Bitcoin Forum
May 11, 2024, 05:15:34 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: think i was scammed but not sure how. please help.  (Read 192 times)
osiris999 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
September 15, 2020, 12:22:20 AM
 #1

well guys it looks like i just lost 1100$ worth of bitcoin but im not sure what i did.
been a little while since i used electrum. this is the first time ive used 4.03. i had a few dollars worth already on electrum but i went to add about 1100$ worth. i clicked on receive and it gave me an address in a box. i sent the bitcoin i just purchased to that address. as soon as i did the transaction was showing up on my balance as incoming like usual. then all of a sudden electrum said my balance was now zero. it confirmed 6 times and is now a green check mark in my history. my balance is still 0. the weird thing is when i look at my history it shows 2 transactions at the same exact time. one coming in with the new bitcoin and one going out with the total amount.

i know that money more than likely gone but im scared to buy any bitcoin till i know how this happened and how i can prevent this.
1715404534
Hero Member
*
Offline Offline

Posts: 1715404534

View Profile Personal Message (Offline)

Ignore
1715404534
Reply with quote  #2

1715404534
Report to moderator
1715404534
Hero Member
*
Offline Offline

Posts: 1715404534

View Profile Personal Message (Offline)

Ignore
1715404534
Reply with quote  #2

1715404534
Report to moderator
1715404534
Hero Member
*
Offline Offline

Posts: 1715404534

View Profile Personal Message (Offline)

Ignore
1715404534
Reply with quote  #2

1715404534
Report to moderator
Once a transaction has 6 confirmations, it is extremely unlikely that an attacker without at least 50% of the network's computation power would be able to reverse it.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715404534
Hero Member
*
Offline Offline

Posts: 1715404534

View Profile Personal Message (Offline)

Ignore
1715404534
Reply with quote  #2

1715404534
Report to moderator
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
September 15, 2020, 12:27:32 AM
 #2

How did you update your version of electrum? There was a phishing message on the old version (anything around 3.x should be considered vulnerable now anyway).

Is there anything else you could've clicked on if it wasn't a phishing message, for example is your wallet password protected as it might be easier to accidentally click send on something otherwise.
osiris999 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
September 15, 2020, 12:49:53 AM
 #3

i went to electrum.org/ and downloaded the 4.0.3 stand alone exe. before i was using 3.3.8.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
September 15, 2020, 12:57:23 AM
Merited by mocacinno (1), ABCbits (1)
 #4

... the weird thing is when i look at my history it shows 2 transactions at the same exact time. one coming in with the new bitcoin and one going out with the total amount.
It would appear that your wallet has been compromised... most likely someone else has the seed for your wallet... they were monitoring your wallet and upon seeing the incoming transaction for $1000+, they created a transaction to steal it all.

How did you backup your wallet seed mnemonic (the 12 recovery words)? Huh Did you ever store this digitally on your computer or on a cloud based server? For example: screenshot, text document, instant messenger, "note" application, email etc? Huh

What address were your coins sent to?


i went to electrum.org/ and downloaded the 4.0.3 stand alone exe. before i was using 3.3.8.
Did you verify the digital signature of that standalone .exe file using GPG/Kleopatra (as per the instructions here)? Huh

If you still have the .exe, you should download the signature file (https://download.electrum.org/4.0.3/electrum-4.0.3.exe.asc) and then verify it, to make sure that the version of Electrum you downloaded is actually legitimate...

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
osiris999 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
September 15, 2020, 01:23:49 AM
 #5

... the weird thing is when i look at my history it shows 2 transactions at the same exact time. one coming in with the new bitcoin and one going out with the total amount.
It would appear that your wallet has been compromised... most likely someone else has the seed for your wallet... they were monitoring your wallet and upon seeing the incoming transaction for $1000+, they created a transaction to steal it all.

How did you backup your wallet seed mnemonic (the 12 recovery words)? Huh Did you ever store this digitally on your computer or on a cloud based server? For example: screenshot, text document, instant messenger, "note" application, email etc? Huh

What address were your coins sent to?


i went to electrum.org/ and downloaded the 4.0.3 stand alone exe. before i was using 3.3.8.
Did you verify the digital signature of that standalone .exe file using GPG/Kleopatra (as per the instructions here)? Huh

If you still have the .exe, you should download the signature file (https[Suspicious link removed].asc) and then verify it, to make sure that the version of Electrum you downloaded is actually legitimate...




seems like i gotta learn this the hard way. when verifying the exe i get "could not determine whether this is an s/mime or an openpgp signature" so i must be doing something wrong. as far as saving my seed looks like i made a big opsec error. its saved in a text file on my windoes pc and also a text file on tails. the text file on windows is what probably burned me. 
osiris999 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
September 15, 2020, 02:04:05 AM
 #6

coins were sent to 16jPSWsActk43MgzN9xZkwdnSpyLJk8iSH btw
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
September 15, 2020, 03:09:35 AM
 #7

as far as saving my seed looks like i made a big opsec error. its saved in a text file on my windoes pc and also a text file on tails. the text file on windows is what probably burned me. 
Yes, I would think that this is indeed where the problem comes from... it would tend to indicate that your PC has been compromised. You should seriously consider completely wiping that PC and reinstalling a fresh OS.

And in the future... NEVER store your seed on an "online" device. It should always be "offline".


coins were sent to 16jPSWsActk43MgzN9xZkwdnSpyLJk8iSH btw
Sorry, I was trying to clarify whether that is your wallet address or that is the address that the thief sent them to? Huh

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
sheenshane
Legendary
*
Offline Offline

Activity: 2408
Merit: 1215


Cashback 15%


View Profile WWW
September 15, 2020, 06:39:27 AM
 #8

Just my assumption and I think you're not downloading the phishing Electrum, probably since then your key has been compromised already with someone else, and waiting to have any amount to withdraw. If you visit the official website of Electrum and download the new version, you're safe in that way, so I think if you are using the old one Electrum key we don't know that has been compromised, that's a problem.

It is easy to make a new Electrum wallet, if you created a new one upon before storing big amounts, probably you're safe from a hack. We should learn how to value our valuable stuff to avoid scam/hack incidents. Never keep your key anywhere else most especially in an email account or social media accounts, it is easy for them to steal your wallet credentials. As the comment above, learn how to verify Electrum using GPG before you will download it.

coins were sent to 16jPSWsActk43MgzN9xZkwdnSpyLJk8iSH btw
If ain't mistaken, the last drop in your Bitcoin is on this address, 1N1RftauCKATtkVFsx1iifRPQVo45myqsm.
Sorry for your loss.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
AhmadM
Sr. Member
****
Offline Offline

Activity: 1022
Merit: 308


View Profile
September 15, 2020, 06:20:16 PM
 #9

coins were sent to 16jPSWsActk43MgzN9xZkwdnSpyLJk8iSH btw
If that is your wallet address then I have hypothesis that your address has been compromised in dusting attack (based on this tx)
And according to this post the attack will leads to this page:
Code:
https://memo.sv/topic/hmwyda

CMIIW
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7137



View Profile
September 16, 2020, 07:36:42 PM
 #10

i went to electrum.org/ and downloaded the 4.0.3 stand alone exe. before i was using 3.3.8.
Are you absolutely positive that you went to the official site and downloaded an official version of the software. I am confused why you couldn't verify it?!

It would appear that your wallet has been compromised... most likely someone else has the seed for your wallet... they were monitoring your wallet and upon seeing the incoming transaction for $1000+, they created a transaction to steal it all.
That fast? OP says that he has two transactions in his history. One incoming and one outgoing at the same time. This looks more like a fake Electrum version/script, rather than someone monitoring his wallet. If, in fact the 2 transactions took place so quickly one after the other.

@osiris999
In your history, how much time passed before the incoming and outgoing transactions in your wallet?
Do you share the computer with anyone? If you didn't download a fake Electrum client, the question is who found your seed and how!?

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5664


Blackjack.fun🎲


View Profile WWW
September 17, 2020, 10:41:58 AM
 #11

Do you share the computer with anyone? If you didn't download a fake Electrum client, the question is who found your seed and how!?

This is a real question, because if more people use this computer, everyone could see the seed that the OP saved as a plain text file.

as far as saving my seed looks like i made a big opsec error. its saved in a text file on my windoes pc and also a text file on tails. the text file on windows is what probably burned me. 

If he is the only user of that computer, then someone did it remotely, and one remote access trojan is quite enough for something like that. It would not be strange if someone had control over his crypto wallet from before, but he was waiting for a slightly higher amount of a few $ that the OP had until then.

Also, although it was not mentioned, maybe that seed was not generated by the OP, but it was a way of buying BTC. In addition to the trick of selling watch-only wallets, some sell the actual seed with a certain amount of BTC - and when a buyer at some point sends a larger amount into his wallet, an unpleasant surprise awaits them.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!