Bitcoin Forum
April 24, 2024, 05:32:03 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 »  All
  Print  
Author Topic: JUST HAD 0.92329 BTC STOLEN - HOW???  (Read 8298 times)
amiryaqot
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000



View Profile
May 02, 2015, 11:14:02 AM
 #21

I just deposited the above amount to one of electrum wallets. Almost immediately the balance was tramsferred to:

13GrQ46YQ3x3fp1p5eHrPKSsMaxjDY9VwC

tx: https://blockchain.info/tx/c92f9c265f0a7a9b7fec9184a0314545f8d3f2b3d6d53c240eec97a087826a00

Noth of the transaction have any confirmations, it just happen immediately. How is this possible and how can I get my funds back??? I cannot understand how this is possible. FML

My address:

https://blockchain.info/address/15WapDB1AsoKKp4vMTims836Jxn9mJdHJA


Help!!! 

Almost immediately? 

Yes, I have seen the two bitcoin transaction:

- https://blockchain.info/it/tx/5cc872a7dc9bebb03290e9d537d57eba51056e764483a4f4ef4f6bc2bac66e0f  (his transfer to the electrum wallet)     
2015-05-02 10:24:40

- https://blockchain.info/it/tx/c92f9c265f0a7a9b7fec9184a0314545f8d3f2b3d6d53c240eec97a087826a00  (the second tx into the hacker address)   
2015-05-02 10:25:41


~ 1 minuted between the two transaction.

yes that is very strange to see this kind of transaction, sorry to see this one, Sad  
how this hacker was quick in this transaction just delay of 1 minute ?
The block chain is the main innovation of Bitcoin. It is the first distributed timestamping system.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713936723
Hero Member
*
Offline Offline

Posts: 1713936723

View Profile Personal Message (Offline)

Ignore
1713936723
Reply with quote  #2

1713936723
Report to moderator
1713936723
Hero Member
*
Offline Offline

Posts: 1713936723

View Profile Personal Message (Offline)

Ignore
1713936723
Reply with quote  #2

1713936723
Report to moderator
bennybong (OP)
Hero Member
*****
Offline Offline

Activity: 682
Merit: 500



View Profile
May 02, 2015, 11:15:26 AM
 #22

Can't find any evidence of an infection. I use VPN on my VM, can't figure this out  Huh
shadobitz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500



View Profile
May 02, 2015, 11:16:35 AM
 #23

Could something be wrong with Electrum?

It's doubtful. It's quite common for hackers to immediately sweep funds out of addressess. This happens very often with weak brainwallets, once the funds are transferred in they are drained within seconds. I suspect the OP may have imported the address into electrum, or may have restored his wallet using a weak seed or such.

i think so really socking to see this one, another transaction made within few seconds..
bennybong (OP)
Hero Member
*****
Offline Offline

Activity: 682
Merit: 500



View Profile
May 02, 2015, 11:17:26 AM
 #24

I've had much more btc in that wallet in the past. And I only fire up my VM to check my electrum which isn't that often. WHY ME AND why now. This is bullshit!
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
May 02, 2015, 11:18:45 AM
 #25

....
yes that is very strange to see this kind of transaction, sorry to see this one, Sad 
how this hacker was quick in this transaction just delay of 1 minute ?

I do not know, it is really strange.



I've had much more btc in that wallet in the past. And I only fire up my VM to check my electrum which isn't that often. WHY ME AND why now. This is bullshit!


Have you downloaded something of strange in the past days/weeks?
Light
Hero Member
*****
Offline Offline

Activity: 742
Merit: 502


Circa 2010


View Profile
May 02, 2015, 11:19:34 AM
 #26

Can't find any evidence of an infection. I use VPN on my VM, can't figure this out  Huh

What AV software are you using if I may ask? Have you used this specific Electrum wallet before (or any other addresses from the same seed)? Did you access the wallet before the funds were stolen - or were they just taken immediately after an initial deposit?

A VPN wouldn't really help you in terms of security for this kind of thing - more useful for privacy and anonymity.
Kprawn
Legendary
*
Offline Offline

Activity: 1904
Merit: 1073


View Profile
May 02, 2015, 11:22:39 AM
 #27

It's too weird to be explained... It's as if it was a automated action. There is about a 1 minute delay between the 2 transactions.

What is the chances of someone sitting and waiting for you to make transactions to steal it immediately?

It's also a single use address... and it would most probably be mixed too.. so you stuffed, if it was not a electrum screw up.  Sad

THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
S4VV4S
Hero Member
*****
Offline Offline

Activity: 1582
Merit: 502


View Profile
May 02, 2015, 11:26:44 AM
 #28

Sorry to ask but I only use Bitcoin Core.

Is Electrum like Brainwallet?

Because if it is then you should know that there is people constantly running brute force apps and waiting for a transaction to take place, then snatch the coins to their own wallet.

There was a post about this someweher in the forums.

Search for Brainwalet hacking and you will find it.
roslinpl
Legendary
*
Offline Offline

Activity: 2212
Merit: 1199


View Profile WWW
May 02, 2015, 11:27:48 AM
 #29

I've had much more btc in that wallet in the past. And I only fire up my VM to check my electrum which isn't that often. WHY ME AND why now. This is bullshit!

There must be a reason why this happens.

I don't know why you and why now, but for some reason your machine was compromised and it's perhaps your fault of not keeping your security at high level.


I am really sorry for your lost. But there is nothing you can do now. But what you need to do is:

-format the drives from the machine where your Electrum was installed and coins were stolen.
-use high standard antimalware, antivirus apps.
-never open suspicious links
-follow other security steps to keep your bitcoins safe.

Also you can keep an eye on 13GrQ46YQ3x3fp1p5eHrPKSsMaxjDY9VwC - only a little chance that you will be able to track those coins but worth a try.

Best regards.
boopy265420
Legendary
*
Offline Offline

Activity: 1876
Merit: 1005


View Profile
May 02, 2015, 11:28:38 AM
 #30

It's too weird to be explained... It's as if it was a automated action. There is about a 1 minute delay between the 2 transactions.

What is the chances of someone sitting and waiting for you to make transactions to steal it immediately?

It's also a single use address... and it would most probably be mixed too.. so you stuffed, if it was not a electrum screw up.  Sad
Sorry for your loss and second yeah this is very strange that all this just happened so quick as someone was waiting but this is not very big amount. This is warning for others to take some extra security measure to keep their funds save. This is good at least others will be more active in future.
bennybong (OP)
Hero Member
*****
Offline Offline

Activity: 682
Merit: 500



View Profile
May 02, 2015, 11:32:39 AM
 #31

....
yes that is very strange to see this kind of transaction, sorry to see this one, Sad  
how this hacker was quick in this transaction just delay of 1 minute ?

I do not know, it is really strange.

Have you downloaded something of strange in the past days/weeks?

No I download a lot of software and I know a scam/trojan link when I see one

Can't find any evidence of an infection. I use VPN on my VM, can't figure this out  Huh

What AV software are you using if I may ask? Have you used this specific Electrum wallet before (or any other addresses from the same seed)? Did you access the wallet before the funds were stolen - or were they just taken immediately after an initial deposit?

A VPN wouldn't really help you in terms of security for this kind of thing - more useful for privacy and anonymity.

Yes I've used the same electrum wallet before but not much.


Oh and I use Avira, MS essential and Malwarebytes. I keep my Computers in order don't you worry Wink
dhimasnk
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


View Profile
May 02, 2015, 11:32:50 AM
 #32

this is one thing that is feared by users bitcoin, bitcoin loss caused by hackers. Hopefully there are no cases like this again

BUY LOW/SELL HIGH
24/7 TRADING BOT  GUNBOT  THE AUTOMATIC PROFIT GENERATOR FOR POLONIEX
LIMITED EDITION NOW AVAILABLE FOR KRAKEN AND BITTREX  My bitcoin address: 37xyZGoqmkeTTatsWcnFJS4iL4xdE4Cuia + wex.nz codes at Peermarketer@gmail.com
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
May 02, 2015, 11:33:25 AM
 #33

Sorry to ask but I only use Bitcoin Core.

Is Electrum like Brainwallet?

Because if it is then you should know that there is people constantly running brute force apps and waiting for a transaction to take place, then snatch the coins to their own wallet.

There was a post about this someweher in the forums.

Search for Brainwalet hacking and you will find it.

No, electrum is really different from the Brainwallet. The first one uses a seed of 12 words so it is really impossible to bruteforce it, instead the second one use only a password. I am still thinking that it was a computer problem.


OP can you explain again if you have stored the seed in some .txt file on the pc?
bennybong (OP)
Hero Member
*****
Offline Offline

Activity: 682
Merit: 500



View Profile
May 02, 2015, 11:35:19 AM
 #34

Sorry to ask but I only use Bitcoin Core.

Is Electrum like Brainwallet?

Because if it is then you should know that there is people constantly running brute force apps and waiting for a transaction to take place, then snatch the coins to their own wallet.

There was a post about this someweher in the forums.

Search for Brainwalet hacking and you will find it.

No, electrum is really different from the Brainwallet. The first one uses a seed of 12 words so it is really impossible to bruteforce it, instead the second one use only a password. I am still thinking that it was a computer problem.


OP can you explain again if you have stored the seed in some .txt file on the pc?

I store the seed in a truecrypt vault. In the past I haven't even bothered saving the seed for security reason. I jut backup my Private keys - which are encrypted

And the password on the wallet is not used anywhere else.
hellyeah
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
May 02, 2015, 11:43:05 AM
 #35

I am sorry for your loss bro.

Did anyone else have access to your PC?

╲╲ ╲╲ COINOMAT.COM ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
╱╱ ╱╱ First Instant Crypto Exchange                              Sign Up Now!                    Visit our Facebook & Twitter
▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃
Blazr
Hero Member
*****
Offline Offline

Activity: 882
Merit: 1005



View Profile
May 02, 2015, 11:47:48 AM
 #36

What operating system were you running on the VM?

And what software were you using for that?

Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
May 02, 2015, 11:48:08 AM
Last edit: May 02, 2015, 12:31:03 PM by Amph
 #37

I've had much more btc in that wallet in the past. And I only fire up my VM to check my electrum which isn't that often. WHY ME AND why now. This is bullshit!

have you downloaded something suspicious yesterday or some time ago?, what is the last thing you downloaded?
Remember remember the 5th of November
Legendary
*
Offline Offline

Activity: 1862
Merit: 1011

Reverse engineer from time to time


View Profile
May 02, 2015, 11:52:25 AM
 #38

A VM tries to keep bad stuff in, if the virus had infected your PC, doesn't matter if you were using a VM, however it would have to know and handle the fact that there is a VM.

BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
Blazr
Hero Member
*****
Offline Offline

Activity: 882
Merit: 1005



View Profile
May 02, 2015, 11:54:46 AM
 #39

A VM tries to keep bad stuff in, if the virus had infected your PC, doesn't matter if you were using a VM, however it would have to know and handle the fact that there is a VM.

There can also be issues with VM's and poor entropy, it's much less secure to put your wallet in a VM in some cases. OP, what operating system did you run in the VM? and what software did you use for it?

bennybong (OP)
Hero Member
*****
Offline Offline

Activity: 682
Merit: 500



View Profile
May 02, 2015, 11:55:27 AM
 #40

No I don't download anything suspicious. The last thing I downloaded was a new driver for my soundcard - from the official website
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!