TR vendors, look into older timelocked tx backups if you have them.

I looked into a vendor's timelocked txs. He saved the timelocked txs after processing a batch of orders, a save was made every day. He had 5 of these, coming from the market's last 5 days.

All the unclaimed transactions were supposed to show up on the page where the timelocked txs were provided, but in the last day or two there were some missing txs.

Some orders were completely missing from the last 2 saves, but the backup from 3 days or earlier still contained all the data for the order. The outputs are still unspent, these coins are still in the multisig escrow addresses. I suspect these orders were finalized while the market was still alive, signed by the vendor and broadcasted using TR's textbox. The tx wasn't broadcasted because of a problem on TR's end, but TR removed these orders from the timelocked txs thinking they were already claimed.

I found several of these timelocked txs in previous backups so if you have these it worths to look into them.

The other anomaly was where only the order number and the amount of BTC were shown, the timelocked tx itself was missing.

Previous saves from 2 days or before that had no such missing txs. I suspect these were the latest finalized orders in the last days of the market and they already had a problem.

Because of these missing txs 85% of the vendor's funds can be moved out of the escrow addresses with the timelocked txs, 15% will be likely stuck especially in the 2of2 multisig address.

All the withdraw addresses in the timelocked txs are the vendor's, so they haven't been changed by an attacker.

The timelocks are based on blockheight, they will be released at around 500000 which should be reached in less than 2 months I believe.

TLDR; Check all the timelocked txs you have from the last days of the market.


Comments


[1 Points] zero234kljf:

what if you don't have them? is there any way to look up the redeem scripts or timelocks from the blockchain by reference of your receiving or sending wallet address?