Author

Topic: Tracking a Bitcoin Thief pt. I: [..] and the Truth behind CryptoRush.in (Read 1433 times)

member
Activity: 308
Merit: 10
Bitcoin is the future


As for google - yes unfortunately our true.io platform is mostly JS and Google is not liking it much. I may have to post it on the tumblr blog, and propagate that URL so it gets spread.

This information needs to get out.

You could try adding plenty of relevant keywords in a meta keywords tag in the page's header. The Google spider should quickly pick them up.
hero member
Activity: 854
Merit: 1001
Heres a swift kick...good work, guys.

EDIT:  Just spent a long time reading, the lesson I think we should ALL take away from this (and other hacks/thefts) are:

Do not re-use passwords. Make a new password for every platform that asks.
newbie
Activity: 24
Merit: 0
when will the part 2 published? Also I find this info very hard to find on google

Thanks for the read!

I will be finishing up part 2 sometime this weekend.

As for google - yes unfortunately our true.io platform is mostly JS and Google is not liking it much. I may have to post it on the tumblr blog, and propagate that URL so it gets spread.

This information needs to get out.
newbie
Activity: 3
Merit: 0
when will the part 2 published? Also I find this info very hard to find on google
newbie
Activity: 24
Merit: 0
Really great piece of investigative journalism. You guys rock !

Thank you! much appreciated.

Side note:

BTC-E.com responded back regarding our findings:

"We will conduct an investigation of the criminal activities of this entity only when requested by law enforcement agencies."

So I presume this means they will continue allowing 'jbluey' to trade stolens Bitcoins through the exchange. Nice.

Cheers!
sr. member
Activity: 462
Merit: 250
Really great piece of investigative journalism. You guys rock !
newbie
Activity: 24
Merit: 0
Thanks for the read!

In regards to getting him caught we have done the following:

- Contacted Chunkhost (vpses used by him, from this company, were used in recent Midascoin/pool hack)
- Contacted the equivalent of Philippine FBI - NBI.gov.ph and provided them all of our research and logs
- Contacted PHCERT - Philippine Computer Emergency Response Team
- Contacted server4you and his other hosts in germany
- Contacted BTC-e.com to disable his BTC-e account which you can see in the screenshots @ https://bitcomsec.true.io where he traded stolen coins
- Contacted GlobeTel/GlobeNet and Smart.com.ph - the two Philippine ISPs he used and are logged in the FTP logs we recovered
- Contacted his Otaku-Streamers.com community

My next moves are to push this incident to other asian Computer Emergency Response Team's in Japan and South Korea who seem proactive in Asian security affairs and may lend a hand in helping reach to the .PH authorities. We're still going strong and are hoping something comes of this.

Cheers!
legendary
Activity: 2294
Merit: 1182
Now the money is free, and so the people will be
Hello,

My name is Mike and I am from the BITCOMSEC (Bitcoin Community Security) Project. We've been reporting security issues to the Bitcoin community (Exchanges, pool, merchants sites and open source projects) with the hope that our little contributions help bring Security awareness to the community.

One of our first thorough reports on tracking a Bitcoin thief involved the hacking of CryptoRush.in, by the owner of known scam pool xtrapool.com. It was a long investigative effort taking many months of tracking down, analyzing evidence and logs and putting it all together for all of you to read. I would appreciate it if you guys took the time to read it as it is indeed intriguing, and hopefully as a community we can come away with this affair with a greater understanding of what these scammers/hackers are doing to our community. Tweeting, redditing and spreading the article will help expose this hacker as well.

You can find our report at:

Tracking a Bitcoin Thief pt. I: The Philippine Connection and the Truth behind CryptoRush.in
https://bitcomsec.true.io/bitcomsec/tracking-a-bitcoin-thief-cryptorush-hack/

You can watch us and our future articles coming up (including Part II to this series detailing how Midascoin/Midaspool was hacked and destroyed by both CryptoRush.in hacker and Midascoin partner) and others in the future by visiting:

https://bitcomsec.true.io

Our contact info in case you need us to help you work on tracking down a thief, deal with post hack-forensic work or have any security questions:

Message us via BitMessage: BM-2cW3Vziujs3zLfFqunF2jeUw6R7djJuk8w
Twitter: @bitcomsec

To donate to our project and keep us going: BTC: 1SEC1BS5wFDSToi1v3RubV9PjCSSPa6s9

Cheers and hope you enjoyed the read!

edited: typos

hmm wow

good work guys.  poor linkandzelda, they were cool.  i loved cryptorush too, had all the coin unknown coins. 

Now how about action?  I would donate to see him brought to arrest, kinda like bounty hunter style
newbie
Activity: 24
Merit: 0
Hello,

My name is Mike and I am from the BITCOMSEC (Bitcoin Community Security) Project. We've been reporting security issues to the Bitcoin community (Exchanges, pool, merchants sites and open source projects) with the hope that our little contributions help bring Security awareness to the community.

One of our first thorough reports on tracking a Bitcoin thief involved the hacking of CryptoRush.in, by the owner of known scam pool xtrapool.com. It was a long investigative effort taking many months of tracking down, analyzing evidence and logs and putting it all together for all of you to read. I would appreciate it if you guys took the time to read it as it is indeed intriguing, and hopefully as a community we can come away with this affair with a greater understanding of what these scammers/hackers are doing to our community. Tweeting, redditing and spreading the article will help expose this hacker as well.

You can find our report at:

Tracking a Bitcoin Thief pt. I: The Philippine Connection and the Truth behind CryptoRush.in
https://bitcomsec.true.io/bitcomsec/tracking-a-bitcoin-thief-cryptorush-hack/

You can watch us and our future articles coming up (including Part II to this series detailing how Midascoin/Midaspool was hacked and destroyed by both CryptoRush.in hacker and Midascoin partner) and others in the future by visiting:

https://bitcomsec.true.io

Our contact info in case you need us to help you work on tracking down a thief, deal with post hack-forensic work or have any security questions:

Message us via BitMessage: BM-2cW3Vziujs3zLfFqunF2jeUw6R7djJuk8w
Twitter: @bitcomsec

To donate to our project and keep us going: BTC: 1SEC1BS5wFDSToi1v3RubV9PjCSSPa6s9

Cheers and hope you enjoyed the read!

edited: typos
Jump to: