27 ms·
CoinDash’s ICO Website Has Been Hacked
- discombobulate 9y agoToken sales are risky. What do people expect? Guaranteed thousands-of-percent returns. At this point, it probably takes good judgement to make money in crypto. You can't just throw fiat at anything & expect to walk away rich. One of the reasons criminals are all over crypto is because they're valuable. When Willie Sutton was asked why he robbed banks he replied: 'Because that's where the money is'. I'd say caveat emptor.
- lin_lin 9y agoThe freedom of unregulated money!
- SirensOfTitan 9y agoThe full title on the link is: "Breaking: CoinDash’s Token Sale (ICO) Website Has Been Hacked." This submission is disingenuous at best, as it implies the ICO contract was hacked: someone hacked the webpage and changed the token sending address. Edit: Looks like the title was updated. :)
- discombobulate 9y ago1) Watch out for the website. And here's another tip from Vitalik, 'Reminder: if someone makes a token sale that gives discounts to large buyers, this can be circumvented via collective-buying smart contract.'[0] I think people are going to start understanding how to navigate the new investment waters. It's going to take time. I still don't have as many sources of info in the area as I'd like. That too -- if the market continues to develop -- will change in time. [0]: https://twitter.com/VitalikButerin/status/886191450727297024 https://twitter.com/VitalikButerin/status/886191450727297024
- joosters 9y agoThe 'tip' can be summarised to just 'avoid token sales, you mug'
- discombobulate 9y agoCan it? I understood it as more nuanced.
- joosters 9y agoIMO, not Vitalik's
- discombobulate 9y agoVitalik was talking about token sales that give discounts to large buyers. And that they can be circumvented via collective-buying smart contracts. I got that information by reading his tweet. Frankly, I don't know what you're talking about. I would imagine if he was trying to convey one should avoid all token sales he would have said something similar to that. Not something specific to a specific situation. The trick I'm employing involves reading comprehension.
- admax88q 9y agolol
- water42 9y agothe only response to something like this
- whataretensors 9y agoPeople lost like half a million dollars and a talented immoral person got a huge reward signal for basically being a predatory jerk. Although I can see the humor, it seems unreasonable to derive joy from such a thing.
- aw3c2 9y agos/People/Gamblers If you cannot afford losing everything you put into cryptocurrencies, don't do it.
- pavel_lishin 9y agoI think there's a whole subreddit dedicated to Bitcoin schaudenfreude. It's fun at first, but then you start reading about the people (presumably with undiagnosed gambling addictions, but hey, I'm not a psychologist) who dump their entire savings, their kids' college funds, etc. into Bitcoin and then lose the whole shebang. That's the kind of decision that will break apart families.
- metroidfan832 9y agoOne Bitcoin is over $2000. How could someone dump everything into Bitcoin and lose the whole shebang?
- detaro 9y agoBy making mistakes: Loosing your wallet, accidentally sending it to the wrong address, having it in the wrong exchange at the wrong time, ...
- SomeStupidPoint 9y agoSo it was their website that got hacked, not their cryptocurrency widget (or whatever the appropriate term is)? I mean, not unexpected: hit the softest part of the chain, which in this case seems to be a webserver rather than the crypto/contract. Just trying to make sure my understanding is correct.
- proto-n 9y agoThe webserver, or you know, their wordpress website (at least according to reddit).
- deleted 9y ago[deleted]
- arcaster 9y agoThis was bound to happen at some point... It'll be interesting to see how low the dip goes as a result of this ICO failure.
- AsyncAwait 9y agoThis seems to be the same problem that many open-source projects have, where the md5 hash to verify your download is at a single, (often the same) location. One possible solution would be to use Twitter pinned tweet to also announce the address, however it's questionable how many people would actually cross check.
- ericfrederich 9y agoI always found that fascinating myself, serving the download and checksum from the same source. Doesn't http have enough redundancy checks built in to make this pointless? The only time to really do a checksum isn't on a browser download, it's when you push it over some serial connection, or android adb or something else.
- sjbase 9y agoI suppose the "Here's the MD5 for your download" concept is useful if the file is being served from a different host than the website itself. Someone could tamper with the file server, but may not have access to the HTML rendering a link to that file server. But you're right about serving the data & checksum from the same source. I don't see what extra layer of security or integrity it adds. Someone tampering with server file system, or the data transfer (MitM) inherently has the access they need to inject their own MD5 into the HTML.
- simias 9y agoIt's useful if you have already downloaded the file from somewhere else and want to check if it's the right one without downloading everything from scratch. Furthermore it's very much possible to get corrupt data over HTTP if you have a poor connection and download a big file. If you want a really secure "checksum" you best bet is probably a GPG signature file from a wildly distributed and trusted key.
- Cshelton 9y agoI know given the thread this is in makes it ironic, but a public blockchain would actually serve as a pretty good place to keep a check sum ;p You would check the official blockchain address for a repository and know that the checksum there has not been modified. As long as the process of creating the transaction is done correctly.
- dvcc 9y ago'Hacked' - or just stolen. Who could ever know in crypto-land? I am sure the ICO contract had something about lost coins in it as well.
- dullgiulio 9y agoNeither. They hacked the webpage and wrote a different address to send money to. Similar to me sending you a letter that I am Oxfam, please send me money. If only the crypto-currency world had laws and the institution of justice...
- deleted 9y ago[deleted]
- lightbyte 9y ago>If only the crypto-currency world had laws A law isn't going to magic peoples coins back if they hit send to the wrong address.
- cyphar 9y agoIt won't magic anything, the person gets caught and court makes a ruling like every other criminal action. That's like saying that laws can't magic a stolen bag of cash in a getaway car back to it's rightful owner. You're right that it's not magic, it's the justice system. And if they don't have the coins, they have to sell assets or go bankrupt.
- greenshackle2 9y agoI think he means CoinDash themselves could have altered the address and claimed it's a hack - which would make it straightforward theft, not a real hack.
- mcherm 9y agoWhere does the amount in the title ("45k ether") come from? I didn't see that in the article. EDIT: Apparently from https://etherscan.io/address/0x6a164122d5cf7c840D26e829b46dCc4ED6C0ae48 https://etherscan.io/address/0x6a164122d5cf7c840D26e829b46dC... , which is something I don't have the depth of knowledge to assess for myself.
- ericfrederich 9y agowow... 6 minutes ago, 1 minute ago... people are still sending this address money?
- forthefuture 9y agoThis sentiment is how normal people feel about all cryptocurrency.
- JustAnotherPat 9y agoYes, it's not really being talked about anywhere because people like to keep this stuff hush hush, so crypto doesn't look bad.
- urethrafranklin 9y agoA sucker is born every minute.
- Moter8 9y agoETH Balance: 43,432.963 ... is the important figure. At the bottom you can see the transactions coming in. First incoming transaction seems to be from Jul-17-2017 01:01:21 PM. View all > last page.
- mcjiggerlog 9y agoOver €6,000,000 at current prices.
- imron 9y ago
- imron 9y ago'hacked'
- dsun176 9y agoRunning a P2P-ICO over a centralised server. Good job coindash. That's exactly what you deserved.
- detaro 9y agoDo other ICOs do a better job distributing instructions? EDIT: so, apart from posting the address across as many channels as possible, and telling people to cross-check, what options are there? You could announce addresses way beforehand and have them send ETH to the final address once you release it, using that as a signal.
- arcaster 9y agoUsually, companies conducting ICO's only release the block number in advance, the smart contract address is generally released last sometimes just hours before the ICO start time.
- joosters 9y agoAll ICOs are centralised. It's lots of people sending their money to one entity, never the other around.
- albertgoeswoof 9y agoNo problem, just hardfork and start again
- dvcc 9y agoThat only works when the money is tied to one of the core developers. Don't worry though, blockchains are immutable and safe from centralization.
- 542458 9y agoWait what? I'm not up to date on all the cryptocurrency going-ons. What's this referring to?
- JoshTriplett 9y agoOne of the main Ethereum code-contracts, the DAO ( https://en.wikipedia.org/wiki/The_DAO_(organization) https://en.wikipedia.org/wiki/The_DAO_(organization) ) had a bug in its code, and someone exploited that bug to extract the value from it. Rather than accept that as consistent with their view of "the code is the contract", the Ethereum developers hard-forked the currency to reverse that result and give everyone their money back.
- qyv 9y agoOh good, so they should be able to do that now and give everyone there money back again. Thank goodness for decentralization! /s
- farresito 9y agoI think he is being sarcastic. He just means that they call it decentralized except when there's a problem that affects the core developers; it's then that they allow themselves to make exceptions, like I believe it happened a year ago or so.
- kalleboo 9y agoThere was an Ethereum contract called The DAO which had a bug in it that got taken advantage of. They decided to hard fork all of Ethereum to retrieve the appropriated money. It's seen as some as an admission that the Ethereum ethos of "the code is the contract" is unrealistic. https://en.wikipedia.org/wiki/The_DAO_(organization) https://en.wikipedia.org/wiki/The_DAO_(organization)
- option_greek 9y agoI don't understand how any of these ICO companies are valued so high. If they had to raise this 12mil from VC/PE would they still be valued the same ?
- sharemywin 9y agoBecause it's not real money, most of it is just bitcoins that got converted to ethereum that got converted to coin dejur. Can you cash it out in small quantities sure, but unless something tangible comes of it you have nothing but worthless tokens.
- deleted 9y ago[deleted]
- hn_throwaway_99 9y agoI think that is key. It's similar to the .com boom (and bust) in the early 2000s. You had lots of examples where super-inflated company A bought company B, and paid for it with their super inflated stock. While the "values" reported won and lost where in the billions (trillions?), the fact is that relatively little of it was actually converted back and forth to real dollars.
- mhluongo 9y agoNo. On top of that, the tokens aren't usually for equity
- fokinsean 9y agoThat's a bummer since Coindash appears to have an MVP and a reasonable funding cap of $12MM. I wouldn't wish this on anyone, but it's unfortunate it didn't happen to one of the scammy ICO's instead. On a side note showcasing the ridiculousness of some of these ICOs, [1]"Useless Ether Token" (UET) raised around $45k and literally doesn't do anything. [1]: https://coinmarketcap.com/assets/useless-ethereum-token/ https://coinmarketcap.com/assets/useless-ethereum-token/ https://uetoken.com/ https://uetoken.com/
- trophycase 9y agoYou do realize that everyone knows UET is a joke right?
- nikolay 9y agoWhere's the news?! Why do people continue to bang heads against the wall with this madness? Unless you're a thief, how is the craptocurrency thing better than my credit card that's insured from unauthorized use and gives me a cash back?! Yeah, you can't speculate with credit cards, and get rich quick, because $1 = $1 like forever, but isn't that what the real investment tools are for?
- btown 9y agoEveryone in cryptocurrency seems to have forgotten that the adage "the devil you know vs. the devil you don't" was a recommendation to prefer the former.
- easytiger 9y agoEveryone in Crypto Currencies are besotted by the "we are in at ground level of a tech revolution" idea... namely they think they saw the kids of the 80s/90s get easy low qualification required tech jobs and one man shops making 100s/millions/dollars. They are the modern prospectors. Free gold on unclaimed land. Like any decent business thinker you don't see the rough edges of your focus. Sometimes when you do it can cripple you. But then again most business fail.
- canistr 9y agoIt's a cute analogy perpetuated by GenX VCs and crypto-wonks who don't see a down-side in making bold, wild claims. It's one of the many problems today in which there is no down-side risk on making extremely early predictions. No one will call you out on being wrong. I view it similar to people who have been calling for another tech bubble and the subsequent market crash even though we're still very much in the midst of consistent All-Time Highs.
- mhluongo 9y agoWhat are you talking about? The dollar loses to inflation every year. A 1990 dollar is $1.87 in 2017 dollars.
- ty_a 9y agoFor anyone wondering, 45k ETH is about 7.65M USD.
- option_greek 9y agoI wonder what happens if someone wants to liquidate this amount to USD immediately. Has ether got enough liquidity to handle it :)
- nashashmi 9y agoI think there was a recent 20% crash in ether price. Probably a result of immediate dumping from this hack.
- arcaster 9y agoYep, there's more than enough liquidity. People clearing more than $70k USD worth of ETH are usually going through OTC channels, not through exchanges like Poloniex and Coinbase. OTC fees are generally higher than exchanges, but offer the advantage of legally guaranteed finality and no chance of slippage affecting your transaction (exactly what happened with GDAX when the price of ETH briefly dropped to $0.10). When deals are large enough, sometimes they are even executed as a set of "tranches" (large set of smaller transactions over time) so the transfer isn't easily traceable and counter-parties remain largely unknown.
- immad 9y agoYes, Ether has $1.5bn in trading volume for the last 24 hours [1]. 1: http://coinmarketcap.com http://coinmarketcap.com
- ganonm 9y agoEither the average blockchain startup is unbelievably amateurish re. security or this was an inside job. I suspect the latter but the former does not surprise me one bit.
- kalleboo 9y agoIsn't most of the IT field unbelievably amateurish re. security? Just look at the bi-monthly releases of user lists from major companies. This is why I think wide adoption of cryptocurrency is a bad idea. Complete computer security is nearly impossible (I want to say completely impossible but I'll end up in an endless debate about single use offline computers printing out paper wallets).
- ganonm 9y agoI think this is a disingenuous argument. Yes the vast majority of the IT field are not experts but if you don't hire one of these experts to secure your system, a system which is aiming to raise $12m, then you shouldn't be surprised when you get hacked. Also, just because you're not an expert does not mean that you have any excuse to be completely clueless and make stupid mistakes.
- tuxxy 9y agoI have seen the code of a Bitcoin startup. Believe me, security is the last thing on their minds. Personally, I find it exceptionally naive that these startups think they can handle payment processing, payment storage, and their core product at the same time. If you're a startup, at least two of these will be ignored for favor of another. One of them makes you money/users, the others don't.
- lloydde 9y ago> CoinDash's Token Sale page was tempered... Now reads "tampered", but "tempered [sic]" would seem to have been appropriate if really was the message sent to investors. Funny how the subheadline had the typo before as well.
- LyndsySimon 9y agoThis is the sort of email you don't spend a lot of time spellchecking.
- lloydde 9y agoRight, I was thinking more of the news site.
- kin 9y agoDoes Ethereum not have an escrow like Bitcoin where a 3rd party can confirm a transaction first? But also, if it's really as easy as replacing some arbitrary address with another I'm surprised Coindash wasn't more careful.
- 52-6F-62 9y agoI believe that is entirely up to the contract programmer(s), and the potential buyers to vet.
- DennisP 9y agoThat's a simple contract, but... If the ICO implements that, there's no protection from someone replacing the ICO address. If buyers use escrow contracts, they have to confirm their transactions before the ICO closes, so for typical hard-capped ICOs you don't have much time to verify things. When the crowdsale's website is displaying wrong information, there's no other source, and the sale is rapidly approaching a hard cap on contributions, there's not much you can do. A better defense against this type of attack is to use the Ethereum Name Service, and publish the address well in advance. It would also help to use crowdsale structures that don't incentivize a mad rush, such as: http://www.blunderingcode.com/fairtokensales/ http://www.blunderingcode.com/fairtokensales/
- sharemywin 9y agoI wonder if a block chain could certify websites: 1. someone writes a url to the chain 2. others post a (url/hash/date time) of the output of the url 3. then people could post an image with their face and a blockchain address. could be a form of ID.
- 52-6F-62 9y agoThere are various groups working toward a blockchain id system including Thomson Reuters[0], and a Microsoft/Phillips-backed company Tierion[1] -- both on the Ethereum public chain. [0] https://blockoneid.thomsonreuters.com/ https://blockoneid.thomsonreuters.com/ [1] https://tierion.com/ https://tierion.com/
- Cshelton 9y agoThis is what the ENS (Ethereum Name System) will be doing. In face, if you see an ICO on the Ethereum platform that doesn't use the ENS, avoid it. The ENS is actually really cool. Although, you should probably avoid all ICO's =p
- imron 9y agoI should launch an ICO.
- deleted 9y ago[deleted]
- eugeneionesco 9y agoYep https://motherboard.vice.com/en_us/article/evd5je/an-ethereum-token-called-fuck-raised-dollar30000-in-30-minutes https://motherboard.vice.com/en_us/article/evd5je/an-ethereu...
- icoicoico 9y agoWaiting for their announcement, but this would be a great way to pull a quick scam. Make a decent looking site promising a random piece of software that seems legit, promote an ICO, setup a fake wallet, then when the ICO goes live claim your site was "hacked" and points to a fake wallet you control. Grab a few million and never have to actually write said piece of software.
- justusw 9y agoCould HTTP public key pinning have prevented this at least partially?
- williamscales 9y agoNot necessarily, because the issue here is that the website containing the address itself was altered. If an attacker can get access to the web server then HTTP public key pinning does nothing to protect you. What would have worked, however, would have been to pin the ICO address to the blockchain in advance. Same concept.
- buryat 9y agoI tend to believe that it was a scam because they refused to disclose the contract beforehand and there were some people claiming that it's a scam few months before [1]. [1] https://bitcointalk.org/index.php?topic=1905500.0 https://bitcointalk.org/index.php?topic=1905500.0
- Obi_Juan_Kenobi 9y agoI say this without an ounce of hyperbole: I assume all ICOs are a scam until convinced otherwise. The majority aren't outright scams (willful intent to defraud), but most are capital grabs with virtually no chance of being successful businesses.
- jamespitts 9y agoImportant information related to this incident: 1. CoinDash did not publish the address of the contract in advance of the ICO: https://www.reddit.com/r/ethereum/comments/6nsy6x/coindash_website_hacked_55_mil_gone/dkbx57x/ https://www.reddit.com/r/ethereum/comments/6nsy6x/coindash_w... 2. Allegedly, CoinDash ignored issues brought up by a software contractor / code reviewer: https://www.reddit.com/r/ethtrader/comments/6nrxk5/never_miss_an_ico_again_coindash_cdt/ https://www.reddit.com/r/ethtrader/comments/6nrxk5/never_mis... > In reviewing their crowdsale code, I found multiple bugs and many errors. I've been ignored since I brought up the problems with the CoinDash team three days ago.
- _jtrig 9y agoThe entire point of Cryptocurrency is to step away from institutional trust, not dive head-first into it. Bitcoin succeeds as a scarce and sovereign wealth management tool but once you give away the private keys, you lose those advantages.
- nosuchthing 9y agoBitcoin is only scarce for late adopters, by design early adopters of BTC software generated thousands of "coins" per week for running a mining-computation node of a normal 2-3GHz CPU. BTC's network protocol service is not unique, and thus not scarce in the least. I.E. other protocols/network designs/token-ledgers offer the same service as BTC in addition to fixing the vulnerability to BTC's hashing algorithm which has led to the ASIC attacks on the Bitcoin network which just lead to centralization by the hardware producers.
- _jtrig 9y agoYou don't understand how currency functions and you certainly don't understand how bitcoin operates. I'll leave you to consoling yourself.
- nosuchthing 9y agoPlease enlighten us. Here are some facts: As per the design of the Bitcoin software, payouts were made to users running standard home PCs with simple ~3Ghz processors, and as a result, the software minted thousands of BTC tokens to their accounts for the rather trivial processor cycles. As per the design of the bitcoin protocol, running the bitcoin software now on the same computer, would mint a fraction of a coin. Bitcoin was designed to favor the people who created it, and the few early users who ran the software. The assumption that the bitcoin service is unique, rare, or scarce is just not the case. The historical records of these ponzi payouts are public record. Hundreds of alt coins with active 'networks' are running on the public Internet right now, offering the same service as the BTC network, and often improved upon features like scrypt, ZKP, or the EVM. The divestment of digital beanie babies as I passed the hot potato of a 2.4-transaction-per-second digital message system with a horrible dev team and censor happy community currently in a civil war, to rubes who exchanged actual universally accepted fiat paper was enough to console me for a years to come. Maybe we are all destined for the moon, as the legends go. Because a distributed database message system and expansive misinformation campaign has convinced people as much. Or maybe bubbles are temporary?
- sna1l 9y agoThis underscores the need for legitimacy and best practices around ICOs. I think CoinList (angellist company) will end up killing it in this space.
- free_everybody 9y agoPlease please PLEASE do not buy into these ICO's. Nothing but vapor, I promise you. Crypto is going to crash SO hard if people keep giving these ICO scammers millions of dollars for each slick marketing campaign they can spin up.
- handzhiev 9y agoHas anyone here played with "HYIPs" few years ago? Stories with many ICO are so similar.
- glacier 9y agoWho's to say they didn't do this themselves? $7m is a lot of money.
- Dolores12 9y agoSo you just got robbed. What law enforcement agency will you complain? Gold rush & Wild wild west.