Update on DHL Withdraws

The last one didn't gain much attention, but here is the rundown. You can withdraw all your balance 2-3 more times even when its empty. They claim this isn't an issue, because the system will stop the other requests if it makes the balance go negative and won't give a reward for it. For there sake, lets hope they are right. They wanted me to clear up it isn't an issue, so here is the basic back and fourth on it. I did it a second time to show them, and they put this.

"Hi,

We have been alerted to your reddit thread.

With all due respect:

There is no bug in our system and no threat. Never has been.

We just wondered why you are able to TRY to request withdrawals even though your balance is already zero.

Here is what our system says in that case:

(Sun Oct 18 20:12:36 EDT 2015) secure-update message file = /tmp/dhl-secure-update/1445213563-withdrawal-JF4ZyccqBM7F4pPs (Sun Oct 18 20:12:44 EDT 2015) containing message type 'withdrawal' == started processing withdrawal message == withdrawal for xx (6150) to address:1y5JfTfGqGBzNs1QMSA4BLZEhPyEarxxx and amount:0.00480000 Successfully verified signature for address userid:6150 address:1y5JfTfGqGBzNs1QMSA4BLZEhPyEarxx amount:0.00480000 ERROR:This withdrawal would make the user's balance negative

--- finished processing message ---

(Sun Oct 18 20:12:44 EDT 2015) secure-update message file = /tmp/dhl-secure-update/1445213569-withdrawal-5aymoqWNmQ7NJIx4 (Sun Oct 18 20:12:50 EDT 2015) containing message type 'withdrawal' == started processing withdrawal message == withdrawal for xxx (6150) to address:1y5JfTfGqGBzNs1QMSA4BLZEhPyxx and amount:0.00480000 Successfully verified signature for address userid:6150 address:1y5JfTfGqGBzNs1QMSA4BLZEhPyEarxx amount:0.00480000 ERROR:This withdrawal would make the user's balance negative

You can clearly see 'ERROR:This withdrawal would make the user's balance negative'

So no withdrawal was ever generated. But we received alerts about your tries to do so.

We changed this already and the button is now greyed out when your balance is 0.

Originally this was intended so we are alerted to members which might be LEO or 'hackers' and put them on a watchlist.

Of course in your case no bad feelings since it seems to be genuine curiosity :)

But please state this correctly since there was never at any time a way 'to drain our wallet'. Also the system is already on automatic. Just with a random security buffer in terms of time when it is processed.

The way you posted that thread makes our market look bad and even though we don't care about reddit much we would appreciate your correction of said post.

We appreciate your concern but in the future when you suspect such a problem you should talk to admins/support first and only iwhen you don't get a reply, go public with your information.

Cheers & Thanks you.

PS: For genuine exploits we are willing to give out bounties all the time and quite big ones. Our warchest for that is around 200 BTC but this will be announced fully when we exit beta since we are still rewriting a lot of code. DHL itself only serves as proof of concept. There are much bigger things being worked on.

'On another note you tried to create multiple withdrawals for the same funds. Can you tell us how you did that exactly?'

There is a big difference between TRYING to create and actually CREATING multiple withdrawals for the same funds ;)"

Anyways, take it how you will. You can request multiple withdraws from an account with no balance, but its no issue for them.


Comments


[2 Points] SmauqDrogs:

Not hating on DHL but since they said they don't care much about reddit... Then I don't understand all the fake accounts and the shill they did to promote the market when agora closed and when that hax0r guy claimed he got DHL's coins.
Just a thought.


[2 Points] whoohoowie:

Originally this was intended so we are alerted to members which might be LEO or 'hackers' and put them on a watchlist.

LOL

The way you posted that thread makes our market look bad and even though we don't care about reddit much we would appreciate your correction of said post.

"we don't care but please do it different since secretly we do care"


[2 Points] deezyyyy:

we don't care about reddit much

Bet they'd care if they were removed from the Superlist...