coinables / Bitcoin-NoAPI-Shopping-Cart

Bitcoin Permission-less API Shopping Cart
13 stars 12 forks source link

No usar, roba tu clave privada #3

Closed Beetario closed 7 years ago

Beetario commented 7 years ago

Hace poco use esta pagina para un proyecto, en el cual al recibir 300 usd en BTC , todos fueron robados, inmediatamente luego de haber ingresado el dinero fue desocupado el wallet generado, no lo usen , no lo recomiendo. Cuidado.

coinables commented 7 years ago

Likely an insecure server. As stated in the README

WARNING: THIS PROJECT STORES PRIVATE KEYS ON YOUR SERVER!!! ITS INTENDED USE IS FOR SMALL VALUE ITEMS. YOU ARE ENCOURAGED TO SWEEP KEYS THROUGH THE ADMIN PANEL AS SOON AS POSSIBLE AFTER A SALE TO REDUCE POTENTIAL RISK.

Beetario commented 7 years ago

ladrón! Estafador!

qirtaiba commented 7 years ago

Definitely not an insecure server, has to be an insecure algorithm because of insufficient randomness. There is someone out there who has generated a bunch of not-really-random addresses with their associated private keys and is regularly sweeping them into their own wallet. See #2.

This problem went away for me after I fixed the algorithm. I didn't do anything else to make my server more secure.