Bitcoin Forum
April 28, 2024, 12:18:31 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ELECTRUM WALLET HACKED  (Read 138 times)
ElectrumHACKED (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
December 17, 2020, 02:03:45 PM
 #1

Guys, please help:

On the 30th of November my electrum wallet was hacked:

Tx ID: 89abc9415125c304773b68bad4dd37456b2f459d035a73c19eea722ab78acc0b

No one knew the seeds, no one got access to my computer.

It seems many other addresses were ''scrapped'', but my seeds were extended.

Question, how should I proceed? Can anyone help me figure out the hackers addresses?
I'd like to finally, recover the funds if the hackers are stupid enough to sell them on exchanges.

Ps. It was 0.91 Bitcoin, not a very large sum, but I'm willing to share the funds if recovered!
"The nature of Bitcoin is such that once version 0.1 was released, the core design was set in stone for the rest of its lifetime." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714306711
Hero Member
*
Offline Offline

Posts: 1714306711

View Profile Personal Message (Offline)

Ignore
1714306711
Reply with quote  #2

1714306711
Report to moderator
1714306711
Hero Member
*
Offline Offline

Posts: 1714306711

View Profile Personal Message (Offline)

Ignore
1714306711
Reply with quote  #2

1714306711
Report to moderator
BitcoinGirl.Club
Legendary
*
Offline Offline

Activity: 2758
Merit: 2711


Farewell LEO: o_e_l_e_o


View Profile WWW
December 17, 2020, 02:06:46 PM
 #2

18Y8B6CJFEMS93zgSPycySNkBNbFwhvE2S
Is this your address? The funds are on this address. If it's not your address than possibly this is the hackers address.


You need to tell the full story. However there are nothing can be done I believe since the funds are confirmed. The only way if he moves them into a KYC verified exchange and the exchange can freeze the fund.

Edit:
I guess your computer was infected with malware. When you copy and pasted the address you wanted to send some coins then this malware changed your sending address and replaced it with the hackers address. Is this what you went through by any chance?

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
ElectrumHACKED (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
December 17, 2020, 02:15:31 PM
 #3

18Y8B6CJFEMS93zgSPycySNkBNbFwhvE2S
Is this your address? The funds are on this address. If it's not your address than possibly this is the hackers address.


You need to tell the full story. However there are nothing can be done I believe since the funds are confirmed. The only way if he moves them into a KYC verified exchange and the exchange can freeze the fund.

Edit:
I guess your computer was infected with malware. When you copy and pasted the address you wanted to send some coins then this malware changed your sending address and replaced it with the hackers address. Is this what you went through by any chance?


- That's what I'm hoping, that the hackers attempt to sell them on a KYC exchange.

- I never attempted to transfer out, it was a holding address only.

BitcoinGirl.Club
Legendary
*
Offline Offline

Activity: 2758
Merit: 2711


Farewell LEO: o_e_l_e_o


View Profile WWW
December 17, 2020, 02:24:47 PM
 #4

- That's what I'm hoping, that the hackers attempt to sell them on a KYC exchange.
I have no idea how to aware the exchanges so that they can concentrate on this address.

There is a site called bitcoinwhoswho the best you can do is to list that address in sites like this and alert the community.


Quote
- I never attempted to transfer out, it was a holding address only.
There must be some error, mistake from your side. Somehow the seeds were compromised without your knowledge or there are no way for anyone to target the address and run a program to find your keys.

Edit:
There are no need to create same topic in more than one board
https://bitcointalk.org/index.php?topic=5300864.0

You can easily move this topic to any section you want.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
ElectrumHACKED (OP)
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
December 17, 2020, 02:33:09 PM
 #5

- That's what I'm hoping, that the hackers attempt to sell them on a KYC exchange.
I have no idea how to aware the exchanges so that they can concentrate on this address.

There is a site called bitcoinwhoswho the best you can do is to list that address in sites like this and alert the community.


Quote
- I never attempted to transfer out, it was a holding address only.
There must be some error, mistake from your side. Somehow the seeds were compromised without your knowledge or there are no way for anyone to target the address and run a program to find your keys.

Edit:
There are no need to create same topic in more than one board
https://bitcointalk.org/index.php?topic=5300864.0

You can easily move this topic to any section you want.


I don't know what to do or where to post it, sorry I'll move it on the most appropriate.

Literally, the only computer which got the wallet has never been exposed on internet, I have no idea how could they do it, but they did.

The receiving address, after mixing is this: bc1qx65xcxz6dfsge2g4eaerercslh83y66wrpm79r
Seems an exchange
BitcoinGirl.Club
Legendary
*
Offline Offline

Activity: 2758
Merit: 2711


Farewell LEO: o_e_l_e_o


View Profile WWW
December 17, 2020, 02:53:34 PM
 #6

The receiving address, after mixing is this: bc1qx65xcxz6dfsge2g4eaerercslh83y66wrpm79r
Seems an exchange
The hacker obviously used a mixer to hide his trace but I am curious how would you know that the quoted address was the output address of the mixer?

I do not have much analytical knowledge to understand a move unless there are any easy open tool.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Easteregg69
Sr. Member
****
Offline Offline

Activity: 1436
Merit: 264



View Profile
December 17, 2020, 02:59:02 PM
 #7

Mark this one and find the thief.

Who uses mixers for laundry? A place to start.

Throw some "shit" and see what sticks.
mocacinno
Legendary
*
Offline Offline

Activity: 3374
Merit: 4919


https://merel.mobi => buy facemasks with BTC/LTC


View Profile WWW
December 17, 2020, 03:04:17 PM
 #8

The receiving address, after mixing is this: bc1qx65xcxz6dfsge2g4eaerercslh83y66wrpm79r
Seems an exchange
The hacker obviously used a mixer to hide his trace but I am curious how would you know that the quoted address was the output address of the mixer?

I do not have much analytical knowledge to understand a move unless there are any easy open tool.

If the hacker used a mixer, there is no way what his receiving address is. That's the point of a mixer...

The only thing i see is this transaction: 89abc9415125c304773b68bad4dd37456b2f459d035a73c19eea722ab78acc0b
It uses 3 unspent outputs to fund address:18Y8B6CJFEMS93zgSPycySNkBNbFwhvE2S
https://www.kycp.org/#/89abc9415125c304773b68bad4dd37456b2f459d035a73c19eea722ab78acc0b

Afterwards, the unspent output funding address 18Y8B6CJFEMS93zgSPycySNkBNbFwhvE2S is spent funding 2 addresses:
bc1ql72syjwvm4m9lwajpaylaxvj9lxc2tzn706ruj (value 0.1)
1KgiSi5wrVYumSskG3GPaaE2MSRdFKyzj7 (value 0.81399400)

the first address is funded with a round amount... This might be because of a self transfer, or a transfer to an exchange...
bc1ql72syjwvm4m9lwajpaylaxvj9lxc2tzn706ruj belongs to a huge wallet: https://www.walletexplorer.com/wallet/000003e028959c0b
So it's probably some sort of active service or exchange...

If the thief's first transaction went to a mixer's deposit address (18Y8B6CJFEMS93zgSPycySNkBNbFwhvE2S), the rest of the trace might belong to somebody completely different... That's how mixers work.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6971



View Profile WWW
December 17, 2020, 03:11:02 PM
 #9

Try to keep the discussion going on a single topic. Otherwise, itt becomes a mess with people repeating the same thing over and over again.

Anyways:
edit 2: The hacker may have sent your coins to Kucoin. Try to contact them? https://vivigle.com/BitWallet/wallet?address=bc1qx65xcxz6dfsge2g4eaerercslh83y66wrpm79r

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Lucius
Legendary
*
Offline Offline

Activity: 3220
Merit: 5633


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
December 17, 2020, 03:11:17 PM
 #10

~snip~

ElectrumHACKED, did you make an Electrum update before hacking or did you do anything else with the wallet? If no one has access to the seed and the computer, still hack somehow had to happen - my guess is that you downloaded the fake Electrum wallet, or you have some nasty trojan on the computer (Remote access trojan).
You can track your funds and contact any exchange that comes to your mind, but unfortunately a hacker is a lot of steps ahead of you given how much time has passed.

Not that I want to kill your hope, but after a month and a half go looking for a thief who may have used a mixer, an almost impossible mission.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
NotATether
Legendary
*
Offline Offline

Activity: 1582
Merit: 6697


bitcoincleanup.com / bitmixlist.org


View Profile WWW
December 17, 2020, 04:48:59 PM
 #11

Was the seed phrase leaked at any point of the wallet's lifetime? If so then they must have brute-forced the extended words too. It's the only likely possibility I can think of.

Did you generate the seed phrase from Electrum or did you generate one from a website? Perhaps the website was compromised or malicious, and in case you didn't also get extended words from there as well, then they were probably brute-forced as I wrote above.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
December 17, 2020, 09:04:56 PM
 #12

No one knew the seeds, no one got access to my computer.

Then the last option would be that you sent the funds yourself.

If this is not the case, then someone actually knew your mnemonic code, seed or private key. Or someone had access to your computer.
If your OS is windows 7 for example, that's already a strong indication for what happened.



Question, how should I proceed?

You should find out how that happened.
It your machine is compromised, more of your data is at risk (e.g. accounts, passwords, mail addresses, etc..).

Did you download any new software in the few days/weeks before 30.10 ? Did you open your wallet before your BTC got stolen?

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!