Bitcoin Forum
May 08, 2024, 09:20:06 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Danger in Automated Trading Bots  (Read 128 times)
tesla80 (OP)
Member
**
Offline Offline

Activity: 448
Merit: 89

Full Stack Engineer


View Profile
May 07, 2018, 11:34:22 AM
 #1

Hello,

As you know there are software systems which trades instead of you 24/7 all the time using some predefined or custom strategies.
Some of them are not open source, some of them are just web sites which require membership and sharing of your API keys for the given exchanges.

The ones which are not working on your local (computer), there are some problems and possibilities your money can be stolen.

When you sign up to a bot web site, you are entering an e-mail address, a password, your name and your API keys.

Some of the bot web sites are fake, even if they work, they have some other stuff on mind.

I saw that they try to login to your exchange using your e-mail and the password in case they are the same with the exchange.

In some of the web sites, there are malicious file injections over javascript (mostly for chrome users), simply the web site uploads a virus to your computer and puts it to Startup folder to make sure it will run after next restart (it wont run immediately because your antivirus or even windows firewall will detect it).
After the file injection, you are open for several types of attacks.
Simply they put some keyloggers and steal your e-mail and exchange passwords using pishing.

So you sign up a web site with expecting more money, but you lose your existing money instead.

How to understand that I'm infected?
Be careful if your browser crashes suddenly, they close the browser and expect you to enter your passwords again, then they will get them.
Stay alerted, check some unusual behavior on your computer, for example more CPU usage, suddenly showing up and hiding console windows.

Check the following files, delete them if you have one on your computer:
c:\users\<user>\AppData\Roaming\Adobe\SWF Frame Renderer\swfrenderer.exe
c:\ProgramData\NTuser.pol
c:\users\<user>\AppData\Roaming\2.exe
c:\program files\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
c:\program files\Common Files\Microsoft Shared\Office16\Office Setup Controller\pkeyconfig.companion.dll
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\program files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe
Delete suspicious files and links in this folder:
c:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

Useful software for virus removal:
It is recommended that you run and scan in this order.
And yes it is not enough to scan with just a few.
RKill - https://www.bleepingcomputer.com/download/rkill/
TDSKiller - https://usa.kaspersky.com/downloads/tdsskiller
AVG Removal Tool - https://www.avg.com/en-GB/Utilities
AdwCleaner - https://toolslib.net/downloads/finish/1/
FRST - https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
JRT - https://www.bleepingcomputer.com/download/junkware-removal-tool/
ComboFix - https://www.bleepingcomputer.com/download/combofix/
RogueKiller - https://www.bleepingcomputer.com/download/roguekiller/
Download Chrome Cleanup Tool - https://www.bleepingcomputer.com/download/chrome-cleanup-tool/
Malwarebytes Anti-Ransomware - https://www.bleepingcomputer.com/download/malwarebytes-anti-ransomware/
Malwarebytes Anti-Rootkit - https://www.bleepingcomputer.com/download/malwarebytes-anti-rootkit/
Malwarebytes Anti-Malware - https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
CCleaner - https://www.bleepingcomputer.com/download/ccleaner/
Microsoft Security Essentials - https://www.microsoft.com/en-us/download/details.aspx?id=5201

Use antivirus:
Recommended BitDefender Internet Security
You can set up a 30 day trial and clean your computer.
Actually there are tons of antiviruses, if you use all of them as demo for 30 days one by one, you can have antivirus protection for a year or more.

Install antivirus on your smartphone:
You can also install BitDefender and scan it again.

How to create the most secure environment for crypto work?
- Activate 2FA, SMS and all other features in all accounts
- Get withdraw compliant measures
- Do not login to the stock exchange a dozen times a day
- Turn off your computers when you are not using them
- Store your money in more than one stock exchange
- Use a separate email address for each stock exchange
- Use a completely different password for each account
- Turn off password saving
- Use a separate browser for crypto work
- Do not have any plugins in the browser
- Use the browser with a theme, customize it, play with the color, then notice it when you see something different.
- Do a virus scan on the computer before entering the stock market or e-mail
- Do not enter sites with free stuff
- Do not tell anyone that you have Bitcoin
- Use an encrypted virtual machine (VM) for your crypto operations: Linux is recommended
- Be careful 2x more on your Windows computer
- Pay attention to the software you installed on your computer
- Choose the software you use for crypto operations from open source ones
- Change your passwords periodically (for example, add a few characters at the end)
- You can use paper to store passwords, do not leave passwords in txt on your computer
- If you want to keep passwords in txt, please keep these files encrypted with WinZip/WinRaR. It is recommended that you also keep the file in a USB flash
- Pay attention to the addresses of the sites you have entered and the security certificates (key icon in the address bar)
- Do not make your phone jailbreak or root. Use cleanly with the original operating system
- Run virus cleanup software periodically or in any doubt and scan
- Remember that not only crypto money, but also your money in the bank can be stolen the same way

A known bot with malicious team is Cryptohopper.com
You can add here other bots with bad manner.

Cyber Security, Mobile Security, Web/Desktop/Embedded Programming, Electronics, M2M, IoT
1715160006
Hero Member
*
Offline Offline

Posts: 1715160006

View Profile Personal Message (Offline)

Ignore
1715160006
Reply with quote  #2

1715160006
Report to moderator
1715160006
Hero Member
*
Offline Offline

Posts: 1715160006

View Profile Personal Message (Offline)

Ignore
1715160006
Reply with quote  #2

1715160006
Report to moderator
You can see the statistics of your reports to moderators on the "Report to moderator" pages.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715160006
Hero Member
*
Offline Offline

Posts: 1715160006

View Profile Personal Message (Offline)

Ignore
1715160006
Reply with quote  #2

1715160006
Report to moderator
BobBct
Sr. Member
****
Offline Offline

Activity: 616
Merit: 250



View Profile
May 07, 2018, 11:46:56 AM
 #2

Trading using bots may cause less risk but of course less the profit because bots use algorithm to trade and if they get a specific pattern that they a programmed to do that's just where you will earn.
Idrisu
Sr. Member
****
Offline Offline

Activity: 924
Merit: 260



View Profile
May 07, 2018, 11:55:31 AM
 #3

I have never used an automated bots in trading because when I was into forex and commodities trading I used a robot software that were make serious loses but people were posting positive reviews about them on there blogs.  I think one should learn how to do this things himself as trading involved your capital and if you did not take control over it you are ban to make loses.
squatz1
Legendary
*
Offline Offline

Activity: 1666
Merit: 1285


Flying Hellfish is a Commie


View Profile
May 07, 2018, 12:16:08 PM
 #4

Trading using bots may cause less risk but of course less the profit because bots use algorithm to trade and if they get a specific pattern that they a programmed to do that's just where you will earn.

This really depends on the amount of risk that you set the bot to take, plus the fact that your bot is fully relying on charts and ta. Which I think isn't working at all, I wouldn't be trusting charts and bots when it comes to my money. I think the markets do what the markets do and its useless to use a bot to try to beat it.

If these bots worked, everyone would be using them and getting rich.




▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄    ▄▄▄▄                  ▄▄▄   ▄▄▄▄▄        ▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄▄    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄▄▄▄   ▄▄▄▄▄▄▄▄▄▄▄
 ▀████████████████▄  ████                 █████   ▀████▄    ▄████▀  ▄██████████████   ████████████▀  ▄█████████████▀  ▄█████████████▄
              ▀████  ████               ▄███▀███▄   ▀████▄▄████▀               ████   ████                ████                   ▀████
   ▄▄▄▄▄▄▄▄▄▄▄█████  ████              ████   ████    ▀██████▀      ██████████████▄   ████████████▀       ████       ▄▄▄▄▄▄▄▄▄▄▄▄████▀
   ██████████████▀   ████            ▄███▀     ▀███▄    ████        ████        ████  ████                ████       ██████████████▀
   ████              ████████████▀  ████   ██████████   ████        ████████████████  █████████████▀      ████       ████      ▀████▄
   ▀▀▀▀              ▀▀▀▀▀▀▀▀▀▀▀   ▀▀▀▀   ▀▀▀▀▀▀▀▀▀▀▀▀  ▀▀▀▀        ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀   ▀▀▀▀▀▀▀▀▀▀▀▀        ▀▀▀▀       ▀▀▀▀        ▀▀▀▀▀

#1 CRYPTO CASINO & SPORTSBOOK
  WELCOME
BONUS
.INSTANT & FAST.
.TRANSACTION.....
.PROVABLY FAIR.
......& SECURE......
.24/7 CUSTOMER.
............SUPPORT.
BTC      |      ETH      |      LTC      |      XRP      |      XMR      |      BNB      |     more
Wilsonong222
Jr. Member
*
Offline Offline

Activity: 130
Merit: 5


View Profile
May 07, 2018, 01:16:35 PM
 #5

Hello,

As you know there are software systems which trades instead of you 24/7 all the time using some predefined or custom strategies.
Some of them are not open source, some of them are just web sites which require membership and sharing of your API keys for the given exchanges.

The ones which are not working on your local (computer), there are some problems and possibilities your money can be stolen.

When you sign up to a bot web site, you are entering an e-mail address, a password, your name and your API keys.

Some of the bot web sites are fake, even if they work, they have some other stuff on mind.

I saw that they try to login to your exchange using your e-mail and the password in case they are the same with the exchange.

In some of the web sites, there are malicious file injections over javascript (mostly for chrome users), simply the web site uploads a virus to your computer and puts it to Startup folder to make sure it will run after next restart (it wont run immediately because your antivirus or even windows firewall will detect it).
After the file injection, you are open for several types of attacks.
Simply they put some keyloggers and steal your e-mail and exchange passwords using pishing.

So you sign up a web site with expecting more money, but you lose your existing money instead.

How to understand that I'm infected?
Be careful if your browser crashes suddenly, they close the browser and expect you to enter your passwords again, then they will get them.
Stay alerted, check some unusual behavior on your computer, for example more CPU usage, suddenly showing up and hiding console windows.

Check the following files, delete them if you have one on your computer:
c:\users\<user>\AppData\Roaming\Adobe\SWF Frame Renderer\swfrenderer.exe
c:\ProgramData\NTuser.pol
c:\users\<user>\AppData\Roaming\2.exe
c:\program files\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
c:\program files\Common Files\Microsoft Shared\Office16\Office Setup Controller\pkeyconfig.companion.dll
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\program files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe
Delete suspicious files and links in this folder:
c:\Users\<user>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

Useful software for virus removal:
It is recommended that you run and scan in this order.
And yes it is not enough to scan with just a few.
RKill - https://www.bleepingcomputer.com/download/rkill/
TDSKiller - https://usa.kaspersky.com/downloads/tdsskiller
AVG Removal Tool - https://www.avg.com/en-GB/Utilities
AdwCleaner - https://toolslib.net/downloads/finish/1/
FRST - https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
JRT - https://www.bleepingcomputer.com/download/junkware-removal-tool/
ComboFix - https://www.bleepingcomputer.com/download/combofix/
RogueKiller - https://www.bleepingcomputer.com/download/roguekiller/
Download Chrome Cleanup Tool - https://www.bleepingcomputer.com/download/chrome-cleanup-tool/
Malwarebytes Anti-Ransomware - https://www.bleepingcomputer.com/download/malwarebytes-anti-ransomware/
Malwarebytes Anti-Rootkit - https://www.bleepingcomputer.com/download/malwarebytes-anti-rootkit/
Malwarebytes Anti-Malware - https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
CCleaner - https://www.bleepingcomputer.com/download/ccleaner/
Microsoft Security Essentials - https://www.microsoft.com/en-us/download/details.aspx?id=5201

Use antivirus:
Recommended BitDefender Internet Security
You can set up a 30 day trial and clean your computer.
Actually there are tons of antiviruses, if you use all of them as demo for 30 days one by one, you can have antivirus protection for a year or more.

Install antivirus on your smartphone:
You can also install BitDefender and scan it again.

How to create the most secure environment for crypto work?
- Activate 2FA, SMS and all other features in all accounts
- Get withdraw compliant measures
- Do not login to the stock exchange a dozen times a day
- Turn off your computers when you are not using them
- Store your money in more than one stock exchange
- Use a separate email address for each stock exchange
- Use a completely different password for each account
- Turn off password saving
- Use a separate browser for crypto work
- Do not have any plugins in the browser
- Use the browser with a theme, customize it, play with the color, then notice it when you see something different.
- Do a virus scan on the computer before entering the stock market or e-mail
- Do not enter sites with free stuff
- Do not tell anyone that you have Bitcoin
- Use an encrypted virtual machine (VM) for your crypto operations: Linux is recommended
- Be careful 2x more on your Windows computer
- Pay attention to the software you installed on your computer
- Choose the software you use for crypto operations from open source ones
- Change your passwords periodically (for example, add a few characters at the end)
- You can use paper to store passwords, do not leave passwords in txt on your computer
- If you want to keep passwords in txt, please keep these files encrypted with WinZip/WinRaR. It is recommended that you also keep the file in a USB flash
- Pay attention to the addresses of the sites you have entered and the security certificates (key icon in the address bar)
- Do not make your phone jailbreak or root. Use cleanly with the original operating system
- Run virus cleanup software periodically or in any doubt and scan
- Remember that not only crypto money, but also your money in the bank can be stolen the same way

A known bot with malicious team is Cryptohopper.com
You can add here other bots with bad manner.

Aside from this all AI program are easily manipulated by a certain group of hackers. I think it is good thing to practice that whenever you this kind of technology you need to build a protection system against the manipulator.

I think what would I do is I will create account which I think I am ready to loss it whenever it crash. Then I will setup another account which is control by me then I will copy the trades of the bot. With this strategy I will able to minimize the risk of failure in trades also in bot hackers.

(((   BIDIUM.io   )))    PRE-ICO ACTIVE
█████████  JOIN NOW!  █████████
supermine
Hero Member
*****
Offline Offline

Activity: 826
Merit: 518


View Profile
May 07, 2018, 01:21:49 PM
 #6

That is a good post which might helpful to save their money for the traders but we need to know that nothing is completely secured in the modern world the hackers and scammers will do their best to steal someone's money so we need to get updated with the technology to keep away from us.Yes we need to stop useless login to exchange accounts and also we can add IP and 2FA authentication will increase the security a lot.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!