Author

Topic: FreeBitco.in-$200 FreeBTC⭐Win Lambo🔥0.2BTC DailyJackpot🏆$32,500 Wager Contest - page 133. (Read 559567 times)

member
Activity: 92
Merit: 36
hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.
newbie
Activity: 7
Merit: 0
hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.
newbie
Activity: 22
Merit: 1
seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js

We need to figure out what's injecting that script into the freebitco.in website's HTML. It doesn't seem to be coming from their end, based on what I can see. My HTML source code is clean and free of any suspicious js calls from cashtravel(dot)info domain.


As far as I can see, malicious code is added to main site document named "?op=home"

Below some screenshots how it looks on my side.
https://www.talkimg.com/images/2024/04/09/j2CCf.png
https://www.talkimg.com/images/2024/04/09/j2QYZ.png
https://www.talkimg.com/images/2024/04/09/j2Gi8.png

Edit:
And also in default index document.
https://www.talkimg.com/images/2024/04/09/j2P49.png
member
Activity: 92
Merit: 36
hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
hero member
Activity: 1456
Merit: 940
🇺🇦 Glory to Ukraine!
seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js

We need to figure out what's injecting that script into the freebitco.in website's HTML. It doesn't seem to be coming from their end, based on what I can see. My HTML source code is clean and free of any suspicious js calls from cashtravel(dot)info domain.
legendary
Activity: 3052
Merit: 2309
As far as I know, car prices have skyrocketed in the last few years all over the world.  Is the price of a Lambo actually still only $200,000 in the US? Has FreeBitco adjusted their top prize to account for inflation?  Cheesy


The price of such a luxury car can vary greatly depending on the trim and options. As far as I know, the price of the Lambo Huracan starts at ~$250k and can go up to ~$350k this year. In any case, I don't think it matters since all previous winners of the Lambo lottery most likely preferred to get the prize in BTC equivalent rather than a car.
newbie
Activity: 7
Merit: 0
hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.
newbie
Activity: 14
Merit: 1
When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.

Oh, that's very interesting finding.
My account has different ID, but I believe that scammers have changed the script few hours ago to attack another active user.

I've reported the sire where thr script is hosted for abuse and the bitwrecken domain
legendary
Activity: 2464
Merit: 1039
Bitcoin Trader
As far as I know, car prices have skyrocketed in the last few years all over the world.  Is the price of a Lambo actually still only $200,000 in the US? Has FreeBitco adjusted their top prize to account for inflation?  Cheesy

Never dreamed of owning a Lambo let alone hoping to get it from this site by collecting gold tickets, I actually don't know if the price of the car has increased due to inflation, if indeed the price has increased I'm sure this site has taken it into account well or maybe there is a series or the type of Lambo that is currently worth $200k, no one knows and I'm not a car lover and don't know for sure its current value, we don't need to doubt this team either because they have given away Lambos so far up to the current round. I'm sure the lucky people who have gotten it already know that.

The $200k price may also just be an estimate but I think a prize of that size is worth it and perhaps not all winners take their Lambo and just exchange bitcoins from the winnings as it might be difficult to pick up the Lambo and receive it from across the country not to mention there will be tax difficulties too other fees, so people prefer to exchange it for bitcoin rather than Lambo, BTW I forgot what round it is now, isn't it already into round 10, who won? It seems I haven't seen a winner in round 10 until now.  Grin
newbie
Activity: 22
Merit: 1
When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.

Oh, that's very interesting finding.
My account has different ID, but I believe that scammers have changed the script few hours ago to attack another active user.
newbie
Activity: 14
Merit: 1
When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.
newbie
Activity: 22
Merit: 1
When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.
newbie
Activity: 14
Merit: 1
seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js
newbie
Activity: 14
Merit: 1
In logs I saw loading a strange js sript so I blocked it with browser plugin and then I managed to withdraw my funds.
+
Now everything works as usual, so I guess I will never know what happened.

- You are unable to understand the "js sript" that you have sucessfully "blocked"? Around here there are people who can help you.

Hey guys I have found the malicious js script on my end I'll paste in on pastebin

this is how its loaded in..... when I check under network in chrome screen shot is as below

https://i.ibb.co/YLBMyvq/Screenshot-2024-04-10-01-24-48.png

This is the pastebin of it https://pastebin.ai/eo0q78pbuj
newbie
Activity: 14
Merit: 1
Hi,
Today, I was playing Muli-BTC as usual and then after some time my account has been locked.
I have only one account, I was not using any VPN and I was not using any bots.
I'm highroller and premium user since the beginning of this program. I'm active FBC user.
As normal I was just using built-in feature "auto-bet" and that's all.
In my history I made a lot of deposits and withdrawals and I've never had a problem.
 
Now when I'm logged in, I have just a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds."

After some time, e-mail address has changed and at present it is:
Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds

https://www.talkimg.com/images/2024/04/09/VeLqf.png

That's very disturbing.


I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"

https://www.talkimg.com/images/2024/04/09/Ve7Sw.png

What the heck?

 don t send nothing,   you need an new device  that you dont used on your internet, and try open your account on other device out of your internet provider. , if they have your email address, , i think you need care of too, open your email on another device out of your internet provider, and cahnge your passs keys, enable 2fa in your email, wrote the key of 2fa on paper, and disable phone recovery of your accounts...dont send any bit for anyone.

Yeah, I know. Like I said before I managed to withdraw all BTC funds from my account.
I have also some quite big bag of FUN token there, but it's locked. I will try to use them when FUN savings matured.

Now, fbc page is working as normal, but in case that my account can be compromised I will not use it anymore.
Pity, because I have unlocked all premium benefits and I will have to start over again.

Anyway, it could have ended much worse.

I checked this on different clean device which was never used for fbc (different OS, different browser, different DNS servers) and still my session was somehow hijacked.
It's also possible that my router is compromised but it's highly unlikely.
From my point of view.. I know it's hard to believe and even I have doubts, but it looks like fbc had some security breach or some 3rd party service they were using. Attackers were targeting only some small group of users (including me) and they managed do inject malicious script only for some accounts.
For a week or so I was also getting notifications about change in deposit address (change to P2SH segwit addresses started with 3...), but I ignored that because I didn't plan to make deposits.
Everything was looking legitimate. This message was looking exactly the same as any other notification on fbc site. Same fonts, same colors, etc.

Now everything works as usual, so I guess I will never know what happened.



That's the message I was getting about thr deposit addresses.....


Hmmm
newbie
Activity: 22
Merit: 1
Hi,
Today, I was playing Muli-BTC as usual and then after some time my account has been locked.
I have only one account, I was not using any VPN and I was not using any bots.
I'm highroller and premium user since the beginning of this program. I'm active FBC user.
As normal I was just using built-in feature "auto-bet" and that's all.
In my history I made a lot of deposits and withdrawals and I've never had a problem.
 
Now when I'm logged in, I have just a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds."

After some time, e-mail address has changed and at present it is:
Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds

https://www.talkimg.com/images/2024/04/09/VeLqf.png

That's very disturbing.


I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"

https://www.talkimg.com/images/2024/04/09/Ve7Sw.png

What the heck?

 don t send nothing,   you need an new device  that you dont used on your internet, and try open your account on other device out of your internet provider. , if they have your email address, , i think you need care of too, open your email on another device out of your internet provider, and cahnge your passs keys, enable 2fa in your email, wrote the key of 2fa on paper, and disable phone recovery of your accounts...dont send any bit for anyone.

Yeah, I know. Like I said before I managed to withdraw all BTC funds from my account.
I have also some quite big bag of FUN token there, but it's locked. I will try to use them when FUN savings matured.

Now, fbc page is working as normal, but in case that my account can be compromised I will not use it anymore.
Pity, because I have unlocked all premium benefits and I will have to start over again.

Anyway, it could have ended much worse.

I checked this on different clean device which was never used for fbc (different OS, different browser, different DNS servers) and still my session was somehow hijacked.
It's also possible that my router is compromised but it's highly unlikely.
From my point of view.. I know it's hard to believe and even I have doubts, but it looks like fbc had some security breach or some 3rd party service they were using. Attackers were targeting only some small group of users (including me) and they managed do inject malicious script only for some accounts.
For a week or so I was also getting notifications about change in deposit address (change to P2SH segwit addresses started with 3...), but I ignored that because I didn't plan to make deposits.
Everything was looking legitimate. This message was looking exactly the same as any other notification on fbc site. Same fonts, same colors, etc.

Now everything works as usual, so I guess I will never know what happened.

ESG
member
Activity: 145
Merit: 54
store secretK on Secret place is almost impossible
Hi,
Today, I was playing Muli-BTC as usual and then after some time my account has been locked.
I have only one account, I was not using any VPN and I was not using any bots.
I'm highroller and premium user since the beginning of this program. I'm active FBC user.
As normal I was just using built-in feature "auto-bet" and that's all.
In my history I made a lot of deposits and withdrawals and I've never had a problem.
 
Now when I'm logged in, I have just a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds."

After some time, e-mail address has changed and at present it is:
Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds



That's very disturbing.


I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"



What the heck?

 don t send nothing,   you need an new device  that you dont used on your internet, and try open your account on other device out of your internet provider. , if they have your email address, , i think you need care of too, open your email on another device out of your internet provider, and cahnge your passs keys, enable 2fa in your email, wrote the key of 2fa on paper, and disable phone recovery of your accounts...dont send any bit for anyone.
newbie
Activity: 22
Merit: 1
Hard to describe it, but it looks like attacker injected malicious js script but not on my side.
I was using fbc on Linux machine with different browser just for fbc.
My account has 2FA enabled.

I wiped all my browser history (all of it), tried on a different browser in private/incognito mode, I even changed the operating system (to Windows 10) and even DNS settings - everything was exactly the same - blank page with message about locked account.
In logs I saw loading a strange js sript so I blocked it with browser plugin and then I managed to withdraw my funds.

I was acting in panic mode so I withdrawed all my funds by Instant method.
They are already on my wallet.

Messages from scammers:
https://www.talkimg.com/images/2024/04/09/Vqumd.png

Edit:
I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"
https://www.talkimg.com/images/2024/04/09/Ve7Sw.png
Freebitco doesn't have telegram support system, and the email you shared isn’t the official support email address of Freebitco. Therefore, your browser has been indeed hacked by someone. Otherwise, your desktop has been compromised. Haven't you tried to login from another browser or device to your Freebitco account? Which browser you are using now? Try to login to all the accounts on another device instead of sending anything to the hacker.

I'm using recent version of Chromium, but the same issue was visible on Firefox and Librewolf.
sr. member
Activity: 1680
Merit: 379
Top Crypto Casino
Hi,
Today, I was playing Muli-BTC as usual and then after some time my account has been locked.
I have only one account, I was not using any VPN and I was not using any bots.
I'm highroller and premium user since the beginning of this program. I'm active FBC user.
As normal I was just using built-in feature "auto-bet" and that's all.
In my history I made a lot of deposits and withdrawals and I've never had a problem.
 
Now when I'm logged in, I have just a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds."

After some time, e-mail address has changed and at present it is:
Your account is locked. Please contact @hallohap_1 on telegram or [email protected] email. Failure to comply will result to a lost of funds



That's very disturbing.


I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"



What the heck?

It definitely sounds like you have malware. Scan your devices for trojans or other virus, and then try to access the website on a clean device. If this ransom message isn’t present, then change the password. Do not send them any payment. It seems like they are bluffing about draining your account.
hero member
Activity: 2240
Merit: 537
FREE passive income eBook @ tinyurl.com/PIA10


What the heck?

Have you tried clearing your browser's entire data and cache and retry? Nothing else suspicious happening on your system, right?
Jump to: