Actually I am the one who breached their site.
Wanted to get people's attention because I tried to inform people on their sub on reddit but they removed i think to post without approval.
Let me explain it here with couple words.
So at this point, I have control over everything in their system.
I can replace wallet address and new users make their first deposit in my wallet (don't worry, I give them money back after a day). Did this to couple accounts just these morons at roobet to see that I am not fucking. I am sure they got some angry users on their support
I gave again these morons accounts with different age: username:password.
We were literally talking and in real time I gave them information about accounts that "This user just made a deposit, this person played and lost everything just now". And the morons confirmed it
I've been getting in real time their database, or to be more clear I got it, now it just syncs with newly registered accounts.
I sent them some code where there are flaws, the dev tells me "The code looks good to me", of course it does you moron, you are web dev and I am making a living of flaws and bugs... The moron looks at front and end to work good together and the security that he can put is some wanky protection and cloudflare and call it a day.
Yep, I am doing it for money, but I want to be paid for telling them how I am STILL in their system, how logs and shit don't show any breach and everything else. This is multi million business, don't you agree that someone with bad intentions would be now multi millionaire? It's easy for me to drain all the wallets, but will get too much attention and probably trouble. So I asked for $300k to give them full report + fixes, so they don't even have to hire a new dev to make them.
And on another note: I am so deep I can delete the whole DB. They will restore it for sure, I will delete it again if I want to. These morons for 6 or 7 days now still can't figure out how I am able to do it.
I sent them a picture where on their site I am able to select a random user (by random I still need to know the username) and get into the account (I still need to be in their system to do this).
I sent them a shit load of proof, like the rest is to tell "Hey, here is how I do it" and explain it...
Their site is like a puzzle with pieces that don't fit well but they smashed them with a hammer to make them fit. And this is how you get holes, that are doors for people like me.
These people are morons or another level.
Now I am torn, I don't want to make the users suffer. Was planning to sell it for real (the db) and cash out even more than I asked them to pay me. Already people on Dread contacted me to buy without even posting it on the markets.
You have the rights to doubt everything I say, but they don't. I gave them even too much proof than I should.
I will torture them a little more, will keep changing Crypto addresses so people complain (don't think they will care but will try this), I will ruin other parts for them (already started). And if they still don't pay so this crap get fixed, I would sell it and let them burn. The problem is that the users will burn more. If I had bad intentions I would've stole the money and run.
I do a living from finding and reporting bugs/flaws and getting paid from companies. Or as most people know it "white" hacker.
I can show emails here where I give them users:passwords. And where in real I tell them who deposits and loses and so on.
P.S: I've taken $0 from anyone (users)! I would rather not get a single $ and destroy them than users making rich someone so careless about the people who fill his pockets (Mr. Allen). And this is what's gonna happen. Before I totally destroy them will put a background warning Users to take their money out of there, give them some time and ERASE the DB.
Small proof they know I am there: https://ibb.co/kgg3dmctold them the registered username, then this and their reply.
Then gave them the password.
Did it with other accounts too....