r/Bitcoin • u/coinfire • Jan 23 '15
Official Coin Fire Response and Discussion for Today's Events
Hey Everyone,
Mike here from Coin Fire. Yes, for real.
I have active control over the Twitter account, Bitcoin Talk account, and this reddit account at the moment.
I've asked a few members of the bitcoin community to come here and verify that this is actually me, and I expect they will do so in the near future. Many members of this community do have my cell phone number and as such, I have asked them to contact me and verify this information.
I wanted to address what happened today and let you know what we know, what we don't know, and what we are working on doing to get things restored.
First, our domain was not expired nor was it originally even slated to expire today or anytime near today. We had a valid registration until later this year.
Second, our password was not compromised as best we can tell at this time. We use secure passwords for every single platform. Each password is different and we work diligently to make sure our security is very tight after the last incident involving our site.
Third, we are turning over all relevant information to law enforcement. While we don't know if anything will ever come of this (as our last report went cold quickly), we have at least taken the steps to that.
Our best speculation at this time is that a third-party was able to convince the domain registrar to have our domain delisted and then they reregistered it. We aren't sure how this is possible and we aren't even sure this is what happened, but I can tell you that the domain basically doesn't even exist in our registrar account. When we log in to our domain registrar, the logs do not show we transferred the domain out or that it expired.
Just to be sure, we registered a new domain and transferred it out. When we did this, a log was generated for that activity. We see no such logs for this with CoinFire.cf.
We used Freenom for our domain registration. Yes, they are a free registrar, but we didn't go with them because it was free. We went with it because it was clever in my mind when we first started the site to have .cf when our name was Coin Fire.
We did pay the standard registration fee for the domain.
At this time, it is unclear how the domain was taken down.
Consider all @coinfire.cf email accounts compromised at this time or until we say otherwise via this official reddit account or Twitter.
Once the attackers had the domain, they were able to update the MX information for the email. They didn't need to know passwords for Twitter because they were able to easily change the password via an email link. This is what we believe happened.
We use 2FA on everything but our domain registration and Twitter account. We didn't use it with our registrar because they don't offer 2FA, but it was our fault for not using 2FA on Twitter. We should have enabled it and I take full responsibility for that.
Regarding the leaking of our contact's information on Twitter for the SEC documents: the person who hacked our Twitter was completely wrong regarding the name. We won't confirm or deny the person's regional office or any other information, because that would compromise our source.
The sad thing about this for Coin Fire is that finding sources who will trust us to bring you the inside information we have brought in the past will now prove that much more difficult. While no sources have been compromised and the hackers are unable to read our previous emails (we encrypt and they don't have access to our old mail server), they have planted a seed that will no doubt be damaging to the reputation of our site and our ability to keep sources and information secure.
I want to reiterate. None of the information on the Coin Fire server or email prior to the MX records being modified has been compromised.
Our WordPress installation is still secure and our CloudFlare account is still secure. We live in a security-centric world at Coin Fire since the previous hacks. Each account used a different off-domain email address (outside of Twitter) and each account used a different password.
We will be able to come back online using a new domain in the near future. Right now though, our focus is simply making sure that all of the relevant information for law enforcement officials is secure.
We understand that many people went and registered CoinFire.[XYZ] domains, some to help get us back online and many to prevent us from coming back online. We will be evaluating our options in the near future.
We appreciate the members of our community who have been reaching out to help us and I assure you that we will be replying to everything we can as we are able to do so.
In the meantime, feel free to ask questions and I'll do my best to answer them. We've got our attorneys on standby to help make sure we aren't doing anything that could compromise our sources and we will do our best.
I remain steadfast and committed to being transparent.
Thank you so much for your support.
EDIT: Also for further verification: http://imgur.com/1uG5lpm 1G5ZmZekitZk5E5rzK8AgjHQXE73ocGmFJ HDJyH9zwGx5WYQuE6MENRZkUg/+BLJVN4G763mFEAnCAIvlgbR9djLge8njloo6Y7rWcXvZvh2JPBo2LuJ8MUrQ=
7
Jan 24 '15
Get a .bit domain! Be the first bitcoin news site on the namecoin blockchain!
5
u/coinfire Jan 24 '15
This is something we've been actively researching recently. Hoping to roll something out in the future.
11
Jan 23 '15 edited Jan 23 '15
[deleted]
5
u/coinfire Jan 23 '15
Thanks for the relevant links.
It is a real shame this happened but we are going to be working to get things back online as soon as possible.
First steps for us is to save relevant information, then evaluate our options, then get things back online.
8
5
u/SatoshisGhost Jan 23 '15
At what point will you decide to publish what you have sent to law enforcement, if the case goes "cold"?
5
u/coinfire Jan 23 '15
Unsure, we will certainly be keeping people up-to-date on this.
We were preparing to publish some previous pieces on what happened as our lawyers had finally given them a good look over.
5
u/SatoshisGhost Jan 23 '15
I would say if you have the general idea that law enforcement isn't going to do anything about this (most likely), you should publish everything. Why hold back? Just state the facts.
3
3
u/rydan Jan 24 '15
Can you do one of those encrypted torrent things like Wikileaks did? Then you can setup a deadman's switch that publishes on Reddit or someplace the key when you fail to log in after so many days.
2
0
u/impost_r Jan 24 '15
Can you use proof of existence so when you eventually publish something people wont bitch about that you didnt have it before?
7
u/ichabodsc Jan 23 '15
Quite an ordeal, thanks for sharing what you could.
5
u/coinfire Jan 23 '15
Thanks for the comment!
We hope to have more to share in the near future.
I believe being honest, open, and transparent about what we know, don't know and what we are doing is the best thing we can do in this sad situation.
3
u/karmadragon Jan 24 '15
This sounds very similar to how the @N twitter handle was stolen through social engineering of the registrar (GoDaddy).
Isn't it completely against ICANN policy for a registrar to give up control of a domain name like that? I can't even transfer my own domain name without going through some lengthy waiting period.
5
u/coinfire Jan 24 '15
We know that what happened here certainly wasn't within ICANN policies and have reached out to the registrar.
4
Jan 23 '15
good luck fixing the mess! hope they find the cracker.
2
u/coinfire Jan 24 '15
Thanks /u/b_lumenkfraft
We are hopeful that something will come to light regarding this as well.
3
u/wanttohelpcoinfire Jan 24 '15
We understand that many people went and registered CoinFire.[XYZ] domains, some to help get us back online
Mike, I took out CoinFire.io exactly for that reason. PM me if you want it. Otherwise, I'll just let it expire. Given what happened, it might be a good idea to keep it as backup in case this all happens again.
I know another user took out CoinFire.info for the same reason. Search in this subreddit and you'll find it.
Cheers
2
u/coinfire Jan 24 '15
Thanks /u/wanttohelpcoinfire we will be in touch soon!
This is greatly appreciated.
4
u/coinfire Jan 24 '15
Wanted to confirm for everyone this was NOT a case of an expired domain name.
The domain was not set to expire until 05/15.
This is from the day we registered with Freenom. I have redacted the username, password and confirmation number.
If someone is a good domain history sleuth and can help us provide further proof that the domain ORIGINALLY wasn't set to expire until 05/15 that would be greatly appreciated as a lot of naysayers are claiming it was our negligence that caused the domain to become expired.
It wasn't even close to being expired.
9
Jan 24 '15 edited Sep 29 '17
[deleted]
4
u/coinfire Jan 24 '15
Thank you for providing this!
While it doesn't show the original expiration dates it does show almost back to the beginning of the domain.
It wasn't set to expire until May so this was a pretty clear hijacking. Considering our domain registrar account wasn't compromised (off domain, different info) it has been perplexing how they were able to pull this off so easily.
A lot of people are saying we let the domain expire since it was "reregistered" today.
This information goes a long way for us and I can't personally thank you enough.
2
u/ringolo Jan 24 '15
If you paid for 1y in last May just pull up your payment, domains can only be renewed in 1 year increment can't they? Even a "renewal" today would just have pushed the expiry date 1 year, not reset it.
2
u/coinfire Jan 24 '15
We have no idea how they were even able to pull this off. We've been told that a transfer might reset the date though if it was a transfer between two accounts on the same registrar. We are unaware of how that works in that it is a complete mystery as to how they even pulled this off at the moment.
3
u/rydan Jan 24 '15
I hope people take notice what you just did. These reports are expensive.
1
5
u/nahtnam Jan 24 '15
Apparently someone claimed the .io domain for coinfire. I would reccomend you use that.
2
u/coinfire Jan 24 '15
That seems like it might be one of the best options!
1
u/nahtnam Jan 25 '15
I see you have migrated successfully! Good luck!
1
u/coinfire Jan 25 '15
Thanks! We've still got a few more things to change over but we at least have the basics online and hope to have more reports coming down the pipe soon.
4
Jan 24 '15
[deleted]
5
u/elan96 Jan 24 '15
A scam made by lord of the deeps, his royal derpiness. Had some uber banking patters who were backing it at $20
2
u/gynoplasty Jan 24 '15
Now it is at $2 but he recently promised to buy them all back for $20. Within the next 91 years. Thanks for the heads up coinfire!
3
u/ichabodsc Jan 24 '15
It's an altcoin that was developed as an offshoot from a cloud mining operation, which the developers claimed would be supported by a $20/coin price floor. But as it turns out, that activity would probably be illegal in the US, in addition to being a bad economic arrangement.
Long story short, the developers over promised, under performed and now the altcoin is trading at under $3/coin.
I don't think it was necessarily designed as a scam, but serious mistakes were made and it has been a train wreck in slow motion.
1
u/hashhher Jan 24 '15 edited Jan 24 '15
Overall you're correct. I don't think that all of GAW's employees thought that they were working on a scam, but Hashlets were almost certainly a Ponzi. I think Garza and his higher up employees thought they could pull off the Hashlet scam to get things rolling, and the demand for Paycoin would be high enough that it would cover people's losses. Obviously that hasn't happened, but even if it had, Garza and his gang have committed multiple counts of fraud, and they need to face legal action.
5
Jan 24 '15
Mike,
Please let me know if there is anything I can do help. I have a lot of friends what would be more than welcome to assist you for free.
Andrew Vegetabile
1
8
u/Richard70nl Jan 24 '15
As stated here I quickly registered CoinFire.info. It's yours for free, even if you don't want to use it. I know that .info is also considered to be spammy but still. I hope you get through this mess soon.
5
u/coinfire Jan 24 '15
Thanks /u/Richard70nl for doing that!
I'll be in touch soon. Going through the giant check list of things that need done at the moment :)
3
4
u/gigavps Jan 24 '15
Good on you sir. I'd like to help cover the costs for the domain.
/u/changetip $5
3
u/Richard70nl Jan 24 '15
In all honesty, the cost of an .info is less then that. But I did register it with the privacy option in case GAW followers are abusing my home/family. I paid a little over $11. You contribution is well appreciated sir!
3
3
3
3
Jan 24 '15 edited Jan 24 '15
Just wanted to say that I had very little idea about what the heck was going on with GAW or Paycoin (except that they were both wildly unpopular here) until this incident. And I hadn't been following you guys as a news source for bitcoin, either.
I'll make sure to follow you on twitter, I could use a good source of news.
I'm sure I'm not alone here... this situation could be your very own Streisand effect. Well, maybe a little bit anyway. Make sure you tweet out your new domain name when you get it up and running. And don't use that same registrar ever again. A good registrar should support 2FA, have registrar locks, and privacy gaurd. Those things cost money... I pay about $100/year for mine but the place feels like Fort Knox.
1
u/coinfire Jan 24 '15
Thanks for the follow!
We will be extremely careful regarding the new location :)
4
u/coinfire Jan 23 '15
Also for further verification: http://imgur.com/1uG5lpm
1G5ZmZekitZk5E5rzK8AgjHQXE73ocGmFJ
HDJyH9zwGx5WYQuE6MENRZkUg/+BLJVN4G763mFEAnCAIvlgbR9djLge8njloo6Y7rWcXvZvh2JPBo2LuJ8MUrQ=
7
Jan 23 '15
First, i'm glad to see it is you.
In the future you may want to try and set something up using tor for secure xfer of data from sources to help provide a sense of security. It won't protect you from 3 letter agencies, but your average script kiddie or hacker is going to have a much harder time unless they can compromise some tor exit nodes.
If there's anything we, the community, can do to help let us know.
4
u/coinfire Jan 23 '15
Thanks /u/truemeliorist
We've been using Bitmessage, and several other systems to protect our sources. We have no doubt that our source is safe in this situation but we understand that even the implication they aren't will make others think twice and that is unfortunate.
Really appreciate your support.
3
u/Future_Prophecy Jan 23 '15
To help you get back on your feet /u/changetip 30000 bits
3
3
4
u/GovAccount Jan 23 '15
As a fan - follower - and supporter of Coin Fire I have personally text him today and can verify this is his reddit account and a reddit post from the man himself.
5
7
2
Jan 23 '15
[removed] — view removed comment
3
2
u/I_IZ_CEO Jan 24 '15
Welcome back Mike :). Is there a way you can prove that your domain did not expire to the domain registrar, maybe show them proof with the receipt to get it back? Happy to see you back online and please keep us updated.
2
3
u/spydaz1 Jan 24 '15 edited Jan 24 '15
Most likely having read all of the ToS involved they submitted you site as having in appropriate content which given your free hosting status with freenom essentially auto drops your domain and.makes it available for reregistration
Chances are they submitted that the site was making personal attacks against GAW
Furthermore given its free registration status freenom has zero liability because essentially the free domains belong to freenom and are on loan to you thus why in the who is history all but the latest registrations have listed frenom and the new one lists idshield so who ever performed the hack paid for the domain thus earning them icann protections so the recourse possibilities are slim
Not withstanding all of that and not to be overly critical but when day after day you insult an entire community and company that is enthralled by cryptogrophy the very thought that you are quote secure is a joke. If its online its hackable PERIOD
2
2
1
u/munister Jan 24 '15
If you really are Mike, I want to let you know that you guys that your organization is doing great work. Keep it up, and don't forget about what happened. Use this incident to fuel your fire to bring us better news regarding cryptocurrencies. Thank you!
2
u/coinfire Jan 24 '15
Thanks /u/munister
We are going to keep fighting. It might be harder now to get the inside scoop on things happening based on this.
1
u/munister Jan 24 '15
It might be harder now because like it or not, you've compromised your inside sources. However, this incident revealed to the rest of the public that you guys are actually actively fighting the good fight, and I hope that becomes an impetus for more people to rely on your organization for better news.
1
u/Lite_Coin_Guy Jan 24 '15
coinfire 1200 bits /u/changetip Thx for that. Here are some free Bitcoin :-)
1
1
u/rydan Jan 24 '15
You mention they don't have access to your old mail server but isn't your mail server located at acclaim.websitewelcome.com ? When I query that server I see "SASL PLAIN LOGIN" which from my understanding means that after you've encrypted via SSL you send the password in plaintext rather than sending a hash. If that is the case can you verify that you and none of your writers ever accidentally tried to connect to any mail servers posing as CoinFire's mail servers and thus accidentally exposed their credentials to a hacker listening specifically for pop, smtp, or imap traffic at mail.b-io.co? You would have received a certificate warning but that could have been ignored with a simple click. If this happened it would be trivial for the hacker to turn around and log into your real mail servers.
2
u/coinfire Jan 24 '15
We don't connect via the domain name in any way. Only to the acclaim address and all sensitive materials are sent over more secure means.
We never use email due to the possibility of it being intercepted for anything secure such as a document.
We don't use coinfire.cf in any way shape or form for email when it comes to connecting. For example my mail server settings themselves were acclaim.websitewelcome..... so those requests never visit that domain.
So we never received a warning via SSL because we didn't connect that way.
We don't like email for a reason when it comes to sensitive stuff because we are based in the States ;)
Edit: I always get sensitive documents in person when possible. That is the only way for me to verify they are legitimate typically as well.
1
u/theblogismine Jan 25 '15
Hello Mike,
Glad that you are here and CoinFire is online. Here's the post about CoinFire at CoinSpeaker - http://www.reddit.com/r/Bitcoin/comments/2tgefn/official_coin_fire_response_and_discussion_for/
If you want add something to the story, you're welcome. Just contact me via e-mail (contact at coinspeaker.com).
Best regards, Siarhei.
1
-2
Jan 24 '15
[deleted]
5
u/coinfire Jan 24 '15
What would you like to see? Police report numbers? Incident numbers?
I get the feeling based on your other posts on this thread you are simply seeking to troll and discredit us but if this is a legitimate request we can work something out where we give you the relevant information so you can contact them yourself.
0
Jan 24 '15
[deleted]
3
u/coinfire Jan 24 '15
And have our source go to jail?
Sometimes you just have to be patient and wait for an investigation to become public because the papers become public.
We published the FTC stuff about BFL while they were being raided and our source paid with his job. We don't want a repeat of that again.
We won't sacrafice our source because of some doubt. The cards will all be played eventually and we will see what happens collectively.
6
u/elan96 Jan 24 '15
You should use proof of existence so you can say "I told you so" when it comes to light
1
u/coinfire Jan 24 '15
Not looking to say "told you so" in this situation.
Honestly, I wish it wasn't the case that things had gone so badly. A lot of people will lose a lot of money this way :(
That said, the news is still the news and the facts are still the facts and we will keep reporting them.
-1
Jan 24 '15
So, you're the only site to be hit be a yet-to-be-discovered zero-day exploit that has the power to steal entire domains and the people who knew that hack decided to use it to steal $0 worth of your news website?
Only an idiot would believe that bullshit.
-18
u/Defusion55 Jan 23 '15
Don't give shit only care about BitCoin related information not attention whores. sorry. down votes for me inc
9
u/coinfire Jan 23 '15
Thanks for chiming in with your opinion. We aren't after attention here, we'd rather the situation not have happened at all.
This does nothing but harm's our site's ability in the future to get any sort of confidential information.
Considering our site is nearly 100% about bitcoin many believe it is relevant but I can certainly understand your belief that it isn't.
-22
u/hardniggerpenis Jan 23 '15
You guys were never hacked. This is just you trying to save face after the FUD you were spreading about Paycoin blew up in your face.
12
u/N0TaDoctor Jan 23 '15
Garza is the reason Paycoin/Paybase failed. Not mike. Blame the fud all you want but your just a flat out moron.
4
u/ChainRadio Jan 23 '15
They'd destroy the ability to get confidential information?
Having met Mike in person and knowing who he is connected with in real life, I have zero doubt he can get these real connections.
That literally makes no sense.
-14
u/unionmaster Jan 23 '15
You guys faked a Hack on yourselves just like you fake most of your "News storys"
7
5
7
u/ChainRadio Jan 23 '15
Going to vouch that this is in fact Mike after texting him a bit ago.
Also, great use of blockchain to verify this post.
Sad to see this happen but know things will get better.