Bitcoin Forum
May 04, 2024, 04:47:25 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Poll
Question: Does anyone know how this happened?
A - 0 (0%)
B - 0 (0%)
Total Voters: 0

Pages: [1]
  Print  
Author Topic: Electrum Wallet Hacked  (Read 676 times)
pegasus9847 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 08, 2017, 11:32:20 PM
 #1

I recently opened electrum wallet to discover that 7.26 BTC was sent to an unknown address on Oct. 2.  I keep this wallet on a thumb drive, and the last time it had been connected online was late August.  If anyone has had a similar experience or could offer any thoughts on how this happened, I'd appreciate it.  Thanks.
1714841245
Hero Member
*
Offline Offline

Posts: 1714841245

View Profile Personal Message (Offline)

Ignore
1714841245
Reply with quote  #2

1714841245
Report to moderator
1714841245
Hero Member
*
Offline Offline

Posts: 1714841245

View Profile Personal Message (Offline)

Ignore
1714841245
Reply with quote  #2

1714841245
Report to moderator
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714841245
Hero Member
*
Offline Offline

Posts: 1714841245

View Profile Personal Message (Offline)

Ignore
1714841245
Reply with quote  #2

1714841245
Report to moderator
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
November 09, 2017, 12:32:42 AM
 #2

The thumb drive still had to be connected to a computer in order to go online with it.  Your computer most likely has a virus/malware on it.  If you want to post the TX here we can take a look to try and help.  Is there any chance you did a transaction and the 7.26 BTC was moved by Electrum to a change address in the same wallet?  You would still see the balance in your Electrum wallet, but the original address would appear empty.  This is how Electrum operates to protect you.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
pegasus9847 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 09, 2017, 12:40:29 AM
 #3

Thanks for responding.
This is the TX;

View on BTC.com
Bitcoin TRANSACTION
8884292a996c1515acade6d6c2ac3cbb4fa7079c3bd504249ee1e151049636b4
aplistir
Full Member
***
Offline Offline

Activity: 378
Merit: 197



View Profile
November 09, 2017, 06:37:43 AM
 #4

The thumb drive still had to be connected to a computer in order to go online with it.  Your computer most likely has a virus/malware on it.  If you want to post the TX here we can take a look to try and help.  Is there any chance you did a transaction and the 7.26 BTC was moved by Electrum to a change address in the same wallet?  You would still see the balance in your Electrum wallet, but the original address would appear empty.  This is how Electrum operates to protect you.

Could be malware, but that is not the only possibility.
Could have been a weak private key or brainwallet
Could be someone who had access to your USB-key. Who knows

I do not think any bitcoin wallet checks that a private key is not weak. But of course it is extremely unlikely, because there are so many possible keys.

My Address: 121f7zb2U4g9iM4MiJTDhEzqeZGHzq5wLh
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5636


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
November 09, 2017, 09:51:23 AM
 #5

I recently opened electrum wallet to discover that 7.26 BTC was sent to an unknown address on Oct. 2.  I keep this wallet on a thumb drive, and the last time it had been connected online was late August.  If anyone has had a similar experience or could offer any thoughts on how this happened, I'd appreciate it.  Thanks.

Unfortunately you are not the only one who lost BTC in a similar way and what is the cause of this we can only guess.Since you have your wallet on thumb drive there is a possibility that there is someone other than you use this drive and stole your coins.But more likely that you somehow exposed your seed/private keys on your PC/laptop and hacker found a way to steal them.

The only safe way for keep you coins safe is hardware wallet in case you need to access them on a daily basis,or paper wallet like cold storage.Identical theft case like yours has been recently reported here : https://bitcointalk.org/index.php?topic=2320352.msg23565839#msg23565839

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
cynical
Full Member
***
Offline Offline

Activity: 490
Merit: 136



View Profile
November 09, 2017, 11:23:12 AM
 #6

hmm strange one this.
is your pen drive encrypted or is it a standard plug and play drive?
I have no idea how this might have happened, just throwing another question into the mix

████          O W N R   W A L L E T          ████   VISA PREPAID CARD    ████  Use crypto to pay in stores with OWNR  ████
❱❱❱❱ ❱❱❱ ❱❱ ❱     Buy, send, receive and exchange crypto        VISA   mastercard   SPA   UnionPay     ❰ ❰❰ ❰❰❰ ❰❰❰❰
BLOG       TWITTER     ██ █▌█ ▌     Manage crypto and VISA card in OWNR Wallet app    ▐ █▐█ ██     REDDIT   YOUTUBE
pegasus9847 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 09, 2017, 03:24:17 PM
 #7

Thanks to all who responded.  Just a little background, although thumb drive was standard, I password protected the individual files with Axcrypt.  I was using Malwarebytes and Eset full security but I think I found a files that could be the culprit to all this.  It was something like service.hostexe* and when I clicked on it, a pop-up appeared asking for a password and username. I did some research on this and it is described as a threat, although there is no way to know if this was responsible for the hack.  When I deleted it, it aromatically reinstalled itself upon reboot. It went undedected, but for any one who is curious, it was found in app data...roaming.  I have since reformatted my hard drive and it is no longer there. One this I noticed was that when you unplug a thumb drive from a pc, it writes some of the files to your hard drive which seems counterintuitive since one point of using an external drive is for privacy.

I know there is nothing I can do at this point, but I hope this helps someone in the future.


Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
November 09, 2017, 11:56:00 PM
 #8

I see that you found your answer.  Sucks though because that's 50 Grand in coin.  Others reading along here, please consider either going "cold" wallet or hardware wallet.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5636


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
November 10, 2017, 10:19:14 AM
 #9

Thanks to all who responded.  Just a little background, although thumb drive was standard, I password protected the individual files with Axcrypt.  I was using Malwarebytes and Eset full security but I think I found a files that could be the culprit to all this.  It was something like service.hostexe* and when I clicked on it, a pop-up appeared asking for a password and username. I did some research on this and it is described as a threat, although there is no way to know if this was responsible for the hack.  When I deleted it, it aromatically reinstalled itself upon reboot. It went undedected, but for any one who is curious, it was found in app data...roaming.  I have since reformatted my hard drive and it is no longer there. One this I noticed was that when you unplug a thumb drive from a pc, it writes some of the files to your hard drive which seems counterintuitive since one point of using an external drive is for privacy.

I know there is nothing I can do at this point, but I hope this helps someone in the future.




I'm interested in how you got caught that virus/malware if you have Eset and Malwarebytes(is this premium or free version?)because it should be good protection.My antivirus is scan every file which is try to download to my PC,and firewall + Malwarebytes Premium for now proved to be adequate protection.

Do you have your seed/private keys backup on your PC/laptop maybe?

It seems that you have on your computer RAT(remote access trojan),and it is good that you formatted hard drive.Hardware wallet is only safe way to store BTC these days since hackers find ways how to steal our coins.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
cynical
Full Member
***
Offline Offline

Activity: 490
Merit: 136



View Profile
November 10, 2017, 11:07:16 AM
 #10

Thanks to all who responded.  Just a little background, although thumb drive was standard, I password protected the individual files with Axcrypt.  I was using Malwarebytes and Eset full security but I think I found a files that could be the culprit to all this.  It was something like service.hostexe* and when I clicked on it, a pop-up appeared asking for a password and username. I did some research on this and it is described as a threat, although there is no way to know if this was responsible for the hack.  When I deleted it, it aromatically reinstalled itself upon reboot. It went undedected, but for any one who is curious, it was found in app data...roaming.  I have since reformatted my hard drive and it is no longer there. One this I noticed was that when you unplug a thumb drive from a pc, it writes some of the files to your hard drive which seems counterintuitive since one point of using an external drive is for privacy.

I know there is nothing I can do at this point, but I hope this helps someone in the future.



thanks for posting back into the board. interesting information.
i wonder how many drives are infected with this?
is this infection targeted to crypto files i wonder?


EDIT ***********
https://malwaretips.com/blogs/svchost-exe-virus-removal/

'The original system file svchost.exe is located in C:\Windows\System32 folder. Any file named “svchost.exe” located in other folder can be considered as a malware.'

████          O W N R   W A L L E T          ████   VISA PREPAID CARD    ████  Use crypto to pay in stores with OWNR  ████
❱❱❱❱ ❱❱❱ ❱❱ ❱     Buy, send, receive and exchange crypto        VISA   mastercard   SPA   UnionPay     ❰ ❰❰ ❰❰❰ ❰❰❰❰
BLOG       TWITTER     ██ █▌█ ▌     Manage crypto and VISA card in OWNR Wallet app    ▐ █▐█ ██     REDDIT   YOUTUBE
pegasus9847 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
November 10, 2017, 04:27:37 PM
 #11

The file "servicehost.exe* seems to nest itself in the C: Drive, at least that was my finding.  I don't know if this virus is specifically engineered to hunt crypto currencies.  From what I read, this is a generic virus that can compromise pretty much anything on your computer that is vulnerable.  I didn't find it on my thumb drive, but like I stated in an earlier post, windows will write files to your hard drive even after the thumb drive is removed without your knowledge.  This is something that people should take note of as there is no pop-up notification to inform you that this is occurring.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!