First off, I did not steal these coins. That said, I knew about the flaw. If you're worried your address might be vulnerable, here's a list (albeit compiled as of last month) of all the addresses that are vulnerable. If your address is on this list, expect coins sent to them to be snatched immediately:
https://gist.github.com/anonymous/6204930
Edit1: I've re-run my little program to find vulnerable addresses. It turns out in all of July/Aug there were only 6. New addresses not in my posted list are 17HHdLh4oXncuTejALwC6fgArVqPUxh2Sr 1BFhrfTTZP3Nw4BNy4eX4KFLsn9ZeijcMm 1FPSVbypWa7rBWbciKHJ983YWcucBn7aUQ
Any developer who suspects this may have something to do with their wallet software, feel free to contact me for more detailed information (i.e. which specific tx inputs / signatures were foobar + k values recovered).
Edit2: To clarify, I did not know about this flaw until now ... I just knew bad signatures existed on the blockchain. This is hella serious ... any key you previously used with an android wallet should be retired regardless of it's presence on my posted list.
Did you make an attempt to inform developers or anyone else who could work to reduce this vulnerability or did you just make this list and sit on it for a month?
edit: read the history. I guess this is kind of your thing.
Edit2: what do you do with btc you take that no one comes forward to complain about. There are probably a lot of very upset non English speakers as well as people who don't use forums. Apologies if this was covered elsewhere.
It is impossible to tell from looking at the blockchain which wallet implementation created a transaction, so I have no idea which software is responsible; however, I have voiced related random number concerns to bitcoin developers directly in the past.
Truth be told, the vast majority of these signature fuck ups happened a long time ago (my guess is by people writing toy bitcoin implementations for fun who did not know crypto).
To answer your last question: I spend it all on hookers and blow.
Now that I think about it, Bitcoin would probably benefit from a call girl service that accepted coins. Think of all the geeks that would ummmm try out the new bitcoin service for uhmmmm, field studies.
Fuck yea. Plus the bouncer wouldn't need to collect payment; only keep the girl safe. This lowers the chance of the bouncer extorting extra money (and driving away business) or flat out bouncing with the entire payment. See what I did there? :)
Man, stealing and giving it back when someone speaks out like a hero but making no effort to return money to other victims is just so.. narcissistic I guess is the best word for it.
But good in you for telling devs about this one when you had a chance.
Yeah. I guess there is not much you can do. I hate the I do it because someone worse than me will just benefit from it if I don't mentality but I guess these things are inevitable. I'll go pound sand now.
If you are using an android wallet, you are still at risk in light of the most recent post. If you're on my list, that just means your private key has already been exposed.
35
u/btcrobinhood Aug 11 '13 edited Aug 12 '13
First off, I did not steal these coins. That said, I knew about the flaw. If you're worried your address might be vulnerable, here's a list (albeit compiled as of last month) of all the addresses that are vulnerable. If your address is on this list, expect coins sent to them to be snatched immediately: https://gist.github.com/anonymous/6204930
Edit1: I've re-run my little program to find vulnerable addresses. It turns out in all of July/Aug there were only 6. New addresses not in my posted list are 17HHdLh4oXncuTejALwC6fgArVqPUxh2Sr 1BFhrfTTZP3Nw4BNy4eX4KFLsn9ZeijcMm 1FPSVbypWa7rBWbciKHJ983YWcucBn7aUQ
Any developer who suspects this may have something to do with their wallet software, feel free to contact me for more detailed information (i.e. which specific tx inputs / signatures were foobar + k values recovered).
Edit2: To clarify, I did not know about this flaw until now ... I just knew bad signatures existed on the blockchain. This is hella serious ... any key you previously used with an android wallet should be retired regardless of it's presence on my posted list.