Bitcoin Forum
May 08, 2024, 07:53:07 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: My wallet on the computer was robbed  (Read 2466 times)
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 09:54:46 AM
 #1

Hi, an intruder robbed my bitcoins. What can I do ? Any suggestions ?
1715154787
Hero Member
*
Offline Offline

Posts: 1715154787

View Profile Personal Message (Offline)

Ignore
1715154787
Reply with quote  #2

1715154787
Report to moderator
1715154787
Hero Member
*
Offline Offline

Posts: 1715154787

View Profile Personal Message (Offline)

Ignore
1715154787
Reply with quote  #2

1715154787
Report to moderator
1715154787
Hero Member
*
Offline Offline

Posts: 1715154787

View Profile Personal Message (Offline)

Ignore
1715154787
Reply with quote  #2

1715154787
Report to moderator
BitcoinCleanup.com: Learn why Bitcoin isn't bad for the environment
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Josef27
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


View Profile
April 09, 2015, 10:17:33 AM
 #2

Wait, a robber rob your computer? Sorry to hear that.

What kind of wallet you're using? If you using the bitcoin-qt, ever you backup the wallet.dat some somewhere else? (Like usb stick, disc, etc)
Also ever you write your own private key on a paper or... copying and put it on txt file or something then put it somewhere?

You can back up your wallet from it, but if you aren't, you can't. Sorry for that.
Next time don't forget to backup.

Or if the robber just access your computer to steal your bitcoin...

You can't get it back... Do you know who is it? Any security cams?
And next time please encrypt your wallet. Don't just leave them open.
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
April 09, 2015, 10:52:56 AM
 #3

Wait, a robber rob your computer? Sorry to hear that.

What kind of wallet you're using? If you using the bitcoin-qt, ever you backup the wallet.dat some somewhere else? (Like usb stick, disc, etc)
Also ever you write your own private key on a paper or... copying and put it on txt file or something then put it somewhere?

You can back up your wallet from it, but if you aren't, you can't. Sorry for that.
Next time don't forget to backup.

Or if the robber just access your computer to steal your bitcoin...

You can't get it back... Do you know who is it? Any security cams?
And next time please encrypt your wallet. Don't just leave them open.

encrypting is uselesses if your computer is unsafe, because at the first time he need to spend them with bitcoin core, he will lost everything anyway

so first clear you OS(in same case this can't be enough as there are some virus that target the bios, but i don't think this is the case...), and then make a new clean installation

add then malware-byte, hitman pro and zeman for protection, and next time use a "trap wallet" in your main machine and the rest in a cold storage, this is the best solution against any hacker
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 12:21:44 PM
 #4

Thanks for your advice, I felt safe, because I had Bitdefender anti virus programme installed, but that one completely disappeared. Looks like the attacker could delete it.

My bitcoins went to this address:  1GgJkUADnzZ6kNF13toGpv7o8bCj3WYQov

One attack came from this IP: 51.21.9.22 Netherland, NL
Second one from here: 198.38.94.199   ALAMO, CALIFORNIA, UNITED STATES   2015-04-09 06:59:08 EST

Can somebody help me to trace this guy ?
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
April 09, 2015, 01:18:08 PM
Last edit: April 09, 2015, 04:30:53 PM by Amph
 #5

Thanks for your advice, I felt safe, because I had Bitdefender anti virus programme installed, but that one completely disappeared. Looks like the attacker could delete it.

My bitcoins went to this address:  1GgJkUADnzZ6kNF13toGpv7o8bCj3WYQov

One attack came from this IP: 51.21.9.22 Netherland, NL
Second one from here: 198.38.94.199   ALAMO, CALIFORNIA, UNITED STATES   2015-04-09 06:59:08 EST

Can somebody help me to trace this guy ?

if he deleted the wallet, you have probably a rootkit or rat, because some antivirus have protection against cancellation from malware(i know malwarebyte has chamaleont)

tracing him would be really hard because it seems he is using a proxy/vpn
OnkelPaul
Legendary
*
Offline Offline

Activity: 1039
Merit: 1004



View Profile
April 09, 2015, 01:31:31 PM
 #6

One attack came from this IP: 51.21.9.22 Netherland, NL
Second one from here: 198.38.94.199   ALAMO, CALIFORNIA, UNITED STATES   2015-04-09 06:59:08 EST

How do you know the IP addresses? It is extremely difficult to find the actual source of malware because by the time it gets active, the traces of its installation are normally gone.
If you're just looking at IP addresses recorded by your firewall software, just ignore them, any computer on the internet is constantly bombarded with "attack" IP packets that are not any more than simple knocks at the door. The firewall has already prevented connections from these IP addresses, but it will not report the real source of a successful attack because it can't - otherwise it would have prevented the attack.

Malware on windows computers is mostly installed either by yourself (when you installed something downloaded from the internet) or by your browser when an attacker exploits a browser security hole.

Onkel Paul

Bitware
Hero Member
*****
Offline Offline

Activity: 926
Merit: 1001


weaving spiders come not here


View Profile
April 09, 2015, 04:01:32 PM
 #7

I recommend buying an old decent quality laptop from ebay. Maybe an IBM Thinkpad with fingerprint recognition. Do a DOD wipe/rewrite of the hard drive or replace it. Install a linux distro. Only connect it to the internet for security updates, Bitcoin core updates, to update the blockchain and to perform Bitcoin transactions. Also, after you installed and updated Bitcoin, disconnect from internet, encrypt wallet in the Bitcoin Core and save a copy into a truecrypt v7 container. I would also encrypt the entire hard drive with truecrypt v7 as well. Use very strong and unique passphrases for each the wallet, portable truecrypt container, and disk encryption.

Here is an example of a very strong passphrase: "My Daughter was born on May 13, 2003 in Hamburg Hospital in Room 213 @ 7:03am."
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 05:28:48 PM
 #8

Thanks, I always wanted to do this, use a cold computer also, but well, too busy with other things, so stupid.
How could the hacker transfer the money ? I had the wallet secured by a password as well ?
Any specialist out there who has a good idea please contact me !
RodeoX
Legendary
*
Offline Offline

Activity: 3066
Merit: 1147


The revolution will be monetized!


View Profile
April 09, 2015, 05:38:06 PM
 #9

You may want to consider your computer compromised.  Undecided

Is it a windows PC? Then you may also want to consider installing Linux in a partition. That way you can boot up Linux when you need better security. (Not that it's fool proof).  It may be hard to determine where you picked up some mal-ware, but avoid downloading programs related to BTC unless they are open source. Anyway, sorry to hear about your loss.

The gospel according to Satoshi - https://bitcoin.org/bitcoin.pdf
Free bitcoin in ? - Stay tuned for this years Bitcoin hunt!
siameze
Legendary
*
Offline Offline

Activity: 1064
Merit: 1000



View Profile
April 09, 2015, 05:42:01 PM
 #10

How could the hacker transfer the money ? I had the wallet secured by a password as well ?


This is quite easy if the attacker had a keylogger installed on your system. A little patience and sooner or later he would see you typing in your password.


                     ▀▀█████████▀████████████████▄
                        ████▄      ▄████████████████
                     ▄██████▀  ▄  ███████████████████
                  ▄█████████▄████▄███████████████████
                ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀████████
                                               ▀▀███▀
    ▄█▀█       ▄▀  ▄▀▀█  ▄▀   █████████████████▄ ██▀         ▄▀█
   ▄█ ▄▀      ▀█▀ █▀ █▀ ▀█▀  ███████████████████ █▀ ▀▀      ▄▀▄▀
  ▄█    ▄███  █     █   █   ████████████████████  ▄█     ▄▀▀██▀ ▄███
███▄▄▄  █▄▄▄ █▄▄ ▄▄▀   █▄▄ ██████████████████▀▀   █▄▄ ▄▄ █▄▄█▄▄▄█▄▄▄
                           ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
                            ▀▀█████████████▄
                                █████████████▄
                                  █████████████▄
                                    ▀███████▀▀▀▀▀
                                      ▀████▀
                                        ▀█▀
LetItRideINNOVATIVE ▬▬▬
DICE GAME
                        ▄███████████▄
                       ██  ██████████▄
                     ▄█████████████  ██▄
            ▄▄▀█▄▄▄▄▄████████████████████▄
        ▄▄█▀   ███████████  █████  ████  █
    ▄██████ ▄▄███████████████████████████▀
 ▄▀▀ ██████████████████████████  ████  █
█  ▄███████████▀▀▀█████████████████████
██████████████    ████████▀▀██████  █▀
██████████████▄▄▄██████████   ▀▀▀▀▀▀▀
███▀ ▀██████████████████████
██    ███████████████████████
██▄▄██████████████████████████
██████████████▀   ██████████
  █████████████   ▄██████▀▀
     ▀▀██████████████▀▀
         ▀▀██████▀▀
PROVABLY
F A I R
▄█████████████▀ ▄█
██            ▄█▀
██          ▄██ ▄█
██ ▄█▄    ▄███  ██
██ ▀███▄ ▄███   ██
██  ▀███████    ██
██    █████     ██
██     ███      ██
██      ▀       ██
██              ██
▀████████████████▀
BUY  BACK
PLANS
[BTC]
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 05:44:17 PM
 #11

OnkelPaul: How do you know the IP addresses?
Thanks for your message. The IP address was used to attack my exchange account at the same time. I know he might have used some vpn, nevertheless I try my best. I also filed a fraud report in the meantime.
MegaFall
Jr. Member
*
Offline Offline

Activity: 56
Merit: 1


View Profile
April 09, 2015, 05:47:10 PM
 #12

How could the hacker transfer the money ? I had the wallet secured by a password as well ?


This is quite easy if the attacker had a keylogger installed on your system. A little patience and sooner or later he would see you typing in your password.

Or could have simply found the private keys...
defcon23
Legendary
*
Offline Offline

Activity: 1120
Merit: 1002


View Profile
April 09, 2015, 05:47:54 PM
 #13

nothing you can do at this point, unless thinking cold storage or hardware wallet..
sorry for your loss.. Lips sealed
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 05:57:30 PM
 #14

MegaFall: Or could have simply found the private keys...

What does that mean exactly ?
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
April 09, 2015, 06:01:59 PM
 #15

MegaFall: Or could have simply found the private keys...

What does that mean exactly ?

if he infected your pc with a rat, he can take control of your pc, and see your private key after you access your wallet, so it doesn't even need to type the password, he just wait you to do so and steal your private key
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 08:11:41 PM
 #16

Amph
ok, I understand, but how could he manage to delete my security software (bitdefender), obviously he hacked my computer and then deleted this programme....
There is a lot of criminal energy involved to achieve this...well like in any other robbery of course.
But longterm this could kill the Bitcoin. If in a case like this, you cannot mark your coins as stolen to block them for further usage at least, not even talking about tracing the coins to the new "owner".
SebastianJu
Legendary
*
Offline Offline

Activity: 2674
Merit: 1082


Legendary Escrow Service - Tip Jar in Profile


View Profile WWW
April 09, 2015, 08:26:33 PM
 #17

Amph
ok, I understand, but how could he manage to delete my security software (bitdefender), obviously he hacked my computer and then deleted this programme....
There is a lot of criminal energy involved to achieve this...well like in any other robbery of course.
But longterm this could kill the Bitcoin. If in a case like this, you cannot mark your coins as stolen to block them for further usage at least, not even talking about tracing the coins to the new "owner".

Marking (Tainting) wouldnt help you. He looks like a pro so you can be very sure that he knows how to exchange his coins to fresh untainted coins. So at the time your coins are found and stopped, they only belong to another innocent person.

I wonder what would happen. Is money marked as belonging to a robbery is seized? I guess so. Maybe then those coins would be seized too and the innocent person would be the victim.

Please ALWAYS contact me through bitcointalk pm before sending someone coins.
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
April 09, 2015, 08:35:22 PM
Last edit: April 10, 2015, 06:08:25 AM by Amph
 #18

Amph
ok, I understand, but how could he manage to delete my security software (bitdefender), obviously he hacked my computer and then deleted this programme....
There is a lot of criminal energy involved to achieve this...well like in any other robbery of course.
But longterm this could kill the Bitcoin. If in a case like this, you cannot mark your coins as stolen to block them for further usage at least, not even talking about tracing the coins to the new "owner".

if he controlling your pc at kernel level, you are screwed, he can do basically everything with your machine, the only option now is to secure erase

next time i would suggest to keep a small amount in your client that is running on your main machine(like 0.01 btc), all your other funds in a different wallet(cold storage, no internet connection)

if your 0.01 vanishes one day, you know you are infected, and you can clean your machine with a minimal loss, it's the best strategy against those malicious guy
Shaolino (OP)
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 09, 2015, 11:30:41 PM
 #19

So, when I am running a new security programme with scanning and all kind of options to debug my computer, will it still not be safe for future attacks ?
Of course I will not store any Bitcoins anymore, just for normal operations.....does it mean that these standard security programmes are not protecting my computer against a pro attack at all ? (obviously Bitdefender did not do the job).
If this is the case I see no future for a digital currency.....
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
April 10, 2015, 06:08:16 AM
 #20

So, when I am running a new security programme with scanning and all kind of options to debug my computer, will it still not be safe for future attacks ?
Of course I will not store any Bitcoins anymore, just for normal operations.....does it mean that these standard security programmes are not protecting my computer against a pro attack at all ? (obviously Bitdefender did not do the job).
If this is the case I see no future for a digital currency.....

they can help, but they will not offer 100% protection, for 100% protection you must build a separate machine and don't surf internet or download anything

for now you should do a format c, to be sure your machine is clear
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!