Coming soon - Get a detailed view of why an account is flagged as spam!
view details
94
PSA: scam warning! - MillionBitcoinCash (MBCH, claimed POS fork)
Post Body

Time to blow the whistle on what looks like a large scale scam being prepared to resemble a fork of Bitcoin Cash to a Proof-of-Stake coin. I've decided to call this out before they make a wider social media push so that fewer people will be deceived.

It's unclear whether the intention is to defraud or just to cause reputational damage and FUD / confusion on Bitcoin Cash. I will refer to the whole scam complex of websites and social media accounts by the acronym 'MBCH'.

NOTE: To prevent accidental visits to their sites, I will break up suspected scam domain names in this post by inserting spaces or otherwise mutating them.

Most domains used by the scam that I saw so far were insecure (all HTTP, no HTTPS). They might contain exploits - use extreme caution and preferably only inspect via a secured browser over TOR in throwaway VM or similar setup.


First I came across was this announcement by fresh user 'MBCH' on the trusted forum bitco.in :

https://bitco.in/forum/threads/million-bitcoin-cash-fork-1-1-of-bitcoin-pro-on-chain-scaling-cheaper-fees.2670/

That referred plainly to source code on Github, forked ABC and Classic binary packages, and the reddit user / u / MillionBitcoinCash who has published a FAQ and made a link post to the millionbitcoincash dot com site:

https://www.reddit.com/user/MillionBitcoinCash/comments/70tml8/millionbitcoin_cash_frequently_asked_questions_faq/

First, I had a look at the code repository on github, and it was immediately clear that it's not a fork of Bitcoin ABC nor of Bitcoin Classic, but of Novacoin. The change history emanates from a single dump with no development history of the changes, so its changes are obfuscated. I did see glaring renaming omissions in crucial packaging files and funny errors such as a copyright notice by the MillionBitcoinCash developers with a date of 2014 in the license file.

The second thing that becomes clear immediately after looking at the published code is that it cannot be used to produce the binary packages, which are therefore produced from closed source.

It's easy to search the github code to look for the fork block height, 8MBblock size cap and SIGHASH_FORKID replay protection which the FAQ claims this MBCH is implementing.

No surprise - this was all not implemented in the published code on Github. There's no way the sources there meet the stated claims.

I think that's enough for the obvious technical clues that this is a scam, or at least not deserving of anyone's trust.

They operate both .com and .org versions of the domains, and host differing binary packages (the ones linked on bitco.in announcing post differ from the download links on the org site).

Both Windows files are detected by Ikarus scanner on VirusTotal.com as containing a trojan. This is just a single report however, and may be a possible false positive. Take extreme care though. The Linux and OSX files are not flagged by VirusTotal, but who would be running closed source cryptocoin software anyway.

I've posted a scam alert on https://forum.bitcoin.com/post98998.html with some more details that I didn't mention here (probable deceptive use of logos of HitBTC and Bittrex, among others).

As stated there, I believe this will be used in an attempt to tarnish the reputation of Bitcoin Cash and supporting organizations.

I think it is also designed to discredit further Bitcoin hard forks at this critical time (with Bitcoin Cash gaining adoption, and SegWit2x coming up as well).

What I hope is that we can make people sufficiently aware and that no-one will fall for this elaborate scam.


Again, please use extreme caution when visiting any of their sites. At the very least your traffic will be in plaintext, and they could log / exploit your browser. Their binaries are not open source, exist in conflicting versions and could be exchanged for malware at any time as they do not publish the checksums.

Stay vigilant and safe :-)

Author
Account Strength
100%
Account Age
8 years
Verified Email
Yes
Verified Flair
No
Total Karma
20,629
Link Karma
7,328
Comment Karma
12,869
Profile updated: 6 days ago
Posts updated: 10 months ago
Bitcoin Cash Developer

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
7 years ago