23/03/2025
News
Rubyly
⚠️ Rubimily and the Forty Thieves!

admin
2025-03-19 17:38:16
20 Comments
641.08k views
⚠️ WE ARE UNDER ATTACK!
Hey there! How was your week?
Shocking news is that RUBI Network had a terrible week, so today I am using this newsletter to inform you about what went wrong!
Have you ever heard of the story "Alibaba and the 40 thieves"? That is the title of a story that most of us Vietnamese know, I don't know if in your country that story has a more interesting title or not.
The story is set in ancient Persia and tells of a group of robbers or thieves who stole a lot of people's property and piled it up. But the end of the story did not end well for the thieves, who were unable to enjoy the wealth they had stolen.
And coincidentally, in the past few days, we have seen such bad thefts right on the RUBI Network. It was so bad that many people did not even know "they were being robbed" until they read this article. Whatever happened, it happened, thieves came to your house and stole your precious RUBI that you had mined.
Although we took immediate action, actively finding and handling the situation before we published this article to you! We took drastic measures, tracked down and restrained the thieves and their accomplices.
Now! Let me explain in detail what happened!
FIRST REPORT!
On March 13th I received the first issue report sent by 2 Nigerian community ambassadors! It was a Nigerian miner who discovered that his 986 RBL was being moved to a new wallet on his own account that he did not create , and he did not have the private key to. This was a first report of this kind, a type of alert that we have not received before.
The amount of more than 900 RBL is a huge amount for a miner to mine, this is a loss that he will almost never be able to compensate for with further mining. Because this number is so serious, we immediately investigated what happened.
SERIES OF THEFTS
Also on the 13th, after discovering more victims, we tracked the victim wallets and found a series of thieves in the act of stealing. We quickly tracked the thief wallets and discovered more victims and where the thieves stored the stolen assets.
On the 15th we decided to update the source code to implement new tools to support the tracking and verification of fraudulent accounts, consumer accounts, and storage accounts.
A race was on, Rubi Network made continuous updates and aggressively tracked, while the thieves also continuously created new wallets to continue stealing, hiding and quickly finding ways to disperse the stolen assets. The race was fierce while most of the miners were sleeping and no one knew about the incident.
THIS IS 40 THIEVES?
After looking at the characteristics of this attack, they showed that this was not a single attack, but was carried out by many thieves, which is why I thought of the story of "40 Thieves". All the characteristics of the attack have shown that this is a common Phishing attack that has been quite popular in the past few years.
The thieves we found were mainly from Iraq, and when we tracked them down, we found so many other thieves that we exclaimed with humor! "Damn - we are dealing with the descendants of the famous thieves from the story of the 40 thieves".
These thieves committed the theft in unison with quick movements, professionalism and speed of ex*****on that showed that these were people with rich experience in the profession of theft.
There were really a lot of them, they acted very quickly, but so did our team! In a few days we quickly added the source code and carried out the tracking and found many "treasures" where they kept what they stole.
HOW THE THIEFS DO IT.
Did the thieves get the Rubies from your wallet? No, they do not attack your wallet, instead they try to hack into the mining pool to steal the mined Rubies that have not been transferred to the wallet. These thieves perform PHISHING attacks to gain access to your account, then they steal the mined RUBI that is sitting outside your wallet.
And here is the sequence they did.
Step 1: They got your email and password in many ways and got access to your account
Step 2: They access the account and check the account status, see if it has been KYCed, see if there is a balance outside?
Step 3: If you have KYC and have untransferred balances, they will go to the wallet creation section and create a new wallet (which is controlled by the thief)
Step 4: They connect the newly created wallet to your account and then create a migration request for all the Rubies from the mining pool to the new wallet.
Step 5: They then quickly transfer all the stolen funds to a wallet on another account that they control.
DAMAGE ESTIMATION
This is a bad attack on the Rubi Network, Phishing attacks are commonly known, attackers perform fraudulent activities to gain access to accounts and passwords, then gain access and commit theft. A typical such attack happened in early 2024 when a group of young scammers scammed away $230 million worth of Bitcoin at that time.
Here are the estimated figures for the damage in the terrible attack by the "40 robbers" on Rubi!
• Hundreds of victims:
Based on what has happened, the number of victims observed has reached several hundred victims and may continue to expand, the victims come from many countries, including Nigeria, Vietnam, India, Indonesia, Pakistan and several others.
• Dozens of attackers:
Several dozen direct attackers, and hundreds of people involved in supporting the hoarding and consumption, they create a complex network of movements to make it difficult to trace.
• Amount of stolen assets:
Based on known figures, the amount of stolen Rubi may be up to more than 400,000 RBL, this is clearly a very serious number. However, the majority of the stolen Rubies are still in the wallets of the thieves, while the rest, up to hundreds of thousands of Rubies, are being sold off at low prices. We are indeed witnessing history repeating itself, and it has always been a part of development.
• Countries with many victims:
Tracking data shows that the attackers were mainly from Iraq, but the victims came from all over the world. The tracking data shows that these are the countries most affected by this crisis: Vietnam, Nigeria, Pakistan, India, Indonesia, Bangladesh, Türkiye, Philippines
IF YOU ARE A VICTIM!
Since the number of victims seen has reached hundreds, we consider this a serious crisis! Please check your account immediately and let us know if you are being attacked by Phishing! Providing more information will help us track down faster and resolve this crisis soon.
How to check:
Go to your account and check for any unusual signs:
• See if there are any new wallets created without your knowledge,
• See if there are any mining Rubi movements made without your knowledge.
A race is on, Rubi Network makes continuous updates and aggressively tracks, while the thieves also continuously create new wallets to continue stealing, hiding and quickly looking for ways to disperse the stolen assets. The race was fierce while most of the miners were sleeping and no one knew about it.
THIS IS THE 40 THIEVES?
After looking at the characteristics of this attack, they showed that this was not a single attack, but was carried out by many thieves, which is why I thought of the story of "40 Thieves". All the characteristics of the attack pointed to the fact that this was a common Phishing attack that had been quite popular in the past few years.
The thieves we found were mainly from Iraq, and when we traced them, we found many other thieves, we exclaimed humorously! "This is bad - we are dealing with the descendants of the famous thieves from the story of 40 Thieves".
These thieves carried out the theft in a coordinated manner with quick movements, professionalism and speed of ex*****on, showing that these are people with rich experience in the profession of theft.
There were indeed many of them, they acted very quickly, but so did our team! In a few days we quickly added the source code and did the tracking and found many "treasures" where they kept what they stole.
HOW THE THIEVES DO IT.
Did the thieves steal Rubies from your wallet? No, they did not attack your wallet, instead they tried to pe*****te the mining area to steal the mined Rubies that had not yet been transferred to the wallet. These thieves performed PHISHING attacks to gain access to your account, then they stole the mined RUBI that was lying outside your wallet.
And here is the sequence they did.
Step 1: They got your email and password in many ways and got access to your account
Step 2: They access your account and check your account status, see if you have KYC, see if there is a balance outside?
Step 3: If you have KYC and have a balance that has not been transferred to the wallet, they will go to the wallet creation section and create a new wallet (this wallet is controlled by the thief)
Step 4: They connect the newly created wallet to your account and then create a migration request for all the Rubies from the mining area to the new wallet.
Step 5: They then quickly transfer all the stolen coins to a wallet on another account that they control.IF YOU ARE A VICTIM!
Since the number of victims seen has reached hundreds, we consider this a serious crisis! Please check your account immediately and let us know if you are being attacked by Phishing! Providing more information will help us track down faster and resolve this crisis soon.
How to check:
Go to your account and check for any unusual signs:
• See if there are any new wallets created without your knowledge,
• See if there are any mining Rubi movements made without your knowledge.
A race is on, Rubi Network makes continuous updates and aggressively tracks, while the thieves also continuously create new wallets to continue stealing, hiding and quickly looking for ways to disperse the stolen assets. The race was fierce while most of the miners were sleeping and no one knew about it.
THIS IS THE 40 THIEVES?
After looking at the characteristics of this attack, they showed that this was not a single attack, but was carried out by many thieves, which is why I thought of the story of "40 Thieves". All the characteristics of the attack pointed to the fact that this was a common Phishing attack that had been quite popular in the past few years.
The thieves we found were mainly from Iraq, and when we traced them, we found many other thieves, we exclaimed humorously! "This is bad - we are dealing with the descendants of the famous thieves from the story of 40 Thieves".
These thieves carried out the theft in a coordinated manner with quick movements, professionalism and speed of ex*****on, showing that these are people with rich experience in the profession of theft.
There were indeed many of them, they acted very quickly, but so did our team! In a few days we quickly added the source code and did the tracking and found many "treasures" where they kept what they stole.
HOW THE THIEVES DO IT.
Did the thieves steal Rubies from your wallet? No, they did not attack your wallet, instead they tried to pe*****te the mining area to steal the mined Rubies that had not yet been transferred to the wallet. These thieves performed PHISHING attacks to gain access to your account, then they stole the mined RUBI that was lying outside your wallet.
And here is the sequence they did.
Step 1: They got your email and password in many ways and got access to your account
Step 2: They access the account and check the account status, see if it has been KYC'd, see if there is a balance outside?
Step 3: If you have been KYC'd and have a balance that has not been transferred to the wallet, they will go to the wallet creation section and create a new wallet (this wallet is controlled by the thief)
Step 4: They connect the newly created wallet to your account and then create a migration request for all the Rubies from the mining area to the new wallet.
Step 5: They then quickly transfer all the stolen coins to a wallet on another account that they control.
DAMAGE ESTIMATION
This is a bad attack on the Rubi Network, Phishing attacks are commonly known, attackers perform fraudulent activities to gain access to accounts and passwords, then gain access and steal. A typical attack like this happened in early 2024 when a group of young scammers scammed away $230 million worth of Bitcoin at the time.
Here are the estimated figures for the damage in the terrible attack by the "40 robbers" on Rubi!
• Hundreds of victims:
Based on what happened, the number of victims observed has reached several hundred victims and may continue to expand, with victims coming from many countries, including Nigeria, Vietnam, India, Indonesia, Pakistan and a few others.
• Dozens of attackers:
A few dozen direct attackers, and hundreds of people involved in supporting the hoarding and consumption, they create a complex network of movements that makes it difficult to trace.
• Number of stolen assets:
Based on known figures, the number of stolen Rubies could be more than 400,000 RBL, which is clearly a very serious number. However, the majority of the stolen Rubies are still in the wallets of the thieves, while another portion, up to hundreds of thousands of Rubies, is consumed by them through cheap dumping. We are really witnessing the lesson of history repeating itself, and it always repeats as part of the development.
• Countries with many victims:
Tracing data shows that the attackers are mainly from Iraq, but the victims come from all over the world. Tracing data shows that these are the countries most affected in this crisis: Vietnam, Nigeria, Pakistan, India, Indonesia, Bangladesh, Turkey, Philippines
IF YOU ARE A VICTIM!
Since the number of victims seen has reached hundreds, we consider this a serious crisis! Please check your account immediately and let us know if you are being attacked by Phishing! Providing more information will help us track down the issue faster and resolve the crisis sooner.
How to check:
Go to your account and check for any unusual signs:
• See if there are any new wallets created without your knowledge,
• See if there are any mining Rubies transferred without your knowledge.