Pages:
Author

Topic: Network Attack on XVG / VERGE - page 56. (Read 29513 times)

newbie
Activity: 5
Merit: 0
April 06, 2018, 02:07:43 PM
Wish people in crypto would stop treating everything like it's their favorite sports team. And that goes for both sides.
It's ridiculous to me that people are legitimately upset the price isn't dumping over this. But also we can't act like nothing happened either, It's a serious issue.


Shit happens, it will be fixed when it's fixed. Whether or not it was handled properly or maturely is up for debate (not a debate I want to participate in).
It's really not the end of the world, if you do or don't want to support the coin anymore that's up to everyone's individual discretion.

Good luck to the holders, pools, and devs, and hopefully everything works out in the best possible way for everyone.
newbie
Activity: 8
Merit: 0
April 06, 2018, 01:35:13 PM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).

Such a person is a retard, and not a developer at all! To illustrate what has happened.

- The retard Verge dude "justinvforvendetta" used the browser !!!THE BROWSER!!! to modify the !!!MAIN BRANCH!!! !!!WITHOUT TESTING!!! !!!OF A MULTI BILLION!!! project.
- That code that the retard Verge dude changes was copy and paste, he failed to do some basic math, really really basic math.

Please do not insult junior developers, by comparing such to the verge retard.

-> My post is in general, not on what the person I quoted wrote. But in general, the verge retard with the nick justinvforvendetta shall not be called a developer, not even a junior dev.

Resorted to name calling like a child. You're pathetic. Grow up dude.
full member
Activity: 252
Merit: 100
April 06, 2018, 01:30:59 PM
sharing this from grant hunter.... worth the read.

The exploit itself is very smart. The attacker has used the flaws in Verge’s code to put an older timestamp on their fake blocks to trick the network into thinking that the fake chain is the real one, by having this broadcast to over 51% of the nodes. They have gained consensus, effectively taking control of the XVG chain. This has meant that the ‘real’ blocks being mined by legitimate miners, are seen as the false ones, and therefore are ignored (orphaned).

The reason why trading is still possible, is because the ‘fake’ chain is still verifying transactions so people can still trade the coin, however, the attacker is adding extra blocks and making extra free XVG for themselves.


No matter how much they try to PR spin their way around this, if what you say is true and the attacker basically gained control of the blockchain to the point they are printing and trading coins by themselves and for themselves, XVG as it is now is ruined. Instead of being so incredibly arrogant, the dev(s) should've shut it down until they could hardfork.

Great write up summing the course of events, it should be posted other places for visibility. As you well say, people oughta get as informed as they can be.

I hope they do it, because in this situation there is no other way.
newbie
Activity: 38
Merit: 0
April 06, 2018, 12:33:48 PM
sharing this from grant hunter.... worth the read.

The exploit itself is very smart. The attacker has used the flaws in Verge’s code to put an older timestamp on their fake blocks to trick the network into thinking that the fake chain is the real one, by having this broadcast to over 51% of the nodes. They have gained consensus, effectively taking control of the XVG chain. This has meant that the ‘real’ blocks being mined by legitimate miners, are seen as the false ones, and therefore are ignored (orphaned).

The reason why trading is still possible, is because the ‘fake’ chain is still verifying transactions so people can still trade the coin, however, the attacker is adding extra blocks and making extra free XVG for themselves.


No matter how much they try to PR spin their way around this, if what you say is true and the attacker basically gained control of the blockchain to the point they are printing and trading coins by themselves and for themselves, XVG as it is now is ruined. Instead of being so incredibly arrogant, the dev(s) should've shut it down until they could hardfork.

Great write up summing the course of events, it should be posted other places for visibility. As you well say, people oughta get as informed as they can be.
newbie
Activity: 11
Merit: 0
April 06, 2018, 12:25:49 PM
This has drawn me thinking how this thing could have been better unfolded.

I am a programmer but have zero exposure to block-chain tech at all, so I would say I am just a speculator when I am putting money in cryptos.
I viewed on Youtube an interview to Sunerok and Pivx guys. I have am impression Sunerok is a confident knowing guy thus XVG is sort of worth a try.

I am thinking if I were Sunerok, what's happened to XVG since McAfee boasted it has been so dramatic but the same time kind of landing both huge responsibility and hope onto my shoulder.  Be noticed I am simply a guy who is pursuing my own vision about how crypto should be and I had never expected it all of sudden reached such a level of position in the list of all blockchain projects.
However, without significant investment, I could only continue and focus the project how it has been going. That's why a partnership with a big business may immediately improve this project from all aspects.

I reviewed some of the conversation (didn't go through all), in which I didn't find anything out of XVG dev is extremely disrespectful, though most their response are short (maybe that is as much as can be done at this point of time).

Now, If i were Cminer, I would have tried to talk Verge to publish the incident themselves (maybe Cminer did). I had all the right to make it public but I would mind the sequence.

I think, for investors, XVG has become a tool for people to make money by trading, it's already marked its position there. For long term hodlers, we will just believe in the vision.
member
Activity: 139
Merit: 11
April 06, 2018, 12:07:25 PM
newbie
Activity: 12
Merit: 0
April 06, 2018, 11:34:13 AM
If the 17th BIG partnership announcement is still in play, the problem is bigger than what we see, that's why (I think) they are handling in this way
newbie
Activity: 20
Merit: 0
April 06, 2018, 11:29:27 AM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).

Such a person is a retard, and not a developer at all! To illustrate what has happened.

- The retard Verge dude "justinvforvendetta" used the browser !!!THE BROWSER!!! to modify the !!!MAIN BRANCH!!! !!!WITHOUT TESTING!!! !!!OF A MULTI BILLION!!! project.
- That code that the retard Verge dude changes was copy and paste, he failed to do some basic math, really really basic math.

Please do not insult junior developers, by comparing such to the verge retard.

-> My post is in general, not on what the person I quoted wrote. But in general, the verge retard with the nick justinvforvendetta shall not be called a developer, not even a junior dev.
legendary
Activity: 2198
Merit: 1150
Freedom&Honor
April 06, 2018, 11:21:11 AM
I really hope Sunerok is going to read through this and realize it's better to have someone help him work on the code.
The community is going to be happy if you do this.

This time the bug was exploited for 0.1% of the supply, but what if it was 10%?
Next time, maybe we won't be as lucky if there's a different exploit.
We need 1 more dev.
full member
Activity: 379
Merit: 100
April 06, 2018, 11:07:46 AM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).

Then you might have miss-understood me, as if you read on this thread you will also see examples of copy-pasted code that contained bugs that should have been fixed before committing that code. Or other examples that I personally encountered such as commiting "OpalCoin" error messages in your code while your coin is called Verge. Don't you think these are something a medior/senior would never do..? The whole point is that these are old examples, and to date you would expect a "lead" dev to have a proper QA process in place able to catch those rookie mistakes, and also prevent accidental mistakes.. But here we are talking about another fiasco.. Its not about releasing fast. Its about doing the mistake once, then putting in place a process that will alarm you for the same mistakes in the future.. Thats what experience is about.

A wrong word in a comment that not change the meaning of the comment is not a bug it's a distraction and even senior can do it.

Yours big mistake is thinking that 2/3 devs are working like a company or are a company.

Yeah in a real company you have the lead dev, QA, testers, code reviews etc ... but they are just trying to make this coin go "viral" to help ALL the cryptocommunity.

This is what you(people) don't understand, make other crypto fails impact ALL the market.

So why all this hate against Verge? If Verge can bring a REAL use for crypto then be it and BTC ETH LTC will do the same.

Error can be fixed, devs can grow from their errors...

Ps: @BitPotus you can take that finger and put it in your a...  Grin
newbie
Activity: 1
Merit: 0
April 06, 2018, 11:04:55 AM
I was mining XVG when this attack started. I noticed that the pool was all of a sudden no longer solving new blocks. Thought it might just be really bad luck at the time. However, this continued and I checked suprnova's twitter and found this post. Been following it ever since.

I just want to say that I appreciate ocminer's post and attempts to notify the mining community and XVG devs about what was going on. What's really sad though is how XVG devs have responded to this. A mix of arrogance, suppression, finger-pointing and incompetence have been on magnificent display throughout this fiasco. This has just about shattered my faith in their coin. If the exchanges start accepting XVG again, pretty sure I'll be selling out what I didn't already have on the exchange (which i already sold).
hero member
Activity: 1050
Merit: 604
April 06, 2018, 10:33:10 AM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).

Then you might have miss-understood me, as if you read on this thread you will also see examples of copy-pasted code that contained bugs that should have been fixed before committing that code. Or other examples that I personally encountered such as commiting "OpalCoin" error messages in your code while your coin is called Verge. Don't you think these are something a medior/senior would never do..? The whole point is that these are old examples, and to date you would expect a "lead" dev to have a proper QA process in place able to catch those rookie mistakes, and also prevent accidental mistakes.. But here we are talking about another fiasco.. Its not about releasing fast. Its about doing the mistake once, then putting in place a process that will alarm you for the same mistakes in the future.. Thats what experience is about.

newbie
Activity: 6
Merit: 0
April 06, 2018, 10:17:22 AM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).

Then you might have miss-understood me, as if you read on this thread you will also see examples of copy-pasted code that contained bugs that should have been fixed before committing that code. Or other examples that I personally encountered such as commiting "OpalCoin" error messages in your code while your coin is called Verge. Don't you think these are something a medior/senior would never do..? The whole point is that these are old examples, and to date you would expect a "lead" dev to have a proper QA process in place able to catch those rookie mistakes, and also prevent accidental mistakes.. But here we are talking about another fiasco.. Its not about releasing fast. Its about doing the mistake once, then putting in place a process that will alarm you for the same mistakes in the future.. Thats what experience is about.
newbie
Activity: 102
Merit: 0
April 06, 2018, 10:17:11 AM
The price really pleases, despite the problems that arose
legendary
Activity: 1311
Merit: 1003
April 06, 2018, 10:13:18 AM
Oh dear, what a shit show.
jr. member
Activity: 181
Merit: 1
April 06, 2018, 10:07:21 AM
whats holding the prices of xvg? why hasnt it plummeted after all this? even exchanges are not accepting deposits
i was waiting to buy some for a low price since page 1 of this thread!

It has! To do a normal retrace, now is clearly in accumulation phase before next wave up so I think this is the perfect time to buy.


im looking to buy but not at its current price 0.055 wanting it to drop to last weeks prices of 0.035
was thinking it was gonna go lower than that with the news of a attack but it seems to be holding pretty good
newbie
Activity: 194
Merit: 0
April 06, 2018, 10:06:32 AM
FUN FACT:

1) they collected 75 million coins in donations for "partnership" and my first thought was: if they need money for partnership, whats gonna happend when they cash out 75 mil coins into real money for that partnership

2) suddenly "hacker" takes over 50 mil (latest number someone mentioned couple of hours ago)

let mw guess next step: "we are sorry FOR THE HUGE DUMP "OF HACKER"  but since xvg is untraceable we couldnr do anything

I guess thats one way to cash partnership money
full member
Activity: 379
Merit: 100
April 06, 2018, 09:58:29 AM
whats holding the prices of xvg? why hasnt it plummeted after all this? even exchanges are not accepting deposits
i was waiting to buy some for a low price since page 1 of this thread!

It has! To do a normal retrace, now is clearly in accumulation phase before next wave up so I think this is the perfect time to buy.

jr. member
Activity: 181
Merit: 1
April 06, 2018, 09:55:34 AM
whats holding the prices of xvg? why hasnt it plummeted after all this? even exchanges are not accepting deposits
i was waiting to buy some for a low price since page 1 of this thread!
full member
Activity: 379
Merit: 100
April 06, 2018, 09:54:29 AM
Thank you for the long and detailed post.
You know what? I am calling the verge team thieves. They are stealing xvgs and no one else whosoever!!!!!  They can do what ocminer advised but they have closed their fucking ears. Do they have ears? I highly doubt. I didn't do enough research. But I didn't lose much money. I just only lost hope.
Fuck them. They will burn in hell with their loots.

I understand your frustration. But calling them names or cursing them will change nothing unfortunately. What you see here might as well have nothing to do with them having closed their ears. It could be that they just plainly don't understand the code so they are incapable of providing a fix. Months ago, when I did my research on Verge looking at the source code I realised that the lead dev is at most a Junior dev that lacks the experience to provide any high quality complex code. This has been proven so many times by their "accidental" mistakes or the copy/pastes that include bugs of others.. Any rants/vents I had, went immediately away. There was no point in venting at a fish because it will not fly.. Its incapable of doing this in the first place..

Take the whole thing as a lesson. An experience to make us smarter in researching and making our choices.

Calling a dev a junior only because uses part of code from others dev makes you the junior here.

I'm a dev too and I honestly do the same to release something faster. If you understand what other devs have done in their code is legit to use it (under proper licence).
Pages:
Jump to: