What happenedOn October 24rd 6:37am UTC+10:, Inputs.io's hot wallet, of 4000btc, was emptied by a hacker.
1 2TradeFortress claimed the hack occurred on the 26th.
3His Linode administrative account was first accessed by the hacker on Oct 23rd, from IP Address 101.0.79.18, at 11:57am UTC+10 from Australia
4.
He gained access to the account by compromising the email address "
[email protected]" and requesting a password reset from the Linode server. The reset link was automatically forwarded from the administrative email "
[email protected]" to "
[email protected]".
5He did not stop forwarding emails until October 27th UTC+10.
5TradeFortress reset his Linode Manager password and logged into it by 8:25pm UTC+10.
4Between 8:25pm UTC+10 and 6:37am UTC+10, Tradefortress did not shut down the site, he did not move any of the coins to a cold wallet, he did not report the theft to local authorities, he did not notify any depositors, and he did not stop any new users from depositing to his site.
Sometime after this but before second hack, TradeFortress enabled 2FA on his Linode Manager.
5On November 8th at 6:01am UTC+10, the server was hacked again using a direct Lish connection, bypassing 2FA and stealing an additional 160 bitcoins.
6By his own admission, TradeFortress was embezzling the deposits of new users to distribute the bitcoins to users that had lost their entire deposits during the hack.
TradeFortress did not have any bitcoins stored in a cold wallet either for CoinLenders.com or Inputs.io.
CoinLenders was affected, because it had a Inputs.io wallet.
If you are a victim.The following will help you to report to the proper authorities;
United States:http://travel.state.gov/travel/cis_pa_tw/cis/cis_4522.htmlGoal of this threadI would like Coinlenders users and Inputs.io users to post relevant information, and I would like to put together a list of users and their claims. I have requested similar documentation from TradeFortress.
I am not interested in any kind of speculation, fiction, trolling, unbacked accusations, "pity-me" stories, or any other kind of uninformative posts. They will be deleted.
Public information regarding this hack will be collated and placed here.
This is to assist in investigation, inform those at stake, perform verification and oversight, and prune useless information.
Australian law enforcement activityTradeFortress and his hosting provider are located in Australia, and although I do not have any hard evidence to post, I am sure that Australian law enforcement has been notified.
TradeFortress' identifying informationhttps://bitcointalksearch.org/topic/--327178http://www.abc.net.au/news/2013-11-08/bitcoin-site-hacked-founder-says/5078148Current plans for remunerationInputs.io accounts are being refunded partial amounts inversely proportionate to the amount of BTC they had at Inputs.io, using a sliding scale.
As a rough estimation (see blow), deposits of over 10btc are refunded less than 50%, deposits below 10btc are refunded greater than 50%.
There has been no announcement yet regarding CoinLenders Deposits.
Inputs.io and Coinlenders account balances.Please send a private message to me, or post below to be added to this list. You will be anonymous unless you explicitly tell me otherwise, or post the information publicly. They will not be verified unless I can get reputable documentation (Most likely from TradeFortress).
I am including interest, because that is owed even if TradeFortress is unable to pay it.
Users will be posted as [Username]:[BTC owed]:[BTC returned]:[
Unverified/
Verified]
CoinLendersDumbFruit:955.24559517:199.383
Anonymous:652.92445572:0:
UMaximGuns:531.87697838:0:
UAnonymous:332.2162344:0:
UAnonymous:327.3652095:0:
Usummerysnow:299.03625778:0:
UAnonymous:284.39655444:0:
UAnonymous:244:0:
Umion:236.77:0:
Udruid:222.7:0:
UBradyon:226.07010047:0:
UAnonymous:189.36658901:0:
UAnonymous:151.15913821:0:
Udwdoc1:150.42238118:0:
UAnonymous:147.46497819:0:
UAnonymous:144:
UAnonymous:112.13755308:0:
UAnonymous:102.89:0:
Udrsteve:102.13386171:0:
Uohyeahok:88:0:
Uhwmax:86.93779676:0:
UAnonymous:76.31622447:0:
Uninjaboon:75.23241838:0:
Udocdocdoc9:53.98199194:0:
UAnonymous:47:0:
Ugotpetum:43.51560284:0:
UBTCWarrior:35.62:0:
UAnonymous:32.15938119:0:
Usleger:30.88981146:0:
Ugoodtimes73:28.58:0:
U001sonkit:26.44:0:
Ucurrencyforall:21.84629652:0:
UAnonymous:21.14:0:
UAnonymous:20.62151404:0:
UAnonymous:20.01551996:0:
Uwindywinter:20:20:
U <--Mistake
[email protected]:19.89484849:0:
U expodryerase:18.51941806:0:
U MaxwellsDemon:17.45:
Uace207:16.68791006:0:
U4btconly:16.20130365:0:
Unsd:15.90443981:0:
UAnonymous:15.78:0:
UTwinWinNerD:15.55:0:
Uflmbg:15.15:0:
Ucismasu:15:0:
UDougie 12.857412:0:
UAnonymous:10.89:0:
Utoer:10.77683827:0:
UAnonymous:10.6815:0:
Udunkbc:10.5627535:0:
Udavecoin:10.05859733:0:
Ugog1:9.80594344:0:
Udoctorbit:8.7:0:
UAnonymous:8.39168696:0:
UAnonymous:8.10636761:0:
UInvalidSnack:7.69121463:0:
UAnonymous:6.28562606:0:
UC10H15N:6.00038338:0:
Uchrishastie27:5:0:
Ubatman:5:0:
Ugravity_boy:4.01865378:0:
Umisterwiser:4.00660825:0:
Ugravity_boy:4.01865378:0:
Ufavdesdu:4:0:
UDorpsgek:3.66741301:0:
Ujoele:3.65732106:0:
Umobile314:3.59998956:0:
Uezacarias:3.593:0:
UXrim:3.5423:0:
UCoinLenders01:3.42991422:0:
UAnonymous:3.14700032:0:
Umaraoz:3.0521687:0:
Udavedx:3.01:0:
Uwayner:2.97:0:
Uefc17:2.96594563:0:
Upoolbath1:2.84476076:0:
Uwheelerscw2000:2.56224724:0:
Uhsharrison:2.43970326:0:
Ugoodhope:2.08111493:0:
UEntropiaFox:1.97655724:0:
UDaytona:1.80:0:
UAnonymous:1.70787314:0:
Uartbatista:1.62:0:
Umxisaac:1.50021415:0:
U[email protected]:1.5001855:0:
Uahbartsch:1.42248522:0:
Uasanerworld: 1.09027010:0:
Usimonsaysmine:1.07027926:0:
UAnonymous:1.0610762:0:
UZedeius:1.05606876:0:
Ukilerz:1.05240088:
UNesa:1.03:0:
Uccpearce:1:0:
UTotal Owed:6514.894239
Total Paid:219.383
Users:94
Inputs.ioTomJeff:440:0:
UMiles:40:0:
Udwdoc1:20.795:8.59:
UHereToTrade:7.74:3.54:
Ulonestar108:7.44986999:0:
Usimple-dice:4.21:2.58:
U -No fee, unconfirmed.
quimpstar:2.785:1.69:
U -Unconfirmed
Anonymous:2.2:0:
UKorbman:1.1263595:0.85:
UAnonymous:1:0.74:
UAnonymous:1:0:
UAnonymous:0.55487:0.45:
UAnonymous:0.5:0.4:
UChrisJ:0.2996:0:
Ubitcoincasinoprojof:0.26:0.26:
Uniktitan132:0.2445:0.03:
Usnuff:0.2856333:0.23:
UAnonymous:0.099:0.08:
UAshu:0.08238875:0:
Uredtwitz:0.08209722:0:
UGoldBit89:0.06972042:0.06:
U -No fee, unconfirmed.
Anonymous:0.63:0.5:
Umisterwiser:0.03079955:0:
UTotal Owed: 531.4448387
Total Paid: 20
Users:23
Food for thought..I do not show this quote to imply that TradeFortress was a scammer, but that the problem that I find myself in, and how to try to avoid it, was written a year before this event took place. So I'm putting it here in case you find it as educational as I did;
This system is obviously far from perfect at the current time. For one, as it is nascent there exists the incentive to follow short term goals : build an identity up to whatever value, then strip it by taking the money and splitting. This has happened so far numerous times, and from a certain perspective it may seem the main economic activity surrounding Bitcoin at the moment, greatly compounded by the yet inept identity-valuation methods used by participants, their unwarranted self confidence (everyone thinks they’re a great judge of men, and everyone thinks their particular assumptions are both correct and warranted), their imbecillic pride manifested in the stupidest way it could, ie trying to keep “things” under wraps and all the rest of typically human failure. For the other, as it is nascent very little is in fact understood or generally known about it, and so gross mistakes happen quite cavalierly.7 -Mircea Popescu
1transaction;
http://blockchain.info/tx/9536feebe3a50b94f85ca27d56e669a7209bd4188385d55c5b97227c95cf7f742address;
http://blockchain.info/address/1EMztWbGCBBrUAHquVeNjWpJKcB8gBzAFx3https://bitcointalksearch.org/topic/m.35059664https://bitcointalksearch.org/topic/m.35053945https://bitcointalksearch.org/topic/m.36322086http://blockchain.info/tx/d9fd404d60cc65e77a0ab460524d112f1a851430ed431b5aa6840bdf9c42355f7http://trilema.com/2012/gpg-contracts/