Pages:
Author

Topic: eXch - instant exchange BTC / LN / XMR / LTC / ETH / ERC20 - page 5. (Read 15019 times)

legendary
Activity: 1456
Merit: 5874
light_warrior ... 🕯️
Have there been any cases of USDT wallet blocking by the issuer(Tether) after an exchange on your exchange?
As you can see above eXch's answer was "no".

I can say from my own experience, half a year ago, when I needed to exchange bitcoins for the dollar equivalent, I first turned my attention to Ledger Live, and after I was horrified to see a 5% commission, I realized that eXch’s commission costs of 0.5% seem simply incredible (btw, I already have Trezor). But before the exchange, I was also bothered by the same question... so I decided to turn to statistics, according to which over the past few years, a total of 1300 USDT addresses and 300 USDC addresses have been blocked.

For this reason, I chose DAI.
member
Activity: 97
Merit: 377
I don't know if this is a typo. But you need to replace one letter


It was not a typo before the recent display name change from eXch.cc to eXch, because the 'eXch.cc' was always our username so it was correct, since the first link actually leads to our Bitcointalk profile.

It became a typo a week ago after the display name change.


I have a question about lightning

I see you need "Zero-amount invoices only"

I am using Aqua wallet, which has LN integrated. The minimum invoice is 1000 sats.

Will my 1000 sats invoice work?

Sorry if it is a dumb question, I have little experience with LN.

There are no dumb questions.

I am personally not aware of how Aqua wallet works since I never used it, but if you provide me with the invoice I can look it up and help you.

I recommend creating a support ticket directly with us where we provide dedicated related to LN even when the issue is not related to our exchange (free of charge), since LN is still very fresh and there are many issues, but we like the tech behind it and would like to contribute to its popularization.

I have two follow up questions.

1. If my order becomes a backorder, will eXch use the exchange rate applicable at the time the reserves fill up and my order gets processed or the rate from when my deposit transaction confirmed? I am pretty sure it's the former, but let's see.

2. What are the possible reasons why a backorder gets refunded from your side? Is it fee related? If I began the exchange at a time when the mining fees for the coin I wanted were low, but then they doubled, would eXch process the order, request more for mining fees, or return the initial deposit?

I checked your FAQ section, but it doesn't mention any of this regarding backorders you just discussed. Perhaps you should add it, so your clients know such an option exists.

1. It's the former.

2. One example I could think of is when a backorder is too big and remains too long on sight we may just revert it to REFUND REQUEST. Let's say the backorder is asking for 50000 XMR. This would take for us at least 2-3 days to fulfill (if not more) and it will also make our 'Reserves' tab to show "0" if our overall balance is below 50000 XMR, since the backordered amount also affects our available reserve. This is the only reason why we ever force-refunded such orders. In regards to mining fees - we never change order details after a deposit confirmation independently of the conditions. If they doubled - we will still proceed with the payout. We also don't let the backorders remain for too long as we usually try to acquire external liquidity for them in order to execute them as fast as possible.

Thank you for the suggestion on adding it to FAQ, it's very likely we will do so.

This is mainly why we have the message "You can start exchange without calculating and send any amount (calculation will be performed on receipt)" right to the "Exchange" button.
Since the Reserves are shown on the same page, I didn't expect this functionality when there are no reserves left.

I checked your FAQ section, but it doesn't mention any of this regarding backorders you just discussed. Perhaps you should add it, so your clients know such an option exists.
I was going to suggest the same thing Smiley

Yeah, it's indeed very unobvious for now. We have many things to improve.

Have there been any cases of USDT wallet blocking by the issuer(Tether) after an exchange on your exchange?

No.

What guarantees do you give when exchanging my BTC for your USDT?

Nobody can guarantee that and I recommend using DAI if you need such a guarantee. However, as long as we are a project that operates in a legal scope and, say, not darknet, we are fine with Tether as well as the funds coming from our address. Tether is also well-aware of our exchange.

Also a good answer here by bitmover in that regards: https://bitcointalksearch.org/topic/m.63792374

what will happen if someone sends stolen money to this USDT ETH address, and then it goes to the client from this address?

The client will receive clean funds from an entity called 'eXch' which is tagged as a centralized exchange by most address categorization engines.

Ethereum is a non-UTXO system and there is no way to tell which exactly part of the previously received funds is being sent forward. Chain analysis systems determine the clean/dirty ratio of an Ethereum address by the percentage of incoming funds and their origin. Our clean ratio is above 50%.

in my opinion, there is a greater chance of getting depeg dai than a random usdt block (for the previous owners of these usdts)

DAI has passed many depeg stress tests successfully already. It has proven itself as a very reliable stablecoin for last years. As for USDT blocks - they happen on a weekly basis. Please check this Twitter: @usdtblacklist


Our domain exch.cx was suspended by Lyubomir Gyundzhiev from Key-Systems who misread our abuse report resulting into suspension of the victim's domain instead of attacker's.
The new domain is not working.
Not even an hour has passed since the new domain was announced, and yet a DDoS attack? really? Huh
Quote
502 Bad Gateway
The server returned an invalid or incomplete response.

It's most probably our service is currently under a DDoS attack.

exch.cx is now redirecting to exch.pw. I guess the issue is close to be solved. However, the Bad Gateway error remains here. Seems to be fixed as of 20h UTC. The redirect to exch.pw however remains.

There were some misconfigurations on our front-end servers that were fixed later. That day was pretty busy for us and everything was done with some significant delay.

Will you also create a vanity .onion name? Something that's easy to remember (partially) and very hard to reproduce. I think the way to do this is generate many vanity .onion domains, and hand-pick one that has "something extra" that rolls off the tongue nicely.

We thought about that, but the efficiency and usefulness of a such address is very questionable.

Having a vanity address won't protect from phishing independently of the invested power to generate it.

Standard security practices for remembering and visiting HSv3 appeal against relying on vanity-generated addresses or their recognizability. During Tor's transition to HSv3 addresses, this topic was widely discussed across Tor Project's discussion boards in regards to the new address format's increased exposure to phishing. Since we have an easy rememberable clearnet domain which lists our valid .onion and see no reason to use other sources other than our clearnet website and maybe this Bitcointalk thread to get the correct .onion.

Moreover, our clearnet website doesn't block Tor like most other projects out there so there is absolutely nothing that would prevent a Tor user from visiting our clearnet domain to get the .onion address. Additionally, there is KycNotMe - a project that is now considered to be the main anti-phishing directory for crypto-related services. Even the DarkNetBible - something that many DNM and Tor users consider a "holy" manual for using Tor - stopped listing crypto-related services and now directly recommends OrangeFren and KycNotMe only.

Given all this, it's a mystery to me how people still manage to get phished given that our genuine .onion is findable in 1 click from many legitimate sources, including our website.

We are also glad to inform you that our latest app's release (1.2.0) makes it possible to set reserve notifications and alerts, so there is no more need to check our website for certain coins reserve updates manually.
Wouldn't it be better to automate the reserve refill so that the balance is refilled every hour or two instead of doing it manually? This will be easier, as if I find that the DAI reserve is zero, this means that I need to wait for the next hour to find that the balance has been refilled.

Stablecoin refills are already automated via Thorchain, but there are people who constantly check our XMR reserves manually and it's not something we currently automate so app users makes it easy for people who look for XMR reserves to appear.

Any updates or estimates for adding Liquid network assets (L-BTC and L-USDT)?

Not yet.

Will you also create a vanity .onion name? Something that's easy to remember (partially) and very hard to reproduce. I think the way to do this is generate many vanity .onion domains, and hand-pick one that has "something extra" that rolls off the tongue nicely.
That's a good idea.
This could make it much harder for scammers to trick users with fake onion links.

Not at all - if you check some mixers who had/have vanity generated addresses, they were/are targeted even more with vanity-generated phishing. Phishing by typosquatting is something much more effective than email spam nowadays.

Let's say we manage to generate this address:

exchcxxxxxxxxxxxxxxxxxvjvmnwj33g4wviuxqzq47emieaxjaxxxxx.onion

It will still be overplayed with typosquatted addresses in the following example:

exchccxxxxxxxxxxxxxxxxvjvmnwj33g4wviuxqzq47emieaxjaxxxxx.onion
exchccxxxxxxxxxxxxxxxvxjvmnwj33g4wviuxqzq47emieaxjaxxxxx.onion
exchxxxxxxxxxxxxxxxxxxvjvmnwj33g4wviuxqzq47emieaxjaxxxxx.onion
exchxxxxxxxxxxxxxxxxnwj3vjvmnwj33g4wviuxqzq47emieacxxxxx.onion
exchxcxxxxxxxxxxxxxxnwj3vjvmnwj33g4wviuxqzq47emieacxxxxx.onion
exxchvvxxxnxxxxxxxxxnwj3vjvmnwj33g4wviuxqzq47emieacxxxxx.onion
exchcccxxxxxxxxxxxxxnwj3vjvmnwj33g4wviuxqzq47emieacxxxxx.onion

and so on...

Phishing is a very tricky business and will always be there for any resource doing money transfers. It targets people who have bad personal security practices. Just in the same way Ethereum-alike address/transaction poisoning works to expect an uncareful user to copy the destination address from his last transaction history which turned to work pretty efficiently and there were millions stolens already this way. Nobody can be blamed here but users themselves.

While people simply "doing it wrong" by copying .onion addresses from random sites and not official ones, it will always be their problem and we are refusing to take any responsibility for their actions.

Also note that it's absolutely nowhere we stated that we are an .onion-first exchange, since we operate in a legal space as an absolutely legal project with a registered company (unlike some scammers who lie about having company registered in Seychelles) and have a clearnet domain that doesn't block Tor users and doesn't use Cloudflare. Please just use it, including for a purpose of finding our .onion, since it's what clearnet sites exist for.


What do you think about having a small informative banner on your website about your official pages and domains?

There are significant upcoming changes in that regards, but it won't be done this way.

OK, you have such information in the footer, many people don't even get to the footer but go directly to the exchange process. I am convinced that it would be very useful to have some kind of warning at the top of the page.
Your fight against phishing sites has only just begun, the more you grow, the more people like Animesh Roy will appear.

The word "fight" itself doesn't scare us a little bit since this whole project is already some kind of fight itself, so we were prepared for it.

What in regards to your concerns to phishing becoming more frequent - I'll slightly disagree here.

This specific phishing campaign is not like others that existed in the past (even targeting other projects) or will exist in the future any soon. You should understand that the amount of time and effort spent only to _prepare it_ are exorbital.

If you check our recent article and dig a bit yourself, you will see that the phisher himself spent a whole 2023 year to only prepare this campaign and he had results only in the recent months. There is a LOT of work he done worth far more than a salary of a full time programmer for a whole year. Phishers like this one is very rare from our experience and this guy literally just threw a year of his hard work to the bin by making us trace him, which took only 3-5 hours of investigation to catch this guy having all the recent data that he exposed about himself and his phishing operation and additional 2 hours to write an article.

From one side he looks quite skilled and creative, but from another side he is pretty dumb to spend so much time and money on something so easily traceable, because the most of his fruits were given by his clearnet domains, where everything is pretty much traceable.

I think who will fight there are phishers like Animesh themselves, in case after our disclosure someone else dares to do it of course, since we pretty much gave the sign to anyone who wish to mess with eXch Security Team to think twice before doing so. For us it will always be a very quick task to track and expose them but for them it's for sure a lot of work to setup such an efficient scheme.

What in regards to some one-time low-effort phishing sites that will only exist within the Tor indexers and not beyond - not that we would care much about it since they are barely effective and people who generally want to use some link from them actually wish to get scammed, so we can't stop them from losing their money voluntarily. They existed before this specific phishing campaign already and will exist after and they are not something that will be on our radar. We are interested in efficient campaigns like this recent one and predict everyone who is behind one ending like that guy from India.

We also won't agree on the opinion that the phishing is a result of some our mistakes - they are not and there are none. Everything you need to not get phished is just to visit our clearnet site or this thread in order to add the correct .onion to your favorites. We also had a link to our Bitcointalk thread on our website from a very relaunch of our project. It's just some Tor users who often surf darknet under the influence of chemical substances in a hurry having 100+ tabs opened simultaneously end by getting scammed due to their own negligence and we nor anybody else can help them unfortunately. The guy who got scammed for 1 ETH was this kind of user exactly, but I'd rather not to go into personalities.

Don't forget also that if we wouldn't expose this phishing campaign and start writing about it, nobody ever would even hear about it, since victims who got scammed managed to do it out of their very uncareful behaviour.

It's really very hard to get phished being an eXch user, given that we are a clearnet-first project and not some darknet site. The investigative report we published is not a sign of sympathy to phished users by the way, since as I explained before, it's *very* and again - *VERY* hard to even find and use a phishing copy of our .onion website.

legendary
Activity: 3668
Merit: 6382
Looking for campaign manager? Contact icopress!
Your fight against phishing sites has only just begun

Indeed. And it just occurred to me that although I've talked about this not long ago, I didn't warn eXch explicitly:
From what I've seen not so long ago on another website that became very popular and next the number of phishing sites started to grow, the next step was that the phishing sites started reporting the original site (!!) to search engines as copy/clone/fraud (!!).
Imho you (eXch) should think one more step ahead and prepare your homework well.
legendary
Activity: 3248
Merit: 3098
The domain redirection from exch.cx to exch.pw will be reverted within 2 days, leaving three separate domains operable without redirection: exch.cx, exch.pw and exch.is (TBD). We are also in a process of acquisition of some more presentable domain name which will be announced once complete.

What do you think about having a small informative banner on your website about your official pages and domains?
OK, you have such information in the footer, many people don't even get to the footer but go directly to the exchange process. I am convinced that it would be very useful to have some kind of warning at the top of the page.
Your fight against phishing sites has only just begun, the more you grow, the more people like Animesh Roy will appear.
legendary
Activity: 2534
Merit: 1713
Top Crypto Casino
I have just seen this, thank you for the initiative. I have taken the opportunity to enter the free raffle and would like to thank those parties involved in making this happen.

You can join the third Raffle and try to win a Custom eXch Cryptosteel Capsule!  

[FREE RAFFLE] - Custom eXch Cryptosteel Capsule (#3)!


Quote
legendary
Activity: 2492
Merit: 2150
Crypto Swap Exchange
unless somebody else wants to do it)

Done:

"Swp is not a phishing site. I will suggest to their admin that they change their design."

which was a reply to some kind of series of replies after yet another known legitimate similar resource operator "tor[.]fish" claimed the following:

Quote from:  TOR.FISH (TDF) admin's post on Dread
"We were approached by a site going by the name of swp[dot]cx about a week ago and offered a large amount of money to list them (which we refused as we don't operate that way). A few days later, another offer from another very suspiciously similar looking exchange. Clearly someone is creating a series of these sites."

That makes it clear that Animesh Roy who is behind SWP[.]CX has used the money he obtained from scamming eXch users by phishing to bribe the DDF admin in order to get his scam platform boosted, given the significant popularity of DDF.

What makes it even more disastrous is that even an admin of a less popular resource TOR[.]FISH (TDF) refused the bribe in order to not risk their reputation because they must be mature enough to understand that it worth a lot more than just money.

This is where also DARK.FAIL's reputation comes to end, exposing this platform as a cheap liar with non-existent ethics capable of thinking only short-term, because SWP[.]CX will eventually exit-scam and forget about the Internet after someone sends him above 5 BTC which is enough money to rebuild some small village in India, while DARK.FAIL's reputation will remain damaged forever.

To finish this article on an additional note, we would like to inform our readers that Njalla/Sarek.fi (a one-man operation domain registrar by Peter Sunde) ignored all our reports and requests to suspend malicious domains mentioned in this article belonging to this scammer. It is widely known that Njalla/Sarek widely popular many years ago but after starting suspending domains and servers purchased from him that host websites that oppose his personal views on some political and controversial topics (like COVID), his service reputation decreased significantly due to people from many privacy-centric communities advocating against using his services. This also demonstrates how Peter Sunde is actively supporting phishers on his domain registrar and hosting, while bashing free speech which he used as his marketing gimmick when he launched his platforms.
member
Activity: 97
Merit: 377
We have released a publication of a full coverage on the phishing situation.

Who is Animesh Roy and how he scams people.
The journey from a sophisticated phishing scheme to bribing an anti-phishing resource DARK.FAIL.


Available at https://anir0y-scams.info


Tor mirror: http://xxkdkmhcrw7mug2nhtorvsusrydoqtfxggeu3rxcxglh3jk7ltmlmeqd.onion



(This format because it's quite a long read with many details and screenshots to make it as a forum post, but I might eventually make a mirror of it in this post later, unless somebody else wants to do it)
legendary
Activity: 1680
Merit: 6524
Fully-fledged Merit Cycler|Spambuster'23|Pie Baker
You can join the third Raffle and try to win a Custom eXch Cryptosteel Capsule!

Thank you paid2 and eXch for another raffle! For more visibility, the raffle was announced in Romanian board too, in a topic dedicated to such announcements, but also in the translation of OP.

Good luck to all participants and many thanks for these prizes!
hero member
Activity: 504
Merit: 1065
Crypto Swap Exchange


You can join the third Raffle and try to win a Custom eXch Cryptosteel Capsule!  

[FREE RAFFLE] - Custom eXch Cryptosteel Capsule (#3)!


Quote
legendary
Activity: 2212
Merit: 7064
Cashback 15%
Finally!
Bitcointalk administartion is getting older and slower, but they get things done.  Wink

Will post on other updates/changes/answers later.
Any updates or estimates for adding Liquid network assets (L-BTC and L-USDT)?

Will you also create a vanity .onion name? Something that's easy to remember (partially) and very hard to reproduce. I think the way to do this is generate many vanity .onion domains, and hand-pick one that has "something extra" that rolls off the tongue nicely.
That's a good idea.
This could make it much harder for scammers to trick users with fake onion links.
legendary
Activity: 3248
Merit: 3098
We are also glad to inform you that our latest app's release (1.2.0) makes it possible to set reserve notifications and alerts, so there is no more need to check our website for certain coins reserve updates manually.
Wouldn't it be better to automate the reserve refill so that the balance is refilled every hour or two instead of doing it manually? This will be easier, as if I find that the DAI reserve is zero, this means that I need to wait for the next hour to find that the balance has been refilled.

I did not understand that they update the wallet reserve balance manually, but the new implementation will help users not to have to manually check the site to have information about whether the reserves have been topped up.
Everything is automatic, and you can receive notifications from the app about changes in the balance of reserves. You don't have to refresh the site anymore for that.
legendary
Activity: 2506
Merit: 3645
Buy/Sell crypto at BestChange
We are also glad to inform you that our latest app's release (1.2.0) makes it possible to set reserve notifications and alerts, so there is no more need to check our website for certain coins reserve updates manually.
Wouldn't it be better to automate the reserve refill so that the balance is refilled every hour or two instead of doing it manually? This will be easier, as if I find that the DAI reserve is zero, this means that I need to wait for the next hour to find that the balance has been refilled.
legendary
Activity: 3290
Merit: 16489
Thick-Skinned Gang Leader and Golden Feather 2021
The domain redirection from exch.cx to exch.pw will be reverted within 2 days, leaving three separate domains operable without redirection: exch.cx, exch.pw and exch.is (TBD). We are also in a process of acquisition of some more presentable domain name which will be announced once complete.
Will you also create a vanity .onion name? Something that's easy to remember (partially) and very hard to reproduce. I think the way to do this is generate many vanity .onion domains, and hand-pick one that has "something extra" that rolls off the tongue nicely.
member
Activity: 97
Merit: 377
We would like to thank the forum administration to finally consider our username change, which was absolutely important.

We are also glad to inform you that our latest app's release (1.2.0) makes it possible to set reserve notifications and alerts, so there is no more need to check our website for certain coins reserve updates manually.

The domain redirection from exch.cx to exch.pw will be reverted within 2 days, leaving three separate domains operable without redirection: exch.cx, exch.pw and exch.is (TBD). We are also in a process of acquisition of some more presentable domain name which will be announced once complete.

Will post on other updates/changes/answers later.

Cheers.
legendary
Activity: 2212
Merit: 7064
Cashback 15%
Our domain exch.cx was suspended by Lyubomir Gyundzhiev from Key-Systems who misread our abuse report resulting into suspension of the victim's domain instead of attacker's.
I can't believe ''mistakes'' like this are actually happening  Roll Eyes
Scammers probably organized paid campaign against eXch website with many reports  Tongue

New domain is working fine for me and it is still redirecting from main domain.


legendary
Activity: 2212
Merit: 5622
Non-custodial BTC Wallet
I hope you solve the problem with the domain soon

I am still waiting for the answer to this question,  as i want to convert some coins to btc lightning.
When the domains gets back i would like to convert.

I have a question about lightning

I see you need "Zero-amount invoices only"



I am using Aqua wallet, which has LN integrated. The minimum invoice is 1000 sats.

Will my 1000 sats invoice work?
legendary
Activity: 3906
Merit: 6249
Decentralization Maximalist
exch.cx is now redirecting to exch.pw. I guess the issue is close to be solved. However, the Bad Gateway error remains here. Seems to be fixed as of 20h UTC. The redirect to exch.pw however remains.
legendary
Activity: 2506
Merit: 3645
Buy/Sell crypto at BestChange
Our domain exch.cx was suspended by Lyubomir Gyundzhiev from Key-Systems who misread our abuse report resulting into suspension of the victim's domain instead of attacker's.
The new domain is not working.
Not even an hour has passed since the new domain was announced, and yet a DDoS attack? really? Huh
Quote
502 Bad Gateway
The server returned an invalid or incomplete response.

It's most probably our service is currently under a DDoS attack.
hero member
Activity: 504
Merit: 1065
Crypto Swap Exchange
We will be moving to some new domain zone soon that is not managed by CentralNic or Key-Systems, since these companies demonstrated inability to handle simple issues and even making negligent harm during issue resolution.

Wow what a bunch of assholes!  Shocked

I was not aware that it was even possible to be so lazy at work, wtf..
I hope that the situation will be solved asap.

member
Activity: 97
Merit: 377
Our domain exch.cx was suspended by Lyubomir Gyundzhiev from Key-Systems who misread our abuse report resulting into suspension of the victim's domain instead of attacker's.

Welcome to 2024 where incompetence is an important skill for being employed by domain registrar companies. The inability to read simple texts is awarded.

Accidently suspending something like a multi-million company's domain must be some kind of trend nowadays.  

Temporarily new domain till these guys resolve it: exch.PW

https://exch.pw




We will be moving to some new domain zone soon that is not managed by CentralNic or Key-Systems, since these companies demonstrated inability to handle simple issues and even making negligent harm during issue resolution.

UPDATE:

After making several phone calls to CentralNic and Key-Systems, exch.CX seems to be unsuspended and is back online now, but we'll keep exch.PW redirection for a few while to ensure nothing breaks again.
Pages:
Jump to: