Bitcoin Forum
May 07, 2024, 11:58:16 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: URGENT! A 2nd Hack into our Blockchain wallet  (Read 680 times)
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:01:06 PM
 #1

We posted about the 1st hack here:
https://bitcointalk.org/index.php?topic=5077276.0

We added a 2FA to protect our Blockchain account, and nonetheless the hacker managed to get another $2,000 from the account - how?!

We got no SMS, no email notification, nothing that told us about this hack, so how did the hacker manage to hack again into that account?

If he had the 12 words (Backup Phrase) from the 1st hack - could he access the funds "without letting us know"? Is it possible?

Can anyone please advise?


🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
1715083096
Hero Member
*
Offline Offline

Posts: 1715083096

View Profile Personal Message (Offline)

Ignore
1715083096
Reply with quote  #2

1715083096
Report to moderator
1715083096
Hero Member
*
Offline Offline

Posts: 1715083096

View Profile Personal Message (Offline)

Ignore
1715083096
Reply with quote  #2

1715083096
Report to moderator
1715083096
Hero Member
*
Offline Offline

Posts: 1715083096

View Profile Personal Message (Offline)

Ignore
1715083096
Reply with quote  #2

1715083096
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715083096
Hero Member
*
Offline Offline

Posts: 1715083096

View Profile Personal Message (Offline)

Ignore
1715083096
Reply with quote  #2

1715083096
Report to moderator
1715083096
Hero Member
*
Offline Offline

Posts: 1715083096

View Profile Personal Message (Offline)

Ignore
1715083096
Reply with quote  #2

1715083096
Report to moderator
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:02:55 PM
 #2

When you go on Blockchain.com to help logging in:
https://login.blockchain.com/en/#/help

You can choose - "Recover your wallet with your 12 word backup phrase" - but if you do that you need to change the current password in the account. How did the hacker knew what was the new password?

When we logged into our hacked account we used the same password from before, so how did the hacker "change" the password back to the original and just took the funds?

Would appreciate any advice.

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
November 30, 2018, 04:04:59 PM
 #3

When you go on Blockchain.com to help logging in:
https://login.blockchain.com/en/#/help

You can choose - "Recover your wallet with your 12 word backup phrase" - but if you do that you need to change the current password in the account. How did the hacker knew what was the new password?

When we logged into our hacked account we used the same password from before, so how did the hacker "change" the password back to the original and just took the funds?

Would appreciate any advice.


If he has the 12 word seed, i'm pretty sure he'll be able to import that into other wallets such as electrum.[1] -- if that's the case, you won't receive any notification whatsoever.

But you state that he also reverted the password back. -- I have no clue what's happening there/how that is possible. I'd heavily suggest to avoid using webwallets in the future.



[1]
See how you can transfer your blockchain.info seed into electrum here; https://bitcoin.stackexchange.com/questions/66601/how-can-i-migrate-from-blockchain-wallet-to-electrum

Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:10:15 PM
 #4


But you state that he also reverted the password back. -- I have no clue what's happening there/how that is possible. I'd heavily suggest to avoid using webwallets in the future.


If the hacker just used the 12 word seed with another wallet, then he left the Blockchain web wallet intact without changing the password i.e. he hasn't changed the password, he just left everything and took the funds, is that what you're saying?

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 30, 2018, 04:12:48 PM
Merited by LoyceV (5), Foxpup (4), dbshck (3), Jet Cash (2)
 #5

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

It is impossible for blockchain.com to know whether the seed as been imported into another wallet.

But let me understand this:
You have used the SAME wallet with the SAME seed on the SAME 3rd party service which is way less secure than a normal wallet AFTER the attacker gained access to your account?

Really.. ?


A really good advice from me: Please stop any business around crypto.
First learn the basics (yes, BASICS), then start dealing with money.

NeuroticFish
Legendary
*
Offline Offline

Activity: 3668
Merit: 6381


Looking for campaign manager? Contact icopress!


View Profile
November 30, 2018, 04:16:41 PM
 #6

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

If the hacker got your seed or private key, he doesn't have to use with Blockchain.com wallet. And if he used it with other wallet, that other wallet will not notify you (why should do that?).
If the user moved away your funds, again, why would Blockchain.com do anything? Since the wallet's seed/private key was used on Bitcoin network, it's considered a legit access.


Now again. I wrote in the 1st hack post too. Consider using a proper (new!) wallet (with new address!!) on a virus-safe computer. Since you already lost 4k$, you should also spend 100$ and get a hardware wallet.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
November 30, 2018, 04:22:17 PM
Merited by vapourminer (1)
 #7

You have used the SAME wallet with the SAME seed on the SAME 3rd party service which is way less secure than a normal wallet AFTER the attacker gained access to your account?

Really.. ?


A really good advice from me: Please stop any business around crypto.
First learn the basics (yes, BASICS), then start dealing with money.

That's crazy. I don't understand.

You were hacked, then you kept your remaining funds there? Or did you put more funds in the hacked account?

 Why didn't you move your funds to another safer Wallet, such as Electrum or ledger as we suggested?

This makes no sense in either way.

When you were hacked, that account was compromised, and that computer as well.
I would format your computer and use only hard wallets.

If you wanna keep working with cryptocurrency, hire someone to manage your funds for you, maybe a escrow?

You really should look for basic information regarding wallets and security. But for you, I can only recommend a ledger nano wallet . You can use it in any infected machine. And please , never tell your seed to anyone, write it in a piece of paper, because no hacker can hack a paper. Never take a picture or something like that.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:25:23 PM
 #8

Or did you put more funds in the hacked account?
 Why didn't you move your funds to another safer Wallet, such as Electrum or ledger as we suggested?

Moved funds to the same account, a terrible and costly mistake.
Yes, now we would use safer wallets.

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:35:16 PM
 #9

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

It is impossible for blockchain.com to know whether the seed as been imported into another wallet.

But let me understand this:
You have used the SAME wallet with the SAME seed on the SAME 3rd party service which is way less secure than a normal wallet AFTER the attacker gained access to your account?

Really.. ?


A really good advice from me: Please stop any business around crypto.
First learn the basics (yes, BASICS), then start dealing with money.

We are experts at advertising and paying users, yes, when it comes to Crypto we have to learn a very hard lesson here.
Who in his right mind would use a compromised account to store more funds?

Yes, it's a terrible mistake, people do make mistakes, this one is indeed quite a costly one, it's no fun for sure, but we would have to storm it out and move on.

Thanks guys for letting us know hackers can use the 12 word seed to move funds without any notification in your web wallet.

So just to clarify, you could have all the "protection" you want, such as 2FA, email verification etc. - but if someone has your Blockchain 12 word seed - he can easily move the funds without having to go through all these security steps, correct?!

So basically these security steps are "Good for nothing" pretty much?!

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
November 30, 2018, 04:35:36 PM
 #10


But you state that he also reverted the password back. -- I have no clue what's happening there/how that is possible. I'd heavily suggest to avoid using webwallets in the future.


If the hacker just used the 12 word seed with another wallet, then he left the Blockchain web wallet intact without changing the password i.e. he hasn't changed the password, he just left everything and took the funds, is that what you're saying?

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

That's probably what happend, yes. It's a possibility for sure, and would explain why the blockchain.info wallet is still intact.

I'm not entirely sure how blockchain.info works in terms of how often you can export your seed, (i thought you could only do it once?), but i'm pretty sure that there's probably a way around that.

So just to clarify, you could have all the "protection" you want, such as 2FA, email verification etc. - but if someone has your Blockchain 12 word seed - he can easily move the funds without having to go through all these security steps, correct?!
Unless you encrypted your seed, yes. (Which again, is (AFAIK) not possible with Blockchain.info)

Quote
So basically these security steps are "Good for nothing" pretty much?!

Not really though. With blockchain.info you can only get someone's seed ( AFAIK, correct me if i'm wrong, i'm not exactly an expert on Blockchain.info) if you have access to his account.
2FA/email verification do make accessing/cracking someone's (web!)wallet a lot harder.

bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
November 30, 2018, 04:35:49 PM
Merited by vapourminer (1)
 #11

You were hacked, then you kept your remaining funds there? Or did you put more funds in the hacked account?


He had a compromised blockchain.info wallet and put more funds into this account (with the same seed).



When you were hacked, that account was compromised, and that computer as well.
I would format your computer and use only hard wallets.

He hasn't been hacked.

The 'admin' downloaded a malicious chrome add-on which allowed the attacker to withdraw all funds + get the seed.

The computer is most probably clean (at least not infected from this malware).
But regarding the very little knowledge about security + crypto, the PC might as well be compromised.



I'm not entirely sure how blockchain.info works in terms of how often you can export your seed, (i thought you could only do it once?), but i'm pretty sure that there's probably a way around that.


AFAIK, you can export the seed as often as you want.
Allowing to export it once wouldn't make sense IMO.

Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 04:44:57 PM
 #12

bob123, you seem like you're pretty spot on.
Thanks.

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
November 30, 2018, 05:01:29 PM
Merited by Jet Cash (2), dbshck (2), vapourminer (1)
 #13

So basically these security steps are "Good for nothing" pretty much?!


No. These security steps makes your blockchain.info wallet safer. This wallet was made to be used with all security steps done.

When you have done all security steps, your account is not going to be compromised so easily.

In your case, if you had 2fa+email verification the attacker would not be able to withdraw your funds, as a 2fa would be asked of him. He would not be able to see your seed, as 2fa is required for that as well. That's not 100%< far from it... But if there is 1% more security, it's worth.

When the attacker saw your seed, it's gone. It's not a matter of the wallet you are using anymore. Bitcoin and the blockchain technology was designed that way. In Bitcoin, the owner of the funds is the person who owns the Private key.

The seed is, simple put, a mathematical function that generate all your private keys.  that's why it must be kept safe. When it was compromised, all your wallet is compromised, you need a new one.


I'm not entirely sure how blockchain.info works in terms of how often you can export your seed, (i thought you could only do it once?), but i'm pretty sure that there's probably a way around that.

You can just click a button "see words" and you will see them.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
November 30, 2018, 05:08:14 PM
 #14

So basically these security steps are "Good for nothing" pretty much?!


No. These security steps makes your blockchain.info wallet safer. This wallet was made to be used with all security steps done.

When you have done all security steps, your account is not going to be compromised so easily.

In your case, if you had 2fa+email verification the attacker would not be able to withdraw your funds, as a 2fa would be asked of him. He would not be able to see your seed, as 2fa is required for that as well. That's not 100%< far from it... But if there is 1% more security, it's worth.

When the attacker saw your seed, it's gone. It's not a matter of the wallet you are using anymore. Bitcoin and the blockchain technology was designed that way. In Bitcoin, the owner of the funds is the person who owns the Private key.

The seed is, simple put, a mathematical function that generate all your private keys.  that's why it must be kept safe. When it was compromised, all your wallet is compromised, you need a new one.


I'm not entirely sure how blockchain.info works in terms of how often you can export your seed, (i thought you could only do it once?), but i'm pretty sure that there's probably a way around that.

You can just click a button "see words" and you will see them.

Thanks for the help bitmover!

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
LoyceMobile
Hero Member
*****
Offline Offline

Activity: 1655
Merit: 687


LoyceV on the road. Or couch.


View Profile WWW
November 30, 2018, 05:17:47 PM
 #15

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?

LoyceV on the road Advertise here for LN Don't deal with this account (exception)
Advertise here for LN Tip my kids Exchange LN (20 coins). 1% fee. No KYC <€50/month
My useful topics: Meritt & Trust & Moreee Art Advertise here for LN Foru[url=https://bitcointalk.org/m
AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
November 30, 2018, 06:03:56 PM
Last edit: November 30, 2018, 06:17:57 PM by AdolfinWolf
 #16

AFAIK, you can export the seed as often as you want.
Allowing to export it once wouldn't make sense IMO.

I can vaguely remember that in earlier versions of their webwallet, you could only backup your phrase once. Seems like that's not the case anymore. (Or maybe it has never been.)

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?
This is indeed an interesting vector.

one of our admins was naive to try it, and the site told him to install an addon in order to withdraw the funds, naively he installed it <...>

He's either pretty damn naive / tech/bitcoin illiterate, or he might be gaming you.  Huh

I mean, you said it yourself;
Who in his right mind would use a compromised account to store more funds?

Even if i knew nothing about bitcoin, i'd probably stop using such an account after it was compromised. I guess that might just be me though.


Something that's also interesting; the first time that you got hacked, the funds got send to

https://www.blockchain.com/btc/address/16EegrNMdZ9Rxku6Za5neEFjMW57wkQr1S

Which seems to be/could be some sort of collection of people that fell victim to this extension.

The second adress however, https://www.blockchain.com/btc/address/1MiMbMZF7QB47AaUp1sg4CWzsPFq7Ruo2e
Only has 1 transaction.

Why would the "hacker" create/send it to a new/clean adress, when he didn't do so in the first place?
Ah well. I'm probably reaching here.

LeGaulois
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 4095


Top Crypto Casino


View Profile
November 30, 2018, 06:07:28 PM
 #17

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?

While reading the OP, I was wondering if it could be something about the APIs, (if the site owner is using any). I am not familiar with it but what about if the hacker is just using it . The hacker didn't access the wallet via the web interface (otherwise he would have received his code), nor via a compromised OS.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
November 30, 2018, 06:24:47 PM
 #18

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?

While reading the OP, I was wondering if it could be something about the APIs, (if the site owner is using any). I am not familiar with it but what about if the hacker is just using it . The hacker didn't access the wallet via the web interface (otherwise he would have received his code), nor via a compromised OS.

When he installed the add-on, he was logged on the wallet in the same browser. Maybe the add-on accessed the browser , like Trojan or something like that.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
LeGaulois
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 4095


Top Crypto Casino


View Profile
November 30, 2018, 09:08:54 PM
 #19

My bad. I have re-read his first thread linked in OP. But in the discussion, he mentioned he formatted his OS, etc too...

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
zupdawg
Hero Member
*****
Offline Offline

Activity: 672
Merit: 508


View Profile
December 01, 2018, 12:59:25 AM
 #20

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?

This is probably the case here, if they still continue to get hacked even the ad-on is removed on the browser as they said previously on the first thread. AFAIK an ad-on dont have a virus-like function that can still access the device if its removed.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Thirdspace
Hero Member
*****
Offline Offline

Activity: 1232
Merit: 738


Mixing reinvented for your privacy | chipmixer.com


View Profile
December 01, 2018, 01:17:57 AM
 #21

Thanks guys for letting us know hackers can use the 12 word seed to move funds without any notification in your web wallet.
weren't there a pop-up warning about it when you save backup phrase for the first time

So just to clarify, you could have all the "protection" you want, such as 2FA, email verification etc. - but if someone has your Blockchain 12 word seed - he can easily move the funds without having to go through all these security steps, correct?!
yes. the same also applies to all standard bitcoin HD wallets
but some other wallets may implement extra Passphrase to protect its BIP39 Mnemonic (word seed)

So basically these security steps are "Good for nothing" pretty much?!
those protections only guard you against any attempts on breaking into your account
once your account breached and backup phrase copied, your bitcoin wallet is compromised
if your bitcoin wallet is compromised, those protections are no longer effective

bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
December 01, 2018, 08:55:12 AM
 #22

Maybe the add-on accessed the browser , like Trojan or something like that.

The whole purpose of a browser extension is to access the browser. Makes sense, doesn't it ?



This is probably the case here, if they still continue to get hacked even the ad-on is removed on the browser as they said previously on the first thread. AFAIK an ad-on dont have a virus-like function that can still access the device if its removed.

It doesn't need to have a 'virus like funtion'. (Also, please not that a virus is just malware which needs interaction from a user).
Once the seed is compromised (meaning: anyone knows the secret which allows to spend the BTC) it will stay compromised forever.



OP, if you have gotten enough ideas, consider closing this thread.
A lot of people have started posting in here without knowing what they are talking about.

buwaytress
Legendary
*
Offline Offline

Activity: 2800
Merit: 3443


Join the world-leading crypto sportsbook NOW!


View Profile
December 01, 2018, 08:55:49 AM
 #23

Have you considered the possibility of an inside job? In other words: how much do you trust your admin?

This is probably the case here, if they still continue to get hacked even the ad-on is removed on the browser as they said previously on the first thread. AFAIK an ad-on dont have a virus-like function that can still access the device if its removed.

There's your vulnerability point, and I think Occam's razor fits well here. The easiest way for this "hack" to have happened is that someone who already has access (seed, password, 2fa etc.) logged in and withdrew the funds.

If they did so, then they could also have been careless. Check access times on the 2fa device, and see if it coincides with the time of the hack, or even ask blockchain.com to see if 2fa alerts were sent. If alerts were sent and login times match, then you likely have the culprit. Maybe he/she even used a known address to withdraw to?

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
December 01, 2018, 08:16:29 PM
 #24


OP, if you have gotten enough ideas, consider closing this thread.
A lot of people have started posting in here without knowing what they are talking about.

Yes, you're right in one way.

One last idea we haven't asked about.

The hacker is the owner of Crypton-Exchange.net (as explained in the 1st thread), can we get to him by contacting the domain registrar of this domain? How feasible is that?

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
bitmover
Legendary
*
Online Online

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
December 01, 2018, 09:27:14 PM
Last edit: December 01, 2018, 09:56:46 PM by bitmover
 #25


One last idea we haven't asked about.

The hacker is the owner of Crypton-Exchange.net (as explained in the 1st thread), can we get to him by contacting the domain registrar of this domain? How feasible is that?


If you have proofs that this person is a criminal and stole your money, you can try to contact authorities . Registrar would be a good way to identify him

However, if he is the attacker (through the addon), it's probably that he also uses some sort of identity protection. It may not be easy to identify him.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
December 02, 2018, 12:58:02 AM
 #26


One last idea we haven't asked about.

The hacker is the owner of Crypton-Exchange.net (as explained in the 1st thread), can we get to him by contacting the domain registrar of this domain? How feasible is that?


If you have proofs that this person is a criminal and stole your money, you can try to contact authorities . Registrar would be a good way to identify him

However, if he is the attacker (through the addon), it's probably that he also uses some sort of identity protection. It may not be easy to identify him.

It might a,os be easy to find an innocent bystander who’s had their identity atolen too...
You might also have to check their and your jurisdication. Sometimes they like you to sue people in their country of residence...
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
December 02, 2018, 04:35:17 AM
 #27

It might a,os be easy to find an innocent bystander who’s had their identity atolen too...
You might also have to check their and your jurisdication. Sometimes they like you to sue people in their country of residence...

The owner of Crypton-Exchange.net was the one who "guided" our admin what to do, he told him to install the addon (and yes, it was naively done, a rookie's mistake), but legally speaking the chats are documented, when we confronted him for the theft he left the chat (he did speak to us initially), it's all documented - it was done from his site, using his site, it wasn't a Skype conversation where you can say it was a hacker hiding behind someone.

All the activity was made from the site, looking at the site ownership it seems to be registered with Reg.ru - we have some contacts who speak perfect Russian and are lawyers too, we will check the possibility of obtaining his details and getting him arrested in Russia, we have all the evidence we need.

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
December 02, 2018, 05:22:27 AM
Merited by dbshck (3)
 #28

So just to clarify, you could have all the "protection" you want, such as 2FA, email verification etc. - but if someone has your Blockchain 12 word seed - he can easily move the funds without having to go through all these security steps, correct?!
All of that creates a false sense of security for newbies. Stop using online wallets and start learning how to secure your systems.

It might a,os be easy to find an innocent bystander who’s had their identity atolen too...
You might also have to check their and your jurisdication. Sometimes they like you to sue people in their country of residence...

The owner of Crypton-Exchange.net was the one who "guided" our admin what to do, he told him to install the addon (and yes, it was naively done, a rookie's mistake), but legally speaking the chats are documented, when we confronted him for the theft he left the chat (he did speak to us initially), it's all documented - it was done from his site, using his site, it wasn't a Skype conversation where you can say it was a hacker hiding behind someone.
Which addon was that exactly?

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
December 02, 2018, 06:54:44 AM
 #29

This is the official reply from Blockchain.com

Hello,

I'm very sorry to hear about this. You may have some type of malware on your computer that resulted in your funds being stolen because your private information was somehow obtained. One of the most common types of these are browser extensions posing as bitcoin price tickers that are actually stealing your account information. There's also the possibility that you visited a phishing site posing as Blockchain. We've also heard of computer viruses that detect when an address is in your clipboard, and replace the one you wanted to use with an address controlled by this malicious party.

By design, Blockchain never has access to users' accounts or funds. If you keep your password and private key backups secure, then your funds are always safe with us. Since this information has been compromised, be sure to never use this wallet or any addresses contained within it. I'd also highly advise against using the same password again. I'm truly sorry that you had funds stolen from you. That certainly is an extremely frustrating experience.

If you’d like to learn more about how our wallet works, please visit: https://www.blockchain.com/learning-portal/wallet-faq.

Brian | Blockchain Support
Facebook: https://www.facebook.com/blockchain Twitter: https://twitter.com/Blockchain
Blog: https://blog.blockchain.com/

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
December 02, 2018, 01:03:26 PM
 #30

Which addon was that exactly?

From OP's first thread:






This is the official reply from Blockchain.com

Hello,

I'm very sorry to hear about this. You may have some type of malware on your computer that resulted in your funds being stolen because your private information was somehow obtained. One of the most common types of these are browser extensions posing as bitcoin price tickers that are actually stealing your account information. There's also the possibility that you visited a phishing site posing as Blockchain. We've also heard of computer viruses that detect when an address is in your clipboard, and replace the one you wanted to use with an address controlled by this malicious party.

By design, Blockchain never has access to users' accounts or funds. If you keep your password and private key backups secure, then your funds are always safe with us. Since this information has been compromised, be sure to never use this wallet or any addresses contained within it. I'd also highly advise against using the same password again. I'm truly sorry that you had funds stolen from you. That certainly is an extremely frustrating experience.

If you’d like to learn more about how our wallet works, please visit: https://www.blockchain.com/learning-portal/wallet-faq.

Brian | Blockchain Support
Facebook: https://www.facebook.com/blockchain Twitter: https://twitter.com/Blockchain
Blog: https://blog.blockchain.com/


I didn't expect anything else from their site.





All of that creates a false sense of security for newbies. Stop using online wallets and start learning how to secure your systems.

This.

Follow this advice.

In fact, noone which handles user funds or relies on funds to pay others should use a web wallet. Never.

keychainX
Member
**
Offline Offline

Activity: 374
Merit: 53

Telegram @keychainX


View Profile WWW
December 03, 2018, 09:39:31 AM
 #31

So Blockchain sends no notification if you import the wallet using the 12 word seed? Is that what happened here?

It is impossible for blockchain.com to know whether the seed as been imported into another wallet.

But let me understand this:
You have used the SAME wallet with the SAME seed on the SAME 3rd party service which is way less secure than a normal wallet AFTER the attacker gained access to your account?

Really.. ?


A really good advice from me: Please stop any business around crypto.
First learn the basics (yes, BASICS), then start dealing with money.

We are experts at advertising and paying users, yes, when it comes to Crypto we have to learn a very hard lesson here.
Who in his right mind would use a compromised account to store more funds?

Yes, it's a terrible mistake, people do make mistakes, this one is indeed quite a costly one, it's no fun for sure, but we would have to storm it out and move on.

Thanks guys for letting us know hackers can use the 12 word seed to move funds without any notification in your web wallet.

So just to clarify, you could have all the "protection" you want, such as 2FA, email verification etc. - but if someone has your Blockchain 12 word seed - he can easily move the funds without having to go through all these security steps, correct?!

So basically these security steps are "Good for nothing" pretty much?!


You should consider changing your e-mail address with blockchain.com , if they got your login credentials and password they could request the mail address to be moved, then they can drain your wallet.

Just make a new account, and change all your mail accounts and passwords.

Consider doing a clean install of your computer as well, just in case you have some code laying around.

You should also consider to check if you have a physical keylogger connected to your keyboard. Simple, is there any usb box between your keyboard cable and the computer (if you dont use a laptop)

/KX

Get-Paid.com (OP)
Sr. Member
****
Offline Offline

Activity: 1820
Merit: 386



View Profile
December 11, 2018, 04:53:31 AM
 #32

We have posted a conversation with the hacker, so this thread is now closed and locked and you can continue reading here:

https://bitcointalk.org/index.php?topic=5083139.0

🍀 Read our Blog how to make money from Gambling --> https://gamblingfreebies.com/ 🍀

💰 Our Top Bitcoin Faucet --> https://freebitcoin.io 💰
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!