Bitcoin Forum

Economy => Service Discussion => Topic started by: starik69 on April 11, 2013, 08:57:35 AM



Title: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 08:57:35 AM
I have a wallet on blockchain.info with address 1AeuWyXeQvdG1eDqht1hAc3w4t2duPU83G. Today i woke up and see that most of my bitcoins have gone with this transaction
https://blockchain.info/en/tx/c84f9ea080b9e6aad84af6daa7c6b018c62caf9615aa583ccfe5ead6228b3f7c

I never did it myself, so somebody guessed my 15 letters password and stole my coins, i think in one bunch among with 108.8BTC from other blockchain.info wallets.

Be careful!


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: refaelsh on April 11, 2013, 08:59:32 AM
I have a wallet on blockchain.info with address 1AeuWyXeQvdG1eDqht1hAc3w4t2duPU83G. Today i woke up and see that most of my bitcoins have gone with this transaction
https://blockchain.info/ru/tx/c84f9ea080b9e6aad84af6daa7c6b018c62caf9615aa583ccfe5ead6228b3f7c

I never did it myself, so somebody guessed my 9 letters password and stole my coins, i think in one bunch among with 108.8BTC from other blockchain.info wallets.

Be careful!
Dude, the link is in Russian, not every body understands Russian (I do :-)).


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: z12 on April 11, 2013, 09:01:10 AM
Sorry for your loss.. So it seems bitcoin has gathered a lot of hacker attention.
It seems there is no need for goverments to waste millions to try to destroy bitcoins, hackers are doing it for them for free.
What Operating system were you using?

And change /ru/ to /en/ for english version


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 09:06:03 AM
My system is W8 x64, chrome browser. I dont think t have some troyan or keylogger.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: Akka on April 11, 2013, 09:10:25 AM
My system is W8 x64, chrome browser. I dont think t have some troyan or keylogger.

Blockchain Wallets with weak passwords get "hacked" all the time.

Did you use a weak password? 1 or 2 regular word and a view numbers for example?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: fr33d0miz3r on April 11, 2013, 09:18:50 AM
My system is W8 x64, chrome browser. I dont think t have some troyan or keylogger.

Sorry for offtopic, but... are you from Tver?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: refaelsh on April 11, 2013, 09:21:05 AM
I have a wallet on blockchain.info with address 1AeuWyXeQvdG1eDqht1hAc3w4t2duPU83G. Today i woke up and see that most of my bitcoins have gone with this transaction
https://blockchain.info/en/tx/c84f9ea080b9e6aad84af6daa7c6b018c62caf9615aa583ccfe5ead6228b3f7c

I never did it myself, so somebody guessed my 15 letters password and stole my coins, i think in one bunch among with 108.8BTC from other blockchain.info wallets.

Be careful!
I suggest that next time You use the LastPass plugin for Chrome and a 100 character password. That's what I do.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 09:23:03 AM
Yes, now i think my password may be weak, it was some non obvious words and i hoped it was difficult to bruteforce 15 letters.

I am not from Tver.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: 🏰 TradeFortress 🏰 on April 11, 2013, 09:23:25 AM
Looks like possibly related to whiskers75?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 09:50:34 AM
Yes, whiskers75 address 1whiskD55W4mRtyFYe92bN4jbsBh1sZut is somehow related. It is also here - https://bitcointalk.org/index.php?topic=173134.0


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: demzie on April 11, 2013, 09:52:59 AM
And the two factor email auth? Dont you use that?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 09:57:18 AM
Nope, was only one password. Its not a big loss for me, i collected some free bitcoins from various sites that give them, so was not especially worried about security.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: dli7319 on April 11, 2013, 10:27:36 AM
me too, how??


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: doobadoo on April 11, 2013, 10:30:27 AM
how do they even get a copy of the wallet?  and a 15 character pass is pretty hard, unless you use a movie title, or  famous quote.   several random words is hard to beat, or am i wrong on that?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 10:35:44 AM
In my case words were not random, but it was not some recognizable or having some sense phrase.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: doobadoo on April 11, 2013, 10:39:35 AM
In my case words were not random, but it was not some recognizable or having some sense phrase.

yeah then its impossible it was hacked cause it sounds random enough.  was it something like   dogpeesinfamilypot?  or samgoestothedrycleaners?

that might as well be as random as it gets.  and 15 char is a lot to brute force.  some one had ur key strokes and clip board with the link to blockinfo.

otherwise we are talking man in the middle, and thats just not very likely.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: dli7319 on April 11, 2013, 10:45:18 AM
I'm guessing wallets weren't encrypted


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 10:48:50 AM
My passphrase had some short real words, not obvious, with no sense, but arranged in some simple algorithm. Now i think it could be guessed.
Another way could be not hacking password, but something like stealing session cookies, my bad i dont know much about such things.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: dli7319 on April 11, 2013, 10:51:19 AM
No way the passwords of that many ppl was guessed


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: doobadoo on April 11, 2013, 10:59:08 AM
did you click any links in the btc-e chatroom, or other bitcoin chatrooms while logged into blockinfo?

use firefox, use noscript


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 11:01:54 AM
did you click any links in the btc-e chatroom, or other bitcoin chatrooms while logged into blockinfo?
Yes, that could have happened.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: doobadoo on April 11, 2013, 11:09:20 AM
did you click any links in the btc-e chatroom, or other bitcoin chatrooms while logged into blockinfo?
Yes, that could have happened.
BINGO!  You caught a javascript keylogger, or a script the performed a cross site scripting attack, pulled your wallet out of the jscript running while you had blockchain.info open in another tab.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: doobadoo on April 11, 2013, 11:13:59 AM
when logged into a bitcoin site that contains your balance run FF with NoScript addon installed (set it to bans scripts globally), then "allow" the ones that are needed for gox and blockchain info, all others shall be banned. Bitcointalk.org is safe too.  Your banking site scripts are ok.  google.com is okay and might need to be allowed too.  everything else by default will be banned.

Use that browser only for your financial stuff.  Browse in chrome for everything else.  Consider linux or os x.  you can buy a $50 external usb hdd and install some kind of linux on that (or repartition your boot drive if your good at stuff like that).  Just run bitcoin on that linux install and run all the security patches.  Use FF on that, just like i told you.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: z12 on April 11, 2013, 11:24:20 AM
Now that you mention it, i just checked my browsing history
The suspicious websites i visited in last week:
Code:
Cryptocoinexplorer.com <= i clicked this from btc-e
bitcoin.clarkmoody.com
bitcoinrush.p4o.net
zerohedge.com
xcannabis.com
wallet.litehosting.eu
thebitcoinchannel.com
coinad.com
cryptocoincharts.info
kamikaze.litecoinland.com
litecoin-store.com
litecoingames.com
litefaucet.com
m-obmen.com
medium.com
minecraftcc.com
otn.dsparking.com
weusecoins.com

These are the domains i visited from last week which i don't instantly trust, Some of them are well known btc/ltc services...
Though my blockchain wallet wasn't touched and i still have my 0.0000105 btc (!) but i lost access to my btc-e account ..
Could one of these install a keylogger on my computer? i don't think so
Edit: Also, i'd like to include that i use lastpass autofill feature to login, i don't think a normal keylogger could log lastpass logins.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: 🏰 TradeFortress 🏰 on April 11, 2013, 11:27:48 AM
Would have to be XSS [or other malware].


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 11:32:22 AM
BINGO!  You caught a javascript keylogger, or a script the performed a cross site scripting attack, pulled your wallet out of the jscript running while you had blockchain.info open in another tab.
I guess if it was a script after reloading os and clearing browser cache it must be gone?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: uMMcQxCWELNzkt on April 11, 2013, 11:38:23 AM
Perhaps it is also possible that you visited a cloned website with a slightly different Domain? This kind of scam happens all the time with Paypal and even student loan websites.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 11:56:11 AM
No, sure it was original site.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: whiskers75 on April 11, 2013, 12:05:25 PM
Yes, I can confirm being hacked. Well, I have 0.1 BTC in Pyramining, so I just need to hit the owner up for that.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: Logik on April 11, 2013, 12:14:44 PM
Nobody has their password 'hacked'. You get exploited through a 0 day through Java or Flash in your browser, or through a file download, and then the program just sits and waits.

- Never re-use your blockchain password for anything else. That's just silly.

- Enable 'click to play' on all browser plugins. There is no pure JavaScript exploit, only browser plugin exploits. Enable browser plugins by default = you're hacked

- Enable one time password 2 factor auth to your PHONE. Not your @#$% email. That's completely redundant. If someone has access to your machine then they have access to the email. No 2 factor to your phone = you're hacked.

If anyone is hit by this then the malware is still going to be on your computer so you need to nuke it from orbit or buy a new computer.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: Logik on April 11, 2013, 12:16:55 PM
A XSS attack on Blockchain.info is possible but would be WAY more serious and so bad to the point of me thinking it shouldn't be possible.

The only other possibility is a compromised browser extension (chrome app) but it's slightly far fetched.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 12:18:20 PM
You get exploited through a 0 day through Java or Flash in your browser
Flash and java were disabled.
- Never re-use your blockchain password for anything else. That's just silly.
Password was unique.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: 🏰 TradeFortress 🏰 on April 11, 2013, 12:18:29 PM
A XSS attack on Blockchain.info is possible but would be WAY more serious and so bad to the point of me thinking it shouldn't be possible.

The only other possibility is a compromised browser extension (chrome app) but it's slightly far fetched.
Pretty sure it's Java now.

hmm? Was notifications enabled?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: JJJJust on April 11, 2013, 12:30:46 PM
I just recently (a week or so ago) wiped and reinstalled Debian, haven't logged into my blockchain wallet on my PC since then... and still got my fraction-of-a-coin swiped. Not sure I buy the XSS explanation.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 12:43:45 PM
hmm? Was notifications enabled?
No, in my case only security option was password.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: casascius on April 11, 2013, 07:35:57 PM
I know someone personally whose blockchain.info funds ended up directly as a txin to this transaction, who wrote me an e-mail today complaining that his 4 or so BTC disappeared.

From the looks of the transaction, one of the txin's belongs directly to him, and none of the others are part of his wallet.  Funds went straight from his address directly into this combined transaction.  In other words it looks like his private key was stolen right out of his account, rather than someone sending funds directly from his account using the web UI.

I wonder if he had a weak password and the encrypted database of blockchain.info wallets has been compromised?  Normally with a keylogger you'd expect somebody to go and log into accounts one by one and steal funds by hand as the accounts are discovered.  The fact that this is a huge combined transaction suggests to me something more sophisticated than that!

EDIT/FOLLOWUP:  I asked him if he would be willing to share his password with me for me to assess its strength against brute force hacking.  His password was 14 characters but, in my opinion, would have been vulnerable to a dictionary attack.  Makes me think somebody out there might have stolen encrypted wallets and is bruteforcing passwords.

ALSO: I have a small amount of coin in a BlockChain wallet with a deliberately weak password.  I don't have the wallet identifier handy, but will soon.  Will be able to check.  It's a wallet I don't use much, so if it's still safe, it could indicate keylogger is more likely than database breach.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 11, 2013, 08:05:24 PM
The fact that this is a huge combined transaction suggests to me something more sophisticated than that!
I agree, hacker definitely stole privkeys from blockchain addresses and used them to combine theft in one transaction.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: MWNinja on April 12, 2013, 01:22:32 AM
Did the ones that got hacked have an easily guessed alias?  Dictionary attack on aliases would give an attacker a bunch of encrypted wallets to offline brute force.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: zkay on April 12, 2013, 01:31:46 AM
Not sure if it's related but I keep getting texts with my current OTP login code for blockchain when I'm at work or otherwise not even accessing the site. Typically it will only send those when it sees someone trying to access your login credentials.

Has anyone with 2FA been compromised?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: casascius on April 12, 2013, 05:24:10 AM
I use BlockChain.info all the time but my advice is:  Keep Bitcoins On Paper Wallets!

Blockchain.info is great for transacting, but I simply don't trust web wallets.  For trivial ad-hoc stuff, I will import a paper wallet, do my business, and send any change back to another paper wallet.  Nothing against BlockChain.info, in fact I like that they make it so convenient to do what I want to do the way I want to do it (such as scanning bitcoin addresses thru webcam)... it's just... in my view, insane to leave bitcoins you want to keep, on a web wallet.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: starik69 on April 12, 2013, 08:24:33 AM
Did the ones that got hacked have an easily guessed alias? 
My alias was same as BTC-e nickname.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: Mike Hearn on April 12, 2013, 09:01:35 AM
My understanding is that blockchain.info will vend your (encrypted) wallet given only a username. Because it uses JavaScript for all its crypto and JavaScript is very slow, the KDF is 10 rounds of SHA1 which is extremely weak.

If my understanding is correct this means anyone who can guess usernames (not passwords) can brute force the encryption, potentially at very high speeds using their GPUs. I haven't seen any software that can do that and don't know enough about GPU programming to know if it's easy to check the resulting keys for correctness, but certainly the KDF in use is not any obstacle to brute forcing. And unfortunately it cannot be, because the nature of blockchain.info is it runs entirely within the browser.

If you have an (unhacked) b.i account, I'd suggest downloading the current beta/snapshot release of MultiBit (0.5.9), creating a new wallet, encrypting it and then sending your money to it. Don't import your b.i wallet for obvious reasons, you'd need to move the money with a real transaction. MultiBit is using a very high number of scrypt iterations that should be a lot more robust against brute forcing.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: JJJJust on April 13, 2013, 02:56:26 PM
After my bitcents were stolen, I turned on logging in my account and didn't bother changing my password. Whatever happened, somehow, SOMEBODY managed to get my blockchain password and has been having a snoop through tor.

Today 01:03:15   get account settings   37.221.170.49   Mozilla/5.0
Today 00:06:41   get account settings   204.124.83.132   Mozilla/5.0
2013-04-12 21:43:37   get account settings   37.130.227.133   Mozilla/5.0


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: mikesheadroom on April 14, 2013, 01:49:54 PM
I was one of the initial victims.  Subsequently I ran multiple malware scans, changed my password, enabled two factor authentication on my Blockchain wallet and installed no script.  I just had my account emptied again.
Logging indicates it was through TOR.
Update:  At this point, I am just completely abandoning the wallet and no longer going to access my new wallet from the potentially compromised computer until a full system wipe is performed.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: HostFat on April 16, 2013, 03:15:22 PM
I hope to hear some news from piuk about this topic ...


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: zebedee on April 17, 2013, 10:49:17 PM
A friend of mine had 7 coins taken from her blockchain wallet.  Like others have reported, oddly the thief left 1 BTC behind.

  https://blockchain.info/tx/df97a2c8722d8980fe87d9696a1bc176cdb818a8fbac253b2c7a2dd315cf4393

I suspect her password was brute-forced, it wasn't particularly strong (but not stupidly easy either).

The facts:

  • Not logged on even once to blockchain.info since wallet was setup last October.  So it's not like the password was keylogged or anything like that.
  • Wallet backup was mailed to her yahoo.co.uk email last October.
  • No wallet alias was used.
  • The transaction that stole the coins returned the change to the original address.  This is typical blockchain.info behaviour.  So I'd guess the thief used blockchain.info to send the coins (rather than crafting their own transaction from the private key).

Does anything above match others' experiences with blockchain thefts?  How can the attacker get hold of the wallet URL?

My understanding is that to take coins, a thief needs both a wallet URL and the password.  What I don't understand is where they are getting the wallet URLs from.

I have only four ideas:

  • Either blockchain.info's database of encrypted wallets has been stolen, or
  • Her yahoo.co.uk email has been hacked, or
  • Someone inside yahoo that works with email there has been trawling for emailed blockchain URLs or backups
  • Web browser malware is searching bookmarks for wallet URLs (I've not yet confirmed she had a bookmark for it, I suspect she did)

Any ideas or other ways of pulling this off?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: 🏰 TradeFortress 🏰 on April 18, 2013, 11:34:27 AM
Browser history check?

Does she have an alias set up?


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: lunarboy on April 18, 2013, 01:52:05 PM

I too have noticed several unauthorised attempts at my account and was wondering how this was possible?
I used to have a similar forum username to my blockchain.info account but have since changed it.

What is current advice? Should I also start a fresh and create a new account or is the change of account name and the creation of a new set of BTC addresses sufficient?

The Bitcoin ecosystem seems to be on a full scale war footing at the moment.  :o


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: zebedee on April 18, 2013, 02:18:07 PM
My friend had no browser bookmarks, and there is no blockchain url at all in her browser history.  So to get the URL one of the following must be true:

  • Her yahoo email is compromised
  • Yahoo have a crooked employee trawling email for URLs
  • blockchain.info has a crooked employee
  • blockchain.info's encrypted wallet database is out in the wild

I see no alternatives.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: crazy_rabbit on April 18, 2013, 02:58:56 PM
I think your friends computer is hacked, not blockchain.info. If you read how their system works (and it's open source) they don't have a copy of your unencrypted wallet. They don't even have a copy of your password (hence if you lose it, you're screwed). The encrypted wallet sits on their server and then your computer decrypts it in the browser.

It's still possible to 'hack' this scenario, but from all angles it's 99.9% that the fault lies somehow with your friends computer and not blockchain.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: zebedee on April 18, 2013, 03:19:15 PM
I think your friends computer is hacked, not blockchain.info. If you read how their system works (and it's open source) they don't have a copy of your unencrypted wallet. They don't even have a copy of your password (hence if you lose it, you're screwed). The encrypted wallet sits on their server and then your computer decrypts it in the browser.

It's still possible to 'hack' this scenario, but from all angles it's 99.9% that the fault lies somehow with your friends computer and not blockchain.
I think that's unlikely - the URL doesn't exist on her machine - not in browser history, no bookmark etc.  She's never visited it since setup over 6 months ago.  I think the URLs have been obtained somewhere else, likely blockchain.info itself.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: optimator on April 18, 2013, 03:55:44 PM
I hate to call it... But the pattern seems very obvious.

Blockchain.info is under a ddos attack - they are unsure how their server ip was leaked.
Multiple wallets with strong-ish passwords have funds disappear.
The funds disappear by access to the private key.

Im not familiar with the exact workings of the blockchain wallet, but I would be very inclined to move the funds to a paper wallet for the near term until this is sorted out.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: crazy_rabbit on April 18, 2013, 07:39:40 PM
It's up and it's working fine. Before spreading FUD you should read the source code behind Blockchains open source software. If they were truly "hacked" it means only the inconvenience of you having to load your wallet backup (You DO backup right?) into your own computer with your own client.

So it's not the end of the world by any means. Even in a total meltdown you still have your funds- and they don't. Thats how it works.


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: ErebusBat on April 18, 2013, 10:14:30 PM
It's up and it's working fine. Before spreading FUD you should read the source code behind Blockchains open source software. If they were truly "hacked" it means only the inconvenience of you having to load your wallet backup (You DO backup right?) into your own computer with your own client.

So it's not the end of the world by any means. Even in a total meltdown you still have your funds- and they don't. Thats how it works.
+1


Title: Re: My (and i think some others) blockchain.info wallet was hacked
Post by: demzie on April 19, 2013, 05:29:28 AM
It's up and it's working fine. Before spreading FUD you should read the source code behind Blockchains open source software. If they were truly "hacked" it means only the inconvenience of you having to load your wallet backup (You DO backup right?) into your own computer with your own client.

So it's not the end of the world by any means. Even in a total meltdown you still have your funds- and they don't. Thats how it works.

+1