Pages:
Author

Topic: Bitcoinica MtGox account compromised - page 35. (Read 156012 times)

vip
Activity: 308
Merit: 250
July 13, 2012, 08:21:42 AM
Once again, someone with a US IP succeed to get Bitcoinica's account credential which did not trigger any alarms since they were fully identified. Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

Thanks for the update. Can you please clarify when the theft occurred?

Unfortunately I am no longer at the office (10:21pm), and I do not have access to such data outside of the office.
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:20:37 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

That source code came from github, not from the deleted servers. On that date the servers were already gone.

Wasn't he in Germany at the the time of the hack?

I heard they were all sleeping at 2 pm GMT+1, when the hack happened Roll Eyes
hero member
Activity: 686
Merit: 500
Wat
July 13, 2012, 08:18:56 AM
*checks bitcoinica source code for intersango admin password
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 08:18:24 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

That source code came from github, not from the deleted servers. On that date the servers were already gone.

Wasn't he in Germany at the the time of the hack?
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:17:54 AM
Isn't it amazing that users with AML verification completed struggle to get $5k transfered out of MtGox, sometimes having to wait several weeks for the funds and somehow one "hacker" withdraws almost half a million quickly without anyone noticing?
Double standards much?
vip
Activity: 308
Merit: 250
July 13, 2012, 08:13:25 AM
Hi everyone

We are once again very sorry to hear what's happening to many of you and that once again Bitconica has been the victim of a theft.

As far as Mt.Gox is concerned and as Genjix explained, we did not suffer any breach or any hack, all other account are safe and the thief only targeted Bitconica's account. Mark (MagicalTux) has been in contact with many Bitcoin players since this announcement and offered any help we can give, but unfortunately all funds (USD & BTC) are no longer within our reach.

Once again, someone with a US IP succeed to get Bitcoinica's account credential which did not trigger any alarms since they were fully identified. Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

Despite our effort on securing Mt.Gox and protecting everyone's asset I would like to remind everyone that it is also your responsibility to secure your account with a very strong password and use either a Yubikey or Google Auth (You can even use both at the same time).

Of course and within our capacity we at Mt.Gox are ready to give a hand in anyway we can to help Bitconica's team.

Mt.Gox

So you Verified and lifted the limits to the Max for a 17 year old boy, Bruno there goes your unanswered question about Mtgox approving minors.

Zhoutong, In my eyes you are the one to blame because this is your fault for not letting me know you was going to sell bitcoinica to intersango. You lied and sold private property trusted in your hands. Unfortunately somebody has to take responsibility for my 16,000 missing bitcoins.

Mtgox, you verify a 17 year old, is that legal to do? Please answer.

Maria.

Let's clarify the situation, Bitcoinica is not verified as an individual but as a company.
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:10:33 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

That source code came from github, not from the deleted servers. On that date the servers were already gone.

Genjix, please explain this.

And it was also genjix who packed that tar file 6 days ago as pointed by bitclown a few posts above mine
Code:
$ tar -jtvf bitcoinica.tar.bz2 | head -n1
drwxr-xr-x genjix/genjix     0 2012-07-07 20:18 bitcoinica_legacy/

He has some splainin' to do, allright Wink
hero member
Activity: 761
Merit: 500
Mine Silent, Mine Deep
July 13, 2012, 08:09:59 AM
Once again, someone with a US IP succeed to get Bitcoinica's account credential which did not trigger any alarms since they were fully identified. Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

Thanks for the update. Can you please clarify when the theft occurred?
sr. member
Activity: 832
Merit: 250
July 13, 2012, 08:07:18 AM
Hi everyone

We are once again very sorry to hear what's happening to many of you and that once again Bitconica has been the victim of a theft.

As far as Mt.Gox is concerned and as Genjix explained, we did not suffer any breach or any hack, all other account are safe and the thief only targeted Bitconica's account. Mark (MagicalTux) has been in contact with many Bitcoin players since this announcement and offered any help we can give, but unfortunately all funds (USD & BTC) are no longer within our reach.

Once again, someone with a US IP succeed to get Bitcoinica's account credential which did not trigger any alarms since they were fully identified. Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

Despite our effort on securing Mt.Gox and protecting everyone's asset I would like to remind everyone that it is also your responsibility to secure your account with a very strong password and use either a Yubikey or Google Auth (You can even use both at the same time).

Of course and within our capacity we at Mt.Gox are ready to give a hand in anyway we can to help Bitconica's team.

Mt.Gox

So you Verified and lifted the limits to the Max for a 17 year old boy, Bruno there goes your unanswered question about Mtgox approving minors.

Zhoutong, In my eyes you are the one to blame because this is your fault for not letting me know you was going to sell bitcoinica to intersango. You lied and sold private property trusted in your hands. Unfortunately somebody has to take responsibility for my 16,000 missing bitcoins.

Mtgox, you verify a 17 year old, is that legal to do? Please answer.

Maria.
hero member
Activity: 504
Merit: 500
July 13, 2012, 08:06:54 AM
What about refusing to raise those limits at MtGox if two steps authentication isn't used?
this a million times. how about it, Gox?
full member
Activity: 154
Merit: 100
July 13, 2012, 08:05:49 AM
Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

I trust they have now put the default limits in place, haven't they?

What about refusing to raise those limits at MtGox if two steps authentication isn't used?
legendary
Activity: 1022
Merit: 1000
July 13, 2012, 08:03:57 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

That source code came from github, not from the deleted servers. On that date the servers were already gone.

Genjix, please explain this.
donator
Activity: 1120
Merit: 1001
July 13, 2012, 08:02:54 AM

Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).


can you help trace the account?
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
July 13, 2012, 07:59:16 AM
This has been one of the most stressful situations with maximum suffering I have ever experienced. I am furious and I hope everyone involved putting us through this gets what's due to them. Karma is a bitch, you fucking wankers.

Right. Because this has not been the most stressful time of my life.

I have physical health problems and need to see a doctor, but haven't had the time. On the forums I'm called a scammer and repeatedly insulted. Someone is trying to sue us. My bank gave me crap and held my money. I was borrowing cash from friends and spent 3 days eating bad muesli and cheap milk. I lost a lot of code by accident. I put a lot of work into the bitcoin.org clients page to make everything fairer, and now it will be removed, helping to recentralise bitcoin again. Electrum maybe has a security flaw and Macs have random problems. The conference needs the CFP announced soon, but I have to deal with Bitcoinica first. My health is suffering and im getting headaches. Right now is the first time I'm feeling depression, and I'm a little worried because I've never had it before but my father did. I emailed a health professional and they advised me to seek help. I've started sleeping very long, being very lethargic and apathetic. When the Bitcoinica thing first happened, I was considering suicide until Tihan said he had the funds.

Don't do too much things at the same time. Deal with Bitcoinica first. Keep in mind, that whatever you will pay out, at least 2/3 of the recipients will be complaining. But once you have paid out all, there is at least nothing left fighting about. Then you can go back to coding and be happy again.

Someone is trying to sue us.
Did you expect everyone to wait forever?


I'm currently on page 4. More pages have been added to this thread since I've started reading, albeit with posts disappearing.

I need to go on vacation. Fishing in Wisconsin with theymos sounds like fun. No internet. Just muskies.

~Bruno~
hero member
Activity: 504
Merit: 500
July 13, 2012, 07:58:48 AM
LastPass contains all your passwords. The username was [email protected].

Can someone please explain the intended meaning of the underlined sentence?

Has there been another leak of sensitive user data, in addition to theft?



by 'your', he is refering to a user of the program, not as in 'all of yours'.
legendary
Activity: 1458
Merit: 1006
July 13, 2012, 07:55:51 AM
LastPass contains all your passwords. The username was [email protected].

Can someone please explain the intended meaning of the underlined sentence?

Has there been another leak of sensitive user data, in addition to theft?

vip
Activity: 308
Merit: 250
July 13, 2012, 07:55:25 AM
Hi everyone

We are once again very sorry to hear what's happening to many of you and that once again Bitconica has been the victim of a theft.

As far as Mt.Gox is concerned and as Genjix explained, we did not suffer any breach or any hack, all other account are safe and the thief only targeted Bitconica's account. Mark (MagicalTux) has been in contact with many Bitcoin players since this announcement and offered any help we can give, but unfortunately all funds (USD & BTC) are no longer within our reach.

Once again, someone with a US IP succeed to get Bitcoinica's account credential which did not trigger any alarms since they were fully identified. Since Bitconica's account was a verified account the owner of this account asked (This happened when Zhou was still controlling Bitconica) to have his limits lifted to the maximum possible, giving the possibility to the thief to move Bitcoinica's assets to another external account (External to MtGox).

Despite our effort on securing Mt.Gox and protecting everyone's asset I would like to remind everyone that it is also your responsibility to secure your account with a very strong password and use either a Yubikey or Google Auth (You can even use both at the same time).

Of course and within our capacity we at Mt.Gox are ready to give a hand in anyway we can to help Bitconica's team.

Mt.Gox

-- EDIT --

We would like to stress that Mt.Gox Verified Bitconica as a Company and NOT as an Individual.
member
Activity: 63
Merit: 10
July 13, 2012, 07:52:36 AM
This has been one of the most stressful situations with maximum suffering I have ever experienced. I am furious and I hope everyone involved putting us through this gets what's due to them. Karma is a bitch, you fucking wankers.

Right. Because this has not been the most stressful time of my life.

I have physical health problems and need to see a doctor, but haven't had the time. On the forums I'm called a scammer and repeatedly insulted. Someone is trying to sue us. My bank gave me crap and held my money. I was borrowing cash from friends and spent 3 days eating bad muesli and cheap milk. I lost a lot of code by accident. I put a lot of work into the bitcoin.org clients page to make everything fairer, and now it will be removed, helping to recentralise bitcoin again. Electrum maybe has a security flaw and Macs have random problems. The conference needs the CFP announced soon, but I have to deal with Bitcoinica first. My health is suffering and im getting headaches. Right now is the first time I'm feeling depression, and I'm a little worried because I've never had it before but my father did. I emailed a health professional and they advised me to seek help. I've started sleeping very long, being very lethargic and apathetic. When the Bitcoinica thing first happened, I was considering suicide until Tihan said he had the funds.


Cool story bro.

http://www.youtube.com/watch?v=DksSPZTZES0

Give us our money back.

I'm only halfway through, and posts are already starting to disappear. What the mother fucking hell is going on here?

~One pissed off mother fucker!!!~


re-Quoted. Screen shot now.
hero member
Activity: 504
Merit: 500
July 13, 2012, 07:50:07 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

and if it was that long ago, it leads me into thinking it unlikely a hacker used the info to guess there was a lastpass invloved...

Who was it that orginally stated that lastpass was the source for the current MtGox login? That person stole your fucking money.....  I'd bet my Scottrade account on it....
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 07:47:39 AM
/bitcoinica_legacy/.git/logs/HEAD
Code:
0000000000000000000000000000000000000000 939e877106a5bd479f350adc6d9e4170c62df8f3 genjix  1338505438 +0200	clone: from [email protected]:bitcoinica/bitcoinica_legacy.git

hmmm... so, it was genjix who leaked the Bitcoinica source code?
That unix timestamp is Thu, 31 May 2012 23:03:58 GMT

That source code came from github, not from the deleted servers. On that date the servers were already gone.
Pages:
Jump to: