Post
Topic
Board Service Discussion
Re: BTC Stolen from Poloniex
by
kneim
on 05/03/2014, 06:59:40 UTC

The hacker discovered that if you place several withdrawals all in practically the same instant, they will get processed at more or less the same time. This will result in a negative balance, but valid insertions into the database, which then get picked up by the withdrawal daemon.


Are you kidding me? Did you do any research on past Bitcoin exchanges hacks before auditing your code?

That exact same "hack" has been done on multiple exchanges in the past.

Another guy who's created an exchange but yet somehow doesn't know what a database transaction is... unreal.
I wonder a little bit about programming skills. As a platform operator I would have a lot of fun detecting anomalies like that, block this customer, and make a very very precise verification of the identity. Perhaps the assets never would be withdrawn.