Bitcoin Forum
May 09, 2024, 10:13:20 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Help recover stolen bitcoins?? How did it happen?  (Read 1913 times)
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 10:00:33 AM
Last edit: October 18, 2017, 11:31:51 AM by Philopolymath
 #1

So somehow I fucked up and all my coins were send to this address
1ARHwvB4nKVPhRRgvdJCctxXwogi1ePbu2

Any way to track or reverse it?

https://blockchain.info/address/1ARHwvB4nKVPhRRgvdJCctxXwogi1ePbu2

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
1715249600
Hero Member
*
Offline Offline

Posts: 1715249600

View Profile Personal Message (Offline)

Ignore
1715249600
Reply with quote  #2

1715249600
Report to moderator
1715249600
Hero Member
*
Offline Offline

Posts: 1715249600

View Profile Personal Message (Offline)

Ignore
1715249600
Reply with quote  #2

1715249600
Report to moderator
No Gods or Kings. Only Bitcoin
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715249600
Hero Member
*
Offline Offline

Posts: 1715249600

View Profile Personal Message (Offline)

Ignore
1715249600
Reply with quote  #2

1715249600
Report to moderator
1715249600
Hero Member
*
Offline Offline

Posts: 1715249600

View Profile Personal Message (Offline)

Ignore
1715249600
Reply with quote  #2

1715249600
Report to moderator
Jonashe
Full Member
***
Offline Offline

Activity: 194
Merit: 100


CryptoPuzzle.com developer


View Profile WWW
October 18, 2017, 10:08:14 AM
 #2

So somehow I fucked up and all my coins were send to this address
1ARHwvB4nKVPhRRgvdJCctxXwogi1ePbu2

Any way to track or reverse it?

https://blockchain.info/address/1ARHwvB4nKVPhRRgvdJCctxXwogi1ePbu2


It was a hack ? Or you did a accidental "swaping" between service ?

https://cryptopuzzle.com : NFT token on Ethereum Blockchain. Now on beta test on Ropsten Ethereum Network !
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 10:11:35 AM
 #3

I have no idea?

Status: 21 confirmations
Date: 10/18/2017 02:09
To: 1ARHwvB4nKVPhRRgvdJCctxXwogi1ePbu2
Debit: -0.62667325 BTC
Transaction fee: -0.00028510 BTC
Net amount: -0.62695835 BTC
Transaction ID: a7b7a674334c2fb313de0861df79e45dc7e756b81f7d21025851dae86eccdb1b
Transaction total size: 5650 bytes
Output index: 0

I did NOT SEND THIS TX

My wallet is core and I had a passphrase and it was locked.
I changed my passphrase after the TX...

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
annmarie
Jr. Member
*
Offline Offline

Activity: 52
Merit: 10


View Profile
October 18, 2017, 10:23:39 AM
 #4

If you didn't send it then someone has access to your private key. if you have any other wallets on your computer with bitcoin in them consider them compromised and move them to a clean computers wallet straight away.

there isnt a way you can reverse transactions.
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 11:35:22 AM
 #5

I recently tried adding  blockchain wallet and bitcoin.com wallet

One of these must have exposed me to the theft?

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
October 18, 2017, 11:39:12 AM
 #6

Passphrase and/or locked wallet ONLY affects the wallet.dat file... if the hacker had your private key, then all the passphrases in the world won't save you. Did you ever export the private key for the address: 1Q1PDnwmbFkNaYbpsiPVUBJe1pEM7m8zYH? Huh

As annmarie suggested, that entire wallet should be considered compromised and you should no longer receive ANY coins to it. I recommended moving any coins you have left to a new wallet immediately. I see that 1Q1PDnwmbFkNaYbpsiPVUBJe1pEM7m8zYH just received more coins today. You need to STOP using that address immediately and move those coins as soon as possible.  Shocked

You should probably also scan your computer for viruses/malware.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 11:43:53 AM
 #7

I did dump the private key planning to write it out on paper...

Since the hack I deleted my hacked wallet.dat
then restarted core to generate a new address and made a new passphrase.

My anti virus scan didn't catch anything

Is my NEW address also compromised?
Does it not generate a new private key?

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
October 18, 2017, 12:00:28 PM
 #8

Most likely dumping the private key out of the wallet and into either a text file or the screen has allowed someone to get access to your private key... It is the only logical explanation for why all your coins got moved without you transferring them.

It is hard to know if your new wallet is compromised or not... The only way to be completely sure is to completely wipe the entire system, reformat and reinstall your operating system...

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 12:59:20 PM
 #9

Fcuk they just got the latest payout to a new address and key !!!

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
Aegean Skipper
Full Member
***
Offline Offline

Activity: 378
Merit: 126



View Profile
October 18, 2017, 01:05:25 PM
 #10

So your PC is compromised or hacked in any way.

Remove the drive from the computer, add it to another PC as secondary and scan it for viruses and malware with more than one antivirus
Stedsm
Legendary
*
Offline Offline

Activity: 3052
Merit: 1273



View Profile
October 18, 2017, 01:15:42 PM
 #11

I did dump the private key planning to write it out on paper...

Since the hack I deleted my hacked wallet.dat
then restarted core to generate a new address and made a new passphrase.

My anti virus scan didn't catch anything

Is my NEW address also compromised?
Does it not generate a new private key?

If your PC's server is hacked anyhow, then I guess nothing that is put on it should be considered as "SAFE" tbh.
Btw, as you received some more coins today over your address, I want to know that were they also sent by the hacker only or you sent them to some other address? As everyone asked, did you try to IMPORT/EXPORT your key to/from somewhere else? Because it makes your key prone to getting hacked as it's all online and if not, then possibly there's someone who had access to your PC either through the network or "by personally using it from your space" < (this looks less likely).

Your NEW address is not compromised unless it has a new PRIVATE KEY (yes, it is obvious that whenever you use a new address, it has its own identity or I must say: PRIVATE KEY). But when you know now that you have had been attacked like this, why don't you stop using these services from the same PC (if everything happened offline) and start using it from another PC (not a public computer).

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 18, 2017, 01:22:33 PM
 #12

the drive passed several anti virus scans...

I'm wiping and formating and installing a clean fresh windows now on another comp

This drive is a clone so i must kill it also


Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
Philopolymath (OP)
Sr. Member
****
Offline Offline

Activity: 558
Merit: 295

Walter Russell's Cosmogony is RIGHT!


View Profile
October 23, 2017, 12:26:15 AM
 #13

But HOW did they know my address? and access my comp? And find My prvate key?

I want these fucking thieves to burn a slow painful death

Support Alien Beer Circle research...www.youtube.com/watch?v=MRXDk2RMQ4A
monkeydominicorobin
Full Member
***
Offline Offline

Activity: 294
Merit: 104


✪ NEXCHANGE | BTC, LTC, ETH & DOGE ✪


View Profile
October 23, 2017, 08:40:46 AM
 #14

I did dump the private key planning to write it out on paper...

Since the hack I deleted my hacked wallet.dat
then restarted core to generate a new address and made a new passphrase.

My anti virus scan didn't catch anything

Is my NEW address also compromised?
Does it not generate a new private key?

I cannot possibly correct your Microsoft Windows Lifestyle. But allow me to remind you that "anti-virus" programs are a bunch of fraud. Never ever rely on a fraud. They are just windows with progress bars. Most probably your anti-virus is just a trojan. And most of you who uses Windows Operating System have this notion that antivirus programs are legit and you never suspect it. Antivirus program is not a god. Do not worship it. Shift to using Linux and this thing will never happen again. Study LINUX. You will never ever have this problem again. You will not need a stupid antivirus or anti-malware created by fraudsters. To steal your Bitcoins.

LoyceV
Legendary
*
Offline Offline

Activity: 3304
Merit: 16623


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
October 23, 2017, 09:03:22 AM
 #15

You should probably also scan your computer for viruses/malware.
That's not enough: It's always wise to assume your computer has been compromised, so backup and reinstall before making a new wallet.

Since the hack I deleted my hacked wallet.dat
Satoshi recommended to never delete a wallet, so just in case: keep your old wallet too, just don't send any coins to it ever again.

Quote
Is my NEW address also compromised?
You can never be sure about this, that's why it's safest to assume your computer is compromised. Unless someone found your piece of paper with the private key, the theft must have happened from your computer.

But HOW did they know my address? and access my comp? And find My prvate key?
Windows can run many virusses that are designed to steal your Bitcoins.

It sucks now, but for future use: create cold storage offline! Writing down a private key from a hot wallet on a piece of paper is much riskier than creating a paper wallet offline from a Linux LIVE CD.

DannyHamilton
Legendary
*
Offline Offline

Activity: 3388
Merit: 4653



View Profile
October 23, 2017, 09:19:46 AM
Merited by bones261 (1)
 #16

the drive passed several anti virus scans...

In that case, it probably is not a virus.  It is probably malware.  At some point in the past, you may have installed a program that you thought was legitimate, and that program was probably designed to steal your bitcoins.

Have you ever installed any pirated software on your computer?
Have you installed wallets for any altcoins on your computer?

Both of those are very common ways to unknowingly install malware.

The other possibility is that you downloaded software from a phishing site without realizing it.  Some phishing sites can look exactly like the real site.  When was the last time that you downloaded some software from a website?

But HOW did they know my address? and access my comp? And find My private key?

I want these fucking thieves to burn a slow painful death

Malware on your computer can look for an installed wallet. It can then capture your password as you type it.  Once it has your wallet and your password, it can access your private keys and spend your bitcoins.
Thekool1s
Legendary
*
Offline Offline

Activity: 1512
Merit: 1218


Change is in your hands


View Profile
October 23, 2017, 10:33:14 AM
 #17

You cant do much, unless you know how to monitor your outgoing traffic, there are many softwares which can help you with this. Lookout for strange ips your computer is trying to communicate with, You may get lucky and find your attackers ip, if they are not using any sorts of proxies or vpns. That's your only chance of finding out who was behind the attack. Other than that you can't do much sadly.
jnano
Member
**
Offline Offline

Activity: 301
Merit: 74


View Profile
October 23, 2017, 09:53:41 PM
 #18

What OS are you running?
Did you do stuff over WiFi recently?

There's a recent WiFi vulnerability. I don't know if it's related or what kind of information can leak, but have a look:
https://www.bleepingcomputer.com/news/security/list-of-firmware-and-driver-updates-for-krack-wpa2-vulnerability/

In that case, it probably is not a virus.  It is probably malware.
Nowadays these are practically synonyms, and antiviruses detect both.
DannyHamilton
Legendary
*
Offline Offline

Activity: 3388
Merit: 4653



View Profile
October 23, 2017, 10:36:33 PM
 #19

In that case, it probably is not a virus.  It is probably malware.
Nowadays these are practically synonyms,

No, they aren't.

In that case, it probably is not a virus.  It is
and antiviruses detect both.

Anti-virus software may try to detect some malware, but it would be impossible for it to detect all malware.
alexjhons
Member
**
Offline Offline

Activity: 69
Merit: 10


View Profile
October 25, 2017, 10:52:04 AM
 #20

It is tough to know if your new wallet is compromised or not... you should completely refresh the entire system or reinstallation process.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!