Bitcoin Forum

Other => Meta => Topic started by: mapuche33 on August 06, 2018, 06:00:27 PM



Title: Recovering my hacked account AvenG [signed message]
Post by: mapuche33 on August 06, 2018, 06:00:27 PM
Hi,
 
My Full Member account with 100 Merit +133 posts, registered on 19th September of 2012 AvenG (https://bitcointalk.org/index.php?action=profile;u=67153/) has been stolen presumably by a russian hacker that managed to compromise my profile.

https://i.imgur.com/4E88Mvq.jpg

Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
My account AvenG (ID: 67153) has been hacked/stolen on 11th july 2018. Please reset the email to ~@protonmail.com. The current date is 6th August 2018.
-----BEGIN SIGNATURE-----
1KmUUTK82zhp2QYULV6CXGbZofepBEpziV
IInjvmjDloAI/JX6dTgKR25ZwoVYmgKXK/Dp19Ts4ydiGZHHnCfYvjT7eVOl4+xazudJn3pecZ+4WqnJJT5IG0g=
-----END BITCOIN SIGNED MESSAGE-----

Here are the unedited posts where I posted that address:
https://bitcointalk.org/index.php?topic=192916.msg2310742#msg2310742
https://bitcointalk.org/index.php?topic=192916.msg2301934#msg2301934

I already PM'ed Cyrus and Theymos. However, due to the unfortunate results and negative feedback from other fellows that are facing similar situations..
I ask YOU for your help, it seems that PM's are not enough so I would appreciate anyone who is able to contact the Admins in a straightforward method (IRC, mail, phone, in person, etc) to mention this issue / incident. Also I would like to heard stories of those users who successfully managed to recover his/her account (I couldn't find any recent cases).

Thanks in advance !
Regards, AvenG


Title: Re: Recovering my hacked account [signed message]
Post by: LoyceV on August 07, 2018, 05:24:10 PM
OP sent me a PM asking "quote me please".
Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
My account AvenG (ID: 67153) has been hacked/stolen on 11th july 2018. Please reset the email to gbsx@protonmail.com. The current date is 6th August 2018.
-----BEGIN SIGNATURE-----
1KmUUTK82zhp2QYULV6CXGbZofepBEpziV
IInjvmjDloAI/JX6dTgKR25ZwoVYmgKXK/Dp19Ts4ydiGZHHnCfYvjT7eVOl4+xazudJn3pecZ+4WqnJJT5IG0g=
-----END BITCOIN SIGNED MESSAGE-----
Verified (https://brainwalletx.github.io/#verify?vrAddr=1KmUUTK82zhp2QYULV6CXGbZofepBEpziV&vrMsg=My%20account%20AvenG%20(ID%3A%2067153)%20has%20been%20hacked%2Fstolen%20on%2011th%20july%202018.%20Please%20reset%20the%20email%20to%20gbsx%40protonmail.com.%20The%20current%20date%20is%206th%20August%202018.&vrSig=IInjvmjDloAI%2FJX6dTgKR25ZwoVYmgKXK%2FDp19Ts4ydiGZHHnCfYvjT7eVOl4%2BxazudJn3pecZ%2B4WqnJJT5IG0g%3D).
I don't think it was hacked on July 11, BPIP.org (https://bpip.org/profile.aspx?p=AvenG) shows this:
Code:
7/19/2018 2:12:30 PM 	    	password changed

Quote
https://bitcointalk.org/index.php?topic=192916.msg2310742#msg2310742
Archived (https://archive.is/vasn7#selection-4061.0-4061.34)
I'll leave red trust on AvenG (https://bitcointalk.org/index.php?action=profile;u=67153). If you get your account back, you'll have to sign another message to confirm it, so I can remove my red trust.

I ask YOU for your help, it seems that PM's are not enough so I would appreciate anyone who is able to contact the Admins in a straightforward method (IRC, mail, phone, in person, etc) to mention this issue / incident.
That's very unlikely to happen.

Quote
Also I would like to heard stories of those users who successfully managed to recover his/her account (I couldn't find any recent cases).
Some accounts have been recovered, but as far as I've seen, most requests are ignored.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on August 07, 2018, 06:18:45 PM
OP sent me a PM asking "quote me please".

Thanks LoyceV, I had to ask someone to verify the signed message as well as quoting in order to stake. Also, I became impatient after noticing that passed 20 views no one leaved a reply. I found you on a related topic here: https://bitcointalk.org/index.php?topic=4605811.0 (https://bitcointalk.org/index.php?topic=4605811.0)

I don't think it was hacked on July 11, BPIP.org (https://bpip.org/profile.aspx?p=AvenG) shows this:
Code:
7/19/2018 2:12:30 PM 	    	password changed

Interesting, I never knew about the existence of BPIP. I assumed that the hacked day was when I received the notification "email address changed" on my gmail inbox. Here: https://i.imgur.com/HgC4VKb.jpg
 
I'll leave red trust on AvenG (https://bitcointalk.org/index.php?action=profile;u=67153). If you get your account back, you'll have to sign another message to confirm it, so I can remove my red trust.

Sure, I expect admins to lock the access or ban my AvenG account until they manage to return it to me. I can sign as many messages as you want with that address as well as the previously associated on my profile 1A6UzoDvPybimQg98B22yMoEF75wAZUdmt (which the hacker already erased it).
 
Some accounts have been recovered, but as far as I've seen, most requests are ignored.

That is unfortunate, Admins don't take precautions against those hackers leaving them the doors open to exploit vulnerabilities on their database. Nonetheless they close the doors to initiate the recovery process, aka ignore our requests.  
This kind of malpractice drives us to no other choice than paying those pirates some rescue amount (which I'm not a fan of).



Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on August 17, 2018, 02:12:49 AM
UPDATE:
 
Hacker managed to sell my account to some spammer 3 days ago, he already updated my profile with a different avatar and signature, as you can see here (https://bitcointalk.org/index.php?action=profile;u=67153/):

https://i.imgur.com/E8VppaB.jpg

Also, he started posting crap consistenly every single day since 13th August on a basis of 2 posts / day on the following boards as you can see here (https://bitcointalk.org/index.php?action=profile;u=67153;sa=showPosts):

https://i.imgur.com/Ctyx1XJ.jpg

Apparently he is growing in rank for later purposes, could be anything.. I would like to ask / request escalating this incident up to the extend of locking my account AvenG (https://bitcointalk.org/index.php?action=profile;u=67153/) so no one can use it (which seems unlikely due to the fact that the Admins ignores us, but at least I try).
 


Title: Re: Recovering my hacked account [signed message]
Post by: SFR10 on August 17, 2018, 02:58:51 AM
Nonetheless they close the doors to initiate the recovery process, aka ignore our requests.  
Regardless of how everything seems to be (at the moment), there are a lot of things going on in the background (highlighted part):

If you have not posted that addy elsewhere, it probably won't be accepted.


We don't actually accept the profile field address unless there's some sort of proof that it's remained unchanged, for that very reason.

I'm working on a new address-staking system which will automatically handle signatures, etc. Might have it ready by the end of the month if nothing else comes up to consume my time.

I would like to ask / request escalating this incident up to the extend of locking my account AvenG (https://bitcointalk.org/index.php?action=profile;u=67153/) so no one can use it (which seems unlikely due to the fact that the Admins ignores us, but at least I try).
Did you set/use the "Secret Question" field on that account?
- If "YES", then you can use that for locking your account: PSA: ACCOUNTS WILL BE LOCKED IF THE SECRET QUESTION IS USED TO RECOVER IT (https://bitcointalk.org/index.php?topic=1206977.0)


Title: Re: Recovering my hacked account [signed message]
Post by: morningcoffee on August 17, 2018, 07:29:14 AM
I feel your pain. I am in the same situation. I also have had my account compromised. I have sent a message to Cyrus as instructed in this thread https://bitcointalk.org/index.php?topic=497545.0 and if he doesn't respond in 2 weeks I will then message Theymos with a signed message using my bitcoin address I posted and still have access to.

My account is being used right now to likely abuse bounty programs... the person who took over the account doesn't seem to use English as a first language, but is rather Eastern European. They did not edit any of my earlier posts oddly, but it's obvious when they started to do this. It is an unfortunate situation. I will follow your thread in hopes that you get your account back, and I will let you know if Cyrus or Theymos respond to me as well. Cheer up, I'm sure they will help eventually.

I really like the idea that Theymos will implement something new to combat this issue. I'm excited to see what he comes up with.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on August 17, 2018, 10:48:16 PM
Did you set/use the "Secret Question" field on that account?
- If "YES", then you can use that for locking your account: PSA: ACCOUNTS WILL BE LOCKED IF THE SECRET QUESTION IS USED TO RECOVER IT (https://bitcointalk.org/index.php?topic=1206977.0)

I have already tried that several times but I'm receiving the following message:
 
Code:
An Error Has Occurred!
Sorry, there is no secret question set for this member.

I don't have written any secret question in the place I store my passwords, so not sure if I ever created one or if the hacker managed to disable it. Any other ideas or suggestions? I will do anything, please someone lock or ban my account until it is returned to me.
 
Anyone knows how many NEGATIVE TRUST do I have to collect in order to get locked / suspended / banned ?  I'll start a TAG ME campaign if it is possible getting locked this way.


Title: Re: Recovering my hacked account [signed message]
Post by: SFR10 on August 18, 2018, 12:45:35 AM
Any other ideas or suggestions?
Since you can't do anything else, I suggest to patiently wait either for the implementation of the new system or until the manual recovery process happens.

Anyone knows how many NEGATIVE TRUST do I have to collect in order to get locked / suspended / banned ?  I'll start a TAG ME campaign if it is possible getting locked this way.
There's no correlation between the amount of negative trusts and account suspensions.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on August 24, 2018, 03:39:50 AM
bump
 
Another 2 weeks passed without response from the admins so I PM'ed again...


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on August 27, 2018, 02:30:20 PM
I feel your pain. I am in the same situation. I also have had my account compromised. I have sent a message to Cyrus as instructed in this thread https://bitcointalk.org/index.php?topic=497545.0 and if he doesn't respond in 2 weeks I will then message Theymos with a signed message using my bitcoin address I posted and still have access to.

My account is being used right now to likely abuse bounty programs... the person who took over the account doesn't seem to use English as a first language, but is rather Eastern European. They did not edit any of my earlier posts oddly, but it's obvious when they started to do this. It is an unfortunate situation. I will follow your thread in hopes that you get your account back, and I will let you know if Cyrus or Theymos respond to me as well. Cheer up, I'm sure they will help eventually.

I really like the idea that Theymos will implement something new to combat this issue. I'm excited to see what he comes up with.

Will see where it goes. So far nobody notice it, is a major concern so action should be taken as soon as possible in order to preserve a healthy community.
Can you tell us more about the Theymos "project" / "new idea" ? for me are just rumors... I mean where are the updates?


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on September 04, 2018, 07:36:13 AM
bump
 
I PM'ed again @cyrus & @theymos, another 2 weeks passed being ignored. Meanwhile spammer is posting crap with my stolen account.


Title: Re: Recovering my hacked account [signed message]
Post by: Lucius on September 04, 2018, 10:49:08 AM
bump
 
I PM'ed again @cyrus & @theymos, another 2 weeks passed being ignored. Meanwhile spammer is posting crap with my stolen account.

Unfortunately for you this procedure may take months, situation is not good regarding recovering stolen/hacked accounts and theymos admitted it - but he is working on something which will allow much easier recovering of hacked accounts, but this will also take some time (few months).

Did you try to contact person who bought your account and present the facts from this thread? It is unlikely to succeed, but I know one case when person who bought stolen account was returned that account to the right owner.


Title: Re: Recovering my hacked account [signed message]
Post by: morningcoffee on September 04, 2018, 12:19:19 PM
I was hoping you would be wrong Lucius, but you were completely right. Thank you for at least correcting my expectations. Cyrus did not respond in two weeks time and now I'm going to try to send a signed message to Theymos. I'm a little less optimistic about my chances of recovering my account now, but as long as there's a chance I will keep trying.

---.-----.---.-----.----.-----.-----.------.-----

Help!

My bitcointalk account kworrom was stolen from me!

      Help!

I have messaged admins Cyrus and Theymos with a signed bitcoin message, but no reply!

            Help!

I have messaged Hilariousandco and mprep about suspending the person who stole my account, but no action taken!

                  Help!

I've posted a public signed BTC message and link to and unedited message where I posted address as kworrom: https://bitcointalk.org/index.php?topic=4864633.msg44391814#msg44391814

                        MY ACCOUNT KWORROM WAS STOLEN! PLEASE HELP!

-----BEGIN BITCOIN SIGNED MESSAGE-------------------------------------------------------------------
This is morningcoffee. My account kworrom was stolen. Please help! This message was created on 9/20/18.
-----BEGIN SIGNATURE----------------------------------------------------------------------------------
189EGkRQHkzPwqrzvaabgAVj696eL6uQeB
HGs4ofERMfkg+yo8E2+HxRsfYxdr8xmfRuGdIB0CMJL4eAIZzicdvnMlJ6WzxvXr9q2hrXblDcLIBN5iLBWSGTM=
-----END BITCOIN SIGNED MESSAGE----------------------------------------------------------------------

AN UNEDITED POST WHERE I USED ADDRESS: https://bitcointalk.org/index.php?topic=246400.msg2633111#msg2633111


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on September 18, 2018, 02:29:59 AM
another 2 weeks passed without any updates from the admins so I PM'ed again.
I also sent a message to @CobraBitcoin on twitter but he also ignored it, so I must assume no one cares.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on October 02, 2018, 03:35:54 AM
15 days passed without any replies or updates so I PM'ed again... 😞


Title: Re: Recovering my hacked account [signed message]
Post by: Dig Bicks on October 02, 2018, 03:47:47 AM
15 days passed without any replies or updates so I PM'ed again... 😞

Just be patient, it will only take 1-2 years most likely.  Maybe 5 years if your unlucky.  Patience is a virtue.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on October 19, 2018, 03:17:52 AM
2 more weeks passed without any updates from the admins so I PM'ed them again.. 👎👎👎


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on November 01, 2018, 02:44:15 PM
15 days passed without any updates or replies so I PM'ed again...  :-\


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on November 15, 2018, 06:02:19 AM
time flies..

another 2 weeks without response nor updates so I PM'ed @theymos and @cyrus again.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on November 30, 2018, 06:34:45 PM
still nothing, so I PM'ed them again.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on December 12, 2018, 02:07:22 PM
December already ! another 2 weeks passed still without any updates from Theymos or Cyrus.
I PM'ed them again it is pointless but I'm still trying...


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on December 28, 2018, 04:11:49 AM
According to the new streamlined process announced by Theymos, I sent an email to the address described here (https://bitcointalk.org/index.php?topic=5089777.0/) with the required data. Will wait for replies and update here accordingly.




Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on January 26, 2019, 02:51:14 PM
UPDATE:
 
Response received from Bitcointalk account recovery team on 10th January asking for a new signed message + accessing a bitcointalk link which seems to be invalid.
I already replied to them with the info requested. Waiting.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on February 22, 2019, 12:11:33 PM
UPDATE: account AvenG has been recovered.


Title: Re: Recovering my hacked account [signed message]
Post by: AvenG on February 22, 2019, 12:13:13 PM
UPDATE: account AvenG has been recovered.

I confirm account has been recovered.


Title: Re: Recovering my hacked account [signed message]
Post by: LoyceV on February 22, 2019, 12:21:05 PM
Can you sign another message, including today's date?
You may also want to delete all posts that you didn't make, to prevent being blamed for plagiarism later on.


Title: Re: Recovering my hacked account [signed message]
Post by: mapuche33 on March 02, 2019, 04:27:02 AM
Can you sign another message, including today's date?
You may also want to delete all posts that you didn't make, to prevent being blamed for plagiarism later on.

Sure, here you are:

Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
My account AvenG (ID:67153) has been recovered on 22th February 2019. Today is 2nd March 2019 my alternative account is Mapuche33 (ID:2328967). Thanks LoyceV for helping :)
-----BEGIN SIGNATURE-----
1KmUUTK82zhp2QYULV6CXGbZofepBEpziV
IKtix8lFG3PUU1dMWgARsysh1zNJxc6D3K96vyCeTrEoINn7Q+wyjABuY2SvEKd0IXwoBsZzVE/AYU7rfWzpnJg=
-----END BITCOIN SIGNED MESSAGE-----

On regard of the other, staff already replied me saying that unfortunately there is no easy way to delete posts and threads. They said that maybe there will be such feature when the new forum software is ready.
Sadly it is not possible to select a recovery point in time to get back to normal prior the hack... So I 'll be wasting my time deleting unwanted posts manually.
They also stated that is not possible merging two accounts. So I'm gonna live with both of them linked to the same address I guess.
 


Title: Re: Recovering my hacked account [signed message]
Post by: AvenG on March 02, 2019, 08:03:24 AM
UPDATE:
After wasting a lot of time deleting awful messages (mostly on Altcoins board) I was able to get rid of all those crappy posts. However, I came across to a pair of topics started by the spammer that I'm unable to erase. Those are the following:

https://bitcointalk.org/index.php?topic=5090044.msg48909369#msg48909369 (https://bitcointalk.org/index.php?topic=5090044.msg48909369#msg48909369)
https://bitcointalk.org/index.php?topic=5077743.msg48329835#msg48329835 (https://bitcointalk.org/index.php?topic=5077743.msg48329835#msg48329835)

https://i.imgur.com/X3AodGK.jpg


For the record: those are not mine so I 'd like to ask some moderator to kindly delete those as well.


Title: Re: Recovering my hacked account [signed message]
Post by: LoyceV on March 02, 2019, 08:38:57 AM
Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
My account AvenG (ID:67153) has been recovered on 22th February 2019. Today is 2nd March 2019 my alternative account is Mapuche33 (ID:2328967). Thanks LoyceV for helping :)
-----BEGIN SIGNATURE-----
1KmUUTK82zhp2QYULV6CXGbZofepBEpziV
IKtix8lFG3PUU1dMWgARsysh1zNJxc6D3K96vyCeTrEoINn7Q+wyjABuY2SvEKd0IXwoBsZzVE/AYU7rfWzpnJg=
-----END BITCOIN SIGNED MESSAGE-----
Verified, and I've removed my red tag. I've left a neutral tag to confirm it's back to it's owner.

Quote
staff already replied me saying that unfortunately there is no easy way to delete posts and threads.
Using your middle mouse button on the delete button is quite fast to get rid of posts. You can't remove threads, but you can edit the OP (say: "this post was created when my account was hacked"), and move (lower-left corner) the threads to Archival.

For the record: those are not mine so I 'd like to ask some moderator to kindly delete those as well.
If the above doesn't suffice, you can click Report to moderator and shortly ask to delete it because it was posted by a hacker