Bitcoin Forum

Economy => Service Discussion => Topic started by: byter on October 11, 2013, 07:55:42 AM



Title: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 07:55:42 AM
Hello,

All my bitcoins are gone from my bitcoin address... Received an e-mail 10 minute ago here:

Transaction reference: 27fb49c7-72d4-4e88-9bb0-d2646d403e97
Date: 2013-10-11 07:43:40 GMT
IP: 209.21.68.151

How is that even possible? I have a very strong password and no viruses... Can't be true!

The IP is in California and I am in Switzerland. Jeez....


Title: Re: MtGox stealing my BTCs?
Post by: Kluge on October 11, 2013, 08:01:12 AM
Perhaps the credentials of your email account or password manager are compromised?


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 08:04:57 AM
I thought about that, but would be strange that the guy doesn't even change the password afterwards... And where would he have found my e-mail address?

That's too much to be true...


Title: Re: MtGox stealing my BTCs?
Post by: Kluge on October 11, 2013, 08:08:51 AM
I thought about that, but would be strange that the guy doesn't even change the password afterwards... And where would he have found my e-mail address?

That's too much to be true...
Email provider should let you check last few IP addresses which accessed your account so you can double-check. (Usually in a "tools" or sometimes "settings" tab - though with smaller providers, you' may have to email support)


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 08:22:33 AM
No connections whatsoever outside of Switzerland...


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 08:27:35 AM
And I guess that MtGox will just tell me that it's my fault of course...


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 08:28:35 AM
By the way, it was sent to: 155SfFNjcqVZdoHDM6M3uR1hSjJtuW3xRf

If anyone can help finding back the guy, I'll reward!


Title: Re: MtGox stealing my BTCs?
Post by: TheButterZone on October 11, 2013, 08:36:00 AM
Well, it's not the first time it's been used... http://blockchain.info/address/155SfFNjcqVZdoHDM6M3uR1hSjJtuW3xRf

If I were MtGox, I'd log the accounts and IPs trying to withdraw to that address, and try to alert the account owners directly before the withdrawals are allowed to execute.


Title: Re: MtGox stealing my BTCs?
Post by: greyhawk on October 11, 2013, 08:38:30 AM
Let me guess. No 2FA?

no viruses...

How would you even know that?


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 09:01:22 AM
Let me guess. No 2FA?

no viruses...

How would you even know that?

Because I ran a full check with 4 different anti malware / anti virus tools?


Title: Re: MtGox stealing my BTCs?
Post by: greyhawk on October 11, 2013, 09:15:24 AM
Let me guess. No 2FA?

no viruses...

How would you even know that?

Because I ran a full check with 4 different anti malware / anti virus tools?

That would only protect you from common threats, which the highly specialiced trojans/keyloggers out for bitcoin exchange login data most definitely are not.

The only way to confidently deny the presence of bitcoin malware is if you'd exclusively accessed exchanges via a fresh and clean VM.


Title: Re: MtGox stealing my BTCs?
Post by: viboracecata on October 11, 2013, 09:23:29 AM
Let me guess. No 2FA?

no viruses...

How would you even know that?

Because I ran a full check with 4 different anti malware / anti virus tools?

antivirus tools can not kill the real cracker's backdoors, your PC using habit is the best safeguard for you private information


Title: Re: MtGox stealing my BTCs?
Post by: posormo on October 11, 2013, 12:42:46 PM
Their stealing their money because your to stupid to secure your shit?  Interesting.   How many btc were taken?  Was your password 1234?


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 11, 2013, 12:59:03 PM
Their stealing their money because your to stupid to secure your shit?  Interesting.   How many btc were taken?  Was your password 1234?

No, I have a strong password. 3 BTCs were taken... Not that much but hey, that sucks...


Title: Re: MtGox stealing my BTCs?
Post by: posormo on October 11, 2013, 02:54:23 PM
Their stealing their money because your to stupid to secure your shit?  Interesting.   How many btc were taken?  Was your password 1234?

No, I have a strong password. 3 BTCs were taken... Not that much but hey, that sucks...

oh, you have a strong password.  that is all you have to say?  now I know its your own fault and not theirs.  typical end user.  ya, they are going to risk it all to steal 3 btc from you.   change the thread title to I don't understand how to use a computer, game over.


Title: Re: MtGox stealing my BTCs?
Post by: byter on October 16, 2013, 11:12:23 AM
Well, I actually know how to use a computer...

Anyways, complaint has been open at the FBI, hope they find the guy :-)

At least I have an IP address to start with...


Title: Re: MtGox stealing my BTCs?
Post by: Newar on October 16, 2013, 11:59:24 AM
Did you have 2FA?


Title: Re: MtGox stealing my BTCs?
Post by: hulk on October 16, 2013, 12:02:01 PM
I believe you don't have 2FA? anyway bye bye 3 BTC. Most likely its hacker and not MTGOX :)


Title: Re: MtGox stealing my BTCs?
Post by: malevolent on October 16, 2013, 08:57:40 PM
That would only protect you from common threats, which the highly specialiced trojans/keyloggers out for bitcoin exchange login data most definitely are not.
The only way to confidently deny the presence of bitcoin malware is if you'd exclusively accessed exchanges via a fresh and clean VM.

It wouldn't be enough if the host OS wasn't "fresh and clean" too.

It would probably be enough if he used the host OS exclusively for accessing exchanges and the guest OS for other Internet-interacting stuff. Though it may still be sometimes possible to compromise the host OS from the guest OS (or other guests if they aren't properly isolated).

http://www.blackhat.com/presentations/bh-usa-09/KORTCHINSKY/BHUSA09-Kortchinsky-Cloudburst-PAPER.pdf
http://media.blackhat.com/bh-us-11/Elhage/BH_US_11_Elhage_Virtunoid_WP.pdf


Title: Re: MtGox stealing my BTCs?
Post by: trilightzone.org on October 17, 2013, 11:30:15 PM
Hello,

All my bitcoins are gone from my bitcoin address... Received an e-mail 10 minute ago here:

Transaction reference: 27fb49c7-72d4-4e88-9bb0-d2646d403e97
Date: 2013-10-11 07:43:40 GMT
IP: 209.21.68.151

How is that even possible? I have a very strong password and no viruses... Can't be true!

The IP is in California and I am in Switzerland. Jeez....

Just did a quick check and this might help too, looks like a gmail user is connected to that IP for sending spam for the site discountflitflopshoes.com:

https://webcache.googleusercontent.com/search?q=cache:g2xvH6u5lVMJ:http://cleantalk.org/blacklists/discountflitflopshoes.com%2B209.21.68.151



Title: Re: MtGox stealing my BTCs?
Post by: bbit on October 18, 2013, 03:58:54 AM
I believe you don't have 2FA? anyway bye bye 3 BTC. Most likely its hacker and not MTGOX :)

it's pretty well known that Mt.Gox is stealing Bitcoins from its users to pay for its insolvency.


Title: Re: MtGox stealing my BTCs?
Post by: bbit on October 18, 2013, 04:21:07 AM
Quote

Links?, Proof?, anything that wasn't pulled out of yer arse?

it's called common sense something you clearly lack.


Title: Re: MtGox stealing my BTCs?
Post by: PuertoLibre on October 18, 2013, 02:30:35 PM
Quote

Links?, Proof?, anything that wasn't pulled out of yer arse?

it's called common sense something you clearly lack.

Ya, throw around unproven lame statements and I'm the one with no common sense.    ::)

https://bitcointalk.org/index.php?topic=312923.0


Title: Re: MtGox stealing my BTCs?
Post by: PuertoLibre on October 18, 2013, 06:28:25 PM
Quote

Links?, Proof?, anything that wasn't pulled out of yer arse?

it's called common sense something you clearly lack.

Ya, throw around unproven lame statements and I'm the one with no common sense.    ::)

https://bitcointalk.org/index.php?topic=312923.0

Umm, is that supposed to be proof that the exchange is the one stealing the money here?  Doesn't read that way.  Sounds like someone got bitten after not knowing how to secure their system correctly.

Okay, tell me, how do you arbitrarily set the withdrawal fee using MtGox's web interface? (to something like 2.2btc)

Okay, go...

http://s23.postimg.org/7av5g2ctn/Mt_Gox_Crazy_Fees.jpg


Title: Re: MtGox stealing my BTCs?
Post by: PuertoLibre on October 18, 2013, 07:14:50 PM
Beware of Mt. Gox - can't get Bitcoin out now without photo ID!

https://bitcointalk.org/index.php?topic=313343.0

Now this...

Anyone have any charts that estimate MtGox's liquidity level?


Title: Re: MtGox stealing my BTCs?
Post by: tvbcof on October 18, 2013, 07:34:23 PM
Beware of Mt. Gox - can't get Bitcoin out now without photo ID!

https://bitcointalk.org/index.php?topic=313343.0

Now this...

Anyone have any charts that estimate MtGox's liquidity level?

I'd love to see one to, but I wouldn't hold my breath.  Mt. Gox has a long history which makes it probably impossible to come up with any meaningful estimates of what they might be sitting on.

It is interesting to watch whether liquidity comes off of the public order-book when large trades happen.  Some of these within the last few days did not seem to.  So it was either BTC that had not been on the market, was in a dark pool, or was newly arrived from quasi-whale contacts of theirs.  The most interesting thing to know would be whether they are burning through their own (probably) substantial pool which they've accumulated over the years.  These things can only be guessed at and inferred absent a whistle-blower, hack, or something like that.  Even then the info would have to be taken with a grain of salt.



Title: Re: MtGox stealing my BTCs?
Post by: deepceleron on October 18, 2013, 07:50:30 PM
Quote

Links?, Proof?, anything that wasn't pulled out of yer arse?

it's called common sense something you clearly lack.

Ya, throw around unproven lame statements and I'm the one with no common sense.    ::)

https://bitcointalk.org/index.php?topic=312923.0

Umm, is that supposed to be proof that the exchange is the one stealing the money here?  Doesn't read that way.  Sounds like someone got bitten after not knowing how to secure their system correctly.

Okay, tell me, how do you arbitrarily set the withdrawal fee using MtGox's web interface? (to something like 2.2btc)

Okay, go...

http://s23.postimg.org/7av5g2ctn/Mt_Gox_Crazy_Fees.jpg

Who says hackers use a web page?

https://en.bitcoin.it/wiki/MtGox/API/HTTP/v1#Withdraw_bitcoins
Withdraw bitcoins

https://data.mtgox.com/api/1/generic/bitcoin/send_simple

Send bitcoins from your account to a bitcoin address.

Parameters:

    Name    Value    Required    Example
    address    string    Yes    N/A
    amount_int    int    Yes    N/A
    fee_int    int    No    N/A
    no_instant    bool    No    N/A
    green    bool    No    N/A

Being ignorant doesn't make either of you right.


Title: Re: MtGox stealing my BTCs?
Post by: PuertoLibre on October 18, 2013, 08:00:52 PM
Quote

Links?, Proof?, anything that wasn't pulled out of yer arse?

it's called common sense something you clearly lack.

Ya, throw around unproven lame statements and I'm the one with no common sense.    ::)

https://bitcointalk.org/index.php?topic=312923.0

Umm, is that supposed to be proof that the exchange is the one stealing the money here?  Doesn't read that way.  Sounds like someone got bitten after not knowing how to secure their system correctly.

Okay, tell me, how do you arbitrarily set the withdrawal fee using MtGox's web interface? (to something like 2.2btc)

Okay, go...

http://s23.postimg.org/7av5g2ctn/Mt_Gox_Crazy_Fees.jpg

Who says hackers use a web page?

https://en.bitcoin.it/wiki/MtGox/API/HTTP/v1#Withdraw_bitcoins
Withdraw bitcoins

https://data.mtgox.com/api/1/generic/bitcoin/send_simple

Send bitcoins from your account to a bitcoin address.

Parameters:

    Name    Value    Required    Example
    address    string    Yes    N/A
    amount_int    int    Yes    N/A
    fee_int    int    No    N/A
    no_instant    bool    No    N/A
    green    bool    No    N/A

Being ignorant doesn't make either of you right.
You can't use the Api without the keys. So that would not be likely.

{"result":"error","error":"Identification required to access private APINULL","token":"login_error_missing_rest_key"}

"Being ignorant doesn't make either of you right"


Title: Re: MtGox stealing my BTCs?
Post by: PuertoLibre on October 19, 2013, 07:45:57 PM


Come on PuertoLibre, its posted by a guy with 4 posts, talking about his "friend" with a few screenshots.   Who knows what his "friend" did or who he gave access to via the API.   Its a little flimsy for be to believe anything this guy is saying.
Did he also fake the receiving address amounts at roughly the same time frame?


sounds like they went trough the API this would allow them to mess up the transaction fees.. the only transaction fee you can choose is a tick box of 0.005 so its either a server exploit of API exploit both of which could or couldnt be your friends fault but should be serious concern to mtgox..