Bitcoin Forum
November 08, 2024, 06:21:19 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: Stolen Coins Right After Getting Vanity Address  (Read 5126 times)
desii1 (OP)
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
February 02, 2014, 08:54:20 PM
 #1

The sad story....  I generated vanity addresses* (online) for two wallets to easily keep them separate.  Moved them into MultiBit and locked the wallets with a 14 character LastPass generated password. 

I did NOT break from the internet when I combined the vanity secret keys.

The next morning MultiBit showed a transfer out of 5 coins to an unrecognized address, the transfer took place two hours after I left the computer. 

I have all of the normal security, e.g. behind a router, Norton firewall and virus protection.  I did have both Flash and Java on the machine.  They are gone now!

I believe two factor would have been my only protection.  Are there any offline wallets with two factor?  I am installing Armory now.

Until someone writes an easily useable, safe, wallet Bitcoin is going to be held back.  I thought I was being more conservative moving my coins out of Coinbase.  Guess not since they use two factor.

I would love to know how it was done.  There should be a centeralized reporting place to see if there are similar problems with specific websites.

*https://bitcoinvanity.appspot.com/  < the site I used.  I am NOT accusing them!
guybrushthreepwood
Legendary
*
Offline Offline

Activity: 1232
Merit: 1195



View Profile
February 02, 2014, 09:07:40 PM
 #2

Blockchain.info has 2 factor auth and a second password to spend funds, so it's pretty secure, but I know a lot of people don't trust keeping coins online, but as you found out storing them on your computer isn't fully safe either.
Colin Miner
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile WWW
February 02, 2014, 09:20:20 PM
 #3

Store your coins in your own bitcoin-qt wallet with a pass phrase. You can import your vanity addresses into it and you don't rely on others to provide security.

You should do a virus scan with a different virus scanner than you are using, like the Kaspersky rescue cd because it looks like you are infected.

FREE Namecoins (NMC), Devcoins (DVC) and IxCoins (iXC) while you mine Bitcoins (BTC) on the pool, in the cloud or both. Free to join, click here to Sign Up and mine your free coins.
Cheap VPS Hosting here or budget conscious Free cPanel hosting here. Buy BTC the safe and easy way at Localbitcoins.com (US and UK).
 "I'm no longer as confident as I was this morning." - xkeyscore89.  My Addie.cc.
more Free: BTC, LTC, FTC, TIPS, WDC, EAC & IFC
miners78
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
February 03, 2014, 02:05:30 AM
 #4

I was about to get a vanity address :S. Guess not now..
MegaHustlr
Hero Member
*****
Offline Offline

Activity: 601
Merit: 500


Vote 4fryn :)


View Profile
February 03, 2014, 05:02:00 PM
 #5

I would never trust vanity addresses, just so dodgy Undecided




                  ▄  ▀▄▄   ▀▄▄ ▀▄ ▀▄
             ▀█▄▄▄▄███▀▀▀▀▀▀▀█████████ ▄
         ▀████▀▀    ▄▄▄▄▄▄▄▄▄▄▄▄▄    ▀███▄
 ▄▄▄▄▄  ▄▄▀      ██▀▀     ▄██▀▀▀   █     ██
██    ▀█  ▄█▀▀▀▄  ▀█   ▄█▀   ▄▄▄ ▀██  █▀▀▄▀▄

▀▀▀   ▐█ █▌    ▐▌  █  ▐█ ▄█▀▀   █ █  ▄▀ ▄█ ▌
      ▐▌ ▀█ ▄▀▄█  █▀  █  █      ▐▌ █▀ █    ▀▄
      █     ▄█▀  ▀▀▀▀▄█  ▀█▄▄▀ ▄▀  █▄ █  ██ ▐▌
     █   ▄███▄▄███▄▄▄▄       ▄█▄▄▄▄ █▄    ▀  █ ▄
   ▄█▀▀▀▀     █▀      █   ▄█▀▀███    ▀▀▄▄   ▄██
  ▐█         ▐▌       ▐▌▄▀     ██        ▀███ ▐█
  █           ▀▄      ▐█▀       ▀█           ▀▀
  █▄           ██     ██         ██▄
   █▀            ▀     ▀          ▀█▀



.







                 ▄████▄▄    ▄
██             ████████████▀
████▄         █████████████▀
▀████████▄▄   █████████████
▄▄█████████████████████████
██████████████████████████
  ▀██████████████████████
   █████████████████████
    ▀█████████████████▀
      ▄█████████████▀
▄▄███████████████▀
   ▀▀▀▀▀▀▀▀▀▀▀




       ▄▄▄▄▄▄
    ▄████████
    █████▀▀▀▀
   ▐████
   ▐████
████████████
████████████
   ▐████
   ▐████
   ▐████
   ▐████




  ▄██▄▄                ▄▄██▄
  ████████▄▄▄▄▄▄▄▄▄▄▄███████
  ██████████████████████████
  ██████████████████████████
▄████████████████████████████▄
██████████████████████████████▌
█████▀                  ▀█████▌
████    ███▄      ▄███    ████▌
████   ▐████      ████▌   ████
 ███    ▀██▀      ▀██▀    ███▀
  ▀██▄                  ▄██▀
    ▀▀██████████████████▀▀




             ▄██▄
     ▄      ▐████   ▄▄
   █████     ██████████
    █████████████████▀
 ▄████████████▀████▌
██████████     ▀████    
 ▀▀   █████     ██████████
      ▀████▌▄████████████▀
    ▄▄▄███████████████▌
   ██████████▀    ▐████
    ▀▀▀  ████▌     ▀▀▀
         ▀███▀
jonanon
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
February 03, 2014, 05:13:17 PM
 #6

Offline storage is the safest way to go  Smiley
Sonny
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
February 05, 2014, 05:57:20 PM
 #7

Sorry to hear your loss.
You should have downloaded Vanitygen and run it offline instead.
yatsey87
Hero Member
*****
Offline Offline

Activity: 840
Merit: 509


View Profile
February 05, 2014, 06:07:19 PM
 #8

I don't trust these vanity address creaters or paper wallets. Do everything like this offline and only start with a small bit of funds being sent.
Sonny
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
February 05, 2014, 06:11:24 PM
 #9

I don't trust these vanity address creaters or paper wallets. Do everything like this offline and only start with a small bit of funds being sent.

I am not sure about other programs, but vanitygen is open-source and you can get the source here.
https://github.com/samr7/vanitygen
Mitchell
Staff
Legendary
*
Offline Offline

Activity: 4102
Merit: 2314


Verified awesomeness ✔


View Profile WWW
February 05, 2014, 06:12:10 PM
 #10

Sorry to hear your loss.
You should have downloaded Vanitygen and run it offline instead.
This. There are ways to safely generate a Vanity address, one being doing it yourself or buying an address from a vanitygen  pool which uses Privkey and Pubkey. However using a vanitygen pool will cost you a bit (click)

I don't trust these vanity address creaters or paper wallets. Do everything like this offline and only start with a small bit of funds being sent.

I am not sure about other programs, but vanitygen is open-source and you can get the source here.
https://github.com/samr7/vanitygen
Vanitygen is safe and has been around for a while now.

.
Duelbits
            ▄████▄▄
          ▄█████████▄
        ▄█████████████▄
     ▄██████████████████▄
   ▄████▄▄▄█████████▄▄▄███▄
 ▄████▐▀▄▄▀▌████▐▀▄▄▀▌██

 ██████▀▀▀▀███████▀▀▀▀█████

▐████████████■▄▄▄■██████████▀
▐██████████████████████████▀
██████████████████████████▀
▀███████████████████████▀
  ▀███████████████████▀
    ▀███████████████▀
.
         ▄ ▄▄▀▀▀▀▄▄
         ▄▀▀▄      █
         █   ▀▄     █
       ▄█▄     ▀▄   █
      ▄▀ ▀▄      ▀█▀
    ▄▀     ▀█▄▄▄▀▀ ▀
  ▄▀  ▄▀  ▄▀

Live Games

   ▄▄▀▀▀▀▀▀▀▄▄
 ▄▀ ▄▄▀▀▀▀▀▄▄ ▀▄
▄▀ █ ▄  █  ▄ █ ▀▄
█ █   ▀   ▀   █ █  ▄▄▄
█ ▀▀▀▀▀▀▀▀▀▀▀▀▀ █ █   █
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█  █▄█
█ ▀▀█  ▀▀█  ▀▀█ █  █▄█

Slots
.
        ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄
        █         ▄▄  █
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▄       █
█  ▄▄         █       █
█             █       █
█   ▄▀▀▄▀▀▄   █       █
█   ▀▄   ▄▀   █       █

Blackjack
|█▀▀▀▀▀█▄▄▄
       ▀████▄▄
         ██████▄
▄▄▄▄▄▄▄▄█▀    ▀▀█
████████▄        █
█████████▄        █
██████████▄     ▄██
█████████▀▀▀█▄▄████
▀▀███▀▀       ████
   █          ███
   █          █▀
▄█████▄▄▄ ▄▄▀▀
███████▀▀▀
.
                 NEW!                  
SPORTS BETTING 
|||
[ Đ ][ Ł ]
AVAILABLE NOW

Advertisements are not endorsed by me.
Sonny
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
February 05, 2014, 06:18:07 PM
 #11

Sorry to hear your loss.
You should have downloaded Vanitygen and run it offline instead.
This. There are ways to safely generate a Vanity address, one being doing it yourself or buying an address from a vanitygen  pool which uses Privkey and Pubkey. However using a vanitygen pool will cost you a bit (click)

I don't trust these vanity address creaters or paper wallets. Do everything like this offline and only start with a small bit of funds being sent.

I am not sure about other programs, but vanitygen is open-source and you can get the source here.
https://github.com/samr7/vanitygen
Vanitygen is safe and has been around for a while now.

Agree with bitcoininformation.  Wink
Oops, it seems like bitcoininformation agrees with me indeed lol  Cheesy
yatsey87
Hero Member
*****
Offline Offline

Activity: 840
Merit: 509


View Profile
February 05, 2014, 06:24:06 PM
 #12

Sorry to hear your loss.
You should have downloaded Vanitygen and run it offline instead.
This. There are ways to safely generate a Vanity address, one being doing it yourself or buying an address from a vanitygen  pool which uses Privkey and Pubkey. However using a vanitygen pool will cost you a bit (click)

I don't trust these vanity address creaters or paper wallets. Do everything like this offline and only start with a small bit of funds being sent.

I am not sure about other programs, but vanitygen is open-source and you can get the source here.
https://github.com/samr7/vanitygen
Vanitygen is safe and has been around for a while now.

I meant like online website ones.
Mythul
Sr. Member
****
Offline Offline

Activity: 644
Merit: 250


View Profile
February 09, 2014, 03:32:44 PM
 #13

I feel sorry for the loss. Maybe you had a hidden trojan somewhere on your pc. Be careful what you download of the internet.
Rawted
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500



View Profile
February 09, 2014, 03:47:24 PM
 #14

Use the QT. Quit relying on others to provide security for you.
2double0
Legendary
*
Offline Offline

Activity: 2618
Merit: 1105


View Profile
February 09, 2014, 03:49:30 PM
 #15

Use the QT. Quit relying on others to provide security for you.

Then you have to be VERY careful about your programs etc. Just use blockchain.info's wallet service.
Omikifuse
Legendary
*
Offline Offline

Activity: 1848
Merit: 1009



View Profile
February 09, 2014, 03:50:59 PM
 #16

So far bitcoin-qt is the best. Just use that wallet and nothing else..
DannyHamilton
Legendary
*
Offline Offline

Activity: 3486
Merit: 4820



View Profile
February 09, 2014, 04:03:47 PM
 #17

Use the QT. Quit relying on others to provide security for you.
Then you have to be VERY careful about your programs etc. Just use blockchain.info's wallet service.

In which case you STILL have to be VERY careful about your programs etc.

blockchain.info's service is just a wallet that runs in your browser.  Any program that can steal your bitcoins from a wallet running on your computer can steal bitcoins from blockchain.info's service.
Sonny
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1000


View Profile
February 09, 2014, 06:32:55 PM
 #18

Use the QT. Quit relying on others to provide security for you.
Then you have to be VERY careful about your programs etc. Just use blockchain.info's wallet service.

In which case you STILL have to be VERY careful about your programs etc.

blockchain.info's service is just a wallet that runs in your browser.  Any program that can steal your bitcoins from a wallet running on your computer can steal bitcoins from blockchain.info's service.

Exactly.

If you have a trojan/keylogger on your computer, your bitcoin will be stolen, no matter you are using bitcoin-qt, electrum, multibit, bc.i online wallet, or using exchanges / gambling sites to keep your bitcoin.

That's why you should never download a random file or click a random link, and you should better use a offline wallet to store your bitcoin. Cheesy
Banksy
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
February 10, 2014, 12:34:24 PM
 #19

Just like to bump this, exact same thing happened to me after using https://bitcoinvanity.appspot.com

I imported the new address into blockchain.info and secured with 2FA and email login approval.  7 BTC lost withdrawn to a random address over the past weekend. 

The only conclusion I can come to is that bitcoinvanity.appspot.com has been hacked, I note that nibors last post on 31 Dec 2013 is:

"Currently off-line due to hack - no bets lost though. Will update later."

This is regarding the sister site www.pinballcoin.com

Im pretty sure my mac has not been compromised, only install files from the app store and I have other wallets that are fine, just this one created via bitcoinvanity.

Expensive lesson for me to try and shortcut running the open source myself but hopefully someone else doesn't make the same mistake.
duhosnyul
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
February 10, 2014, 01:03:07 PM
 #20

Why need those vanity address. You are just creating another hole to your security. QT is enough and use a new clean install pc with only antivirus on it besides bitcoin and never use it other than storing your bitcoins.

Energycoin. eD5Kv8NxNAgge58bbyJfZpANDDJg2G7uid
Freebiescoin- Free Distribution
FCsxVbuZzEekqY9q9voNZHps7fnqndRfuF
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!