alia (OP)
Jr. Member
Offline
Activity: 56
Merit: 115
Lowest EVER interest lending! (Use escrow always)
|
|
February 25, 2018, 11:25:06 AM |
|
I just got screwed out of 0.03 BTC because of a malware that changes any address you copy into the malware owner's address. It even used a vanity gen to make the two first characters of the address the same (I was sending to 1Gm..., so the malware created a 1Gm address).
1. Before sending, always check the first two and last two letters to make sure it is the same address you are copying! 2. If possible, check a random string in the middle and compare it! Even better.
Be vigilant, y'all!
|
Lowest interest lending in bitcointalk history. https://bitcointalk.org/index.php?topic=2846750.0
|
|
|
AB de Royse777
Legendary
Offline
Activity: 2660
Merit: 4140
Campaign Manager. My Telegram @Royse777
|
|
February 25, 2018, 11:30:55 AM |
|
Do you have any idea where you got the malware from?
|
..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
alia (OP)
Jr. Member
Offline
Activity: 56
Merit: 115
Lowest EVER interest lending! (Use escrow always)
|
|
February 25, 2018, 11:35:58 AM |
|
Do you have any idea where you got the malware from?
No clue at all... and I'm not one to download rogue files, especially from crypto sites. It was likely something browser-based and stealthy.
|
Lowest interest lending in bitcointalk history. https://bitcointalk.org/index.php?topic=2846750.0
|
|
|
batang_bitcoin
|
|
February 25, 2018, 11:38:53 AM |
|
I just got screwed out of 0.03 BTC because of a malware that changes any address you copy into the malware owner's address. It even used a vanity gen to make the two first characters of the address the same (I was sending to 1Gm..., so the malware created a 1Gm address).
1. Before sending, always check the first two and last two letters to make sure it is the same address you are copying! 2. If possible, check a random string in the middle and compare it! Even better.
Be vigilant, y'all!
That's for sharing your experience mate but this issue has been revolving through the community for a year I guess. https://www.reddit.com/r/Bitcoin/comments/79pai0/be_careful_out_there_everyone_there_is_malware/Have you downloaded some apps? Do you have any idea where you got the malware from?
I guess he got it from downloading a very unfamiliar source.
|
|
|
|
Yakult
Member
Offline
Activity: 144
Merit: 10
|
|
February 25, 2018, 11:44:06 AM |
|
I feel bad for you man. Checking the address should be a habit. Better be careful next time doing transaction.Avoid any downloads from random sites and at least use private browsing with every transaction. Having you system protected with anti virus would be a good idea as well. We are talking about hard work money here, keeping them insured is a must.
|
|
|
|
meyklove
Member
Offline
Activity: 210
Merit: 14
|
|
February 25, 2018, 11:44:54 AM |
|
Sorry to hear that buddy. Yes, we should always check the addresses that we use to send coins because it will never be return if it happens.
|
|
|
|
cissrawk
Sr. Member
Offline
Activity: 1218
Merit: 410
Secure your crypto : https://notyourkeys.org
|
|
February 25, 2018, 01:14:30 PM |
|
you should scan your hardware with antivirus. I recommend you use malwarebyte, since i has same problem in the past and it solved my problem. Or you can try this way Uninstall some useless or unknown program from your hardware maybe can help but you must scan again with antivirus after uninstall it to make sure the virus is already gone.
|
|
|
|
bad_apple
Newbie
Offline
Activity: 150
Merit: 0
|
|
February 25, 2018, 01:53:51 PM |
|
I also experience this kind of virus on my laptop when I suddenly double-checked my ETH address on etherscan but it shows different account and has almost 70 ETH on his wallet, I double-checked my wallet address on my copy and BOOM! The address that I've been copy-pasting is not mine, but its the hacker's. I searched about it and I saw this site https://ethereumworldnews.com/careful-copying-pasting-ethereum-wallet-address/ which tells that it is Trojan.Coinbitclip which automatically replaces your 40-character hexadecimal address into theirs. Those hackers have lots of addresses so they have different options to work to. Be careful on downloading files or visiting websites as it may contain malwares and bad stuffs. Just use a legitimate anti-virus software to fix this or just reformat it. Additionaly, you can still copy-past your address using your infected device, but instead of copying it all, leave atleast 2 characters when copying, then paste it and fill the last 2 characters of your address and all will be fine.
|
|
|
|
tegarp90
|
|
February 25, 2018, 02:10:46 PM |
|
also check the website's address , many phising sites right now, once you enter your password or private key. you'll lost all your funds
|
|
|
|
A Feeder
|
|
February 25, 2018, 02:20:03 PM |
|
I just got screwed out of 0.03 BTC because of a malware that changes any address you copy into the malware owner's address. It even used a vanity gen to make the two first characters of the address the same (I was sending to 1Gm..., so the malware created a 1Gm address).
1. Before sending, always check the first two and last two letters to make sure it is the same address you are copying! 2. If possible, check a random string in the middle and compare it! Even better.
Be vigilant, y'all!
Good thing to know because I might also have been a victim of it. Doesn't your PC has an anti malware or something? You should also make your PC secured from threats because the internet is a deadly place. Since it is my address, I am very familiar with it and I also double check it before sending.
|
|
|
|
Trofo
Legendary
Offline
Activity: 2660
Merit: 2704
Join the world-leading crypto sportsbook NOW!
|
|
February 25, 2018, 02:26:13 PM |
|
I just got screwed out of 0.03 BTC because of a malware that changes any address you copy into the malware owner's address. It even used a vanity gen to make the two first characters of the address the same (I was sending to 1Gm..., so the malware created a 1Gm address).
1. Before sending, always check the first two and last two letters to make sure it is the same address you are copying! 2. If possible, check a random string in the middle and compare it! Even better.
Be vigilant, y'all!
Damn, didn't heard about this particular type of attack before. One more thing to check up every time when doing transfers. This one is much more difficult to prevent than phishing attacks. For phishing attacks it is usually enough to just bookmark your sites and never click on any link received trough email, social networks, etc..
|
|
|
|
ciciteng
Jr. Member
Offline
Activity: 168
Merit: 2
|
|
February 25, 2018, 02:30:06 PM |
|
Do you mind share what kind of malware that you're talking about? so all of us will aware about that. My suggestion is, please keep your antivirus updated and don't click any suspicious link or install crappy-shit plugins that offer some magic that will solve your computer's problem. Stay safe, and agree, always double check your address.
|
|
|
|
brotherwood12
Member
Offline
Activity: 686
Merit: 30
|
|
February 25, 2018, 02:35:42 PM |
|
what i do to check my addres is after i put my addres into something like send wallet or accept something , i do ctrl+f on my chrome and copy my addres into it , it will reveal if my addres correct or not
|
|
|
|
judeafante
|
|
February 25, 2018, 02:39:18 PM |
|
Do you have any idea where you got the malware from?
No clue at all... and I'm not one to download rogue files, especially from crypto sites. It was likely something browser-based and stealthy. I have read a lot of this, but still, surprise with all the many anti-virus we have online there is still this kind of malware, I have bitdefender and malwarebytes but still looking for my address, and check if it is indeed right before sending my funds.
|
| . SECONDLIVE | | | │ | | | | | | │ | | | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ S T A K E L I T T L E W I N B I G ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ | ▄▄███████▄▄▄ ▄▄████████████████▄▄ ██████████████████████▄ ████████▀▀▀██████████████ ███████▌ ▀█████████████ ████████▀ ▀▀▄▄██▀▀▀██████████ ███████ ▀████████ ███████▄ ████████ ████████▄▄ ▄████████ ███████████▄▄▄▄██████████ ▀█████████████████████▀ ▀████████████████▀▀ ██████████████████████ |
|
|
|
puruntung213
Jr. Member
Offline
Activity: 236
Merit: 1
|
|
February 25, 2018, 02:42:31 PM |
|
What im doing and my other friends before sending double check the address if its right were checking three first and three last character of the address to be sure we were sending in the right address
|
|
|
|
Caesar-Giulius
Sr. Member
Offline
Activity: 728
Merit: 250
Buy, sell and store real cryptocurrencies
|
|
February 25, 2018, 04:30:48 PM |
|
Sorry to hear about your loss and thank you for notifying us about this. I have heard of this malware and have been checking the full address before sending.
|
. │ │ │ | | .
| | . │ │ │ │ | | | | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████ ██████████████████████████████████████ ███████████████████████▀██████████████ █████████▄▄ ▀▀██▀╜ ▀▀███████████ ████████████▄ ██ ▀^╓▀█████████ ██████████████ ║█ ,▀██████████ █████████████▄▄ █▌ ████████████ ████████████████▄ ▀█▄ ███████████ ████████████████▀,,, ╙▀▀█▀ ████████ █████████████████▀▀▀█▄▄ ████████ ███████████████▀ ▀███████▀████████ ██████████████▌ ▐█* ▀▓▀ ████████ ████████████*██▄ ▄██▄▄▄▄▄▄████████ ██████████▀` ▀██▄ ▀████████████████ ████████▀` ▄█████▌ ╙███████████████ ████████▄, ▀████ ,,, "▀▀███████████ ██████████,,,,, ╙█▄███▄▄,,,,╙▀████████ ██████████████████████████████████████ ██████████████████████████████████████ ██████████████████████████████████████ | | | | L B X | | | | . │ │ │ | | | | | | | | . │ │ │ | | .
| | . │ │ │ | | .
| | . │ │ │ |
|
|
|
sasinghal
Jr. Member
Offline
Activity: 70
Merit: 2
|
|
February 25, 2018, 04:43:20 PM |
|
Yes you are right, the addressed should be cross checked by checking atleast first two and last two digits. This thing happened with one of my friend as it happened with you, he had lost 0.05 BTC.
|
____Kukucoin.io____ Value of cocoa harvesting, Marketing and Trading (http://kukucoin.io) ▬▬▬▬▬▬▬▬▬▬ ● ⋆ ● ▬▬▬▬▬▬▬▬▬▬[/cen
|
|
|
kueyen
Member
Offline
Activity: 140
Merit: 10
|
|
February 25, 2018, 05:32:16 PM |
|
This is a very smart way to implement a malware, no? Especially when you're copying and pasting addresses, you never feel the need to check it once again. Although I'm sad OP lost their money due to this malware, I'm amazed at how inventive this method is.
|
|
|
|
Kprawn
Legendary
Offline
Activity: 1904
Merit: 1074
|
|
February 25, 2018, 05:44:00 PM |
|
This is why Ledger wallet implemented a new procedure, where the user confirm the "receive" address on the device and not on the browser side. That is not necessarily Malware, because these addresses are being changed manually by the hacker. I make a habit to triple check my "Send" & "Receive" address, before I do anything. I do not trust "software"...
|
|
|
|
Alanpigi80
|
|
February 26, 2018, 06:35:53 AM |
|
That's always bad news to hear. I'm sorry OP.
A good way to protect our wallets could be using a laptop only for transactions? I don't trust antiviruses and antimalwares because of the "day-zero" that not every software have good protection
|
|
|
|
|