Bitcoin Forum

Bitcoin => Bitcoin Technical Support => Topic started by: CryptGo on March 25, 2018, 04:47:00 PM



Title: Was i phished?
Post by: CryptGo on March 25, 2018, 04:47:00 PM
Yesterday i transferred BTC from from GDAX to binance.  I copied the address from binance and pasted it into GDAX to perform the withdraw.  After not showing up for 12 hours I looked and realized it is a different address than my binance address that i sent it to.  This is the second time this has happened transferring from gdax.  last time it happened i lost some litecoin.  How can i prevent this and is there a chance i am somehow hacked leading to this happened?


Title: Re: Was i phished?
Post by: TryNinja on March 25, 2018, 04:52:20 PM
I can think of two things that may have happened:

1. The website you visited wasn't Binance.
2. You have a bitcoin address clipboard malware that changes the address that you have in your clipboard to the hacker's address.

Did you double check the address you pasted before sending the coins?
Can you run a malware scan to see if your computer is infected?
Can you check your browser history to see if you clicked in any fake Binance website?


Title: Re: Was i phished?
Post by: CryptGo on March 25, 2018, 05:25:22 PM
thank you so much.  im going to check those things.  the address i copied was definitely the address that "binance" showed.


Title: Re: Was i phished?
Post by: crairezx20 on March 25, 2018, 05:52:49 PM
There are many cases the same as yours here in the forum always check the url or ask here in the forum about fake Binance and malware that could automatically paste other bitcoin or litecoin address to unknown address. Much better to use a bootable virus and malware scanner to scan the whole files in your computer to safely use for the cryptocurrency.

You may check this other cases here https://bitcointalk.org/index.php?topic=1527250.0

some reply from this thread is helpful to make sure to read them first.

And check this for fake binance https://bitcointalk.org/index.php?topic=2699331.0


Title: Re: Was i phished?
Post by: buwaytress on March 25, 2018, 07:07:33 PM
If you haven't already done so, it's time to use your personal user account on your web browser. Use it to store bookmarks of every website you frequent (after verifying they're legit of course), so you lower your risk of visiting a "fake" site / phishing link. If this is the second time it's happened, don't wait for the third.

There's probably more secure ways but it's a simple step to start with. I use a Google account on Chrome for most web-related things now - even my 2FA - so even if I lose my device, I've just restore my account from another. Password's all memorised too, mnemonic seed style, works for me.


Title: Re: Was i phished?
Post by: CryptGo on March 25, 2018, 09:00:03 PM
I have checked through my history and there arn't any binance look alikes.  I remember thinking it wasn't the right address when it showed it but than i mistaking thought that it had generated me a new address but binance doesn't do that.  I'm going to read through the other posts and try to get to the bottom of this.  thanks all!!!


Title: Re: Was i phished?
Post by: Thirdspace on March 25, 2018, 09:49:48 PM
I copied the address from binance and pasted it into GDAX to perform the withdraw.  After not showing up for 12 hours I looked and realized it is a different address than my binance address that i sent it to.
2. You have a bitcoin address clipboard malware that changes the address that you have in your clipboard to the hacker's address.

most likely what happened is what TryNinja said, you have a clipboard malware
it was a common issue a few months ago, do a forum's google search on "clipboard malware"
next time make sure to check the first 6 letters and the last 6 letters of the address before clicking send


Title: Re: Was i phished?
Post by: bob123 on March 26, 2018, 08:42:14 AM
most likely what happened is what TryNinja said, you have a clipboard malware
~snip~

I don't think OP is a victim of clipping board malware.
OP wrote that he is sure that the address he sent the coins to is the same as shown by binance:

..the address i copied was definitely the address that "binance" showed.


So, if OP checked the address before sending and he copied the right address, i only see 2 options at the moment:

1) Phishing site
2) Malicious wallet installed

1) is self-explanatory
2) OP, what wallet were you using? Are you sure your wallet is a trusted one? Did you check the signature to verify its not a fake (malicious) wallet?






Title: Re: Was i phished?
Post by: Thirdspace on March 26, 2018, 12:41:16 PM
I don't think OP is a victim of clipping board malware.
OP wrote that he is sure that the address he sent the coins to is the same as shown by binance:

..the address i copied was definitely the address that "binance" showed.
---snip---
2) OP, what wallet were you using? Are you sure your wallet is a trusted one? Did you check the signature to verify its not a fake (malicious) wallet?
he said 2 conflicting statements, he is sure copied what binance showed but then said he realized it is a different address??
he's not using any wallet, I believe he's transferring between exchanges Binance and GDAX

... I copied the address from binance and pasted it into GDAX to perform the withdraw.  After not showing up for 12 hours I looked and realized it is a different address than my binance address that i sent it to.  This is the second time this has happened transferring from gdax.
how did you realize it? by looking your withdraw history or checking your transaction on an explorer?
remember addresses on exchanges are not yours, you shouldn't check transactions from your GDAX deposit address
if you send from GDAX to binance, check your deposit address on binance, the sender could be any address own by GDAX


Title: Re: Was i phished?
Post by: Maricel2017 on March 26, 2018, 12:49:27 PM
I can think of two things that may have happened:

1. The website you visited wasn't Binance.
2. You have a bitcoin address clipboard malware that changes the address that you have in your clipboard to the hacker's address.

Did you double check the address you pasted before sending the coins?
Can you run a malware scan to see if your computer is infected?
Can you check your browser history to see if you clicked in any fake Binance website?
This things you should consider before proceeding your transaction, there are some instances that you click wrong site instead of legit site you click is phishing site. Hope you will learn for your mistakes and will not happen again make extra careful of handling our fund also always double or multiple check the address which we are copied and paste.


Title: Re: Was i phished?
Post by: reflector on March 26, 2018, 06:37:50 PM
From Bob123 to others did not notice the confirmation by the op I think. There in last he confirms that issue on his side and thanked for Tyrantt since op does not used the right address mate.

I do not know why you know not checking the Op's reply in technical assistance thread and all.
Suggestion for op: Please look into the address multiple times when you want to transfer from the one wallet to another whether it exchange or other wallet. Please applies the same for all dude. Hope others would reply the other suggestion since the issue confirmed up.


Title: Re: Was i phished?
Post by: r1s2g3 on March 27, 2018, 04:20:33 AM
I have checked through my history and there arn't any binance look alikes.  I remember thinking it wasn't the right address when it showed it but than i mistaking thought that it had generated me a new address but binance doesn't do that.  I'm going to read through the other posts and try to get to the bottom of this.  thanks all!!!

You are not the first one that observed this, we already have a thread (https://bitcointalk.org/index.php?topic=1153338.0) for this.

Since you are sure that site is indeed binance then your system might be affected by Coin RPG Malware (https://www.reddit.com/r/Bitcoin/comments/29z742/help_freaking_outpasting_is_not_pasting_the/) or Faux Paste Malware (https://www.reddit.com/r/Bitcoin/comments/79s5nn/bitcoin_copy_faux_paste_malware_investigated/).

Some time back , I mentioned about this in one of my post (https://bitcointalk.org/index.php?topic=2970157.msg30515162#msg30515162)


11. While copy pasting your wallet address , recheck the address that is pasted is same what you copied. (you might be affected by Coin RPG malware)



Title: Re: Was i phished?
Post by: Mrt2018 on March 27, 2018, 10:23:24 AM
Are you sure you were in Binance website?

There are several fake Binance websites that have other characters like the one in this article for example:
http://thecompletecoinguide.com/no-hack-binance-like-a-boss/


Title: Re: Was i phished?
Post by: crypto-bit on April 01, 2018, 07:44:26 AM
Based on what i read regarding on your case.I think that you did not double check your address before sending your coin or maybe you are in hurry that why you forgot to check the correct addresses.I suggest that always double check before sending out your coin and you should check always the domain name of the website if it is correct so that you will not got to chaos.
 


Title: Re: Was i phished?
Post by: milewilda on April 01, 2018, 10:11:11 PM
I have checked through my history and there arn't any binance look alikes.  I remember thinking it wasn't the right address when it showed it but than i mistaking thought that it had generated me a new address but binance doesn't do that.  I'm going to read through the other posts and try to get to the bottom of this.  thanks all!!!
I guess theres no need to look for further post since the best answers and advise is already being given which is actually right.If you sure that you copied the right address on where binance do give and when you paste it out into withdrawal input bar and shows others non-familiar address then definitely you are having a malware into your computer which this issue is already being experienced back in the past victimizing lots of people losing out lots of money.For now the suggestion would be either a complete scan of your pc if the problem persist then better to do a full wipe or reformat.