Bitcoin Forum
May 08, 2024, 01:44:53 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: BTG fake claim site coinomiwallet , BTC gone :(  (Read 429 times)
Tiberian1986 (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
November 13, 2017, 04:24:56 PM
Last edit: November 13, 2017, 06:59:02 PM by Tiberian1986
 #1

Hi,
first of all I guess everyone expected a post like this after the BTG fork haha.

So I used http://coinomiwallet.com/claimbtg.php to claim my BTG and I used https://btgwallet.online/#newAddress to create a BTG wallet.
I used my Exodus reovery words on coinomi..

Nothing happend after 1hour so I decided to download the coinomiwallet on my android smartphone.
There I used my exodus recovery words to get the exodus btc wallet on my android.
When I watched my exodus I saw two btc transaction to  1FmswbioLza58LDhnxnQX344gJhUnKDhzY (unspent)
Funnily, I dont know that adress Grin and I guess atleast the first tx was made before I downloaded the wallet.
My litecoins are still on my exodus wallet so it shouldnt be just a exodus hack.

Anyone got a clue if this coinomiwallet or btgwallet is fake Cheesy? Or where the btc could go?

Is it possible to found atleast out, which wallet 1FmswbioLza58LDhnxnQX344gJhUnKDhzY  adress is like coinomi or not.
So that I can know if its lost forever because a fake site or if I own it but dont know where it is now xD?

early Tx: 11267f78f1bac41b64bf7a155418f5721d2a022767f70d1d9cd73ddb12b66349
35min later Tx bc6ea0a353696adb9b09e763b5f438edf64344ce8018acdda66584e7ca10edb5
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
1715175893
Hero Member
*
Offline Offline

Posts: 1715175893

View Profile Personal Message (Offline)

Ignore
1715175893
Reply with quote  #2

1715175893
Report to moderator
tulakill
Newbie
*
Offline Offline

Activity: 28
Merit: 10


View Profile
November 13, 2017, 04:28:37 PM
 #2

Bitcoin is not subject to the laws. so you can not complain to anyone. You have to take responsibility for your wallet. Do not go to unreliable sites , I recommend taking bitcoin on cold wallets
Lutpin
Copper Member
Legendary
*
Offline Offline

Activity: 1876
Merit: 1874


Goodbye, Z.


View Profile WWW
November 13, 2017, 04:33:20 PM
 #3

So I used http://coinomiwallet[dot]com/claimbtg.php to claim my BTG and I used https://btgwallet.online/#newAddress to create a BTG wallet.
I used my Exodus reovery words on coinomi.
You've fallen for a scam/phishing site.

https://coinomi.com/ is the original and authentic domain,
http://coinomiwallet[dot]com/ is a phishing copy of the first.

As you have given the scammers your full recovery phrase, they now can access all coins stored in addresses connected to this prhase.

▄▄█████████▄▄
▄█████████████████▄
▄████▀▀▀▀█████▀▀▀▀████▄
████▀██████▀█▀██████▀████
██████████████████████████
▐█████▄███████████████▄█████▌
▐███████▄▄█████████▄▄███████▌
▐██████▀█████████████▀██████▌
▐███████████████████████████▌
▀██████████████████████▀
▀████▄████▄▀▀▄████▄████▀
▀███████▀███▀███████▀
▀▀█████████████▀▀
  ▀▀▀▀▀▀▀▀▀
   ███████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
███████



             ▄████████████████████████████████████████████████████████████▄
            ██                          ▄▄▄▄▄▄                           ██
           ██  ██████                ▄██████████▄     ████████████████████▀
          ██  ████████             ▄████▀   ▀████▄    ████▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
         ██  ████  ████           ████▀       ▀██▀    ████
        ██  ████    ████        ▄███▀                 ████

       ██  ████      ████       ███▀                  ████▄▄▄▄▄▄▄▄▄▄
      ██  ████        ████      ███                   ██████████████
     ██  ████          ████     ███▄                  ████▀▀▀▀▀▀▀▀▀▀

    ██  ████████████████████    ▀████                 ████
   ██  ██████████████████████    ▀████▄        ▄██▄   ████

  ██  ████                ████     ▀████▄   ▄████▀    ████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 ██  ████                  ████      ▀██████████▀     ████████████████████▄
  ██                                    ▀▀▀▀▀▀                           ██
   ▀█████████████████████████████████████████████████████████████████████▀
Tiberian1986 (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
November 13, 2017, 04:39:34 PM
 #4

Ok thank you at least I know now Cheesy
Just a question 1 of the tx is not confirmed. Is there a chance to cancel atleast that order?

P.s Just wonder why my litecoins are still on wallet.
Lutpin
Copper Member
Legendary
*
Offline Offline

Activity: 1876
Merit: 1874


Goodbye, Z.


View Profile WWW
November 13, 2017, 04:47:48 PM
 #5

Just a question 1 of the tx is not confirmed. Is there a chance to cancel atleast that order?
(if you have the private keys to all three input addresses), You could attempt to double-spend that transaction with a higher fee, at current mempool status, you might even have a chance with that.

P.s Just wonder why my litecoins are still on wallet.
I'm not familiar with exodus and don't know how they manage different currencies.
If the same recovery phrase is used for all currencies, your LTC are at risk and you should move them asap to another secure address/wallet.
The scammers possibly just checked for BTC balances and didn't notice any other coins/balances they have access to, yet.

▄▄█████████▄▄
▄█████████████████▄
▄████▀▀▀▀█████▀▀▀▀████▄
████▀██████▀█▀██████▀████
██████████████████████████
▐█████▄███████████████▄█████▌
▐███████▄▄█████████▄▄███████▌
▐██████▀█████████████▀██████▌
▐███████████████████████████▌
▀██████████████████████▀
▀████▄████▄▀▀▄████▄████▀
▀███████▀███▀███████▀
▀▀█████████████▀▀
  ▀▀▀▀▀▀▀▀▀
   ███████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
██████████
███████



             ▄████████████████████████████████████████████████████████████▄
            ██                          ▄▄▄▄▄▄                           ██
           ██  ██████                ▄██████████▄     ████████████████████▀
          ██  ████████             ▄████▀   ▀████▄    ████▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
         ██  ████  ████           ████▀       ▀██▀    ████
        ██  ████    ████        ▄███▀                 ████

       ██  ████      ████       ███▀                  ████▄▄▄▄▄▄▄▄▄▄
      ██  ████        ████      ███                   ██████████████
     ██  ████          ████     ███▄                  ████▀▀▀▀▀▀▀▀▀▀

    ██  ████████████████████    ▀████                 ████
   ██  ██████████████████████    ▀████▄        ▄██▄   ████

  ██  ████                ████     ▀████▄   ▄████▀    ████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 ██  ████                  ████      ▀██████████▀     ████████████████████▄
  ██                                    ▀▀▀▀▀▀                           ██
   ▀█████████████████████████████████████████████████████████████████████▀
jacobmayes94
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
November 13, 2017, 05:09:38 PM
Last edit: November 13, 2017, 05:31:07 PM by jacobmayes94
 #6

I would attempt to double spend the coins quick.


Download the coinomi app on your phone FROM THE PLAY STORE (or use Electrum-LTC to do it) and enter the seed phrase and MOVE ANY other litecoins tied to that recovery phrase that have not yet been stolen, its now compromised. The litecoins attached to that recovery phrase, install the coinomi android app and MOVE them to a NEW litecoin address you control. AS FAST AS POSSIBLE, AS ITS POSSIBLE THEY DO NOT KNOW THE RECOVERY PHRASE IS LINKED TO MULTIPLE COINS and thus only generated the BTC private keys.

create a ltc wallet quickly here or on your own client if you have it installed https://www.litevault.net/ and move the litecoins from that compromised seed to a new address there, then generate a new seed and wallet and move them back. Please hurry, anything to stop the little slimeballs getting their hands on more of your coins is a bonus.




You want to try generating a raw transaction from the BTC address private key thats been compromised, to an uncompromised address that you control.

https://bitzuma.com/posts/how-to-clear-a-stuck-bitcoin-transaction/

Double spend it with a £5 fee to a different address than the one its been stolen to that you control to make sure it gets through. My full node is not synced and would take too long, but send the signed transaction to someone here who can push it through for you, or do it on your own client. The clock is ticking, hurry! I know the amount is $40 USD, but this in the principle and is rightfully your money.


As for the litecoins, I do not know how much you have in Litecoins, but please, move them, and do it fast.

Change the thread title to add about help with double spending, i have posted a thread in the meantime to get people here, as the clock is ticking. As someone may be able to help you. Maybe the stuck network helped someone after all. I pray this works. You can get the private key from the compromised recovery phrase by using electrum and adding the seed through that, selecting BIP39 seed and you can view the private keys to the input addresses to generate transactions.


Tiberian1986 (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
November 13, 2017, 06:24:06 PM
 #7

I was able to rescue Litecoin and I suprisingly got my BTG
BTC not so far because I have to look where I have still some btc to try that cancel trick.

But the BTG are connected with the exodus recovery words which were used on my android coin.. acc.
I have to get them out as well but not so easy to find a exchange with no maintenance (BTG).
jacobmayes94
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
November 13, 2017, 09:44:33 PM
Last edit: November 14, 2017, 09:20:43 AM by jacobmayes94
 #8

Create a BTG wallet on your phone with a new seed, take that down and save the address. Reload the compromised seed and send from that address to the new generated one youve saved, then load the new seed again with the wallet you created at the start. Smiley

Step 1. Create new seed on coinomi, generate BTG wallet. Write down the seed.
Step 2. Save BTG wallet address
Step 3. Remove the wallet from coinomi and load the compromised seed. Send BTG from compromised address to the new address you created before.
Step 4. Remove compromised seed from wallet, reload new seed where you sent the BTG to.

Glad you got your litecoins out, was it a sizable amount?

Try the double spend trick, you have nothing to lose and potentially everything to gain.


I would buy yourself a ledger Nano S wallet. They are much more secure than ever using any other form of wallet, or set up an electrum 2FA wallet, but keep the seed safe which has 2 of the 3 keys and keep the auth code written down, and keep a copy of the authenticator key to save you having to remove 2FA via using the seed.

Let me know if you need any help double spending them. I am syncing up my Core Node so if you have issues broadcasting the generated transaction via your private keys, send it to me after signing it, and i will push out the signed transaction using my node, I am letting it sync up with the blockchain as fast as I can. But if you can do it via your own node do it as fast as possible, as mine will take several hours or perhaps overnight so sync, so it may be too late if you cannot find someone with a node to push it out for you. If nothing doing and its still unconfirmed, I will try and push out the signed TX if you cannot.

I did a thread asking if someone could come to your aid with a synced node, but if nothing doing I started syncing as a backup plan once it is ready I will post again. No one can get private keys from the signed hexadecimal transaction, as you have already signed the unsigned with your private keys this generating that signed transaction which can be pushed out by any node.


These inputs:

1K86Xi9ovCZo6fCKuK8M6PdxZsEcsJ4tqK
1NuqMx1LEQwnRVmudgmjt3ST5WAyQyLTzm
1PNh8EMtXrANA3cvpv8mZM1ZoFS7sPNdnV

You want to sign a raw transaction from these input private keys to an address you control, which you then wish to broadcast, the signed transactions can then be pushed out by a node.  Either you could do it yourself, and open the Bitcoin core console, and enter with the signed transaction after the command: sendrawtransaction

I don't know if you could double spend them by 'sweeping' the private keys instead which might be more simple? Not sure if that would work though, but you could always give that a try in the meantime.


If you are really having trouble generating the signed TX for me to push out, i would happily place 40USD of BTC or LTC of my own coins in escrow with a trusted member here (you could arrange this, ognasty or psychoticboy I trust both, ill pay the fee) and have a go at double-spending it using your actual private keys to sign transactions then send them to an address you control, if you are having problems figuring out how to do it. I know its only 40 USD but that may be a lot of money to you and its the principle of it, its people like this that really give BTC a bad rap, 40 USD is a days wages for some. Move your BTG first in the way I described above, to at least protect those funds. If you have any Bitcoin cash on the same seed, do that as well.

Let me know how it goes, and i will post back when my node is fully synced. Let me know if you manage to do it yourself, as well. If you need help signing the TX i have offered my help as above to try.



EDIT:

https://blockchain.info/tx/bc6ea0a353696adb9b09e763b5f438edf64344ce8018acdda66584e7ca10edb5

looks like we are too late, sorry buddy! :/ at least you got out your LTC and probably your BTG!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!