Bitcoin Forum
May 28, 2024, 12:52:40 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Economy / Service Discussion / Re: Cryptsy account got hacked on: February 13, 2014, 01:44:19 AM
Quote
Any updates on this?
So far it looks like the guys on Crypty don't have any intention to respond to my support ticket.
As for the address I mentioned before, it seems to belong to Mtgox which isn't very helpful.

I included the original transactions of the withdraws from my account in case anyone is interested:

BTC transaction: 6bcb605dad4c252958c9e33d67fe7e3f91739db0fc126fc01a0ca528404066fa
DOGE  transaction: cda9f2e70c6c898ddb21447324563299e2e07099ab0b8aa21c9af16e8c573f43

2  Other / Beginners & Help / Re: Hashblaster.com SCAM transactions on: February 10, 2014, 08:28:55 PM
Quote
Are you sure this address belongs to Hashblaster?
I was wondering who owns this address since my Cryptsy's account balance got wiped out and all of the BTC were transferred to this address.
3  Economy / Service Discussion / Re: Cryptsy account got hacked on: February 03, 2014, 08:45:43 PM
Quote
Unlike your misfortune, no BTC was actually withdrawn from our account.  2 Billion CENT was sold for LTC, then our ZET was sold for BTC.  The LTC balance was sold for BTC, all ending with a very large and expensive NMC purchase.  Then finally NMC was sold for BTC for a VERY TINY fraction of the worth of the rest of the coins.  The end result is our entire balances of alt coins and btc were essentially wiped out.  No withdrawals were made at all.
Wow, that's a pretty unusual way to steal one's coins. That's the only way I can think right now that would actually enable to deplete account's balance without needing to access its email address, which shows that having a secure email address won't always save you.
I think it's a shame that there is no option to require 2FA for every withdrawal and every trade that I make.
4  Economy / Service Discussion / Re: Cryptsy account got hacked on: February 03, 2014, 08:11:21 PM
Quote
Once you login, you're asked to enter your two factor authentication details, right? After that, it doesn't ask you until your next login, correct? If this is the case, sounds like a piece of malware just stole the session authentication token (Cookie) and then used that (Maybe in conjunction with relaying the connection through your computer, in case Cryptsy checks the IP it was issued to).
Apparently 2FA is not as secure as I thought. That's probably what happened.

Quote
Do you mind testing something? Withdraw something, verify it, then, without logging out, withdraw something else, tell me if it makes you verify then, in if doesn't, my first theory is looking all the better, if it doesn't, what actually stops him from just deleting the mail after he's done? Do you host your own mail server? Can you get logs?
It requires email verification for every withdrawal. I'm starting to believe that whoever did that actually managed to access my email, verify the withdrawals, and then delete all the withdrawal emails. I'm using an email address from walla.com which turns out to be not so secure. I just was under the impression that by using 2FA my Crypty account is uncrackable. Well, so much for that...
5  Economy / Service Discussion / Re: Cryptsy account got hacked on: February 03, 2014, 01:24:32 PM
It looks like my BTC went through several addresses and ended here:
1Facb8QnikfPUoo8WVFnyai3e1Hcov9y8T

Does anyone know anything about this address? Can I find where it's from?
6  Economy / Service Discussion / Cryptsy account got hacked on: February 03, 2014, 02:22:09 AM
About 14 hours ago I had about 700 Cat coins and 500000 Doge coins on my Cryptsy account. I have sold 0.02725061 BTC worth of DOGE and withdraw it to another address. Soon after as expected I received an email to verify the withdrawal.

About 30 minutes later my account got hacked. All of my Doge coins ware withdrawn from my account, All of my Cat coins ware sold to BTC and then they were also withdrawn from my account.

All of this happened while I was using my PC, therefore it can't be a remote desktop program. Secondly, this account has two factor authentication which requires access to my phone, which means that simply having my user name and my password would not help in this case.

The most disturbing thing hare is that I did not receive a verification email for any of these 2 withdrawals. As far as I know after every withdrawal from Cryptsy I'm supposed to get a email to verify the withdrawal, which clearly did not happen. Whoever did this managed to withdraw from my account without needing to access to my email account, which indicates that there is a serious security hole in Cryptsy.

By the time I found out about this all of the transactions ware already confirmed. I opened a support ticket, but I did not receive an answer yet. I just can't wrap my mind around this. How on earth did this happen? He bypassed my two factor authentication, he did it while I way using my PC, and he did it without needing to access my email.

I'm posting this because I'm looking for ideas about how whoever did this managed to accomplish this taking into account everything that I have just said.
Secondly I would like to know if this is a single case, or whether more people have experiences similar to this from Cryptsy.

7  Economy / Trading Discussion / Re: Gekko - a javascript trading bot for nodejs on: January 23, 2014, 01:13:05 AM
I don't know if this have suggested before, but I'm sure a lot of people would appreciate it you ware to add a support for the exchanges on cryptsy.com.
Cheers.  Grin
8  Other / Beginners & Help / Re: BTC Guild being DDos'd ? on: July 05, 2011, 11:59:16 PM
Took the day off from mining.  Smiley

BTW the USeast server if running. Never thought I'd see BTC Guild runing with 351 workers.
9  Other / Beginners & Help / Re: Introduce yourself :) on: July 05, 2011, 11:40:52 PM
I have been beating my head against the wall for about 20 minuts before I realized that I can post only in the NEWBIES section.

Just wanted to buy Bad Company 2 with BTC...  Cry
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!