05:59:55 P2Pool-main has been attacked too, today at 00:02:46 UTC - see the log https://p2pool.io/p2pool_main_attack.log.xz All P2Pool miners, you must update to v4.16 immediately if you don't want to mine to the attacker's wallet! Update here: https://github.com/SChernykh/p2pool/releases/latest 06:18:52 sech1: instead of trying to get the few people that are probably just chillin at the beach without being chronically online and dont read the reddit/twatter/matrix/irc, would adding more hashrate could solve the issue? like, there's over 2Gh/s on supportxmr, 1.2Gh/s on nanopool while all the P2Pool combined are like 250Mh/s ri [... too long, see https://mrelay.p2pool.observer/e/-ebRxI0LYmpidS1f ] 06:20:36 More hashrate can allow non-upgraded miners to join back the original P2Pooll chain, but only until the next attack which can happen any moment, so it's futile 06:20:56 As long as 51% of hashrate or more updates, it will be an automatic process 06:21:17 oh dang ok, i thought it would have been like a "hardfork" type thing, that the attack would have been mitigated completely as long as majority of the nodes are updated 06:21:18 For P2Pool-main, it's already more than 60%, but for P2Pool-nano it's only around 30% 06:22:22 The attack inflates the calculated difficulty and "weight" of the affected chain, so honest miners have to mine for many hours to overcome it (if they have 51%) 06:22:23 oooh, so nano/mini does count torward main as well then? main cant be on its own being 60% updated and safe, it still also need mini/nano to update too? 06:22:39 no, they are separate chains 06:22:54 Main was attacked, but the aftermath is much easier in this case 06:23:04 Because a lot of hashrate was already on v4.16 06:23:28 ok so what's wrong with main right now then? if 60% have updated, how come the attack was possible? not enough time yet? 06:23:42 Attack affects only non-upgraded miners 06:23:48 It splits the chain in two 06:23:56 v4.16 keeps mining like nothing happened 06:24:08 v4.15.1 and older miners start mining to the attacker's wallet 06:24:48 Main lost around ~40 MH/s to the attacker 06:25:08 No, closer to 60 MH/s 06:25:10 08:23:28 ok so what's wrong with main right now then? if 60% have updated, how come the attack was possible? not enough time yet? 06:25:10 due to the attack inflating shares they see the attacked chain as the majority of hashrate 06:25:41 oooh ok, thanks on those explanations 06:25:45 as sech1 once those shares go outside of the PPLNS weight window for sync they can re-merge 06:25:57 in fact... nano attacked side had more hashrate 06:26:13 Could a possible mitigation be to attack the chain too ? That'd dilute the attacker. 06:26:19 so once that became valid again (no attacked shares in window) P2Pool v4.16 switched back there 06:26:41 With the caveat that if the attacked miners can't even mine a single share (because of too many uncle shares there), they'll get stuck on that chain forever, I think 06:26:51 At least until they update 06:27:19 moneromooo: it was considered :) 06:27:34 for now we added changes to our seed nodes that make it easier for old nodes to re-join 06:28:14 or maybe they'll get stuck for a few days, I'm not sure 06:34:42 so with > 61 MH/s lost to the attacker, the attacker gets 80% of the block rewards mined by vulnerable miners, which is ~1400 USD/day now 06:36:25 that is for a sustained attack 06:36:33 still not as bad as qubic, and at least cant be as bad since P2Pool didnt get much adoption but yea, that's a phat stack of cash right there... hopefully it get sorted out, people chillin at the beach need to update already 06:36:44 for a single broadcast, that will be only 2-3 mine XMR blocks time 0.8 per block 06:36:47 *times 06:37:10 so around 500-800 USD 06:39:46 I did the math, and a single broadcast actually gives 0.96 XMR to the attacker (80% of 2 Monero blocks on average due to how PPLNS window is adjusted) 06:43:16 isn't a "counter attack" that mines funds for monero ccs general fund or a burn address a good thing? there is no way to save the miners unless they update. at least reduce the profit of the attacker? he shouldn't get away with this. 06:43:48 @eravsar:raubritter.org: thought that too but then, they forked already to the attacker wallet, cant be hijacking it now, right? 06:45:02 @gaming-research-lab:matrix.org: oh i didn't know that. then it would've been be better if devs ran the attack before a random guy i guess lol 06:46:02 guess so yea, well, maybe that's already the case but we cant know lol 06:50:30 and tbh, even if sech1 is the attacker, like, he found the vulnerability, fixed it, did all that could have been done so people would update, 3 days might have been short notice but if longer, someone else would prob have ran the llm on it to figure out the thing too eventually, like, he deserve those payouts ngl lol, people a [... too long, see https://mrelay.p2pool.observer/e/idzFxY0LQjR2SC0t ] 06:53:10 @gaming-research-lab:matrix.org: yeah exactly. i wouldn't care if he exploited it for himself after doing everything he could do, p2pool is amazing, he deserves that. but there is certainly a need to better inform miners in cases like this. they should maybe subscribe to an email list for crucial updates. not everyone scrolls reddit everyday. 06:56:53 we posted on IRC channels for p2pool, Matrix channels for p2pool too at the same time 06:57:03 observer added a warning as well at the same time 06:57:16 these are places you can subscribe to. 06:57:43 releases on github you can subscribe as well, or security advisories 06:58:26 Contextually, Github have RSS feeds for releases 06:59:40 Discord and reddit too 06:59:44 main p2pool.io site 06:59:49 Sadly, saying that people should be better informed, not gonna make those people seek out such information, otherwise, there's already ample amount of channels 06:59:50 The announcement was everywhere 07:00:07 i guess it is just unlucky then. this incident shows how valuable solo mining is. even though p2pool is amazing a small bug can cause this. so an open protocol doesn't make it entirely reliable 07:00:13 sech1: Thanks to ya! 07:00:39 https://inv.nadeko.net/watch?v=8xLbMQBkWhw 07:01:11 @eravsar:raubritter.org: Factually, there's almost no software - that's without bugs 07:03:39 @gan:skhron.org: right, like, could have been a monero protocol issue straight up, emergency fork and that would have been similar issue there tbh 07:23:08 @eravsar:raubritter.org: oh! or since sech did mentioned that adding more hashrate would allow them to join back the main chain, then maybe it would be doable? step 1: add more hashrate so they join back main chain, step 2: hijack the non-upgraded ones to a newer wallet thing, could be fun there i guess lol, until attacker #1 one gets the opportunity as well again to do step 1 to 2 lol 07:29:12 like, general fund could be used to rent temporary aws instances to bring the hashrate up until they join back, perform the attack, for 1 monero a day, would be fun if original attacker would do the same as well afterward 07:29:35 @gaming-research-lab:matrix.org: lmao 07:29:57 cat and mouse game 07:37:57 well, 1 monero a day was with mini/nano only, now with main the numbers are a bit more on that, 4 moneros or so as was being specified earlier, will be interesting to follow along regardless, how many will update, how much will be left on the old version for literally forever, and if that cat and mouse game thing will ever be [... too long, see https://mrelay.p2pool.observer/e/0bbzxo0Ld3poOERi ] 07:45:02 as more miners update, old version nodes will lose connectivity eventually, and thus won't be exploitable 07:45:16 they'll be essentially solo mining 07:57:49 oh right, duh! lol, and my bad being spammy a bit today, been legit trying to understand the thing, so thanks on the explanations and also for your work and taking the initiative on that sech1, cheers yall! keep up the good work! <3 08:27:35 Me and DataHoarder are currently running a counter-attack by mining malformed blocks ourselves - to hijack the payouts from the attacker and redistribute them to miners later. Currently doing it on p2pool-mini 08:27:45 We will ask for more hashrate later, once everything is set up properly 08:33:36 Damn, good luck comrades. 08:48:28 If anyone wants to participate in the defense, run XMRig and point it to this url: "xmrig -o stratum+tcp://p2pool-defense.p2pool.observer:3330" (for p2pool-main). For p2pool-mini, use port 3331, and for p2pool-nano use port 3332. 08:49:22 We are mining to this address: 42rWdYtoWxwYdDeasYiq1gRF21JKTHom3RsnqYKj1R4c643g4KBJ92qdUT3fhnDEcebcbGfmNpt2r7ufQjHWdwHdLgRxns6 - viewkey is 3500585bb0de52da0f330edb268417cef0fffd90d378bf294cd01f3a0909ccae 08:49:37 Which one is more in need of help? (I can bring 100kh/s to a single one) 08:50:32 p2pool-main 08:50:35 so port 3330 08:51:27 Main. We can probably cover nano/mini ourselves. I'll make an automatic switcher in a few hours on port 3333 that will automatically send hashrate where needed 08:58:17 I am also archiving the received blocks/sidechains and afterwards attempting even distribution on non-cheated shares across all collected for people mining old versions (discounting any affected) 09:08:17 You should keep the equivalent of the invested time and money out of the redistribution sum 09:09:05 server for this is $270/m or so hopefully people update quick 09:10:13 $270/minute? :D 09:14:05 month :) 09:27:17 https://mrelay.p2pool.observer/m/matrix.org/xMVXldrCvIWhnUZAPtmWlHfA.png (image.png) 09:27:23 idk why is not stable tho, like it crashing or somethin 09:28:15 oh wut and now just got an "stratum+tcp://p2pool-defense.p2pool.observer:3330 164.92.150.65 connect error: "connection refused"" but idk, shares literally got accepted earlier, idk, maybe is a rig issue tbh, havent mined the monero with that one yet 09:29:34 Nah I have the same issue on my proxy (although I might DoS it a little with 100kH/s) 09:30:35 it's fine, I keep restarting it 09:30:45 aight, it got an other accepted share, thanks on the feedback as well @albertlarsan68:albertlarsan.fr, was worried was on my end 09:31:04 I keep making improvements to be more efficient against the attacker :) 09:31:23 you got this! <3 09:39:08 that will be stable for a while now. thanks for the collaboration! 09:40:19 👍️ 09:47:08 was 50kh/s all that you needed btw? or more hashrate is always good too? DataHoarder, and i guess rn u might be busy setting up the autoswitching thing on port 3333 so when that's ready please keep us updated on that too, so can do the switch when is ready too 09:48:03 more hashrate is good, allows higher rate of shares 09:48:07 specially for main 09:48:37 aight, so is like an mmorpg raid thing then, eryone doing the thing lol 09:49:39 more hashrate on the defense side is better 09:50:54 But is defense (ie on the invalid chain) better than updated hashrate? 09:51:39 Updating to v4.16 is always preferred 09:51:50 We're defending only people who didn't update 09:53:18 Updated hashrate should be more than 51% to make sure updated miners don't switch to the old chain once the attack is over 09:53:47 It is for p2pool-main, but not for p2pool-mini for example 09:54:05 *nano 09:54:08 like in world of warcraft there that capture the flag thing (warsong gulch) and like, defending your base type thing, or the whole pve/pvm battleground "alterac valley" and is like, there's even a whole raid boss you defending too, this is the defending side rn lol 09:54:09 maybe mini too 09:54:47 IIUC a single sidechain share can take up to 80% of the payout, for the PoW cost of a single sidechain share? 09:55:00 yes 09:55:05 more or less 09:58:50 Correct me if I’m wrong, but my 100kH/s of updated hashrate is more useful on nano than on main defense? 10:03:03 main has 60+ MH/s needing defense 10:03:13 nano only 2-3 MH/s 10:03:17 would still need few megahashes on nano to get majority to be updated over there tho, from my understanding at least, still a bit confused on some of the maths there from earlier, but defense as was being talked in #monero-community earlier, it dont need that much hashrate to defend apparently, it's different 10:03:19 but more individual miners tbh 10:03:37 no, you just need to mine one share to hijack the rewards 10:03:42 we already did it for nano 10:03:47 currently working on mini and main 10:04:21 so focus your hashrate on p2pool-main 10:04:42 it will hijack more reward so we will be able to redistribute more to miners once it's all over 10:04:44 but you said that updated hashrate (to have 51% updated) is better. I am confused. 10:05:05 updated hashrate protects only itself 10:05:09 yes, 51% of updated is good 10:05:25 but the rest is unprotected so we're protecting them by hijacking rewards and paying them later 10:07:56 insane statement but yep. We compete with the attacker to redirect further towards miners later 10:11:50 Does the defense "pool" have tls support? 10:11:53 for stratum 10:11:58 like, working overtime and paying electricity so the ones that are having a tan at the beach and enjoying the sun and all can come back to their mining rewards being given back to them instead of hijacked by idk, sech1 other persona type thing lol 10:12:45 we can't give back more than 80% though. Realistically no more than 30-40% because we're competing with the attacker. 10:12:59 DataHoarder: you said is stable btw but didnt get an accepted share in like 40mins now, is normal? 10:13:15 it's mining at the full sidechain difficulty 10:13:16 difficulty is difficulty of p2pool main 10:13:20 That is why I say that sech1 and datahoarder should first remove the costs, both money for servers and time from the amount that will be redistributed 10:13:22 so you will only get accepted when it mines a sidechain share 10:13:51 oh ok, makes senses 10:13:56 Is this an option in p2pool? 10:14:00 yes 10:14:03 this is go-p2pool :) 10:14:14 "--no-autodiff" in p2pool 10:15:17 DataHoarder will fix it 10:15:37 I'll put xmrig-proxy in front I guess 10:16:28 xmrig-proxy doesn’t do "custom" diffs, it only relays/multiplexes the stratum messages. 10:17:02 but it can do autodiff 10:17:14 ie if the proxy upstream asks for 2190973422 diff, then all the clients will get 2190973422 diff 10:19:01 xmrig-proxy can autodiff 10:29:37 ports 33330-33331-33332 for main/mini/nano using the proxy 10:33:53 I have looked everywhere in the docs and no mention everywhere, except for the custom-diff-stats (which is not autodiff AFAICS). 10:36:52 it's indeed not autodiff :( 10:37:06 but it's setup at 1M difficulty in simple mode 10:37:52 is this any different than just having the pool difficulty for nicehash/rentals sech1? Given it ends up mapping it 1:1 when running in simple mode 10:38:13 it's mapping 1:1 in simple mode, it just set fixed diff 10:38:20 and you can track the hashrate this way 10:39:43 yeah, I am able to track it indeed 11:29:40 https://mrelay.p2pool.observer/m/matrix.org/lKAbvmVoMPQnqdhFRHMHVRKV.png (Free money hack lol) 11:31:22 Rates are just slow to update 11:34:24 @ofrnxmr:xmr.mx: Ahhh that makes sense yeah, i saw it and was like tf lol, and i look at the exchange rating in trocador and it was also B rated lol 11:59:11 did you try execute it tho 11:59:58 misread 14:16:18 how much hashrate/money is the p2pool guy making 14:52:43 @nickaname:matrix.org: b for bitcoin 17:35:35 q 18:07:31 preliminary PSA: if you run haveno, be cautious. there may be an ongoing attack 18:07:47 you may want to revoke you offers until its determined whats going on 18:24:14 @ofrnxmr:xmr.mx: where do you see that? what are the signs? 18:25:01 https://monero-orderbooks.com/ 18:25:12 all btc-xmr offers are gone 18:25:16 there were probably 150 of them 18:25:34 hopefully because makers pulled them off 18:27:41 the btc-xmr side? not xmr-fiat side? 18:28:24 oh nvm, u did say that, so like, same as last time pretty much 18:30:05 haveno should be for xmr-fiat, my opinion on that is trading the cryptocoin for an other cryptocoin is just dumb anyways, thanks on the preliminary pre-PSA, if anyone wanna post about it somewhere else then feel free too, am too lazy for the whole crypto casino bs out here, well... maybe xmr-fiat also at risk there so... errr... alright jfc.... 18:32:46 @hbs:matrix.org: they were reported as disappearing before anyone was notified 18:33:25 er, i mean, when someone notified, they did so by saying they had an offer go to arbitrition after 10 confs, and that the orderbook was getting wiped out at the same time 18:43:10 Hi 18:47:43 @ofrnxmr:xmr.mx: could it just be whale that bought the whole orderbook tho? 18:47:54 no 18:48:10 damn 18:48:33 Fed my logs to ai, here's its explanation: 18:48:33 "What the attacker did 18:48:33 Took the offer and completed normal multisig + deposit setup with the real arbitrator (7xktb2...). 18:48:33 Never sent payment (no PaymentSent in logs). 18:48:33 Skipped the arbitrator and sent dispute messages directly to the seller from their own onion (fg2lhfh...):[... more lines follow, see https://mrelay.p2pool.observer/e/j6iL2o0LZ3NLeHFP ] 18:48:43 fwd from haveno dev channel 18:50:01 again? 18:52:54 did the dev ask ai to review the codebase after the first incident 18:53:37 apparently "ai didnt find it" (the original) 18:59:19 ai could not find lack of input validation ? i dont have maximum context but that seems unlikely 19:15:56 "DisputeOpenedMessage sender not checked" - I can't even... 19:32:57 it's funny how everything in the monero ecosystem is burning to the ground and it has 0 impact on the price because 99.8% of people are just buying on cex 19:34:20 bisq, haveno, eigen, openmonero, p2pool, haveno again 19:37:27 BasicswapDex is unaffected, so not everything 19:38:14 basicswapdex is cryptocasino bs tho, no offense lol, truth tho 19:40:02 tf u talking bout 19:40:42 its literally an atomic swap dex. theres not casino bs or frills. fuckin clown take 19:40:47 trading the cryptocoin for an other cryptocoin, that's gambling on the market bullshit, on/offramps like bisq and haveno does bring actual use and allow people to live off of monero 19:41:28 ok, so how is eigenewallet or retoswap better? retoswap exploits keep happening on crypto-crypto orderbooks 19:41:40 and 95% of the liquidity on it is crypto-crypto 19:41:49 on reto* 19:42:00 right, fiat trades havent been affected on haveno, maybe that's the design issue there... should have kept it fiat only and have something else for the gamblers 19:42:01 bisq too 19:42:26 they have been affected, just nobody cares to exploit the liquidity offered there 19:42:30 well, who knows what the issue is right now if fiat trades are affected, hopefully not, but last time they werent 19:42:56 oh... well still, that actually brings actually value to the space, gambling bullshit, not so much 19:43:07 they were. but they are limited to much smaller values, so not worth wasting time on when you can steal 500xmr 19:43:22 how do you figure? 19:43:43 you can buy ltc on a cex in europe or phillipines, but you cannot buy xmr 19:43:53 Maybe Haveno shouldnt be focusing too much on high-value offers 19:44:06 there are no damn offers on haveno for phillipines for xmr. so youd buy ltc and swap it into xmr on basicswapdex 19:44:15 assuming its casino bs in total retard take 19:45:19 and vice versa, if you need to cash out xmr, are you supposed to be the only person in the country using retoswap? if you dont care about kyc and all of that, you can still cash out using other coins 19:46:09 I really don't like how there are literally no way to cash out small quantities of XMR without KYC 19:46:15 using monero doesnt mean you have to be an someone who refuses to use a cex. 19:46:21 But so many ways to do so with very large quantities of XMR 19:46:30 Usually it would be the opposite 19:46:32 people in europe used kraken until they delisted eurupe 19:46:52 I was looking at the monero-wallet-cli documentation and tweeking some settings, and, as far as I understand, `print-ring-members` simply shows more information, but what about `store-tx-info` and `track-uses`? What do these two options entail? The first one relatively easy to understand -- it stores extra information, which would, I guess, be locally discarded otherwise, and probably shouldn't be 19:46:54 exposed -- except where the data is being stored. Is it in the wallet file or somewhere else? 19:47:21 you cant really use retoswap without some form of kyc, whether that be address, banking info (including real name and account numbers, obv) 19:47:44 youre not giving up ID, but you still VERY MUCH know who your customers are 19:48:08 @ofrnxmr:xmr.mx: Especially if doing SEPA transfers since VoP came into effect last October 19:48:20 the thing that would fix 99% of monero's decentralized trading problems is a wrapped monero on eth 19:48:24 Also I find it dumb that nobody sees a problem with 500-1000 XMR offers anonymously 19:48:38 then you could just lp on uniswap 19:48:39 Tax authorities will find that really suspicious 19:48:39 @kiersten5821:matrix.org: Heretic! 19:48:52 @kiersten5821:matrix.org: Who would you trust with your XMR? 19:48:54 kiersten5821: Okay and who's gonna hold the XMR 19:48:57 The second one is somewhat vague (and I am not "in the know" about what does "owned outputs uses" mean), also. 19:49:09 @hbs:matrix.org: 🔥👨 19:49:10 @kiersten5821:matrix.org: so wagyu lol? wrapped protocols are custodial 19:49:18 @ofrnxmr:xmr.mx: 19:49:18 > youre not giving up ID, but you still VERY MUCH know who your customers are 19:49:18 that's why this thread over there: https://monero.forum/thread/burnt-out-trying-find-way-avoid-kyc-exchanges[... more lines follow, see https://mrelay.p2pool.observer/e/_L_p240LUUcxMG9T ] 19:49:22 Cindy__: perpetualcow of wagyu 19:49:53 @ofrnxmr:xmr.mx: yes, wrapped custody is bad, but one of those giant multisigs with stake based on a coin like tbtc is not THAT bad 19:49:58 @ofrnxmr:xmr.mx: Hope he doesn't forget his ledger PIN 19:50:00 even serai will have its own coin 19:50:07 for the chain security 19:50:09 as i udnerstand 19:50:46 Why would anyone work on that when they could just do wrapped custody and bait everyone into falling for it 19:50:49 Then rugpull 19:52:31 why does anyone work on anything when they could just do that 19:53:04 How will you find the one good wrapped token in a sea of impostors and rugpullers 19:54:11 alcedo: IIRC that's for tracking in which tx your outputs were used as decoys 20:00:57 Really? Does that happend locally, or are some special requests made towards the network? 20:08:01 The info is saved as your wallet scans txes. So it's done locally, from info that was pulled from the network, and saved to the wallet cache file. 20:26:42 Thanks! 20:30:25 moneromooo: Is the cache a seperate file or part of the large wallet file? 20:39:35 It's a large wallet file, called quux if your keys are in quux.keys. 20:42:29 moneromooo: Thanks for confirming it. I suspected as much, since there were seemingly no other files connected to monero except for the wallet file and the .keys (and an .old_cache file, but I guess it's vestigial).