Bitcoin Forum
December 13, 2024, 04:42:33 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Someone hacked into our Blockchain.com wallet  (Read 680 times)
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
November 29, 2018, 07:09:40 PM
 #21

@get-paid, another user sent me the source code. I’ll take a look through it tonight and see if there’s anything that looks particularly tragic on it, although I’m going to say it’s probably a 5-7 score on your computer being fullly safe after uninstalling the plugin.
xhomerx10
Legendary
*
Offline Offline

Activity: 4060
Merit: 8976



View Profile
November 29, 2018, 07:13:04 PM
 #22

Someone posted here a scam (Crypton-Exchange.net), one of our admins was naive to try it, and the site told him to install an addon in order to withdraw the funds, naively he installed it and now we realized someone withdrew $2,300 from our Blockchain.com account (money that we intended to use to pay publishers, sadly is gone now).

The money was sent to 16EegrNMdZ9Rxku6Za5neEFjMW57wkQr1S
https://www.blockchain.com/btc/tx/0fe187e55c07772d47d1c588c80195f5977aa139d814feb39bdab968253c8f60

The addon was:
https://chrome.google.com/webstore/detail/cr-cash-plugin/joofmeiidadomccpmeaoagdogmbifhlh/related
From CryptoDraw.org

Few questions:

1) How did the Chrome addon allowed someone to withdraw funds from Blockchain.com? Isn't Blockchain.com safe?
2) Does this admin of ours need to format his laptop and change all passwords? He did remove that Chrome extension from his laptop.
3) Is anyone familiar with these types of scams? Can you provide more info about this Google Chrome extension etc.?





 2) It's a moot point.  You've terminated his employment with you and changed your Blockchain.com wallet for a new one, right?!
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2504



View Profile WWW
November 29, 2018, 09:33:41 PM
Merited by bitmover (1)
 #23

Thanks for the info about this.
How certain are you regarding this information? (say on a scale of 1 to 10).



Putting answers on a scale is quite hard.

Let me rephrase it:

1) There is no known chrome vulnerability currently (IF you are on the latest version) to break out of the sandbox.
This means that there is no way for an attacker to access your filesystem or your saved passwords.

The very tiny chance that he used a 0-day-exploit exists, but is negligibly small (especially considering that this is a 'simple add-on scam').

This means that:
  • Your saved passwords should be safe
  • Any keepass database or any other files on your harddrive should be safe
  • Your machine should be clean

Definitely tell your admin to check which browser version he has used. If it was not the latest, we have to dig further to find out if there are vulnerabilities which would allow to break out of the sandbox.



2) Depending on the permissions your administrator gave to the extension (assuming all have been granted):
  • Chances are VERY high that each password entered into the browser while the addon was active has been compromised
  • Chances are VERY high that ANY information entered into the browser while installed has been compromised


I hope this is enough information for you. Rating it on a scale between 1 and 10 wouldn't be close to professional.





Left to me, i will say 7 out of 10.  Always use a local password manager like KeePass

What ?

1) I don't think he has asked you.
2) I made 6 different statements. How can you simply say "7 out of 10" Huh
3) It is not about password manager. Even using a password manager would have caused the theft of the funds. Please read the whole thread.

Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1878
Merit: 389



View Profile
November 30, 2018, 03:25:40 PM
Last edit: November 30, 2018, 04:04:21 PM by Get-Paid.com
 #24

URGENT

Looks like he stole another $2k from us:

https://www.blockchain.com/btc/tx/0358082dda05367d4a1dba52d6bd0b64a8067dccbcf233684488b7fab58fa868

We did set up 2FA with the account, is it because of the 12 words (the key) that he was able to gain access? We got no email and no notification when these funds were stolen.

Someone else is going to be in charge of the funds from now on with a different PC and in a different country.


The issue is urgent and we need help, so we started a new topic:
https://bitcointalk.org/index.php?topic=5078190.0

This one will be locked.

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!