Overstock cryptocurrency flaw muddles bitcoin payments and refunds | finder.com

Overstock cryptocurrency flaw muddles bitcoin payments and refunds

Peter Terlato 10 January 2018 NEWS

The payments bug, accepting bitcoin and Bitcoin Cash as equivalent payments, was active for three weeks.

American online retailer Overstock recently suffered a cryptocurrency payments bug that severely impacted the cost of purchases and allowed some customers to claim refunds at a significantly higher rate of return.

In a blog post this week on KrebsOnSecurity, journalist Brian Krebs said he was contacted by computer security firm Bancsec’s chief executive JB Snyder. The cybersecurity expert told Krebs that last week, when attempting to purchase an item on Overstock using digital currency, he realized the site was accepting both bitcoin and Bitcoin Cash as equivalent payments, despite the vast differences in their individual values.

For example, bitcoin (BTC) is currently worth around $14,500 per unit, while Bitcoin Cash (BCH) is valued at approximately $2,600, less than one fifth (18%) of the price. See the chart below for live valuations.

Confirming the issue, KrebsOnSecurity purchased three outdoor solar lamps from Overstock at US$78.27. Krebs indicated he wished to make the purchase using bitcoin and Overstock sent an invoice for 0.00475574 bitcoins. Using digital currency exchange Coinbase, Krebs paid the total in bitcoin cash, rather than bitcoin.

Overstock approved the payment and sent Krebs an email confirming that the items would be shipped shortly.

“I had just made a US$78 purchase by sending approximately US$12 worth of bitcoin cash,” Krebs said.

However, when Krebs attempted to return the lamps for a refund, Overstock sent him US$78.27 (the original purchase price) worth of bitcoins, instead of the US$12 in bitcoin cash he actually used for the transaction.

When contacted for comment, Overstock informed KrebsOnSecurity that “a fix implemented by Coinbase” had resolved the issue and that the internet retailer hadn’t changed any actual code on its shopping website. Cryptocurrency payments on Overstock’s site were temporarily disabled but have since been restored.

Coinbase said the issue was brought about by its “merchant partner improperly using the return values in our merchant integration API”. The digital currency exchange website said no other customers had this problem.

“To our knowledge, a very small number of transactions were impacted by this issue,” Coinbase said.

Coinbase told KrebsOnSecurity that the payments flaw was active on Overstock for approximately three weeks.

A number of big businesses have debated the use of cryptocurrencies as a result of their price volatility.
Microsoft briefly ceased accepting bitcoin as a payment method earlier this week but has since restored this option. Entertainment and gaming platform Steam announced in December last year that it would no longer support bitcoin payments, given the cryptocurrency’s unreliable value and inherently high processing fees.

Additionally, several prepaid cryptocurrency debit card providers have had their services suspended by Visa.

Cryptocurrency exchange Binance lifted its temporary ban on new user accounts this week after experiencing a recent surge in popularity. However, only a limited number of new registrations will be permitted each day.

Discover the difference between bitcoin and Bitcoin Cash and learn more about various cryptocurrencies.

Disclaimer: This information should not be interpreted as an endorsement of cryptocurrency or any specific provider, service or offering. It is not a recommendation to trade. Cryptocurrencies are speculative, complex and involve significant risks – they are highly volatile and sensitive to secondary activity. Performance is unpredictable and past performance is no guarantee of future performance. Consider your own circumstances, and obtain your own advice, before relying on this information. You should also verify the nature of any product or service (including its legal status and relevant regulatory requirements) and consult the relevant Regulators' websites before making any decision. Finder, or the author, may have holdings in the cryptocurrencies discussed.

Latest news headlines

Picture: Shutterstock

Ask an Expert

You are about to post a question on finder.com:

  • Do not enter personal information (eg. surname, phone number, bank details) as your question will be made public
  • finder.com is a financial comparison and information service, not a bank or product provider
  • We cannot provide you with personal advice or recommendations
  • Your answer might already be waiting – check previous questions below to see if yours has already been asked

Finder only provides general advice and factual information, so consider your own circumstances, or seek advice before you decide to act on our content. By submitting a question, you're accepting our Terms and Conditions and Privacy Policy.
Go to site