Bitcoin Forum
May 21, 2024, 01:57:58 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Heads up! Someone is trying to hack into Blockchain.info wallets  (Read 3016 times)
Trader Steve (OP)
Hero Member
*****
Offline Offline

Activity: 836
Merit: 1007


"How do you eat an elephant? One bit at a time..."


View Profile
December 23, 2012, 03:19:39 PM
Last edit: December 23, 2012, 04:09:46 PM by Trader Steve
 #1

FYI: I tried logging into my blockchain account from my desktop (Mac) the other day and received a message that my account was locked for 4 hours due to too many login attempts. I knew something was amiss as I had not tried to access my account in days (I then accessed my Blockchain wallet from my mobile app and transferred the funds to an offline wallet).

Yesterday, after closing my desktop browser and attempting to open my blockchain wallet again, I received the following script notification:

*** Serious Error - Javascript inconsistencies found. Maybe malicious -
Do not Login! Please contact support@pi.uk.com


I had previously downloaded and installed the browser plug-in that checks the script so I suspect this was its way of notifying me of a script problem. I had also previously set up my 2-factor authentication so I believe this was able to protect me. I use the Firefox browser.

Now again this morning I received an email notifying me that a login attempt was made at 12:05 AM this morning.

Has anyone else had this issue? Anyway, not sure what to do next. I've emailed piuk on Friday but have not heard anything back yet.

cypherdoc
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
December 23, 2012, 03:25:50 PM
 #2

Steve, use Armory!
Trader Steve (OP)
Hero Member
*****
Offline Offline

Activity: 836
Merit: 1007


"How do you eat an elephant? One bit at a time..."


View Profile
December 23, 2012, 03:28:34 PM
 #3

Steve, use Armory!

Yes, it is time!
lulzplzkthx
Sr. Member
****
Offline Offline

Activity: 322
Merit: 251



View Profile WWW
December 23, 2012, 03:28:51 PM
 #4

FYI: I tried logging into my blockchain account from my desktop (Mac) the other day and received a message that my account was locked for 4 hours due to too many login attempts. I knew something was amiss as I had not tried to access my account in days (I then accessed my Blockchain wallet from my mobile app and transferred the funds to an offline wallet).

Yesterday, after closing my desktop browser and attempting to open my blockchain wallet again, I received the following script notification:

*** Serious Error - Javascript inconsistencies found. Maybe malicious -
Do not Login! Please contact support@pi.uk.com


I had previously downloaded and installed the browser plug-in that checks the script so I suspect this was its way of notifying me of a script problem. I had also previously set up my 2-factor authentication so I believe this was able to protect me. I use the Firefox browser.

Now again this morning I received an email notifying me that a login attempt was made at 12:05 AM this morning.

Has anyone else had this issue? Anyway, not sure what to do next. I've emailed piuk on Friday but have not heard anything back yet.



I tried logging on from my phone last night and was getting a few messages about my IP being banned due to invalid login attempts. It definitely wasn't me. Switched to wifi and it worked fine.

piuk
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1005



View Profile WWW
December 23, 2012, 03:35:18 PM
 #5

I've emailed piuk on Friday but have not heard anything back yet.

I cannot find your email, please send me your wallet identifier to help@blockchain.info

piuk
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1005



View Profile WWW
December 23, 2012, 05:49:21 PM
Last edit: December 23, 2012, 06:04:00 PM by piuk
 #6

After some discussion with Steve it appears someone may have attempted to login to his wallet however they were unable to pass the two factor authentication test. I believe he has moved the coins elsewhere now anyway.

I had previously downloaded and installed the browser plug-in that checks the script so I suspect this was its way of notifying me of a script problem.

Sometimes the verifier can throw erroneous warnings if there is a problem downloading any of the scripts. If an error is displayed try refreshing the page, if it keeps appearing there may be a problem but otherwise the error can be ignored.

------

There are currently no known specific threats to any wallet or the site in general.

nethead
Sr. Member
****
Offline Offline

Activity: 322
Merit: 250



View Profile
December 23, 2012, 07:17:57 PM
 #7

FYI: I tried logging into my blockchain account from my desktop (Mac) the other day and received a message that my account was locked for 4 hours due to too many login attempts. I knew something was amiss as I had not tried to access my account in days (I then accessed my Blockchain wallet from my mobile app and transferred the funds to an offline wallet).

Yesterday, after closing my desktop browser and attempting to open my blockchain wallet again, I received the following script notification:

*** Serious Error - Javascript inconsistencies found. Maybe malicious -
Do not Login! Please contact support@pi.uk.com


I had previously downloaded and installed the browser plug-in that checks the script so I suspect this was its way of notifying me of a script problem. I had also previously set up my 2-factor authentication so I believe this was able to protect me. I use the Firefox browser.

Now again this morning I received an email notifying me that a login attempt was made at 12:05 AM this morning.

Has anyone else had this issue? Anyway, not sure what to do next. I've emailed piuk on Friday but have not heard anything back yet.



I got a similar error when i first got blockchain wallet. I do not think its a "hacking" attempt, my case was that blockchain didnt mail the 2factor validation, and i tried to login 3-4 times so i stayed locked out of my wallet for some hours, my btc havent been touched by anyone, and after those few hours everything was back to normal
BlackLilac Jordan
Full Member
***
Offline Offline

Activity: 163
Merit: 100



View Profile
December 26, 2012, 12:33:00 AM
 #8

There is a blockchain.info phishing site on a .info misspell domain, watch out. I almost fell for it once, it's fairly well done and looks almost exactly like the real site, but the form looks slightly different and it's not on https. I will try to find the exact domain. If you typed in your identifier and password there once without noticing, they may have tried to get in to your account but were foiled by the 2-factor auth.
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
December 26, 2012, 02:08:31 AM
 #9

There is a blockchain.info phishing site on a .info misspell domain, watch out. I almost fell for it once,

Wow, yes there is.  Omit the c in block,  i.e.,  Blok*

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
December 26, 2012, 05:34:10 AM
 #10

After some discussion with Steve it appears someone may have attempted to login to his wallet however they were unable to pass the two factor authentication test. I believe he has moved the coins elsewhere now anyway.

I had previously downloaded and installed the browser plug-in that checks the script so I suspect this was its way of notifying me of a script problem.

Sometimes the verifier can throw erroneous warnings if there is a problem downloading any of the scripts. If an error is displayed try refreshing the page, if it keeps appearing there may be a problem but otherwise the error can be ignored.

The verifier is essentially ineffective.
niko
Hero Member
*****
Offline Offline

Activity: 756
Merit: 501


There is more to Bitcoin than bitcoins.


View Profile
December 26, 2012, 05:57:56 AM
 #11

There is a blockchain.info phishing site on a .info misspell domain, watch out. I almost fell for it once,

Wow, yes there is.  Omit the c in block,  i.e.,  Blok*

I just tried it out, somewhere along the way it redirected me to blockchain.info. 

They're there, in their room.
Your mining rig is on fire, yet you're very calm.
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2506
Merit: 1010


View Profile
December 29, 2012, 04:35:15 AM
 #12

I just tried it out, somewhere along the way it redirected me to blockchain.info. 

Now it is using an iframe. 
 serialsforyou (dot) info (slash) securelog32

I'm not sure what the applet and/or windows executables are doing (view source) but definitely not anything you want.

Unichange.me

            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █
            █


niko
Hero Member
*****
Offline Offline

Activity: 756
Merit: 501


There is more to Bitcoin than bitcoins.


View Profile
December 29, 2012, 04:19:24 PM
 #13

I just tried it out, somewhere along the way it redirected me to blockchain.info. 

Now it is using an iframe. 
 serialsforyou (dot) info (slash) securelog32

I'm not sure what the applet and/or windows executables are doing (view source) but definitely not anything you want.
Nasty. Isn't this something Piuk should take down? Copyright, if nothing else.

They're there, in their room.
Your mining rig is on fire, yet you're very calm.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!