Pages:
Author

Topic: Cryptoine.com HACKED [race condition bug] [exchange closed] - page 2. (Read 3397 times)

sr. member
Activity: 348
Merit: 250
Feel like alot of sites have been hacked recently, first it was lendo then evolution now this  Shocked

Evolution was not exactly hacked, the administrator shut it down and stole everyone's coins. When Bter got "hacked" there were suspicions it was an inside job, but nobody can prove if t was or wasn't. Evolution was definitely an inside job.
hero member
Activity: 490
Merit: 500
Feel like alot of sites have been hacked recently, first it was lendo then evolution now this  Shocked
legendary
Activity: 1778
Merit: 1043
#Free market
Again..so many bitcoin exchange/trading sites hacked.

Its a warning to everyone to not keep a lot of money in exchanger/trading site.

Is there any information about the total money stolen by the hacker?


No I didn't find any other article about the presumed hack, we should wait a couple of days and I am sure they will give the full and clear explanation. However this is really impressive, one after the other.
sr. member
Activity: 348
Merit: 250
It's not long ago since allcrypt was hacked. The hackers seem to be targeting the little exchanges. I'm surprised they considered it worth hacking either cryptoine or allcrypt. Neither of them did any big amounts of trading.
hero member
Activity: 714
Merit: 500
Another exchange hacked, if they will say "our cold wallet has been hacked" I don't trust them. They are kidding us, and I will never trust what they will say (WTF).
legendary
Activity: 3500
Merit: 1354
Again..so many bitcoin exchange/trading sites hacked.

Its a warning to everyone to not keep a lot of money in exchanger/trading site.

Is there any information about the total money stolen by the hacker?



member
Activity: 112
Merit: 10
Hey guys, today I have opened https://cryptoine.com/ and found this message :

Unfortunately, cryptoine was hacked.

The hacker found some race condition bug in our trading engine. Manipulation of orders gave him false balances.

Soon we reveal more details.



 Roll Eyes I don't know what should I think.

Usually the next message talks about how much money is gone. Then.....
legendary
Activity: 1778
Merit: 1043
#Free market
Hey guys, today I have opened https://cryptoine.com/ and found this message :


2015-04-04 09:15 UTC
Users will receive 100% XMG refund. Thanks to joelao95 (@coinmagi) 14996 XMG donation.


2015-04-03 16:00 UTC
Please withdraw your coins, you should do it ASAP!

This website and all services will be unavailable after April 30 2015.


2015-03-27 21:26 UTC

Users will receive a refund in the following amounts:

40% bitcoin,
40% litecoin,
90% urocoin,
65% dogecoin,
40% bitcoinscrypt,
82% magi,
40% darkcoin,
50% dogecoindark,
40% cannabis
100% of other coins (or equivalent in other cryptocurrency)
This applies to balances before attacker activity! (2015-03-24 03:15)


2015-03-26 08:36 UTC

We apologize everyone, and thank you all for your understanding.

Attacker acted in hours from 3:15 to 10:00 UTC.

Cryptoine database is reversed to 2015-03-24 03:08 UTC and frozen.

In response to many questions...

There was no break-in to the system
There was no leak of data
Wallet private keys are safe and not compromised
The attacker was not able to execute any external code
The bug has been located and fixed. However, the losses are irreversible. We plan to complete the activity of exchange.

We will enable withdrawals in April 2015.

It's sad to say goodbye to all crypto-community. We need to take a few months break. But we will back stronger and more experienced than ever before.



2015-03-24 19:45 UTC

Our hot wallets was drained, coins: bitcoin, litecoin, urocoin, dogecoin, bitcoinscrypt, magi, darkcoin, dogecoindark, cannabis

All coins that we have, will be returned to users. Coins stolen - in correspondingly smaller quantities.

We had wallets in the ratio 60%/40% (hot/cold).

withdrawals made by hacker:

address                                 amount          coin          ip                date
LN6Y9Etr5B1p6A7DdkUGUef9U4tV1NajYa    500             litecoin      46.98.75.23    2015-03-24 09:00:22.886758
LN6Y9Etr5B1p6A7DdkUGUef9U4tV1NajYa    24.99746504     litecoin      46.98.75.23    2015-03-24 08:28:21.178608
1HF3WND3pG9VEW6Kt7Qj33LoCqVbFpHp2n    0.1             bitcoin       46.98.75.23    2015-03-24 08:20:04.507378
LN6Y9Etr5B1p6A7DdkUGUef9U4tV1NajYa    7.94331864      litecoin      46.98.75.23    2015-03-24 08:06:02.539477
Um2fYEPJ9uVnC31bxaFWBD7PmrzhgUNE2D    16.89396348     urocoin       46.98.75.23    2015-03-24 08:04:50.16697
DHXBCX6qsayWYdTw9DygE5pmBfaQG9TxUk    36661.31739499  dogecoin      46.98.78.245    2015-03-24 07:16:00.387179
1NuEdUhdwVsuFg2noqpNjcpBamEJMYXHUv    2999.99943972   bitcoinscrypt 46.98.78.245    2015-03-24 07:02:02.404771
DHXBCX6qsayWYdTw9DygE5pmBfaQG9TxUk    32265.60946069  dogecoin      46.98.78.245    2015-03-24 05:40:55.727633
99grxHJ2cMAZpbtqbNaTbcpnNjxQ2XoGs8    14996.31229316  magi          46.98.78.245    2015-03-24 05:33:57.490186
Xe6duo43m3xWb2Hw3CFVo3EJJ56m29L5kg    15.44527325     darkcoin      46.98.78.245    2015-03-24 05:25:27.019065
D5AuHhndAvFARTJ9MJ8qJkJgC1iHGNVy42    219999.99997229 dogecoindark  46.98.78.245    2015-03-24 05:24:15.654911
CbtR69smzynN1MfTZXmWje9Ay8VgeWgfxz    2156.27062232   cannabis      46.98.78.245    2015-03-24 05:21:52.423902
1NuEdUhdwVsuFg2noqpNjcpBamEJMYXHUv    8459.64676958   bitcoinscrypt 46.98.78.245    2015-03-24 05:19:37.350262
DHXBCX6qsayWYdTw9DygE5pmBfaQG9TxUk    265334.39030659 dogecoin      46.98.78.245    2015-03-24 05:10:24.015617
LN6Y9Etr5B1p6A7DdkUGUef9U4tV1NajYa    2.16209537      litecoin      46.98.33.104    2015-03-24 04:34:30.514059
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    0.5             bitcoin       46.98.33.104    2015-03-24 04:31:50.770491
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    0.5             bitcoin       46.98.33.104    2015-03-24 04:28:40.170138
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    1               bitcoin       46.98.33.104    2015-03-24 04:27:57.658323
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    1               bitcoin       46.98.33.104    2015-03-24 04:23:13.164357
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    1               bitcoin       46.98.33.104    2015-03-24 04:21:27.592489
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    1               bitcoin       46.98.33.104    2015-03-24 04:18:45.405848
1Dwoam5EXn6g1NuAK8moEd5cpDvUFcqvPi    0.5             bitcoin       46.98.33.104    2015-03-24 04:16:58.138757
DGbs2YfkN5n5sALDdZmSRpdPa5mVtW5HQX    6               dogecoin      46.98.33.104    2015-03-24 03:29:29.110043
Registered to e-mail addresses: [email protected], [email protected], [email protected]



2015-03-24 10:00 UTC

Unfortunately, cryptoine was hacked.

The hacker found some race condition bug in our trading engine. Manipulation of orders gave him false balances.

Soon we reveal more details.



Here an article about what was happened to Cryptoine.com :

[...] Despite all of these – and other – security precautions, you still run the risk of discovering a bug once the damage has been done. Unfortunately for the Cryptoine team, this is exactly what happened overnight. According to the message posted on the website’s main page, a hacker managed to exploit a race condition bug in the trading engine.

Because of this race condition exploit, the hacker [apparently, it was one individual as far as we know] managed to manipulate several of the exchange’s orders and create a fake balance for himself/herself. It remains unclear whether or not this hacker managed to withdraw any of the funds, as the Cryptoine team has not revealed those details yet.


More at: http://btcfeed.net/news/bitcoin-exchange-cryptoine-hacked-due-to-trading-engine-bug/


 Roll Eyes I don't know what should I think. Another thread, same end....
Pages:
Jump to: