Bitcoin Forum

Economy => Service Discussion => Topic started by: gmaxwell on March 28, 2013, 07:40:22 AM



Title: random person on irc reports strongcoin compromised
Post by: gmaxwell on March 28, 2013, 07:40:22 AM
For your consideration, #bitcoin on freenode (times US Pacific):

00:04 -!- R0x0rMcpwnage [~damiya@cpe-98-149-168-77.socal.res.rr.com] has joined #bitcoin
00:04 < R0x0rMcpwnage> hello friends this is a helpful announcement about strongcoin.com . If you use it, you should stop.
00:04 < R0x0rMcpwnage> 'why?' you ask?
00:04 < R0x0rMcpwnage> good question
00:04 < R0x0rMcpwnage> http://pastie.org/7147005
00:05 < R0x0rMcpwnage> it's a pastie, dude.
00:05 < R0x0rMcpwnage> http://pastie.org/7147015
00:06 < R0x0rMcpwnage> anyways that was just a helpful warning about strongcoin remove it or don't ;)

I have not verified the veracity of the claims.


Title: Re: random person on irc reports strongcoin compromised
Post by: rme on March 28, 2013, 07:53:12 AM
Seems that the labels of the addresses have been leaked.
The labels are not a great leak.


Title: Re: random person on irc reports strongcoin compromised
Post by: repentance on March 28, 2013, 08:28:06 AM
Might as well check the veracity of this while you're at it.

Quote
StrongCoin's wallet hint is
Car reg Corsa then Triumph, sperated by 3 dollars. Caps for 1st letters of car reg




Title: Re: random person on irc reports strongcoin compromised
Post by: eyci on March 29, 2013, 10:17:34 AM
This just appeared on reddit:

Quote
So I just got home and checked by BTC balance on my strongcoin account. I had the page open already in my browser and I just wanted to see the balance update with the latest $ value. Balance went from around 17 BTC to zero. I feel pretty gutted and am struggling to fiure out how it happened and feeling really foolish as I am an IT professional and know about security, using SSL, encrypted VPN etc.
Anyone here have experience with strongcoin able to help me figure out the transaction history of my account? It doesn't seem to make sense, my public address for the account is listed as the recipient whether its a deposit or withdrawal and there are multiple recipient addresses lisrted in some transactions with the final withdrawal (the theft that cleaned me out) there are several including mine. I'm pretty confused.

http://www.reddit.com/r/Bitcoin/comments/1b8gir/strongcoin_account_hackedcleaned_out/


Title: Re: random person on irc reports strongcoin compromised
Post by: pikeadz on March 29, 2013, 10:43:38 AM
I am curious how strongcoin addresses this.  It could always be someone trying to spread FUD, but if this guy's legit, well, at a minimum, they need to take down the "The Safest Way to Store Bitcoins!" sign on their page.


Title: Re: random person on irc reports strongcoin compromised
Post by: dogisland on March 29, 2013, 12:27:33 PM
We're looking at this now.


Title: Re: random person on irc reports strongcoin compromised
Post by: foo on March 30, 2013, 08:34:02 AM
We're looking at this now.

...and? Looks quite embarrassing.


Title: Re: random person on irc reports strongcoin compromised
Post by: Technomage on March 30, 2013, 12:07:49 PM
This is for real btw. If you have bitcoins at Strongcoin and the password and/or the hint isn't strong, odds are that the coins are already gone. I'm aware of many thefts relating to this.


Title: Re: random person on irc reports strongcoin compromised
Post by: MPOE-PR on April 02, 2013, 12:04:52 PM
Somebody was pasting passwords into MPEx' submit field earlier, they look like this list.

If you're using the same pw other places please change it now, it's likely the attacker will try all BTC services.