Pages:
Author

Topic: [ANN] Whirlwind.money | ⚡No Fee⚡ | Ultimate Privacy | Anonymity Mining 12% APR🔥 - page 36. (Read 12789 times)

legendary
Activity: 2268
Merit: 2327
Marketing Campaign Manager |Telegram ID- @LT_Mouse
Can someone or whirlwind please respond on this part from my review-

I don't know if this is intentional from whirlwind or not. Here's my mixing-
1. my addy to WHIRLWIND1 address
2. WHIRLWIND1 sent BTC to their X address
3. And sent me BTC to my desired address from address X (same address from the 2nd step)

Again,
1. Used Notes- sent BTC from my address to WHIRLWIND2 address.
2. WHIRLWIND2 sent BTC to X (same as previous)
3. When I withdrew, they again sent me BTC from address X
Does it work this way? I don't think so. Basically, it's like MY btc to whirlwind and the same BTC is being sent to me.
I felt like I was sent my BTC.

I'm not a guy who used a mixer a lot of time. I used it mostly just to check out how it works. I have tested a few mixers including ChipMixer and all of those were to get an experience of how the process work in individual site.
May I know what I'm missing? My bad if this is a very much stupid question I had though I think it wasn't.
copper member
Activity: 112
Merit: 338
A new update just went live. Most if not all issues raised in the review campaign until now should be fixed.

Changelog

04.04.2023 06:00:00 AM UTC
-Fees were reduced from 0.00015BTC/address to 0.0001BTC/address
-Website is now fully responsive
-All "unclickable" buttons fixed
-Note can now be downloaded in the same way as the Letter of Guarantee
-Tor header added
-HTTP Strict-Transport-Security added
-Captcha can be refreshed
-Clearnet link added to footer
-Added warning on the Withdraw Note/Combine Note pages (Your note will only work after the deposit is fully confirmed.)
-If user doesen't have JS enabled an error will be displayed
-Sliders fixed
-Network fees now adjust automatically based on market conditions so transactions shouldn't get stuck anymore

I saw a review campaign and was ready to participate in, but I see the same thing will be repeated over and over. Even if I could add an adress analysis from a tool used by CEXs to make it a bit different and a website security check.


However, I have a question

The website is missing the HTTP   security header
You know what I mean? The point saying to browsers that Whirlwind should only be accessed with HTTPS, and any connection using HTTP should automatically be converted to HTTPS

However, I believe you configured a 301 redirect on your server (HTTP to HTTPS) , it does almost the same thing but the HTTP connection is still vulnerable to a man-in-the-middle attack

Just for my information, TYVM

By the way: Pretty smart to use Njalla  Smiley
If you have the time I'd appreciate your review

HSTS was fixed too. Even though I believe the other implementation was good enough (a user would have to take extra steps in order to use HTTP so it couldn't happen by accident), I agree with you that this is the right way to do it.

They are just one of many providers that we use, but for Clearnet at least it does the trick
copper member
Activity: 2940
Merit: 4101
Top Crypto Casino
I saw a review campaign and was ready to participate in, but I see the same thing will be repeated over and over. Even if I could add an adress analysis from a tool used by CEXs to make it a bit different and a website security check.


However, I have a question

The website is missing the HTTP   security header
You know what I mean? The point saying to browsers that Whirlwind should only be accessed with HTTPS, and any connection using HTTP should automatically be converted to HTTPS

However, I believe you configured a 301 redirect on your server (HTTP to HTTPS) , it does almost the same thing but the HTTP connection is still vulnerable to a man-in-the-middle attack

Just for my information, TYVM

By the way: Pretty smart to use Njalla  Smiley
copper member
Activity: 112
Merit: 338
Exactly, the same here I have been trying to see the content and the features in the site before making proper Review on the site but the website both the onion and clearnet are not working instead one shows "The site can't be reached".👇
I can open the page with no problems. I have to wait 5 seconds for it to load, but otherwise everything is fine.  Smiley



@whirlwindmoney
It might be good to translate the site into other languages. Even if many people understand English, there are still people who have problems with it and only use a site if it is also offered in their mother tongue. I've noticed this very often, especially with people from Germany, for example. Other mixers often offer the option of changing the language. Maybe that would also be a good suggestion for Whirlwind.  Smiley

There was no downtime after my previous message. If you encounter any issues with Clearnet try another browser, otherwise please use the Tor version.

Thanks for the suggestion, we'll translate the site into other languages very soon. I want to get the user experience right before that though, I'm already working on some changes considering the feedback I got until now from the review campaign. After a few days of receiving feedback and fixing we should arrive at the final form and then I will look to translate the website and create a presentation/tutorial video.
legendary
Activity: 1988
Merit: 1768
Exactly, the same here I have been trying to see the content and the features in the site before making proper Review on the site but the website both the onion and clearnet are not working instead one shows "The site can't be reached".👇
I can open the page with no problems. I have to wait 5 seconds for it to load, but otherwise everything is fine.  Smiley



@whirlwindmoney
It might be good to translate the site into other languages. Even if many people understand English, there are still people who have problems with it and only use a site if it is also offered in their mother tongue. I've noticed this very often, especially with people from Germany, for example. Other mixers often offer the option of changing the language. Maybe that would also be a good suggestion for Whirlwind.  Smiley
legendary
Activity: 2758
Merit: 6830
Exactly, the same here I have been trying to see the content and the features in the site before making proper Review on the site but the website both the onion and clearnet are not working instead one shows "The site can't be reached".👇
It has been working fine for me since OP's last message. Keep in mind that the .onion domain can only be accessed through Tor.
legendary
Activity: 1106
Merit: 1372
I keep getting a "Backend offline. Please try again later" message and I noticed that the API calls are returning the 500 status. Both clearnet and Tor. DDoS maybe?
Exactly, the same here I have been trying to see the content and the features in the site before making proper Review on the site but the website both the onion and clearnet are not working instead one shows "The site can't be reached".👇

And second one (clearnet) shows pure blank page👇


With this we can't say anything about the site until the site works properly before people can make their honest review and comments. So make the site working for easy access and mixing with fair transactions.
copper member
Activity: 112
Merit: 338
I keep getting a "Backend offline. Please try again later" message and I noticed that the API calls are returning the 500 status. Both clearnet and Tor. DDoS maybe?
I am doing some adjustments on the ddos protection, I really want to get this right and not use cloudflare or any 3rd party. Everything will be back to normal in about an hour or so and it should be able to handle attacks better afterwards.

edit: service is back online, apologies for the inconvenience
You are in very safe hands with Hhampuz managing your campaign here.

Welcome to the forum  Smiley

Clearnet link is online, if you encounter any issues while on it please use the Tor version.

More BTC will be added to the reserve in the following days, for technical info concerning the current setup and our future plans please read this thread.

Thank you!
legendary
Activity: 2758
Merit: 6830
I keep getting a "Backend offline. Please try again later" message and I noticed that the API calls are returning the 500 status. Both clearnet and Tor. DDoS maybe?
legendary
Activity: 3122
Merit: 1102
Leading Crypto Sports Betting & Casino Platform
You are in very safe hands with Hhampuz managing your campaign here.

Welcome to the forum  Smiley

Clearnet link is online, if you encounter any issues while on it please use the Tor version.

More BTC will be added to the reserve in the following days, for technical info concerning the current setup and our future plans please read this thread.


there's no doubt Hhampuz is one of the prominent CMs in this forum. and he will stop the campaign anytime if he sees any anomaly going on.

on the note of this service, their rep is quite active here. so that's a good start. but they should not change their approach on this as they are still gaining the trust and confidence of mixer users. if they are easy to contact anytime, then, people will really start using their platform. users are now very cautious because of what happened to one of the biggest mixers found in the forum. their entry is just a good timing.
legendary
Activity: 2534
Merit: 1713
Top Crypto Casino
You are in very safe hands with Hhampuz managing your campaign here.

Welcome to the forum  Smiley

Clearnet link is online, if you encounter any issues while on it please use the Tor version.

More BTC will be added to the reserve in the following days, for technical info concerning the current setup and our future plans please read this thread.

copper member
Activity: 112
Merit: 338
OK, I am interested in testing your service when this new campaign opens, and maybe you could learn from mistakes chipmixer made and make some improvements.
It's not only trust I question, I also wonder if you have enough Bitcoins in reserve to support mixer operating for future, or you are basing Whirlwind future only on earning from fees?
What is maxiumm amount of Bitcoin someone could mix today using Whirlwind.money?
We do have our own Bitcoins which are added gradually with other users deposits. The amount currently in the pool is a bit over 3BTC but I expect it will grow at a fast pace over the next weeks. The anonimity set (amount of deposits your output transaction could originate from) is only going to become stronger the longer the service runs.

The reserve can always be verified here: https://blockchair.com/bitcoin/address/bc1qf8h5k6sash8007vpesymxkw2xsg5d0r3j4l5vmcrwpz2pqu66fjstzgd3r

It's hard to come up with a number for the maximum amount because it depends on a few things. If you use Fast mode then I wouldn't recommend sending more than the amount currently in the pool. If you use Notes then it doesen't really matter since you can deposit and withdraw whenever you like, so you could deposit any amount, but withdraw over a longer period.

How long do you keep this records (note public key and balance) and do you keep any IP address from users?
We keep the public key and balance stored until the Note's balance is completely spent. Nothing else is logged, no IP (we also don't use cloudflare or any other 3rd party), no deposit address/transaction or anything that could link the Note to you. You also have the option to combine 2 or more Notes and get a new one. For example you have a 1BTC Note and another 0.5BTC Note, you can combine them and you get a new Note with a 1.5BTC balance. The now used 2 Notes are then deleted from the servers.

I also want to make it clear that we do not use mixing codes or anything that could link your transactions.

Don't get me wrong, nothing personal against you, but I am always a bit suspicious to any new service that shows up.
All good, if you have other questions please ask otherwise I'll wait for your review!

Welcome to bitcointalk and as a campaign participant I will use my first week's payment to test the site and afterwards give my reviews on the mixing facility of a whirlwind, even though this project came as a replacement to chipmixer it's very important to know what users stands to the gain from using this services.

But I must say that the site is quite friendly and could become the next stop point for many mixer users who may have been disappointed in the seizure of chip mixer site.
Thank you and waiting for your review! The part that I bolded is not accurate though, we were working on this long before anything happened. I started this because I believe our mechanism is superior compared to the other solutions, including CM. The CM saga more or less proved my assumption that a better service is needed right.
hero member
Activity: 910
Merit: 507
Welcome to bitcointalk and as a campaign participant I will use my first week's payment to test the site and afterwards give my reviews on the mixing facility of a whirlwind, even though this project came as a replacement to chipmixer it's very important to know what users stands to the gain from using this services.

But I must say that the site is quite friendly and could become the next stop point for many mixer users who may have been disappointed in the seizure of chip mixer site.
legendary
Activity: 2212
Merit: 7064
We will launch a review campaign shortly with funds held in escrow by minerjones, you'll be able to try out the service safely. It's going to take time to build trust, but we'll be here to prove ourselves.
OK, I am interested in testing your service when this new campaign opens, and maybe you could learn from mistakes chipmixer made and make some improvements.
It's not only trust I question, I also wonder if you have enough Bitcoins in reserve to support mixer operating for future, or you are basing Whirlwind future only on earning from fees?
What is maxiumm amount of Bitcoin someone could mix today using Whirlwind.money?

All funds are stored in the multi-sig, Notes are proof that you are owed BTC from the pool. We only keep the public key of the Note and the balance, nothing else. There is no identifiable information such as deposit address/timestamp, that's why it's so important that you store your Note private key safely, you will need it to withdraw.
How long do you keep this records (note public key and balance) and do you keep any IP address from users?

Apologies if it's too much info and it's hard to follow, but I want to be as transparent as possible and not leave out important details. It's normal if some are skeptical because the service works differently than what they're used to and because of the latest events, but i'm confident that once we get over the trust issues and users understand how everything works, Whirlwind will become the benchmark in this niche.
Don't get me wrong, nothing personal against you, but I am always a bit suspicious to any new service that shows up.
copper member
Activity: 112
Merit: 338
We all know what happened with one big mixer recently and reading reports we could see that authorities seized a lot of coins and other data stored on 7TB drives.
There is a lot of competition for remaining mixers and there is certainly demand for bitcoin mixing, but it's hard for me to trust any new mixer.
I know it takes time for this, so I hope you will remain active in bitcointalk forum in future.
We will launch a review campaign shortly with funds held in escrow by minerjones, you'll be able to try out the service safely. It's going to take time to build trust, but we'll be here to prove ourselves.

My question is, what is Whirlwind.money doing differently that will prevent something like this happening for you in future, and do you store coins in hot or cold wallets?
Thanks for the question - we went to great lenghts to protect against any kind of hack/attack on our service and this is mostly the reason why it took us over 2 months to develop and test Whirlwind. I'll quote some answers

Since we are using a single aggregate address for all deposits and withdrawals, holding its private key on a server would be a risky move. That is why we decided to use a backend+validator model. The backend’s job will be to interact with end users by generating deposit addresses, processing withdrawals, etc. In the initial design, there will be x validators which will validate all of the backend’s actions (verify funds were received from the deposit address to the main aggregate address, verify submitted credit notes for withdrawals). These x validators will hold the multi-sig keys for the main address and will be hosted on different servers. Whenever a withdraw transaction is being sent, the signatures must be retrieved from all validators which are able to verify the transaction is correct. If an attacker manages to gain access to the backend, it would be pointless, as he will not be able to steal the funds (since the keys are on different servers), and he will not be able to forge proofs in order to withdraw another user’s BTC to his wallet. Using this model, we will be able to further decentralise this service by allowing other trusted members to run their own federated validators so that a single entity will no longer hold all of the multi-sig keys.

When a user deposits BTC using the fast withdraw method, the backend sends the deposit hash to the validators and whitelists the receiving addresses. After the signature is sent to the backend, the validators delete all proofs of those receiving addresses, keeping only the deposit transaction hash so that they would not accept a “duplicate proof”.
When a user deposits BTC using the slow withdraw method, the backend sends the deposit hash to the validators and they assign credit to the note’s public key. When the user wants to withdraw his BTC, he must send a signature to the backend which will process this. This signature will also be sent to the validators which will check it and remove credit from the note’s public key and whitelist the receiving addresses. If an attacker compromises the backend server, he would not be able to forge user note signatures in order to fool a validator to send him funds, because only the users have access to the notes’s private keys. Again, the proofs are deleted after their use.

At the moment, with whirlwindmoney being the sole operator of the site, then they are in control of all 3 keys in a 3-of-3 multi-sig. This provides additional security against a single server being seized or infiltrated, but it still requires complete trust from the end user that whirlwindmoney won't scam them, as it would in a normal single-sig set up.

Bottom line is that compared to the service you asked me about that was running on 2 servers, I can't say our exact number,but we have >5. And if you don't get access to all of them at the same time then it's the same as getting access to none, there is nothing you can do. The only server that is public is the clearnet frontend, which we assumed is infiltrated from day 1, so nothing to worry about there. The others are behind lots of layers so even if it would be possible to somehow get to them, it would definitely take a lot of time. (Servers are not exposed between them, so even if you get access to the backend, you won't know the IPs of the signers and other servers)

All servers are from different providers and we will change them with new ones once every month or so, just in case.

I see that you are using multisig setup, and I like this approach, but are Notes ever stored anywhere online by you or not?
All funds are stored in the multi-sig, Notes are proof that you are owed BTC from the pool. We only keep the public key of the Note and the balance, nothing else. There is no identifiable information such as deposit address/timestamp, that's why it's so important that you store your Note private key safely, you will need it to withdraw.

Apologies if it's too much info and it's hard to follow, but I want to be as transparent as possible and not leave out important details. It's normal if some are skeptical because the service works differently than what they're used to and because of the latest events, but i'm confident that once we get over the trust issues and users understand how everything works, Whirlwind will become the benchmark in this niche.

For any other questions I'm always here
legendary
Activity: 2212
Merit: 7064
We all know what happened with one big mixer recently and reading reports we could see that authorities seized a lot of coins and other data stored on 7TB drives.
There is a lot of competition for remaining mixers and there is certainly demand for bitcoin mixing, but it's hard for me to trust any new mixer.
I know it takes time for this, so I hope you will remain active in bitcointalk forum in future.

My question is, what is Whirlwind.money doing differently that will prevent something like this happening for you in future, and do you store coins in hot or cold wallets?
I see that you are using multisig setup, and I like this approach, but are Notes ever stored anywhere online by you or not?
copper member
Activity: 112
Merit: 338
@whirlwindmoney, Hi.

Just to let you know.
While trying the onion service yesterday, I got a pop up with the message like "sorry, an error occurred".
I have been able to duplicate the message twice but then it was fine on my end.

Reading @RapTarX I suppose the clearnet version is now avalaible? Because I get a timer of 5 seconds and then get HTTP ERROR 500

Welcome to the niche. More mixers there are, better it is. Smiley
Hi, thanks for letting me know. This may happen if you manually stop the page from loading or refresh before loading is completed, but it's not an issue even if that happens.

The 5 second countdown is normal, it's related to the ddos protection.

copper member
Activity: 2940
Merit: 4101
Top Crypto Casino


Yeah, I'm now able to see the clearnet version.
Probably just a delay in the DNS propagation since the website is freshly hosted

hero member
Activity: 1358
Merit: 851
Reading @RapTarX I suppose the clearnet version is now avalaible? Because I get a timer of 5 seconds and then get HTTP ERROR 500
I just checked out it and was able to browse without any issues. Haven't tried the tor site yet though. Do you encounter the problem now? I too get a 5 seconds timer and then redirected to their website homepage. No issue was encountered.
Edit- Just checked the tor website and it works perfectly from my end. I guess there was some issue from your end or it's possible that whirlwind was down when you tried.
copper member
Activity: 2940
Merit: 4101
Top Crypto Casino
@whirlwindmoney, Hi.

Just to let you know.
While trying the onion service yesterday, I got a pop up with the message like "sorry, an error occurred".
I have been able to duplicate the message twice but then it was fine on my end.

Reading @RapTarX I suppose the clearnet version is now avalaible? Because I get a timer of 5 seconds and then get HTTP ERROR 500

Welcome to the niche. More mixers there are, better it is. Smiley
Pages:
Jump to: