PrimeDice, which is a very popular BTC gambling site, has fucked me and a friend of mine over. Let me explain:
Well, some time ago, I reported a persistent XSS exploit to PD which was on their front page. Everything was going fine until I actually sent them the exploit. Then they ignored me for a couple of hours. After they fixed the exploit, they said that another guy told them the exploit as well.
https://gyazo.com/dbba3aca6190dddbcececd084a750cf7The thing is, they fixed the exploit exactly 5-10 minutes after
I reported it to them. Funny coincidence. I didn't mind it at first as he said that he'll ask the owner to arrange a reward for both of us. Then, some time later, I get this E-Mail from PD:
https://gyazo.com/0b555023901f4a2086db185dffb8ec07Apparently, 3 people reported the same exploit now. Wait. Didn't they say it was only 2? It's a very weird "coincidence". Unless PD can provide proof along with the timestamps of the guy's E-Mail (the one who reported it before me), I'll see myself as screwed by them.
I cannot find the transaction link nor the messages, but I'll makes sure I find them. Basically, he deposited around 10-13 BTC onto PrimeDice. The money got confirmed and it didn't appear. They just said that someone logged into his account and took the money outta it. Now, he hasn't shared his password with anyone nor has he used any type of script that may have gotten access to his account. He got the money by reporting an exploit to Uber so he isn't ratted either.