Bitcoin Forum

Bitcoin => Bitcoin Technical Support => Topic started by: StackGambler on August 26, 2019, 07:10:33 PM



Title: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 26, 2019, 07:10:33 PM
A hacker breached my server and stole all the funds: https://www.blockchain.com/btc/tx/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b

A very low fee was used.

Just got back server access and am trying to cancel the transaction. Tried zapwallettxes and deleting the mempool, didn't work.

If anyone has a solution that would be excellent.

39U2gKxvdL25WZgRwxg1Y1a5k3cv1U3uad is the address I would like the funds sent to.

I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee since I don't know how to. Or, any other help or suggestion.

I will pay 0.03 BTC from the recovered amount to whoever can help out.



Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AB de Royse777 on August 26, 2019, 07:15:17 PM
A hacker breached my server and stole all the funds: https://www.blockchain.com/btc/tx/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b

A very low fee was used.

Just got back server access and am trying to cancel the transaction. Tried zapwallettxes and deleting the mempool, didn't work.

If anyone has a solution that would be excellent.

39U2gKxvdL25WZgRwxg1Y1a5k3cv1U3uad is the address I would like the funds sent to.

I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee since I don't know how to. Or, any other help or suggestion.

I will pay 0.03 BTC from the recovered amount to whoever can help out.


So sorry to see this. It's an attack Electrum users were facing. I think your client was Electrum?

I have no idea if there is a possibility but good thing is that the fees are too low (precisely 0.547 sat/B). This will give you some time to buy. I hope someone can give you some resources to save you.  


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 26, 2019, 07:16:25 PM
A hacker breached my server and stole all the funds: https://www.blockchain.com/btc/tx/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b

A very low fee was used.

Just got back server access and am trying to cancel the transaction. Tried zapwallettxes and deleting the mempool, didn't work.

If anyone has a solution that would be excellent.

39U2gKxvdL25WZgRwxg1Y1a5k3cv1U3uad is the address I would like the funds sent to.

I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee since I don't know how to. Or, any other help or suggestion.

I will pay 0.03 BTC from the recovered amount to whoever can help out.


So sorry to see this. It's an attack Electrum users were facing. I think your client was Electrum?

I have no idea if there is a possibility but good thing is that the fees are too low (precisely 0.547 sat/B). This will give you some time to buy. I hope someone can give you some resources to save you.  

My client was Bitcoin Core. Luckily it seems like a novice since he used an ultra-low fee. Hoping someone can help me compile a new transaction which I can sign from the node and rebroadcast. Zapping the wallet, abandoning tx, or a double spend from the wallet isn't working.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AB de Royse777 on August 26, 2019, 07:17:20 PM
Can you check this article while I try to find any other resource for you: https://coincentral.com/cancel-unconfirmed-bitcoin-transaction/

Edit:
Zapping the wallet, abandoning tx, or a double spend from the wallet isn't working.
Okay that's sad news.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 26, 2019, 07:19:33 PM
Your chance is almost 0, but if you're desperate there are 2 options :
1. Make transaction with same input, but with different output (Bitcoin address which owned you and not hacked). Then personally make a request to pools/miners to include your transaction.
2. Similar with 1st step, but broadcast the transaction instead (which most likely will be rejected by other nodes).

I don't know how to do that I'm hoping someone can do that from me by the txid, I will give them 0.03 if it works


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AB de Royse777 on August 26, 2019, 07:22:59 PM
Then personally make a request to pools/miners to include your transaction.
How do someone will know who is a miner and how do someone contact them? I think OP needs a very quick movement. Do you know anyone in person?


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 26, 2019, 07:27:20 PM
From my Bitcoin Core window I have successfully cancelled the tx and sent it to the new one, BUT it is not showing on the blockchain. My address I want it sent to is empty.

NEW transaction I created that is showing as sent out in Core: 1d85a3028958a8c7838dc9823c8d2ded7ee0b792b8f447af1209f29d4a4107e9 (showing as invalid on explorers)

Please someone help.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: Continuous on August 26, 2019, 07:32:14 PM
From my Bitcoin Core window I have successfully cancelled the tx and sent it to the new one, BUT it is not showing on the blockchain. My address I want it sent to is empty.

NEW transaction I created that is showing as sent out in Core: 1d85a3028958a8c7838dc9823c8d2ded7ee0b792b8f447af1209f29d4a4107e9 (showing as invalid on explorers)

Please someone help.

Shows up valid here - https://www.blockchain.com/en/btc/tx/1d85a3028958a8c7838dc9823c8d2ded7ee0b792b8f447af1209f29d4a4107e9


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AB de Royse777 on August 26, 2019, 07:34:42 PM
From my Bitcoin Core window I have successfully cancelled the tx and sent it to the new one, BUT it is not showing on the blockchain. My address I want it sent to is empty.

NEW transaction I created that is showing as sent out in Core: 1d85a3028958a8c7838dc9823c8d2ded7ee0b792b8f447af1209f29d4a4107e9 (showing as invalid on explorers)

Please someone help.
I think you made it!
http://prntscr.com/oxt9u7


I do not see the old tx in the block explorer anymore but I see the new one and it's going to your desired address which is this: 39U2gKxvdL25WZgRwxg1Y1a5k3cv1U3uad

You are good now :-)


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 26, 2019, 07:38:45 PM
My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: o_e_l_e_o on August 26, 2019, 07:42:58 PM
The old transaction still exists in some nodes. For example:

https://blockchair.com/bitcoin/transaction/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b
https://explorer.viabtc.com/btc/tx/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b
https://live.blockcypher.com/btc/tx/1a62267aa812b8d289148192ff15cb2d6a1fccf40ce0e31278125191ff9d181b/

Just because the new transaction has currently been accepted by some nodes, doesn't mean it will definitely confirm first. The miners who find the next few blocks might only be seeing the old transaction and not the new one. The mempool being a little fuller right now will work in your favor, as even if they are only seeing the old transaction, they are unlikely to pick it for their block due to its low fees. Having said all that, you aren't 100% safe until you have some confirmations on the new transaction.

Edit: Looks like the new transaction has one confirmation and the old one has disappeared from all the sites above.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AB de Royse777 on August 26, 2019, 07:47:04 PM
I am archiving this topic for reference: http://archive.is/V2M8I

Someone PMed me with some concerns and seems like it's very possible. I will wait for the right person to make a post here or any other section.

Having said all that, you aren't 100% safe until you have some confirmations on the new transaction.
The 2nd one got one confirmation: https://www.blockchain.com/btc/tx/1d85a3028958a8c7838dc9823c8d2ded7ee0b792b8f447af1209f29d4a4107e9

My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.
Did you forget something?


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: Quickseller on August 27, 2019, 03:19:46 AM

My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.
Did you forget something?
Given the OP's history, I would not be especially surprised to see him not follow through on his bounty promise. I also have doubts as to his story, but that is besides the point.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: Thirdspace on August 27, 2019, 05:26:52 AM
Someone PMed me with some concerns and seems like it's very possible. I will wait for the right person to make a post here or any other section.
what is it about? double spend to scam?

I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee since I don't know how to. Or, any other help or suggestion.

I will pay 0.03 BTC from the recovered amount to whoever can help out.
My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.
Did you forget something?
he asked for someone to create a new transaction with $5 fee bump, so he can sign and broadcast it
since no one here seems to actually provide him with such transaction, but his dev created it
he doesn't have to pay/reward anyone, unless I'm missing something here


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: hacker1001101001 on August 27, 2019, 06:17:04 AM
he asked for someone to create a new transaction with $5 fee bump, so he can sign and broadcast it
since no one here seems to actually provide him with such transaction, but his dev created it
he doesn't have to pay/reward anyone, unless I'm missing something here

You are right, he is not inclined to pay anyone here as none of them helped in the solving the transaction problem, and asking about it is somewhat stupid.

Anyways, he has already paid the bounty ( funds to help ) to his dev, as he stated here.

It's been paid to my dev: https://www.blockchain.com/btc/tx/517fad7595b55a3b2468cfeb7105239c48cf5c29ee7c461c183c2297027a864c



@StackGambler, I am more than interested to know, basic details about how your dev managed to change the output address ? It would be nice if you can let us know.. Thank You !


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: TalkStar on August 27, 2019, 09:14:51 AM
My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.
Feeling great to hear that your issue have been solved. I hope you can share all the details on your thread which can be a proper guideline for someone in the future. Nowadays its quite common to face this kinda hackers attack on bitcoin wallets and solution something like this could be really helpful. Maybe your little help can saves many bitcoin users from those unexpected hacking attempts.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on August 28, 2019, 05:22:43 AM
Someone PMed me with some concerns and seems like it's very possible. I will wait for the right person to make a post here or any other section.
what is it about? double spend to scam?

I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee since I don't know how to. Or, any other help or suggestion.

I will pay 0.03 BTC from the recovered amount to whoever can help out.
My dev was a genius, he managed to recreate and rebroadcast a new transaction after dropping the hacker's one. Utterly stunning. Thank you everyone for the help nonetheless. Great learning experience for me.
Did you forget something?
he asked for someone to create a new transaction with $5 fee bump, so he can sign and broadcast it
since no one here seems to actually provide him with such transaction, but his dev created it
he doesn't have to pay/reward anyone, unless I'm missing something here

This pretty much sums it up, nobody here built the tx I asked for, but my dev handled it.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: LoyceV on August 28, 2019, 12:39:15 PM
I am hoping someone from here can build a transaction for me to sign from the wallet and rebroadcast at a $5 fee
I haven't responded here yet, but ever since I read this I've been wondering: why didn't you just do this at Coinb.in (https://coinb.in/#newTransaction)? It allows you to create and sign the transaction (the latter can be done offline).


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: Myleschetty on August 29, 2019, 03:28:37 PM
I never know there's a chance of cancelling a transaction which is already sent on the blockchain and I go through this thread but still don't understand how the process was done since OP don't explain in length and ETFbitcoin message too tech for me to understand very well.


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: AdolfinWolf on August 29, 2019, 03:42:56 PM
I never know there's a chance of cancelling a transaction which is already sent on the blockchain and I go through this thread but still don't understand how the process was done since OP don't explain in length and ETFbitcoin message too tech for me to understand very well.
He sent another transaction which spent the same funds, but to a different adress with much, much higher fees.
So the miners added his transaction instead of the other one, due to the bigger monetary reward it would get them.

The transaction was never ‘canceled’ it was simply overridden by another one because the “first” transaction wasn’t confirmed yet.

If it was already confirmed (a miner has already mined a block including his transaction), it wouldn’t have been possible to do what he did. (Unless someone does a much more sophisticated attack, which usually isn’t worth it or even possible in the first place.)

Basically: https://coinsutra.com/bitcoin-double-spending/


Title: Re: [URGENT] Need help cancelling a transaction from a hacker [0.03 BTC bounty]
Post by: StackGambler on September 01, 2019, 04:42:19 PM
I never know there's a chance of cancelling a transaction which is already sent on the blockchain and I go through this thread but still don't understand how the process was done since OP don't explain in length and ETFbitcoin message too tech for me to understand very well.
He sent another transaction which spent the same funds, but to a different adress with much, much higher fees.
So the miners added his transaction instead of the other one, due to the bigger monetary reward it would get them.

The transaction was never ‘canceled’ it was simply overridden by another one because the “first” transaction wasn’t confirmed yet.

If it was already confirmed (a miner has already mined a block including his transaction), it wouldn’t have been possible to do what he did. (Unless someone does a much more sophisticated attack, which usually isn’t worth it or even possible in the first place.)

Basically: https://coinsutra.com/bitcoin-double-spending/

Thank you, that's an excellent explanation that even a noob like me can digest.