Pages:
Author

Topic: [ANN][MOON] Mooncoin: You know where it's headed! KGW exploit FIXED 4/3/2014 - page 80. (Read 1106913 times)

member
Activity: 115
Merit: 10
The community has finally decided to invite an independent auditor, Titan, an experienced cryptocoder, Luckycoin developer since 2013, to investigate Mooncoin script.
He has promised to complete it till Christmas. He will decompile a wallet and will investigate new and old open sources, too.

If you have ideas on what an independent auditor should focus his attention, please share it, or PM him directly: https://bitcointalksearch.org/user/titan-124654

4 wallets have been suffered since December 7:

2SQDhN8NE4Sk92MikERTzkz4a6PBuJ3HnB
2Z25JRcYYnvN52wJQy4FxZZPhnesBwiiqP
2bfkzvCAvvBASYZihFC66QykKiQNz2xgJ4
2aaiutvFC3nm7vuSM5AST51ANX9PztFKqe

Total coins stolen around 17.5 bln.

Currently there is no evidence that all Mooncoin wallets were compromised, but let's be careful and wait for the end of investigation before final conclusions.
sr. member
Activity: 340
Merit: 250
Does MoonCoin have the same backdoor as TIPS to steal wallets even with the private key ?

I was reading a document and you can "apparently" clone other peoples wallets and even though there is a private key you can still gain access to it by making a mould....

Maybe that is what happened.

No, I already posted what happened after I talked to Cryptsy's fraud dept.


This was not Cryptsy's fault - people left same RPC PASS/Login across multiple wallets and someone with daemon wallet cleared them out.

THIS IS DEFINITELY NOT PROVEN !!!

It was just a first suspicion of mine that I wrote to cryptsy.
But during the last days I tried to connect via RPC to my mooncoin wallet, testing different mooncoin.conf configurations. And it was not possible for me to reach it because the RPC Port 44663 is not  reachable from the internet because my router doesnt know what to do with port 44663. And my computer with the wallet ALWAYS was behind a router. The only way to establish connections from the outside to my wallet is with P2P Port 44664, which the wallet uses for mooncoin network communication.
As long as no one can get access to a mooncoin wallet via RPC (mooncoin.conf in server mode and no rpcuser and no rpcpass set) it is unlikely that the thief could connect via RPC !

Please help to think about other vulnerabilities so that we can find the real reason to disable it within the coming new wallet version!

What is with the SSH-Heartbleed bug?

Does MoonCoin have the same backdoor as TIPS to steal wallets even with the private key ?

I was reading a document and you can "apparently" clone other peoples wallets and even though there is a private key you can still gain access to it by making a mould....

Maybe that is what happened.
--> this is also something we should think about, could you please send me details about the fedoracoin issue?

And to avoid panic: please keep your coins ALWAYS in an ENCRYPTED wallet. Then every transaction out needs the wallet passphrase. I made this mistake to not encrypt my wallet and the thief could initiate transactions, on which way ever (we have to find out).

best regards,
peme



legendary
Activity: 1375
Merit: 1010

sooner or later we will know ....they are investigating ...

when the situation will be clear we will collect donations for compensation to cheat people
legendary
Activity: 3052
Merit: 1534
www.ixcoin.net
Does MoonCoin have the same backdoor as TIPS to steal wallets even with the private key ?

I was reading a document and you can "apparently" clone other peoples wallets and even though there is a private key you can still gain access to it by making a mould....

Maybe that is what happened.

No, I already posted what happened after I talked to Cryptsy's fraud dept.


This was not Cryptsy's fault - people left same RPC PASS/Login across multiple wallets and someone with daemon wallet cleared them out.
newbie
Activity: 2
Merit: 0
Whoever owns 2DMfpxPiMtpVDVyrxQAAmfBbZnDH4XCMfK needs to be taken down. He's stolen 6 billions. How can we track this thief?

These addresses were also cleared from different wallets, where there was more than one address:
2SQDhN8NE4Sk92MikERTzkz4a6PBuJ3HnB
2aaiutvFC3nm7vuSM5AST51ANX9PztFKqe
and kept on:

2JA3Cqf9on8YuxngxdXStCFKanAGnaQU5A
2GWu3v33XYU8G6vHFaChYc6YA6edDmW1cK
together over 11 billions Moon.
legendary
Activity: 1554
Merit: 1001
Does MoonCoin have the same backdoor as TIPS to steal wallets even with the private key ?

I was reading a document and you can "apparently" clone other peoples wallets and even though there is a private key you can still gain access to it by making a mould....

Maybe that is what happened.
member
Activity: 218
Merit: 10
Whoever owns 2DMfpxPiMtpVDVyrxQAAmfBbZnDH4XCMfK needs to be taken down. He's stolen 6 billions. How can we track this thief?
legendary
Activity: 1375
Merit: 1010
Great hendrix today fed fomc i open short position on the future eur/usd ...
you could do a lot more gains in the stock market future CME.. Grin



Now eur usd futures -1,12  Grin
legendary
Activity: 1375
Merit: 1010
OFFICIAL POOL LIST
Multipool.us: http://multipool.us

Mooncoin P2Pool: Mooncoin P2Pool

moon.bitember.com: http://moon.bitember.com
legendary
Activity: 1890
Merit: 1031
legendary
Activity: 1375
Merit: 1010
Great hendrix today fed fomc i open short position on the future eur/usd ...
you could do a lot more gains in the stock market future CME.. Grin

Now eur/usd futures -1,12  Grin
newbie
Activity: 36
Merit: 0
Yes, I have some more, but will keep those in case we reach 60 again or dip under 11. Right now Im in profit, so I basically have a free MOON ride!

Lol someone bought all my MOON from the dump to 11. Thanks! Made almost 80% in profits  Cool

i bought some.you have some more? Wink
i hope you are a millionaire by now...
Merry Christmas!

You should wriite a book of your successful trading with mooncoin  Wink
member
Activity: 71
Merit: 10
Yes, I have some more, but will keep those in case we reach 60 again or dip under 11. Right now Im in profit, so I basically have a free MOON ride!

Lol someone bought all my MOON from the dump to 11. Thanks! Made almost 80% in profits  Cool

i bought some.you have some more? Wink
i hope you are a millionaire by now...
Merry Christmas!
newbie
Activity: 36
Merit: 0
Lol someone bought all my MOON from the dump to 11. Thanks! Made almost 80% in profits  Cool

i bought some.you have some more? Wink
i hope you are a millionaire by now...
Merry Christmas!
member
Activity: 71
Merit: 10
Lol someone bought all my MOON from the dump to 11. Thanks! Made almost 80% in profits  Cool
member
Activity: 218
Merit: 10
My wall at 30 removed Grin

You can thank whoever nicked all my mooncoins for that.
legendary
Activity: 1375
Merit: 1010
member
Activity: 218
Merit: 10
Right folks. I've just bought back in - all billion mooncoins I lost.

Long live Moon.
sr. member
Activity: 340
Merit: 250
too much coins stolen  Cry

Please contact cryptsy with all details to wich addresses your mooncoins have been transferred to.
If they are able to find a cryptsy account to an address they can freeze it.
Please don't give up, we will try everything.

We have to find out why this all could happen to update the new wallet version.

Perhaps cryptsy will think about a blockchain rollback now, we will see.

Hi redjedievolution I have been the victim of a large (over a billion) theft too. I was wondering - would it be worth trying to make a list of all hacked addresses and recipient addresses? We can try to gather evidence and track what has happened. I contacted cryptsy but no response yet.

Yes, and to find out what happened, it would also be nice if we could find out what all the affected users had in common (operating system, behind a router or not, using team viewer, wallet encrypted?, download of other coinwallet before the theft, download of any other software to that machine where the affected wallet was, etc....)
legendary
Activity: 1375
Merit: 1010
@MooncoinItalia: Tks @cryptsy
Pages:
Jump to: