Pages:
Author

Topic: [ANN][Pool][Profit-Switch][Optional Auto-Exchange per Coin][Vardiff] ~ Hashcows - page 96. (Read 347337 times)

legendary
Activity: 1988
Merit: 1007
Report from the Mineshaft - The Cost Of Success (Middlecoin and Hashcows)
http://www.devtome.com/doku.php?id=report_from_the_mineshaft-the_cost_of_success

Let me get this straight. According to this opinion piece, ANY balance above a daily payout treshold (whatever that might be) is "fair game" to hackers and we have no right to complain about it being stolen or demand reimbursement?

Well I don't agree. Hypotethically, you could have been mining on Cows for just one day (e.g. the 23rd of December) and just before your automatic daily payout occurs on the 24th, the site is hacked and you lose everything. Hypothetically. Are you still not allowed to complain? How could you have prevented any of this? Manual payouts every hour? WTF do you draw the line??

To take it a step further, I had auto payouts disabled, as did many others. Whoever did this forced MANUAL payouts on tons of people. In fact, when I logged in and saw my missing balance, I checked the minimum payout. It was still disabled.
newbie
Activity: 4
Merit: 0
I have the same problems. My address is changed.

I try to change my password several times, they accept my email and my pin but always the same database error.

And now I can't login....



full member
Activity: 181
Merit: 100
Report from the Mineshaft - The Cost Of Success (Middlecoin and Hashcows)
http://www.devtome.com/doku.php?id=report_from_the_mineshaft-the_cost_of_success

Let me get this straight. According to this opinion piece, ANY balance above a daily payout treshold (whatever that might be) is "fair game" to hackers and we have no right to complain about it being stolen or demand reimbursement?

Well I don't agree. Hypotethically, you could have been mining on Cows for just one day (e.g. the 23rd of December) and just before your automatic daily payout occurs on the 24th, the site is hacked and you lose everything. Hypothetically. Are you still not allowed to complain? How could you have prevented any of this? Manual payouts every hour? WTF do you draw the line??
hero member
Activity: 526
Merit: 500
Its all about the Gold
hello,
looks like i was like many who had withdrawals of their account and not authorized  and changed addresses with pin Sad

this is not my address :

btc   13R87ropkDKzDEuVeQoX64kkcLvPWVdTKH    Debit_ATP   0.00211817   0   0   2013-12-24 11:37:26







my address:

************************************* (sent to your pm)

so far it appears my other addresses are not changed.

i want to know how my pin was used or even changed?
can i change it back to mine  yet or should i just keep it as is   until  further notice?
sr. member
Activity: 364
Merit: 250
I'm sure the admins will have a way of repaying the missing coins like 0 fees or something like that but right now they are trying to fix what the hacker did.
member
Activity: 224
Merit: 10
would be nice if Bitcoin had a feature to stop coin theft like this...
Either way, this can be tracked and found... Bitcoin is NOT like Fiat cash... IT IS Traceable. 

I would give 25% of my loss as a reward to catching the crook. 
With 40-400 BTC at stake, 10-100 BTC as a reward for bringing the guy to justice would be a nice reward...
Anyone else care to chip into the reward system and get people investigating to catch the MoFu?
time to make a bitcoin assassination fund on the hit market!

Never... This is not what I asked for... I asked for getting this guy and bringing him to Justice.  Not to assassinate him.
I would love to see the guy ROT in jail and let the "shower" guys take good care of him.
it was a joke
sr. member
Activity: 266
Merit: 250
Never... This is not what I asked for... I asked for getting this guy and bringing him to Justice.  Not to assassinate him.
I would love to see the guy ROT in jail and let the "shower" guys take good care of him.

His death would be justice. Alternatives would be chopping both his hands off and blinding him.  Grin
gas leak/faulty wiring/loose bolts on car
newbie
Activity: 54
Merit: 0
Never... This is not what I asked for... I asked for getting this guy and bringing him to Justice.  Not to assassinate him.
I would love to see the guy ROT in jail and let the "shower" guys take good care of him.

His death would be justice. Alternatives would be chopping both his hands off and blinding him.  Grin
full member
Activity: 200
Merit: 100
Ops should reimburse users, but only partially - if someone is too stupid to leave 0.5+ BTC on pool ran by two (doesn´t matter how honest) guys, where no one can expect robust security platform, deserves nothing more than loose it. During 6 months of mining I lost coins in various scams (Unocs, Orbit Coin, PhenixEx..) and I learned one thing - You are on enemy territory and if You loose, it was by your mistake so blame no one but You.

aTriz and nearmiss did great job here, so stop complain and try to be supportive.

The only person stupid here is you... Be supportive for a bunch of f... amateurs. I WANT MY FUCKING MONEY BACK

Glad you are being so mature about all this, we can tell who are the adults in the room!

In other news, we continue to have login's/payouts DISABLED, we will update here and in IRC within a few hours after me and nearmiss have a sit down and discuss things.

~Hashcows Team~

P.S. Merry Christmas everyone, sorry to start it off with this bad day!
The one thing I would like to honestly know is how they broke into the system and changed everything.  In my view, it seems like they broke in by the SQL Database server and mass changed the bitcoin withdrawal address, maybe changed the 4 digit pin code and then triggered the withdrawals.  Or they issued the SQL execute command to process the withdrawals bypassing the security protocols.

Either way, if Hashcows knows how they did it, please provide detailed evidence and if there was a fault by the software or human error, step forward and announce it.  If it is software, it would be best to patch it asap.  If Human error, well, you know what to do then...
full member
Activity: 200
Merit: 100
would be nice if Bitcoin had a feature to stop coin theft like this...
Either way, this can be tracked and found... Bitcoin is NOT like Fiat cash... IT IS Traceable. 

I would give 25% of my loss as a reward to catching the crook. 
With 40-400 BTC at stake, 10-100 BTC as a reward for bringing the guy to justice would be a nice reward...
Anyone else care to chip into the reward system and get people investigating to catch the MoFu?
time to make a bitcoin assassination fund on the hit market!

Never... This is not what I asked for... I asked for getting this guy and bringing him to Justice.  Not to assassinate him.
I would love to see the guy ROT in jail and let the "shower" guys take good care of him.
member
Activity: 70
Merit: 10
My payout address was changed, but nothing was taken out. Still not going to mine until the payout addy gets changed back.
full member
Activity: 141
Merit: 100
Yeah, I was logged in when all this went down. My payout address was not changed, nothing bad happened, but I still decided to change my password. But, the site was already in read-only lockdown, so it didn't work.

We'll just have to wait for the operators to resolve all this before we can log in again.
full member
Activity: 129
Merit: 100
is there a password reset link somewhere?   I can't login to check to see if I was affected, it doesn't take my password.

Edit:  just saw the post about being locked down.  That explains things Smiley
newbie
Activity: 14
Merit: 0
mining seems to be working normally, I never logged out of the site to begin with and my est and confirmed balance keeps updating

just can't withdraw or get payouts, as previously stated
newbie
Activity: 58
Merit: 0
full member
Activity: 141
Merit: 100
member
Activity: 112
Merit: 10
By the way, it looks as if the rouge wallet was created for the hack, the hack lasted for about two hours and they stole about $32500 worth of coin.

https://blockchain.info/address/13R87ropkDKzDEuVeQoX64kkcLvPWVdTKH?offset=0&filter=0
member
Activity: 112
Merit: 10
I doubt your actual account was hacked, this looks like an sql injection done via the website exploiting a security flaw in the sites code. I'm guessing they exposed the database and then injected their own payout address into every payout record. I'm guessing every single account has had it's payout address changed. Mine has. I was able to login a while ago and found my payout address has been changed to 13R87ropkDKzDEuVeQoX64kkcLvPWVdTKH. I haven't lost any coin but would have if the auto payout threshold had been reached.
full member
Activity: 201
Merit: 100
NEWS:
1. Site is currently in lockdown, NO LOGINS or WITHDRAWALS for now.
2. You can continue to mine with Hashcows if you choose, you will be paid.
3. We will not be making any quick, hash decisions, I understand that many of you are upset/angry, but nobody wins if we do not take our time in this matter and look at all avenues. The only thing I can assure you is we are both working on MULTIPLE ends to figure out what happened and how we are going to rectify this.

The community behind hashcows is truly amazing, from the bad times to the good, most of you have stuck by our side, we appreciate all the support you all have shown.

Merry Christmas,
Hashcows Team

Hopefully will have some more updates within the coming days.

Thanks for a small update but I hope you have an answer about the lost coins sooner than a few days.  I can't even log in to see "if/what" was stolen.  At this point the lack of info from admins about what's going on doesn't help out trust in the pool.  I can't even find out if my account was hacked.
full member
Activity: 155
Merit: 100
NEWS:
1. Site is currently in lockdown, NO LOGINS or WITHDRAWALS for now.
2. You can continue to mine with Hashcows if you choose, you will be paid.
3. We will not be making any quick, hash decisions, I understand that many of you are upset/angry, but nobody wins if we do not take our time in this matter and look at all avenues. The only thing I can assure you is we are both working on MULTIPLE ends to figure out what happened and how we are going to rectify this.

EXACTLY the type of update I was hoping to see, great job Cows!
Pages:
Jump to: