Post
Topic
Board Service Announcements
Merits 27 from 3 users
Re: [ANN] ✰ WhaleMixer.com ✰ Mixer That Dispense Freshly Mined Coins
by
mocacinno
on 13/07/2021, 12:52:55 UTC
⭐ Merited by LoyceV (20) ,dkbit98 (5) ,TryNinja (2)
Ok... So, in order to summarise the issues (once again), i dug into your site and made following screenshot of the services your provide.
I take these services as a contract: mixing is based on trust. If I read a list like this on a mixer, i think there should be no wiggle room for discussion, the list is iron-clad. Even a single lie in a list like this should have grave consequences!
You are a mixer, you should do, without any discussion, everything you promise on your main page... No smallprint, no hidden twisted phrases in your TOS that allow you to divert from your promises... A mixer should be upfront and completely honest about everything they claim.

I've included a color code:
  • Red: proven to be (partially) untrue
  • Yellow: unproven or unprovable
  • Green: (mostly) true



Red: proven to be (partially) untrue
  • Low service fee: Our service fee is random between 1.00% and 2.99% => I have seen 1 legit user posting details of 1 mix and the service fee he payed was 19,3% proof. You do not indicate any other fees on your main page, nor in your TOS
  • Farm mixed fresh: Coins are freshly mixed from our mining farm => I have proven there are no meaningfull coinbase rewards within a reasonable distance. proof. You keep throwing statements around telling us you want to protect your miners, and i keep telling you that it simply does not work like this: a coinbase reward is always visible. If you mixed fresh coins, they were exchanged with tainted coins and you're giving away tainted funds, not fresh.
  • Fast support: We reply to all our clients within 1-24 hours and we support PGP encryption => but there are users claiming they never received a reply
  • Letter of guarantee: You can check the guarantee letter on our check status page => i could not find a link to your check status page, and even if there was such a link, you cannot publish a static page and use it as a letter of guarantee extra info

Yellow: unproven or unprovable
  • Logless transactions: Logs are destroyed automatically after transactions complete => unprovable, but no mixer can proof this, so it shouldn't be used against you or your service
  • Two pools system: We have a receiving pool and a sending pool => i only had the option to study one mixing session, it did not allow me to verify this claim
  • Talkless database: Receiving and sending database are seperated => unprovable, but no mixer can proof this, so it shouldn't be used against you or your service
  • Fully automated: Our site is fully automated to ensure highest level of privacy => eventough automation has little to do with privacy, and i have a gut feeling this claim might not be 100% true, i cannot verify
  • High volume mixing: Our reserve holds high volume of fresh coins for mixing => i personally do not believe you hold the volume you say you're holding. I'm not even talking about the amount you claim to actually hold, whilst advertising an amount that's 100x higher proof. But there is no 100% conclusive way to proof anything. You say you hold 50 BTC, the one mixing session does not show this, you refuse to sign a message... It's possible you hold 50 BTC, but i seriously doubt it (but cannot provide proof)
  • The highest level of protection: We take privacy protection seriously as it is our core business => after analysing Tryninja's mixing session, i seriously believe i'm seeing funds payed out to your other clients, and the phrasing "highest level of protection" is also a pretty big claim... I seriously doubt it, but i cannot provide any evidence


Green: (mostly) true
  • Variable receive time: Random delay between 5 minutes - 6 hours to ensure privacy => Eventough i've seen clients of you claim to have waited far longer (so your statement is partially true), the time seems to be random... If it's in order to increase the privacy, or because you're manually creating transactions, or because you're waiting for dips in the mempool so you can pay lower transaction fees and keep more money to yourself... i simply cannot tell
  • Multi Crypto Support: We currently support 6 different coins => eventough i've only seen people testing out BTC mixing, you do seem to accept other coins aswell
  • SSL protected: Our sites are protected from data leaks => this is true, no MITM... You're using an X3 certificate, which is good
  • No registration required: We do not collect personal data and no registration required => seems to be true, unless your customer wants an api key
  • Onion Site friendly: Our service is also available on TOR network for better privacy => true

Next to this, there are other issues:
  • At least one user claims not to have received his mixed coins. You say you refunded him (no proof), he says he didn't receive anything (no proof either)
  • There is no address check, you can enter whatever (incorrect) address you want, and your system will blindly accept it
  • Not all security headers are fixed: Strict-Transport-Security Content-Security-Policy X-Frame-Options X-Content-Type-Options Referrer-Policy Permissions-Policy
  • Nginx 1.10.1 was released in 2016... Time for a new version?
  • Your website seems to be down quite often, which might mean there are underlying issues with the hardware or the setup.
  • I'm not a native speaker, and i'm a dyslectic... Still, i spot loads of spelling mistakes. This might indicate a very cheap translation, or a slightly modified google translation. Which might result in subtility's getting lost in translation.
  • A daily reboot? Why? I have production systems that run 24/7 between 2 patchcycles. It's not uncommon for a linux server to remain online for several months.
  • I have read the discussion you had with VOD, and i found it childish you kept calling him a girl. Where i'm from, it's no shame being a girl, but the way you kept repeating this word tells me you meant it as an insult. That's not how a business is supposed to operate... Really...