Bitcoin Forum
May 13, 2024, 01:25:43 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Just lost 6.4 bitcoins or 663 euros from MT.gox STOLEN  (Read 1520 times)
etheral (OP)
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
April 23, 2013, 01:49:36 AM
Last edit: April 23, 2013, 02:12:16 AM by etheral
 #1

http://i36.tinypic.com/2rrs9z8.jpg

Just noticed that an hour ago someone transferred approx 660 euros from my account

I used different email and mt.gox passwords, both very relatively strong and my pc is not infected

I have never opened any unknown executable files without scanning with virustotal.com

My only guess is that my account was hacked by some kind of bot that just brute forced my password

And I was just going to sleep... no words


I contacted mt.gox but of course I doubt they will be able to help

The worst thing is that I have no idea how this happened

Another thing that might have compromised me is lastpass add-on that stores my logins and passwords




thief who got my bitcoins: https://blockchain.info/address/1TM5uR7wRo3n5tr4NMpakuMEeU8TeFruS
info from Mt.Gox:

>Transaction reference: 07439aba-a384-4e72-9c0b-d2391a7fc35e
>
> Date: 2013-04-23 00:42:45 GMT
>
> IP: 78.108.63.44
>


feel my pain?: 1CoPSAzTBNYAuqi9tZq4hEK9B5HYsVWTTZ
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
1715606743
Hero Member
*
Offline Offline

Posts: 1715606743

View Profile Personal Message (Offline)

Ignore
1715606743
Reply with quote  #2

1715606743
Report to moderator
altmine2
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
April 23, 2013, 05:19:01 AM
 #2

Ouch that sounds pretty horrible. You may have been subject to a Man-In-The-Middle attack, or someone may have brute forced your password. Maybe someone stole your Mt.Gox session for a malicious website you visited. There are so many threats.

When picking a password, the longer you can go, the better.
Code:
Correct horse battery staple!
is a better password than
Code:
14Ms0l33t!$

Either way, I feel sorry for your loss. Hope it doesn't happen again!
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
April 23, 2013, 05:21:35 AM
 #3

2FA, is this hard?
shibaji
Full Member
***
Offline Offline

Activity: 308
Merit: 102



View Profile
April 23, 2013, 05:25:10 AM
 #4

2FA, is this hard?

What is the way to do 2FA at mt.gox ? I use this at blockchain.info but cannot see any 2FA via email at gox other than yubikey
advanced
Sr. Member
****
Offline Offline

Activity: 267
Merit: 250


Woodwallets.io


View Profile WWW
April 23, 2013, 06:34:39 AM
 #5

2FA, is this hard?

What is the way to do 2FA at mt.gox ? I use this at blockchain.info but cannot see any 2FA via email at gox other than yubikey

yubikey is 2FA, isn't it?

Bitmessage : BM-NAx31aEiqeq5zKUtxhKscXQ7Dwn1jJfR
shibaji
Full Member
***
Offline Offline

Activity: 308
Merit: 102



View Profile
April 23, 2013, 06:36:44 AM
 #6

2FA, is this hard?

What is the way to do 2FA at mt.gox ? I use this at blockchain.info but cannot see any 2FA via email at gox other than yubikey

yubikey is 2FA, isn't it?

Well, its a hassle and not free. Blockchain 2FA is much better.
BadBear
v2.0
Legendary
*
Offline Offline

Activity: 1652
Merit: 1127



View Profile WWW
April 23, 2013, 06:51:45 AM
 #7

2FA, is this hard?

What is the way to do 2FA at mt.gox ? I use this at blockchain.info but cannot see any 2FA via email at gox other than yubikey

yubikey is 2FA, isn't it?

Well, its a hassle and not free. Blockchain 2FA is much better.

Getting robbed and trying to recover it is even more of a hassle.

1Kz25jm6pjNTaz8bFezEYUeBYfEtpjuKRG | PGP: B5797C4F

Tired of annoying signature ads? Ad block for signatures
Remember remember the 5th of November
Legendary
*
Offline Offline

Activity: 1862
Merit: 1011

Reverse engineer from time to time


View Profile
April 23, 2013, 06:57:58 AM
 #8

The IP you have given corresponds to the Bitcoinica mtgox account hacker.

https://bitcointalk.org/index.php?topic=95738.0

BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
shibaji
Full Member
***
Offline Offline

Activity: 308
Merit: 102



View Profile
April 23, 2013, 06:58:23 AM
 #9

2FA, is this hard?

What is the way to do 2FA at mt.gox ? I use this at blockchain.info but cannot see any 2FA via email at gox other than yubikey

yubikey is 2FA, isn't it?

Well, its a hassle and not free. Blockchain 2FA is much better.

Getting robbed and trying to recover it is even more of a hassle.

True - I was just looking for a easier 2FA, if there is any. I do not keep much in Gox for this reason.
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1226


Away on an extended break


View Profile
April 23, 2013, 07:47:27 AM
 #10

A simple Google search reveals that this guy is a frequent thief. He apparently does not cover his tracks well, and he's most probably a member here....a simple taint search shows even I am connected to him somehow. He's probably behind the blockchain.info hacks involving whiskers75 and others too.

https://bitcointalk.org/index.php?topic=180261.0
etheral (OP)
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
April 23, 2013, 11:07:37 AM
 #11

I just analysed my passwords and the only places where I used the same password as for mt.gox are https://bitme.com/ and http://betsofbitco.in/   (I know - stupid)

I am 90% sure that one of these websites is connected to the breach of my mt.gox account

I am giving the other 9% to a few bitcoin mining programs and 1% for a brute force attack

I find it really sad that someone is working fulltime on scamming other people, very sad indeed
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1226


Away on an extended break


View Profile
April 23, 2013, 11:31:38 AM
 #12

There's a java exploit running rampant lately - did you visit any dodgy looking sites lately?
etheral (OP)
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
April 23, 2013, 11:40:56 AM
 #13

no, that's why I am 90% sure that one of these websites is connected
elux
Legendary
*
Offline Offline

Activity: 1458
Merit: 1006



View Profile
April 23, 2013, 11:49:12 AM
 #14

I just analysed my passwords and the only places where I used the same password as for mt.gox are https://bitme.com/ and http://betsofbitco.in/   (I know - stupid)

You just gave the hacker the information he needs to clean out any remaining balance from those two sites.

Same login/username too? What is bitme.com?
etheral (OP)
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
April 23, 2013, 12:29:10 PM
 #15

I don't have any balance on those sites
bitme was an exchange
jonytk
Member
**
Offline Offline

Activity: 106
Merit: 10



View Profile
April 23, 2013, 01:26:45 PM
 #16

2FA
use google authenticator if you have android !!!

that's why they say in the media bitcoins is for nerds...

you need a computer technician to certify your computer is clean and protected,

i worked as system administrator for the government and you cannot believe the amount of viruses i had to clean.

most likely you clicked a link related to bitcoin somwhere that uses the java /flash exploit.

Mushoz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Bitbuy


View Profile WWW
April 23, 2013, 01:34:39 PM
 #17

Mtgox supports google authenticator just like blockchain.info, so there's no reason at all not to use 2-FA for Mtgox. I'm sorry for your loss Sad

www.bitbuy.nl - Koop eenvoudig, snel en goedkoop bitcoins bij Bitbuy!
shibaji
Full Member
***
Offline Offline

Activity: 308
Merit: 102



View Profile
April 23, 2013, 10:06:13 PM
 #18

Mtgox supports google authenticator just like blockchain.info, so there's no reason at all not to use 2-FA for Mtgox. I'm sorry for your loss Sad

Please show me where. All I see is yubikey.
bizz
Hero Member
*****
Offline Offline

Activity: 492
Merit: 500


View Profile
April 23, 2013, 10:41:20 PM
 #19

Mtgox supports google authenticator just like blockchain.info, so there's no reason at all not to use 2-FA for Mtgox. I'm sorry for your loss Sad

Please show me where. All I see is yubikey.

https://mtgox.com/security

Quote
Welcome to the Mt.Gox Security Center.

Here you can secure your account by linking One Time Password (OTP) solutions such as a YubiKey or Google Authenticator to various account functions.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!