Bitcoin Forum
June 21, 2024, 08:58:08 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 »  All
  Print  
Author Topic: FreeBitco.in Appears Hacked - Monthly Prize Money Stolen From Multiple Users  (Read 1851 times)
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 09:39:36 AM
 #21

I don't know if it's worse to do nothing for now or to still try to make a withdrawal Undecided

Similar quandary...

Yeah same. Sooner or later my balance will hit the minimum withdrawal threshold. Will the hackers attempt to strike again!?

I did nothing. Yet the hackers were still able to initiate a withdrawal of my entire balance, and overwrite my profile address.

The only thing that saved me was the payment request confirmation email.

Then I enabled 2FA and it was all gone.

In hindsight, if I hadn't enabled 2FA I'd still have my coins.

It was only $50. Fortunately I'd withdrawn April earnings before the wagering contest winners were announced.

It seems there's no way to defend against this attack other than to disable 2FA. Even so, that's no guarantee that deposits or withdrawals will be sent to an address you specify.

At least with 2FA disabled you'll get a payment request confirmation email and you can decide whether to approve the payment or not.


http://dripdropcoin.com/
mindrust
Legendary
*
Offline Offline

Activity: 3290
Merit: 2450



View Profile WWW
May 04, 2024, 10:13:02 AM
 #22

That email looks legit. It is probably not a part of the attacker’s plan. Still though, like I said what you see on your browser isn’t the truth probably as the victims are loading a malicious script. As long as the backend of the app is safe, you shouldn’t worry. Hopefully it is safe Grin

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Lucius
Legendary
*
Offline Offline

Activity: 3276
Merit: 5730


Top Crypto Casino BC.GAME🎲


View Profile WWW
May 04, 2024, 10:17:27 AM
Merited by uneng (1)
 #23

I advise everyone to refrain from making deposits until further notice, and to be extra careful when making withdrawals - I personally have a nice sum there, but I don't know if it's worse to do nothing for now or to still try to make a withdrawal Undecided
Just cashed out all my satoshis from the platform yesterday after reading all these news. Withdrawal went fine and arrived on my wallet without delays, as usual.
~snip~


Thanks for the info, because it means that the entire system is not compromised, but someone obviously has access to a part of the system that they are manipulating for malicious purposes. Given that in some posts it was possible to read that freebitco occasionally has help from the side, it is possible that one of the external collaborators decided to use their access to the system and the apparent current lack of control and supervision from the owner.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 10:22:31 AM
 #24

That email looks legit. It is probably not a part of the attacker’s plan. Still though, like I said what you see on your browser isn’t the truth probably as the victims are loading a malicious script. As long as the backend of the app is safe, you shouldn’t worry. Hopefully it is safe Grin

Yes, understood. Thankyou.

I'd like to know more about this malicious script. Do you know if anyone has posted the script source code to Pastebin or simular.



http://dripdropcoin.com/
mindrust
Legendary
*
Offline Offline

Activity: 3290
Merit: 2450



View Profile WWW
May 04, 2024, 10:26:14 AM
 #25

I’d like to look when I am home but I am scared to touch that shit too as I also have an acc there.

I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Drazen2003
Jr. Member
*
Offline Offline

Activity: 43
Merit: 1


View Profile
May 04, 2024, 10:29:00 AM
 #26

I didn't do anything. I certainly wasn't tricked into doing anything
I received an email notification that I had won a place in the wagering contest. I was expecting this email. I didn't click any links.
I opened chrome and clicked my freebitcoin bookmark to check if the prize money was in my account. It was. I was staring right at the balance. It disappeared. Went to zero. Then the referral coins started trickling in again.
Then I got an email notification about a pending withdrawal.
I hadn't done anything except open freebitcoin in chrome to check my balance.
After an hour the withdrawal was reversed and the coins returned to my account.
That's when I made the mistake of enabling 2FA

I think you got a fake email because the attacker already knew that you were going to be one of the winners of that contest. Who is the sender? Did it come from freebitco.in?

As the other victims pointed out, there seems to be a malicious script that’s targeting certain people. However this script loads on your browser. (Client-side) That means it has the ability to show you anything. Who knows what’s in that script… It can probably show a fake deposit address too.

That’s where you were getting tricked.

 Just because you saw 0 balance didn’t mean you actually had 0 because your balance’s record kept at the back-end (server-side) of the application.

So till freebitco.in finds a fix, nobody should do anything stupid like sending coins to another wallet or deposit to a fake address. Better stay away for a while.

Some people managed to withdraw their coins successfully, maybe try that

In my case, stolen twice in the last month (one depositing from kraken to a "new" Diposit Address that appeared in the Freebitco.in Deposit window and another one making a widthdrawal introducing the address manually but when clicking the widthdraw button all changed (I have an screenshot just before clicking and the sent movement in the Stats - Profile page naming another address different to the one I wrote).

More than 48 hours later, my Deposit address continue being false and i have the cashtravel script in the developer tools. I have tested in 2 different PCs, 3 different navigators and 1 mobile phone. In all of them the Deposit address is not the mine one.

Then, i cannot recover my address, I cannot use the page. Freebitco.in have some emails but...
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 10:35:16 AM
 #27

...
I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

Yes, it can do both. An unauthorised withdrawal was initiated on my account. And it was able to bypass my profile address instead inserting the attackers address.

http://dripdropcoin.com/
mindrust
Legendary
*
Offline Offline

Activity: 3290
Merit: 2450



View Profile WWW
May 04, 2024, 10:38:29 AM
 #28

...
I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

Yes, it can do both. An unauthorised withdrawal was initiated on my account. And it was able to bypass my profile address.

Shiet. Now we all can panic.

TheQuin where the hell are you man your establishment has caught FIRE!

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 10:48:51 AM
 #29

...
I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

Yes, it can do both. An unauthorised withdrawal was initiated on my account. And it was able to bypass my profile address.

Shiet. Now we all can panic.

TheQuin where the hell are you man your establishment has caught FIRE!
Absolutely!

If you have 2FA enabled you won't get a payment request confirmation email from freebitco.in

What you will get is a payment sent confirmation email.

The attackers targeted the bigger fish. This time...

http://dripdropcoin.com/
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 11:01:14 AM
Last edit: May 04, 2024, 11:30:48 AM by codergeek
 #30

...
Yeah.

It's not safe to deposit. The attackers can change the destination address.

It's not safe to withdraw. For the same reason.

It's not safe to stand idly by and do nothing. The attackers can initiate a withdrawal and overwrite the profile adress

The attackers know that their attack was successful.
I would expect them to target any user with a balance above the minimum withdrawal threshold next.

The attackers also know that the vulnerability that they are exploiting will sooner or later be patched

If you can get your coins out now before the attackers make their next move...

http://dripdropcoin.com/
Drazen2003
Jr. Member
*
Offline Offline

Activity: 43
Merit: 1


View Profile
May 04, 2024, 02:31:01 PM
 #31

...
Yeah.

It's not safe to deposit. The attackers can change the destination address.

It's not safe to withdraw. For the same reason.

It's not safe to stand idly by and do nothing. The attackers can initiate a withdrawal and overwrite the profile adress

The attackers know that their attack was successful.
I would expect them to target any user with a balance above the minimum withdrawal threshold next.

The attackers also know that the vulnerability that they are exploiting will sooner or later be patched

If you can get your coins out now before the attackers make their next move...


It is not safe and there is more than one problem. There has been talk of a cashtravel script that those of us affected have had but now it no longer appears and even so, the deposit addresses are fake (and it is not possible to change it) so any withdrawal can go to any unknown address.

This is the address where all my funds were stolen and still is the Deposit address when i click the Deposit button: 144p3SroEwDs1rdMmBqkCKHLpQ2TUCH3Li.

My real Diposit address does not even appear in the old ones inside the window.

I have made my account available to freebitco.in by email for investigation but they do not respond to any email. I hope they are doing something even if it is silent.

By the moment, of couse I cannot do anything in freebitco.in and i am recomending not using the page.


Saint-loup
Legendary
*
Offline Offline

Activity: 2646
Merit: 2382



View Profile
May 04, 2024, 05:36:57 PM
Last edit: May 04, 2024, 06:44:51 PM by Saint-loup
 #32

...
I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

Yes, it can do both. An unauthorised withdrawal was initiated on my account. And it was able to bypass my profile address.

Shiet. Now we all can panic.

TheQuin where the hell are you man your establishment has caught FIRE!
Absolutely!

If you have 2FA enabled you won't get a payment request confirmation email from freebitco.in

What you will get is a payment sent confirmation email.

The attackers targeted the bigger fish. This time...
If the attackers are able to bypass the 2FA security and to initiate withdrawals whenever they want why you are the only user reporting it till now? They would have no reason to wait before withdrawing as much funds as they can, so I think many people would already be here complaining about random withdrawals happening spontaneously. That's why your claim is a little bit surprising. Are you sure no one living with you, has been able to steal your funds? If yes, are you sure your 2FA device is safe and hasn't been compromised too?

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 08:53:21 PM
Last edit: May 04, 2024, 10:44:34 PM by codergeek
 #33

...
I wonder if this script can send a withdrawal request or change the withdrawal address though. Since it has an access to the client side, it can do whatever it wants. (From your side)

Yes, it can do both. An unauthorised withdrawal was initiated on my account. And it was able to bypass my profile address.

Shiet. Now we all can panic.

TheQuin where the hell are you man your establishment has caught FIRE!
Absolutely!

If you have 2FA enabled you won't get a payment request confirmation email from freebitco.in

What you will get is a payment sent confirmation email.

The attackers targeted the bigger fish. This time...
If the attackers are able to bypass the 2FA security and to initiate withdrawals whenever they want why you are the only user reporting it till now? They would have no reason to wait before withdrawing as much funds as they can, so I think many people would already be here complaining about random withdrawals happening spontaneously. That's why your claim is a little bit surprising. Are you sure no one living with you, has been able to steal your funds? If yes, are you sure your 2FA device is safe and hasn't been compromised too?

The OP listed points 1-8 above

My situation and reaction was almost identical. Obviously the amount I won was different. The unknown address was also different.

I didn't say, "the attackers are able to bypass the 2FA security..."

I said they were able to initiate an unauthorised withdrawal, bypass my default profile address and insert an unknown Bitcoin address.

It's important to note that this happened prior to enabling 2FA.

After I enabled 2FA, I initiated an authorised withdrawal. The attackers hijacked this withdrawal.

What I said in relation to 2FA was you won't receive a payment request confirmation if 2FA is enabled.

So, having 2FA enabled therefore does work to the attackers advantage.


Maybe something got lost in the translation.






http://dripdropcoin.com/
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 04, 2024, 10:07:08 PM
Last edit: May 05, 2024, 01:27:21 AM by codergeek
 #34

That's when I made the mistake of enabling 2FA

Even with 2fa, my default profile address never changed...

Same here, my profile address never changed.

I didn't even attempt a withdrawal.

The hackers triggered the withdrawal seconds after the prize money was credited to my account, and somehow they managed to bypass my profile address.

Ouch, gotcha... Takes the sting out of me at least trying to get process a little less stingy... *sigh*

They must have been able to solve our 2fa "upgrade" for us... how kind.

Initially I didn't make a withdrawal.

I just opened freebitcoin to check my balance just as you did.




Someone has pasted a version of the malicious cash travel js here https://pastebin.ai/eo0q78pbuj




http://dripdropcoin.com/
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 05, 2024, 01:56:37 AM
 #35

@BayAreaCoins

Someone mentioned in another simular topic that the link to the malicious script was somehow hidden in the advanced tracking using tags button code on the freebitco.in site.

https://bitcointalk.org/index.php?topic=5492456.msg64033700#msg64033700

I actually did click that button days prior to the attack on my account.

Food for thought.

http://dripdropcoin.com/
ixi1234
Jr. Member
*
Online Online

Activity: 53
Merit: 2


View Profile
May 05, 2024, 02:44:15 AM
Last edit: June 07, 2024, 04:04:49 PM by ixi1234
 #36

OK, so that people no longer have doubts about how the address is being changed when withdrawing funds. At the end of the video, watch carefully how my output address was changed!!! I hope no one else will say that we are deceiving you and the site is not hacked!
https://www.dropbox.com/scl/fi/rsu1hq8tgj810e2p8bqj7/video_20240505_093225_edit.mp4?rlkey=me946bfe2utlhz2vtc3yqjgg7&st=ywer9mzb&dl=0



Update!!:
After I posted the video with the substitution of the withdrawal address, an hour later I tried to withdraw funds again and surprisingly my address did not change and the withdrawal went to the correct address! Is it a coincidence??? Or are hackers monitoring this forum topic?
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 05, 2024, 05:02:16 AM
 #37

OK, so that people no longer have doubts about how the address is being changed when withdrawing funds. At the end of the video, watch carefully how my output address was changed!!! I hope no one else will say that we are deceiving you and the site is not hacked!
https://dropmefiles.com/56V5d



Update!!:
After I posted the video with the substitution of the withdrawal address, an hour later I tried to withdraw funds again and surprisingly my address did not change and the withdrawal went to the correct address! Is it a coincidence??? Or are hackers monitoring this forum topic?

It appears you do not have 2FA enabled which is why you received a payment request confirmation email and were therefore able to abort the withdrawal by not clicking the confirmation link in the email.

I have disabled 2FA for this reason.

Thankyou for the video. Much appreciated.


http://dripdropcoin.com/
ixi1234
Jr. Member
*
Online Online

Activity: 53
Merit: 2


View Profile
May 05, 2024, 05:11:49 AM
 #38

OK, so that people no longer have doubts about how the address is being changed when withdrawing funds. At the end of the video, watch carefully how my output address was changed!!! I hope no one else will say that we are deceiving you and the site is not hacked!
https://dropmefiles.com/56V5d



Update!!:
After I posted the video with the substitution of the withdrawal address, an hour later I tried to withdraw funds again and surprisingly my address did not change and the withdrawal went to the correct address! Is it a coincidence??? Or are hackers monitoring this forum topic?

It appears you do not have 2FA enabled which is why you received a payment request confirmation email and were therefore able to abort the withdrawal by not clicking the confirmation link in the email.

I have disabled 2FA for this reason.

Thankyou for the video. Much appreciated.



I also turned off 2fa for this reason, but! there is one important caveat, if you withdraw funds to an address linked to an fbc account, then an email with a confirmation link will not be sent. Therefore, you need to make a withdrawal to an address that is not linked to the account!
codergeek
Jr. Member
*
Offline Offline

Activity: 105
Merit: 2


View Profile WWW
May 05, 2024, 05:21:10 AM
 #39

OK, so that people no longer have doubts about how the address is being changed when withdrawing funds. At the end of the video, watch carefully how my output address was changed!!! I hope no one else will say that we are deceiving you and the site is not hacked!
https://dropmefiles.com/56V5d



Update!!:
After I posted the video with the substitution of the withdrawal address, an hour later I tried to withdraw funds again and surprisingly my address did not change and the withdrawal went to the correct address! Is it a coincidence??? Or are hackers monitoring this forum topic?

It appears you do not have 2FA enabled which is why you received a payment request confirmation email and were therefore able to abort the withdrawal by not clicking the confirmation link in the email.

I have disabled 2FA for this reason.

Thankyou for the video. Much appreciated.



I also turned off 2fa for this reason, but! there is one important caveat, if you withdraw funds to an address linked to an fbc account, then an email with a confirmation link will not be sent. Therefore, you need to make a withdrawal to an address that is not linked to the account!

Thanks for the additional information.

It would seem then that the safest course of action is to turn off 2FA and generate a new Bitcoin wallet address. And of course confirming the address before clicking the confirmation link in the email.

http://dripdropcoin.com/
GinnyBanzz
Newbie
*
Offline Offline

Activity: 43
Merit: 0


View Profile
May 05, 2024, 06:16:41 AM
 #40

I looked through the malicious JS code. It seems to be targetting user id 31898443 specifically (unless a different ID is loaded based on the url parameters used to load the js from the cashtravel site.

It appears then to hit https://bitwrecken.com/?action=new&id=31898443 to get the new / rogue deposit address. Presumably this is done so the attackers can cycle through various different rogue deposit addresses, or even randomise them.

There is a then a html element called main_deposit_address which is replaced by the value retrieved from the bitwrecken.com site

The script is actually rather simple in how it works, nothing complicated going on.

The worrying part, is how the attackers were able to embed this into the freebitco.in site and whether it has affected all users. It feels like those who clicked the advanced tracking button in the referral page may be the ones who were hit, but not seen any confirmation of this.

Pages: « 1 [2] 3 4 5 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!