Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Beware of hidden fee hard-coded into z-nomp fork advertised by the devs #180

Closed
oliverw opened this issue Nov 13, 2017 · 182 comments
Closed

Comments

@oliverw
Copy link

oliverw commented Nov 13, 2017

Looks like StarbugBG (Martin Kuvandzhiev) snuck a little easter egg in form of a hidden 0.5% fee directly paid to his wallet via coinbase tx into the pool code he suggested everyone to use:

https://github.com/StarbuckBG/node-stratum-pool/blob/master/lib/pool.js#L267

@oliverw oliverw changed the title Beware of hidden fee hard-coded into z-nomp fork advertised by the devs here Beware of hidden fee hard-coded into z-nomp fork advertised by the devs Nov 13, 2017
@pocesar
Copy link

pocesar commented Nov 13, 2017

funny he called the commit "Added support for BTG"

@jagottsicher
Copy link
Contributor

found also here in the node.js
https://github.com/poolgold/z-nomp-bitcoin-gold
I forked from, now I need to cleanup that also. F u ck

@Thecreator1
Copy link

if(options.testnet == false){ options.rewardRecipients['GPY1LMyM8kaysLEB4a4nUCJ23Y6Wgd5zTC'] = 0.5;

@Esonics
Copy link

Esonics commented Nov 13, 2017

Also found in
/node_modules/stratum-pool/lib/pool.js

@pocesar
Copy link

pocesar commented Nov 13, 2017

the code itself is wrong, it's not testing for undefined or null anymore, it's literally testing for !== null which is clearly wrong and will crap out in unexpected ways. the guy doesn't seem to know what he is doing

this commit poolgold/z-nomp-bitcoin-gold@5e66e54

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@pocesar It's telling that neither him nor anyone else has been active here since yesterdays clusterfuck of a launch. I'd expect all hands on deck on launch day and the following week. Not so with this project. Perhaps mission accomplished already?

@jagottsicher
Copy link
Contributor

If this is really a Scam, then it is a double-pity.
I think the idea is awesome, but from the beginning on the Chinese support was weak and now it comes more and more out what a crappy thing they produced. Hope some people have enough enthusiam to clean up behind that guys.
They did not even need to premine, just prouce crappy code is already enough.

@pocesar
Copy link

pocesar commented Nov 13, 2017

the mine.pool.gold is paying 0 ATM, although 6 blocks were found already, which is really really really suspicious

image
image

@martin-key
Copy link
Collaborator

martin-key commented Nov 13, 2017 via email

@Bourne-ID
Copy link

Interestingly a PR to remove this will not be merged (reference)

I will not merge this PR, but will leave it here, so it is visible for everyone.

Aren't all merged changed and commits visible to everyone?

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@sammy007 was right all along.

@Thecreator1
Copy link

Redirected all resources away from BTG enough is enough.
When they start to hide elements like this in the code trust is reduced to 0.

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@StarbuckBG It's freaking unbelievable but totally telling that this has even to be explained: Samm007's proxy has the fee listed prominently in the readme. Your's is hidden.

@sammy007
Copy link

Not cool at all. If you got enough hashrate you can use my stratum with 2% devfee https://github.com/sammy007/zcash-proxy/releases. Unlocked versions (stratum and full stack pool) with source code access available for reasonable price.

@adnjoo
Copy link

adnjoo commented Nov 13, 2017

0 integrity.. sad..

@sammy007
Copy link

@StarbuckBG 8K blocks premine is not enough?

@sammy007
Copy link

Your hidden fee is like a keylogger in open source software, no one actually read source of Linux kernel in a distributive including all the software. Did you inspect all deb-src yourself? People didn't expect this gem. Period.

@argospam
Copy link

argospam commented Nov 13, 2017

Invalid address transaction must go somewhere. If you like to use your address as default, in pool_configs/btg.json file simply add "invalidAddress":"your own fancy fallback address",

https://github.com/poolgold/z-nomp-bitcoin-gold/blob/master/libs/paymentProcessor.js#L1403

@Bourne-ID
Copy link

I have no quarrels if you add fees into your example code, but the issue I find is with the lack of communication around it. It does appear that it was put in there without wanting people to find it (the check in comment didn't state 'adding fees' for example and no mention of it in the readme). Chances are if it wasn't for possibly 2 users it wouldn't have been found for some time.

If you stated in the readme, or elsewhere in obvious documents that this has hard-coded fees included then I wouldn't have had an issue with it. Transparency of these things adds trust, explaining why gives an understanding on why there is a fee. The lack of transparency unfortunately removes that trust. And it leaves me personally questioning if I can truly trust BTG's intentions.

@martin-key
Copy link
Collaborator

martin-key commented Nov 13, 2017 via email

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@StarbuckBG

Ok! Without all of these software which of the pools will runs ?
You can run the pure z-nomp and check if it is working (:

They have alternatives. Sammy implemented it for his proxy and I integrated BTG into MiningCore

@martin-key
Copy link
Collaborator

martin-key commented Nov 13, 2017 via email

@sammy007
Copy link

sammy007 commented Nov 13, 2017

@StarbuckBG I asked for a stratum spec, idiot. Feel the difference.

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@sammy007 Hopeless.

@ocminer
Copy link

ocminer commented Nov 13, 2017

Btw there would be at least two working pools.. as I don't use this repo at all ;)

@gagarin55
Copy link

I still can't understand why you are doing this when you got 8000 blocks of pre-mine?
The only reason I can imagine is that pre-mine was not for developers, but for Jack Liao only.
And so called "developers" need to get food by themselves.

@martin-key
Copy link
Collaborator

@sammy007 why you don't open your software that is containing fee?
Why you look at my software? And it is not 2% like the proxy it is just 0.5%. This is 1 USD per month from mining machine... a whole dollar ?
It is easy to post everywhere black marketing, but at the end you are the one that have made a closed software with dev fee. I challenge you to open it to the people. Like I have done. Open it and let the people decide whether to remove the dev fee, because I did that. I left the people to remove it, if they like to do so!

@oliverw
Copy link
Author

oliverw commented Nov 13, 2017

@StarbuckBG You get criticized because this issue is about your software. What the hell has Sammy's proxy to do with this? Stop attempting to deflect the blame. If you can't take the heat don't associate yourself with a shady project like this. Otherwise get used to the scrutiny resulting from the overall smell of this PoS.

@martin-key
Copy link
Collaborator

@oliverw why you don't tell the others that you are working with @sammy007 . And that you are trying to speculate using this news to get more people using your proxy and your pools... Everyone can check you "hidden commits", that can be viewed when they open your profile.

@quadrigahacker
Copy link

quadrigahacker commented Nov 17, 2017

@AnthonyLaw

BTG team FORKed the client from Bitcoin Core. Nobody in Bitcoin is going to sue BTG for promoting scam. Look at how generous we are. :)

@TheComputerGenie
Copy link

@systemeintegratedsolutions You seem to have missed my point.
Every on of the modules used in the stratum and the portal are open-source as well. There is an inherent trust system upon which all of this functions. I am certain that the bgold "dev" didn't check the code for the imported modules any more than most folks that trusted him check to see if he added a self-serving fee to every block for the "work" of editing the header values; they trusted him as he trusted those before him.

@yt-bg
Copy link

yt-bg commented Nov 17, 2017

There is no such thing as "inherent trust system" when forking. I am sure that there are at least 100 forks in GitHub containing malicious code.

@ghost
Copy link

ghost commented Nov 17, 2017 via email

@quadrigahacker
Copy link

Lmao. Now truth does not stand on your side so you want to quit the discussion. Okay, then please don't come back. :)

I repeat, Bitcoin Gold is a scam and its team shall not be trusted. The developer has tried to steal users money twice since the launch date.

@OhGodAPet
Copy link

@quadrigahacker BTG is a joke, and not a funny one, either. Just because I called you out when you said some dumb shit doesn't mean I like BTG.

@ghost
Copy link

ghost commented Nov 17, 2017 via email

@martin-key
Copy link
Collaborator

martin-key commented Nov 17, 2017 via email

@OhGodAPet
Copy link

@StarbuckBG Thank you; I applaud the honesty. You can't change the past, but you admit you were wrong, and are trying to fix it, which is all anyone can ask.

@martin-key
Copy link
Collaborator

martin-key commented Nov 17, 2017 via email

@mjoh090
Copy link

mjoh090 commented Nov 18, 2017

@StarbuckBG In terms of this issue, you have now done what you needed to do. Well done.

I think the biggest mistake that you have made is staying loyal to a team that appears to have abandoned you.

You have taken all the heat, spending a considerable amount of time responding to issues. Jack Liao as the founder and figurehead should have been the one fronting, giving you the time and space to fulfil your role as one of the developers of this project. For the most part, the very few and lazy responses that I have seen from Jack has been tonally belligerent and bordering on unintelligible. From my perspective, he appears to be completely inept in terms leadership, and his ability to communicate in english. He appears to me to be an albertros around your neck (and indeed the neck of this project).

This project is in desperate need of support from the open source developer community. There are some very smart people here that appear to have a range of skills needed to rescue this project and make it successful. Have no illusions, perception is reality, and the growing perception is that this project has no future.

It may be worth considering thinking about ways you can encourage support from the open source community for this project.

Possibly, one way to make this happen is to nucleate a new btcgpu movement - fork the fork with community support and with development proceeding with transparency and consensus. Relinquish control to the community and together, with you as the new figurehead/spokesperson, make btcgpu a competitive, truly trustless, decentralised, economically viable alternative cryptocurrency that miners can get excited about.

You have a real opportunity to positively raise your profile and credibility by being the figurehead/spokesperson of a successful community driven project.

@S5h4D3S
Copy link

S5h4D3S commented Nov 18, 2017

@StarbuckBG 16 days ago someone asked you what changes you've made with z-nomp and mining clients, but you never answered the question straight away it was in thread. But easiest for you was to mute that person from the git.... #112 (comment)

Not mentioning your other accounts such ZhiKosta and others on Slack multiple entities that you created to support your self writing comments to your self trough multiple accounts and promoting of gold pool, because all world hates you and everywhere are haters. Good psychiatric sessions can fix your bipolar and paranoid personality...

You are just Quack Martin Kuvandzhiev, thief and now everyone on this planet know what you've done, too late for apologize, no jobs for you in USA you are on the black list = financial crimes - possible stealing of company money with malicious code. = Hands off.
Good luck...

@ZhiKosta
Copy link
Contributor

ZhiKosta commented Nov 18, 2017 via email

@quadrigahacker
Copy link

@ZhiKosta I'm so glad that you joined the scam-y Bitcoin Gold and will soon lost all your money. :)

@quadrigahacker
Copy link

quadrigahacker commented Nov 18, 2017

@StarbuckBG, just look at how your other team members treat you. I think some of the anonymous account here might be Jack Liao who doesn't even dare to speak for you. I agree with @mjoh090 that you're truly under-served and should quit and create your own development team.

@quadrigahacker
Copy link

If anyone's still in BTG you need to get out immediately because the scam continues. The official BTG website listed "My BTG wallet" as an approved wallet. Now it is known that this wallet is a scam and steals your Bitcoin.

This is, what? The third time @StarbuckBG and Jack Liao try to steal your money, right?

@mjoh090
Copy link

mjoh090 commented Nov 19, 2017

@quadrigahacker The loss of your BTG I imagine is very frustrating and disappointing for you. Have you tried speaking privately with @StarbuckBG about this issue? Maybe you can be compensated for your loss. Anyone that has lost money from pools or wallets endorsed by the BTCGPU team, before the red box 3rd-party disclaimer on the Bitcoingold.org website, I think is entitled to compensation.

@quadrigahacker I suspect that you will find that it is as frustrating for Martin as it is for you that you have lost money. This is possibly a soluble issue. Go talk to him respectfully, and let us know the outcome.

@ZhiKosta
Copy link
Contributor

ZhiKosta commented Nov 19, 2017 via email

@mjoh090
Copy link

mjoh090 commented Nov 19, 2017

@ZhiKosta Yes, it is my understanding too that people who have lost money are being compensated.

@ZhiKosta
Copy link
Contributor

ZhiKosta commented Nov 19, 2017 via email

@quadrigahacker
Copy link

quadrigahacker commented Nov 19, 2017

Lol who said I lost any money? I've never touched Bitcoin Gold from the beginning because from the first day I heard of BTG, I know it's a scam. Someone on Reddit did, however. And there're a lot of them. @StarbuckBG and Jack Liao is going to jail.

I'm only here for some fun seeing how criminals like @StarbuckBG can lose all their reputations and money just by their wrong actions themselves.

You really think me ditching here helped in any way of the BTG price going down? No, I don't think so. Not a lot of people would read Github comments. It's all just BTG team's own silly action. They've started to shot themselves in the foot from the beginning.

Also, just curious, what's the "unfortunate incident in the beginning"? Are there any more scam-y accident about BTG that I don't know?

@quadrigahacker
Copy link

If you sometimes browse Reddit forums, here's one of them. https://www.reddit.com/r/CryptoCurrency/comments/7drv3v/scam_warningbitcoin_gold_wallet_stole_all_my/

@ZhiKosta
Copy link
Contributor

ZhiKosta commented Nov 19, 2017 via email

@DemonRx
Copy link
Contributor

DemonRx commented Nov 19, 2017

@ZhiKosta like I said before... the guy is nothing but a troll and a quack. and ppl just keep feeding into this pointless matter, noboody will care about it or remember it in 100 years, just end this thread already, seriously.

@quadrigahacker
Copy link

Lol who's there needing help? I'm not the one that losing money from BTG, but I bet you are @ZhiKosta, right? Anyone still joining the Bitcoin Gold scam is plain stupid and should find themselves in hospital.

I've been consistent with my action from the beginning, but what are you doing @StarbuckBG (a.k.a. @ZhiKosta)? You have "changed your mind" many times regarding the stealing issue and each time you do, you prove how immature you are.

People won't just "let this matter die". This matter will keep coming out any time when Bitcoin Gold is proved scam-y. People will mention this again in the MyBTGWallet issue, and in any future thread when their money is stolen again.

Lol if you lose, just leave. Nobody forces any of you @ZhiKosta @D3m0nKingx to be here. Bye and have a good time! :)

@S5h4D3S
Copy link

S5h4D3S commented Nov 19, 2017

@StarbuckBG is Quack as i said before - facts...
Do not speak how he is underpaid he got 833 BTG from pre-mined..... Not enough? Stealing money everywhere,,,,

Official statement: https://bitcoingold.org/premine-endowment/

"There was, understandably, a lot of attention to the 5% of the premine which was earmarked as “Initial reward for core team” in the Roadmap. That represents 5,000 coins, divided among six core team members, or about 833 coins each – so each core member receives about 0.005% of the existing coin supply (at the time) for their roles in getting this project off the ground during months before launch. "

@jagottsicher
Copy link
Contributor

in my Opinion guthub is generally NOT the right place to discuss this or to blame anyone more than needed. As an initial start it is good to mentions some hidden fees here, but an ongoing discussion is better at
reddit
slack
medium
twitter
or whatever social platform you prefer. There you can write pages over pages and articles about it, duscuss it, diss and blame whoever you want, but github is a place for development and distributed work on a project and a discussion platform for bugs, issues and so on.

If someone discovers a hidden fee in a fork which was not explained and showed in the readme you can "force" that peron my social pressure to do so. In the firts time to hide some fee is already a demolition of any crypto project. But that is another topic to discus somewhere else. If you want to get rid of the fee use the little button at the top right of the project page which is labeled with "FORK".

@evadogstar
Copy link

@jagottsicher No, we does not have reddit,slack or twitter and they are not so useful to discuss something like github

@ZhiKosta
Copy link
Contributor

I wish to say hi to all the trolls that were shitting on BTG. We're still here and stronger then ever. How about you?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests