create account

Serious EOS ICO Vulnerability by useruploads

View this thread on: hive.blogpeakd.comecency.com
· @useruploads ·
Serious EOS ICO Vulnerability
<span class="viewly_preview"><a href="https://upload.view.ly/view/useruploads/d1d3--2017-08-19--serious-eos-ico-vulnerability"><img src="https://ipfs.view.ly/ipfs/Qma4qUe9WJ6dTy9YCWqjG9ZtNBCkcVeZyk13pxyaHYmKQA/thumbnail_masked.png" alt=""></a><br>Watch it on <a href="https://upload.view.ly/view/useruploads/d1d3--2017-08-19--serious-eos-ico-vulnerability">Viewly</a> <br><br></span>*end-preview* <hr><br>====== Serious EOS ICO Vulnerability discovered ======

Dev must pls move fast before more people exploit it.

****** PLEASE READ TILL END, BEFORE U DO ANYTHING ****

EOS Dev team, please fix this urgently before it's exploited and the value of tokens crash!!!

The vulnerability only presents itself when using EXODUS WALLET 1.30.0 or Mist. I couldn't get it to work with the other wallets.
I think the vulnerability only exists because the developers are still developing the platform it's probably used as a faucet but a combination
of actions/software versions cause an issue with the ECR 20 tokens.

I'm unsure if it's specificly due to EOS code or the ethereum network as a whole, effectively the correct software version, and timing can cause quadruple spending 
when amounts larger than 0.5 eth is transferred into a very specific address, it only seems to work once per 'receiving-address' in other words trying to send twice from the same wallet does not work.

I am NOT certain of what other variables could also present this vulnerability.

Following these steps to reproduce:

1) Create a wallet on Exodus (1.31.1 -> It's important that you ensure this is the version you have) or Mist (Only tested latest version), I have reports that MyEtherWallet also works.
2) Open up https://www.timeanddate.com/worldclock/ look at the bottom right of the table for the current UTC time, know keep this in mind, you have to click the send button when:
    - the 'seconds' of time is exactly 00, in otherwords if it hits 12:32:00, or 01:43:00 then click the send button.
3) Send any amount higher than 0.5 ETH to 0x69901950aae2B2884770C8cA6A735d307Fb2DAFF It's IMPORTANT that you click send on :00 (explained in step 2). 
4) Wait 30 minutes (depends on eth network speed), check your tokens, you will have roughly 2 ETH worth of EOS tokens, the amount worth of tokens seems to be 'sent-amount' * 4.

The wierd thing is if i look at ethscan and look at that address it doesn't show my transactions at all, which makes me think maybe it's an Eth-network bug.

I have also managed to sell my EOS tokens this way and get the ETH back!!!!!! this is ridiculous
NOTE: This only works ONCE per wallet address (in other words doing it twice with the same wallet will fail).

I believe this vulnerability is being actively exploited by someone else if you look at the 24hour volume charts, 
it's pretty obvious something fishy is going on with EOS as the currency has been very stable beforehand.

PLEASE, I believe in what EOS project presents - pls fix it devs before more people exploit this bug.

PLEASE PLEASE anyone other than devs reading this:
PLEASE do not exploit this bug. EOS is interested project, you can make some quick free money sure, but it will hurt the devs and set the project back.

I hope by the time most of you read this open letter that the bug has already been patched, my full faith is in Dan Larimer and team!

thank #team-joker
👍  , , , , , , ,
👎  , ,
properties (23)
authoruseruploads
permlinkd1d3--2017-08-19--serious-eos-ico-vulnerability
categorycrypto
json_metadata"{"app": "steemq/0.1", "steemq": {"ipfs_root": "Qma4qUe9WJ6dTy9YCWqjG9ZtNBCkcVeZyk13pxyaHYmKQA", "video_file": "mp4_720p.mp4", "files": [{"Name": "mp4_720p.mp4", "Hash": "QmS4p4Z5JyLrvHbuHepz58kgNtnvzNfY9hyLVFtXVKmpvE", "Size": 5436945}, {"Name": "thumbnail_0.png", "Hash": "QmceH2LV2eK3XUj4v2n1pNwmbX3WggiByQoiQAEtMRMJgn", "Size": 60500}, {"Name": "thumbnail_1.png", "Hash": "QmS7BnneVrv8LVgytLXme6JJhyioJLjyHHy7gui6awif9j", "Size": 124887}, {"Name": "thumbnail_2.png", "Hash": "Qmf95AaywqTwYTkJmMYsKQZjwAWQS5c4x9dAFQRPaiC9Wy", "Size": 192411}, {"Name": "thumbnail_3.png", "Hash": "QmNfkMLNfVDV34dAHVXTidMQx9uiq511Qo7JGNpfw3qsFe", "Size": 210387}, {"Name": "thumbnail_masked.png", "Hash": "QmTFLD23n9zQA9at3jpH3n3AZxui83MTMfjN3u7NL4knoe", "Size": 554339}, {"Name": "tilesheet_8_5_192_108.png", "Hash": "QmaAP4ZDsdnVTgJw4hMnodYsPafkeDQ5GLvii4sWmFCcnt", "Size": 187603}]}, "image": ["https://ipfs.view.ly/ipfs/Qma4qUe9WJ6dTy9YCWqjG9ZtNBCkcVeZyk13pxyaHYmKQA/thumbnail_masked.png"], "community": "viewly", "tags": ["crypto", "eos", "exploit", "hack", "money"]}"
created2017-08-19 10:23:09
last_update2017-08-19 10:23:09
depth0
children3
last_payout2017-08-26 10:23:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,395
author_reputation-642,592,913,672
root_title"Serious EOS ICO Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,251,366
net_rshares-158,218,181,184,247
author_curate_reward""
vote details (11)
@andersrh ·
haha
👍  
properties (23)
authorandersrh
permlinkre-useruploads-d1d3--2017-08-19--serious-eos-ico-vulnerability-20170820t131138759z
categorycrypto
json_metadata{"tags":["crypto"],"app":"steemit/0.1"}
created2017-08-20 13:11:39
last_update2017-08-20 13:11:39
depth1
children0
last_payout2017-08-27 13:11:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4
author_reputation62,397,247,186
root_title"Serious EOS ICO Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,346,275
net_rshares0
author_curate_reward""
vote details (1)
@onthewayout ·
Is this a joke? The correct address for the EOS contract is 0xd0a6E6C54DbC68Db5db3A091B171A77407Ff7ccf
properties (22)
authoronthewayout
permlinkre-useruploads-d1d3--2017-08-19--serious-eos-ico-vulnerability-20170819t154247886z
categorycrypto
json_metadata{"tags":["crypto"],"app":"steemit/0.1"}
created2017-08-19 15:42:51
last_update2017-08-19 15:42:51
depth1
children0
last_payout2017-08-26 15:42:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length102
author_reputation13,205,527,560,619
root_title"Serious EOS ICO Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,272,627
net_rshares0
@upgrade ·
So you are basically asking people to send coins to your wallet as a test? Good one.
👍  
properties (23)
authorupgrade
permlinkre-useruploads-d1d3--2017-08-19--serious-eos-ico-vulnerability-20170819t121811509z
categorycrypto
json_metadata{"tags":["crypto"],"app":"steemit/0.1"}
created2017-08-19 12:18:12
last_update2017-08-19 12:18:12
depth1
children0
last_payout2017-08-26 12:18:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length84
author_reputation64,053,381,612
root_title"Serious EOS ICO Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,257,997
net_rshares1,143,236,450
author_curate_reward""
vote details (1)