Bitcoin Forum

Bitcoin => Armory => Topic started by: bissell on August 04, 2014, 07:01:33 PM



Title: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: bissell on August 04, 2014, 07:01:33 PM
Hi everyone, just to say all is now 100% perfect in the Armory world!!! Got my problem sorted and am going to stop hitting the beers as much!!

Goatpig is a total BTC STAR and if I ever meet him I will tell him so!! and that also applies to member ForgottenPassword Many many thanks!!!!!!

Thanks to everyone who has helped me on this forum, you are all truly wonderful people!!

Many many thanks.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: goatpig on August 04, 2014, 07:11:54 PM
There's a support channel for these matters. If you still choose to resort to a forum post, the least you could do is to provide proof of what you are purporting, and attach some log files.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: moko666 on August 04, 2014, 07:13:30 PM
thats why always trust and use the originals
bitcoin qt wallet is better then others
only issue is big block chain


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: doug_armory on August 04, 2014, 07:15:14 PM
There's a support channel for these matters. If you still choose to resort to a forum post, the least you could do is to provide proof of what you are purporting, and attach some log files.

In addition, you could tell us where exactly you downloaded Armory. I believe there was an issue awhile back where somebody registered a similar-sounding domain and uploaded a version that may or may not have been altered. (I don't recall the exact details offhand.)


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: TimS on August 04, 2014, 07:17:57 PM
Sounds highly unlikely. Have you made sure that you generated enough addresses on your watch-only wallet? Maybe the addresses they were sent to belong to your offline wallet.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: goatpig on August 04, 2014, 07:24:16 PM
Sounds highly unlikely. Have you made sure that you generated enough addresses on your watch-only wallet? Maybe the addresses they were sent to belong to your offline wallet.

That's a possibility, but unlikely. Unless he stopped using his original online machine and started using a second machine to extend the chain past the first 100 pre-computed addresses, he would not have an off sync WO chain on the first machine.

Still, looking at single address balance on Blockchain.info is not conclusive. BC.i is completely oblivious to the wallet's structure.

I'm still waiting for a log file to pronounce anything, but since he mentioned Armory crashed while syncing, it is very likely he isn't seeing his wallet's valid balance, nor which addresses have UTXOs, thus possibly researching addresses on BC.i that he depleted a while ago.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: goatpig on August 04, 2014, 09:18:28 PM
I can't tell you a thing without seeing a log file.

In Armory's datadir folder, you'll find armorylog.txt and armorycpplog.txt. Post both of these.

The default datadir can be found here:

Windows -> C:\Users\*myusername*\AppData\Roaming\Armory
Linux -> ~/.armory
OSX -> ask Doug, I got no idea


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: Sophokles on August 04, 2014, 10:10:23 PM

Even now when I load my Watch only wallet it says my correct balance but then totally freezes after loading is complete when I click on the transactions tab, so I checked my addresses on Blockexplorer today and 3 different addresses have been TOTALLY wiped out for 4 BTC.


I find this very hard to believe. Which version of Armory did you use? Can you post the 3 addresses the 4 BTC were taken from?
How many more addresses did you have in that watching wallet? How many BTC left?


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: Abdussamad on August 04, 2014, 11:18:44 PM
Looks like he's confused by change addresses. Wallet shows the correct balance but then he had to go and check the raw addresses on block explorer. Confusion and panic ensues.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: ForgottenPassword on August 04, 2014, 11:24:30 PM
Yes it sounds like your not understanding how the bitcoin transactions work with change addresses.

More info on change addresses here:
https://en.bitcoin.it/wiki/Change

If what you say is true I doubt you were hacked unless you downloaded a modified copy of Armory, a hacker got hold of a wallet backup, a hacker was listening on your network when you printed a wallet backup and you didnt use SecurePrint or a very advanced adversary broke into your house and made modifications to the PC which you generated the Armory wallet on or modified it before you purchased it.

Those are the only ways you could've been hacked apart from backdoors in Armory or your OS.

What version of Armory were you running?


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: ForgottenPassword on August 04, 2014, 11:37:45 PM
How do I make sure the next copy of Armory I download is legit?

Verify the signature using PGP. Instructions here: https://bitcoinarmory.com/download/

Has this ever been Known to have happened before?

There are no known weaknesses in Armory. I don't know if anyones ever reported it but I would assume users have had funds stolen from Armory due to their own errors.

Surely a hacker would have cleaned out my other BTC as well if they could, it`s been 3 weeks now?

Armory is deterministic so it'd be highly unlikely that an attacker was ONLY able to compromise some of your addresses in your wallet. I doubt even less you were hacked.


Why does my balance show as correct as soon as my WO has finished scanning the transaction history but as soon as I click on the transactions tab it freezes and it is impossible to now see any of my transactions when last month it worked perfectly?

Actually I think this may be a bug. This also happened to me recently. I couldn't figure out why and didn't have time to investigate but I deleted the armory data directory, restored my wallet and it worked. If you think you were hacked you should NOT delete the directory or use the PC if possible as you'll want to preserve as much evidence as possible.


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: Bit_Happy on August 05, 2014, 02:31:58 AM
.....
This has been the first time I have posted on this forum but I have been reading it daily for 2 years now and all of your support and concern is really touching and I only hope that I can help anyone of you 1 day in the future. Many thanks.

You could edit the thread title.  :)


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: ForgottenPassword on August 05, 2014, 02:32:13 AM
Also is it safe to post these 3 missing BTC addresses on this forum for anyone to check, because if the answer is yes I will gladly post them.

If you post them people will be able to see your transactions. It's bad for your privacy as someone might be able to see what you've been buying, but not for your security. Nobody will be able to steal your BTC without the private keys if that is what you are asking.

If you don't mind the privacy infringement it is perfectly safe to post them. Every used address is already public in the blockchain. Make sure the addresses begin with a 1 before posting them (NOT a 5!).


Title: Re: ARMORY WALLET HACKED!!!! BEWARE ALL USERS!!!
Post by: Bit_Happy on August 05, 2014, 02:42:58 AM
Hi, I`m going to edit the thread title now.

Much better, thanks.  :)


Title: Re: ARMORY WALLET CONCERNS.
Post by: ForgottenPassword on August 05, 2014, 03:00:29 AM
Hi, the wallet addresses are,

You are lucky! All of your funds are safe and sound. All of those balances are fully correct (in fact each address has 0.00000001BTC more), you weren't hacked at all.


Try reinstalling a fresh new copy of armory. Be sure to verify it with the PGP signature this time and be sure you have a wallet backup before you uninstall/delete anything. Rename the ~/.armory directory to something else like ~/.armory.old before you launch your new armory for the first time and restore your wallet. This should fix any problems you have.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: ForgottenPassword on August 05, 2014, 03:55:40 AM
Glad everything worked out! Good to hear a happy ending for once.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: goatpig on August 05, 2014, 10:22:26 AM
So I wake up this morning to find bissell's ticket on the support channel, with his log file. Let's say there is a lot of pebkac going on here, but so far it seems under control.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: bissell on August 05, 2014, 11:40:55 AM
Hi everybody,

bissell PEBKAC is my new name and I`m going to wear it as a badge of shame for the rest of my life for even doubting this wonderful software that is Armory!!

In my defence though I am as blind as Mr. Magoo and I cannot hardly see my hand in front of my face especially after a few beers that are needed to get me through my wifes monthly period tantrums which reached a crescendo yesterday just as I thought my addresses had been compromised, she was screaming, shouting, swearing etc etc, maybe another day I would have been a bit more attentive to what was actually going on!!

What I can`t understand though is how or why, somebody got hold of my 3 addresses from my WO wallets to deposit 00000001 into them when they have never ever been online at all, not even checked on Blockchain info until yesterday etc, they have always just been in my WO wallets.

Why and how could someone do this? I have never heard of this happening before, does this mean my WO wallet privacy has been breached??

Has any other user ever heard of this happening before?

Version 0.88.1 was working perfectly until a month ago but now it just refuses to work, how do I download the latest version and can I just do it with my WO computer? because I destroyed the original PC that I first created my offline wallet on.

Thanks once again Goatpig and the rest of the forum members who took the time to reply to me.

PEBKAC.
 


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: ForgottenPassword on August 05, 2014, 11:45:12 AM
Somebody sent 1 satoshi to thousands of bitcoin addresses. People do this from time-to-time because it doesn't cost them much to do, hard to think of a reason really, sometimes it can be a mistake or technical bug on their end, sometimes for no obvious reason at all. It's nothing to be concerned about - you can't stop someone from sending you free BTC. I have received tons of these over the years, some much larger than 1 satoshi.

Every bitcoin address that has received coins is public in the blockchain, we just have no idea who they belong to.

how do I download the latest version and can I just do it with my WO computer? because I destroyed the original PC that I first created my offline wallet on.

Yeah you can do it on your WO computer so long as you restore the WO wallet on it and not the real one.

https://bitcoinarmory.com/download

Also read the part about verifying signatures.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: bissell on August 05, 2014, 11:58:53 AM
Thanks for your reply, I really appreciate it!!


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: goatpig on August 05, 2014, 12:19:15 PM
Let me stress that you should listen to my advice and move your coins to a proper WO wallet. You should create that new wallet on an offline machine as well. Can't you put some old parts together to get something to boot a live Linux?

ForgottenPassword put you in the right direction for the download. Once you have downloaded 0.92.1, let it do its thing, and you should soon be able to witness your actual balance.

As for the satoshis you received, this is called dust. The main purpose is to link your addresses together and reveal your wallet's structure. The attack is undiscriminated so you shouldn't feel directly targeted. It is easily mitigated: don't consume the dust UTXOs and avoid address reuse.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: ForgottenPassword on August 05, 2014, 12:34:48 PM
As for the satoshis you received, this is called dust. The main purpose is to link your addresses together and reveal your wallet's structure. The attack is undiscriminated so you shouldn't feel directly targeted. It is easily mitigated: don't consume the dust UTXOs and avoid address reuse.

These addresses already have a balance on them. Sending them dust wouldn't aid in revealing the wallets structure unless they were previously used but now empty addresses.

Let me stress that you should listen to my advice and move your coins to a proper WO wallet. You should create that new wallet on an offline machine as well. Can't you put some old parts together to get something to boot a live Linux?

Yes you should do this. Keeping your wallet as a paper wallet like you are doing is generally a bad idea.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: goatpig on August 05, 2014, 12:58:41 PM
These addresses already have a balance on them. Sending them dust wouldn't aid in revealing the wallets structure unless they were previously used but now empty addresses.

I was under the impression he was talking about the addresses he found empty. There is also sort of a denial of service attack associated with spending dust.


Title: Re: ARMORY WALLET IS THE BEST!! THANKS EVERYONE!!!!!
Post by: bissell on August 06, 2014, 03:36:59 PM
Hi member Forgotten Password,

please can you tell me why this is a bad idea?

many thanks.