Bitcoin Forum
May 12, 2024, 05:33:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »  All
  Print  
Author Topic: IOTA - Thousands of Wallets Compromised and Funds Stolen  (Read 2618 times)
exadex.org
Full Member
***
Offline Offline

Activity: 122
Merit: 100



View Profile WWW
January 21, 2018, 03:47:12 PM
 #21

Looks like they just ignored the users who told them to add a seed generator to the client. This would have easily prevented this situation.

Although it's still stupid to use an online service that generates your passwords. Grin

1715535195
Hero Member
*
Offline Offline

Posts: 1715535195

View Profile Personal Message (Offline)

Ignore
1715535195
Reply with quote  #2

1715535195
Report to moderator
1715535195
Hero Member
*
Offline Offline

Posts: 1715535195

View Profile Personal Message (Offline)

Ignore
1715535195
Reply with quote  #2

1715535195
Report to moderator
"There should not be any signed int. If you've found a signed int somewhere, please tell me (within the next 25 years please) and I'll change it to unsigned int." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715535195
Hero Member
*
Offline Offline

Posts: 1715535195

View Profile Personal Message (Offline)

Ignore
1715535195
Reply with quote  #2

1715535195
Report to moderator
1715535195
Hero Member
*
Offline Offline

Posts: 1715535195

View Profile Personal Message (Offline)

Ignore
1715535195
Reply with quote  #2

1715535195
Report to moderator
1715535195
Hero Member
*
Offline Offline

Posts: 1715535195

View Profile Personal Message (Offline)

Ignore
1715535195
Reply with quote  #2

1715535195
Report to moderator
MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 03:52:00 PM
 #22

I personally got 5 Gi stolen, that is about 15kUS$, saw one guy posting today that lost 150kUS$.

The big problem with that whole IOTA system is that they use the seed, which is similar to the private key, and no password or any protection at all, to log into their system. At least one could call it a huge design flaw. I'd call it putting everybody in huge, unnecessary risk. And that is not the first time this happens. A private key should never be exposed to anything. Never. And they require it as part of their regular usage.
exadex.org
Full Member
***
Offline Offline

Activity: 122
Merit: 100



View Profile WWW
January 21, 2018, 04:01:31 PM
 #23

A private key should never be exposed to anything. Never

Then stop exposing your private keys to your Bitcoin wallet. Wink

BitcoinTurk
Hero Member
*****
Offline Offline

Activity: 1624
Merit: 624


View Profile
January 21, 2018, 04:06:55 PM
 #24

Ha ha ha it's a very funny situation for IOTA investors because everybody thinks IOTA is good for investing. But i say again, ''IOTA is not investing coin, it is a just PUMP coin. IOTA technology and IOTA investments are dead investment.
MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:08:03 PM
 #25

Then stop exposing your privates keys to your Bitcoin wallet. Wink
What's that supposed to mean? Your Bitcoin (and Altcoin) wallet private key is never exposed, never used to log into you wallet, never created online, and untouchable to anyone, unless you decide to post it online somewhere.

IOTA on the contrary requires the seed, which is the private key, to log into your wallet. You can not even use that wallet to create this key aka seed locally. The functionality does not exist. And there is no way to password protect it, actually there are no means at all to protect it.
anthi
Member
**
Offline Offline

Activity: 149
Merit: 10


View Profile
January 21, 2018, 04:15:48 PM
 #26

don't blame iota for the stupidness of people

everyone who uses a 3rd party seed generator from questionable sources and then just copies this seed 1 to 1 should be aware that his funds aren't safe

if u are lazy you could even take the so generated seed and just change a few letters with others and or replace a few for 9s
thats enough to secure the seed but sure its not enough to take the risk and just hope for the best

send 2 btc, get 1 back :p
bc1q0zvjvfzyl8792pemrgdkrg78z7fm4e6m6nztmr
MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:17:31 PM
 #27

I disagree. It is a huge design flaw. The very thing they would need to implement is:
1) create seeds locally
2) password protect the wallet.

MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:26:47 PM
 #28

Wow crazy, always felt skeptical about not using a wallet through Ledger. I've used a couple wallets to get off the exchange and stake. Wish they were ledger supported.
That would not have protected you, unless the Ledger would have created the seed. Their wallet can not do it, so you are always depending on a third party solution or your own luck with a dice.
QFT
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


View Profile
January 21, 2018, 04:35:59 PM
 #29

The next big hack, 1.5 billion...an enormous amount. I already got rid of iota, but it always sucks to see news like this.
Sorry for the people that got affected.
MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:39:38 PM
 #30

If your funds were stolen, please report the address it was sent to here:

https://forum.helloiota.com/9284/Call-to-action-lets-catch-the-thief

That is time critical to get these accounts blocked!
gikere
Member
**
Offline Offline

Activity: 171
Merit: 11


View Profile
January 21, 2018, 04:44:01 PM
 #31

If you bought IOTA, check your wallet. Chances are high that it is empty now.

Don't believe me? Open it and find out yourself that all your funds have been stolen.

How so? People were told to use online seed generators. Yes, a seed, online. Not from the wallet itself, no password, not protection at all. And one clever chap collected all the generated seeds and just cashed in.

What can you do? If it is still "Pending" then check out this posting from the official IOTA forum. If it says confirmed as it does for me, funds are gone.

https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances

IOTA tries to blame people now for using the online seed generators. I think the party to blame is IOTA itself, for not putting a seed generator in their light wallet, and for not password protecting it.

This actually calls for class action as thousands of accounts were compromised!

(my x-post from Steemit)
ONLINE, SEED, GENERATORS
What the hell? Why anyone dumb enough to allow this kind of feature exist, let alone user using it.
The One Who Knocks
Jr. Member
*
Offline Offline

Activity: 41
Merit: 2


View Profile
January 21, 2018, 04:50:00 PM
 #32

I mean, who in their right mind would use a 3rd party online seed generator without knowing anything about it? This more than proves that people just care about cryptos just for their value and do not spare enough of their time to search for what it means and the whole world about it...
exadex.org
Full Member
***
Offline Offline

Activity: 122
Merit: 100



View Profile WWW
January 21, 2018, 04:53:58 PM
 #33

Then stop exposing your privates keys to your Bitcoin wallet. Wink
What's that supposed to mean?

When you use the Bitcoin Core client for example, you have a wallet.dat file where your private keys are saved. You need this file to access your Bitcoins and by this, you expose your private keys to your Bitcoin wallet the same way that you enter a pass phrase to login to your IOTA account.

MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:55:58 PM
 #34

I mean, who in their right mind would use a 3rd party online seed generator without knowing anything about it? This more than proves that people just care about cryptos just for their value and do not spare enough of their time to search for what it means and the whole world about it...
Well, as a developer of that currency I'd have put that functionality into the wallet/client as all other coins do it to create the private key locally. They just forgot about it it seem. And one was and still is required to use 3rd party solutions as this functionality does not exist, to date. There is no way to create a private key/seed with the IOTA wallet. So it will happen again. Ignorance of the developers, and people simply don't know and are led into loss. Not the first time with IOTA.
MadMac (OP)
Full Member
***
Offline Offline

Activity: 756
Merit: 103



View Profile
January 21, 2018, 04:58:14 PM
 #35

... you expose your private keys to your Bitcoin wallet the same way that you enter a pass phrase to login to your IOTA account.
No, you don't. At no time do you expose your private key. You enter a password, so your wallet is password protected (which IOTA cannot do). And that's it. The private key stays private.
coolcountry
Member
**
Offline Offline

Activity: 154
Merit: 11


View Profile
January 21, 2018, 05:00:22 PM
 #36

$1.5bn is no small amount. Really makes you wonder how patient these scammers were, you have to wait a considerable time for your seed generator to become popular and then extract all that money in one fell swoop. Sorry for people who lost their money, but we have to understand that owning coins is not like putting banknotes in your wallet; you have to remain vigilant at all times.

exadex.org
Full Member
***
Offline Offline

Activity: 122
Merit: 100



View Profile WWW
January 21, 2018, 05:00:59 PM
 #37

Your Bitcoin private key stays private when your Bitcoin client doesn't send it to someone else. The same applies to IOTA.

bit247
Member
**
Offline Offline

Activity: 123
Merit: 10

bitcoin.org


View Profile
January 21, 2018, 05:02:34 PM
 #38

IOTA is just another shitcoin, lol

BTCitcoin: 35DtMsEK1g1xVMKh4V7beAyguiU9qcHwtF  || ETH: Hacked Sad
aznboy84
Full Member
***
Offline Offline

Activity: 137
Merit: 100



View Profile
January 21, 2018, 05:03:41 PM
 #39

If you bought IOTA, check your wallet. Chances are high that it is empty now.

Don't believe me? Open it and find out yourself that all your funds have been stolen.

This is true, but the hack happened more than months ago, or did it happened again? IOTA is not safe, and that is why i do not like to keep it over the exchanges, because it is 10 times more risky than just having it on your wallet.

Dahman El_Harrachi
Hero Member
*****
Offline Offline

Activity: 630
Merit: 501



View Profile
January 21, 2018, 05:06:46 PM
 #40

... you expose your private keys to your Bitcoin wallet the same way that you enter a pass phrase to login to your IOTA account.
No, you don't. At no time do you expose your private key. You enter a password, so your wallet is password protected (which IOTA cannot do). And that's it. The private key stays private.
so myetherwallet is not safe because u can login with just some random characters and u can't protect it with password  Shocked
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!