Bitcoin Forum
June 23, 2024, 06:14:12 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: Urgent Beware - My Blockchain.info account was drained!  (Read 6973 times)
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 09:03:44 PM
 #1

I just had my Blockchain.info wallet drained. I was logged in and watched helplessly as my entire bitcoin balance was drained and sent to another wallet.

I put in a support ticket and have heard nothing back at all from Blockchain.info. I found the IP address of the hacker in my logs. Still no reply from Blockchain.info

Please change your passwords immediately for Blockchain.info

Kluge
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1015



View Profile
August 12, 2013, 09:12:23 PM
 #2

Were addresses ever used on the mobile version? https://bitcointalk.org/index.php?topic=271831.0
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 09:21:53 PM
 #3

Yeh I pretty much guessed they won't/can't give it back. For future reference the offending IP that accessed my account is 202.60.90.137

Anyone any ideas? if it was a remote desktop app certainly wasn't notified, does anyone know what to look for in the Task manager for suspicious apps?
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 09:28:23 PM
 #4


Quote
Were addresses ever used on the mobile version? https://bitcointalk.org/index.php?topic=271831.0

@Kluge - No, it only ever been used from my win8 laptop and all received came from online exhanges
DannyHamilton
Legendary
*
Offline Offline

Activity: 3430
Merit: 4672



View Profile
August 12, 2013, 09:33:04 PM
 #5

Yeh I pretty much guessed they won't/can't give it back. For future reference the offending IP that accessed my account is 202.60.90.137

Anyone any ideas? if it was a remote desktop app certainly wasn't notified, does anyone know what to look for in the Task manager for suspicious apps?

There are many vectors of attack if you are not careful.

Do you have backups of your blockchain.info wallet? If so, where?  Are they sent to your email? Are they stored on dropbox?

Do you have a complex and secure password?  (AT LEAST 10 characters long, including uppercase, lowercase, numbers, and symbols, with no real words)

Have you imported any private keys or addresses into your wallet that were generated elsewhere?

Have you accessed your wallet from a mobile device or public computer?

How sure are you that you don't have any malware running on your computer?

Did you accidentally access a phishing website that was designed to look like a legitimate site but was actually run by hackers?
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 09:40:40 PM
 #6

Quote
There are many vectors of attack if you are not careful.

Do you have backups of your blockchain.info wallet? If so, where?  Are they sent to your email? Are they stored on dropbox?

Do you have a complex and secure password?  (AT LEAST 10 characters long, including uppercase, lowercase, numbers, and symbols, with no real words)

Have you imported any private keys or addresses into your wallet that were generated elsewhere?

Have you accessed your wallet from a mobile device or public computer?

How sure are you that you don't have any malware running on your computer?

Did you accidentally access a phishing website that was designed to look like a legitimate site but was actually run by hackers?

thanks for the rundown...

Backups were stored on Dropbox and email

Yes password is very secure multiple 16 chars

No imported keys or addresses

No haven't accessed wallet from anything but this win8 laptop

Last scan for malware was yesterday after a defender update. No issues reported.

Haven't accessed any phising sites that I'm aware of. I used Bitvisitor.com to get extra coin from their services. Wallet address included in URL

DannyHamilton
Legendary
*
Offline Offline

Activity: 3430
Merit: 4672



View Profile
August 12, 2013, 09:43:39 PM
 #7

- snip -
Backups were stored on Dropbox and email

Yes password is very secure multiple 16 chars
- snip -

Did you happen to send a copy of your password to yourself in your email so you wouldn't forget it?
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 09:46:48 PM
 #8

No I never save passwords anywhere, I have a very good memory.

Could someone access my account from gmail? without a password? or Dropbox?

The only way I could see, is that from the logs, the hacker did it while I was actually online and logged to the wallet. Remote desktop access?
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 12, 2013, 09:47:30 PM
 #9


Last scan for malware was yesterday after a defender update. No issues reported.


Malware scan does not helps in every case as virus/trojan could be "FUD"(Fully undetectable).

Do you have java on your pc, or visited any suspicious site /downloaded some  app recently ?
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 12, 2013, 09:48:46 PM
 #10

Install a firewall and check incoming/outgoing connections.
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 10:06:25 PM
 #11

@ escrow.ms

Quote
Malware scan does not helps in every case as virus/trojan could be "FUD"(Fully undetectable).

Do you have java on your pc, or visited any suspicious site /downloaded some  app recently ?

Install a firewall and check incoming/outgoing connections.

Java is disabled in firefox

Yes, I am checking incoming and outgoing connections now.

I did notice that inside Firfore Options>Network  Blockchain.info is listed as 'allowed to store data for offline use'

I've removed that listing, no idea if Blockchain put it there or a hack of some kind.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 12, 2013, 10:12:54 PM
 #12


I did notice that inside Firfore Options>Network  Blockchain.info is listed as 'allowed to store data for offline use'

I've removed that listing, no idea if Blockchain put it there or a hack of some kind.

https://blockchain.info/wallet/security

Local storage

No sensitive data is stored in your browser's local storage. If available the site will cache your wallet identifier, address balances and transactions, in the event of login with a different identifier this data is cleared
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 12, 2013, 11:53:19 PM
 #13

Now all my account info and transactions history has been zeroed too.  Its like a blank wallet. What's going on with that?
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 12, 2013, 11:56:36 PM
 #14

Now all my account info and transactions history has been zeroed too.  Its like a blank wallet. What's going on with that?

Quote
I've removed that listing
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 13, 2013, 12:08:03 AM
 #15

Ah, right, I'm getting paranoid.

I'll post if I find out anymore, very bummed at having my little bitcoin account robbed so easily. Not very comfortable using bitcoin at all now.
adamcol
Newbie
*
Offline Offline

Activity: 27
Merit: 0


View Profile
August 13, 2013, 12:21:09 AM
 #16

Were you on Windows? Maybe you had a keylogger.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 13, 2013, 12:21:44 AM
 #17

Ah, right, I'm getting paranoid.

I'll post if I find out anymore, very bummed at having my little bitcoin account robbed so easily. Not very comfortable using bitcoin at all now.

Use offline wallets (Paper wallet,armory cold storage) until you are sure that your pc is clean.
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 13, 2013, 02:50:51 AM
 #18

Good idea, but I haven't any bitcoin left now, so it doesn't really matter. Am cleaning the laptop. Deep scan shows nothing at all. no evidence of keylogging either

If anyone wants to donate some bitcoin to my new wallet at another site to get me started again: 1FvbpQt5zREwPJ5CKUX8wH7E1EPCHTduqW


Ok I know its wishful thinking, just depressed to lose everything in front of my eyes, no bitcoin, no happy.  Cry

Still no reply from Bitchain.info on the support ticket either.
AAleron (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
August 13, 2013, 06:33:53 AM
 #19

Hey, whoever sent that little donation. Thanks! very much appreciated. You're a star! Restores my trust a little in humanity  Cool

Still no reply to my support ticket on Blockchain.info  Will let people know if I find out how they stole all my money.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
August 13, 2013, 06:39:36 AM
 #20

Hey, whoever sent that little donation. Thanks! very much appreciated. You're a star! Restores my trust a little in humanity  Cool

Still no reply to my support ticket on Blockchain.info  Will let people know if I find out how they stole all my money.

what was your blockchain's bitcoin address?
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!