Bitcoin Forum
April 24, 2024, 07:03:04 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: I think I was hacked on Bitfinex - what to do?  (Read 1325 times)
oddity (OP)
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile
February 04, 2014, 02:31:46 AM
 #1

I just had a very alarming series of events happen and would appreciate any advice as to my best course of action.

This is what went down:

1. I logged into my Bitfinex account for the first time in a couple of months.

2. Upon logging in I was asked for my google authenticator one-time key. I had not yet set up OTP on this account and so this was confusing.

3. While sitting there trying to think what to do I recieved an email from Bitfinex with an authorisation link to setup OTP. I clicked that link.

4. This took me to the security settings page. This page said that OTP was enabled. I couldn't disable it without an OTP code.

5. At this time I started receiving emails saying that BTC were being withdrawn from my account. I didn't authorise any trades or withdraws so I am not sure why this was happening.

6. I logged out of the account.


Does anyone know what could be happening here?
I've emailed BitFinex support to ask what happened. Is there anything else I can do? Is there a phone number or other contact? What else should I do??

Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713985384
Hero Member
*
Offline Offline

Posts: 1713985384

View Profile Personal Message (Offline)

Ignore
1713985384
Reply with quote  #2

1713985384
Report to moderator
HairyMaclairy
Legendary
*
Offline Offline

Activity: 1414
Merit: 2174


Degenerate bull hatter & Bitcoin monotheist


View Profile
February 04, 2014, 03:14:28 AM
 #2

Google "hong kong company search", find a search provider and do a search for Bitfinex.  You should be able to find phone numbers or at least registered addresses that way.
flower1024
Legendary
*
Offline Offline

Activity: 1428
Merit: 1000


View Profile
February 04, 2014, 03:17:27 AM
 #3

or you just use their support page: https://www.bitfinex.com/pages/support

you may get your account back, but i am not sure about the coins
Elwar
Legendary
*
Offline Offline

Activity: 3598
Merit: 2384


Viva Ut Vivas


View Profile WWW
February 04, 2014, 04:36:20 AM
 #4

Did you login to bitfinex.com from your address bar or did you click on an e-mail from Bitfinex and login with your username and password?

First seastead company actually selling sea homes: Ocean Builders https://ocean.builders  Of course we accept bitcoin.
oddity (OP)
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile
February 04, 2014, 09:10:14 AM
 #5

I logged in from the address bar but I now cant log in again because it is asking for an OTP code which I never set...

This also means I cannot start a ticket from within the Bitfinex website. From my point of view, it seems that the website has been compromised and that this is something that should be escalated quickly. I received multiple email notifications saying that BTC had been withdrawn from my account but I did not make any transactions at all so I am quite worried.

I emailed support 6+ hours ago and have had no response. I've tried messaging bitfinex people on this and other forums. I did a company search as suggested by HairyMaclairy but could not find a phone number. Anything else I can try?
anddam
Newbie
*
Offline Offline

Activity: 27
Merit: 0


View Profile
February 13, 2014, 03:40:04 PM
 #6

From what you wrote it sounds very much like your account got hacked (possibly by accessing your email box) and the hacker himself enabled the OTP.

Now it's been a few days since you opened the thread, can you provide us an update?
Rannasha
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


View Profile
February 13, 2014, 03:50:04 PM
 #7

Someone obtained your login-details. Either through malware on your computer (a keylogger) or from another website where you used the same credentials.

The attacker then added 2-factor-authentication to keep you out of your account.

Your first order of business is to assume your machine has been compromised and make sure that any Bitcoins are moved to a safe wallet. You can contact Bitfinex (check the official thread for usernames of Bitfinex-operators), but honestly I don't know how much they can do about the situation other than refunding you out of their own pocket.
alfabitcoin
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


View Profile
February 13, 2014, 04:14:24 PM
 #8

Hacker could get your email login and with your email in control used reset password to gain an access. Then setup otp himself.
Never use weak passwords on your email, try to find email service what offer otp and enable it in all internet services.
PirateHatForTea
Full Member
***
Offline Offline

Activity: 181
Merit: 104


View Profile
February 14, 2014, 12:34:05 AM
 #9

This sounds like it could have been a phishing attack in fact - are you sure thast the address bar showed the right url?

Unlevereged financial instruments acting as a store of value that fluctuate 50% within 10 minutes is perfectly acceptable. I think it should be offered in IRA form to soon to be retirees.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!