Bitcoin Forum
May 05, 2024, 01:59:38 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 19, 2019, 07:22:18 PM
alastori, i recently find interesting article how 2FA can be bypass in combination with phishing attack, and although this does not have to be something that has happened to you, it is possible that you are a victim of a similar attack.

The hack employs two tools, called Muraena and NecroBrowser, which work in tandem to automate the attacks. The two tools work together like the perfect crime duo. Think of Muraena as the clever bank robber, and NecroBrowser as the getaway driver.

Muraena intercepts traffic between the user and the target website, acting as a proxy between the victim and a legitimate website. Once Muraena has the victim on a phony site that looks like a real login page, users will be asked to enter their login credentials, and 2FA code, as usual. Once the Muraena authenticates the session’s cookie, it is then passed along to NecroBrowser, which can create windows to keep track of the private accounts of tens of thousands of victims.

Regarding error you see, this is something I never see in time I use blockchain wallet. Whatever happened with your account, there is a probability that some trace has remained and that blockchain will find something.

Are you check your home wirelles network for intruders? All protection can be hacked, and everything depends on your modem / router firmware.

https://www.bleepingcomputer.com/news/security/new-method-simplifies-cracking-wpa-wpa2-passwords-on-80211-networks/

Yeah I understand how this attack works, the thing is i never open blockchain wallet from a link or something like that, i always type the URL key by key, the WPA2 password on my wireless network would take probably months to crack, no neighbours who are into this field, so I am ruling that out too.

I even made a request to Blockchain.info to send logs of IP addresses that logged in to my wallet, just to confirm that nobody else was able to log in there, but they are not responding.
Does your account don't have that email verification each time you log in? they display IP address everytime you log in. Check your email because it also includes the browser used, operating system and the time of accessing.

The title of that email should be 'Authorize log-in attempt'.

I have the email verification, that's 2FA. It never showed any login attempt for me to verify, I have 2FA in my email too, no suspicious log-in attempts.
Okay that means that there's nothing wrong if you have verified it on the email that I'm talking. I don't have anything to add anymore since you have validated most of it and you're sure that you have done you part.

And there's no negligence on your side, did they replied already to the support report that you did?

Nope, no reply yet.
2  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 18, 2019, 10:46:08 PM
I even made a request to Blockchain.info to send logs of IP addresses that logged in to my wallet, just to confirm that nobody else was able to log in there, but they are not responding.
Does your account don't have that email verification each time you log in? they display IP address everytime you log in. Check your email because it also includes the browser used, operating system and the time of accessing.

The title of that email should be 'Authorize log-in attempt'.

I have the email verification, that's 2FA. It never showed any login attempt for me to verify, I have 2FA in my email too, no suspicious log-in attempts.
3  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 18, 2019, 09:40:02 PM
I even made a request to Blockchain.info to send logs of IP addresses that logged in to my wallet, just to confirm that nobody else was able to log in there, but they are not responding.
4  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 18, 2019, 09:31:57 PM
Op really seems to be knowledgeable about cyber security and knows where he should place himself. The fault should really be on blockchain.com's end.

alastori, you should report this to them on https://support.blockchain.com/hc/en-us/requests/new though I doubt that they will compensate your loss but let's see if they can stand and will figure out this faulty issue on their end.



I have already reported it to blockchain but i have not received a response yet.
What hurts the most is that everybody thinks it's always the clients fault, I am highly educated in cybersecurity and it is in my nature to not fall for stupid phishing attacks or to install suspicious malware.
Every time I have to deal with a file that comes from an unverified source, I view it on a virtual machine or when a VM is not available i use sandboxes to open it. It's very hard to get the usual malware on Linux, especially when you are educated on cybersecurity, because most hackers target their malware to Windows users because they are the majority, not Linux users. Everything is regularly updated on my PC and I only use 2 or 3 browser add-ons that are among the most popular ones. Plus they are all disabled on incognito mode by default, unless you SPECIFICALLY go and enable them in incognito, which is a thing I have not done. My wireless network was a home one, not a cafe or a restaurant etc., so I am excluding a MITM attack. Even if someone was theoretically sniffing my traffic, the traffic is already encrypted by SSL. If it was a non-secure wallet with other circumstances, I would not even open this thread. If I had a malware on my device, they would steal the funds from the other blockchain.info wallet too, not just this one. Plus, the weird error that i screenshotted, what's that ? I never encountered an error like that in my 3 years or so experience of Blockchain.info.
5  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 09:40:52 PM
I was using a secure mail provider, Tuta.io and 2FA was enabled on both the email account and the blockchain.info wallet.
I know i was probably compromised but I have no idea how. All the latest updates of Ubuntu are installed and no new software has been installed in the previous 2 months or so.

If you had 2fa on both email and blockchain.info , the attacker somehow got access to your browser or seed. Theoretically, your seed in blockchain.jnfo is always compromised because you received it from your browser (someone could be watching)

I would format everything, as I already said. And review your online habits.

Also , try a more secure wallet next time, such as Electrum.org
Blockchain info is also a secured wallet. At least I have used it for over two years without any issues. Except he exposed his 12 passphrase words online or someone around the OP got hold of them, I still don't know how it could be hacked. To even say that the 2FA authenticator was beaten in this case is really surprising to me to say the lest.

It was my money I lost, I have no reason to lie. I would never fall victim to a phishing attack, my 12 word seed was not stored anywhere online.
If I had no idea around hacking or cybersecurity, I would understand that it is my fault and I wouldn't even open this thread. The only logical explanation is that there is some kind of zero day exploit that the public doesn't know about yet, or that the blockchain.info wallet is not as secure as you think.
I would recommend everybody to use another wallet, I'm already using Electrum, my BTC there is safe. Stop giving web wallets a chance, I knew i was probably making a mistake but i thought that since the blockchain.info wallet is probably the oldest it is probably safe. It is not.
6  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 11:48:19 AM
The BTC has now been moved out of 16MgFBd4ay7Yz5bw2HEpvTzCFQwqRmFK73 .
I guess they are gone forever.

Yes, they are gone.you were hacked. Your system is compromised .

I would format all computers/smartphone that you ever used to access your wallet.

Where did you store the seed? Was it in a paper? Or in a Google draft, drive, cloud storage?

Blockchain.info wallet is not very safe, as there are many ways a hacker could get access to it.
Maybe even the e email that you used to create the wallet is compromised. Change its password and add 2fa to it.

The 12 word seed was only stored on plain paper and the papers aren't lost or stolen.
I was using a secure mail provider, Tuta.io and 2FA was enabled on both the email account and the blockchain.info wallet.
I know i was probably compromised but I have no idea how. All the latest updates of Ubuntu are installed and no new software has been installed in the previous 2 months or so.
7  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 10:12:50 AM
The BTC has now been moved out of 16MgFBd4ay7Yz5bw2HEpvTzCFQwqRmFK73 .
I guess they are gone forever.
8  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 08:05:13 AM
I have created both of the wallets myself in early 2017.
The 12 word seed was only stored on plain paper and the papers aren't lost or stolen. I think this is all somehow related to the sending problem I had because there is no other logical explanation for it. I have never exported the address private keys because I simple didn't have the need to. I have contacted blockchain.info support and I am waiting for their reply. I am excluding some type of cookie attack because i logged out of my wallet 2 or 3 minutes before the BTC were gone so that would reset the session ID and therefore even if my cookies were stolen they would be invalid.
9  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 02:24:39 AM
And btw after I lost the BTC i tried some other transactions on the same wallet and kept getting the same error as in the screenshot that i have posted. After 2 or 3 tries i was able to send money again and I am ruling out the phishing or malware part because I am using Two Factor Authentication so it's highly unlikely that I was hacked. I saw some other users are also having issues with some funds in blockchain.info so maybe it is related to that?
10  Economy / Web Wallets / Re: BTC is missing from Blockchain.info wallet on: July 16, 2019, 02:12:30 AM
With those limited info, it's kinda hard to tell.
I could be a phishing site, compromised wallet/account, watch-only wallet, malicious browser extension and other "common" scams.

We need more information about the wallet, how you've created it and the actual URL of the website that you're visiting.

I am 100% certain that it was https://www.blockchain.com/wallet.
No malware extensions because I was using incognito mode and they are disabled on incognito mode.
I am certain it wasn't a malware or something else because if it was a malware the hackers would have stolen the funds in my other wallet too. That's why I am so confused.
11  Economy / Web Wallets / BTC is missing from Blockchain.info wallet on: July 16, 2019, 01:09:32 AM
Hello everybody,
Tonight I was trying to send some money from a blockchain.info wallet(INCOGNITO window) to my other blockchain wallet(normal window) and i kept getting an error "bitcoin transaction failed to send. Please try again" ( https://prnt.sc/ofizu7 ) something like this. I kept trying for like 3-4 minutes, i tried changing the fee and all that but i still couldn't send the money to my main blockchain wallet, so after some tries i gave up and decided to try again later so i closed my browser completely(including the incognito one) and after more than an hour i decided to login again and try and i saw that my funds (0.27735 BTC) were sent to this address: 16MgFBd4ay7Yz5bw2HEpvTzCFQwqRmFK73 so I immediately checked the other blockchain wallet if it was compromised or something but the other one was untouched. I don't know this address, I've checked my history and I've never copied or anything and as a matter of fact i wasn't even trying to send money from my main account(the one where i lost the bitcoins).
I have 2FA enabled and no signs of some malware or other stuff in my computer, i am using Ubuntu Linux.
Can someone please help me find out how I just lost ~3K USD?
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!