Bitcoin Forum
September 11, 2024, 03:23:30 PM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: NXT stolen  (Read 1510 times)
light888 (OP)
Newbie
*
Offline Offline

Activity: 26
Merit: 0


View Profile
January 24, 2014, 07:08:20 AM
 #1

I only have 3 NXTs in my wallet and they are transferred to this address 10411181763421717624.
It is not much NXTs but I have absolutely no idea on how it got stolen.
Link to my address: http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=14639139826719190448

I have never sent any NXT to anyone or any exchanges. Having troubles syncing my wallet, I looked up the blockchain, only to find that it
was transferred to this address somehow. My computer is with me all the time and I have a fairly secure password.

The point here is that NXT is not secure as it seems and can be easily compromised. I was trying to get started with NXT and was a believer of NXT until now, I have no idea how it happened but I will investigate more and will update on this matter. If anyone with similar experience or any solutions, I will appreciate your insights. I am trying to assume that I have downloaded malware that steals NXTs but so far my files are clean.

Any thoughts?
ak84
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
January 24, 2014, 07:16:59 AM
 #2

What was your password?

▬▬▬▬▬▬▬▬▬ Edutainment.Tech ▬▬▬▬▬▬▬▬▬
Double ICO: Games for smart and games for business
SmartGames    ◼ CorpEdu
light888 (OP)
Newbie
*
Offline Offline

Activity: 26
Merit: 0


View Profile
January 24, 2014, 07:30:59 AM
 #3

What was your password?

10 chars, combination of alphabets, numbers and symbols.
Possible brute force attack but I would like to know how is it done. If the attacker has access to my network and PC then I need to do something about it. If it is just some sniffing and cracking passwords then I'd say that it is not that secure comparing to Bitcoin.
ak84
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
January 24, 2014, 07:34:35 AM
 #4

I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

▬▬▬▬▬▬▬▬▬ Edutainment.Tech ▬▬▬▬▬▬▬▬▬
Double ICO: Games for smart and games for business
SmartGames    ◼ CorpEdu
digit
Legendary
*
Offline Offline

Activity: 1672
Merit: 1010



View Profile WWW
January 24, 2014, 07:38:55 AM
 #5

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.

Stay Safe and use NO KYC exchanges ■ Craig Wright is NOT Satoshi  ■
BTC:1DigitwteXwFcRAaWpVDRp6eKqzC6y9tgm ■ ŁTC:LKMcEHoFWHAUoRscqW1cwjhLgFrk7MgCWU ■ Coinkit:digit ■ §digit
light888 (OP)
Newbie
*
Offline Offline

Activity: 26
Merit: 0


View Profile
January 24, 2014, 07:52:04 AM
 #6

I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. Smiley

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?
extee
Full Member
***
Offline Offline

Activity: 171
Merit: 100


View Profile
January 24, 2014, 08:08:25 AM
 #7

it says clearly that the passpharse should be at least 30.
if you made a passphrase of only 10 charchters long it's your own fault . nothing to do with NXT.
BCFrictionless
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
January 24, 2014, 08:12:10 AM
Last edit: June 22, 2014, 03:17:23 PM by BCFrictionless
 #8

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

why not check out 3RD GENERATION Frictionlesscoin https://bitcointalk.org/index.php?topic=429478.0
NXT IS JUST A STEPPING STONE TO FLC
light888 (OP)
Newbie
*
Offline Offline

Activity: 26
Merit: 0


View Profile
January 24, 2014, 08:19:27 AM
 #9

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

Seems like trolling. A password for NXT should look like this

yx^Ffk]?Hn:dBDqNb/MuMV66sKR%C;dRxZ}WFu,gQrR,64XmuneYt>sj;ba#e{Kz*7XFN38@MHbX^NRgFt$kz)NZ&RRd4pNLXHHV

THE PASSWORD IS YOUR ACCOUNT/ WHO WOULD BE SO STUPID TO CHOOSE 10 CHARS?



However/why not check out 3RD GENERATION Frictionlesscoin https://bitcointalk.org/index.php?topic=429478.0

I am not trolling, but you sir are trolling.

it says clearly that the passpharse should be at least 30.
if you made a passphrase of only 10 charchters long it's your own fault . nothing to do with NXT.


Yes it is my fault for setting an insecure password. But I do not see what you said about passphrase length in the client.
relgub
Newbie
*
Offline Offline

Activity: 27
Merit: 0


View Profile
January 24, 2014, 08:22:22 AM
 #10

I have an extreme password. I received 3 nxt from a faucet and the transaction appeared in the unconfirmed transactions part of my wallet.
But the 3 nxt never made to my transactions.  Why is that?

This wallet doesn't seem to work. Needless to say my address is the same and I haven't changed the password.
instacalm
Hero Member
*****
Offline Offline

Activity: 798
Merit: 500



View Profile
January 24, 2014, 08:24:38 AM
 #11

I have an extreme password. I received 3 nxt from a faucet and the transaction appeared in the unconfirmed transactions part of my wallet.
But the 3 nxt never made to my transactions.  Why is that?

This wallet doesn't seem to work. Needless to say my address is the same and I haven't changed the password.

Check your balance: http://87.230.14.1/nxt/nxt.cgi?action=100 / http://www.mynxt.info/blockexplorer/

Perhaps your client's blocks are/were not synced with the network.
digit
Legendary
*
Offline Offline

Activity: 1672
Merit: 1010



View Profile WWW
January 24, 2014, 08:27:12 AM
 #12

I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. Smiley

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?

NXT requires a complete change in thinking.  There is no wallet.dat to protect. The passphrase/password is the same as the privatekey in bitcoin type cryptos!  Entering that passphrase in NXT wallet is like importing a privatekey into a bitcoin wallet.  
The more complicated your passphrase the more secure your NXT will be, and like privatekeys in bitcoin each passphrase equals one unique NXT address.  

More information on security for NXT can be found here http://wiki.nxtcrypto.org/wiki/Account_Security

Stay Safe and use NO KYC exchanges ■ Craig Wright is NOT Satoshi  ■
BTC:1DigitwteXwFcRAaWpVDRp6eKqzC6y9tgm ■ ŁTC:LKMcEHoFWHAUoRscqW1cwjhLgFrk7MgCWU ■ Coinkit:digit ■ §digit
Snail2
Legendary
*
Offline Offline

Activity: 1512
Merit: 1000



View Profile
January 24, 2014, 10:02:20 AM
 #13

A 10 char alphanumeric password is clearly too short. However OP has a good point about Average Joe who used to choose quite simple passwords.
jason006
Newbie
*
Offline Offline

Activity: 40
Merit: 0


View Profile
January 24, 2014, 11:38:56 AM
 #14

the same to me
i have 2NXT got from the beginning i open an occunt
but one week later,it disappeared
FrictionlessCoin
Legendary
*
Offline Offline

Activity: 868
Merit: 1000


Cryptotalk.org - Get paid for every post!


View Profile
January 24, 2014, 11:41:13 AM
 #15

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


Likely brute forced if 10 characters.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
FrictionlessCoin
Legendary
*
Offline Offline

Activity: 868
Merit: 1000


Cryptotalk.org - Get paid for every post!


View Profile
January 24, 2014, 11:42:42 AM
 #16

I'd guess brute force attack.. sorry about that sucks.

Make a new account and I'll send you 3 NXT

BTW i think the nxt client recommends super long passwords.

That is very nice of you. Thanks but I am not here to ask for NXTs. Smiley

I am more concern of the security and the future of NXT. If stealing NXT is just the matter of guessing one's password, then its security is nothing compared
to the good ol' Bitcoin.

10 characters is too short, you need to use at least 50 characters for NXT.  use a random password generator to make it.


I don't think the average Joe would go through that kind of trouble to do that, it is a good thing to have a 50 char password but it is just not practical.
I suppose more than 15 char is recommended.

My thoughts on the security aspects. If the wallet provides you with the option of having a password, shouldn't it be the second line of defense instead of being the only one ?

NXT requires a complete change in thinking.  There is no wallet.dat to protect. The passphrase/password is the same as the privatekey in bitcoin type cryptos!  Entering that passphrase in NXT wallet is like importing a privatekey into a bitcoin wallet.  
The more complicated your passphrase the more secure your NXT will be, and like privatekeys in bitcoin each passphrase equals one unique NXT address.  

More information on security for NXT can be found here http://wiki.nxtcrypto.org/wiki/Account_Security

Exactly.  Been screaming about this.  It is just insane.   You can collect all the addresses by reading the chain,  then you run a brute force to see if any matches the chain.

It is crazy!!

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
QNX
Newbie
*
Offline Offline

Activity: 58
Merit: 0


View Profile
January 26, 2014, 03:13:01 AM
 #17

Bastard 10411181763421717624 also stoled my 54 nxt, password was long ыbought, but only from digits 16 chars Sad
anderl
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500



View Profile
January 26, 2014, 03:14:22 AM
 #18

Avoid NXT.
cryptohunter
Legendary
*
Offline Offline

Activity: 2100
Merit: 1167

MY RED TRUST LEFT BY SCUMBAGS - READ MY SIG


View Profile
January 26, 2014, 03:27:42 AM
 #19

yeah nxt is like someone already having your wallet infront of them with unlimited time and chances to crack your account.... sadly a good gpu farm will rape most passwords in a matter of days unless it is way longer than 10 digits. I bet on the way to your account he cracked a few others too.

samysamy1
Sr. Member
****
Offline Offline

Activity: 490
Merit: 252



View Profile
January 26, 2014, 03:35:03 AM
 #20

Bastard 10411181763421717624 also stoled my 54 nxt, password was long ыbought, but only from digits 16 chars Sad


Where and when did you download the last update of the client?
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!