Bitcoin Forum
May 12, 2024, 11:35:00 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: MEW DNS hack report  (Read 101 times)
asere (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
May 23, 2018, 09:07:57 AM
 #1

Hi,


Me too was a victim of this hack.
Actually I agree its not a real hack but a DNS exploit that along my carefulness about the SSL warning led to my account being robbed.

The thing I want to stress out is the fact that its known who invaded my account and stole my coins.
Its on a public ledger and his address is known.

Actually the fucker has this address https://etherscan.io/address/0x4b688d297e3b4f3359f8ab9883ebaf300fc01497

My questions are:

1. Shouldn't WE ,as a community, have a place where these fuckers are reported/banned.

2. How can this fucker be identified? At some point he will use this address to send the coins to an exchange for FIAT conversion or for trading.
    Then he is identifiable(?)

I know its my mistake for being careless with my surfing habits and I will not see these coins again,
but more important than my money is to save others from this...and to make the use of cryptos better.

Any thoughts on this is appreciated.

Peace
1715556900
Hero Member
*
Offline Offline

Posts: 1715556900

View Profile Personal Message (Offline)

Ignore
1715556900
Reply with quote  #2

1715556900
Report to moderator
1715556900
Hero Member
*
Offline Offline

Posts: 1715556900

View Profile Personal Message (Offline)

Ignore
1715556900
Reply with quote  #2

1715556900
Report to moderator
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715556900
Hero Member
*
Offline Offline

Posts: 1715556900

View Profile Personal Message (Offline)

Ignore
1715556900
Reply with quote  #2

1715556900
Report to moderator
Ekosistim
Jr. Member
*
Offline Offline

Activity: 196
Merit: 1


View Profile WWW
May 23, 2018, 09:09:33 AM
 #2

maybe we cant count anymore how many victim by this problem, so for secure our assets its better to use metamask or ledger i think.

FINANCEX || THE NEXT GENERATION EXCHANGE
━ ⋄❖⋄ PUBLIC ICO COUNTDOWN : ICO WEBSITE || Join NOW!!! ⋄❖⋄ ━ (https://ico.financex.io/)
lucian999
Newbie
*
Offline Offline

Activity: 144
Merit: 0


View Profile
May 23, 2018, 09:14:07 AM
 #3

there are many hackers who want to hack the mews so double remember one of their modes is to sign up on the links or airdrops and telegram so avoid doing so just do not sign up for the first try before signing up for no Get the best you can with your mew
asere (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
May 23, 2018, 09:20:39 AM
 #4

maybe we cant count anymore how many victim by this problem, so for secure our assets its better to use metamask or ledger i think.

I was using Metamask!
So I guess thats not where the problem is.
Quincy01
Newbie
*
Offline Offline

Activity: 140
Merit: 0


View Profile
May 23, 2018, 03:18:25 PM
 #5

I am so sorry to hear this sad experience with your stolen tokens, it is really sad because my friend was also robbed by theses hackers two weeks again and up to this moment he is still in that shock and sick of the entire system. My opinion here is that the MEW support team should upgrade there software in such a way that before any transaction flies through, there should be some level of verification that needs to be done and they should tighten the security of the system because it is too porous, thousands of people are crying over this issue and they just can't keep quite about it.
marks1976
Sr. Member
****
Offline Offline

Activity: 893
Merit: 250


View Profile
May 23, 2018, 03:22:14 PM
 #6

Hi,


Me too was a victim of this hack.
Actually I agree its not a real hack but a DNS exploit that along my carefulness about the SSL warning led to my account being robbed.

The thing I want to stress out is the fact that its known who invaded my account and stole my coins.
Its on a public ledger and his address is known.

Actually the fucker has this address https://etherscan.io/address/0x4b688d297e3b4f3359f8ab9883ebaf300fc01497

My questions are:

1. Shouldn't WE ,as a community, have a place where these fuckers are reported/banned.

2. How can this fucker be identified? At some point he will use this address to send the coins to an exchange for FIAT conversion or for trading.
    Then he is identifiable(?)

I know its my mistake for being careless with my surfing habits and I will not see these coins again,
but more important than my money is to save others from this...and to make the use of cryptos better.

Any thoughts on this is appreciated.

Peace
1 Since the crypto can be considered as psudonymous and there is no way to report them. This mean if that will be useless.

2 these hackers get secured by the algoritm that has been implemented in the crypto currency and they can't be identified as far as i know. n

 
        ▄██████
      ▄█▀██████
    ▄█▀  ██████
  ▄█▀    ██████
▄██▄▄▄▄▄▄██████
███████████████
███████████████
███████▀▀▀▀▀▀▀▀
███████▄▄▄▄▄▄▄▄
███████
███████▀▀▀▀▀▀▀▀
███████▄▄▄▄▄▄▄▄
████████████
███████████████
 ▀█████████████

<█▄▄▄

▄▄▄▄▄▄▄▄▄▄ █▄▄▄▄

▄▄▄▄▄ █▄▄▄▄▄

│   ▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄(▄▄▄
$▄▄▄▄▄▄█▄▄▄▄▄▄, █▄▄▄▄▄▄▄ $▄▄▄▄▄▄: ▄▄▄▄▄
│   █
│   │   //█▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
│   │   $▄▄▄▄▄▄▄▄█▄▄▄▄ ▄▄▄▄▄▄_▄▄▄(▄▄▄▄▄▄█▄▄▄▄▄▄, █████████▄█████▄███████):
│   │   $▄▄▄▄▄▄▄▄█▄▄▄▄ ▄▄ ▄▄▄▄▄▄($▄▄▄▄▄▄▄ - > ▄▄▄▄▄()) ▄▄▄▄▄▄▄:
│   │   ▄▄ (!$▄▄▄▄▄▄▄▄▄█▄▄▄▄▄▄ !$▄▄▄▄▄▄▄█▄▄▄▄▄) █
│   │      ▄▄▄▄▄▄ ▄▄▄▄▄▄
│   │   █
 
           ▄███▄        ▄███▄
     ▄███████▄    ▄███████▄
     █████████    █████████
      ███████      ███████
       ▀▀▀▀▀        ▀▀▀▀▀
 ▄▄████▄▄▄▄▄█▀ ▄▄████▄▄▄▄████▄▄
█████████▀███ ██████████████████
███████▀  ███ ██████████████████
       ▄█ 
    ▄▄███▄▄▄▄▄▄        █▄
    ▀█████████▀   ▄▄▄▄▄███▄
      ▀██       ▄███████████
        ▀              ███▀
                       ▀
   
P2P CASH
▄▄▄▄▄▄ Send money worldwide fast ▄▄▄▄▄▄
 
███████████████████▄
█████████████████████
████           ▀██████
████             ██████
████              █████
████             ▄█████      ▄
████            ▄██████    ▄██
████     ▄▄▄▄▄████████    ▄███
████   ▄████████████▀   ▄█████
████ ▄███████████▀▀   ▄███████
██████████▀         ▄█████████
████████▀  ▄▄███████████▀ ████
██████▀  ▄████████████▀   ████
████▀   ███████▀▀▀▀▀▀     ████
██▀    ██████▀            ████
▀      █████              ████
       █████              ████
       █████▄             ████
       ▀██████▄           ████
        ▀█████████████████████
          ▀███████████████████
  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ safe an easy with P2P ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
P2P is the open source smart
contract platform
fully dedicated to
international money transactions
     
   ▄▄██▄▄▄▄▄▄██▄▄
  ████████████████
 ██████████████████
▄████▄  ███▄  ▄████▄
█████▄  ███▄  ▄█████
████████████████████
 ▄████  ▄▄▄▄  ████▄
   
▄      ▄███▄▄
██▄▄▄ ██████▀
████████████
 ██████████▀
   ███████▀
 ▄█████▀▀
   
             ▄▄
       ▄▄▄█████
  ▄▄▄███▀▀▄███
▀▀███▀ ▄██████
    █ ███████
     ██▀▀▀███
           ▀▀
███





███
██████████████████████████

            JOIN

██████████████████████████
███
  █
  █
  █
  █
  █
███
asere (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
May 24, 2018, 06:06:20 AM
 #7

-why the MEW is at all available to anyone when  he is so risky?
-Is it so hard to make a verification before the transaction?
90 percent off people who have experienced this will never again touch crypto!

Agree on both statements!

... there should be some level of verification that needs to be done ...

I agree second level verification is a must.

Quote from: marks1976
1 Since the crypto can be considered as psudonymous and there is no way to report them. This mean if that will be useless.

2 these hackers get secured by the algoritm that has been implemented in the crypto currency and they can't be identified as far as i know. n

You identify yourself when you seek the connection to a bank for fiat transfer.

But concider this:
If the same address is repeatedly reported as a thieve-address and is banned on the public ledger then the funds that it holds would become inactive/burned.
This is fair and would be a nice addition to any blockchain.

Actually there might exist a blockchain that would rate addresses (eventually the person behind an address) and sort them in a list as reliable/not reliable

butka
Full Member
***
Offline Offline

Activity: 434
Merit: 246


View Profile
May 24, 2018, 06:16:11 AM
 #8

I was using Metamask!
So I guess thats not where the problem is.
Yes, metamask is more secure and not susceptible to attacks of this type. It is important to stress that MEW's website wasn't hacked. It was a public DNS server that was hacked (Google’s DNS in fact), which then led to people landing on the wrong IP (attacker's sever rather than the MEW's server).
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!