Bitcoin Forum
June 06, 2024, 06:23:26 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 »  All
  Print  
Author Topic: MyEtherWallet Succumbs to DNS Attack with $ 17 million stolen  (Read 517 times)
RothsCoin (OP)
Member
**
Offline Offline

Activity: 201
Merit: 10


View Profile
April 25, 2018, 04:41:54 AM
 #1



Popular Ethereum wallet interface MyEtherWallet has succumbed to a DNS hijacking attack that allowed a hacker to redirect users to a malicious version of the website.

The MEW confirmed that this was not their fault and was trying their best to identify the attacked server to fix things as soon as possible.
This topic is rapidly spreading on the Reddit forum. The attacking IP address seems to come from Russia. At the time of writing, 25,000 ETH ($ 17 million) has been stolen.

It is highly recommend that everyone be careful when using the MEW wallet and follow the security instructions by MEW wallet. In other words, you are advised to integrate Metamask into login and make direct transactions via Metamask. If you want to check your balance, visit https://etherscan.io/, which means you do not have to log into MyEtherwallet.com anymore, so you will avoid the hidden potential risk here.

Rothscoin team.
Herbert2020
Legendary
*
Offline Offline

Activity: 1946
Merit: 1137


View Profile
April 25, 2018, 05:20:03 AM
 #2

this is always going to be the problem with web wallets which is why they are always considered the least secure of all types of wallets. but unfortunately for ethereum there aren't any good options like there are for bitcoin. for instance we have Electrum for bitcoin which is a light wallet which is fast, secure and easy to use. but for ethereum there aren't any easy to use wallets that are fast and secure and don't take up all your hard disk space and bandwidth.

Weak hands have been complaining about missing out ever since bitcoin was $1 and never buy the dip.
Whales are those who keep buying the dip.
jinxcreedy
Newbie
*
Offline Offline

Activity: 37
Merit: 0


View Profile
April 25, 2018, 05:29:52 AM
 #3

When I saw we this I felt bad for the victims. Many will blame MEW for security issue but they fail to realize that security of a software can only stand strong when the user employ good internet surfing habits.

Quite unfortunate though.

I have been a target of a cyber attack some years ago. Within 5 hours I got h it t over 23 times. But I didn't fall because I employ good surfing habits /ethics
yomarve
Jr. Member
*
Offline Offline

Activity: 196
Merit: 6

https://cryptotvplus.com


View Profile WWW
April 25, 2018, 05:33:25 AM
 #4

17Million dollars?  How could people have fallen for this?  When my devices are connected to my financial dealings I can access any site with them but the one i use for crypto or internet banking holds extra security. I don't access just any site.

I feel sorry for those victims.

https://cryptotvplus.com
qiwoman2
Legendary
*
Offline Offline

Activity: 2114
Merit: 1023


Oikos.cash | Decentralized Finance on Tron


View Profile
April 25, 2018, 05:43:21 AM
 #5

The problem is if people rush a lot, like we did a few days ago, it is very easy to lose a ton. Many people were redirected to a phishing site so that is the way they lost money and access to their tokens and ETH. Always you need to check that there is a green bar at the top, never ever put in your private keys without seeing the proper URL. We need to slow down and be very careful because in this Industry there are so many thieves waiting for us to make just one mistake and we lose everything. We all need to take cyber security in general more seriously, especially when we are dealing with money issues.


█▀█ █ █▄▀ █▀█ █▀ ░ █▀▀ ▄▀█ █▀ █░█
█▄█ █ █░█ █▄█ ▄█ ▄ █▄▄ █▀█ ▄█ █▀█



DeFi on Tron
and trustless token exchange
█████











█████

██████████████████████████████████████████████████████

JOIN OIKOS

██████████████████████████████████████████████████████

█████
    █
    █
    █
    █
    █
    █
    █
    █
    █
    █
    █
█████
snapee11
Jr. Member
*
Offline Offline

Activity: 182
Merit: 1


View Profile
April 25, 2018, 06:00:41 AM
 #6

I expected this problem but it seems to be very big with that $17M perhaps it happened for long a period of time before they noticed. And the people will gradually pullout their money
jamesdean35
Member
**
Offline Offline

Activity: 336
Merit: 10


View Profile
April 25, 2018, 06:19:31 AM
 #7

this situation panicked in the world of cryptographic currency units. hackers steal tokens using advanced technology. now the thieves must stop. I'm afraid to look at your wallet as someone who uses myetherwallet.

cilgindansci
Member
**
Offline Offline

Activity: 504
Merit: 10

umachit.fund


View Profile
April 25, 2018, 06:23:00 AM
 #8

Such an attack made us all sad. 25,000 ETH is very serious. The required courses must be taken and the same problems shouldn't happen again.



kecitiaoc
Member
**
Offline Offline

Activity: 140
Merit: 12


View Profile
April 25, 2018, 06:30:18 AM
 #9

Has the very unfortunate news been hacked again? I have also used it recently, hoping that there will be no loss, although I have very little money. However, this issue requires the official to strengthen security, otherwise many people are afraid to use it again.
Bayoe_noe
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250



View Profile
April 25, 2018, 06:34:22 AM
 #10

yes ,,, I also heard the news ... maybe we should be careful and also give extra security to our wallet if we use myetherwallet ...and also do not leave a lot of balance in our wallet ... so we can avoid hacker attacks...
coinshn
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
April 25, 2018, 06:34:52 AM
 #11

When you see the actual number like 17 million it's a wake-up call.

I had over $600 of cryptos stolen last year from a wallet. I wonder if that 17 million number only includes ETH and doesn't count the value of all tokens stolen?
dhiraj0977
Jr. Member
*
Offline Offline

Activity: 518
Merit: 1


View Profile WWW
April 25, 2018, 06:36:39 AM
 #12

Really scaring MEW threat. I will always now scan my balance on etherscan and ethplorer for update, try to prevent login directly in MEW wallet.

HARA │ Empowering billions through data one byte at a time
chanc3r
Sr. Member
****
Offline Offline

Activity: 952
Merit: 253



View Profile
April 25, 2018, 06:40:30 AM
 #13

The problem is if people rush a lot, like we did a few days ago, it is very easy to lose a ton. Many people were redirected to a phishing site so that is the way they lost money and access to their tokens and ETH. Always you need to check that there is a green bar at the top, never ever put in your private keys without seeing the proper URL. We need to slow down and be very careful because in this Industry there are so many thieves waiting for us to make just one mistake and we lose everything. We all need to take cyber security in general more seriously, especially when we are dealing with money issues.
This is no only the first time the scammers are using DNS hijacking method to replace the real site with a fake one. I remember there are some icos are getting the same problem like parity. Remember this already happened with MEW for a few times. I guess use google DNS is not safe anymore and i'm not using it and nothing happen to me.

Bttzed03
Legendary
*
Offline Offline

Activity: 2114
Merit: 1149


https://bitcoincleanup.com/


View Profile
April 25, 2018, 06:40:54 AM
 #14

This is really unfortunate. I believe MEW have been notified of this issue before by BLUE team way back in January. I think MEW could have prevented this if they welcomed the warning and took the necessary action.
santouao
Full Member
***
Offline Offline

Activity: 560
Merit: 101


#SWGT PRE-SALE IS LIVE


View Profile
April 25, 2018, 06:51:17 AM
 #15

Beware if the myetherwallet website is don't have https and don't use private key when accessing your myetherwallet. For now don't transact yet while ethereum developers fixing myetherwallet to prevent loosing ethereum and tokens. We can use an alternative coin for now like bitcoin, neo, and other altcoins for all of our transactions while ethereum is recovering.

╓                                        SWG.io  ⁞ Pre-Sale is LIVE at $0.14                                        ╖
║     〘 Available On Binance Square 〙•〘 ◊ ICOHOLDER ⁞ 4.45 〙•〘 ✅ Certik Audited 〙     ║
╙           ›››››››››››››››››››››››››››››› BUY  NOW ‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹‹           ╜
[/center]
Duzenn
Member
**
Offline Offline

Activity: 252
Merit: 10

The Experience Layer of the Decentralized Internet


View Profile
April 25, 2018, 06:55:08 AM
 #16

That's the bad news.
Because most of the time I trust online wallets, I'm afraid to use MyEtherWallet wallet again, and I'm afraid of losing.

h55
Member
**
Offline Offline

Activity: 210
Merit: 11


View Profile
April 25, 2018, 06:57:43 AM
 #17



Popular Ethereum wallet interface MyEtherWallet has succumbed to a DNS hijacking attack that allowed a hacker to redirect users to a malicious version of the website.

The MEW confirmed that this was not their fault and was trying their best to identify the attacked server to fix things as soon as possible.
This topic is rapidly spreading on the Reddit forum. The attacking IP address seems to come from Russia. At the time of writing, 25,000 ETH ($ 17 million) has been stolen.

It is highly recommend that everyone be careful when using the MEW wallet and follow the security instructions by MEW wallet. In other words, you are advised to integrate Metamask into login and make direct transactions via Metamask. If you want to check your balance, visit https://etherscan.io/, which means you do not have to log into MyEtherwallet.com anymore, so you will avoid the hidden potential risk here.

Rothscoin team.


yesterday DNS erorr was clear. but after 2 hours they try to fix it. Now it works fine for me. hackers tried to hack DNS from last week and i did not login to my wallet.
Dudesss
Jr. Member
*
Offline Offline

Activity: 173
Merit: 1


View Profile WWW
April 25, 2018, 07:04:58 AM
 #18

Yea I have noticed yesterday that the website of MEW is not accesable there was something on the page that it was being attack by some kind of crap I thought I was having problem with my Internet or Browser and now that I have read this it is clear now Thanks!

-FILIPINO TRANSLATOR-
willoweb
Sr. Member
****
Offline Offline

Activity: 658
Merit: 251



View Profile
April 25, 2018, 08:13:54 AM
 #19

Hardware wallets our salvation in such situations, well, or at least Metamask, but certainly not a private key to access the wallet through MEW.

Kleks Academy
▄▄▄███████▄▄▄
▄▄███▀▀       ▀▀███▄▄
▄██▀▀               ▀▀██▄
██▀                     ▀██
██▀ ███     ▄▄█▀         ▀██
███  ███▄▄██▀             ███
███  ██████▀███▄            ███
███  ███    ▀███▄          ███
██▄ ▀▀▀      ▀███▄       ▄██
██▄            ▀▀███▄▄▄ ▄██
▀██▄▄               ▄▄██▀
▀▀███▄▄       ▄▄███▀▀
▀▀▀███████▀▀▀
      ▄█
     ███▌
 ██▄ ▀█▀
 ▀██▌▄▀▄██
█▄ ▀ █ █▀
▀██▄▐▌  ▄█
▄ ▀▀▐▌ ██▀
 ███ █ ▀ ▄█▄
  ▀▀▀ █  ██▀
  ███▄ █ ▀ ▄█▄
   ▀▀▀▀ ▀▄ ███
     ▄██▄ ▀▄▀
      ▀▀▀▀  ▀▄
THE LEGEND RETURNS!
▀██████▄   TWITTER   ▀▄   INSTAGRAM   ▄▀   DISCORD   ▄█████▀
      █▄
     ▐███
      ▀█▀ ▄██
    ██▄▀▄▐██▀
     ▀█ █ ▀ ▄█
    █▄  ▐▌▄██▀
    ▀██ ▐▌▀▀ ▄
  ▄█▄ ▀ █ ███
  ▀██  █ ▀▀▀
▄█▄ ▀ █ ▄███
███ ▄▀ ▀▀▀▀
 ▀▄▀ ▄██▄
▄▀  ▀▀▀▀
██     ██████████████                 ██████████████████████████████████████████████████████████████████
►►  Powered by
BOUNTYDETECTIVE
feny.blackpink
Newbie
*
Offline Offline

Activity: 196
Merit: 0


View Profile
April 25, 2018, 08:47:17 AM
 #20



Popular Ethereum wallet interface MyEtherWallet has succumbed to a DNS hijacking attack that allowed a hacker to redirect users to a malicious version of the website.

The MEW confirmed that this was not their fault and was trying their best to identify the attacked server to fix things as soon as possible.
This topic is rapidly spreading on the Reddit forum. The attacking IP address seems to come from Russia. At the time of writing, 25,000 ETH ($ 17 million) has been stolen.

It is highly recommend that everyone be careful when using the MEW wallet and follow the security instructions by MEW wallet. In other words, you are advised to integrate Metamask into login and make direct transactions via Metamask. If you want to check your balance, visit https://etherscan.io/, which means you do not have to log into MyEtherwallet.com anymore, so you will avoid the hidden potential risk here.

Rothscoin team.


Yes it is not the MEW side fault. but maybe in the future, can they have a 2fa authentication for login into MEW ?
i think it is necessary to develop some security system on the web wallet such as MEW.
Pages: [1] 2 3 4 5 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!