Professional Documents
Culture Documents
Colin ZS Bitgrail Chat Log TheBomber
Colin ZS Bitgrail Chat Log TheBomber
Hi Colin
Colin LeMahieu 11:08:21 AM
CL
How's it all going?
The Bomber
Hey B, I just talked to Colin. He said that time stamps on th…
^
Colin LeMahieu
The time stamps on the site are when the transactios arrive…
Can there be exceptions?
Colin LeMahieu
Well it's similar to a "last accessed" timestamp. It's just stor…
check this
https://raiblocks.net/account/index.php? 11:15:39 AM
acc=xrb_37qbnxbqutynm1yq6ui6bw7q738jqn6we6wikahh74g
63wwh96yjs3oun8gy
(https://raiblocks.net/account/index.php?
acc=xrb_37qbnxbqutynm1yq6ui6bw7q738jqn6we6wikahh74g
63wwh96yjs3oun8gy)
F9F8F3 11:15:49 AM
Colin LeMahieu
As far as I know we've never changed any of it, it should be …
have you checked the txs of that address?
the first one is the last one if you see the date
and there are so many all with the same date 11:20:21 AM
millions* 11:20:34 AM
https://raiblocks.net/block/index.php? 11:21:33 AM
h=7547EDDDB87D6D47975B6EA98A41BEB6C7DE31C952C0BF
2487F6E8E3DB8D4BE9 (https://raiblocks.net/block/index.php?
h=7547EDDDB87D6D47975B6EA98A41BEB6C7DE31C952C0BF
2487F6E8E3DB8D4BE9)
https://raiblocks.net/block/index.php? 11:21:44 AM
h=DA8A14DA791F26AB923ED69FE7B9AF7838A3AA529C768C
ED18F8009A5F6764F9 (https://raiblocks.net/block/index.php?
h=DA8A14DA791F26AB923ED69FE7B9AF7838A3AA529C768C
ED18F8009A5F6764F9)
All transactions that are stolen have the wrong date. 11:22:40 AM
When your system makes trades, do you keep a date of when it 11:23:12 AM
operates?
Colin LeMahieu
When your system makes trades, do you keep a date of whe…
trades, withdraws, deposits yes
we can try to calculate the date but is very difficlt if explorer is 11:24:30 AM
incorrect
this is why I asked zack if it was accurate edited 11:24:46 AM
That's just a local date to the explorer machine though, it's not 11:25:43 AM
a guaruntee.
we have suffered a stolen and did not know when this was
Colin LeMahieu
For instance if you have a record of a deposit for hash AAA…
if not, we havent a date
Zack Shapiro
how much have you allegedly lost exactly?
Seems 15 MLN
Zack Shapiro 11:31:04 AM
ZS
XRB or USD
XRB
Zack Shapiro
didnt you only have 6 in your wallet?
we have 4 in our wallet right now
https://raiblocks.net/account/index.php? 11:31:54 AM
acc=xrb_39ymww61tksoddjh1e43mprw5r8uu1318it9z3agm7e
6f96kg4ndqg9tuds4 (https://raiblocks.net/account/index.php?
acc=xrb_39ymww61tksoddjh1e43mprw5r8uu1318it9z3agm7e
6f96kg4ndqg9tuds4)
https://raiblocks.net/account/index.php? 11:32:00 AM
acc=xrb_31a51k53fdzam7bhrgi4b67py9o7wp33rec1hi7k6z1w
sgh8oagqs7bui9p1 (https://raiblocks.net/account/index.php?
acc=xrb_31a51k53fdzam7bhrgi4b67py9o7wp33rec1hi7k6z1w
sgh8oagqs7bui9p1)
Zack Shapiro
if someone stole 15M, it would be on the chain somewhere...
if we get all addresses you can block in some way?
Zack Shapiro
how are you determining if a transaction was "stolen"
is not in our database withdrawals list
maybe 11:33:18 AM
Zack Shapiro
what if it's a bug in your code where you just didnt record it 11:33:32 AM
ZS
what if it's a bug in your code where you just didnt record it
no we have the balance of all users
anyway i've closed all XRB markets and XRB deposits / 11:35:44 AM
withdraws right now
Zack Shapiro
do you have transactions coming from your wallet(s) to any …
yes
The Bomber
user with this address -> https://raiblocks.net/account/in…
this is one of the address who stole the xrb
Zack Shapiro
@TheBomber how much do you owe people, how much do …
Users:
19069089.34979714
https://raiblocks.net/account/index.php?acc=xrb_39ymww…
have: ^
Zack Shapiro
so you owe 19M and you have ~6M?
no
not 6 11:45:04 AM
https://raiblocks.net/account/index.php? 11:45:17 AM
acc=xrb_39ymww61tksoddjh1e43mprw5r8uu1318it9z3agm7e
6f96kg4ndqg9tuds4 (https://raiblocks.net/account/index.php?
acc=xrb_39ymww61tksoddjh1e43mprw5r8uu1318it9z3agm7e
6f96kg4ndqg9tuds4)
The Bomber
Colin LeMahieu 11:45:36 AM
Your other account has 2m more it seems?
2k
https://raiblocks.net/account/index.php?
acc=xrb_31a51k53fdzam7bhrgi4b67py9o7wp33rec1hi7k6z1w
sgh8oagqs7bui9p1 (https://raiblocks.net/account/index.php?
acc=xrb_31a51k53fdzam7bhrgi4b67py9o7wp33rec1hi7k6z1w
sgh8oagqs7bui9p1)
anyway
https://raiblocks.net/account/index.php? 11:47:50 AM
acc=xrb_1fioob7u6ia76rfo1medtrwwdobey1ua8qe7z55qyjimir
5b9d95hkdabbjn (https://raiblocks.net/account/index.php?
acc=xrb_1fioob7u6ia76rfo1medtrwwdobey1ua8qe7z55qyjimir
5b9d95hkdabbjn)
Zack Shapiro
when did you first find out about the hacker
this morning
My lawyer and I are going to the police, when we come back we 11:52:17 AM
will give the news of the stolen
Thnaks
4.002.000
Zack Shapiro
And how much was “hacked?”
15 mln
yes zack
It looks like it’s been going on for months from the chain 11:56:56 AM
if you get bitgrail exchange you can refund with burned coin 11:57:21 AM
and give users their funds
Zack Shapiro
Why did you just close trading if you “discovered” this 8 ho…
We spent time trying to understand what happened
Zack Shapiro
You didn’t notice anything at all was wrong until 8 hours ago?
no Zack, iin case i had suspended the trade before
Zack Shapiro
I don’t understand?
we spotted the problem this morning
Zack Shapiro
If withdrawals have been closed for the last month, how did…
currently no one know WHEN the hack was done
date* 12:02:46 PM
The Bomber
Colin we only have these transactions with 19 Junuary as dare
and nobody can explain why
The Bomber
Colin LeMahieu 12:04:15 PM
Ok, what hash/date happened before the bad transactions …
You probably don't understand
Colin LeMahieu
Right, before those transactions, you have valid withdrawls …
yes
Colin LeMahieu
Right, before those transactions, you have valid withdrawls …
how can i know what are the transaction before?
Top is most recent and bottom in least recent in that exact 12:05:40 PM
order.
The Bomber
Colin LeMahieu 12:05:47 PM
Top is most recent and bottom in least recent in that exact …
yes
So find a deposit/withdrawl before and after and then you have 12:06:24 PM
a range.
The Bomber
https://raiblocks.net/account/index.php?acc=xrb_37qbnxb…
^
yes colin we can have the last stored info to get the renge
One solution can be, I give you bitgrail with all wallets and db, 12:32:05 PM
and you fork the burned transaction to refund users
Your transaction log date/hash for before and after, any 1:01:31 PM
transaction, doesn’t need to be the same account.
().txt 21 KB
Download ()
our timestamp
ok 1:36:43 PM
Zack Shapiro
we're having a team conversation
Guys ping me when you’re done
Zack Shapiro
let us think about it
One thing zack
We need to report to the police the solution too to avoid website 2:39:39 PM
shutdown by police
Zack Shapiro
explained what thing
When i will come to police to report the stole, probably they
confiscate the server to be able to investigate
I think 2:43:20 PM
So, if you are able to get a solution for the stolen, better to
report to the police too 2:44:00 PM
Zack Shapiro
ok. speak in the morning
Is there any possibility to fork the chain and get xrb from burned
address?
Zack Shapiro
Can we talk about this tomorrow?
Yes, tomorrow mean in 10 hours here
Hi guys
Zack Shapiro
We’re not making a statement with you. 1:05:31 AM
ZS
ok, we have to do it
Due to an xrb bug that caused the node to crash, the attackers
forced the system to get double payments for which we have no
trace of time due to another bug in xrb official explorer.
We are going to report the incident to the police, first and then 1:17:33 AM
we will explain what happened
I hope you have understood this before making the decision not 1:19:28 AM
to cooperate