Skip to content

Comment on How Primedice was exploited for $1M in Bitcoin

Comments

and time again to investigate and each time our developers could not find any wrong-doing.
...
This was done by sending it more requests than it could handle in a small time period, think hundreds of requests in under a second

Sounds like your developers really messed up. The server logs would be the #1 place I would look. Where else really? How do you not notice hundreds of requests per second (from the same IP I assume)?

This was my question as well. How do you not notice 100's of qps from the same IP, and then go on to say, he was betting $8k/second. server logs, and basic networking chomps seems like it would have found this much quicker.

I've never heard of Primedice before, but based on their blog post (and the general concept of a bitcoin casino)...

...I can't imagine the slightest reason why they would expect, would want, or would tolerate automated gambling. ANY evidence that someone is using a script or bot, making too many bets, making bets with an oddly regular pattern, making too many requests from a single IP, making requests from different IPs at the same time, etc. would seem to be a red flag, and should cause the associated account to be suspended. Right?

Like, if there's a hole in your code, the attacker is very likely to automate the attack to try and maximise their gains. But if there's no hole in your code, your punters are very unlikely to automate their playing. Any hint of automation is a huge red flag; any hint of automation combined with a string of "lucky" wins should be an automatic account suspension, because you're obviously looking at successful attack.

Saying that your developers couldn't find any "wrong-doing" just raises questions. Like, why do your developers need to look, shouldn't those checks be automated? And how did they miss it when it turns out it was obvious? And why were you even looking when the underlying activity was obviously illegitimate? Real casinos don't wait until they understand the scam before cutting someone off.

So many questions.

How do you not notice hundreds of requests per second (from the same IP I assume)

To be fair to them, I imagine a bitcoin casino is a magnet for weird traffic patterns. Giving them the benefit of the doubt, maybe they're getting bursts of crazy traffic all the time, and they had no way of knowing which ones were "potential timing attacks" and not just "bored script kiddy with a botnet". Maybe "Hufflepuff" was hitting them from an unrelated network constantly, and a small fraction of those times he also made a bet he already knew the outcome of. Maybe he was also making normal bets at the same time. (...or maybe not.)

Still, even if the bad traffic was hidden by noise, I don't believe that his account activity could have looked normal the entire time he was building up his 1 million payout.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.