Bitcoin Forum

Bitcoin => Bitcoin Technical Support => Topic started by: CWestermark36 on November 13, 2019, 01:04:09 AM



Title: Address Info - Did I get hacked?
Post by: CWestermark36 on November 13, 2019, 01:04:09 AM
Hi,

is there any way to get any information about the address https://btc.exan.tech/address/1M3jWAPH6Uq5ZS1GwB1jcfkPuRXBscdXw1 (https://btc.exan.tech/address/1M3jWAPH6Uq5ZS1GwB1jcfkPuRXBscdXw1) and who is potentially controlling it?

My wallet sent 3.8BTC to this address (Hash 443030647c938503d12d09373f8f1c84083be1f8b2e1c48c107fb27cc561ddeb ) and I do not why. The address receives a lot of transactions and is very active. Has my computer maybe got compromised? Can one from the behavior of an address get an indication what actor (Scammer, Exchange....) is controlling it?

Appreciate any help / info. Take care
/Christian


Title: Re: Address Info - Did I get hacked?
Post by: masulum on November 13, 2019, 01:19:59 AM
If you are never send any BTC, of course someone stolen your BTC. Where you save your bitcoin? Web wallet, app or  pc wallet/trezor?


Title: Re: Address Info - Did I get hacked?
Post by: CWestermark36 on November 13, 2019, 01:29:32 AM
A Nano ledger X HW wallet, which should be 100% safe!! I canīt get my head around how this transaction has happen. I received 7.7BTC from Binance to an address that is controlled by the ledger ( 3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai ), and 20min later roughly 50% of the amount is sent on to the above mentioned address 1M3jWAPH6Uq5ZS1GwB1jcfkPuRXBscdXw1 that is very active

Both transactions involving my Ledger HW address 3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai can be seen here.
https://btc.com/3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai (https://btc.com/3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai)



Title: Re: Address Info - Did I get hacked?
Post by: TryNinja on November 13, 2019, 02:00:42 AM
A Nano ledger X HW wallet, which should be 100% safe!! I canīt get my head around how this transaction has happen. I received 7.7BTC from Binance to an address that is controlled by the ledger ( 3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai ), and 20min later roughly 50% of the amount is sent on to the above mentioned address 1M3jWAPH6Uq5ZS1GwB1jcfkPuRXBscdXw1 that is very active

Both transactions involving my Ledger HW address 3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai can be seen here.
https://btc.com/3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai (https://btc.com/3GXzXTwfHCppzei7BQqipGNQiTPRPdFLai)
How did you backup your wallet seed? Have you ever typed it in your phone, email, computer, etc? Do you still have anything in your wallet or did everything was sent to this random address? (why did you say 50% was sent?)


Title: Re: Address Info - Did I get hacked?
Post by: nc50lc on November 13, 2019, 02:03:47 AM
Hardware wallets are supposed to be immune to such hacks,
the problem must be the client, address changing malware (clipboard hijacking) or social engineering tactics.
Because if it's the seed, all of the wallet's balance should be wiped by now.

Questions:
  • 1. Is the address: 32ZVUuEqNHmN4E3nEGwQ8G4L2awHyM9B7K belongs to you?
    Because you've mentioned that almost half of the amount was sent, so this must be your change address.
  • 2. The address: 34Ad7ccMtEhcuN9j1YWvQwcQiwjoT2YGST also belongs to you?
    If #1 and this are true, then that transaction was probably sent with your consent (unintentionally because of the possible reason above);
    if not, there's a problem with your HW.
  • 3. Have you tried to send the same amount to another address prior to this "hack"?


Title: Re: Address Info - Did I get hacked?
Post by: CWestermark36 on November 13, 2019, 04:03:31 AM
After a long dinner the transaction had a good end. It was an ICO investment that was not entered into our Cointracking :)


Title: Re: Address Info - Did I get hacked?
Post by: TryNinja on November 13, 2019, 04:06:48 AM
After a long dinner the transaction had a good end. It was an ICO investment that was not entered into our Cointracking :)
So no coins were lost? Glad to read that. :)

I advise you to lock the thread now (bottom-left corner of the page) to avoid the spammers coming here, not reading that you solve it and trying to "help".