Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: Yuzu on August 31, 2014, 05:03:53 PM



Title: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 05:03:53 PM
Hey, I don't even know why I'm posting this.  I'm so mad and disappointed.  My NXT account has been hacked.  All my NXT is gone.  I'm not as mad about that as I am that my assets are gone as well.  Whoever stole them, Karma is a bitch.  I promise you I will try to find you and you won't be happy when I do.  Here's the addy where they have gone:
NXT-FFJQ-RK5R-474V-E4XCD

If anyone can help me trace this person I'd appreciate it.  Thank you much.


Title: Re: NXT account hacked. All assets gone.
Post by: instacalm on August 31, 2014, 05:10:45 PM
Hi, got more details ie. length and complexity of passphrase, operating system etc.?

Sorry for your loss


Title: Re: NXT account hacked. All assets gone.
Post by: MyPotPlantDied on August 31, 2014, 05:12:17 PM
Sucks man, sorry for your loss. Lots of NXT hacks lately. You need to provide more details so people can help you track him down.


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 05:21:33 PM
Sorry, my head is just reeling.  I'm on Mac OSX 10.9.  My passphrase wasn't complex enough--my own stupidity.  Kept meaning to change it and life kept getting in the way.  So I'm learning my lesson the hard way.  This is the transaction:

30/08/2014 03:07:59      21'787 + 1   NXT-FFJQ-RK5R-474V-E4XCD   10+

The asshole sold all my assets, and then took my NXT.


Title: Re: NXT account hacked. All assets gone.
Post by: instacalm on August 31, 2014, 05:24:38 PM
Track whether the thief sends the NXT over to an exchange's hot wallet in the future (should he want to sell), then get in touch with that particular exchange. They might be able to give you more information such as IP. You can setup an alerter which automatically emails you when the account initiates any transactions: http://www.mynxt.info/alerts.php

Other than that please make sure to use passwords of great complexity from now on, I can highly recommend 1Password to generate and keep track of all your passwords if you're on OS X.


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 05:36:53 PM
Thank you very much.  I'll look into 1password.


Title: Re: NXT account hacked. All assets gone.
Post by: WhatTheGox on August 31, 2014, 06:20:55 PM

dam this sucks :(


Title: Re: NXT account hacked. All assets gone.
Post by: sx100 on August 31, 2014, 06:45:47 PM
Thank you very much.  I'll look into 1password.

Keepass is good too and does an OSX version.

http://sourceforge.net/projects/keepass/


Title: Re: NXT account hacked. All assets gone.
Post by: Spoetnik on August 31, 2014, 07:20:38 PM
just ask for a rollback.


lol so true !

and this makes me think.. we can now so he "private" this coin really is..

see what was suggested here "anon" coin floggers see how easy the technique of cross referencing is ?
see how your stupid anon gimmick coins are a joke yet ?

edit:
i like Password Depot
but i don't think they have a mac version :(
it can run in free ware mode i here and has free mobile version.
http://www.password-depot.com/download.htm
http://www.password-depot.com/download-special-editions.htm

it has lots of features and was one of the best when i seen reviews first online too.
They are faster at updating the Firefox plugin compared to Kaspersky's Pass manager.

i like the tray icon.. you can right click it and select make new password.. really easy !
no reason for weak passwords these days..


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 07:25:36 PM
NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.


Title: Re: NXT account hacked. All assets gone.
Post by: scryptasicminer on August 31, 2014, 07:27:08 PM
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.


Title: Re: NXT account hacked. All assets gone.
Post by: Spoetnik on August 31, 2014, 07:29:48 PM
NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.

it was a fair and quite funny joke considering the exchange BTER was hacked for NXT a matter of 2/3 weeks ago.
So in case people don't know out there that is why the joke is funny.. HA HA
(NXT cheerleaders asked for a rollback on the BTER hack)

nothing to do with an "agenda" bud lol


Title: Re: NXT account hacked. All assets gone.
Post by: Spoetnik on August 31, 2014, 07:30:46 PM
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.

yup !

i agree.. seems to be a lot of security issues swirling around this coin.. not a good impression at all !


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 07:31:50 PM
I'm a bud-ette.  I guess I just don't see the humor in all my assets being gone.  My sense of humor today is quite gone.  As for security issues, I can't really say.  My password wasn't very strong.  And other people don't seem to be having a problem. 


Title: Re: NXT account hacked. All assets gone.
Post by: manrus on August 31, 2014, 07:42:02 PM
Use keepassx. Free and mac os support ;)


Title: Re: NXT account hacked. All assets gone.
Post by: EvilDave on August 31, 2014, 07:44:03 PM
It appears to have a lot of hack on NXT lately.

A 3rd party observer may think this is a coin security issue.

The recent NXT thefts had sod-all to do with NXT security, but are all about password security.
Whether its guys choosing "dog" as a secure password for a brainwallet, or server admins using the same password for everything......it's always password security or simple social engineering behind most crypto-thefts.

NXT didn't do a rollback when they were hacked, but thanks for taking this post and making it all about an agenda.  I messed up with and didn't have a secure enough password, and I'm not asking for anything except information anyone might have.

it was a fair and quite funny joke considering the exchange BTER was hacked for NXT a matter of 2/3 weeks ago.
So in case people don't know out there that is why the joke is funny.. HA HA
(NXT cheerleaders asked for a rollback on the BTER hack)

nothing to do with an "agenda" bud lol

BTER were the guys keen on the rollback, most of NXT community were against it, so Spoetnik is kinda twisting the truth here.
And, yeah, way to express some sympathy.

@Yuzu: what was your password/passphrase ?
It's been compromised, so it's fuck-all good to you now, but it'd be good to see an example of a compromised password.
Might serve as a warning for other people: Choose a very secure password for your crypto! 8 lowercase characters doesn't hack it any more.
You have my sympathy, btw, thieves suck.


Title: Re: NXT account hacked. All assets gone.
Post by: BitcoinEXpress on August 31, 2014, 07:46:37 PM
It appears to have a lot of hack on NXT lately.

A 3rd party  casual observer may will rightfully think this is a coin with security issues.



Fixed that for you.

Isn't roll backs part of the unique built in features to prevent successful thefts in NXT?


~BCX~


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 07:49:44 PM
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  :-\


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 07:56:30 PM
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  :-\

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.


~BCX~

You're right about that.  I have no one to blame but myself.  Like I said, it will never happen again.  Not to me.  I'm just posting this as a warning to those who might have done what I did.


Title: Re: NXT account hacked. All assets gone.
Post by: EvilDave on August 31, 2014, 08:11:33 PM
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  :-\

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.

~BCX~

Ah...trojans and dodgy sites are possible, but don't forget that there are also guys running rainbow tables against the NXT blockchain 24/7.
Any simple (or well known) password will be compromised, given enough time.
Had a guy on www.NXTforum.org a few days ago who had chosen a Bible verse as his password, and that got compromised pretty quickly.

The answer is simple: use a complex password, ffs. Not one that is easy to remember......
35 characters, upper+lower case, numbers and symbols.

@Yuzu: I know how much getting shit stolen hurts, so post or PM me your new NXT account (with a supersecure password) and I'll send 1000 NXT to help you back on track a little bit.


Title: Re: NXT account hacked. All assets gone.
Post by: devphp on August 31, 2014, 08:12:40 PM

Actually the PW strength probably wasn't the issue.


In NXT, which is a brain wallet, PW strength is exactly the issue.

OP says it was a word + number + symbol = 12 chars.

So, something like this: Generation5!

It was most likely brute-forced using a dictionary.

Something like this: MaQorLdNxE5!    would be much more secure, also 12 characters, but no dictionary words. At least 20 or more random characters are recommended for better security, with no dictionary words.


Title: Re: NXT account hacked. All assets gone.
Post by: Nullu on August 31, 2014, 08:24:05 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?


Title: Re: NXT account hacked. All assets gone.
Post by: devphp on August 31, 2014, 08:27:32 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear :) Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.


Title: Re: NXT account hacked. All assets gone.
Post by: Spoetnik on August 31, 2014, 08:29:41 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 08:30:34 PM
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  :-\

Actually the PW strength probably wasn't the issue.

Malware and using it on other sites are more than likely the issue.

If you were too lazy to change it,

then there is a high probability you reused it or a similar variation of it somewhere else.

~BCX~

Ah...trojans and dodgy sites are possible, but don't forget that there are also guys running rainbow tables against the NXT blockchain 24/7.
Any simple (or well known) password will be compromised, given enough time.
Had a guy on www.NXTforum.org a few days ago who had chosen a Bible verse as his password, and that got compromised pretty quickly.

The answer is simple: use a complex password, ffs. Not one that is easy to remember......
35 characters, upper+lower case, numbers and symbols.

@Yuzu: I know how much getting shit stolen hurts, so post or PM me your new NXT account (with a supersecure password) and I'll send 1000 NXT to help you back on track a little bit.

Dave, that's so damn nice of you.  But I can't take anything from anybody, though I appreciate the offer more than I can tell you.  Take that 1000NXT and get some of a nice asset like USDbitfnx.  It's a nice quiet little asset that pays out every two weeks.  I'm going to buy more of it when I get more funds.  But thanks, thanks, thanks!


Title: no reuse !
Post by: Spoetnik on August 31, 2014, 08:31:59 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear :) Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.

and even more importantly as BitcoinExpress just said.. DO NOT RE-USE YOUR PASSWORDS !

EVER !!!!!!!!!!!!!!!!!!!!!!! period !!!!!!!!!!!!!!!

you can have 9327587298467508926409750602916843509287640956 of random characters
but when you re-use it.. your fucked !


Title: Re: NXT account hacked. All assets gone.
Post by: Nullu on August 31, 2014, 08:37:10 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.


Title: Re: NXT account hacked. All assets gone.
Post by: Magic8Ball on August 31, 2014, 08:42:28 PM
Thanks EvilDave.  While I'm changing ALL of my passwords I don't want to put my old one out yet.  It was very simple for a hacker and I meant to change it but kept putting it off.  It was just a Word+number+symbol.  Twelve characters.  Bad, bad, bad.  For anyone who is out there reading this and thinks they have a 'good enough' password, for goodness sakes update it right now.  This truly sucks, and you don't want to be in my postion.  :-\

Very sad to hear. I hope that the thief gets his comeuppance soon.

I had one simple account created initially which had a few hundred NXT, but its all gone long back. I haven't looked into NXT since.


Title: Re: no reuse !
Post by: EvilDave on August 31, 2014, 08:46:20 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

Someone is doing exactly that. Try to create an account with a simple password, fund it with a few coins and track how long it'll take for coins to disappear :) Someone did that experiment in Bitcoin with a brain wallet too, brain wallet with a phrase like 'hello, world' or something, it was gone in 5 mins. Moral of the story: use a truely random pass of 20+ chars and keep your PC clean from trojans of course.

and even more importantly as BitcoinExpress just said.. DO NOT RE-USE YOUR PASSWORDS !

EVER !!!!!!!!!!!!!!!!!!!!!!! period !!!!!!!!!!!!!!!

you can have 9327587298467508926409750602916843509287640956 of random characters
but when you re-use it.. your fucked !

Its a strange moment....total agreement with Spoetnik!
This was the cause of the BTER hack: if you re-use a password, and it gets compromised somewhere.....the rest of your shit is immediately compromised.

@Yuzu: good luck, mate. I'll see if I can find some orphans to pass a 1000 NXT on to...... ;)


Title: Re: NXT account hacked. All assets gone.
Post by: EvilDave on August 31, 2014, 08:51:41 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

Account Control is coming up soon as a NXT feature....it'll allow you to cold-wallet and lockdown your account.
But the point is: the user is responsible for his own security.
NXT is safe, provided you use a decent password and the normal security precautions such as anti-malware scanners and not clicking on every link you see.


Title: Re: NXT account hacked. All assets gone.
Post by: Nullu on August 31, 2014, 08:57:24 PM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

Account Control is coming up soon as a NXT feature....it'll allow you to cold-wallet and lockdown your account.
But the point is: the user is responsible for his own security.
NXT is safe, provided you use a decent password and the normal security precautions such as anti-malware scanners and not clicking on every link you see.

Ultimately it's the user's responsibility, yes, but even allowing weak passwords to begin with seems counter-intuitive if hackers are allowed unlimited password attempts.


Title: Re: NXT account hacked. All assets gone.
Post by: MacDuro on August 31, 2014, 08:58:33 PM
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .


Title: Re: NXT account hacked. All assets gone.
Post by: Yuzu on August 31, 2014, 09:01:17 PM
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

Dude, do it right now.  Don't be like me!  ;)


Title: Re: NXT account hacked. All assets gone.
Post by: EvilDave on August 31, 2014, 10:08:43 PM
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!

BTW: the random 12 word passphrase that current NXT clients have should be secure enough. We've never heard of a randomly generated passphrase being compromised, only bad user-chosen passwords. 


Title: Re: NXT account hacked. All assets gone.
Post by: MacDuro on September 01, 2014, 12:10:42 AM
I'm still using the one that they randomly generate , I know bad move ... time to create another wallet , transfer funds and pay the damm NxT fess .

The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!

BTW: the random 12 word passphrase that current NXT clients have should be secure enough. We've never heard of a randomly generated passphrase being compromised, only bad user-chosen passwords. 

Thax for all your advices , didn't know about the fess , I think I will create another account just because that password in English is really hard to rememeber for me .


Title: Re: NXT account hacked. All assets gone.
Post by: sx100 on September 01, 2014, 12:24:46 AM


The fee you see on the transfer page is only a suggestion.......1 NXT is the minimum, and it doesn't matter how much you transfer.
Someone should have told the BTER hacker that, as he paid out the recommended 51,000 NXT fee on the transfer out of BTERs account.....one very happy forger!
 

Would the hacker's transaction have confirmed faster because he paid the 51,000 NXT fee, or would it have confirmed just as fast if he had paid a 1 NXT fee?


Title: Re: NXT account hacked. All assets gone.
Post by: digital7 on September 01, 2014, 02:34:46 AM
oh, maybe you are water army   ;D ;D ;D


Title: Re: NXT account hacked. All assets gone.
Post by: Zer0Sum on September 01, 2014, 03:23:24 AM
This is what worries me about NXT. Can't you just literally bruteforce it until you come across weak passwords?

yeah and that is not FUD'ing but a valid concern !!!

They could easily introduce some basic protection. Prevent weak passwords from being allowable. Temp I.P ban users who make too many password attempts. Force two-step verification. There are so many options to choose from, and I can't see any valid counter-argument to implementing some basic security protection.  You wouldn't expect your online bank to let you have such weak security.

I doubt that you hear about even 10% of crypto hacks...
In fact, virtually all security deficiencies are automatically blamed on "password hacks".

Would you put $1,000,000 on the NXT platform?

OP, don't feel bad...
For every post I read where the user maybe was careless...
I read another one where victim was an amateur cryptologist, jumped through 100 hoops, and still got ripped off.

Decentralized crypto security = Free Lunch.


Title: Re: NXT account hacked. All assets gone.
Post by: NattyLiteCoin on September 01, 2014, 04:05:10 AM
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.


Title: Re: NXT account hacked. All assets gone.
Post by: devphp on September 01, 2014, 05:19:27 AM
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

12 random words generated by the client are secure.

It's when a user rejects that random pass and invents their own weak password that most of the hacks take place.

If you can't invent your own secure password, just use what the client software tells you to use and you'll be safe.


Title: Re: NXT account hacked. All assets gone.
Post by: smoothie on September 01, 2014, 06:57:56 AM
just ask for a rollback.

lol thanks for that!  ;D ;D ;D


Title: Re: NXT account hacked. All assets gone.
Post by: Nullu on September 01, 2014, 10:04:26 AM
just ask for a rollback.

To day 0? I'm sure the big holders would love that one.  ;)


Title: Re: NXT account hacked. All assets gone.
Post by: ChetnotAtkins on September 01, 2014, 10:21:41 AM
Sorry for your loss. Yes you cannot stress enough how important a secure passphrase is. Many people become lazy at some point and sacrifice their security for comfort - big mistake, especially in the wild west of cryptos


Title: Re: NXT account hacked. All assets gone.
Post by: CryptoBang on September 02, 2014, 09:45:43 AM
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

Hi guys!

Be careful, it is one NXT drawbacks. I have recently posted an article about this coin, you can find it here http://www.cryptobang.com/2014/09/01/check-out-interesting-facts-about-nxt/

i am going to create many articles which will give info about different cryptocurrencies.

Is you no some facts - please you the form on my site "Drop facts"

Or maybe you are interested in a concrete coin - you can order the investigation :)


Title: Re: NXT account hacked. All assets gone.
Post by: abuelau on September 03, 2014, 10:46:20 AM
So the the password I got from NXT is not secure?

Freeze gulp magnetic vibe manifest knee sprain winter ungulate hoofed your mom

Solid fucking gold right there.

Hi guys!

Be careful, it is one NXT drawbacks. I have recently posted an article about this coin, you can find it here http://www.cryptobang.com/2014/09/01/check-out-interesting-facts-about-nxt/

i am going to create many articles which will give info about different cryptocurrencies.

Is you no some facts - please you the form on my site "Drop facts"

Or maybe you are interested in a concrete coin - you can order the investigation :)

That's a really lame and inaccurate article. You should learn more before posting anything like that.