Pages:
Author

Topic: Network Attack on XVG / VERGE - page 82. (Read 29513 times)

member
Activity: 266
Merit: 27
April 04, 2018, 05:03:09 PM
we are not doing a rollback and we are preparing a fork to patch this up.

Sorry to mess up this thread and topic a bit, but after i do not get for hours an answer on twitter, neither does the email function on the Verge homepage work, nor does someone respond on the Verge Bitcoin thread i have to try my luck here.

I visited some hours ago the official Verge Twitter profil to read the news about the hash hack. While reading the tweed i noticed several messages offering a compensation for the attack by Verge. Send x Eth and you get some bonus back. Sounded legit to me as it was affilated to the hash attack and i suffered from it as well having had some hours only orphaned blocks on all my baikals, hence i fall victim to this damn scam on the official twitter page.

Now, while i have myself for sure some vault for this i'am seriously angry about how on the official verge twitter page 100s of scams and fake messages that say they got the ETH back are tolerated and nobody cares about it?!?! How is this possible. After i realized i got scammed i even made a post in this tweet that its a scam and to remove it asap, nothing happened and people still fall after that scam. Only on that scam by now 12+ Eth have been transfered the last hours.

Damn, i'am not a twitter guy and very rarely use it, but from an official Verge twitter profil i personal await its clean and at very least if this for some reason is not possible that there are warning messages about these scams!!!! But no, nothing, the whole official Verge Twitter profil is FULL of scams that are tolerated and people like me, fall victims to it. Fine, i lost some 1.8 ETH, but hourly these scams seems to collect a huge amount of ETH that way and nobody there at Verge cares?

Seriously, so far i wondered about the twitter decision to ban crypto, but i begin to understand the decision. They must get shitload of complains from victims like me.....

And what makes me even more angry ... no response:
- Messaged some hours ago verge on twitter .... nothing, scams are staying and getting more and more
- Put a tweet on the Verge tweet to remove the scams .... nothing, scams are just staying there
- posted in the official bitcointalk Verge thread, nothing ......
- tried to email Verge about the ongoing scams .... email function on the homepage isn't even working, it just loads forever. And after 5 attempts to load it still loads after 2 hours, lol.

I'am writting this as a XVG miner and lover, but this all makes me really sad and angry .....

not sure if you thought we had the ability to delete them, but we dont. we have written to twitter about this. it's happening to all major coins right now. =\

I'am not a twitter guy, no idea about other coins or twitter in general, but yes, i thought you can either block, ban or delete such messages as the profil owner.
And as i wrote allready, if it is NOT possible for some reason, why no big warning on top?? I mean it seems you are aware of these 100's of scams on your official Verge profil, but people like me interested in XVG are not.
nothing can be done, this has happened even with Vitalik, cz and many other important figures. It is up to Twitter to do anything about them (keep in mind there are paid people saying "thank you for X ETH" in order to lure you).
member
Activity: 420
Merit: 13
April 04, 2018, 04:58:02 PM
we are not doing a rollback and we are preparing a fork to patch this up.

Sorry to mess up this thread and topic a bit, but after i do not get for hours an answer on twitter, neither does the email function on the Verge homepage work, nor does someone respond on the Verge Bitcoin thread i have to try my luck here.

I visited some hours ago the official Verge Twitter profil to read the news about the hash hack. While reading the tweed i noticed several messages offering a compensation for the attack by Verge. Send x Eth and you get some bonus back. Sounded legit to me as it was affilated to the hash attack and i suffered from it as well having had some hours only orphaned blocks on all my baikals, hence i fall victim to this damn scam on the official twitter page.

Now, while i have myself for sure some vault for this i'am seriously angry about how on the official verge twitter page 100s of scams and fake messages that say they got the ETH back are tolerated and nobody cares about it?!?! How is this possible. After i realized i got scammed i even made a post in this tweet that its a scam and to remove it asap, nothing happened and people still fall after that scam. Only on that scam by now 12+ Eth have been transfered the last hours.

Damn, i'am not a twitter guy and very rarely use it, but from an official Verge twitter profil i personal await its clean and at very least if this for some reason is not possible that there are warning messages about these scams!!!! But no, nothing, the whole official Verge Twitter profil is FULL of scams that are tolerated and people like me, fall victims to it. Fine, i lost some 1.8 ETH, but hourly these scams seems to collect a huge amount of ETH that way and nobody there at Verge cares?

Seriously, so far i wondered about the twitter decision to ban crypto, but i begin to understand the decision. They must get shitload of complains from victims like me.....

And what makes me even more angry ... no response:
- Messaged some hours ago verge on twitter .... nothing, scams are staying and getting more and more
- Put a tweet on the Verge tweet to remove the scams .... nothing, scams are just staying there
- posted in the official bitcointalk Verge thread, nothing ......
- tried to email Verge about the ongoing scams .... email function on the homepage isn't even working, it just loads forever. And after 5 attempts to load it still loads after 2 hours, lol.

I'am writting this as a XVG miner and lover, but this all makes me really sad and angry .....

not sure if you thought we had the ability to delete them, but we dont. we have written to twitter about this. it's happening to all major coins right now. =\

I'am not a twitter guy, no idea about other coins or twitter in general, but yes, i thought you can either block, ban or delete such messages as the profil owner.
And as i wrote allready, if it is NOT possible for some reason, why no big warning on top?? I mean it seems you are aware of these 100's of scams on your official Verge profil, but people like me interested in XVG are not.
legendary
Activity: 1708
Merit: 1009
$XVG - The Standard in Crypto as a Currency!
April 04, 2018, 04:52:44 PM
we are not doing a rollback and we are preparing a fork to patch this up.

Sorry to mess up this thread and topic a bit, but after i do not get for hours an answer on twitter, neither does the email function on the Verge homepage work, nor does someone respond on the Verge Bitcoin thread i have to try my luck here.

I visited some hours ago the official Verge Twitter profil to read the news about the hash hack. While reading the tweed i noticed several messages offering a compensation for the attack by Verge. Send x Eth and you get some bonus back. Sounded legit to me as it was affilated to the hash attack and i suffered from it as well having had some hours only orphaned blocks on all my baikals, hence i fall victim to this damn scam on the official twitter page.

Now, while i have myself for sure some vault for this i'am seriously angry about how on the official verge twitter page 100s of scams and fake messages that say they got the ETH back are tolerated and nobody cares about it?!?! How is this possible. After i realized i got scammed i even made a post in this tweet that its a scam and to remove it asap, nothing happened and people still fall after that scam. Only on that scam by now 12+ Eth have been transfered the last hours.

Damn, i'am not a twitter guy and very rarely use it, but from an official Verge twitter profil i personal await its clean and at very least if this for some reason is not possible that there are warning messages about these scams!!!! But no, nothing, the whole official Verge Twitter profil is FULL of scams that are tolerated and people like me, fall victims to it. Fine, i lost some 1.8 ETH, but hourly these scams seems to collect a huge amount of ETH that way and nobody there at Verge cares?

Seriously, so far i wondered about the twitter decision to ban crypto, but i begin to understand the decision. They must get shitload of complains from victims like me.....

And what makes me even more angry ... no response:
- Messaged some hours ago verge on twitter .... nothing, scams are staying and getting more and more
- Put a tweet on the Verge tweet to remove the scams .... nothing, scams are just staying there
- posted in the official bitcointalk Verge thread, nothing ......
- tried to email Verge about the ongoing scams .... email function on the homepage isn't even working, it just loads forever. And after 5 attempts to load it still loads after 2 hours, lol.

I'am writting this as a XVG miner and lover, but this all makes me really sad and angry .....

not sure if you thought we had the ability to delete them, but we dont. we have written to twitter about this. it's happening to all major coins right now. =\
member
Activity: 420
Merit: 13
April 04, 2018, 04:51:16 PM
we are not doing a rollback and we are preparing a fork to patch this up.

Sorry to mess up this thread and topic a bit, but after i do not get for hours an answer on twitter, neither does the email function on the Verge homepage work, nor does someone respond on the Verge Bitcoin thread i have to try my luck here.

I visited some hours ago the official Verge Twitter profil to read the news about the hash hack. While reading the tweed i noticed several messages offering a compensation for the attack by Verge. Send x Eth and you get some bonus back. Sounded legit to me as it was affilated to the hash attack and i suffered from it as well having had some hours only orphaned blocks on all my baikals, hence i fall victim to this damn scam on the official twitter page.

Now, while i have myself for sure some vault for this i'am seriously angry about how on the official verge twitter page 100s of scams and fake messages that say they got the ETH back are tolerated and nobody cares about it?!?! How is this possible. After i realized i got scammed i even made a post in this tweet that its a scam and to remove it asap, nothing happened and people still fall after that scam. Only on that scam by now 12+ Eth have been transfered the last hours.

Damn, i'am not a twitter guy and very rarely use it, but from an official Verge twitter profil i personal await its clean and at very least if this for some reason is not possible that there are warning messages about these scams!!!! But no, nothing, the whole official Verge Twitter profil is FULL of scams that are tolerated and people like me, fall victims to it. Fine, i lost some 1.8 ETH, but hourly these scams seems to collect a huge amount of ETH that way and nobody there at Verge cares?

Seriously, so far i wondered about the twitter decision to ban crypto, but i begin to understand the decision. They must get shitload of complains from victims like me.....

And what makes me even more angry ... no response:
- Messaged some hours ago verge on twitter .... nothing, scams are staying and getting more and more
- Put a tweet on the Verge tweet to remove the scams .... nothing, scams are just staying there
- posted in the official bitcointalk Verge thread, nothing ......
- tried to email Verge about the ongoing scams .... email function on the homepage isn't even working, it just loads forever. And after 5 attempts to load it still loads after 2 hours, lol.

I'am writting this as a XVG miner and lover, but this all makes me really sad and angry .....
legendary
Activity: 1708
Merit: 1009
$XVG - The Standard in Crypto as a Currency!
April 04, 2018, 04:50:06 PM
nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

how can we verify the hardfork ?

just download an updated wallet which includes the "fix" - then download the blockchain snapshot and try to sync up to the latest block...it will get stuck at 2007364

Confirmed.    client stalls at block 2007364


yeah we removed that, and we're doing a full fork update with extra block verifications. will be ready by tmrw =]
member
Activity: 179
Merit: 27
April 04, 2018, 04:39:03 PM
nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

how can we verify the hardfork ?

just download an updated wallet which includes the "fix" - then download the blockchain snapshot and try to sync up to the latest block...it will get stuck at 2007364

Confirmed.    client stalls at block 2007364

newbie
Activity: 6
Merit: 0
April 04, 2018, 04:36:25 PM
sorry tryd to make a quote from my last post.... but made a qoute from some one else here

i just made a paymen from Binance : Completed XVG9.9 2018-04-04 23:20:54 Address:   DLv25ww5CipJngsKMYemBTBWH14CUpucxX

to the verge fundraise adress : 4th Apr 2018 23:23:52   d9480b0f0b95bb5ec8a066d93b54fcd8b97c7b7c0ee83effe4ad95b80f004a83   + 9.90000000

so i think my investment is safe for now,i was really hoping to get a fair reaction from one of you Huh

thanks anyway for making a contribution in making the verge blockchain more reliable

good luck and happy trading(mining) to you
legendary
Activity: 1708
Merit: 1009
$XVG - The Standard in Crypto as a Currency!
April 04, 2018, 04:33:16 PM
we are not doing a rollback and we are preparing a fork to patch this up.
sr. member
Activity: 356
Merit: 335
If you don’t believe, why are you here?
April 04, 2018, 04:18:57 PM
nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

Thank you ocminer, I hope that dev coin team will fix this problem and warn pools in a timely manner if a fork should be done. i'd be happy that we revert the coins mined by the attacker.


From what I know they won't roll back and just move on.. However, they still must do the hardfork in a proper way

I'd prefer that XVG coin dev team decide to roll back to cancel the coins mined during the hack, it is better I think.


What do you think guys ?

A rollback?

XVG will be judged accordingly.
newbie
Activity: 192
Merit: 0
April 04, 2018, 04:07:33 PM
@OP

As an avid Verge supporter I'm actually glad you did what you did. Thanks for helping.

Don't listen to the radicals on both sides.

Seems the issue is fixed, let's all move on and be happy this happened now and not later.

Finally! A VALID response from VergeFam! Thanks Ragnarok for posting something of value!
full member
Activity: 172
Merit: 101
Mining pool operator @ https://www.unimining.net
April 04, 2018, 04:05:15 PM
nice a new version of the famed timewarp attack.. very interesting.

yep.. we pushed a quick fix and most pools have already updated.. we're already working on a whole new block verification process.

we're kinda glad this happened and that it wasn't as bad as it could have been.


Hmm, you guys are aware that the "fix" you pushed actually IS a hardfork ? So your blockchain snapshot is not valid anymore, the wallet's won't sync up from scratch anymore and the current chain is simply not usable anymore with that new "fix" ?

Your change simply disagrees with the attackers blocks, the first block I see from the attacker was 2007365 - so the wallets will stop syncing there and simply not progress any further.

I remember your first forking dramas when trying to fork into Tor which failed 2 times IIRC.

You should immediately refrain from that "fix" and set a proper fork-height (at least 48h) and the chain up until the fork block MUST accept blocks with the old timestamps and blocks after that fork block then only with the new timestamp.




bumping this for awareness

Thank you ocminer, I hope that dev coin team will fix this problem and warn pools in a timely manner if a fork should be done. i'd be happy that we revert the coins mined by the attacker.


From what I know they won't roll back and just move on.. However, they still must do the hardfork in a proper way

I'd prefer that XVG coin dev team decide to roll back to cancel the coins mined during the hack, it is better I think.


What do you think guys ?
newbie
Activity: 7
Merit: 0
April 04, 2018, 04:03:14 PM
Hey Verge Team,
get some real developers and fix your code.
We have found another 2 exploits which can make quick hashes aswell.

The (soon) Bits Team.
member
Activity: 420
Merit: 13
April 04, 2018, 04:01:44 PM
Great post ocminer, thanks for this valuable information

Totally agree. ocminer should get rewarded with some bigger amount of XVG from Verge for showing them a lot of their problems.
GJ ocminer. Rarely seen such informative and excelent described problems on a forum. Hope you keep up the good work.
newbie
Activity: 3
Merit: 0
April 04, 2018, 04:00:58 PM
U can't fix it through time... Why wouldn't u fix it through the prefix of current readable algorythm? I don't know how hard is it to realise, but (1) u may call each reachable algorythm with the new block with the prefix. Like for the SHA-256 - 00A-, DH - 00B-, Crypt - 00C-, NightCrypt - 01N-, Keccak - 01K-, Lyra - 012-,  X11 - 00D-, X15 - 01D-, Blake - 01B-, Quibit - 00Q-, Quark - 01Q-... etc
(2) Randomise it. (3) Implement Not-in-a-row accessable algorythm. Done. Too hard? - skip (1)
newbie
Activity: 6
Merit: 0
April 04, 2018, 04:00:28 PM
i,m just a little seed and dont have any tech skills,verge is really a sollid part of my portfolio.
i have a question if the buck stops @ block  2007365 and will stop syncing there and not progress any further.
then the blockchain will stop and payments will stop with it so wouldend there be a lot of spam in the telegram and discord from people who are not getting there transactions thrue?
i hope i can get a anwser to my question because FUD is the right statement of my state of being right now and asking these questions in discord or telegram is like putting your head in a sling right about now.... Cry
i just want to protect my investment and really believe in what verge represents but my $$$ are more important

greetings from a little seedling  Roll Eyes
legendary
Activity: 1884
Merit: 1005
April 04, 2018, 03:59:41 PM
Github XVG:

"justinvforvendetta replied 2 hours ago
i'm glad this happened now. it's got us working on a whole new method for block and transaction verification =]"

Yeah, maybe work on a new verification method for blocks if he dev doesnt even know that nMaxClockDrift is in seconds..

static const int64 nMaxClockDrift = 2 * 15;        // fifteen minutes

newbie
Activity: 21
Merit: 0
April 04, 2018, 03:54:44 PM
So if I transfer XVG from exchange to my wallet there's the risk that my coins will be lost due hardfork?

newbie
Activity: 7
Merit: 0
April 04, 2018, 03:54:14 PM
Can confirm it is still exploitable, will not abuse it futher myself but fix this problem immediately I'll give Verge some hours to solve this otherwise I'll make this public and another unpatchable problem.
newbie
Activity: 213
Merit: 0
April 04, 2018, 03:49:26 PM
How can one initiate an attack such as this?

Do you need step by step instructions?

Yes
legendary
Activity: 1884
Merit: 1005
April 04, 2018, 03:41:18 PM
Great post ocminer, thanks for this valuable information & awesome to see the newbie accounts pop up and say its fake and fud Cheesy

Pages:
Jump to: