Bitcoin Forum
April 19, 2024, 11:07:46 PM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Bitcoin redirected from my address as soon as it was sent to me  (Read 1946 times)
securus (OP)
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
July 29, 2016, 10:07:36 AM
 #1

I don’t know if the is the right list, but I hope someone can advise.

In the early hours of this morning I sent 1.01 BTC from my Xapo wallet to the address 12iocUthp58E72ZksRmToDFPfM1WCPKv91. This is an address in my Bitcoin Core wallet, running on my laptop, for which I control the private key. My client had been running all day and the blockchain was synced and up-to-date.

The instant that this amount was received into the above address (before the transaction was even confirmed) the entire amount was then sent to another address 1aa5cmqmvQq8YQTEqcTmW7dfBNuFwgdCD which I have never heard and do not have the private key for, something which I did not think was possible.

What the hell happened and where is my Bitcoin?
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
You get merit points when someone likes your post enough to give you some. And for every 2 merit points you receive, you can send 1 merit point to someone else!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
1713568066
Hero Member
*
Offline Offline

Posts: 1713568066

View Profile Personal Message (Offline)

Ignore
1713568066
Reply with quote  #2

1713568066
Report to moderator
Xanidas
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500



View Profile WWW
July 29, 2016, 10:25:20 AM
 #2

looks like the destination address is linked to some issues in the past.

https://bitcointalk.org/index.php?topic=1175321.msg12715624#msg12715624
https://bitcointalk.org/index.php?topic=1293658.msg13305218#msg13305218

not sure what happened to you but maybe your computer is infected by some kind of malware


NEUROMATION

▀▀
██
 
██
   
██
   
██
   
██
   
██
▄▄
    █▄     
    ███▄   
    ██▀██▄ 
█▄   ▀  ▀██▄
███▄      ██
██▀██▄    ██
██  ▀██▄  ██
██    ▀██▄██
██▄     ▀███
 ▀██▄  ▄  ▀█
   ▀██▄██   
     ▀███   
       ▀█   
▀▀
██
 
██
   
██
   
██
   
██
   
██
▄▄
....Distributed Synthetic Data Platform for Deep Learning Applications....
▬ ● ● ● ● ▬▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬ ● ● ● ● ▬▬▬▬▬▬ ● ● ● ● ▬
Facebook LinkedIn Twitter White Paper Reddit YouTube Medium
▀▀
██
 
██
   
██
   
██
   
██
   
██
▄▄
NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6349


Looking for campaign manager? Contact icopress!


View Profile
July 29, 2016, 10:29:40 AM
 #3

looks like the destination address is linked to some issues in the past.

https://bitcointalk.org/index.php?topic=1175321.msg12715624#msg12715624
https://bitcointalk.org/index.php?topic=1293658.msg13305218#msg13305218

not sure what happened to you but maybe your computer is infected by some kind of malware

Whether it's infected or was in the past, clearly somebody else got OPs private key and transferred out those BTC.

What the hell happened and where is my Bitcoin?

It was stolen. Sorry.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
securus (OP)
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
July 29, 2016, 10:39:59 AM
 #4

Thanks for your replies.

I am running Bitcoin-Qt on a mac that I have just recently installed so the possibility of Malware is small. The coins were transferred out the exact same second as they arrived, and before the transaction was confirmed, I did not think that was possible.
NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6349


Looking for campaign manager? Contact icopress!


View Profile
July 29, 2016, 11:16:50 AM
 #5

Thanks for your replies.

I am running Bitcoin-Qt on a mac that I have just recently installed so the possibility of Malware is small. The coins were transferred out the exact same second as they arrived, and before the transaction was confirmed, I did not think that was possible.



The attacker has your private key. Even your wallet knows you've got money in the second they've came in.
It's not that difficult to code something similar and when the "money in" notification comes, the money is sent out by a script.
It doesn't have to be on your computer. The attacker has your private key and can do all this on his own computer.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Shiroslullaby
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
July 29, 2016, 12:00:21 PM
 #6

You said the Mac OS was recently installed.
Did you wipe your computer at some point? Have you ever had malware detected in the past?

Also if someone can post some technical details of how you would make a script to monitor a BTC address, that would be really interesting.
I'm going to do some research on the topic on my lunch break today.
(Is it similar to how miners get notified when they discover a block?)

DannyHamilton
Legendary
*
Offline Offline

Activity: 3360
Merit: 4570



View Profile
July 29, 2016, 12:32:03 PM
 #7

- snip -
to the address 12iocUthp58E72ZksRmToDFPfM1WCPKv91. This is an address in my Bitcoin Core wallet, running on my laptop, for which I control the private key.
- snip -
The instant that this amount was received into the above address (before the transaction was even confirmed) the entire amount was then sent to another address 1aa5cmqmvQq8YQTEqcTmW7dfBNuFwgdCD which I have never heard and do not have the private key for
- snip -
What the hell happened and where is my Bitcoin?

You do not have exclusive control of the private key.  Someone else has that private key as well.

How did you get that address and private key?  Did you generate the address with the Bitcoin Core wallet immediately before sending the transaction? Did you import the private key into Bitcoin Core?  Was it generated with VanityGen?  Was is generated with bitaddress.org?  Was it a "brainwallet", generated from a passphrase?  Did you get the private key from someone else?

If you generated the address with the Bitcoin Core wallet, have you ever had that wallet.dat file installed on any other computer in the past?

- snip -
The coins were transferred out the exact same second as they arrived, and before the transaction was confirmed, I did not think that was possible.

It is.

It is a good idea to wait until a transaction is confirmed before you spend the bitcoins that are received from the transactions (just in case the transaction never confirms), but it is not necessary to wait for confirmation.  Unconfirmed bitcoins can be spent.
securus (OP)
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
July 29, 2016, 12:32:39 PM
 #8

Quote
The attacker has your private key. Even your wallet knows you've got money in the second they've came in.
It's not that difficult to code something similar and when the "money in" notification comes, the money is sent out by a script.
It doesn't have to be on your computer. The attacker has your private key and can do all this on his own computer.

I was given to understand that it was not possible to spend unconfirmed coins on your address, I still don't understand how they were able to send the coins the instant they arrived.

I too am intrigued on how you would go about doing this.
 
securus (OP)
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
July 29, 2016, 12:39:05 PM
 #9

Quote
It is.

It is a good idea to wait until a transaction is confirmed before you spend the bitcoins that are received from the transactions (just in case the transaction never confirms), but it is not necessary to wait for confirmation.  Unconfirmed bitcoins can be spent.

You must have replied the same time as me.

I have indeed imported some keys into my wallet.

I transferred my entire balance to my Coinbase account and deleted/recreated my wallet.dat file. An expensive lesson but it could have been lot worse.
DannyHamilton
Legendary
*
Offline Offline

Activity: 3360
Merit: 4570



View Profile
July 29, 2016, 12:43:48 PM
 #10

I have indeed imported some keys into my wallet.

Where did those keys come from?

If it was a source that you thought was trustworthy, then it might be a good idea to warn others not to use that source.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
July 31, 2016, 10:19:48 AM
 #11

You do not have exclusive control of the private key.  Someone else has that private key as well.
true

Quote
It was stolen. Sorry.
It was taken. Not stolen.

I was given to understand that it was not possible to spend unconfirmed coins on your address,
It is possible.

Quote
I still don't understand how they were able to send the coins the instant they arrived.
Your knowledge about bitcoin network has gaps. Live with it or teach yourself.
PremiumCodeX
Hero Member
*****
Offline Offline

Activity: 1204
Merit: 531


Metaverse 👾 Cyberweapons


View Profile
July 31, 2016, 01:56:27 PM
 #12

OP, I am sorry for your loss, your BTC was taken. In fact, there are MAC malware, but whoever took your BTC did not need it if he had your private key. Since I really cannot see a way to recover your value, I advise you to use additional anti-malware software on your computer and make sure you have exclusive knowledge of your private key to prevent similar cases in the future.

Also if someone can post some technical details of how you would make a script to monitor a BTC address, that would be really interesting.
I'm going to do some research on the topic on my lunch break today.
(Is it similar to how miners get notified when they discover a block?)

I wondered the same some days ago and I was advised to check some BTC block explorer to discover the relations of a BTC address. After the update where you automatically get a new address after each transaction, you may do not want to monitor a BTC address but a person's BTC addresses, but as far as I know, it still is possible with block exploring.

[TUTORIAL] How to steal $350 000?
Best OS for recovering stolen BTCs.
Visit our FREE Bitcointalk thread.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
July 31, 2016, 02:14:33 PM
 #13

Also if someone can post some technical details of how you would make a script to monitor a BTC address, that would be really interesting.
I'm going to do some research on the topic on my lunch break today.
(Is it similar to how miners get notified when they discover a block?)
Start with this https://github.com/sebicas/bitcoin-sniffer
And ask me anything.
DannyHamilton
Legendary
*
Offline Offline

Activity: 3360
Merit: 4570



View Profile
July 31, 2016, 08:07:14 PM
 #14

It was taken. Not stolen.

If something is taken, and the taker doesn't have permission to take it, then it is stolen.
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
July 31, 2016, 08:14:47 PM
 #15

If something is taken, and the taker doesn't have permission to take it, then it is stolen.
OK, seems to me that OP stolen my private key and its address  Grin
Should I prove that 12iocUthp58E72ZksRmToDFPfM1WCPKv91 belongs to me?  Grin
NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6349


Looking for campaign manager? Contact icopress!


View Profile
August 01, 2016, 02:28:27 PM
 #16

If something is taken, and the taker doesn't have permission to take it, then it is stolen.
OK, seems to me that OP stolen my private key and its address  Grin
Should I prove that 12iocUthp58E72ZksRmToDFPfM1WCPKv91 belongs to me?  Grin

Although you are Legendary rank, with your trust rating with so much RED, I am inclined to believe that you've got a newbie's private keys (and money), or you are trying to imply that.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
August 01, 2016, 02:36:47 PM
 #17

Although you are Legendary rank, with your trust rating with so much RED, I am inclined to believe that you've got a newbie's private keys (and money), or you are trying to imply that.
You are insulting me undeservedly. I did not touch money. At least you will not be able to prove it.
I encourage you to look up words and terms not misleading readers.
NeuroticFish
Legendary
*
Offline Offline

Activity: 3654
Merit: 6349


Looking for campaign manager? Contact icopress!


View Profile
August 01, 2016, 02:55:38 PM
 #18

Although you are Legendary rank, with your trust rating with so much RED, I am inclined to believe that you've got a newbie's private keys (and money), or you are trying to imply that.
You are insulting me undeservedly. I did not touch money. At least you will not be able to prove it.
I encourage you to look up words and terms not misleading readers.

I did not say anything I cannot prove.
I did not say you did anything. I said that I am inclined to believe you did.
And I pointed out your trust rating, which is red, nothing special to prove there.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
amaclin
Legendary
*
Offline Offline

Activity: 1260
Merit: 1019


View Profile
August 01, 2016, 03:14:26 PM
Last edit: August 01, 2016, 03:25:23 PM by amaclin
 #19

I said that I am inclined to believe you did.
Oups, sorry. You may also believe that I am a murderer of JFK. Grin

Quote
with your trust rating with so much RED
I do not care about it. This is your problem to look at the rank, not mine.
cr1776
Legendary
*
Offline Offline

Activity: 4018
Merit: 1299


View Profile
August 01, 2016, 03:34:47 PM
 #20

I don’t know if the is the right list, but I hope someone can advise.

In the early hours of this morning I sent 1.01 BTC from my Xapo wallet to the address 12iocUthp58E72ZksRmToDFPfM1WCPKv91. This is an address in my Bitcoin Core wallet, running on my laptop, for which I control the private key. My client had been running all day and the blockchain was synced and up-to-date.

The instant that this amount was received into the above address (before the transaction was even confirmed) the entire amount was then sent to another address 1aa5cmqmvQq8YQTEqcTmW7dfBNuFwgdCD which I have never heard and do not have the private key for, something which I did not think was possible.

What the hell happened and where is my Bitcoin?


One question, you also had said previously that you had imported some keys. Was this one of them?

And as DH asked above, where did those keys come from?
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!