Bitcoin Forum

Bitcoin => Electrum => Topic started by: jwmiller6 on February 23, 2019, 03:54:47 PM



Title: Electrum Wallet Compromised??
Post by: jwmiller6 on February 23, 2019, 03:54:47 PM
This morning I sent my Electrum wallet some BTC from coinbase and went on with my day. Came back 45mins later to find at the very same second I had initiated my receiving transaction, my wallet had also initiated (on its own) a send transaction to an unknown address before the funds were even available in my wallet. There was no way to stop it and my funds are now gone... Is this some sort of glitch in electrum's system, or is this signs of a compromised wallet?

Receiving transaction ID: 11ba4ba28dd4230c15781a1e8c755f5d9b89862612b7b6cf415bf4978e99375b

Sending ID: c40d8a10d51a1d54cdd989364513d8cdcaa5fc83711016c5ce3d2a0803ded67d

Any help would be appreciated......


Title: Re: Electrum Wallet Compromised??
Post by: NeuroticFish on February 23, 2019, 06:29:33 PM
Any help would be appreciated......

Your wallet didn't send the funds by itself. Your wallet just "noticed" that your funds were sent out.
Most probably somebody else has the private keys of your wallet. Everybody who has the private keys has access to spend your funds (doesn't need access to your wallet!).


What to do:
Uninstall the wallet, clean up your computer, install a brand new electrum and make sure you download it from the official website https://electrum.org make a completely new wallet and make sure you never use or restore the old one.


Title: Re: Electrum Wallet Compromised??
Post by: DireWolfM14 on February 23, 2019, 06:59:18 PM
This morning I sent my Electrum wallet some BTC from coinbase and went on with my day. Came back 45mins later to find at the very same second I had initiated my receiving transaction, my wallet had also initiated (on its own) a send transaction to an unknown address before the funds were even available in my wallet. There was no way to stop it and my funds are now gone... Is this some sort of glitch in electrum's system, or is this signs of a compromised wallet?

Receiving transaction ID: 11ba4ba28dd4230c15781a1e8c755f5d9b89862612b7b6cf415bf4978e99375b

Sending ID: c40d8a10d51a1d54cdd989364513d8cdcaa5fc83711016c5ce3d2a0803ded67d

Any help would be appreciated......

The funds are still in this address (https://btc.com/bc1q7hsnpd794pap2hd3htn8hszdfk5hzgsj5md9lz) for the time being, but that address has been very busy.  It looks like it recently sent 15BTC to a mixer, and it's had almost 37BTC roll through since Feb. 4 2019.

It certainly appears you've been hit by a scammer.  Any information you can share that would help others avoid being targeted would be much appreciated.  Can you give us more information, such as your operating system and version of Electrum?  Do you remember from where you downloaded the wallet software?  Do you remember how you initiated the wallet, was it a new seed, restored seed, imported private key?



Title: Re: Electrum Wallet Compromised??
Post by: joniboini on February 24, 2019, 05:38:32 AM
Looks like this guy has managed to steal a lot of Bitcoins. Here's some receiving address that's related to the hacker[1]:
Quote
bc1q6c5ad6nez36c9d5pwdgeme2kqwu5qqw7ngmmnv
1BqWGXvYig5tGzBHGccfR9Kwb3VUDf94G5
13nhXgLW2UfG6ET4mvcWKPZRh98W1r8j9j
bc1qdhz5znte2jkv8wkkcvkdrzvmqhwgkmw08g6vmt

OP you should make a new wallet, and make sure your OS is protected from keylogger and etc.

[1] https://hashxp.org/bc1q7hsnpd794pap2hd3htn8hszdfk5hzgsj5md9lz