Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: rushingfn on October 31, 2017, 10:49:45 AM



Title: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: rushingfn on October 31, 2017, 10:49:45 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: eckmar on October 31, 2017, 10:55:13 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: rushingfn on October 31, 2017, 10:59:13 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: mk4 on October 31, 2017, 11:02:08 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.

I'm pretty sure you're alot more likely to be easier to be hacked if you're using SMS authentication rather than Google's 2FA.

There's like a 90% chance that the problem is on your side and not Coinbase's. If Coinbase actually got hacked then the news should be spreading fast like wildfire. Any chance that you're using the same password in multiple websites? Also, definitely do a malware scan on your computer asap.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: nydiacaskey01 on October 31, 2017, 11:04:16 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.
So I guess what happened is you have 2FA activated but you ticked that box that asked you to never ask you again in 30 days for the same computer. Did you use a public computer? I don't tick that box that disables 2FA in 30 days. It beats the purpose of having 2FA security and again it's not a good idea to store your coins in an online wallet.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: mr_stark on October 31, 2017, 11:21:07 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.
I don't think it is possible to bypass 2FA or crack it. You should keep all the funds in vault and if keeping on exchange secure it by 2FA on login and withdrawal.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: bob123 on October 31, 2017, 11:55:31 AM
SMS 2FA is more vulnerable to spoofing than Google Authenticator.
But despite of any vulnerabilities.. you should never store coins longer than necessary on an exchange.
You should definetly run a full malware scan.
Do you have any clue how this happened? Did you already scan your pc for malware?
Did you logon from mobile phones? Or via hotspot? Did you always check you are on the official site? Also checked TLS encryption (https)?
If you have different passwords for coinbase and your email account and you never reused a password twice the chances that
you are infected with a trojan is very very high. In this case clean your PC, get a fresh OS and only then start storing
bitcoins (or login credentials to exchanges) on your pc again.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Jonsnowstark on October 31, 2017, 12:15:52 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

This is sad. I don't think coinbase is vulnerable though. Just a note, never keep your coins in an exchange site for too long. Secure your wallet address in a place where it cannot be easily stolen. I do 2fa for my accounts in exchange sites too and i never have problems with it. That's the best way to feel secure about my investments.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: amila_cs on October 31, 2017, 12:21:24 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

Everybody I know is saying not to store coins in Exchanges. But when you are into day trading, how do you manage that. Having coins in the exchange is pretty much easy to buy/sell in sudden market movements


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: farhaan on October 31, 2017, 12:27:51 PM
That's why it is always said not to store your bitcoins in exchange ever.We are already familiar wit Mt.Gox collapse.But even now,some newbies don't know about the seriousness of storing bitcoins in exchanges.

Always store in desktop wallets like Electrum which are safe and secure.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Baofeng on October 31, 2017, 12:28:03 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

Everybody I know is saying not to store coins in Exchanges. But when you are into day trading, how do you manage that. Having coins in the exchange is pretty much easy to buy/sell in sudden market movements

Oh well, hackers strikes again and I'm sorry for you lost. I think they found vulnerabilities in you. Vault is a good practice as well as Google Authenticator. We preached not to put a lot of bitcoin in a exchange because of the chances of a hack, so I also hope that what they took from you is just a small amount of bitcoins, used only for your day trading. I familiar with RAT virus or malware though, will try to research later so that I can prevent myself for being hack as well.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Hexah on October 31, 2017, 12:38:59 PM
It is not really recommended to keep your coins to an exchange because it's prone to hacking activities andany frauds, so, if you want to keep your coins store it on hardware wallets or if you don't have that one maybe you can use cold wallets for long term or hot wallets if you used your coins everyday. Online web wallets are not good wallets to keep your coins because it isn't a private one though, so better move to keep it on a cold, hardware and paper wallets for better security.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Priktrice on October 31, 2017, 12:59:38 PM
was able to login from my IP and was able to login to my email despite the fact that I had just changed my password.
You most likely have a rat (remote administrator tool) on your computer allowing that very hacker to see everything you do and type,  and also to remote control your computer as well as using his computer to browse from your ip address.  My guess is that he grabbed your login for your email and used a reverse proxy to login and change your info and take your btc.  I would recommend checking your computer for malware and also checking your startup entries. If that doesn't get rid of the hacker,  then you probably should just reset and keep only what you need.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: rifiuti on October 31, 2017, 01:04:53 PM
To OP and hodlers;

Get an USB
Install persistent ubuntu with Electrum
When you want to send some coins, reboot computer and plug USB and switch to Ubuntu
Don't connect the internet when USB is plugged
Broadcast the transaction
Reboot
Switch to Windows
Verify the transaction

I believe this would be the most secure way.

I'm sure this advice given thousand times but; If you can afford Bitcoin, you can afford a damn Trezor or Ledger Nano. Better safe than sorry.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: eagleman on October 31, 2017, 01:09:43 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

That's why I'm not going to store most of my bitcoin on an exchange because there's no perfect exchange. I just can't understand on how did the hacker was able to log in with your IP, are you exposing your details online or you are sharing someone with your internet? Did you reached out the coinbase support and asked to help you with your problem? You should ask them to help you since it's also a fault to their system until finding out that it's your fault.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Mahanton on October 31, 2017, 01:16:09 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.
Quiet odd that you didnt activate that sms verification. Ive been using coinbase and this security features ive been using which it do send codes into my mobile phone number  and then an email verification before you would able to log in completely.I suspect theres a RAT on your pc which the hacker did able to know all the credentials needed for accessing your account.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Lucius on October 31, 2017, 01:19:00 PM
Every day a new case of lost / stolen BTC from online,but also from desktop wallets tells us that people just do not stick to the most basic things when using computers and the internet.It does not matter do you keep BTC on online or desktop wallet if you let something bad to infects your PC,such is this RAT(remote access trojan).I agree that if you have a significant amount of coins hardware/paper wallet is something that simply must be used.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: bigboybitcoin on October 31, 2017, 01:28:03 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.
I think your 2fa was compromised some how.
Or if you have not enebled 2fa it was your fault.
Though i feel for your loss and pain .
In September i also lost 3000usd from poloniex even i have 2fa enabled there.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: JeffBrad12 on October 31, 2017, 01:28:20 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.
I just know about the coinbase has 2fa verification and why you are no using it. The possible thing about you were getting phishing. If the hacker be able to login into your email and that will be the end of the story.
Or another speculation about your computer got infected by ransom ware. Remember to not to publicly your email address that has used to store all of your data.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: tj4dmx on October 31, 2017, 01:30:48 PM
Basically,the hacking was possible by using a RAT !
Your security is already compromised !!

You need a fresh laptop or even maybe you can get a brand new laptop !!
Sorry bro.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: cipher-x_09 on October 31, 2017, 01:32:02 PM
Maybe your computer is filled with virus or many during transaction there might be open tab or links in your browser in which you accidentally  click into either way what's  done is done lesson learned you should never store your coins in coin bank during transactions.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: romecheo on October 31, 2017, 01:38:05 PM
That's the reason why exchange offers several combination of security for any transaction, to suppress any unauthorized transaction.

Beside password, we have to enable Two Factor Authentication, we can also set IP white listing, or Withdrawal white listing.

Remember when setting your password it should be a strong password, which a combination of Big and Small Letter, Numbers, special Characters and at least 25 to 30 characters long.

https://www.lifewire.com/strong-password-examples-2483118 (https://www.lifewire.com/strong-password-examples-2483118)  

and don't forget to tighten security of workstation.

OS updates, Anti-malware, browser protection.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Odora on October 31, 2017, 01:43:09 PM
how can , I still ask if you go to a fake site, I have an account in coinbase too,
I think coinbase is safe enough, it will be lesson for me to be more careful again .. :)


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: gesdan on October 31, 2017, 01:46:22 PM
my advice is dont tell anyone your password and email about bitcoin, second safe your password only on you mind or you can write it in paper with some code encryption, second check twice about the url that you visit is the link is valid or its a fake one


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: ahmedjamal1998 on October 31, 2017, 01:48:42 PM
Sorry to hear that mate. Hope it wasn't much but yes it was totally wrong to leave coins on an exchange.
Why would you do that ? Even if they weren't stolen, what if the exchange just goes down ? Or turns out to be scammy suddenly ?

Definitely not a good idea ! Your coins would be gone the same way they were. I've been saying this almost every single week. DON'T leave coins except in your own wallet and in an address that you have the private keys to saved somewhere safe.

the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

You changed your password recently and he could get it that easy ? Well, this suggests one thing only ! The thief hacked into your computer and must've installed some sort of key logger. Hacking stuff are crazy, he might have just used your computer (remote control) and send the coins (I guess you probably have your login info saved in the browser ? ) or even worse you got tricked into entering your login info into a fake phishing site that was sent to your email and you thought it's from them.

Plus don't they have 2fa ? If it exists and you didn't set it up, that's definitely a huge mistake.
Well, we learn from our mistakes but I guess this was a costly one.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Prodigan786 on October 31, 2017, 01:53:57 PM
Thanks for your experience but now a days we cant even trust ether wallet for holding tokens lots of hacks happening. But i dint heard about bitcoin wallet hacks. in my country its difficult to find hardware or cold wallet .


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: yamortsac on October 31, 2017, 02:03:37 PM
It feels sad and scary to know about that what happened but thank you for sharing this because this will be a warning for us to be more secure in our wallet. I learned a lesson from this.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: cammie16 on October 31, 2017, 02:09:00 PM
That's why it is always said not to store your bitcoins in exchange ever.We are already familiar wit Mt.Gox collapse.But even now,some newbies don't know about the seriousness of storing bitcoins in exchanges.

Always store in desktop wallets like Electrum which are safe and secure.

I have some bitcoins in an exchange, now Im planning it to withdraw. I used electrum once so maybe I should use a desktop wallet now.
Anyway, Sorry to hear about what happened to OP. Next time just add more securities to all your wallets.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: mashort on October 31, 2017, 03:39:56 PM
 what is your opinion of mycellium wallet. is it safe?


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Svelto on October 31, 2017, 05:03:22 PM
OP, sorry for your losses. You really have to stop using exchanges.


what is your opinion of mycellium wallet. is it safe?

Getting a hardware wallet will be safer. Since you are storing BTC which is valuable, get a hardware wallet under $100 to safeguard your BTC and Altcoins. Treat it as an insurance or something. Hardware wallet is definitely worth the money.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: rushingfn on October 31, 2017, 05:09:01 PM
To answer some questions: This does appear to have been caused by malware. Which I've cleaned up

The vulnerability is that anyone could mask your IP and do a forgotten password exploit. This guy was able to loginto my email and clicked the link from there. Apparently there is no 2 step authentication when logging in after a new password is created. He was able to drain my hot wallet despite me replying to the text and via email that I did not change my password.

I did not keep myself off 2fa authentication for 30 days.

I have not heard too much from coinbase and I am worried that this vulnerability. I figure that this is a loss.

I am however keeping on the sunny side as I have still not lost any money in bicoin despite the theft.

Be careful out there.  


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: bitjoin on October 31, 2017, 05:12:32 PM

I find it hard to understand why coinbase would have it so if you reset your password there is no 2FA?  Most other exchanges block you from doing stuff after a password reset not lessen your security and give you more freedom. Never used coinbase so dont know.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: mobilazy on October 31, 2017, 05:30:01 PM
Sorry to hear it. You taught me a valuable lesson. I assumed that exchanges as Coinbase are quite safe.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: posternat on October 31, 2017, 05:54:05 PM
Its so sad. That's the reason why i suggest people to use hardware wallet instead online wallets. Now days its easy to hack everything. Hackers are now more cleaver than before. Anyways people learn from his mistake you should not store your bitcoin in exchange. Again i suggest you to use hardware wallet like Ledger Nano S


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: bitorama on October 31, 2017, 05:54:33 PM
it's safer to keep coins in the cold wallet or hardware wallet


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Lampaster on October 31, 2017, 06:07:24 PM
I never keep coins for a long time in the account on the exchange. I go translate the coins just before exchange to Fiat. After the exchange, I immediately transfer money to a Bank card. If transaction cost would be below these problems could have been avoided. The time of the transaction must also be reduced to a minimum.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Frank0209 on October 31, 2017, 06:08:13 PM
Its so sad. That's the reason why i suggest people to use hardware wallet instead online wallets. Now days its easy to hack everything. Hackers are now more cleaver than before. Anyways people learn from his mistake you should not store your bitcoin in exchange. Again i suggest you to use hardware wallet like Ledger Nano S

I agree with you but I'm still curious that there are a lot of topic like "which wallet should I use?", "How to keep my Bitcoin safe?", "Which is the best wallet?".....so many topics like that in here but I think people just want to ask but they don't really care about other opinion and experience :)). They received a lot of good advices that they only should use Off wallet and Coldstorage wallet but they still use web wallet or exchanges.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: jagdeepjd on October 31, 2017, 06:14:22 PM
This is sad i am also using coinbase and have the sms authentication it asks for sms before withdraw. After your incident i may think of transferring my coins to some other wallet.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Crypdon on October 31, 2017, 06:22:32 PM
Not sure how it can be possible. Even sh*t exchanges like nova will send an email to your account asking you to confirm the withdrawal. Why is this not done on coinbase?


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: athanz88 on October 31, 2017, 06:24:36 PM
Okay this is some serious issue, and i am really sorry for your trouble. But even when you lose, you still can share this wonderful knowledge to all of us.
So, i learn some things.
1. Exchange is some website or smartphone app wallet
2. Hard wallet is like a usb device that store all your coin in it and it is safer because it has some extra protection.
3. Do not store bitcoin long enough in an exchange app

So for me, who does not have hard wallet, i guess it is better if every time i get bitcoin i will directly trade it to fiat currency? Or do you guys have any idea and experience on how to keep bitcoin safely without hard wallet? Please do tell us, share some knowledge.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: bitjoin on October 31, 2017, 07:00:27 PM
Not sure how it can be possible. Even sh*t exchanges like nova will send an email to your account asking you to confirm the withdrawal. Why is this not done on coinbase?

Kraken sends an email but its not a click to confirm withdraw one etc.  It just tells you withdraw is happening and to stop into you have o take action. What they do though is not allow any withdraw address to be added unless confirmed via email.  The OP is saying his email got hacked though so would not have saved him.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: marckenigsberg on November 01, 2017, 08:25:12 AM
Sorry to hear about this, no matter how it happened, it hurts.
As said even with RAT your 2FA should have stopped the login.
Trading requires some coins to be on an exchange but you should only keep what you're actively trading.
If someone is concerned about the technical of using ubuntu etc then just get a trezor.
It's a great level of security that's easy to use


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: nextel on November 01, 2017, 08:50:52 AM
There are plenty of ways to secure wallets and keys. It's jist that you're too confident on storing your coins in exchange. After buying or selling, you better pull or widthraw everything.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: taxmanmt5 on November 07, 2017, 05:48:30 PM
Sorry to hear about this, no matter how it happened, it hurts.
As said even with RAT your 2FA should have stopped the login.
Trading requires some coins to be on an exchange but you should only keep what you're actively trading.
If someone is concerned about the technical of using ubuntu etc then just get a trezor.
It's a great level of security that's easy to use


I feel so sad. Its your shocking story. I know how you struggle hard to earn these bitcoin and at the end someone stole it. I think you learn something from it. You should not use the online wallet. Try to use hardware wallet instead of Software Wallets. Hardware wallets are bit expensive to maybe you should try Software you can download it from internet.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: reflector on November 07, 2017, 05:57:28 PM
Sorry to hear about this, no matter how it happened, it hurts.
As said even with RAT your 2FA should have stopped the login.
Trading requires some coins to be on an exchange but you should only keep what you're actively trading.
If someone is concerned about the technical of using ubuntu etc then just get a trezor.
It's a great level of security that's easy to use


I feel so sad. Its your shocking story. I know how you struggle hard to earn these bitcoin and at the end someone stole it. I think you learn something from it. You should not use the online wallet. Try to use hardware wallet instead of Software Wallets. Hardware wallets are bit expensive to maybe you should try Software you can download it from internet.

That does not need dude. If you keep on checking your wallet and having the e-mail security with the two factor authentication means you can use the exchange or online wallet. Nothing will cause a problem to you.
Maximum you can have desktop wallet which is easy accessible and can use it any time and keep your private key and wallet seed from others.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: player514 on November 07, 2017, 05:59:50 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I second this idea. Sounds like a RAT attack to me. There's no way some random person can quickly know an IP and mask theirs as the slave IP. Chances are that the person sent you some adware or you stumbled on a bad file that gave path to someone's RAT. Be very careful with what you download on the internet nowadays. People will come at a few coins with whatever they have. Bitcoin offers no security to you even if you do get scammed or robbed.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: iamsange on November 07, 2017, 06:11:41 PM
Okay this is some serious issue, and i am really sorry for your trouble. But even when you lose, you still can share this wonderful knowledge to all of us.
So, i learn some things.
1. Exchange is some website or smartphone app wallet
2. Hard wallet is like a usb device that store all your coin in it and it is safer because it has some extra protection.
3. Do not store bitcoin long enough in an exchange app

So for me, who does not have hard wallet, i guess it is better if every time i get bitcoin i will directly trade it to fiat currency? Or do you guys have any idea and experience on how to keep bitcoin safely without hard wallet? Please do tell us, share some knowledge.
if you not want to hold your coins maybe it is better to do that, i always sell my coins and left around 0.05-0.1 in my local exchanger wallet.the reason is same with everyone maybe. i afraid if get hacked


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: nexus2k14 on November 07, 2017, 10:36:05 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

Sorry to hear bad news like this. I don't understand why you didn't enable 2-factor authentication? You should enable on any website that supports it for example (Amazon, NiceHash, LocalBitcoins, Gmail and all exchanges that support 2FA) Ebay don't have 2FA but if they do I will enable too.

Next time you will know, it's not safe to keep BTC or ETH or any other crypto on exchange, one day even most trusted exchange can be in troubles (like BTC-e)

We all make mistakes, and it doesn't matter if you the newbie or experienced user. I was in hurry and transferred eth to another exchange into other Token address, theoretically, I lost my Etereum but I contacted this exchange and after mentioning I will leave negative feedback on forum and Trust Review website I had another reply from Tech support that they will check for me and get them back, exchange fixed this for me, even they state Tokes send to wrong address are lost.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: iluvpie60 on November 07, 2017, 10:47:19 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

Are you able to file something with coinbase to let them know that you were hacked?

Is there any chance that you weren't really hacked but instead what happened was that someone you know or has access to your computer might have done this?

Does anyone else know your password to your PC and or phone??? Do you share a computer?


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: finzyoj on November 07, 2017, 10:50:22 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

Your lose gives lesson to everyone specially to those who are new in this. Everyone learns from mistakes. There are lot of theft and hacker around the globe and it is hard to find which security is good to use so they cannot enter in such way. It is better to not leave the money in any transaction site specially if it is big amount because it is hot in the eye on the theft.  


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Sadlife on November 07, 2017, 10:59:16 PM
Most likely is that coinbase is not at fault here their security seems good so the only way for hackers to breach your account and access your email is some kind a remote access tool that infected your computer and got all your credentials then spoof your IP that's why he was able to hack the 2FA.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: grermezter on November 07, 2017, 11:01:38 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.
It's never a good idea to keep your money in exchanges especially when they are being hacked all the time. I thought you would have had more stringent security measures in place to prevent these kind of this like a 2FA security which makes it a bit harder for hackers to gain access into your account.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: drm on November 07, 2017, 11:03:50 PM
Besides 2fa, lot's of exchanges disable withdrawal for 24 hours after changing credentials.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: DAVETUN on November 07, 2017, 11:14:25 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.


This is quite sad,scammers and hackers on the move daily,reason whu caution has to be the watch word, I do not respond to message that has to do with change of password
Coinbae need to strengthen there site against intruderd


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Sebas.tian on November 09, 2017, 10:44:40 AM
Having coins on exchanges is like putting your money in a not-so-hard glass case--it barely has protection and can be destroyed anytime. I myself have learned this lesson the hard way and from then on, I don't care how paranoid people might think I am because in reality you'll wont think hacking is possible until it happens to you.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Cryptoshaft on November 09, 2017, 10:48:29 AM
To OP and hodlers;

Get an USB
Install persistent ubuntu with Electrum
When you want to send some coins, reboot computer and plug USB and switch to Ubuntu
Don't connect the internet when USB is plugged
Broadcast the transaction
Reboot
Switch to Windows
Verify the transaction

I believe this would be the most secure way.

I'm sure this advice given thousand times but; If you can afford Bitcoin, you can afford a damn Trezor or Ledger Nano. Better safe than sorry.

really much hassle but really really safe way.
i thought that 2FA is more than enough, but i can't think of where did the OP miss


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: ruthbabe on November 09, 2017, 11:07:50 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

If you have a lot of coins in coinbase that amounted to hundreds or thousands of dollars, I would suggest you buy TREZOR or Ledger Nano and transfer a big part your coins there.



Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: roshanface123 on November 09, 2017, 11:11:19 AM
I am sorry for your loss and also thanks for your information i am quit new to crypto currency trading i started trading some altcoins in different exchanges and keep them in exchanges by believing exchanges are safe now i am not keeping any of my holding in exchanges.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Virtual miner on November 09, 2017, 11:13:46 AM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

It's never a good idea to store coins on exchange. However I doubt Coinbase has serious vulnerabilities. What happened is that you most likely got infected with a RAT. Its not a problem for the hacker to log in with your IP and your email really. Ways to prevent this is usage of 2FA

I do use 2FA. I need google authenticator every login. I wish it would have been SMS. I'm not sure how this happened. I just wish I would have kept more of them in a vault, or sold my hot wallet contents earlier.
Yes quite astonished to see that people dont use 2FA. I have kept my exchange accounts safe with 2FA but I am not quite sure how is the new number patched every minute. I mean is there a unique number for my mobile's IMEI number or for my gmail account because if its for gmail account then its not much safe. Moreover I have always been against keeping your coins on exchange it isnt much surprising if coinbase themselves might have hacked your account.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Rosberger on November 09, 2017, 11:17:51 AM
I think coinbase is safe and that you are infected. Could it be that you were downloading things from the internet ? Always use more than 3 virus scanners for more safety.

Don't click on links that somebody just gave you. You need to check the url search it on google for example.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: nydiacaskey01 on November 09, 2017, 11:45:53 AM
If your BTC wallet was hacked, its not the fault of coinbase because they have all bases covered from 2fa to suggesting a strong password. You also need to do your part by changing your password from time to time and not using a password that is very common like your date of birth and don't click any links sent you via private message or not ever.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: trk on November 09, 2017, 12:44:10 PM
That's why I installed 2FA for all my email, because I save private information in it
The only concern for now is MEW which is currently only secured by Pv Key without additional protection, hope they will add 2FA soon


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: intelligentdude on November 09, 2017, 01:04:45 PM
Sorry about your loss. I concur with you,it is best to store your coins in a cold wallet.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Sachinist on November 09, 2017, 01:12:03 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

Coinbase is a joke but they're not at fault here. No 2FA means you leave yourself vulnerable.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: squallw on November 09, 2017, 02:32:51 PM
Its bad idea to use exchange instead your wallet, you must store your balance in a secure wallet that you can have the control.

Some exchanges like Bittrex, you need to confirm if you have access to another IP, it is more secure, even if you compromised your password and did not have 2FA active, the thief would't access your account.

Anyway 2FA should be mandatory if you cares about your security.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Rrita on November 09, 2017, 02:40:48 PM
I am user of coinbase wallet about 2 years ago.Till now not faced such kind of situation.I am using mobile number verification and email verification for preventing hack.Its a good way to kept safe my wallet from hack.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: kriticko29 on November 09, 2017, 02:44:34 PM
Well i guess you were opening different sites. Mostly hackers encryps hacking codes in pop-ups and then gather your account informations. Be safe next time ! Been there done that !


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: ninabobo on November 09, 2017, 02:59:20 PM
My coinbase got hacked today. I got a message on my phone saying that my password had changed. I attempted to follow instructions to stop it, but by the time I had, it was too late and the theif emptied out my hot wallet. The only saving grace was that coinbase has vaults which give 48 hour delay. I wish that I would have transferred more coins to the vault as they were protected. Coinbase has some serious vulnerabilities, but whoever the thief was was able to login from my IP and was able to login to my email despite the fact that I had just changed my password. Be careful out there. Cold wallet your coins.

I think someone knows with you. how could she get on your phone. I think it's planned, maybe your tokens are so many, so you are a target for those who want to plan on stealing your wallet.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Pan Troglodytes on November 09, 2017, 03:48:32 PM
I don't know how to safely day trade - you have to trust the exchange in the end - and this is why even if I can see a price change that I know is the opportunity to buy or sell, I simply keep a low profile, hold to my bitcoins and wait through the price change. This is not the most rewarding strategy, but much much safer. I had my money in a cold wallet and now I am testing a hardware wallet, both are secure I think.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Pan Troglodytes on November 09, 2017, 03:56:20 PM
Oh, it occured to me the moment I posted the last reply - there is this functionality in some of the hardware wallets, they provide 2FA using built in private keys. The device is separated from the computer and the phone, so probably it is unhackable (?). You could read about it and maybe use it in the future. That will not bring your funds back, but maybe it will secure your future funds. I have never used it so you must do your own research.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: ice18 on November 11, 2017, 08:33:51 AM
We must learn this as a lesson from another user do not store your hard earned bitcoins on an online exchange wallet for a long time use a desktop wallet instead phising site is everywhere hacking is everywhere so we must always aware of official websites of this exchanges check first if https encryption is present in the beginning of every web address always bookmarked it on your favorite browser beware of look a like sites your system might be compromised.   


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: mondobitcoin on November 11, 2017, 08:41:04 AM
An online wallet is never safe, the better thing is to use an offline wallet, stored in a computer used only for that
And an exchange wallet is worse than all, because they can disappear with your money


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: Nasty23 on November 11, 2017, 08:53:04 AM
We must learn this as a lesson from another user do not store your hard earned bitcoins on an online exchange wallet for a long time use a desktop wallet instead phising site is everywhere hacking is everywhere so we must always aware of official websites of this exchanges check first if https encryption is present in the beginning of every web address always bookmarked it on your favorite browser beware of look a like sites your system might be compromised.   
Yes we should not store our bitcoins in the online wallet because there are many scammers and hackers now that are wanted to steal bitcoin for their own wants without knowing the other emotion if they steal it. Online wallet can now be hacked by a different way but the most popular now is using the phishing sites that can get our all login information in the site.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: guoyu78 on November 13, 2017, 02:38:42 PM
If your BTC wallet was hacked, its not the fault of coinbase because they have all bases covered from 2fa to suggesting a strong password. You also need to do your part by changing your password from time to time and not using a password that is very common like your date of birth and don't click any links sent you via private message or not ever.
This is the reality why the bitcoin is being use and the why the bitcoin is helping all the people as you are aware of the bitcoin wallets that the bitcoin has the a lot of the wallet and the payment through the bitcoin wallet is now the way of the profit and the income indeed I am aware of it that as much the bitcoin getting wide the bitcoin is getting expensive so according to me the bitcoin is really good to invest on time.


Title: Re: Got hacked and robbed. My mistake for keeping coins on exchange
Post by: BitcoinCommodor on November 15, 2017, 02:17:10 PM
That's why I installed 2FA for all my email, because I save private information in it
The only concern for now is MEW which is currently only secured by Pv Key without additional protection, hope they will add 2FA soon
Use the precautionary measure to save your capital from the dark web monsters and I also apply a lot for security protocols to save my personal information from the hackers and as there are a lot of people around me who are complaining same thing this is not the fault of bitcoin this is totally fault for the user that he must have to secure his asset and as you have so precious coin then apply security to save it man.