Moddin February 5 2007 6:22 AM EST

I'm writing this through the account of my friend Moddin.
I am the owner of the account "TwoNinE".
My account was obviously hacked this night by someone owning the account "Mazzus (BookCase)".
I cant login anymore!!!
Plus, according to the transfer log, he transfered all my 26mil to his character "BookCase":
TwoNinE (The Generator) Mazzus (BookCase) $26000000 February 4 2007 1:54 PM EST
and right after that the dough was sent to "Black Thunder (The Bad Apple)":
Mazzus (BookCase) Black Thunder (The Bad Apple) $26000000 February 4 2007 1:57 PM EST
This guy again spread my money all over the place.
You can verify, that I am the legal owner of the account and the dough by responding to the E-Mail address attached to the account "TwoNinE" if it wasn't changed to.
Please help me to get my stuff back and make this bastard suffer!!!
Thank you all

AdminShade February 5 2007 6:28 AM EST

I can't do too much, but your money now is in hands of people who bought CB from Black Thunder...

Flamey February 5 2007 6:33 AM EST

<system> [mail:] You have been assigned as a mentor to twonineII, who is currently in the room 'new players'. CB has taken the liberty of forging a chatmail from you welcoming him. Thanks for your help!


Moddin February 5 2007 6:36 AM EST

So he will get away with it and I'm the boned???
I mean honestly...that can't be it...!!??

Moddin February 5 2007 6:41 AM EST

I tried to create myself a new account to post this here, but the tutorial kept me away from using the forum. So I asked for using the "Moddin"-Account to post. Whats the point?

bartjan February 5 2007 7:11 AM EST

For now I'm convinced that:

Because of this, I have moved the character back to your own account, together with the repo'd the cash.
Most likely the account was broken into because of a weak password. I for now don't know this for sure, and if there should be an admin fee/stupidity tax charged (because this then could have been avoided...)

Moddin February 5 2007 7:24 AM EST

Thank you so much for helping so far, bartjan!!!!!!!!
Maybe I had a bad password, but when I started playing, I wasn't aware, that there is a danger of getting robed in here!!!
I can see, that "TwoNinE" now has a third character with my money.
But still I can't log on to it.
I was a little hasty creating "twonineII" for posting here and I used my old E-Mail-address.
So now I have only access to twonineII, which of course can be removed again!
I'm sorry for the trouble....

AdminShade February 5 2007 7:27 AM EST

twonineII should indeed be removed, and you will get the old account back when bartjan is done with his 'research'

bartjan February 5 2007 7:47 AM EST

D'oh! forgot that you indeed couldn't access the account. Could you send me a chatmail with a working email address that should be used for the account. Try to avoid something like hotmail, as they tend to be a bit demented when it comes to receiving email.

QBRanger February 5 2007 7:52 AM EST

Well Bart repod the 20M I paid USD for.

THAT IS CRAP!!!!!!!!

I paid usd for it like any normal transaction.

Why should I pay for someones inability to protect their account by making a password that can be hacked!

How do we know they are not in this together.


GO PATS February 5 2007 7:56 AM EST

That's crazy... I thought the rules were clear on this? I'm not happy that someone got hacked but there are warnings all over about it saying that the admins cannot and will not get your stuff back... why was this changed for this one specific occasion?

bartjan February 5 2007 7:56 AM EST

Next time:
- Make sure you don't buy large amounts from people that surprise you that they suddenly have that much cash.
- Make sure you make a Public Record post or any other forum post (in advance) detailing the transfer.
- Contact Paypal and scream "Fraud!".

QBRanger February 5 2007 7:59 AM EST


That is crap, utter crap and everyone knows it.

So are the admins now in the repo business due to someone's inability to protect their account?????

GO PATS February 5 2007 8:01 AM EST

Why didn't Jon just create a new 26m and give it to the one who got hacked instead of taking the money that PM paid actual cash for? I know that would be "wrong" but so is what just happened.

QBRanger February 5 2007 8:03 AM EST

And as we know, paypal will do nothing as they have done in the past.

Xenko February 5 2007 8:09 AM EST

I think this sets a bad precedent... are players now responsible to try and track every transfer that another player has done, just to try and somehow ensure that there was no illicit activity? Even then, how was PM supposed to know that a hack had occurred?

I think both TwoNinE and PM got scammed in this... and yet PM seems to be the one being punished, despite the fact that TwoNinE was the one with a weak p/w who got hacked. Don't get me wrong, I feel bad for TwoNinE, but why should he suffer no consequences, while PM loses out on a large sum of money for something he obviously had no control over?

velvetpickle February 5 2007 8:12 AM EST


I have to agree that in this instance it is unfortunate that someone lost money due to a hacked account, but you have now made others suffer due to this fact. CB has always had a strict policy about how these things are dealt with, and through bypassing these policies, you have caused other players inconvenience, and loss. Again I don't feel it is right that twonine's account was hijacked and resources were lost, but it certianly is not fair to repo the money from another character who purchased it legitimatly with no knowledge of the theft.

Again, through circumventing the rules strictly outlined by CB, you have recouperated some of the funds lost by one innocent player, but caused another innocent player a significant loss and that is not justified.

QBJohnnywas February 5 2007 8:13 AM EST

I think it is every player's responsibility to check out who they're dealing with. I wouldn't hand money over to anybody in RL without double checking on them, if I could.

But the thing is, Bart was putting right something that happened in game. USD transactions are outside the game. If you're making a deal outside the game it's your responsibility completely.

AC 478 February 5 2007 8:17 AM EST

Wow.. I feel so bad for PM, I think Bart did the wrong thing here. did the guy just find someone with loads of cash and try to guess his password? smells a bit fishy to me.

Mikel February 5 2007 8:18 AM EST

Bad business for USD Buyers, now we should give 1 week before we actually pay for the cb2 sent to us.

Xenko February 5 2007 8:19 AM EST

"But the thing is, Bart was putting right something that happened in game."

Which goes against CB policy. How are player's supposed to follow the rules if the admins are free to change them radically (I can understand minor changes in the rules depending on the situation, but this completely ignores CB's policy on the issue).

QBJohnnywas February 5 2007 8:23 AM EST

Ok, here is the paragraph from the Public Record forum:

If 2 people enter into a deal, and it is posted here, and one person backs out, or scams the other person, here is what will happen:

'If person A scams person B, we will reset A. We do not want to encourage scamming. BUT, it is your responsibility to make sure the person you are dealing with is trustworthy. We also do not want to encourage the thinking of, "so what if this guy offering me a cornuthaum for $100k is scamming me, all I have to is whine to the admins to get my money back." So no, we're not in the property recovery business. Same goes for loan installment payments. In other words: if you want truly scamproof trading, your only option is the auction system. '

Two things to note: any scamming here was the sale of the Cb$. What happened to TwoNine was hacking and theft. It is a completely different situation. And in that same paragraph that people bring up regarding scamming is the following sentence: "it is your responsibility to make sure the person you are dealing with is trustworthy".

Wasp February 5 2007 8:28 AM EST

Maybe a 10 million stupidity tax should be sent to Popsicle man. He seems to be the only party losing out, and he was nothing to do with it.

This situation is a bit different from property recovery, someones account was cracked.

It seems a bad precedent will be created if this is allowed. Let me quickly ask my friend to hack my account, sell my money, so I can get it back and sell it again. Lovely Jubbly

velvetpickle February 5 2007 8:28 AM EST

here is the thing.... Think what would have happened if the situation were reversed:

Lets say PM (or anyone) sent a paypal payment for $CB and the gold was never sent. If they had filed a complaint, could show CM logs, and a log of the paypal pmt., the admin would do NOTHING about getting the rightful gold to the purchaser, b/c this is the policy. The admin would have every capablity to "make things right in the game" but they would take no action. I am sure with a small ammount of research cases could be doccumented where this has been the case.

Again it makes no sense that with reversed circumstances that they should penalize a character with no involvement, to rectify a character who was hijacked.

bartjan February 5 2007 8:29 AM EST

As I remember it, transactions as a result of hacking were always reversed.
I'm trying to dig up the forum posts involving Tizzo, but it seems like Google forgot all about CB1 and is offline right now.

AC 478 February 5 2007 8:32 AM EST

you have to be sure he was hacked thought right?

QBRanger February 5 2007 8:39 AM EST

"It seems a bad precedent will be created if this is allowed. Let me quickly ask my friend to hack my account, sell my money, so I can get it back and sell it again. Lovely Jubbly"

Man, could I make a lot of money from that!!

Very Very bad precedent being set. Now we have to look through all the past transfers of all people, ask for 10 references, get a detailed history of their life, etc... What a crock.

I am sorry someone got hacked, but that comes from having a poor password. So I should be responsible for someone not doing things right? Seems so.

AdminShade February 5 2007 8:45 AM EST

If I recall correctly as well as bartjan did, all the Hacked money from Tizzo was refunded to the people on cb1 from paypal...

Drack February 5 2007 8:46 AM EST

thats' totally unfair that Popsicle Man is the guy under the chopping board

speaking of stupidity - the person who should lose out (if anyone) here would have been the guy with the weak password

what does critters have to say about this too?

Duke February 5 2007 8:49 AM EST

I am not a expert in internet technologie but how Twinine and modin been able to get a IP from RIPE.A quick look at tell me that its just not a ISP and they have members in Canada, black thunder is from Canada.

jayuu February 5 2007 8:50 AM EST

If it makes you feel any better PM (I doubt it will), you're not the only one getting ripped-off here. I bought 8.7M (for USD) from Black Thunder and had the CB cash repo'd this morning. I don't have much hope of seeing 'justice' done either.

QBRanger February 5 2007 9:26 AM EST

Hot off the press from Paypal:

Dear (xxxxx),

Our investigation into your claim is complete. As stated in our User
Agreement, the claims process only applies to the shipment of goods. It
does not apply to complaints about the attributes or quality of goods
received. Therefore, we are unable to reverse this transaction or issue a

Transaction Details

Transaction Date: Feb 4, 2007
Transaction Amount: -$170.00 USD
Your Transaction ID: 27K97096F54771528
Seller's Transaction ID: 9SA513158K271941B
Case Number: PP-248-652-403
Seller's Name: Aaron Ayers
Seller's Email:

GO PATS February 5 2007 9:48 AM EST

Just wondering... if PM had bought that money and then spent it quickly, would the person who got the money from PM be stripped of thier cash? This makes no sense to me, because the person who got ripped off in basically "fake" money was given his "fake" money back, but the person who bought that "fake" money with "real" money is stripped of the "fake" money instead of just creating some more "fake" money to give to the first guy who lost it?

Relic February 5 2007 9:59 AM EST

To me this is a no brainer. PM as well as anyone else who bought CB2 with USD and can prove it through paypal transaction logs, should be able to keep their paid for game cash. Paypal sucks at recovering fraudulent transactions. TwoNinE, while it is too bad, should get his character back, password reset, and that is the end of it. Anything that was pilfered on the hacked account is not the fault of anyone else but the weak password and hacker (if this truly is a hack case). I looked at the IP addresses used by the hacker and TwoNinE and they both are Canadian, while this does not prove guilt, it is convenient and suspicious.

QBBarzooMonkey February 5 2007 10:02 AM EST

From: Black Thunder Sent: February 4 2007 2:06 PM EST

Hey, I have an steal of a deal for you. I'll sell you $28.5M for 250 US. What do you say?

Having been here more than 2 years now, burned a couple of times myself and watched multiple burns go down via the forums, I passed on this as "too good to be true", with my best judgment telling me it was a multi, or scammer...

Just an observation...

Relic February 5 2007 10:06 AM EST

After a little more research, it appears that TwoNinE and Moddin are both from Germany and Black Thunder is from Canada.

QBRanger February 5 2007 10:06 AM EST


That was not "too good a deal"

Jon was selling cb2 for 45 usd for 5M cb2. About the same price as Black Thunder.

I get a lot of CM's offering to sell me cb2 for less then 10 bucks per million. Are all of them scams?

I guess in the future, all of us will have to get tons of references before buying any items not in auctions (and perhaps even then if they were "stolen") before actually buying something.

Very poor precedent.

Rubberduck[T] [Hell Blenders] February 5 2007 10:22 AM EST

Whilst some warning signs were present here I don't think they should be used to brush it off as "should have been more careful"
The admins have corrected 1 side of the scam but not the other.
I understand that it is not desirable to create CB$ to reimburse PM and Jayuu because of a hack but the present resolution doesn't seem adequate either...

QBBarzooMonkey February 5 2007 10:27 AM EST

PM, there really is no comparison between what Jon was doing as a rare, 1 time thing, and receiving an unsolicited CM from someone relatively new with a large bulk amount at a "bargain" quick sale price.

Any unsolicited CMs from someone I haven't dealt with before offering more than 4 or 5 mil at one time raises red flags with me. But that's just me...

I'm not advocating brushing this off, either. Honestly, I hope PM and Jay get either their USD or CB$ back, I really do. I believe that some instances, such as these here (for both Moddin and those guys), should be cause for the Admins to get into the "recovery business". But I'm simply offering my experience as some "live and learn" advice to the community...

QBJohnnywas February 5 2007 10:32 AM EST

It might seem unfair. But the deal/transaction for the CB$ was made outside of CB, and so is outside of CB's admin.

And is it right that people keep money that is known to be 'stolen', regardless of the fact that they didn't know at the time of the transaction?

Tezmac February 5 2007 10:34 AM EST

Why don't we all just stop chipping in our two cents on this one and just wait to see what the admins/Jon do ok?

bartjan February 5 2007 10:37 AM EST

I already sent Jon an email asking for his input...

AdminNightStrike February 5 2007 11:09 AM EST

"That he indeed cracked your account (login from an IP on a completely different continent, and the first/only things he did was change password and move the loot)."

Really... you know what's interesting? I connect to the net through ip addresses all over the globe, including Antarctica. If that's your logic, it seems that perhaps I should use one of my VPNs in Japan to login as a different user and really capitalize on my excess in-game wealth.

I think you might want to learn a little more about internet scams.

Regarding this ordeal.... $20m isn't a lot. Just take it off of Central Bank and send it to Ranger and be done with it.

One more thing -- for all those people claiming that the password is weak, you might want to consider the number of logon attempts. What is more likely is that the aggressor stole the password via keyboard logging or some such thing. Cracking a password, outside of porn sites, is not only blatantly obvious, but a total waste of time.

TwoNinE February 5 2007 11:46 AM EST

Hi again everyone,
one last thing from me about the whole incident via my own account:
Blame me for whatever: weak password, scammer, name it.
Fact is: I am a member of this community since September of 2006 and I never got into any debt!

Fact is: the money is on my account again. It will not move nowhere till there is a reasonable decision from the high entity!

Fact is: characters "Moddin" and "TwoNinE" coexist here since the day I joined and we NEVER acted any multi-like!

Fact is: weak Password back and forth: everyone is invited to check if their login is unhackable anyway.

I feel real sorry for the other two guys, but we all where shammed!
I would really appreciate if there can be solution that fits all of our claims!!!
Maybe the whole thing uncovers a very basic problem of the "pour real money into the game thing"!!


AdminJonathan February 5 2007 12:33 PM EST

I don't believe in Central Bank bailing people out for the same reason that I think having taxpayers foot the bill for underinsured people building in risky areas is a bad idea: incentives matter, and that encourages exactly the wrong behavior.

I'm also anal about not creating money ex nihilo as far as the game mechanics are concerned.

So, I think that (1) the USD buyers should immediately make a claim through paypal, and (2) they should get twonine's money until paypal follows through. I think both can be trusted to either send the USD or equivalent CB to twonine if they get it back.

Should they have been more careful? Yes, but in this case the greater blame lies with twonine for setting his password to his username. (I checked a db backup.) I think for that lesson twonine got off relatively easily.

(For newbies to the whole IntarWeb thing: while exceptions exist, crackers almost never try really hard to get into a specific account; instead, they scan as many accounts as they can find for stupid passwords such as "password," "123456," "qwerty," password same as username, etc.)

AdminJonathan February 5 2007 12:34 PM EST

I'd also like to stress that bartjan acted in good faith and this does not constitute a rebuke to him or anything like that.

AdminJonathan February 5 2007 12:36 PM EST

I also agree with PM that we don't want to encourage people to try to double-scam by faking a hacked account.

AdminJonathan February 5 2007 12:41 PM EST

Transferred funds to jayuu and PM.

QBRanger February 5 2007 12:46 PM EST

Thank you Jon.

QBRanger February 5 2007 12:49 PM EST

I already did file a claim with PayPal and the email I received from them was posted above.

Basically, nothing will be done.

AdminNightStrike February 6 2007 11:58 AM EST

You can argue with paypal that the goods were never delivered. Paypal has some of the worst customer service ever, and is heavily regarded in the online currency world as non-existent for the simple fact that they are a horrible service on many levels. I myself was involved in a class-action lawsuit against them because they stole several thousand dollars out of my account -- I got back $50 out of the lawsuit. The bottom line is: 1 - don't use paypal. 2 - If you are forced to use paypal, only spend via a mastercard (not visa, not discover, not Amex, etc). When paypal refuses to acknolwedge your claim, reverse the charge through mastercard, explain what happened, and MC will politely inform Paypal that if they don't comply within 30 days, they will lose MC privileges and be fined $50k per dollar withheld.

This is what I do, at least, and I've never been scammed since. Your mileage may vary, and I'm just explaining how I've worked with various financial institutions through the years, and how I've found what works for me.

As a final note... e-gold all the way!

QBsutekh137 February 6 2007 1:26 PM EST

Jonathan, is is hard to enforce better passwords upon initial registration and password changes?

smallpau1 - Go Blues [Lower My Fees] February 6 2007 1:29 PM EST

there isnt gonna be a stupidity tax in this case?

Miandrital February 12 2007 7:19 PM EST

small, I'd say the 26 mil stupidity tax enacted on TwoNinE is rather hefty.

QBOddBird February 12 2007 7:23 PM EST

"Because of this, I have moved the character back to your own account, together with the repo'd the cash."

he repo'd the cash. There was no loss on TwoNinE's part.

AdminShade February 12 2007 7:23 PM EST

In response to Sutekh, perhaps indeed make it so that passwords have to have both letters as well as digits?

QBRanger February 12 2007 7:27 PM EST

No OB,

Jon then moved the money back to myself and Jayuu.

Saying it was not our fault as his password was as simple as his character name.

Yes, it was a large stupidity tax, but imagine in the real world if he did the same thing. Like for his bank account, etc...

QBOddBird February 12 2007 7:31 PM EST

Ah, I gotcha. I read it as you and jayuu being transferred funds, and didn't realize that meant they were TwoNinE's. But agreed, the stupidity tax was fully justified.

AdminQBVerifex [Serenity In Chaos] February 12 2007 8:55 PM EST

This is 2007, there is no excuse for people still using their username as their password. If you are using a computer you really should learn about "safe practices" before using the computer. Here is some good examples.

Computer Safe Practices
