Author

Topic: [ANN][XCP] Counterparty - Pioneering Peer-to-Peer Finance - Official Thread - page 486. (Read 1276923 times)

sr. member
Activity: 531
Merit: 260
Vires in Numeris
I've not read this thread but note that the Poloniex link to Counterparty XCP from its homepage is tripping through to NXT rather than any error or statement about this.
hero member
Activity: 491
Merit: 500
hero member
Activity: 898
Merit: 1000
Hey guys, I just double checked the OP and found this:

Disclaimer: The code being released here is of alpha-quality and under heavy development. You should expect to encounter significant bugs when using it. It is even possible that a bug might cause you might lose some money. The Counterparty team will do everything in its power to prevent this from happening, but this technology is very new, and the implementation is not yet well-tested. In particular, we may at some point have to change the Counterparty protocol in a not backwards-compatible way, if such a change is necessary to fix a bad bug or an exploit. As always, don't invest more than you can afford to lose.

I wish they'd made it stand out more by making the text red or something.
hero member
Activity: 714
Merit: 502
What will happen to the orders and balances on poloniex?

+1, I had a few hundreds over there

Presumably it is suspended until it can be fixed and there is more certainty. Its going to take sometime until the smoke clears out.


I just lost 300 million TIPS yesterday, because of a fucking bug in the paper wallet algorithm, I hope I haven't lost some of my XCPs as well, or that could be more than a third of all my investments that I lost in a very short time, without me being at fault (hacked,..).

Fuck my life :/

You must be a bloody good waiter!
sr. member
Activity: 364
Merit: 250
Owner of Poloniex
As someone said before--do NOT buy XCP from anyone until this is fixed. Not on the DEX, not privately, not anywhere.
sr. member
Activity: 294
Merit: 250
What will happen to the orders and balances on poloniex?

+1, I had a few hundreds over there

Presumably it is suspended until it can be fixed and there is more certainty. Its going to take sometime until the smoke clears out.


I just lost 300 million TIPS yesterday, because of a fucking bug in the paper wallet algorithm, I hope I haven't lost some of my XCPs as well, or that could be more than a third of all my investments that I lost in a very short time, without me being at fault (hacked,..).

Fuck my life :/
sr. member
Activity: 364
Merit: 250
Owner of Poloniex
Wow, that disappointing...
That said, I'm happy that it happened so early, before XCP has spread to other exchanges.

Also, seems that it will boost the Dex (as it should), as it seems to be much safer (or so I hope!).

No, the Dex is not safer from this attack.

Devs are on it now.
full member
Activity: 196
Merit: 100
What will happen to the orders and balances on poloniex?

+1, I had a few hundreds over there

Presumably it is suspended until it can be fixed and there is more certainty. Its going to take sometime until the smoke clears out.
hero member
Activity: 491
Merit: 500
Can we halt all orders on xcp or somehow rollback? Is it even possible to rollback?
sr. member
Activity: 294
Merit: 250
What will happen to the orders and balances on poloniex?

+1, I had a few hundreds over there
legendary
Activity: 1120
Merit: 1000
This is as good a time as any to make a plug for the DEX.

Let's fix the issue with trolling orders so we don't have to worry about centralized points of failure ever again.

+1

Why would a hacker wanting to make a demonstration have done the deed on Poloniex and not the DEX?  If he really wanted to show a problem with the protocol he would have hacked the DEX.

Maybe he's a white hat who wants to help, rather than a black hat who wants to destroy. Better to do it on an honest exchange where it can be fixed easily than on the DEX.
hero member
Activity: 491
Merit: 500
What will happen to the orders and balances on poloniex?
hero member
Activity: 756
Merit: 502
Ok I think I see the vulnerability as well. I am inclined to believe busoni now. Hopefully the devs will get right on it.

The good news is if our benevolent attacker friend didn't withdraw his BTC everything can just be rolled back.

Clever attack.

Will you explain it after it was plugged?
hero member
Activity: 756
Merit: 502
Wow, that disappointing...
That said, I'm happy that it happened so early, before XCP has spread to other exchanges.

Also, seems that it will boost the Dex (as it should), as it seems to be much safer (or so I hope!).
hero member
Activity: 686
Merit: 500
trouble in paradise  Roll Eyes
member
Activity: 82
Merit: 10
This is as good a time as any to make a plug for the DEX.

Let's fix the issue with trolling orders so we don't have to worry about centralized points of failure ever again.

+1

Why would a hacker wanting to make a demonstration have done the deed on Poloniex and not the DEX?  If he really wanted to show a problem with the protocol he would have hacked the DEX.
sr. member
Activity: 364
Merit: 250
Owner of Poloniex
I messaged PhantomPhreak, but if any XCP developers are online right now, please message me right away.

The attacked left 35BTC in his account. He has been very cooperative so far and has asked for an address to return the BTC he took. I'll keep you all updated.
legendary
Activity: 1120
Merit: 1000
Guys, why don't we reserve judgement on Poloniex and Busoni until we hear back one way or the other from the devs. Until we hear from them, everything is just speculation.

Busoni says he explained the vulnerability, now we wait.
legendary
Activity: 882
Merit: 1002
busoni please answer how many BTC the attacker still has in his account?
and if all users BTC are safe? (I am no talking about the btc the attacker got from the 35,000 xcp sell and withdraw)
Jump to: