Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: tintumon on March 01, 2014, 07:06:19 AM



Title: My poloniex account got hacked. Check yours
Post by: tintumon on March 01, 2014, 07:06:19 AM
I was shocked to see that my poloniex account got hacked yesterday, and the hacker withdrew all my BTC and LTC.

The strange thing is, poloniex used to send me confirmation on withdrawals, but not when the hacker withdrew my coins.

Please check your account and make sure you are not affected.



Title: Re: My poloniex account got hacked. Check yours
Post by: username here on March 01, 2014, 07:45:29 AM
If you are keeping coins on an exchange, you need to have 2FA set up. 


Title: Re: My poloniex account got hacked. Check yours
Post by: tintumon on March 01, 2014, 08:41:56 AM
yup, lesson learned the hardway


Title: Re: My poloniex account got hacked. Check yours
Post by: Cryptock on March 01, 2014, 11:54:58 AM
Keylogger?


Title: Re: My poloniex account got hacked. Check yours
Post by: LiteMine on March 01, 2014, 02:56:09 PM
He still should have received the email confirmation.


Title: Re: My poloniex account got hacked. Check yours
Post by: SlidingHorn on March 01, 2014, 02:58:26 PM
If you are keeping coins on an exchange, you need to have 2FA set up.  

^^  THIS  ^^

If you don't you're begging people to steal from you.

You shouldn't "keep" them on an exchange though.  Only put coins on an exchange that you intend on trading in a reasonably short period of time.  You don't want to get Goxxed if/when the exchange tanks.


Title: Re: My poloniex account got hacked. Check yours
Post by: Armadyl on March 01, 2014, 03:06:21 PM
How much did you lose? And the hacker may have removed the emails afterwards, so you wouldn't know right?


Title: Re: My poloniex account got hacked. Check yours
Post by: drippx on March 01, 2014, 03:24:16 PM
trojan wallet stealer?


Title: Re: My poloniex account got hacked. Check yours
Post by: rebel24 on March 02, 2014, 01:18:57 PM
same thing happened to me, see my thread:
https://bitcointalk.org/index.php?topic=495565.new#new

but now I know what happened, poloniex is being DDOS'ed, as well as cryptorush.io
I had the same robberies happen at both places. They are DDOS'ing the sites, taking the login info, and, for me, stupidly, I used the same login info for my email as my login there. So they logged into my email to confirm the withdrawls.

Now I have 2 way authentication and different passwords, I HIGHLY RECOMMEND EVERYONE DO THIS RIGHT NOW IF YOU HAVENT ALREADY


Title: Re: My poloniex account got hacked. Check yours
Post by: BitJohn on March 02, 2014, 02:16:25 PM
He still should have received the email confirmation.

He Likely did get the email typically these start with user getting malware (keylogger) Gets into exchange gets into email. Hacker comes along now has login info sells it off withdraws deletes the confirm emails immediately so they don't get tipped off. IF you ask your mail provider they can likely verify they got the email and that it has been deleted.

So only way to prevent this is Strong 2FA recommend every use it and different passwords login info on all sites.


Title: Re: My poloniex account got hacked. Check yours
Post by: Nxtblg on March 02, 2014, 03:40:58 PM
And Poloniex goes down...Hmm...


Title: Re: My poloniex account got hacked. Check yours
Post by: Nullu on March 02, 2014, 03:57:17 PM
I think it should be made very clear that this was a PC vulnerability, not an exchange vulnerability.

The exchange didn't get hacked. Your computer did. Unless you had a very easy to guess/bruteforce password.


Title: Re: My poloniex account got hacked. Check yours
Post by: bittyweb on March 02, 2014, 04:22:23 PM
Did you have 2 factor authenticiation enabled?


Title: Re: My poloniex account got hacked. Check yours
Post by: Amph on March 02, 2014, 04:28:20 PM
next time don't manually type your password, use the "remember me" from google, or just scan with malwarebyte, it destroy every trojan or keylogger


Title: Re: My poloniex account got hacked. Check yours
Post by: scribe on March 02, 2014, 04:29:12 PM
I've got 2FA enabled, but when I login I currently don't get asked to enter the code - the email/password form just redirects to itself. Pretty sure password is OK as pasting it from a password manager.

+1 to only keeping long term things in your own wallet.


Title: Re: My poloniex account got hacked. Check yours
Post by: Armadyl on March 02, 2014, 04:30:15 PM
next time don't manually type your password, use the "remember me" from google, or just scan with malwarebyte, it destroy every trojan or keylogger

No, most keyloggers or rats have stored password list, so if that's the case they can get it easier from that method..


Title: Re: My poloniex account got hacked. Check yours
Post by: Amph on March 02, 2014, 05:23:46 PM
next time don't manually type your password, use the "remember me" from google, or just scan with malwarebyte, it destroy every trojan or keylogger

No, most keyloggers or rats have stored password list, so if that's the case they can get it easier from that method..

didn't know about that


Title: Re: My poloniex account got hacked. Check yours
Post by: Nullu on March 02, 2014, 05:25:18 PM
next time don't manually type your password, use the "remember me" from google, or just scan with malwarebyte, it destroy every trojan or keylogger

I use AntiLogger, which encrypts keystrokes.


Title: Re: My poloniex account got hacked. Check yours
Post by: silvestar on March 02, 2014, 07:56:44 PM
How much have you lost?


Title: Re: My poloniex account got hacked. Check yours
Post by: tintumon on March 02, 2014, 09:02:47 PM
Actually the hacker, first hacked my email and then sent forgot my password to all the exchanges I trade with.

Once he got the password reset, he basically sold all my altcoins to BTC and then transferred them to his wallet.

He also deleted all the email confirmations from the mail inbox.
I actually noticed the unable to login with poloniex couple of times, but since poloniex was wobbly at that time, i thought it was a server issue.

Altogether I lost around 6LTC and 0.06BTC

Thanks.


Title: Re: My poloniex account got hacked. Check yours
Post by: silvestar on March 02, 2014, 09:03:34 PM
Actually the hacker, first hacked my email and then sent forgot my password to all the exchanges I trade with.

Once he got the password reset, he basically sold all my altcoins to BTC and then transferred them to his wallet.

He also deleted all the email confirmations from the mail inbox.
I actually noticed the unable to login with poloniex couple of times, but since poloniex was wobbly at that time, i thought it was a server issue.

Altogether I lost around 6LTC and 0.06BTC

Thanks.

sad to hear that :(


Title: Re: My poloniex account got hacked. Check yours
Post by: subseaguru on March 02, 2014, 09:59:51 PM
this same thing happened on BTC-E a few months ago and no one could figure it out. im still not sure if anyone actually found out what happened. it seemed like it happened from the server end but BTC-E never admitted anything. they bypassed 2FA and confirmation emails and made withdrawls, which BTC-E said could not happen.


Title: Re: My poloniex account got hacked. Check yours
Post by: busoni on March 02, 2014, 11:40:55 PM
I just saw this thread.

First of all, I really can't think of a way someone could possibly confirm withdrawals without email access. However, people who still aren't using 2FA should realize that someone with access to your account doesn't even need to withdraw to steal your money. There are some thinly traded markets on Poloniex--all they would have to do is use your funds to buy up an order book and fill some absurd order like 1 IFC for 1 LTC.

This is why there is 2FA. It really is important. All an exchange can do is offer you the option to be secure--it's up to you to use those options.