Bitcoin Forum
June 01, 2024, 02:46:02 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: lost btc  (Read 1323 times)
phir3 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
January 25, 2016, 09:50:06 PM
 #1

hey guys, i made the noob mistake of being hasty and not double checking that my wallet address was the same as the address i was using to buy btc from a btc vendor (coinloft). when my btc didn't go in after a while i did doublecheck my wallet address and noticed it wasn't the same. it was this one https://blockchain.info/address/19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u
it seems my wallet has been compromised somehow as i literally cannot copy MY wallet address and the above address gets copied into my clipboard instead both by ctrl+c, the "copy" button and right-click has been disabled in multibit. can i copy some log data or something so that developers are aware of this possible exploit?
achow101
Moderator
Legendary
*
Offline Offline

Activity: 3402
Merit: 6663


Just writing some code


View Profile WWW
January 25, 2016, 09:54:28 PM
 #2

hey guys, i made the noob mistake of being hasty and not double checking that my wallet address was the same as the address i was using to buy btc from a btc vendor (coinloft). when my btc didn't go in after a while i did doublecheck my wallet address and noticed it wasn't the same. it was this one https://blockchain.info/address/19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u
it seems my wallet has been compromised somehow as i literally cannot copy MY wallet address and the above address gets copied into my clipboard instead both by ctrl+c, the "copy" button and right-click has been disabled in multibit. can i copy some log data or something so that developers are aware of this possible exploit?
I don't think that has anything to do with multibit. It is likely to do with a virus you probably have on your computer. IIRC there is actually a virus that changes the address you copy to the clipboard so that you end up accidentally sending the Bitcoin to the attacker. Try copying and pasting someone else's address just to test if it actually does work. Even if it does, you should get yourself a good antivirus and let it scan your computer and remove anything that might be on it.

morantis
Hero Member
*****
Offline Offline

Activity: 868
Merit: 503



View Profile
January 25, 2016, 09:56:19 PM
 #3

hey guys, i made the noob mistake of being hasty and not double checking that my wallet address was the same as the address i was using to buy btc from a btc vendor (coinloft). when my btc didn't go in after a while i did doublecheck my wallet address and noticed it wasn't the same. it was this one https://blockchain.info/address/19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u
it seems my wallet has been compromised somehow as i literally cannot copy MY wallet address and the above address gets copied into my clipboard instead both by ctrl+c, the "copy" button and right-click has been disabled in multibit. can i copy some log data or something so that developers are aware of this possible exploit?

You can do whatever you want, but that is a pretty common virus that only hits the very wide open security and most of us are well beyond that point.  The information is already out there and every one knows about the virus, thanks but no thanks.
unholycactus
Legendary
*
Offline Offline

Activity: 1078
Merit: 1024



View Profile WWW
January 26, 2016, 12:14:58 AM
 #4

To avoid this problem in the future, you should always check when copy and pasting addresses.
Even if your computer isn't compromised, there's a chance you use the wrong address by your own mistake.

Also, your computer seems to be compromised (doubt it's the wallet like you said), you should stop using it completely for transactions.
phir3 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
January 26, 2016, 12:31:23 AM
 #5

i now have no doubt that it would've been a virus. cheers for the replies guys. so, in order to avoid this again and set myself up better upon windows reinstall (i know linux is the most solid, obvious suggestion), can fellas suggest what protection i should employ? i have bitdefender and malwarebytes but i may have installed it too late (infection could have been before and i removed everything i could find when i did the installs), i have noscript installed in firefox and i use purevpn. some of us learn the hard way and in my case it was 2btc :/ thanks in advance
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
January 26, 2016, 02:46:29 AM
 #6

i now have no doubt that it would've been a virus. cheers for the replies guys. so, in order to avoid this again and set myself up better upon windows reinstall (i know linux is the most solid, obvious suggestion), can fellas suggest what protection i should employ? i have bitdefender and malwarebytes but i may have installed it too late (infection could have been before and i removed everything i could find when i did the installs), i have noscript installed in firefox and i use purevpn. some of us learn the hard way and in my case it was 2btc :/ thanks in advance
The best way to protect yourself from viruses is obviously avoiding clicking on suspicious links and downloading programs. It is possible for viruses to exist in cracked versions of Windows, be careful about that. For this kind of virus, the best way is to always check the first bits of address and ensure that it's the same as what you intended.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 26, 2016, 08:24:38 AM
 #7

i now have no doubt that it would've been a virus. cheers for the replies guys. so, in order to avoid this again and set myself up better upon windows reinstall (i know linux is the most solid, obvious suggestion), can fellas suggest what protection i should employ? i have bitdefender and malwarebytes but i may have installed it too late (infection could have been before and i removed everything i could find when i did the installs), i have noscript installed in firefox and i use purevpn. some of us learn the hard way and in my case it was 2btc :/ thanks in advance
The best way to protect yourself from viruses is obviously avoiding clicking on suspicious links and downloading programs. It is possible for viruses to exist in cracked versions of Windows, be careful about that. For this kind of virus, the best way is to always check the first bits of address and ensure that it's the same as what you intended.

Also check the last few symbols, they contain the checksum. If the beginning and the end matches it next to impossible that someone created a specific address to fool you. Most malware that is replacing addresses is not that good, but it might be in the future.

Other than that, anti virus software is not going to do much. As ranochigo said, you most likely installed or downloaded the malware yourself. Stay away from software from shady sources and make it a habit to verify the downloads. Most bitcoin related software is either PGP signed or at the very least offers checksums. For Windows systems I use HashCalc.

Im not really here, its just your imagination.
watashi-kokoto
Sr. Member
****
Offline Offline

Activity: 682
Merit: 269



View Profile
January 26, 2016, 02:52:54 PM
 #8

If you completely ignore computer security then don't be surprised. All official Bitcoin programs are signed by developers,
you should check every program you download is OK not only to catch fake versions, but program can also damage by error when
transferring over the internet.

If you use verified windows and verified bitcoin then things like this will never happen to you.
-XXIII-
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
January 27, 2016, 02:42:57 AM
 #9

i know linux is the most solid, obvious suggestion

I'd highly recommend Linux any day. For a fresh-from-windows user, my suggestion is to look into Ubuntu MATE.
HarHarHar9965
Hero Member
*****
Offline Offline

Activity: 994
Merit: 1000


View Profile
January 27, 2016, 08:56:00 AM
 #10

hey guys, i made the noob mistake of being hasty and not double checking that my wallet address was the same as the address i was using to buy btc from a btc vendor (coinloft). when my btc didn't go in after a while i did doublecheck my wallet address and noticed it wasn't the same. it was this one https://blockchain.info/address/19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u
it seems my wallet has been compromised somehow as i literally cannot copy MY wallet address and the above address gets copied into my clipboard instead both by ctrl+c, the "copy" button and right-click has been disabled in multibit. can i copy some log data or something so that developers are aware of this possible exploit?

In multibit Virus is getting form easily I guess. Even I switched to Electrum Its more efficient than multibit So people can could go for that I fell. Instead go for solving the issues.
Outlander
Legendary
*
Offline Offline

Activity: 1218
Merit: 1000



View Profile
January 27, 2016, 09:30:43 AM
 #11

If you completely ignore computer security then don't be surprised. All official Bitcoin programs are signed by developers,
you should check every program you download is OK not only to catch fake versions, but program can also damage by error when
transferring over the internet.

If you use verified windows and verified bitcoin then things like this will never happen to you.
not exactly! The virus will be penetrated to your computer no matter what versions of systems you are using! It is caused by that the users accidently click the fishy links and download the virus without any implication!

racquemis
Full Member
***
Offline Offline

Activity: 174
Merit: 100


View Profile
January 27, 2016, 09:33:26 AM
 #12

If you completely ignore computer security then don't be surprised. All official Bitcoin programs are signed by developers,
you should check every program you download is OK not only to catch fake versions, but program can also damage by error when
transferring over the internet.

If you use verified windows and verified bitcoin then things like this will never happen to you.
not exactly! The virus will be penetrated to your computer no matter what versions of systems you are using! It is caused by that the users accidently click the fishy links and download the virus without any implication!

Not to mention you can also get infected just a visiting a JDB site.
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
January 27, 2016, 10:41:46 AM
 #13

hey guys, i made the noob mistake of being hasty and not double checking that my wallet address was the same as the address i was using to buy btc from a btc vendor (coinloft). when my btc didn't go in after a while i did doublecheck my wallet address and noticed it wasn't the same. it was this one https://blockchain.info/address/19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u
it seems my wallet has been compromised somehow as i literally cannot copy MY wallet address and the above address gets copied into my clipboard instead both by ctrl+c, the "copy" button and right-click has been disabled in multibit. can i copy some log data or something so that developers are aware of this possible exploit?

In multibit Virus is getting form easily I guess. Even I switched to Electrum Its more efficient than multibit So people can could go for that I fell. Instead go for solving the issues.
Nope. The virus replaces the Bitcoin address in the clipboard and hope that the user won't see it and click send. This can usually be verified by checking parts of the address and make sure that it matches. Since it intercepts your clipboard, no matter what program you use, as long as you copy Bitcoin addresses, it would get replaced.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
wayniac30
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250


View Profile
January 27, 2016, 04:46:08 PM
 #14

If you completely ignore computer security then don't be surprised. All official Bitcoin programs are signed by developers,
you should check every program you download is OK not only to catch fake versions, but program can also damage by error when
transferring over the internet.

If you use verified windows and verified bitcoin then things like this will never happen to you.
not exactly! The virus will be penetrated to your computer no matter what versions of systems you are using! It is caused by that the users accidently click the fishy links and download the virus without any implication!

Not to mention you can also get infected just a visiting a JDB site.

Happened to me once, caught it in time though.
Nybbas
Member
**
Offline Offline

Activity: 60
Merit: 10


View Profile
January 27, 2016, 10:17:49 PM
 #15

Where are those places you can get that?
Torrents sites? BTC-TALK?
AliceWonderMiscreations
Full Member
***
Offline Offline

Activity: 182
Merit: 107


View Profile WWW
January 28, 2016, 12:57:22 AM
 #16

Linux. The choice of a GNU generation.

Seriously people, stop using Windows and malware problems go away.

Will that always be the case? I don't know, but it has been that way for me for almost two decades now.

I hereby reserve the right to sometimes be wrong
arbitrage
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500



View Profile
January 28, 2016, 02:37:11 PM
 #17

Most of malwares and viruses in existence are related with windows platforms.
Linux distributions are better choices i must agree but for starters it looks very hard to learn.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!