Bitcoin Forum
May 24, 2024, 08:06:58 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: mtgox account compromised minutes after requesting dwolla dep/with ability  (Read 4486 times)
donkeybozo (OP)
Newbie
*
Offline Offline

Activity: 34
Merit: 0



View Profile
May 02, 2013, 07:41:30 PM
 #1

Yesturday my mtgox account was finally verified and i had cash in the account. After my account was verified I requested to make deposit withdrawl using Dwolla possible in the future. and the system needed to verify that. Minutes after the system verified Dwolla someone purchased bitcoins with my cash and then transferred the btc to a outside address.
2x0ninja
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
May 02, 2013, 07:55:27 PM
 #2

Your computer is probably compromised. Not sure what you can do to get your money back.

Burn yourself a live CD (like ubuntu) and change your password from that. Then you'll probably want to backup your files (non executable only), reformat and reinstall your main OS. REFORMAT, DON'T JUST REINSTALL WINDOWS THAT MIGHT LEAVE FILES THAT COULD REINFECT YOU.
I'd recommend using a sandbox program for running downloaded files and your web browser. Sandboxie is my favorite and, last I checked, the most secure. It has a 30 day trail, but when it expires there's just a 5 sec nag screen and you still get full protection. There's also browser plugins that can help prevent you being hacked as well. Firefox with NoScript is a great start. Request Policy is another great one. Only allow sites you really trust, never allow things you just clicked on off of google. Also it's smart not to just google for porn or "free" downloads, find a few well established sites and stick to them.
donkeybozo (OP)
Newbie
*
Offline Offline

Activity: 34
Merit: 0



View Profile
May 02, 2013, 08:01:48 PM
 #3

Only used my smartphone when I would log on to GOX
dwolfman
Full Member
***
Offline Offline

Activity: 224
Merit: 100



View Profile WWW
May 02, 2013, 08:07:02 PM
 #4

You sure it was Mt Gox account that was compromised?  Maybe Dwolla was compromised.

Did you use different passwords everywhere?

Wanna send coins my way? 1BY2rZduB9j8Exa4158QXPFJoJ2NWU1NGf or just scan the QR code in my avatar.  :-)
donkeybozo (OP)
Newbie
*
Offline Offline

Activity: 34
Merit: 0



View Profile
May 02, 2013, 08:17:55 PM
 #5

Yes I did. I'm trying to understand the timing of the situation. Why would it happen minutes after I request deposit withdraw dwolla capability ?
tHash
Sr. Member
****
Offline Offline

Activity: 260
Merit: 250


View Profile
May 02, 2013, 10:44:01 PM
 #6

It has to be a coincidence.   For future reference, the only safe thing to do is use two factor authentication.
virtualfaqs
Hero Member
*****
Offline Offline

Activity: 700
Merit: 500



View Profile WWW
May 02, 2013, 10:47:57 PM
 #7

Get a Yobe key.

https://twitter.com/virtualfaqs
Looking for altcoin pump advice? Then follow me.
uuidman
Full Member
***
Offline Offline

Activity: 121
Merit: 100


View Profile
May 03, 2013, 12:21:40 AM
 #8

Only used my smartphone when I would log on to GOX
What OS, android or IOS ? Is the phone rooted or not ? How strong was the password used ?
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
May 03, 2013, 12:24:18 AM
 #9

You were using 2FA right?

Rhetorical questions as these events which happen on an almost daily basis never involve 2FA.  To any noob reading if you don't use 2FA you are one malware, 0-day java exploit, or phishing attack from losing your entire bitcoin savings in a split second.
ProfMac
Legendary
*
Offline Offline

Activity: 1246
Merit: 1001



View Profile
May 03, 2013, 12:30:35 AM
 #10

You were using 2FA right?

Rhetorical questions as these events which happen on an almost daily basis never involve 2FA.  To any noob reading if you don't use 2FA you are one malware, 0-day java exploit, or phishing attack from losing your entire bitcoin savings in a split second.

Mt. Gox sent me a Yubikey.  They paid the entire cost, and it was about 3 days from the time I submitted my street address until the package was at the front door.

The guy who lost 60 BTC last week had a rooted android.


I try to be respectful and informed.
coastermonger
Sr. Member
****
Offline Offline

Activity: 367
Merit: 250

Find me at Bitrated


View Profile
May 03, 2013, 02:43:46 AM
 #11

OP, most importantly were you using 2 factor authorization?

Bitrated user: Rees.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!