Author

Topic: [ANN][BETA][EXCHANGE][REALTIME] CoinEX realtime exchange - page 134. (Read 283795 times)

newbie
Activity: 21
Merit: 0
Damn, you have bad luck.
Give us the IP of the guy and let's track him down  Tongue

Hum, don't burn the witch, m'kay ? :>
legendary
Activity: 2674
Merit: 2965
Terminated.
Damn, you have bad luck.
Give us the IP of the guy and let's track him down  Tongue
legendary
Activity: 1048
Merit: 1000
https://r.honeygain.me/XEDDM2B07C

Thats too bad. Lets see if legal recourse can help you.

Any details on how the attack was done? I remember a couple of weeks back some pool got drained of its funds.
There was a place at our code which missed an addition database integrity check. So when the load went high, it was unable to update the database properly and this led to a bug where one could cancel his order multiple times and get BTCs refunded to his account multiple times. So that thief occasionally discovered this and used it to generate a big fake BTC balance which allowed him to withdraw all the BTC in the exchange's wallet and also to buy up alot of other coins. So he withdrew 22.5 BTC and bought up around 40BTC worth of other coins. Still investigating how much of those he was able to withdraw. This takes alot of work to reapply all trades on all user balances to verify balances integrity.

I am working hard on it and will get trade engine back online as soon as I verify that all the balances are correct. This is likely to happen today. On the other side, withdrawals are still suspended since exchange wallet is mostly empty anyway.
We've raised around 4BTC in donations and I go all in with my 7BTC which I was able to gather selling my holds. That amount is still way less than sum of exchange accounts balances so enabling withdrawals right now will lead to getting it empty quite fast. I'm going to re-enable withdrawals at a point where we will run less than 25% BTCs short guessing that some people won't withdraw their coins right away.

I will keep you posted on the status of all this. There is also a twitter account @coinexpw where I post updates and link to posts in this thread to keep people up to speed in this situation.

Sincerely yours,
- erundook


Man this is pissing me off. Some people have absolutley NO morals and it is people like that, that give the bitcoin community a bad name. If there is anything we can do to help man, let us know. It is such a piss off that these idiots get to roam free while people like you have to pay the consequences. ugh.
sr. member
Activity: 448
Merit: 250

Thats too bad. Lets see if legal recourse can help you.

Any details on how the attack was done? I remember a couple of weeks back some pool got drained of its funds.
There was a place at our code which missed an addition database integrity check. So when the load went high, it was unable to update the database properly and this led to a bug where one could cancel his order multiple times and get BTCs refunded to his account multiple times. So that thief occasionally discovered this and used it to generate a big fake BTC balance which allowed him to withdraw all the BTC in the exchange's wallet and also to buy up alot of other coins. So he withdrew 22.5 BTC and bought up around 40BTC worth of other coins. Still investigating how much of those he was able to withdraw. This takes alot of work to reapply all trades on all user balances to verify balances integrity.

I am working hard on it and will get trade engine back online as soon as I verify that all the balances are correct. This is likely to happen today. On the other side, withdrawals are still suspended since exchange wallet is mostly empty anyway.
We've raised around 4BTC in donations and I go all in with my 7BTC which I was able to gather selling my holds. That amount is still way less than sum of exchange accounts balances so enabling withdrawals right now will lead to getting it empty quite fast. I'm going to re-enable withdrawals at a point where we will run less than 25% BTCs short guessing that some people won't withdraw their coins right away.

I will keep you posted on the status of all this. There is also a twitter account @coinexpw where I post updates and link to posts in this thread to keep people up to speed in this situation.

Sincerely yours,
- erundook
newbie
Activity: 27
Merit: 0
Okay another update on this situation.
Total calculated loss is way over 20BTC.
That account withdrew 22.5 BTC in total, and when exchange was out of BTC he used his fake balance to buy alot of ZET.
After reviewing all logs, exchange is running short for ~66 BTC.
Donations barely covered that, so I'm now making a deal with an investor who wishes to buy a share of the exchange.
I will use funds gained from that to cover the loss and resume the service.

Thus, I presume it could take a little more than 24hrs (though we're trying to make this deal as soon as possible).
Please give us some more time to fix all the mess and resume the operation.

That sucks dude, i've donated what little i can, hope you can get things sorted out soon. Your hard work and constant updates are appreciated Smiley

Best of luck!
legendary
Activity: 1050
Merit: 1000
Okay another update on this situation.
Total calculated loss is way over 20BTC.
That account withdrew 22.5 BTC in total, and when exchange was out of BTC he used his fake balance to buy alot of ZET.
After reviewing all logs, exchange is running short for ~66 BTC.
Donations barely covered that, so I'm now making a deal with an investor who wishes to buy a share of the exchange.
I will use funds gained from that to cover the loss and resume the service.

Thus, I presume it could take a little more than 24hrs (though we're trying to make this deal as soon as possible).
Please give us some more time to fix all the mess and resume the operation.

Thats too bad. Lets see if legal recourse can help you.

Any details on how the attack was done? I remember a couple of weeks back some pool got drained of its funds.
sr. member
Activity: 448
Merit: 250
Okay another update on this situation.
Total calculated loss is way over 20BTC.
That account withdrew 22.5 BTC in total, and when exchange was out of BTC he used his fake balance to buy alot of ZET.
After reviewing all logs, exchange is running short for ~66 BTC.
Donations barely covered that, so I'm now making a deal with an investor who wishes to buy a share of the exchange.
I will use funds gained from that to cover the loss and resume the service.

Thus, I presume it could take a little more than 24hrs (though we're trying to make this deal as soon as possible).
Please give us some more time to fix all the mess and resume the operation.
erk
hero member
Activity: 826
Merit: 500
all withdrawals except BTC were enabled

Is this true? When I try withdraw ZET is says transaction completed but then nothing happens - I do not get my ZET and they still on my account - nothing happens.
Can someone confirm?
Try reading the obvious notice at the top of every coin page.

Quote
IMPORTANT: maintenance mode, most parts of the site won't work during that time, including all withdrawals and trades.
Please allow up to 24hrs to secure your balances and restore a solid service.
In the mean time, please follow @coinexpw twitter account to get all the latest updates on status of the site and also check out this and this. Thanks!
sr. member
Activity: 420
Merit: 250
have tried to withdraw, nothing happens
the withdrawals are enabled, but no actual transfer of funds is actually executed...
 
sr. member
Activity: 420
Merit: 250
no it's not
full member
Activity: 344
Merit: 100
all withdrawals except BTC were enabled

Is this true? When I try withdraw ZET is says transaction completed but then nothing happens - I do not get my ZET and they still on my account - nothing happens.
Can someone confirm?
sr. member
Activity: 644
Merit: 250
I emailed erundook the dox info, so he could confirm it.
legendary
Activity: 1048
Merit: 1000
https://r.honeygain.me/XEDDM2B07C
Quote
i second this. we can't be sure who was it and if funds will not get returned we will start an official case at NYPD and that's their job
to trace him down.
i'm not sure how did they get that info and i kindly ask to remove the picture at least.

Damn bro, some people have no sense or human morality. Im sorry for your loss bro. I was just thinking, what software are you using for your site, because I remember someone using the same tactic on a pool a while back that caused nearmiss to lose a bunch of coin. I'd look into it, and if the code is OS then I would contact the dev and let him know. That sucks, but justice will be served, and if you can confirm that d0x is the guy, let me know Smiley
full member
Activity: 168
Merit: 100
Designer & Developer
So besides that guy stealing $2,000+ USD what is up with the exchange? Are all withdrawals suspended currently or just BTC?
full member
Activity: 158
Merit: 100
Erm, is anyone else uncomfortable with someone being doxxed with no evidence or information? That post should be removed imo.
Totally agree.
full member
Activity: 203
Merit: 100
Erm, is anyone else uncomfortable with someone being doxxed with no evidence or information? That post should be removed imo.
i second this. we can't be sure who was it and if funds will not get returned we will start an official case at NYPD and that's their job
to trace him down.
i'm not sure how did they get that info and i kindly ask to remove the picture at least.

Glad to see you feel the same erundook. Sorry this happened to you, shitty situation.

Hell, if the guy who really was hurt by this says this, then OBVIOUSLY the info isn't verified in any way, shape or form. It should be removed.

full member
Activity: 203
Merit: 100
Erm, is anyone else uncomfortable with someone being doxxed with no evidence or information? That post should be removed imo.

Doxing is not disallowed by forum rules, as all information gathered by doxing is Publicly available. If you start posting someones SSN thats one thing, but posting name, address, phone numbers, etc can all be found through a google or whitepages search.

However, I would encourage 2kool to remove the dox and save it, while they and erundook compare notes. It really sucks when you dox the wrong person due to a technical error, and then some random guy starts getting hate mail and pizzas sent to their house.

Then this forum indirectly supports it and should change that policy. Posting info like that in a thread saying THIS IS THE GUY!!! GET HIM!!!! with no evidence is pretty dangerous. Just because he found some dude's information online doesn't mean it should be in a thread to hunt him down. See - Spike Lee tweeting some family's address and bringing the wrath of the net on them.
legendary
Activity: 2590
Merit: 2156
Welcome to the SaltySpitoon, how Tough are ya?
i second this. we can't be sure who was it and if funds will not get returned we will start an official case at NYPD and that's their job
to trace him down.
i'm not sure how did they get that info and i kindly ask to remove the picture at least.

Thats not actually a picture of the person lol, thats Dog the Bounty hunter. He was some guy on T.V who chased down people who skipped bail, and then brought them into the police or something like that.
sr. member
Activity: 448
Merit: 250
Erm, is anyone else uncomfortable with someone being doxxed with no evidence or information? That post should be removed imo.
i second this. we can't be sure who was it and if funds will not get returned we will start an official case at NYPD and that's their job
to trace him down.
i'm not sure how did they get that info and i kindly ask to remove the picture at least.
sr. member
Activity: 281
Merit: 250
The Gold Standard of Digital Currency.
Donated, Zero fees aside, I hope you catch that guy and recover all the stolen btc.

Good Luck  Wink
Jump to: