reported issues of customer visiting .com and depositing to ChipMixer deposit address. After deposit .com timeouts and when it starts working again all chips are already sweeped.
Both issues are being investigated. Please be aware of issues and if possible with your privacy plan keep documenting interaction with our service (ie. check SSL certificate, do and keep screenshots).
Nope, I can only see one deposit made on the deposit address i.e. the funds I sent. Also, only one sweeping transaction was made i.e. with the chips equivalent to my deposit less fees. I can't see the other deposit/withdrawal you are talking about.
Could you send an e-mail to
[email protected] to avoid discussing addresses and txid in public? After your post there was only one support email about this issue and there were two deposits with that case.
By the way, I noticed one thing - the browser cookie was changing whenever I was refreshing the session page. I am talking about this one:
It has to remain same unless I close my browser session, isn't it?
Refreshing session page should not change cookie.
It maybe changing due to the use of VPN. Can this be the reason someone else got hold of my session? Does this cookie has any direct relation with session token? Is it possible that my session token got mingled with another user on site and both of us were shown same session?
When you access .com website with correct SSL - your headers are encrypted and only you and .com server can see that. Cookie has relation with session token. It is unlikely to share session with other user in this case.
The case still needs answers. @Chipmixer, do you want me to send e-mail with more extensive information like the txid I sent, etc? I need to get to the end of what actually happened because I regularly use Chipmixer and this is my common setup (VPN+browser+clearnet). It never happened before and I don't want this to happen again.
Please do send us as much information as you are willing to. Including VPN provider.
What do you think about giving the user a signed letter with the deposit address so they can confirm nothing went wrong?
This idea was discussed in 2019:
With your proposal ChipMixer signs letter that contains address. User say they did not receive chips. They publish signed letter that address is ChipMixer address. ChipMixer says they released chips. Who is lying? Nobody knows - only known thing is that it was ChipMixer address and funds were deposited. User cannot prove they did not receive chips. ChipMixer cannot prove they released chips. What kind of guarantee is that?
We could do it anyway to provide integrity of server response ie. nobody switched deposit address but it would force users to check another thing (and they would not do that every time) and server response integrity is already guaranteed with SSL.