Bitcoin Forum
November 14, 2024, 09:48:01 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Stolen funds from Ledger Live?  (Read 335 times)
mocacinno
Legendary
*
Offline Offline

Activity: 3570
Merit: 5233


https://merel.mobi => buy facemasks with BTC/LTC


View Profile WWW
November 24, 2020, 02:08:48 PM
 #21

--snip--
Thanks and I agree - I rely a lot on the police now and hope they manage to investigate this properly.

Not sure whether I risk to blow up something if I share the transaction info?

you risk your privacy if you do so...

Your account name is known, your ip is known (bitcointalk uses cloudflare)... If you post your txid, people can couple some of your addresses to this account, and a couple of law enforcement agency's can do the same with your ip...
But other than this, you can do no harm by posting addresses or transaction id's.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
DaveF
Legendary
*
Offline Offline

Activity: 3654
Merit: 6671


Crypto Swap Exchange


View Profile WWW
November 24, 2020, 03:09:08 PM
 #22

There were (are) still some sophisticated phishing attacks against the ledger live app.

https://www.coindesk.com/phishing-attack-ledger-cryptocurrency-wallet

Even someone with good opsec can still mess up now and then.

And there have been a few fake extensions put up. They usually get taken down quickly but there are still up occasionally.

So even with what the OP said, there is still a chance that it came from elsewhere.

-Dave


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 24, 2020, 03:15:56 PM
 #23

I don't think it's a matter of the recovery phrase since the fraud happened shortly after I was logged in (for the first time in many months). Coincidence?
[...]
That said I did put my fingers on the recovery phrase and put it on my table for a while. And I did leave my desk - maybe with the Ledger device connected. But even if that is the case, how can it happen that the money left my account (as I didn't do anything related to a transaction or approving anything physically other than logging in a couple of times).

Are you sure that no one had access to your desk?

Since the transaction happened shortly after this session and you had your mnemonic on your desk, the possibility of someone taking a photo of it to steal your funds theoretically exists.
As well as someone using your ledger to sign such a transaction.

Did you ever use your mnemonic code for anything?

Porfirii
Legendary
*
Offline Offline

Activity: 1974
Merit: 2443


The Alliance Of Bitcointalk Translators - ENG>SPA


View Profile WWW
November 24, 2020, 03:31:13 PM
 #24

Are you sure that no one had access to your desk?

Since the transaction happened shortly after this session and you had your mnemonic on your desk, the possibility of someone taking a photo of it to steal your funds theoretically exists.
As well as someone using your ledger to sign such a transaction.

Did you ever use your mnemonic code for anything?

I am everything but an opsec master here... but just in case, and sorry if the question is dumb, I have to ask, as this is something that I care about every time I take out the paper with the phrase out of the envelope:

Is it possible to have one's smartphone hacked, so when your lift it and the camera points to the desk with the paper in sight it captures the words taking a screenshot? every time I touch the paper I try to make sure no cameras can look at it (and I feel a bit paranoid, but hey! better safe than sorry).

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18747


View Profile
November 24, 2020, 03:38:09 PM
 #25

Is it possible to have one's smartphone hacked, so when your lift it and the camera points to the desk with the paper in sight it captures the words taking a screenshot?
Yes, this is entirely possible. It also applies to cameras on laptops or tablets or standalone webcams plugged in to a computer. When they are not being used, you should disconnect any cameras you can, and cover them if you cannot disconnect them. A piece of tape is a sufficient and cheap option, but you can also buy phone cases with physical sliders or shutters to block cameras.

This isn't just good security, but given the mass spying and surveillance conducted by the US government and others, it is just common sense. The ex-director of the FBI says he covers all his cameras when not in use.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 24, 2020, 03:44:48 PM
 #26

Is it possible to have one's smartphone hacked, so when your lift it and the camera points to the desk with the paper in sight it captures the words taking a screenshot?

Possible? Definitely.
But is it likely? Not so much.

If you want to be sure that no one is spying on you through your smart phones camera, i'd recommend a webcam cover, i.e. something like that:


Source: amazon.com

They are pretty cheap and are available for all kinds of cameras (smart phones, laptop, webcams).

However, if you fear getting spied on through your smartphone, you'd also have to make sure it can't record ambient sound.
Whether that is paranoid or a possibly used attack vector, is completely up to you and depends on you and the situation you are in.

20kevin20
Legendary
*
Offline Offline

Activity: 1134
Merit: 1598


View Profile
November 24, 2020, 04:35:55 PM
 #27

However, if you fear getting spied on through your smartphone, you'd also have to make sure it can't record ambient sound.
Whether that is paranoid or a possibly used attack vector, is completely up to you and depends on you and the situation you are in.
While I'm quite paranoid about smartphones and cameras, imo if one gets to the point where they're so paranoid that they can't trust their smartphone at all anymore, it may be time to use a dumb phone instead. Like, I do this as a security and privacy practice - not necessarily because I'd be scared of someone monitoring my webcam activity.

For ambient sounds, if you're talking about microphones, it's quite hard to get the 3 microphones disconnected from a smartphone. I don't think there are any (or a lot of) smartphones out there that have modular microphones, they're usually soldered into the motherboard and requires micro-soldering skills to disconnect them. And that implies some very rough possible consequences: you'd have to only use headphones for microphone, so imagine having to call 911 in an emergency.

The thing is, even with your cameras and microphones removed, your phone's hardware and OS are the main issue. If you fear being spied through microphones and cameras, I'd have a much larger fear for the blobs and closed-source stuff the operating system has. At that point, Librem phones should be considered if you really need a smartphone (or a dumb phone, which is as cheap as a meal and can be disposed at any given time).

Another option is to use a Faraday cage to cut all external connections to the phone. Include a white noise generator next to it (or inside the cage) if you're afraid sounds are recorded offline only to be streamed once the phone reconnects to the internet.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 24, 2020, 06:18:07 PM
 #28

Another option is to use a Faraday cage to cut all external connections to the phone. Include a white noise generator next to it (or inside the cage) if you're afraid sounds are recorded offline only to be streamed once the phone reconnects to the internet.

That's definitely an option for the over-paranoid (some of them probably even are right in being paranoid about this).

Another option would be a completely open source mobile where the software and the hardware is open source.
Precursor is such a project. This isn't just a mobile built with purely open source software, but even the hardware can be verified.

That's a project from bunnie who held a very interesting talk about the supplychain of hardware and how an open source design is not enough to protect against supply chain attacks. This 1 hour long video can be found here. It is definitely worth to watch.

Pmalek
Legendary
*
Offline Offline

Activity: 2940
Merit: 7554


Playgram - The Telegram Casino


View Profile
November 24, 2020, 10:11:25 PM
 #29

The fact that you couldn't access your Ethereum accounts without an update a month ago is suspicious, especially since you were then robbed a few minutes later.
The two events don't have to be connected. During October, Ethereum accounts couldn't sync within Ledger Live. Their developer team found out that users who had Synthetix tokens, TIC, and sUSD couldn't sync their ETH accounts for whatever reason.

He used his Ledger Live account on 21 August. This is the official response from Ledger regarding the sync issues:
Quote
Attention #Ledger #Ethereum users

Your #ETH account may be stuck in syncing if you ever had one of these tokens:
- Synthetix (old contract address)
- TIC
- sUSD (old contract address)

While we're working on fixing this, you can use your Ledger with
@MyCrypto
 or
@myetherwallet
https://twitter.com/Ledger_Support/status/1318899089241743361

@ KrJS81
Did you, or do you still have any of those 3 tokens on your hardware wallet?
Can you walk us through (if you remember) your online activity on the day your funds were stolen? As much details as possible.

▄▄███████▄▄███████
▄███████████████▄▄▄▄▄
▄████████████████████▀░
▄█████████████████████▄░
▄█████████▀▀████████████▄
██████████████▀▀█████████
████████████████████████
██████████████▄▄█████████
▀█████████▄▄████████████▀
▀█████████████████████▀░
▀████████████████████▄░
▀███████████████▀▀▀▀▀
▀▀███████▀▀███████

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 
Playgram.io
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▄▄▄░░
▀▄







▄▀
▀▀▀░░
▄▄▄███████▄▄▄
▄▄███████████████▄▄
▄███████████████████▄
▄██████████████▀▀█████▄
▄██████████▀▀█████▐████▄
██████▀▀████▄▄▀▀█████████
████▄▄███▄██▀█████▐██████
█████████▀██████████████
▀███████▌▐██████▐██████▀
▀███████▄▄███▄████████▀
▀███████████████████▀
▀▀███████████████▀▀
▀▀▀███████▀▀▀
██████▄▄███████▄▄████████
███▄███████████████▄░░▀█▀
███████████░█████████░░
░█████▀██▄▄░▄▄██▀█████░
█████▄░▄███▄███▄░▄█████
███████████████████████
███████████████████████
██░▄▄▄░██░▄▄▄░██░▄▄▄░██
██░░░░██░░░░██░░░░████
██░░░░██░░░░██░░░░████
██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████
███████████████████████
███████████████████████
 
PLAY NOW

on Telegram
[/
fdfg123
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
December 02, 2020, 12:56:49 PM
 #30

Probably, pin-hole camera or imagining radar something.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!