About Cryptonite hack (and the btc38 exchange)

Chinese translation by liuweimm below


About the Cryptonite (XCN) hack and the btc38 exchange (now AEX.com)

By Pallas with help from sekker, bitfreak, the XCN team and community

Cryptonite is a very innovative coin, if you consider it was conceived in 2013 and published in 2014.
Its “account balance” system made waves in the crypto coin community because it was such a different approach from bitcoin.
That of course needed a lot of new code and replacement of the stable bitcoin base, stuff that most coin didn’t even dare to touch.
The original coin developer (who went by the pseudonym “catia”), was hired to make the actual code and he was not part of the team.
A very talented programmer, produced high quality code which is by most part still running as of today, without issues.
Unfortunately, a glitch was introduced in an important part of the code, which dealt with block and transactions check.
The result was the possibility to craft malicious raw transactions creating coins out of thin air. It required advanced coding
knowledge, but apparently someone dedicated a lot of hours to take advantage of this and created some hacked blocks with a lot of
“stolen” funds.
Back to the history of the coin, in 2016 the coin community was stagnant and no development nor promotion was underway. Still, the coin
had followers and was listed in some major exchanges. This, plus the fact that development was resumed, made its price and volume rise
again, to the point that, in summer 2017, millions of dollars where traded every day and it’s safe to assume that some of the hacked
funds where sold during that period.
During the peak of june 2017, the strongest volume was on btc38, a chinese exchange which, apparently, was used by the hacker as there is proof
of him sending millions of XCN to their wallet. It was at that time the bug was discovered, because the total supply was too low compared
to the funds they had. The XCN team started working on the issue and an updated wallet was released, which closed the hole that the hacker used,
and also blocked some of his accounts. The team notified all the exchanges of the issue, so they could do their investigation on the
hacked funds, in the hope they could block the accounts before thay could spread the coins and make the distinction between “good and bad” funds
impossible.
The team itself, of course, didn’t have access to the internal user data (balances, transactions) of the exchanges,
so they did all they could to address the matter, but it was up to the exchanges themselves to do the work on their own data.
As far as we know, nothing was done on the exchange side to address the issue, and this was especially concerning in the case of btc38,
which was holding the most part of the stolen coins. Instead, they asked the XCN team to make a new coin and do a swap, then submit the new
coin to their exchange for listing. This is not a good solution for the following reasons:

1) the hacked coins could be swapped for new coins, making all the effort totally useless
2) cryptonite is believed to be safe now, so there is no reason to stop its development and/or halt its blockchain
3) making a new coin and submitting it to the exchanges is expensive in terms of time and resources (we understand why they’d want us to do that…)
4) we believe the cryptonite history is a plus to the value of the coin, as compared to all the coin scam clones which come out everyday

The team tried to explain this to the now called AEX exchange but in vain.
Unfortunately, the chinese community was, and is still, fed with false information by multiple sources, and they believe the team is not doing
anything, not following the AEX advices etc; this is caused by the influence the AEX staff has on the crypto chinese communities and the language
barrier.
This is one of the reason we wrote this document, and we will translate it to the more languages possible, so people will know what’s
our position and opinion on the matter, and know that we have been actively developing and fighting to make XCN continue to grow,
regardless of the unfortunate events that happened.
We are an open community with no development funds, no premine and no other income; but we will continue improving the coin and supporting it,
because we believe in its values and the technology advancements it brought to the crypto community in general.

 

Chinese Translation by liuweimmm:

关于Cryptonite 被黑事件与btc38的关联

关于Cryptonite被黑事件与btc38(现AEX.com)的关联其内容来自Pallas, SEKKER,  BITFREAK, XCN团队和社区的帮助。

Cryptonite2013年至2014年间发布,这是一款非常创新的加密货币。

其独特的账户系统在加密货币社区掀起了一阵浪潮,也因它比比特币在交换方面更加的快捷。

当然,完成这一点需要团队对比特币源代码进行大量和稳定的更换,这也是大部分加密货币不敢尝试的事情。

我们一开始时聘请了CATIACryptonite进行开发,他是一个非常有才华的程序员,完成了很多高质量的代码,如今大部分的代码依旧在正常工作,没有任何问题。

但不幸的是,在代码的一个重要位置有一个故障,它原本是用来处理区块和事务的。

有人使用相当高级的代码知识利用了这一故障进行黑客攻击,凭空创造了硬币。

首先要说明的是,在2016年,Cryptonite社区从没有发展和推广到恢复发展是真实的,价格和成交量也是在上升的。

再次强调,在2017年夏季时,每天数百万美元的交易中,并没有发生黑客攻击,所有交易都是安全的。

直到20176月的高峰期,在BTC38这个交易所,显然某些交易是被黑客利用的,这是有证据的。

黑客向交易所的钱包发送了数百万的XCN,因为与总的供应量不符,也就是那是团队发现了这个bugXCN团队开始处理这个问题,发布了一个修复了漏洞的钱包,还监视了它的一些账户。

团队还通知了交易所,告诉他们黑客攻击了钱包,希望他们能对有问题的账户转进的货币进行封存,区分开”好与坏“的货币。

但他们什么也没有做。

对于加密货币而言,团队本身并没有访问交易所内部用户数据的权利,因此尽管我们竭尽全力的想要解决这个问题,但终究还是要由交易所自己来变更他们的数据才行。

据团队了解,BTC38并没有做任何事情来解决这个问题,他们也占据了被黑货币的绝大部分。相反,他们还要求XCN团队制造一款新的加密货币并与原有货币进行交换来参与交易。

制造新的加密货币上市,这并不是一个好的解决方案,原因如下:

  1. 被黑客攻击的货币也可以兑换新货币,这并没有解决任何问题。

  2. XCN原有的漏洞已经进行修复,我们不应该阻碍它的发展或破坏它原有的区块。

  3. 制造一款新的加密货币是非常消耗时间和资源的事情(当然我们明白他们为什么叫我们这样做)

  4. XCN并不是那些每天都出现的单纯的克隆币,在加密货币的体系里它是有价值和优势的。

团队试图向现在被称为AEX的交易所解释这一点,但徒劳。

不幸的是,中国社区因为信息不流通的关系,他们觉得团队没有作为,没有遵从AEX建议等等。

团队与中国社区之间有一堵屏障。

这也是团队编写这份文档的原因之一,我们会将文档翻译成更多的语言,让人民了解到真正的原因。

无论发生何事,团队都会坚定的为了XCN的积极发展所奋斗。

我们只是一个开放性社区,没有发展基金,没有预挖矿,也没有其他收入,但我们也会继续改进和支持XCN

因为我们相信XCN的价值和它的技术是对加密货币社区的技术进步是有所贡献的。