Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: Tirapon on October 03, 2014, 11:27:56 AM



Title: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: Tirapon on October 03, 2014, 11:27:56 AM
http://www.reddit.com/r/Bitcoin/comments/2i5gzg/largescale_phishing_attack_via_satoshi_spam/


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: medUSA on October 03, 2014, 11:36:30 AM
Seems to be a genuine phishing attack. Read OP's link above. ^^^

Quote
Typing in a valid Blockchain Identifier brings you to "https://bbckchain.info". Obviously, do not click this link.


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: TrailingComet on October 03, 2014, 11:41:39 AM
Thanks for the cautionary post,I have 2FA enabled so should hopefully be safe if I take the usual precautions


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: Tirapon on October 03, 2014, 11:41:47 AM
https://blockchain.info/address/15QwSkSFLGEaENDzRHBDAhQeTzjUT36ESL?offset=2100&filter=0

The address started sending out dust transactions to multiple addresses yesterday. Fortunately it looks like the link (New Message - bitmsqr.com) has been removed (by blockchain.info staff?)


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: H.W.Z on October 03, 2014, 11:52:56 AM
Go to blockchain wallet and always type by ourself, make sure the address is blockchain.info


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: Q7 on October 03, 2014, 12:05:55 PM
I just reposted this on my local bitcoin community forum. Hopefully nobody fell for it


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: Onestopbrokers Directory on October 03, 2014, 12:10:02 PM
Thanks for posting about this.


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: bitllionaire on October 03, 2014, 12:10:54 PM
but how do they try to get your data? I can't see it


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: Tirapon on October 03, 2014, 12:25:07 PM
but how do they try to get your data? I can't see it

https://blockchain.info/address/15QwSkSFLGEaENDzRHBDAhQeTzjUT36ESL?offset=2100&filter=0

The address started sending out dust transactions to multiple addresses yesterday. Fortunately it looks like the link (New Message - bitmsqr.com) has been removed (by blockchain.info staff?)


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: a447513372 on October 04, 2014, 05:07:43 AM
https://blockchain.info/address/15QwSkSFLGEaENDzRHBDAhQeTzjUT36ESL?offset=2100&filter=0

The address started sending out dust transactions to multiple addresses yesterday. Fortunately it looks like the link (New Message - bitmsqr.com) has been removed (by blockchain.info staff?)
This is a real weakness of the 'tagging' system of blockchain.info as they let you tag your address as anything you wish in an automated fashion.

I would say this is a prime example as to why you should only log into any site after you have personally typed in the address into your address bar


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: twister on October 04, 2014, 06:59:54 AM
Seems to be a genuine phishing attack. Read OP's link above. ^^^

Quote
Typing in a valid Blockchain Identifier brings you to "https://bbckchain.info". Obviously, do not click this link.

Wait, I don't understand this part.  ???

If I copy paste my identifier, the one which is provided when you make a blockchain wallet, it can't take u to bbockchain mentioned above, can it?

I mean copy pasting the entire link into the address bar, blockchain.info/wallet/ --identifier--


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: pabpete on October 05, 2014, 02:07:35 PM
Thanks for the heads up! ;D


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: chanz on October 05, 2014, 02:47:17 PM
I don't even have a blockchain.info wallet but i got my 0.0001 BTC anyways :P

They are getting addresses from incoming transactions on blockchain no matter which wallet you have.
if it happens to be a transactions going on from your wallet you got one.

I got got one yesterday too but now the tagged link "bitmsqr.com" and the message have been removed by blockchain
and it's confirmed too now. So, just be careful what you click at.


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: BTCmoons on October 05, 2014, 04:04:14 PM
Seems to be a genuine phishing attack. Read OP's link above. ^^^

Quote
Typing in a valid Blockchain Identifier brings you to "https://bbckchain.info". Obviously, do not click this link.

Wait, I don't understand this part.  ???

If I copy paste my identifier, the one which is provided when you make a blockchain wallet, it can't take u to bbockchain mentioned above, can it?

I mean copy pasting the entire link into the address bar, blockchain.info/wallet/ --identifier--
When you log into your blockchain.info wallet you should manually type in the address into your browser (I would not even use bookmarks) and if your identifier is not prefilled (because of the lack of cookies) then you should copy/paste your identifier into the identifier field to login.


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: TradeSmart on October 05, 2014, 04:16:20 PM
Received this as well. Hopefully no one will fall for this.


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: ofortuna on October 05, 2014, 09:09:11 PM
Seems to be a genuine phishing attack. Read OP's link above. ^^^

Quote
Typing in a valid Blockchain Identifier brings you to "https://bbckchain.info". Obviously, do not click this link.

Wait, I don't understand this part.  ???

If I copy paste my identifier, the one which is provided when you make a blockchain wallet, it can't take u to bbockchain mentioned above, can it?

I mean copy pasting the entire link into the address bar, blockchain.info/wallet/ --identifier--
When you log into your blockchain.info wallet you should manually type in the address into your browser (I would not even use bookmarks) and if your identifier is not prefilled (because of the lack of cookies) then you should copy/paste your identifier into the identifier field to login.

Excellent tips


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: mnmShadyBTC on October 05, 2014, 11:29:53 PM
I don't even have a blockchain.info wallet but i got my 0.0001 BTC anyways :P

They are getting addresses from incoming transactions on blockchain no matter which wallet you have.
if it happens to be a transactions going on from your wallet you got one.

I got got one yesterday too but now the tagged link "bitmsqr.com" and the message have been removed by blockchain
and it's confirmed too now. So, just be careful what you click at.
blockchain.info is one of (if not the) most widely used wallet service used. I don't think they were doing this but it is possible to look at individual transactions and see that a TX was first relayed via blockchain.info and infer that the blockchain.info wallet is being used


Title: Re: Caution - Large scale phishing attempt (targeting blockchain.info wallets)
Post by: twister on October 06, 2014, 03:11:00 AM
Seems to be a genuine phishing attack. Read OP's link above. ^^^

Quote
Typing in a valid Blockchain Identifier brings you to "https://bbckchain.info". Obviously, do not click this link.

Wait, I don't understand this part.  ???

If I copy paste my identifier, the one which is provided when you make a blockchain wallet, it can't take u to bbockchain mentioned above, can it?

I mean copy pasting the entire link into the address bar, blockchain.info/wallet/ --identifier--
When you log into your blockchain.info wallet you should manually type in the address into your browser (I would not even use bookmarks) and if your identifier is not prefilled (because of the lack of cookies) then you should copy/paste your identifier into the identifier field to login.

Yes, I do just that, I type the website name in the address bar and copy-paste my identifier into the sub-field, I assumed it was the safest way. Thanks for clearing that for me.