Pages:
Author

Topic: Reused R values again - page 16. (Read 121295 times)

legendary
Activity: 1652
Merit: 1029
December 10, 2014, 01:57:32 PM
hero member
Activity: 742
Merit: 500
December 10, 2014, 01:45:14 PM

Epic johoe!

I wish there were more like him. We sure need them!

Will johoe post an address so that we, the impressed spectators, can send him a few beers? Also, is blockchain.info rewarding this hero in anyway?
legendary
Activity: 2226
Merit: 1052
December 10, 2014, 01:42:48 PM
This is awesome. Great example set by U Smiley

Since this thread was bumped, I think I should update it.

There seems to be a new buggy program that reuses the same R value for all signatures in a transaction.  It started around September 2014. Because the program uses mostly unique addresses, the bug is not always exploitable.  But reuse happened often enough to break over 400 new keys. The list is getting too long to post it here so here are the links:

http://johoe.mooo.com/bitcoin/broken.txt
http://johoe.mooo.com/bitcoin/endangered.txt

The first list contains the addresses whose private key can be computed from the block chain.  The second list additionally contains addresses that were used by the faulty client but only in a context where it cannot be broken (unless I'm missing something).

Does anyone know what the buggy program is?  Or does anyone recognize any of the more recent addresses?

Note that the addresses that appear only in the second list still may be in danger, e.g., if they stem from a BIP32 wallet and one knows the "xpub" public key.

It looks like there are some bots sweeping all funds that go to such a broken wallet.


May I ask you that after creating an address, if I check it against these 2 lists and my address is not available among them, then am I safe ?

If not, then what is the way to check the safety of a new address ?
hero member
Activity: 553
Merit: 1000
Rollin.io - Faucet up to 5k satoshis.
December 10, 2014, 01:32:56 PM
Hats off!!
full member
Activity: 129
Merit: 100
December 10, 2014, 11:48:13 AM
Nicely done.  Good to see positivism within the community. 
hero member
Activity: 640
Merit: 500
interested to BUY CASASCIUS
December 10, 2014, 11:23:00 AM
congratulations
!!!
legendary
Activity: 1904
Merit: 1074
December 10, 2014, 08:41:59 AM
All white hats off to Johoe  Grin Grin Grin Tip that ChangeTip hat for him on Reddit people.
http://www.reddit.com/r/Bitcoin/comments/2otekd/white_hat_johoe_returns_255_btc_to_blockchaininfo/

We need more people like him/her in this world.

I have been thinking "Bitcoin" has lost the plot, with all the hacks and scamming going around, and then this happens.

It gives me hope in humanity!!
hero member
Activity: 531
Merit: 500
December 10, 2014, 08:00:22 AM
Congratulations I bow before your gesture!
Congratulations ....
legendary
Activity: 1778
Merit: 1043
#Free market
December 10, 2014, 07:53:15 AM
Amazing hero ! I think the bitcoin community need more users like you , great job Wink.
legendary
Activity: 3556
Merit: 9709
#1 VIP Crypto Casino
December 10, 2014, 07:43:22 AM
Wow Johoe what a guy.
Fucking hero.
hero member
Activity: 1582
Merit: 759
December 10, 2014, 07:25:08 AM
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.

Quote
From: Ben Reeves <[email protected]>
If you could return the funds to address 15tXHJCjehqCEL6zRCkGwvuDY6YzZV5sKP that would be fantastic.

I should also add if that using our admin tools, if users supply us with the correct wallet information, we are able to accurately determine which refund claims are valid and which are not. So far we have processed over 30 refund requests and will be processing more over the rest of this week.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

15tXHJCjehqCEL6zRCkGwvuDY6YzZV5sKP
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iQEcBAEBAgAGBQJUh5AdAAoJEP3NqDUC96SQqH0H/3pTTawCXZWfWAwIoVQPkSYa
DgpioEvHLDHXegfAfXyo8X9vc50kEseQVeZ5FAvoeC3Hy76gNIgEDllP5o6FUXL2
HsEj7qcafY5AxlxMgRRG9p1OcbeJS6mlbZrjB78BD+zrtzZaLFoSAf4+lw3YZHg5
xvA0WyNoHE1Hzg8+pdPbg1PPN6dHT38+PCyqFgYIjkjq07UbxxtyyWs8KIQqSuTe
4XIh0gjd73Wqtxm4CAHtnwy0PA5Pi/lE7v0d6qqF2l86SlxDkT6067asMw9Te0JJ
WgnFM8fePrM8HU980n0xvamae7J71zlFMN2/RYfj2t/pTIEWz25ZI2iVS0MGg14=
=9MGK
-----END PGP SIGNATURE——

PGP key is available from https://blockchain.info/security.txt



https://blockchain.info/tx/ea8fa447d59000843910932a42bf7a28915772d97a006e97714d026b78885754

I cannot express my gratitude towards you. Thank you so very much for this. Sort-of a "Faith in Humanity Restored" moment right now.

Do you mind posting a Bitcoin wallet. As soon as I get the coins back from BlockChain.info; I'll be sure to send something.

Thanks! Rep ++ left.
cor
full member
Activity: 121
Merit: 100
December 10, 2014, 07:16:17 AM
The money has been returned to blockchain.info.  Please write to blockchain support to claim refund.
...
https://blockchain.info/tx/ea8fa447d59000843910932a42bf7a28915772d97a006e97714d026b78885754

Johoe well done!
People like you are a gem. Please accept this small reward from me for being an ethical hacker:



Let me know how to get it to you.
sr. member
Activity: 432
Merit: 250
December 10, 2014, 06:53:12 AM
There was a tx signing bug in BitcoinJs which Counterwallet (a Counterparty web wallet) triggered. Counterwallet has been patched, and all users of Counterwallet should indeed generate new accounts and sweep all of their funds there.

See the original announcement.

Just quoting this in case anyone is confused about the whole situation. The issues affecting Blockchain.info have nothing to do with Counterwallet, and everything has been fixed there since ages.
sr. member
Activity: 455
Merit: 251
blockchain longa, vita brevis
December 10, 2014, 06:30:45 AM
Your parents should be proud of you, johoe!
newbie
Activity: 33
Merit: 0
December 10, 2014, 06:07:25 AM
That was awesome of you johoe Cheesy
full member
Activity: 309
Merit: 100
December 10, 2014, 05:57:17 AM
Thanks Johoe that you are one of the good guys.

I would have done the same, but not everyone would have.



legendary
Activity: 874
Merit: 1000
monero
December 10, 2014, 05:56:09 AM
haven't seen this yet, so  Grin THIS IS GENTLEMEN!
legendary
Activity: 1511
Merit: 1072
quack
December 10, 2014, 05:37:42 AM
Good to see this. Btw is there changetip for bct?
legendary
Activity: 2126
Merit: 1001
December 10, 2014, 05:28:18 AM
Johoe, you are heroic!
Thank you.

Ente
sr. member
Activity: 317
Merit: 275
December 10, 2014, 05:03:15 AM
What about this claim, was it confirmed? It does not seem to have been picked up by @johoe.

That address is listed here near the very end: http://johoe.mooo.com/bitcoin/broken.txt

And johoe said that he didn't swipe them all:
The scale is also much bigger (500 addresses in one day, >200 BTC).  I still count almost 300 unspent outputs (but I'm too lazy to swipe them all).

So I guess somebody else did... Too bad. But maybe it's another Good Samaritan.

Yeah, somebody else took it:

Quote from: Guy who lost 100BTC
joehoe has been an absolute huge help. I had 100 coins stolen, unfortunately after speaking to him he didn't catch my address.
Pages:
Jump to: