We all remember March 2019 hack by bignut74, btcmonkey348 and buster192 where entire hot wallet was emptied. At that time Daniel, the owner of bustabit.com had no choice but to admit to a hack and existing vulnerability to a web socket. A connection between gaming server and web server has been compromised and an attacker was able to see a bust of the game in progress allowing riding it all the way to the bust insuring maximum profit from each game. Well, looking at the graph of bignut74 it does not take a genius to see that the user did NOT play consecutive games and won big 8 games in the row. The only logical conclusion is that the bust was known before the game started, and not during the game.
After bignut74 hack the patch has been applied and Daniel refunded the lost to investors. Since the March 2019, not that I was actively looking for it, I have noticed 3 users that graph looked, somewhat interesting. Users Marketmaker, idexExchange and very recently itsjustChuckless have followed similar pattern. As there may be more users, I only spotted these three.
1) All users logged on and played for short period of time and very small number of games.
2) All users ended at very specific or close to specific total of winnings, as they had a set limit.
3) All users followed same pattern, as they did know the bust of the game in progress, but not before.
4) None of these have been publicly announced as a hack.
Let’s assume this is a hack; Given that Daniel and his staff is keeping very close tabs on the game and any abnormalities are detected it is very odd that the same wining pattern continues. Very simple database query can be run as often as one desire to detect “quick” winners that are able to cashed the game i.e. at 14.07x and game busted at 15.68 and within little over 100 games user walks away with 10 BTC in winnings.
However if this is not a hack, then someone from bustabit team is taking advantage of privileged information and using it by himself or releasing it to third party. If this is truth then this is a theft from players and investors. The three users I have mentioned walked away with total of 22 BTS there in today’s exchange rate is little over a quarter of a million USD.
I have contacted the support at bustabit and this is a copy of the email exchange I had with Daniel, Keep it in mind that the order of messages is in reverse and the only edit I did was to remove Daniels and my last name.
Hello,
I can reassure you that I have no reason to believe that any of these users were cheating in any way. Their bets do not strike me as suspicious.
Kind regards,
Daniel
Marcin:
Thank you for your respond.
Please take a look at the graphs of these users. You are very smart
person, I am sure you can figure it out.
The play/win pattern , betting style, cashouts and final total.
Would this be a hack or something else?
On 8/8/2019 12:41 AM, Daniel wrote:
Hello,
Please clarify your question or how I can help you.
Thanks,
Daniel
Daniel at bustabit:
User: (anonymous)
https[Suspicious link removed]xchange
https://www.bustabit.com/user/Marketmaker