Bitcoin Forum
May 12, 2024, 03:13:53 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Logging in on scam website with ledger nano  (Read 418 times)
gatz (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
December 29, 2020, 10:54:07 PM
 #1

Hello,

Today I fell for a scam email that sent me to a copy of stellar website. There I logged in with my ledger nano s through usb. Then I realized that something is fishy, so I disconnected my ledger from laptop, created a new wallet on the same ledger and moved everything from the initial wallet to the 2nd one.
The scam website is similar with the original/ but had .mu at the end
I didn't gave away my secret words or anything inside the website. I just did the normal operations on the ledger (enter ledger pin, open stellar app)

1. I can consider my initial stellar wallet compromised?
2. I can consider my whole ledger nano compromised? if so I should reset the ledger and transfer all crypto assets to new accounts?

Thanks
1715526833
Hero Member
*
Offline Offline

Posts: 1715526833

View Profile Personal Message (Offline)

Ignore
1715526833
Reply with quote  #2

1715526833
Report to moderator
The grue lurks in the darkest places of the earth. Its favorite diet is adventurers, but its insatiable appetite is tempered by its fear of light. No grue has ever been seen by the light of day, and few have survived its fearsome jaws to tell the tale.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715526833
Hero Member
*
Offline Offline

Posts: 1715526833

View Profile Personal Message (Offline)

Ignore
1715526833
Reply with quote  #2

1715526833
Report to moderator
1715526833
Hero Member
*
Offline Offline

Posts: 1715526833

View Profile Personal Message (Offline)

Ignore
1715526833
Reply with quote  #2

1715526833
Report to moderator
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
December 30, 2020, 02:45:02 AM
 #2

I would say the answers to #1 and #2 are both: "Most likely not"... I suspect that fake website is designed to either steal Stellar "secret keys" by tricking users into connecting and opening the wallet using that key to connect and/or steal coins by simply getting users to send their coins to a fake "staking" service.

As you connected with the Nano S, the keys will not have been exposed as they are secured within the secure element in the device... and no wallet (or website) is able to extract them. This is the advantage of the hardware wallet... your keys cannot be compromised unless you explicitly type them into the website (or fake app) as they cannot be extract from the device.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
gatz (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
December 30, 2020, 12:22:39 PM
 #3

Thanks a lot. I figured as much, but I panicked a bit and wanted to be sure.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
December 30, 2020, 03:05:51 PM
 #4

1. I can consider my initial stellar wallet compromised?
2. I can consider my whole ledger nano compromised? if so I should reset the ledger and transfer all crypto assets to new accounts?

This is only the case if either:
1) you have entered the mnemonic code into the website or
2) there is an unknown vulnerability which allows to compromise the device by opening the application and communicating with it. This is extremely unlikely and shouldn't be considered. Especially because "wasting" such a worthy exploit for an attack like that would be... dumb.

So, in short: No, you are fine. Don't worry.

Don't enter your mnemonic code anywhere and don't confirm things on your nano without knowing what you are doing, and you are fine.

aoluain
Legendary
*
Offline Offline

Activity: 2254
Merit: 1256



View Profile
January 09, 2021, 07:42:49 PM
 #5

Hello,

Today I fell for a scam email that sent me to a copy of stellar website. There I logged in with my ledger nano s through usb. Then I realized that something is fishy, so I disconnected my ledger from laptop, created a new wallet on the same ledger and moved everything from the initial wallet to the 2nd one.
The scam website is similar with the original/ but had .mu at the end
I didn't gave away my secret words or anything inside the website. I just did the normal operations on the ledger (enter ledger pin, open stellar app)

1. I can consider my initial stellar wallet compromised?
2. I can consider my whole ledger nano compromised? if so I should reset the ledger and transfer all crypto assets to new accounts?

Thanks

sorry to hear that, this is a reminder that in these very
positive times the scammers are still scamming!

I created this thread last year about a fake ledger
website I came across, I bet so many people get scammed
by these. Here is the link to the thread, I hope it helps
others become aware of the scam.

We have to remember to be vigilant, hopefully you noticed
the scam in time to protect your stellar and wallet.

https://bitcointalk.org/index.php?topic=5205126.msg53198360#msg53198360

good advice from bob123 !

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7138



View Profile
January 10, 2021, 08:30:29 AM
 #6

That fake Stellar website reminds me of the incident that happened with EtherDelta back in 2017/2018. EtherDelta's DNS servers were compromised and users were redirected to a fake site. The way EtherDelta works is that you need to enter the private key of your Ethereum account on the site. Another way is to initiate a connection with the site through your hardware wallet.

A long story short, those who inserted their private keys, got their tokens stolen. The users who accessed the fake site with a hardware wallet remained safe. That's because there is no known attack vector that would allow a user to remotely steal your crypto from a hardware wallet unless you confirm the transactions physically or hand over your seed. 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!