Author

Topic: [ANN][XCP] Counterparty - Pioneering Peer-to-Peer Finance - Official Thread - page 469. (Read 1276923 times)

sr. member
Activity: 602
Merit: 252
The development team has extended a 12 BTC reward to the hacker for finding the security flaws, contingent upon returning the missing BTC. We are waiting to hear back.

We have offered these BTC out of our pockets, but, beyond that, we hope the community can pull together to make things right. As a reminder, the donation address for the security bouty is: <14Tf35AovvRVURzd623q5i9kry2EW8WzyL>.

What we do next depends on what the hacker does.

Regarding the discussion on a XCP "tax" or "re-burn", we can state this: The strength of Counterparty's community helps differentiate us from other projects, and it is precisely that strength which makes it clear it is best not to introduce a new burn period.

While the protocol will become more secure and robust as time goes on and our community grows, it is also the case that if there are serious bugs in the future, more people will be affected, and, as a project, Counterparty will have more to lose. Our decisions now will determine how the community evolves, and by demonstrating our collective firmness, we are setting important precedent for the future: those who invest in XCP are investing in a currency with a stable money supply, the integrity of which will be maintained even in difficult circumstances.

Take Bitcoin as an example: there have been times in Bitcoin's history where a serious bug could have been dealt with by, for example, increasing the total number of Bitcoins. If this had happened, would Bitcoin still be seen as an example of stable money supply and good store-of-value?

The seriousness of this bug should not be underplayed, but by taking our growing pains in their stride, we are strengthening Counterparty for the future.

Waiting for the hacker's response.
legendary
Activity: 1320
Merit: 1007
Is there a command to see which version you are running?

Also, is this the command everyone is using to update to the latest version?

C:\Python32\python.exe setup.py update
full member
Activity: 532
Merit: 100
PrimeDAO - An Adoption Engine for Open Finance
hi guys, i am buying XCP @ 0.003BTC , please PM with offers.
newbie
Activity: 59
Merit: 0
Okay thanks for the quick replies guys I will just wait let them get on with sorting this
newbie
Activity: 8
Merit: 0
XCP is an interesting project. I'm watching silently.
hero member
Activity: 672
Merit: 500
I bought some XCP at 0.002 during the crash. I'm happy to return them to poloniex but where should we send them? Or are we just waiting to hear back from everyone still?

This is a nice attitude. I think the best is to contact poloniex directly and handle this with them.

I'm glad to see that all hope is not lost and I can still have faith in humanity! I'd send you some karma if I could.

Since you are the first to come out of the wood, and if you can send me the proof that you returned the XCP, I can sell you a percentage of these XCP at that bargain price (if you still want to hold XCP of course)

disclaimer : I don't own much XCP, and while I saw the dump happening, I didn't took advantage of it.
newbie
Activity: 56
Merit: 0
I'd advise you to sit back and let the devs and poloniex handle the situation. They've already shown to be very competent, professional and trustworthy and they will fix this one way or the other. And if at any point your nerves get the better of you remember it could have been far worse; if you hadn't burned your BTC they would still be in your Mt. Gox account Wink

Alleluia to this.
hero member
Activity: 602
Merit: 500
I don't know whether the XCP rollback and platform rollback is a way.

Maybe one solution:

1.Hacker return BTC back.

2.XCP rollback. All XCPs go back the address before the attack. So these XCP withdrawals after the attack will go back to the platform account.

3.Platform rollback
hero member
Activity: 617
Merit: 528
Correct me if I'm wrong but this is what I understood:

Someone sold 35k fake XCP on Poloniex. Then withdrew the BTC. After the hack was discovered Poloniex lost this 35k XCP. If the hacker would return the BTC everything could just be rolled back and everyone would have the same amount of XCP or BTC as before the hack. However, some people withdrew 7k XCP from Poloniex before trade was halted, and Poloniex never received this 7000XCP from the hacker (they got fakes). So if everyone were to withdraw their XCP now Poloniex would be 7k short. So no you won't lose your XCP we just need to figure out a way to come up with 7000 XCP to cover the loss.

-people who withdrew the 7k could return the XCP
-community could donate 7k
-Poloniex could sell a kidney to cover it themselves

I'd advise you to sit back and let the devs and poloniex handle the situation. They've already shown to be very competent, professional and trustworthy and they will fix this one way or the other. And if at any point your nerves get the better of you remember it could have been far worse; if you hadn't burned your BTC they would still be in your Mt. Gox account Wink
newbie
Activity: 32
Merit: 0
Right so just trying to get my head round this. I had bought some xcp before the bug. Is the 7000 missing xcp just from that which was bought during the dump or all xcp on the site. I.e. Will I lose all of my xcp or just any that was purchased as the price fell. Also I'd be happy to donate bitcoin but having trouble reindexing blockchain on counterpartyd so can't send xcp.

XCP on the site is safe, atleast for now  Wink
newbie
Activity: 59
Merit: 0
Right so just trying to get my head round this. I had bought some xcp before the bug. Is the 7000 missing xcp just from that which was bought during the dump or all xcp on the site. I.e. Will I lose all of my xcp or just any that was purchased as the price fell. Also I'd be happy to donate bitcoin but having trouble reindexing blockchain on counterpartyd so can't send xcp.
hero member
Activity: 588
Merit: 504
Hah! Ooops, for some reason, an old edit got restored that had that $4 category (we had taken it out). Still, we will honor this as our first bug bounty find!  Send your address to [email protected] and we'll send you some BTC dust. Smiley

Hehe please, donate to developer beer-fund instead, 1/2 a pint Smiley

Great initiative with this bounty. Had not followed recent drama in past days but team seems to be handling everything in their stride.
Happy to be a part in this community. Hope some kinks can be ironed out gradually.
sr. member
Activity: 602
Merit: 252
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.

Great to hear this.
sr. member
Activity: 390
Merit: 254
Counterparty Developer
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.

very nice.

Looking forward to collecting a sandwich Grin



Haha. I just reported that myself.

YOU do not qualify. Cheesy
sr. member
Activity: 390
Merit: 254
Counterparty Developer
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.

very nice.

Looking forward to collecting a sandwich Grin



Hah! Ooops, for some reason, an old edit got restored that had that $4 category (we had taken it out). Still, we will honor this as our first bug bounty find!  Send your address to [email protected] and we'll send you some BTC dust. Smiley
hero member
Activity: 602
Merit: 500
The development team has extended a 12 BTC reward to the hacker for finding the security flaws, contingent upon returning the missing BTC. We are waiting to hear back.

We have offered these BTC out of our pockets, but, beyond that, we hope the community can pull together to make things right. As a reminder, the donation address for the security bouty is: <14Tf35AovvRVURzd623q5i9kry2EW8WzyL>.

What we do next depends on what the hacker does.

Regarding the discussion on a XCP "tax" or "re-burn", we can state this: The strength of Counterparty's community helps differentiate us from other projects, and it is precisely that strength which makes it clear it is best not to introduce a new burn period.

While the protocol will become more secure and robust as time goes on and our community grows, it is also the case that if there are serious bugs in the future, more people will be affected, and, as a project, Counterparty will have more to lose. Our decisions now will determine how the community evolves, and by demonstrating our collective firmness, we are setting important precedent for the future: those who invest in XCP are investing in a currency with a stable money supply, the integrity of which will be maintained even in difficult circumstances.

Take Bitcoin as an example: there have been times in Bitcoin's history where a serious bug could have been dealt with by, for example, increasing the total number of Bitcoins. If this had happened, would Bitcoin still be seen as an example of stable money supply and good store-of-value?

The seriousness of this bug should not be underplayed, but by taking our growing pains in their stride, we are strengthening Counterparty for the future.

Absolutely agree with you!  "re-burn" or "tax" will kill Counterparty XCP and become a joke.
sr. member
Activity: 476
Merit: 300
Counterparty Chief Scientist and Co-Founder
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.

very nice.

Looking forward to collecting a sandwich Grin



Haha. I just reported that myself. Wink
hero member
Activity: 588
Merit: 504
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.

very nice.

Looking forward to collecting a sandwich Grin

full member
Activity: 182
Merit: 100

Those who traded on poloniex took the risk that something bad would happen to the centralized exchange. And it did. Why did the hacker not try withdrawing funds from a random large address before the central exchange was up? Because he had no way of cashing out a large quantity of BTCs quickly. Poloniex gave him that opportunity by having lax risk controls.


You all were so happy when that poloniex took XCP, look at what happened the price skyrocketed!! making you all rich!

But now you all blame poloniex for being "centralized" and the users who wanted to buy XCP , as "they should have known"! "it's risky!"

Yeah OK last time I had looked at the Decentralized exchange there were hardly any XCP for sale, and all very overpriced. and hard to use, you have to know command line to use it. Yeah good luck getting new people into the community that way.

You can't have your Cake and eat it too, without poloniex and those people buying XCP for ten times what it was worth, you'd just have worthless XCP...  so don't blame poloneix or it's users.  Only "lax risk control" is dealing with XCP in first place, you should thank , not criticize,

I'll make a prediction here today, you will not see another "centralized exchange" take XCP any time soon after the way people jump to attack Busonli when he first report bug, and now how you say he "took a risk" - yes to your advantage , only to his disadvantage


This is an excellent point.
sr. member
Activity: 390
Merit: 254
Counterparty Developer
We have released our Bug Bounty program: https://counterparty.co/bug-bounty-program/

Comments/suggestions welcome.
Jump to: