3s3s / opentrade

OpenTrade - Open Source Cryptocurrency Exchange
MIT License
396 stars 401 forks source link

hack !!! https://altmarkets.cc/announce #207

Open diakas opened 5 years ago

diakas commented 5 years ago

https://altmarkets.cc/announce

After investigating all of the logs and balances here is what the hacker has taken:

864878 doge

2.785 BTC

61924 x42

What happened? They have the old version?

ghost commented 5 years ago

I have been in some chats when them and they were up to date on the git

juanmantelli commented 5 years ago

Is important for all of us to know what happend. We have to improve the security of the code together

cryptobot123 commented 5 years ago

inside job

IMPERIUM-main-dev commented 5 years ago

......

IMPERIUM-main-dev commented 5 years ago

Either they got hacked or it was an exit scam.

IMPERIUM-main-dev commented 5 years ago

Or they just did not use the latest opentrade code or they added bad code.

IMPERIUM-main-dev commented 5 years ago

Starving this month because I got listed 10 days for 0.01 BTC and I'm poor.....

ExchangeTime commented 5 years ago

They deleted everything, destroyed and left their discord. No posts on twitter and other social medias. Talking about SQL injection on balance. Isnt it grabbing the account from RPC wallet before any withdraws meaning even if you change the values on website you cant go > userID / wallet account.

Looks like a 100% exitscam from their side as i even got banned from their discord when i came with facts.

jonn4y commented 5 years ago

normally i wouldn't waste my time responding to shit like this but ok. 1: " Isnt it grabbing the account from RPC wallet before any withdraws meaning even if you change the values on website you cant go > userID / wallet account."

you clearly do not know how OpenTrade works, all balances from the wallet account go to a root account and everything is then handled via database.

2: you prob got banned for being a dick / troll

3: if it was an exit scam, we wouldn't be refunding everyone, we would have taken all the balances and dumped them on other exchanges. you would see the proof of our refunds going out but, you are banned so yeah

huuhait commented 5 years ago

change to peatio :)) image

Latinex commented 5 years ago

is a problem of opensource, should be updated much more, there is only one person working on the base code while there should be people reviewing several points, a part would need a much wider readme

Latinex commented 5 years ago

change to peatio :)) image

Peatio is built in ruby5, it is quite difficult to edit, it also needs many more resources and is much less scalable

huuhait commented 5 years ago

Of course it's not for noob

ExchangeTime commented 5 years ago

@Latinex @Thedabest What layouts on peatio is that?

Latinex commented 5 years ago

@Latinex @Thedabest What layouts on peatio is that?

https://rubykube.io/

huuhait commented 5 years ago

my custom layouts rubykube use default peatio layouts

diakas commented 5 years ago

Opentrade the author stops posting updates to github https://bitcointalk.org/index.php?topic=2509833.msg48033457#msg48033457

Most likely they had an old version of the engine. Or one of two... By the way I decided to stop to upload a new version to github. So who will forcat - looking for programmer which will be finished to your wishlist.

diakas commented 5 years ago

I think this project is early to bury the opposite test a sign of interest and they are perfecting the skill!

As an option of protection I think that it is necessary for each user to give a unique hash when entering and to carry out all operations in encrypted form - to exclude addition manually in request of a malicious injection.

Who will be able to realize it?

https://bitcointalk.org/index.php?topic=2509833.msg48081990#msg48081990

kokucrypto commented 5 years ago

I'm sorry for altmarkets, it was a very good exchange with gently devs,always active and present.

Let's work all togheter to find bugs and make opentrade more secure.

jonn4y commented 5 years ago

Are you for real? You are like a kid that just found out Santa isn’t real. You are commenting on a old thread with inaccurate information we’re not even using that shit script check the source code and back your claims before you post incorrect facts.

Show me where I mentioned these 13 exploits it’s a very specific number

I have fixed and changes for opentrade that I will push once I have finished on the new AltMarkets

knkrth commented 5 years ago

@jonn4y Does the latest https://altmarkets.io/ run's open trade Or peatio Or any other exchange framework?

cryptobot123 commented 5 years ago

Email me if you like to buy exchange based on peatio. demo: www.devkube.com

On Tue, Jun 25, 2019, 2:52 PM karthik notifications@github.com wrote:

@jonn4y https://github.com/jonn4y Does the latest https://altmarkets.io/ run's open trade https://github.com/3s3s/opentrade Or peatio https://github.com/peatio/peatio Or any other exchange framework?

— You are receiving this because you commented. Reply to this email directly, view it on GitHub https://github.com/3s3s/opentrade/issues/207?email_source=notifications&email_token=AIYEKO7CEAXZU77O4LDER2DP4G6D7A5CNFSM4GFAOX6KYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYPHFJQ#issuecomment-505311910, or mute the thread https://github.com/notifications/unsubscribe-auth/AIYEKO7AIKXBJHDL7WF5CVTP4G6D7ANCNFSM4GFAOX6A .