Bitcoin Forum
April 26, 2026, 03:38:51 AM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Another strange case of Bitcoin loss.  (Read 275 times)
mcdouglasx (OP)
Hero Member
*****
Offline Offline

Activity: 980
Merit: 535



View Profile WWW
December 02, 2024, 01:47:39 AM
 #1

About a month ago, while researching BIP39 with Copilot, I was given an example of a BIP39 seed. I entered it into Electrum and saw that there were 2 transactions

in the change address: 172LHmTcW1VESuNtVtPKUdpQNPh2XURjar for 99 BTC. I didn't pay much attention to it, but today I opened Electrum and out of curiosity I

googled that address 172LHmTcW1VESuNtVtPKUdpQNPh2XURjar and found this post https://coinforum.de/topic/30100-einzahlung-auf-electrum-wurde-direkt-an-fremde-adresse-weitergeleitet/ where a user says they lost those 99 BTC.

What could have happened here?.

I suspect that the user might have had bad luck downloading compromised software, although this happens daily. I'm intrigued by why only this change address

was used that one time, and all the others have 0 transactions. It's overwhelming to think that someone with access to such a large amount of money was a victim of

this rare and little-known case.

What do you think could have happened here?.

██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██



██
██
██
██
██
██
██



██
██
██
██
██



██
██

██
██
██
██
██
██
██
██
██
██
███████▄▄███████▄▄
████▄███████████████▄█████▄▄▄
██▄███████████████████▄▄██▀████▄▄▄▄▄▄▄▄███▄██████
▄███████████████████▀▄█████▄▄███████████▄▀▀▀██▄██
▄███▐███████████████▄▄▀███▀███▄█████████████▄███████
████▐██████████████████▀██▄▀██▐██▄▄▄▄██▀███▀▀███▀▀▀
█████████████████████▌▄▄▄██▐██▐██▀▀▀▀███████████
███████▌█████████▐██████▄▀██▄▀█████████████████████▄
▀██▐███▌█████████▐███▀████████▄██████████▀███████████
▀█▐█████████████████▀▀▀███▀██▀▀▀▀▀▀▀▀▀██▀▀▀███▀▀▀▀▀
██▀███████████████████▀▄██▀
████▀███████████████▀
███████▀▀███████▀▀
██
██


██
██
██
██
██
██
██
██
██

██
██
██


██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
 
    FAST    🔒 SECURE    🛡️ NO KYC        EXCHANGE NOW      
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██

██
██
██
██
██
██


██
██
██
██
██
██
██
██
██
██

██
██
██
██
██
██
██
██
██
██
██
Mia Chloe
Legendary
*
Offline Offline

Activity: 1050
Merit: 2177


Contact me for your designs...


View Profile
December 02, 2024, 05:31:03 AM
Merited by vapourminer (4), pooya87 (4), ABCbits (1)
 #2

After going through the whole writeup, two things popped up in my mind. Although it's possible he may have downloaded a compromised or fake software that has been tweaked by a hacker, it's also possible he is using an original software but his device is either infected by a key logger or he has a malware like clipboard virus. If it was a key logger, they probably used it to get hold of his seed s and only signed transactions after he attempted to make one.

If they have his seed it's possible for them to use CPFP to resend the funds to their own wallet just before it gets confirmed and if it's a clipboard virus then every time he copied and pasted a receiving address the hackers address was pasted instead. When hackers do things like this they make use of huge fees so before you notice it has already been long confirmed.

Don't forget to keep your keys safe!!

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
nc50lc
Legendary
*
Offline Offline

Activity: 3122
Merit: 8671


Self-proclaimed Genius


View Profile
December 02, 2024, 06:05:46 AM
Merited by vapourminer (4), pooya87 (4)
 #3

I'm intrigued by why only this change address

was used that one time, and all the others have 0 transactions. It's overwhelming to think that someone with access to such a large amount of money was a victim of
You're overthinking it.
The owner is free to select which address that he will use as a paper wallet from his wallet's keys and address.
He might have selected a change address maybe because he's thinking that it's safer.

If it's not a paper wallet (unlike the author mentioned), it could be an RBF transaction that sent the BTC back to self.
e.g.: Electrum uses its change address as a recipient when using that feature, given the relatively high fee, he may have attempted to do it in Electrum but on a compromised client/machine.

Anyways, you'll only be receiving "educated guesses" without solid information about the case.
Is the seed phrase somehow peculiar?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Hatchy
Legendary
*
Offline Offline

Activity: 1120
Merit: 1193


Hatchy managerial services


View Profile WWW
December 02, 2024, 07:24:45 AM
 #4

The owner is free to select which address that he will use as a paper wallet from his wallet's keys and address.
He might have selected a change address maybe because he's thinking that it's safer.

If it's not a paper wallet (unlike the author mentioned), it could be an RBF transaction that sent the BTC back to self.
e.g.: Electrum uses its change address as a recipient when using that feature, given the relatively high fee, he may have attempted to do it in Electrum but on a compromised client/machine.

Anyways, you'll only be receiving "educated guesses" without solid information about the case.
Is the seed phrase somehow peculiar?
Upon reading the through, I can see that the sender isn't sure of what he did. He claimed to have sent the coins to an address he copied but upon confirmation, the coins were been transferred immediately to another address unknown to him. It's more like the coin has already been received to his destination and someone had access to his key. So there's only one thing that might have been wrong and that's his wallet had been compromised and a hacker has he's seed phrase. Like I said, the story isn't clear as the author wasn't sure of what he did. All we know was that his coins kept been transferred out of his wallet.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
mcdouglasx (OP)
Hero Member
*****
Offline Offline

Activity: 980
Merit: 535



View Profile WWW
December 02, 2024, 01:32:28 PM
 #5

If they have his seed it's possible for them to use CPFP to resend the funds to their own wallet just before it gets confirmed and if it's a clipboard virus then every time he copied and pasted a receiving address the hackers address was pasted instead. When hackers do things like this they make use of huge fees so before you notice it has already been long confirmed.

Surely this is what happened to him: he downloaded compromised software and the hacker used CPFP through a bot. Because according to him, his sending wallet's funds remained intact, so the compromised one was the receiving wallet. I say it's compromised software because I don't think the user would use a seed suggested by an AI.

Is the seed phrase somehow peculiar?

The seed itself isn't strange; what's strange is that Copilot used it as an example, citing https://everybithelps.io/bip39-wordlist/, but there's no indication of the seed on that page.


██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██



██
██
██
██
██
██
██



██
██
██
██
██



██
██

██
██
██
██
██
██
██
██
██
██
███████▄▄███████▄▄
████▄███████████████▄█████▄▄▄
██▄███████████████████▄▄██▀████▄▄▄▄▄▄▄▄███▄██████
▄███████████████████▀▄█████▄▄███████████▄▀▀▀██▄██
▄███▐███████████████▄▄▀███▀███▄█████████████▄███████
████▐██████████████████▀██▄▀██▐██▄▄▄▄██▀███▀▀███▀▀▀
█████████████████████▌▄▄▄██▐██▐██▀▀▀▀███████████
███████▌█████████▐██████▄▀██▄▀█████████████████████▄
▀██▐███▌█████████▐███▀████████▄██████████▀███████████
▀█▐█████████████████▀▀▀███▀██▀▀▀▀▀▀▀▀▀██▀▀▀███▀▀▀▀▀
██▀███████████████████▀▄██▀
████▀███████████████▀
███████▀▀███████▀▀
██
██


██
██
██
██
██
██
██
██
██

██
██
██


██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
 
    FAST    🔒 SECURE    🛡️ NO KYC        EXCHANGE NOW      
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██

██
██
██
██
██
██


██
██
██
██
██
██
██
██
██
██

██
██
██
██
██
██
██
██
██
██
██
ymgve2
Full Member
***
Offline Offline

Activity: 162
Merit: 230


View Profile
December 07, 2024, 04:08:52 PM
 #6

What's the actual seed phrase? Could be an example used in some github code.
Cricktor
Legendary
*
Offline Offline

Activity: 1470
Merit: 3904



View Profile
December 15, 2024, 12:06:03 PM
Merited by vapourminer (1)
 #7

The thread opener ("TO") in coinforum.de topic refused to answer some questions that arose while the topic was "hot".

Some details were a bit vague, but to me it seems his Electrum wallet software was genuine, so no fake Electrum wallet used. "TO" stated that the compromised receiving address was part of an Electrum wallet he owned. No details were provided how this receiving Electrum wallet was created.

There was no RBF involved, the stealing transactions spent the unconfirmed output(s) of the destination Electrum wallet's address as a CPFP in the same block. It's obvious that the private key(s) of the destination address(es) is/are compromised and known to the thief.

How and why the destination wallet's private key(s) were compromised could not be determined. I can think of many stupid ways of how to compromise a wallet. Most of them gravitate around making digital backups or pictures of your mnemonic seed words, compromised devices and/or using extremely weak or bad entropy or even publicly known mnemonic seed words, how stupid is that!

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!