Bitcoin Forum

Other => Beginners & Help => Topic started by: cryptolaxy on September 01, 2013, 09:50:53 AM



Title: Suprise
Post by: cryptolaxy on September 01, 2013, 09:50:53 AM
this is the best bitcoin forum i have come across.

i just have an issue which i will really much appreciate your inputs. my blockchain.info account got hacked today and 9btc was stolen from my account. i had set up sms two factor authentication on my account and i also disabled tor login. i also setup a secondary password. i just couldnt understand how my account got hacked and my coins stolen. does this mean that sms two factor authentication isn't as secure as it seems?


Title: Re: Suprise
Post by: Deathwing on September 01, 2013, 09:58:25 AM
Maybe you forgot to enable the SMS option.


Title: Re: Suprise
Post by: Boukefalos on September 01, 2013, 10:02:09 AM
It could be that your pc is compromised. Check for viruses or spyware using a descent antivirus tool (I use Avast Free Antivirus). In the worst case scenario, an attacker might have gotten access to your backup password. I recommend that you take precautions before you open a new account!


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:05:20 AM
Maybe you forgot to enable the SMS option.

SMS option was enabled because I made a few transactions and each time I login I always get the SMS code.


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:14:51 AM
It could be that your pc is compromised. Check for viruses or spyware using a descent antivirus tool (I use Avast Free Antivirus). In the worst case scenario, an attacker might have gotten access to your backup password. I recommend that you take precautions before you open a new account!

If my pc was compromised, does that mean my phone was compromised also?


Title: Re: Suprise
Post by: marcovaldo on September 01, 2013, 10:15:12 AM
You can send a pm to piuk.
It is very strange if you have a SMS alert and still, you got hacked.


Maybe you gave the private key of the address to someone and it has nothing to do with blokchchain.info?
Or maybe you did the transfer and don't remember it?


You should not be able to bypass double authen


Title: Re: Suprise
Post by: favdesu on September 01, 2013, 10:16:42 AM
best thing would be to send the support an email and let him check it.

where do you keep the wallet backup?


Title: Re: Suprise
Post by: b!z on September 01, 2013, 10:19:11 AM
Did you generate your wallet on android? Some pc browsers also created weak addresses that were hacked. Do some searching to see if your address was on the list.

You should also think about whether or not your phone has malware installed. If it doesn't have spyware, then was the SMS intercepted?


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:21:17 AM
You can send a pm to piuk.
It is very strange if you have a SMS alert and still, you got hacked.


Maybe you gave the private key of the address to someone and it has nothing to do with blokchchain.info?
Or maybe you did the transfer and don't remember it?


You should not be able to bypass double authen

I don't even know how to find my private key on blockchain.info, so I couldn't have given it out to anyone. Also it's not possible i send a transaction and not remember it. My wallet was wiped clean.


Title: Re: Suprise
Post by: marcovaldo on September 01, 2013, 10:22:39 AM
What is the link of the address?


Title: Re: Suprise
Post by: favdesu on September 01, 2013, 10:29:03 AM
Hmm that seems a rather unlikely event. He would need to compromise both your pc and phone.
Have you contacted support?

no need for sms if attacker got the wallet backup and phished the unlock password.


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:29:47 AM
What is the link of the address?
https://blockchain.info/tx/b193b63265225d3477639ff465baded76536576249774bf0f8fdc3d94cb105b3


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:35:59 AM
Hmm that seems a rather unlikely event. He would need to compromise both your pc and phone.
Have you contacted support?


i havent contacted support. i just thought since bitcoins transactions are irreversible, there is little or nothing support can do to recover my coins.


Title: Re: Suprise
Post by: marcovaldo on September 01, 2013, 10:40:56 AM
So I guess that your address is     1HuDSbSCtcDBx4MPmSqTZr2CPgDUEPkVoQ

I see a - 4 btc transaction, just 20 min before the -9.
Did you do this one?

Maybe the double authentification is valid for a period of time.


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:42:00 AM
Hmm that seems a rather unlikely event. He would need to compromise both your pc and phone.
Have you contacted support?

no need for sms if attacker got the wallet backup and phished the unlock password.

My wallet backup gets delivered to my hotmail email account. And my hotmail email account also has two factor authentication. It baffles me.


Title: Re: Suprise
Post by: favdesu on September 01, 2013, 10:46:04 AM
Hmm that seems a rather unlikely event. He would need to compromise both your pc and phone.
Have you contacted support?

no need for sms if attacker got the wallet backup and phished the unlock password.

My wallet backup gets delivered to my hotmail email account. And my hotmail email account also has two factor authentication. It baffles me.
so
mh yeah, just checked my blockhain.info settings. you can even export the unencrypted private keys with the password/s alone. so basically anyone with access to your pc / method to catch you password could easily wipe your account


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:48:24 AM
So I guess that your address is     1HuDSbSCtcDBx4MPmSqTZr2CPgDUEPkVoQ

I see a - 4 btc transaction, just 20 min before the -9.
Did you do this one?

Maybe the double authentification is valid for a period of time.

Yes that is my wallet address. And yes I made the 4btc transaction.


Title: Re: Suprise
Post by: marcovaldo on September 01, 2013, 10:49:58 AM
Yes that is my wallet address. And yes I made the 4btc transaction.


I think that you only need to have the double authen for logging in the wallet, so your computer might have been compromised and they got a cookie or something from you that allowed them to do the second transaction right after the first one.


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 10:54:56 AM
So I guess that your address is     1HuDSbSCtcDBx4MPmSqTZr2CPgDUEPkVoQ

I see a - 4 btc transaction, just 20 min before the -9.
Did you do this one?

Maybe the double authentification is valid for a period of time.

Yes that is my wallet address. And yes I made the 4btc transaction.

After I sent the 4btc transaction, I logged out of my wallet, then I got an email from blockchain saying they blocked an attempted tor login. Minutes after the email I got the SMS of 9btc transfer.


Title: Re: Suprise
Post by: cryptolaxy on September 01, 2013, 11:44:38 AM
i just changed my two factor from sms to google authenticator. could this be a step in the right direction?


Title: Re: Suprise
Post by: marcovaldo on September 01, 2013, 12:05:16 PM
i just changed my two factor from sms to google authenticator. could this be a step in the right direction?

I don't see why it will be more secure than SMS to your personal phone.
Did you send a pm to piuk to check how they could bypass 2 authen?