Bitcoin Forum
May 22, 2024, 06:21:54 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: My coins just got stolen from blockchain.info  (Read 3927 times)
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 03:22:37 AM
 #1

Two passwords, each unique to the site and a yubikey. Only device attached to the account was my cellphone - which was in my pocket while I was driving to work as this heist occurred.

https://blockchain.info/tx/1826f610d9dea7698d906da8f874974240204f42500fa621f1581c7023c6cc61

I think I'm going to vomit...
hiltonizer
Member
**
Offline Offline

Activity: 104
Merit: 10



View Profile
April 27, 2013, 03:40:13 AM
 #2

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.


DarkCoin: XiZutyRTPTEFQm5aH2de2SCmzfgE6B78uK
Bitcoin: 1P4wYgkKTh3WzHUGqLFaef23bAeM4UV2jB
proudhon
Legendary
*
Offline Offline

Activity: 2198
Merit: 1311



View Profile
April 27, 2013, 03:43:57 AM
 #3

Assuming this is legitimate, I'm very sorry.  So far it seems what's common among all these blockchain.info heists are linked mobile devices.  In any event, I no longer trust blockchain.info with any amount, whether my phone is linked or not.

Bitcoin Fact: the price of bitcoin will not be greater than $70k for more than 25 consecutive days at any point in the rest of recorded human history.
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 03:44:18 AM
 #4

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.



Well that's just lovely. Nice to know that memorizing those ridiculous passwords and buying a yubikey was worth it. Time to go print myself a paper wallet.
proudhon
Legendary
*
Offline Offline

Activity: 2198
Merit: 1311



View Profile
April 27, 2013, 03:46:25 AM
 #5

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.



IIRC, so far it's only been android devices.

Bitcoin Fact: the price of bitcoin will not be greater than $70k for more than 25 consecutive days at any point in the rest of recorded human history.
Fiyasko
Legendary
*
Offline Offline

Activity: 1428
Merit: 1001


Okey Dokey Lokey


View Profile
April 27, 2013, 03:50:07 AM
 #6

Mother.... fucking...... thieves....
We really need to identify how the hell this is happening to people!

http://bitcoin-otc.com/viewratingdetail.php?nick=DingoRabiit&sign=ANY&type=RECV <-My Ratings
https://bitcointalk.org/index.php?topic=857670.0 GAWminers and associated things are not to be trusted, Especially the "mineral" exchange
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 03:53:34 AM
 #7

Mother.... fucking...... thieves....
We really need to identify how the hell this is happening to people!

Well if it came from my phone, then I can tell you exactly where the malware came from, the only app I've installed in months is BitCare, because I needed a mining widget. I don't do much on my phone but make calls and such, I have a tablet for games et al and the blockchain app wasn't installed on the tablet.
cypherdoc
Legendary
*
Offline Offline

Activity: 1764
Merit: 1002



View Profile
April 27, 2013, 03:54:42 AM
 #8

this is why you don't use online wallets.

Armory is your safest bet.
datafish
Donator
Full Member
*
Offline Offline

Activity: 129
Merit: 100


Swimming in a sea of data


View Profile
April 27, 2013, 03:55:49 AM
 #9

Were you using the Blockchain app or a browser to access your account? 

I worry every time I update an app that one of these software authors got greedy.
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 03:57:45 AM
 #10

this is why you don't use online wallets.

Armory is your safest bet.

I usually only keep a little in there for convenience and keep the bulk of my coins in cold storage etc, but I got way too busy and ended up letting too much coin pile up. Keeping that many coins there was my error, but it still shouldn't happen. Maybe where bc.info is a service that stores peoples coins they could have an optional feature requiring email confirmation before sending more than a configurable amount? I won't feel bad if someone steals $50 because I screwed up, but this is too much.
shawshankinmate37927
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1000


Bitcoin: The People's Bailout


View Profile
April 27, 2013, 04:01:47 AM
Last edit: April 27, 2013, 11:12:22 AM by shawshankinmate37927
 #11

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.


IIRC, so far it's only been android devices.

If that's the case, I guess the reduced functionality of the iPhone version of the blockchain.info app ended up being a good thing.  I have the blockchain.info app installed on my non-jailbroken iPhone and linked to a wallet that does not use 2FA, or a second password, and I haven't had any coins stolen....knock on wood.

"It is well enough that people of the nation do not understand our banking and monetary system, for if they did, I believe there would be a revolution before tomorrow morning."   - Henry Ford
meowmeowbrowncow
Sr. Member
****
Offline Offline

Activity: 322
Merit: 250



View Profile
April 27, 2013, 04:03:36 AM
 #12


Sorry to hear.  I have also experience massive online theft.



I have been experiencing an odd behavior with blockchain.info for the past few days.  It no longer accepts my alias - and email alerts me that my browser user-agent string is unidentified (and it's indeed my real user-agent and IP.)


*shrugs*


"Bitcoin has been an amazing ride, but the most fascinating part to me is the seemingly universal tendency of libertarians to immediately become authoritarians the very moment they are given any measure of power to silence the dissent of others."  - The Bible
hiltonizer
Member
**
Offline Offline

Activity: 104
Merit: 10



View Profile
April 27, 2013, 04:06:06 AM
 #13

this is why you don't use online wallets.

Armory is your safest bet.

I don't think this is the fault of blockchain.info, well... maybe their mobile app... but this is why you don't use phone wallets.... which is a bit of a problem if its ever expected to be used for POS payments. Some enterprising genius better got on the stick.


DarkCoin: XiZutyRTPTEFQm5aH2de2SCmzfgE6B78uK
Bitcoin: 1P4wYgkKTh3WzHUGqLFaef23bAeM4UV2jB
hiltonizer
Member
**
Offline Offline

Activity: 104
Merit: 10



View Profile
April 27, 2013, 04:09:31 AM
 #14

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.



IIRC, so far it's only been android devices.

If you're savvy enough to use bitcoin, i'd hope your savvy enough to avoid iOS devices period. That said, I don't know of any bitcoin wallets for non-jailbroken iPhones (i may be wrong of course as I no longer use one)

DarkCoin: XiZutyRTPTEFQm5aH2de2SCmzfgE6B78uK
Bitcoin: 1P4wYgkKTh3WzHUGqLFaef23bAeM4UV2jB
wingsuit
Member
**
Offline Offline

Activity: 64
Merit: 10


2100 trillion sats baby


View Profile
April 27, 2013, 04:22:06 AM
 #15

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.



IIRC, so far it's only been android devices.

If you're savvy enough to use bitcoin, i'd hope your savvy enough to avoid iOS devices period. That said, I don't know of any bitcoin wallets for non-jailbroken iPhones (i may be wrong of course as I no longer use one)

The blockchain info app is a fully functional wallet

FLY
shawshankinmate37927
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1000


Bitcoin: The People's Bailout


View Profile
April 27, 2013, 04:37:01 AM
 #16

a lot of these threads here and on reddit the last few days... common factor always seem to be a cell phone. I think its fair to say some cell phone malware is going around.



IIRC, so far it's only been android devices.

If you're savvy enough to use bitcoin, i'd hope your savvy enough to avoid iOS devices period. That said, I don't know of any bitcoin wallets for non-jailbroken iPhones (i may be wrong of course as I no longer use one)

The blockchain info app is a fully functional wallet

Straight from https://blockchain.info/wallet/iphone-app:

"Where can I download it?
Due to restrictions from Apple the bitcoin wallet functionaility is not available in the app store version. However it is still available for free download with limited features.

For Jailbroken iphones the app is also available in TheBigBoss.org Cydia Repository"




"It is well enough that people of the nation do not understand our banking and monetary system, for if they did, I believe there would be a revolution before tomorrow morning."   - Henry Ford
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 05:15:27 AM
 #17

Live and learn I guess. I've washed my pants with my physical leather wallet in them plenty of times, it was only a matter of time before I did the digital equivalent. I kind of wish I'd been more vigilant about keeping less cash in said wallet, but it happens. I've updated all my posted addresses, informed those who had the old ones saved, etc. Time to start being more careful about moving to cold storage again.
zebedee
Donator
Hero Member
*
Offline Offline

Activity: 668
Merit: 500



View Profile
April 27, 2013, 05:16:00 AM
 #18

Wow, no end to the number of these Sad  I feel something undetected has happened to the site itself.
jubalix
Legendary
*
Offline Offline

Activity: 2618
Merit: 1022


View Profile WWW
April 27, 2013, 05:18:13 AM
 #19

Two passwords, each unique to the site and a yubikey. Only device attached to the account was my cellphone - which was in my pocket while I was driving to work as this heist occurred.

https://blockchain.info/tx/1826f610d9dea7698d906da8f874974240204f42500fa621f1581c7023c6cc61

I think I'm going to vomit...

how does it get past yubi key and 2 passwords....did it inject a redirect???

Admitted Practicing Lawyer::BTC/Crypto Specialist. B.Engineering/B.Laws

https://www.binance.com/?ref=10062065
enmaku (OP)
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


View Profile
April 27, 2013, 05:20:03 AM
 #20

Wow, no end to the number of these Sad  I feel something undetected has happened to the site itself.

Apparently it's some kind of Android-based malware, so my phone was probably the culprit. What's really embarrassing is that I'm one of the "Ease of Use" panelists at the Bitcoin 2013 conference next month and I was about to sing their praises for how much easier they've made things.

It's always embarrassing to be the victim of theft I suppose, but everyone will lose some coins eventually, it's all about minimizing your losses. Thankfully I do keep the bulk of my coins in cold storage, I'd just taken a few too many coins in and hadn't sent them off to cold storage in way too long - an oversight I doubt I'll repeat after learning a $1,000 lesson.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!