Suggested to not buy Bytecoin, DashCoin, DigitalNote (Bug in CryptoNote found)

7 days ago
72 in bitcoin

For start to keep things clean and not scare people dont dont know whats up - DashCoin is NOT DASH
Monero, Bytecoin, DashCoin, DigitalNote are coins based on CryptoNote, they are forks.

XMR team has found a bug in the code some time ago allowing to create unlimited free coins in this technology.

They patched it and let other coins know. Aeon, Boolberry and Forknote are updated now along with XMR.

BCN DSH XDN still didnt update and news of the vulnerability are now public.

Mitigation (quote if the original article gets edited)

Several options exist for mitigation. The simplest, least invasive is noted below.

To mitigate, check key images for correctness by multiplying by the curve order l. Check that the result is the identity element.

Hexadecimal values of each:

Identity element = "0100000000000000000000000000000000000000000000000000000000000000"
Curve order (little endian) = "edd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010"
For each transaction key image, check ((key image * curve order) == (identity element)); reject transaction if false.Several options exist for mitigation. The simplest, least invasive is noted below.
To mitigate, check key images for correctness by multiplying by the curve order l. Check that the result is the identity element.
Hexadecimal values of each:
Identity element = "0100000000000000000000000000000000000000000000000000000000000000"
Curve order (little endian) = "edd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010"
For each transaction key image, check ((key image * curve order) == (identity element)); reject transaction if false.

Mentioned Coins Pumping



I suggest waiting for patches to be confirmed by devs.

Follow, Resteem and VOTE UP @kingscrown creator of http://fuk.io blog for 0day cryptocurrency news and tips!

Authors get paid when people like you upvote their post.
Join our amazing community to comment and reward others.
Sort Order:  trending
68
  ·  6 days ago

In addition to the updated coins mentioned in the quote, Dashcoin (not Dash, which is unaffected) was already updated and Bytecoin released an update yesterday.

·
72
  ·  6 days ago

Great to know! Upped so people see your comment

·
61
  ·  6 days ago

That's great @smooth. I'll make a note on my post on about this issue.

46
  ·  5 days ago

Thanks for update

·
53
  ·  7 days ago

Lol - I used her yesterday.... hard hacking kittie :)
https://steemit.com/story/@hastla/thinkings-ransomware-wannacry-i-wanna-cry

·
·
43
  ·  6 days ago

:D

·
·
·
39
  ·  7 days ago

No time to waste.
z4Ci0f.gif

·
68
  ·  7 days ago

cute kitty hacking the bitcoin ....... ha ha

·
·
43
  ·  6 days ago

kitty will be rich in minutes and forget where he stores money :D

·
·
·
68
  ·  6 days ago

HA HA ........ :D

·
32
  ·  7 days ago

This is literally me at work lol

·
·
43
  ·  6 days ago

:D

64
  ·  6 days ago

Congratulations @kingscrown!
Your post was mentioned in my hit parade in the following categories:

  • Upvotes - Ranked 4 with 479 upvotes
  • Pending payout - Ranked 2 with $ 396,18
65
  ·  6 days ago

Create unlimited free coins on all coins forked from CryptoNote before the fix?

The exploit allows double-spends. It allows anyone to create an infinite amount of coins in a way that is impossible to detect (unless you write special code to look for it)

Monero claims their chain is safe and they've already checked it.

Who has checked Monero's test? How can you look for these inflated coins?

Basically it means you could use your wallet to "pump up" other wallet balances with double spends. You could then sell these fake created coins on exchanges or stock pile them.

You basically have to edit every transaction on the entire chain.

I personally will not be buying any CryptoNote forked coin including Monero until more information is available. :(

This is a massive problem.

·
68
  ·  6 days ago

Who has checked Monero's test? How can you look for these inflated coins?

The detection is built into the standard node (and the code for that is in github, in case you want to check it). If you are using any recent version and you have synced from scratch then you have checked that the entire chain is devoid of any use of the exploit.

·
·
65
  ·  6 days ago

EXCELLENT. This info needs to be on the Monero website. Makes a lot of sense.

·
·
·
51
  ·  4 days ago

The method is core::check_tx_inputs_keyimages_domain(const transaction& tx) const. If you do hack and dump, send a tip my way. :)

37
  ·  7 days ago

Awesome - bought em yesterday... : )

·
54
  ·  7 days ago

Is it? It seems also rather old, as often it happens.

42
  ·  7 days ago

Really appreciate you taking the time to share this! There is so much to keep up with in this crypto world!

42
  ·  6 days ago

Dam the hackers are making it more and more scary... Anything related to internet is becoming scary.

36
  ·  7 days ago

Good to know. I'll transfer more fund to steem... :)

56
  ·  7 days ago

Careful bugs aboard!

46
  ·  5 days ago

thank you for the info and this was very interesting and makes me think of how too do it better

42
  ·  6 days ago

weird pump begin
PD325923_1.JPG

42
  ·  7 days ago

Hmm that´s actually a little scary, especially whenever you have a look on the value of some coins. It got a serious market that could experience a major drawback in case someone is successful on such a bug on a major coin... Especially as the public would then just be driven away even further from crypto.

61
  ·  7 days ago

Good catch on this man, thank you.

41
  ·  7 days ago

Thanks for the update. Soo many of these pump and dumps on the market these days. I think it's important to research the team behind the coin first and foremost for long term investment. Otherwise it's essentially a dice roll.

64
  ·  7 days ago

great post! what with us that have some money in monero and dash?

·
46
  ·  7 days ago

he clearly said it's NOT DASH (dude, he stressed in all-CAPS that DasCoin is something different), read it!

·
72
  ·  7 days ago

XMR and DASH are safe, dont worry

·
·
64
  ·  7 days ago

thanks :)

·
68
  ·  6 days ago

Dash is Bitcoin-based and does not relate to this issue. DashCoin is Crptonote derived and was patched, although the Monero statement originally incorrectly said otherwise (may have been fixed now, I'm not sure).

·
·
64
  ·  6 days ago

thanks :)

·
·
67
  ·  3 days ago

@smooth I have been trying to contact you... Please check your messages on Chat! Thanks. Sorry for my unrelated comments here @kingscrown... he's a hard man to find sometimes!

42
  ·  7 days ago

Wow this is new to me. I never heard!

58
  ·  7 days ago

Maybe edit the title slightly to "found and patched/fixed". Thanks for the info.

/Thomas

37
  ·  7 days ago

I like to invest in 3 coins, i start with litecoin....but what others can i choose, Some low cost who have potential to grow...i have zero exp in cryptoccurencie.

40
  ·  7 days ago

Good to know. As I am still a newbie with crypto, does this mean that if endless supplies of those coins can be made from think air like in fiat currencies that that particular crypto will soon be worthless???

·
72
  ·  7 days ago

if somebody does the attack before its patched - then yes, it can be dumped to zero

·
54
  ·  7 days ago

It would be a problem for sure. Bitcoin had bugs at least one important bug, and needed patch, too. It is important that everyone updates the software as soon as possible. Anyway, it seems to be an old scam, though I haven't double checked.

25
  ·  7 days ago

Dash not updating is disconcerting

68
  ·  6 days ago

That's fucked up.

45
  ·  7 days ago

Something did seem really fishy about that bytecoin pump! Thanks for the info

39
  ·  7 days ago

Nice catch. Thanks for the heads up.

52
  ·  6 days ago

Thanks for information @kingscrown

67
  ·  7 days ago

So those of us that only have Steem have nothing to worry about right???

·
59
  ·  7 days ago

Well, only those who're of high self-eSTEEM, of course ;)

68
  ·  7 days ago

thanks for alerting :)

40
  ·  6 days ago

Vote for me, please.

45
  ·  6 days ago

Lets avoid it..

62
  ·  7 days ago

Whaaat? I was longing Monero!?!

·
72
  ·  7 days ago

XMR fixed the bug and found it, no worries here (unless the bug was exploited before patching)

·
·
62
  ·  7 days ago

Hehe, it is fine! I do have some, but I was referring to @meesterboom's crypto trading post. Good to have a heads up! Thanks!

25
  ·  7 days ago

Well I saw this yesterday (link below) and thought it interesting, but there are websites since 2015 that mine Doge coin; a game you play using a pick-axe, your doing the work while they get coins.

https://cointelegraph.com/news/wannacry-not-first-nsa-enabled-cyberattack-hackers-made-computers-mine-monero

55
  ·  5 days ago

It's funny to watch how bytecoin has been pumped like crazy recently. The project looks almost dead, has a non-functioning wallet (for Mac) and still it entered top 10 in market cap. To me it is proof you better watch out which train you jump on. Bytecoin is scratched from my list at least. I mined it this winter and sold the last pieces in the latest pump. Could have done better, but i dont care. There are better projects out there.

44
  ·  7 days ago

What do you guys and gals think about gridcoin or ripple?

43
  ·  5 days ago

up voted for this information almost buy the dnote

40
  ·  3 days ago

hey, good job there! Check out my profile, if there is anything you like. If you could just upvote it, it would made my day.

46
  ·  yesterday

Great!
I'm buying SWT, STEEM adn WAVES!
Steem on!