Bitcoin Forum
May 13, 2024, 09:55:22 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: 1 2 [All]
  Print  
Author Topic: [Information Request]Someone tried to login into my blockchain wallet  (Read 1630 times)
stingers (OP)
Legendary
*
Offline Offline

Activity: 1184
Merit: 1013


View Profile
February 13, 2016, 07:31:32 AM
 #1

Someone recently tried to target my blockchain wallet. Here are some of the details. :

Time: 2016-02-13 05:08:13
IP Address: 195.211.192.206 (Russian Federation)
Browser: Chrome 15
User Agent: Mozilla/5.0 (Linux x86_64) AppleWebKit/560.0 (KHTML, like Gecko) Chrome/15.024.208 Safari/560

Cab someone get me more on this?  I have no link with anyone from Russian federation. Does this I.P seem known to anyone else out there?
1715594122
Hero Member
*
Offline Offline

Posts: 1715594122

View Profile Personal Message (Offline)

Ignore
1715594122
Reply with quote  #2

1715594122
Report to moderator
1715594122
Hero Member
*
Offline Offline

Posts: 1715594122

View Profile Personal Message (Offline)

Ignore
1715594122
Reply with quote  #2

1715594122
Report to moderator
1715594122
Hero Member
*
Offline Offline

Posts: 1715594122

View Profile Personal Message (Offline)

Ignore
1715594122
Reply with quote  #2

1715594122
Report to moderator
The network tries to produce one block per 10 minutes. It does this by automatically adjusting how difficult it is to produce blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715594122
Hero Member
*
Offline Offline

Posts: 1715594122

View Profile Personal Message (Offline)

Ignore
1715594122
Reply with quote  #2

1715594122
Report to moderator
A73841
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
February 13, 2016, 07:41:20 AM
 #2

some info maybe it helps you out

http://www.ip-adress.com/ip_tracer/195.211.192.206
freebitcoin.co
Newbie
*
Offline Offline

Activity: 58
Merit: 0


View Profile
February 13, 2016, 08:53:31 AM
 #3

its most likely a proxy/vpn ip addresss
BitcoinSupremo
Copper Member
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 529


View Profile
February 13, 2016, 08:52:00 PM
 #4

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh
Your Point Is Invalid
Hero Member
*****
Offline Offline

Activity: 756
Merit: 510


Dear me, I think I'm becoming a god


View Profile WWW
February 13, 2016, 08:54:19 PM
 #5

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh
if 99% of people use blockchain.info then 99% of the time issues raised are going to be about them
OP just save your private keys, create a new wallet and import the keys to the new wallet, the hacker probably has your identifier

stingers (OP)
Legendary
*
Offline Offline

Activity: 1184
Merit: 1013


View Profile
February 14, 2016, 03:01:26 AM
 #6

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh
No it doesn't feel strange. There are thieves all over the world and this is like a natural thing to happen.

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh
if 99% of people use blockchain.info then 99% of the time issues raised are going to be about them
OP just save your private keys, create a new wallet and import the keys to the new wallet, the hacker probably has your identifier
Well yes, I am going to do that. But I was more worried about that how was he able to access my identifier and if he has my password too. Till now I have almost checked all my accounts(gmail etc ), none has been compromised. I wonder why did he try my blockchain.
A73841
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
February 14, 2016, 03:19:41 AM
 #7

are you sure that there is no maleware on your computer?

or maybe there is just random identifers on the net and yours was one of them
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2301


View Profile
February 14, 2016, 05:15:19 AM
 #8

IMO, it is highly unlikely that this person will ever be found, especially considering the number of hackers that are based in Russia

It does appear however that your blockchain.info identifier has been compromised and you should no longer actively use the identifier, addresses/private keys contained in that wallet, nor any HD seeds contained in that wallet. At an absolute minimum, you should create a new blockchain.info wallet, backup the private keys/seed associated with that wallet and send any BTC in the wallet that had the hacking attempt to your newly created wallet. (A better solution however would be to stop using a web wallet and use a wallet like electrum).

In addition to the possibility of having malware, it is possible that someone was able to access your email address that received an email from blockchain.info with your identifier.
Laosai
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


View Profile
February 14, 2016, 10:42:56 AM
 #9

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh
if 99% of people use blockchain.info then 99% of the time issues raised are going to be about them
OP just save your private keys, create a new wallet and import the keys to the new wallet, the hacker probably has your identifier

Good point but I'm not sure it's the real ratio. We should have a ledger somewhere to note all those kind of attacks to be sure on which is the most targeted.

james.lent
Hero Member
*****
Offline Offline

Activity: 602
Merit: 501



View Profile
February 14, 2016, 11:16:10 AM
 #10

Same thing just happened to me :



Damn KGBs  Undecided
mexxer-2
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1005


4 Mana 7/7


View Profile
February 14, 2016, 11:20:00 AM
 #11

Same thing just happened to me :

[img ]https://i.imgur.com/0QjNx2x.png?1[/img]

Damn KGBs  Undecided
Same here too, didn't use blockchain anyway. @QS it seems the hacker only knows the wallet-identifiers and is just brute-forcing as I did get an email only to confirm the login.
james.lent
Hero Member
*****
Offline Offline

Activity: 602
Merit: 501



View Profile
February 14, 2016, 11:22:25 AM
 #12

Same thing just happened to me :

[img ]https://i.imgur.com/0QjNx2x.png?1[/img]

Damn KGBs  Undecided
Same here too, didn't use blockchain anyway. @QS it seems the hacker only knows the wallet-identifiers and is just brute-forcing as I did get an email only to confirm the login.

Yeah i wonder how did they get the wallet-identifiers. I rarely use blockchain though. Been using localbitcoins for some years now  Grin
thugster
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
February 14, 2016, 12:50:55 PM
 #13

Just google up that IP. Its already showing that IP belongs to a hacker and also, that IP has IIS 7 running. So maybe someone can get out more info out of IIS7 thing?
stingers (OP)
Legendary
*
Offline Offline

Activity: 1184
Merit: 1013


View Profile
February 14, 2016, 12:57:23 PM
 #14

Okay great! Now everyone is being targeted(relieved to hear that I wasn't the only one being targeted). Blockchain guys should do something about it. They need to somehow stop the guys from brute forcing usernames, why can't they have some captchas if a users is acting in a fishy manner?  
james.lent
Hero Member
*****
Offline Offline

Activity: 602
Merit: 501



View Profile
February 14, 2016, 01:24:49 PM
 #15

Okay great! Now everyone is being targeted(relieved to hear that I wasn't the only one being targeted). Blockchain guys should do something about it. They need to somehow stop the guys from brute forcing usernames, why can't they have some captchas if a users is acting in a fishy manner?  

There must be a blockchain identifier dump somewhere on the deep web, gotta do some searching later. It's better to change all your email passwords too. No more blockchain wallets for me thats for sure.
Your Point Is Invalid
Hero Member
*****
Offline Offline

Activity: 756
Merit: 510


Dear me, I think I'm becoming a god


View Profile WWW
February 14, 2016, 01:35:03 PM
 #16

Okay great! Now everyone is being targeted(relieved to hear that I wasn't the only one being targeted). Blockchain guys should do something about it. They need to somehow stop the guys from brute forcing usernames, why can't they have some captchas if a users is acting in a fishy manner?  
There is no need, they cant do anything with just our identifiers, they would need to hack the password and they would also need to hack into our email to validate the login attempt

A73841
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
February 14, 2016, 01:46:57 PM
 #17

i just got some email that there was a login attempt to my wallet and this wallet is just 1 week old because i did try out blockchain.info
Slunt
Jr. Member
*
Offline Offline

Activity: 59
Merit: 10


View Profile
February 15, 2016, 03:35:38 PM
 #18

Did any of you have your alias as your username here or some sort of simple dictionary word? Wouldn't surprise me if hackers were using bots to try get hits on usernames and then focusing on the ones they find.

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh

If you can't keep your funds safe then using a desktop wallet wont be any good either. At least blockchain.info has several security features that prevent a hacker getting in. Even if they had your password and identifyer they wouldnt be able to get in without confirming via email and 2-factor if you have that set up which you should have and even then they wouldn't be able to spend the funds if you had a second password on.
BitcoinSupremo
Copper Member
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 529


View Profile
February 15, 2016, 06:46:50 PM
 #19

Did any of you have your alias as your username here or some sort of simple dictionary word? Wouldn't surprise me if hackers were using bots to try get hits on usernames and then focusing on the ones they find.

Doesn't it feel strange that all these strange things happens to one and only one online wallet, 99% of the cases is blockchain.info . Well after reading other stories here, I raise a reasonable doubt, why people should continue using it  Huh

If you can't keep your funds safe then using a desktop wallet wont be any good either. At least blockchain.info has several security features that prevent a hacker getting in. Even if they had your password and identifyer they wouldnt be able to get in without confirming via email and 2-factor if you have that set up which you should have and even then they wouldn't be able to spend the funds if you had a second password on.

If hackers brute forces it, he probably have the private keys, the best practice to follow is to create a new wallet, after you format your PC if you don't have any important documents there. If so create a new wallet straight after you have installed windows. Keep a copy of the private keys in a safe place, enable 2fa and email confirmation. And don't share your identifier in any other pc rather than this. Keep this as secure as you can with antivirus and antispyware.

Above all this, a wallet like Electrum is easy to maintain. Suppose you have just installed windows. Save electrum seed in a document in some safe place like USB or external HDD. Put a strong password to it, then start using it, chances of you getting hacked are very very small this way.
Never open that USB or external HDD in a infected PC. You can do more than this, but this is pretty basic things you need to know to have above normal security.
Mickeyb
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000

Move On !!!!!!


View Profile
February 15, 2016, 06:48:58 PM
 #20


If hackers brute forces it, he probably have the private keys, the best practice to follow is to create a new wallet, after you format your PC if you don't have any important documents there.
The OP is talking about Blockchain.info a web-based wallet service, so you obviously don't enter your priv key rather your password.
BitcoinSupremo
Copper Member
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 529


View Profile
February 15, 2016, 07:35:59 PM
 #21


If hackers brute forces it, he probably have the private keys, the best practice to follow is to create a new wallet, after you format your PC if you don't have any important documents there.
The OP is talking about Blockchain.info a web-based wallet service, so you obviously don't enter your priv key rather your password.


Yes but the hacker can have keylogger, so they check when OP logs in and get his private keys. In this scenario, nor 2FA nor EMail confirmation helps you out cause he can do whatever he likes with OP account. I thought OP was hacked, if not then I am very happy for him.
Mickeyb
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000

Move On !!!!!!


View Profile
February 15, 2016, 07:51:03 PM
 #22

Yes but the hacker can have keylogger, so they check when OP logs in and get his private keys. In this scenario, nor 2FA nor EMail confirmation helps you out cause he can do whatever he likes with OP account. I thought OP was hacked, if not then I am very happy for him.
If you read the previous posts, its highly likely someone is bruteforcing the passwords. Which if you don't know if not in anyway similar to keylogging, what you're saying does not even make sense. You mean to say email accounts of dozens of members have been compromised and the hackers haven't used them, stupid FFS
Dogedigital
Legendary
*
Offline Offline

Activity: 1330
Merit: 1000


View Profile
February 16, 2016, 07:26:40 PM
 #23

I received a few of these emails just the other day as well.

I'm in the opinion that an identifier list was leaked somehow.
james.lent
Hero Member
*****
Offline Offline

Activity: 602
Merit: 501



View Profile
February 17, 2016, 12:48:05 AM
 #24

I received a few of these emails just the other day as well.

I'm in the opinion that an identifier list was leaked somehow.

Thought the same, could be an inside job for all we know
warningsigns
Hero Member
*****
Offline Offline

Activity: 896
Merit: 1082


View Profile
February 17, 2016, 01:41:43 AM
 #25

Good to know. Moved my blockchain wallet's coins to my breadwallet app. Deleting my blockchain app now.


kingaltcoins
Hero Member
*****
Offline Offline

Activity: 784
Merit: 502


View Profile
February 18, 2016, 09:13:56 AM
 #26

I am wondering why are everyone not using Blockchain's Chrome extension app and not enabling more layers of security when they have such options available?



Try to add 2 factor with your email so whenever you send payments you will have to verify from your email. Also increase PBKDF2 Iterations to 20000 which will stretch your password to an extreme level.



Add a second password which must not be same as your login password and must be a harder one to brute force.
But do not set that password hint since anyone will get that hint if they knows the wallet identifier.



Block all TOR IP addresses by clicking that check-box and whitelist your IP for better protection. If possible try to restrict access to your whitelisted IP addresses only but you will not be able to open your wallet at all if you have a dynamic IP so be careful to check with your ISP for possible dynamic IPs before enabling this option.

I have taken all these secure measures and now my wallet is having 4 layers of security: Primary password + Secondary password + Email authentication + Block TOR IPs. I invite all the professional hackers to hack my wallet Cool
stingers (OP)
Legendary
*
Offline Offline

Activity: 1184
Merit: 1013


View Profile
February 18, 2016, 11:10:17 AM
 #27

I am wondering why are everyone not using Blockchain's Chrome extension app and not enabling more layers of security when they have such options available?



Try to add 2 factor with your email so whenever you send payments you will have to verify from your email. Also increase PBKDF2 Iterations to 20000 which will stretch your password to an extreme level.



Add a second password which must not be same as your login password and must be a harder one to brute force.
But do not set that password hint since anyone will get that hint if they knows the wallet identifier.



Block all TOR IP addresses by clicking that check-box and whitelist your IP for better protection. If possible try to restrict access to your whitelisted IP addresses only but you will not be able to open your wallet at all if you have a dynamic IP so be careful to check with your ISP for possible dynamic IPs before enabling this option.

I have taken all these secure measures and now my wallet is having 4 layers of security: Primary password + Secondary password + Email authentication + Block TOR IPs. I invite all the professional hackers to hack my wallet Cool
Chrome extention : No. I am using mobile most of the times. Also yes, these passwords can be used but it then kinda mixed up. Anyways what you said is correct for improving security. Thanks.
h3m96
Member
**
Offline Offline

Activity: 60
Merit: 10


View Profile
February 29, 2016, 03:16:09 AM
 #28

Stingers:  I got similar email on Feb 12 2016.  Had my blockchain wallet for maybe 2 years now, haven't signed in there in a long time.  Just FYI
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!