Bitcoin Forum
November 11, 2024, 05:18:43 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: someone stole my bitcoin from an encrypted electrum wallet  (Read 912 times)
niokobo (OP)
Full Member
***
Offline Offline

Activity: 182
Merit: 101


View Profile
November 21, 2017, 01:56:10 PM
 #1

someone just emptied my wallet on electrum with 16,2 btc

the wallet file is encrypted how is this possible

here is the theft

here were my bitcoin
162Q35GC13aFaF6XVRpibVddpjSCbsFkaF
 and now they are here

179kCMPuv8uo9DAzaNUwf3A6FNnpNAsEQU

can anyone help me
markj113
Legendary
*
Offline Offline

Activity: 2254
Merit: 1043



View Profile
November 21, 2017, 02:07:51 PM
 #2

someone just emptied my wallet on electrum with 16,2 btc

the wallet file is encrypted how is this possible

here is the theft

here were my bitcoin
162Q35GC13aFaF6XVRpibVddpjSCbsFkaF
 and now they are here

179kCMPuv8uo9DAzaNUwf3A6FNnpNAsEQU

can anyone help me

Sorry for your loss but as a full member here you should know by now that when its gone its gone.

I would check your pc thoroughly for some malware/keylogger.

If it was me it would be fresh install time to be sure
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 21, 2017, 02:12:55 PM
 #3

Sorry for your loss but as a full member here you should know by now that when its gone its gone.

I would check your pc thoroughly for some malware/keylogger.

If it was me it would be fresh install time to be sure

i did that

how is it possible that they steal my coins when its encrypted and without the private keys

well i know when its gone its gone but i thought it was a flaw or something on the side of electrum
markj113
Legendary
*
Offline Offline

Activity: 2254
Merit: 1043



View Profile
November 21, 2017, 02:13:50 PM
 #4

Sorry for your loss but as a full member here you should know by now that when its gone its gone.

I would check your pc thoroughly for some malware/keylogger.

If it was me it would be fresh install time to be sure

i did that

how is it possible that they steal my coins when its encrypted and without the private keys

well i know when its gone its gone but i thought it was a flaw or something on the side of electrum

Alt account much & both red flagged?

 Roll Eyes Roll Eyes Roll Eyes Roll Eyes
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 21, 2017, 02:16:42 PM
 #5

what are you saying
markj113
Legendary
*
Offline Offline

Activity: 2254
Merit: 1043



View Profile
November 21, 2017, 02:18:39 PM
 #6

what are you saying


I am saying you originally posted with the username "niokobo" now your are posting with the username "sengazumi" ?
thesmallgod
Full Member
***
Offline Offline

Activity: 1498
Merit: 129


View Profile
November 21, 2017, 02:19:09 PM
 #7

this is really painful. I have seen so many thread concerning how coin were being stolen and it is good to learn for me how to avoid this. I will like to see many senior member comment on this subject because i use electrum wallet too. however have you considered maybe you are being setup probably someone close to you who have access to your device or maybe you kept your private key and seed to your wallet in unsecure places like mails and some other file sharing site.
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 21, 2017, 02:23:49 PM
 #8

this is really painful. I have seen so many thread concerning how coin were being stolen and it is good to learn for me how to avoid this. I will like to see many senior member comment on this subject because i use electrum wallet too. however have you considered maybe you are being setup probably someone close to you who have access to your device or maybe you kept your private key and seed to your wallet in unsecure places like mails and some other file sharing site.

yes i have 2 different accounts

well i thought my opsec was pretty good and i kept moving my coins from address to address just to make sure noone can get my keys
but i guess i was wrong

i still hope someone can tell me that this is a flaw in electrum wallet and my coins havent been stolen
markj113
Legendary
*
Offline Offline

Activity: 2254
Merit: 1043



View Profile
November 21, 2017, 02:26:45 PM
 #9

Could be by continually moving your coins you created more opportunity for a hacker/keylogger to compromise you.

I now use a nano ledger S for peace of mind.  I think when you get to a reasonable amount of bitcoin your nuts if you dont use a hardware wallet.
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 21, 2017, 02:28:42 PM
 #10

Could be by continually moving your coins you created more opportunity for a hacker/keylogger to compromise you.

im using ubuntu, how can they install a keylogger without my  password?

LoyceV
Legendary
*
Offline Offline

Activity: 3486
Merit: 17657


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
November 21, 2017, 06:17:30 PM
 #11

well i thought my opsec was pretty good and i kept moving my coins from address to address just to make sure noone can get my keys
How exactly did you do that? Did you move your coins within your own wallet to a different address within the same wallet?
There was a transaction to your address 9 blocks before the theft. You've been reusing the same address for many transactions. If your private keys got compromised, that's a long-term risk.

Quote
i still hope someone can tell me that this is a flaw in electrum wallet and my coins havent been stolen
It's not a flaw in Electrum. That's a lot of money to lose Shocked It's also a lot of money to keep in a hot wallet Shocked

im using ubuntu, how can they install a keylogger without my  password?
It's impossible to tell exactly what caused it, there are many different possibilities.

Since there were 9 blocks between your transaction and the theft, is it possible someone gained physical access to your computer?
The 9 blocks between you typing in your password and the theft suggest a manual theft, specialized malware works much faster.

▄▄███████████████████▄▄
▄█████████▀█████████████▄
███████████▄▐▀▄██████████
███████▀▀███████▀▀███████
██████▀███▄▄████████████
█████████▐█████████▐█████
█████████▐█████████▐█████
██████████▀███▀███▄██████
████████████████▄▄███████
███████████▄▄▄███████████
█████████████████████████
▀█████▄▄████████████████▀
▀▀███████████████████▀▀
Peach
BTC bitcoin
Buy and Sell
Bitcoin P2P
.
.
▄▄███████▄▄
▄████████
██████▄
▄██
█████████████████▄
▄███████
██████████████▄
███████████████████████
█████████████████████████
████████████████████████
█████████████████████████
▀███████████████████████▀
▀█████████████████████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀

▀▀▀▀███▀▀▀▀
EUROPE | AFRICA
LATIN AMERICA
▄▀▀▀











▀▄▄▄


███████▄█
███████▀
██▄▄▄▄▄░▄▄▄▄▄
████████████▀
▐███████████▌
▐███████████▌
████████████▄
██████████████
███▀███▀▀███▀
.
Download on the
App Store
▀▀▀▄











▄▄▄▀
▄▀▀▀











▀▄▄▄


▄██▄
██████▄
█████████▄
████████████▄
███████████████
████████████▀
█████████▀
██████▀
▀██▀
.
GET IT ON
Google Play
▀▀▀▄











▄▄▄▀
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 22, 2017, 08:31:55 AM
 #12

no i dont think anyone has access to my laptop

and it seems only my electrum wallet is compromissed, i had 501 BTC on a different wallet and nothing happened, none of my email accounts facebook, or any other crypto platform seems to be affected.

The last 3 months i travelled 3 times to asia and holand finland austria and some other countries and unforutatly i used public wifi alot without vpn

the weird thing is my electrum wallet was encrypted, so i dont know how the gained access to that cause i dont write down passwords anywhere
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 22, 2017, 09:09:54 AM
Last edit: November 23, 2017, 10:59:11 AM by sengazumi
 #13

I will pay a nice reward for anyone that helps me track down this piece of shit
Lucius
Legendary
*
Offline Offline

Activity: 3416
Merit: 6149


Crypto Swap Exchange🈺


View Profile WWW
November 22, 2017, 11:14:38 AM
 #14

no i dont think anyone has access to my laptop

and it seems only my electrum wallet is compromissed, i had 501 BTC on a different wallet and nothing happened, none of my email accounts facebook, or any other crypto platform seems to be affected.

The last 3 months i travelled 3 times to asia and holand finland austria and some other countries and unforutatly i used public wifi alot without vpn

the weird thing is my electrum wallet was encrypted, so i dont know how the gained access to that cause i dont write down passwords anywhere

Almost there is no day to get at least one user of Electrum wallet who was hacked and lost their BTC.It seems to me that there is something specially targeted and attacking users of Electrum on all operating systems and no matter what type of protection they use.

You probably picked up something when using that public wi-fi,but it is strange that only Electrum is affected.It seems that the only correct and safe way to store BTC is hardware wallet/paper wallet/cold storage.

The conclusion is clear,regardless of the steps that we can take to secure our desktop hot wallets they simply are not safe anymore.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
DannyHamilton
Legendary
*
Offline Offline

Activity: 3486
Merit: 4832



View Profile
November 22, 2017, 02:41:47 PM
 #15

yes i have 2 different accounts

well i thought my opsec was pretty good

Clearly not, if you can't even keep track of which account you are posting from.

Additionally, it appears you re-used the 162Q35GC13aFaF6XVRpibVddpjSCbsFkaF address multiple times (at least 61 times?!)
It is recommended to use each address only once.

and i kept moving my coins from address to address just to make sure noone can get my keys

That won't help at all.  There is nothing about a new key that makes it any more difficult to "get" than an old key.  You probably have malware on your computer that accessed your private keys when you decrypted your wallet to move your coins from address to address.

i still hope someone can tell me that this is a flaw in electrum wallet and my coins havent been stolen

I'm not aware of any such flaw.  Electrum doesn't just send bitcoin transactions when it isn't asked to.  Either you sent a transaction, or someone else gained access to your keys and they sent a transaction.

According to your earlier post, you were using bitcoin-cli, NOT Electrum.  So, if you are now using Electrum AND you are still using the same address, then it sounds like you were moving private keys around.  That is horrible OpSec.  You shouldn't be exposing private keys to multiple pieces of software and extracting them into human readable forms.

If you didn't send that transaction, then there isn't going to be anything you can do to get the bitcoins back.

im using ubuntu, how can they install a keylogger without my  password?

They probably tricked you into installing it for them.

the weird thing is my electrum wallet was encrypted, so i dont know how the gained access to that cause i dont write down passwords anywhere

There are several possibilities.

The thief could have accessed your wallet when you decrypted it to "send bitcoins from address to address".
The thief could have gained access to your Electrum Seed words.
The thief could have gained access to your password when you typed it.
The thief could have gained access to the private key that you exported from Bitcoin Core.
You could have sent the transactions yourself, and then forgotten that you did so.
The thief could have figured out what your password is.
You could have used a weak "brain wallet" instead of letting well written software create the private keys for you.
You could have used poorly written software (which used an insufficient RNG) to generate your private keys for you.
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 22, 2017, 09:26:29 PM
 #16

thanks everyone for the answers

i think electrum users are targeted with this attack from pornhub

I have seen a video from john mcafee talking about the dangers of porn sites and were he warned explicitly users of pornsites and even said in this video that 1 day users of porn sites will wake up and have their wallets emptied

Here is the video
https://www.youtube.com/watch?v=GuWvIeQpd4A
CryptoMonitorBot
Member
**
Offline Offline

Activity: 104
Merit: 10

Crypto Monitoring Bot is life =)


View Profile WWW
November 22, 2017, 10:52:58 PM
 #17

You can easily diagnose from where comes the leak :

- Was your computer on when the coins have been sent ?
- Do you have an anti-virus software or firewall ? Was it up to date ?
- Did you have the same password on your wallet and on any internet website/service ?
- Did you enter your password anywhere ?

If I'm right, now your money is here:
https://blockchain.info/address/1K44FRM82amtFBNY6kcJaMb5uUMKDtpoKN
12.47 BTC

And 3.64 BTC was spent here:
https://blockchain.info/address/1EfgpbHDJYvm4VC21WomUTEpLNTrjyV5Cz

Among with 50 BTC going here:
https://blockchain.info/address/1NJghHFxp6GjecKgMtam3mVnued7qFRxQ1
Can we check wether this address is on Bittrex or any other exchange ?

I don't know if that's relevant.. but my Bittrex BTC address also starts with "1N"
coincidence ?

Best regards

CryptoMonitor.tech 🔹 Telegram Bot 🔹 Alerts 🔹 MultiConverter 🔹 BittrexTicker 🔹 Wallet checker
sengazumi
Member
**
Offline Offline

Activity: 107
Merit: 100


View Profile WWW
November 23, 2017, 10:57:01 AM
 #18

You can easily diagnose from where comes the leak :

- Was your computer on when the coins have been sent ?
- Do you have an anti-virus software or firewall ? Was it up to date ?
- Did you have the same password on your wallet and on any internet website/service ?
- Did you enter your password anywhere ?

If I'm right, now your money is here:
https://blockchain.info/address/1K44FRM82amtFBNY6kcJaMb5uUMKDtpoKN
12.47 BTC

And 3.64 BTC was spent here:
https://blockchain.info/address/1EfgpbHDJYvm4VC21WomUTEpLNTrjyV5Cz

Among with 50 BTC going here:
https://blockchain.info/address/1NJghHFxp6GjecKgMtam3mVnued7qFRxQ1
Can we check wether this address is on Bittrex or any other exchange ?

I don't know if that's relevant.. but my Bittrex BTC address also starts with "1N"
coincidence ?


thanks i see the coins

answers to your questions:
1) no i was offlin when coins were sent
2)no i have no antivirus or firewall- im using ubuntu 16.04
3)no password was only used for electrum wallet
4)no
Best regards
Lucius
Legendary
*
Offline Offline

Activity: 3416
Merit: 6149


Crypto Swap Exchange🈺


View Profile WWW
November 23, 2017, 11:55:19 AM
 #19

thanks everyone for the answers

i think electrum users are targeted with this attack from pornhub

I have seen a video from john mcafee talking about the dangers of porn sites and were he warned explicitly users of pornsites and even said in this video that 1 day users of porn sites will wake up and have their wallets emptied

Here is the video
https://www.youtube.com/watch?v=GuWvIeQpd4A

John McAfee is right about some things regarding security,there is too many infected devices and most of users do not take care too much about their online security.This is one of the reason why there is so many hacks of BTC wallets on desktop PC and probably on mobile devices where security is on more lower level.

He just gives an example of porn sites as a potential source of infection,but you can get virus/malware on almost any site you visit.I agree that hardware wallets should be the best option to keep coins safe,so far they proved impossible to hack.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
adaseb
Legendary
*
Offline Offline

Activity: 3878
Merit: 1733


View Profile
November 27, 2017, 09:54:48 PM
 #20



Clearly not, if you can't even keep track of which account you are posting from.

Additionally, it appears you re-used the 162Q35GC13aFaF6XVRpibVddpjSCbsFkaF address multiple times (at least 61 times?!)
It is recommended to use each address only once.



Just wondering why its bad to reuse addresses. Besides exposing your public key and privacy, it seems still safe.

Many exchanges re-use addresses thousands of times without issue.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!