allcrypt
|
|
June 18, 2014, 04:56:49 PM |
|
ouch. I committed a sin, I used the same user/password for Allcrypt and Bittrex without 2FA. Just woke up today June 18 to find both accounts drained of JPC and BTC.
For reference, the unauthorized user first turns off all alert settings, then withdraws via Allcrypt 0.16650878 BTC to 1MGHKXe7WFdKb8DmnTCQaXAM1gK2HToTg2 899999.99999977 JPC to JXrUjsULGLePz9CXbkGbgd5X2Ln7L6PiWC
On Bittrex, the unauthorized user utilizes my account to buy HIGH and sell LOW against a low volume market (ITC/BTC) to capture gains without even making a withdrawal. Traceable only if the admin of Bittrex is able to capture the counterparty buyer when my account sells ridiculously low, and counterparty seller when my account buys obscenely high.
Very savvy culprits these days. I'm irritated but quite impressed that the days of "using a cryptic and long password" are no longer relevant.
Just saw this. Never saw a support ticket. I'll check the logs ASAP and get back to you.
|
|
|
|
Spoetnik
Legendary
Offline
Activity: 1540
Merit: 1011
FUD Philanthropist™
|
|
June 18, 2014, 06:25:30 PM |
|
If you don't have a smart phone then just get an old old ipod touch for like $50 They are very cheap these days. And stick with Apple instead of Android. Too much Malware on the Google Play store. There's not enough money and gold in the known universe that you could pay me to use an Apple product... Bleh! iphone are leaders in the current market oni 3 things, small screens with low res, small battery (non-removable ofc, just like their macbook pro) AND high price. Is your name Maddox? http://www.thebestpageintheuniverse.net/c.cgi?u=iphonethat is awesome he's my kinda guy and that story is truth ! also i have an old buddy i had not talked too for ages with that name i wonder if that is him ? hmmm
|
FUD first & ask questions later™
|
|
|
Spoetnik
Legendary
Offline
Activity: 1540
Merit: 1011
FUD Philanthropist™
|
|
June 18, 2014, 06:33:51 PM |
|
The first Anonymous Pool for JackpotCoinhttp://dwarfpool.com/jpc * Highly developed project without registration* Autopayouts from 1000 JPC once an hour * True round based PPS (proportional your shares) 1% fee forever for members who will come within next 3 days! From Friday 20.07 fee increases to 2% * No transaction fee * Jackpot Reward will be split 50/50 between block finder and other members in the winning round * 100% failover-infrastructure uptime * DDoS protection by different providers * Free choice of 2 dedicated server locations worldwide. To ensure 100% uptime, put the other servers as backup * Separate workers with the same wallet-id for better vardiff and detailed per rig statistics * Monitoring of every rig via email * Greatly optimized stratum pool engine. Not P2Pool! * Maxmimum transparency, no stealing shares, no hidden fees! * "Fake shares" Attack resistant!* Vardiff 16-1024 * Exellent Support 24/7 in english, pyccкий, deutsch more features coming soon http://dwarfpool.com/jpcDwarfPool German quality you can trust! i find a lot of that bullshit and i am curious do you have one example you can PROVE of a fake share being submitted to a pool in the last year ? what proves do you expect, logs, IPs? )) I just like to say you are happy not to know what it is .. you can't imagine what a great work stands behind a reliable self-developed pool! uhh what the fuck was that ? i pointed out how your statement is a wall of shit lol show me on example in the last year of a fake share being submitted to a pool.. any coin and any pool What you claim is not possible So your reasons for coming to the pool is dishonest making claims that are bullshit. lol Since you didn't get what i said i will point out also how i agree with the guy earlier about being the first anonymous pool.. i could go on but i have been trying to be nice.. Claiming you are protecting people from a danger that does not exist is sleazy..
|
FUD first & ask questions later™
|
|
|
Spoetnik
Legendary
Offline
Activity: 1540
Merit: 1011
FUD Philanthropist™
|
|
June 18, 2014, 06:38:28 PM |
|
i wouldn't pay much attention to the numbers they are made up lol
|
FUD first & ask questions later™
|
|
|
Spoetnik
Legendary
Offline
Activity: 1540
Merit: 1011
FUD Philanthropist™
|
|
June 18, 2014, 06:42:43 PM |
|
No, because the net hashrate is no reported correctly by the wallet, it's actually much more like 35GH/s. says who ? prove it.. if this is true i want the dev to admit it.. i've been over this dozens of times.. if it is true then he should do something to make it more accurate then because it creates a lot of false data and confusion AND would be a major aspect of the coin that is broken bad. Yet he has seen us talk about it a dozen times and i pointed out a dozen times why i think it IS correct and he never said a word once.. hmm my cpu miner has my name and the coin dev in the credits.. we both worked on the hashing algo code and you guys did what again ? lol so i guess just ignore me what do i know ;)
|
FUD first & ask questions later™
|
|
|
|
adaseb
Legendary
Offline
Activity: 3878
Merit: 1733
|
|
June 18, 2014, 07:30:16 PM |
|
ouch. I committed a sin, I used the same user/password for Allcrypt and Bittrex without 2FA. Just woke up today June 18 to find both accounts drained of JPC and BTC.
For reference, the unauthorized user first turns off all alert settings, then withdraws via Allcrypt 0.16650878 BTC to 1MGHKXe7WFdKb8DmnTCQaXAM1gK2HToTg2 899999.99999977 JPC to JXrUjsULGLePz9CXbkGbgd5X2Ln7L6PiWC
On Bittrex, the unauthorized user utilizes my account to buy HIGH and sell LOW against a low volume market (ITC/BTC) to capture gains without even making a withdrawal. Traceable only if the admin of Bittrex is able to capture the counterparty buyer when my account sells ridiculously low, and counterparty seller when my account buys obscenely high.
Very savvy culprits these days. I'm irritated but quite impressed that the days of "using a cryptic and long password" are no longer relevant.
Besides these 2 exchanges where else did you use the same password? Maybe AllCrypt has a security issue somewhere? Something like Hearbleed? This is getting ridiculous.
|
|
|
|
allcrypt
|
|
June 18, 2014, 07:45:19 PM |
|
We patched heartbleed back in April when it was announced.
If the password was used on 2 sites I'd wager a fair amount it was used virtually everywhere. You either practice good password security or you don't.
Still haven't heard back from the user. We don't know his username to even begin to look. Not sure why someone gets hacked and does NOT contact the exchange. The same thing happened with the bittrex JPC 100mil hack. I spoke to the bittrex admin. He said that he still hadn't been contacted by the user.
|
|
|
|
djm34
Legendary
Offline
Activity: 1400
Merit: 1050
|
|
June 18, 2014, 07:48:34 PM |
|
We patched heartbleed back in April when it was announced.
If the password was used on 2 sites I'd wager a fair amount it was used virtually everywhere. You either practice good password security or you don't.
Still haven't heard back from the user. We don't know his username to even begin to look. Not sure why someone gets hacked and does NOT contact the exchange. The same thing happened with the bittrex JPC 100mil hack. I spoke to the bittrex admin. He said that he still hadn't been contacted by the user.
may-be nobody was hacked, just someone who wanted to sell his large stack and prefered to say it was a hacker if the price is going down rather than admitting it was him cashing out...
|
djm34 facebook pageBTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
|
|
|
shutopia
Newbie
Offline
Activity: 5
Merit: 0
|
|
June 18, 2014, 08:03:38 PM |
|
@Allcrypt, I reported the unauthorized access, a bit late though. Sorry, I just got around to submitting a trouble ticket with withdrawal details. I'm sure you'll spot the two withdrawals within your history log. Not sure what provisions you have in place for handling these issues. I'd love to know what is possible.
@djm34, not a bad way to read the situation.
@adaseb, only two sites. I was careless to share it on two exchange sites. I use different pw combos on larger exchange accounts so am confident that these were the only two. I don't believe Allcrypt and Bittrex account passwords would be that easy to compromise. The recent wave (June 10-18) of hacks we're witnessing around the community must be related in some way.
@Amph, my malwarebytes is active. Scans do not return keylogger trojans. Has not for months. Then again, I wouldn't rule it out. With a keylogger, you'd think they would go after actual wallets instead of an exchange account with < 0.5BTC. But I suppose 100x small exchange accounts would be a prize worth going after.
|
|
|
|
Amph
Legendary
Offline
Activity: 3248
Merit: 1070
|
|
June 18, 2014, 08:08:59 PM |
|
@Amph, my malwarebytes is active. Scans do not return keylogger trojans. Has not for months. Then again, I wouldn't rule it out. With a keylogger, you'd think they would go after actual wallets instead of an exchange account with < 0.5BTC. But I suppose 100x small exchange accounts would be a prize worth going after.
it could just be a keylogger/screenlogger ecc... without being also a wallet stealer
|
|
|
|
adaseb
Legendary
Offline
Activity: 3878
Merit: 1733
|
|
June 18, 2014, 08:14:48 PM |
|
So what is a recommended virus scanner/ spyware scanner?
I use 5 at once and sometimes I think its not enough.
|
|
|
|
Amph
Legendary
Offline
Activity: 3248
Merit: 1070
|
|
June 18, 2014, 08:19:13 PM |
|
So what is a recommended virus scanner/ spyware scanner?
I use 5 at once and sometimes I think its not enough.
i just use hitmanpro + malwarebyte last version and virus total plus checking every folder/connection activity from time to time some chinese tried to take on my account on mintpal, received warning from there no success for him, also someone tried to rob my gmail, but i have 2fa via sms on a normal phone, unbreakable
|
|
|
|
trotter55
Member
Offline
Activity: 65
Merit: 10
|
|
June 18, 2014, 08:24:23 PM |
|
So what is a recommended virus scanner/ spyware scanner?
I use 5 at once and sometimes I think its not enough.
I check every wallet I download with virustotal online scanner before installing anything. Virustotal runs a file through 50+ of the most popular virus scanners. https://www.virustotal.com/
|
|
|
|
minimila
Member
Offline
Activity: 84
Merit: 10
|
|
June 18, 2014, 08:26:53 PM |
|
The first Anonymous Pool for JackpotCoinhttp://dwarfpool.com/jpc * Highly developed project without registration* Autopayouts from 1000 JPC once an hour * True round based PPS (proportional your shares) 1% fee forever for members who will come within next 3 days! From Friday 20.07 fee increases to 2% * No transaction fee * Jackpot Reward will be split 50/50 between block finder and other members in the winning round * 100% failover-infrastructure uptime * DDoS protection by different providers * Free choice of 2 dedicated server locations worldwide. To ensure 100% uptime, put the other servers as backup * Separate workers with the same wallet-id for better vardiff and detailed per rig statistics * Monitoring of every rig via email * Greatly optimized stratum pool engine. Not P2Pool! * Maxmimum transparency, no stealing shares, no hidden fees! * "Fake shares" Attack resistant!* Vardiff 16-1024 * Exellent Support 24/7 in english, pyccкий, deutsch more features coming soon http://dwarfpool.com/jpcDwarfPool German quality you can trust! i find a lot of that bullshit and i am curious do you have one example you can PROVE of a fake share being submitted to a pool in the last year ? what proves do you expect, logs, IPs? )) I just like to say you are happy not to know what it is .. you can't imagine what a great work stands behind a reliable self-developed pool! uhh what the fuck was that ? i pointed out how your statement is a wall of shit lol show me on example in the last year of a fake share being submitted to a pool.. any coin and any pool What you claim is not possible So your reasons for coming to the pool is dishonest making claims that are bullshit. lol Since you didn't get what i said i will point out also how i agree with the guy earlier about being the first anonymous pool.. i could go on but i have been trying to be nice.. Claiming you are protecting people from a danger that does not exist is sleazy.. calm down with your accusation. the same here I tried to be polite PMing you, but apparently some people who don't want to, don't also hear something around themselves, so what sense to prove anything to death? not to notice, there is still one more pool with no registration, is not a lie. NO ONE can accuse me or pool of dishonesty! that just mean you never worked with dwarves before.
|
|
|
|
e6ug
|
|
June 18, 2014, 08:43:16 PM |
|
dwarfpool is awesome. mining some good coins
|
|
|
|
kebabman
|
|
June 18, 2014, 08:49:38 PM |
|
Come on now, I like Dwarves and all, but Hash@Me is clearly better...bro! No, because the net hashrate is no reported correctly by the wallet, it's actually much more like 35GH/s. says who ? prove it.. if this is true i want the dev to admit it.. i've been over this dozens of times.. if it is true then he should do something to make it more accurate then because it creates a lot of false data and confusion AND would be a major aspect of the coin that is broken bad. Yet he has seen us talk about it a dozen times and i pointed out a dozen times why i think it IS correct and he never said a word once.. hmm my cpu miner has my name and the coin dev in the credits.. we both worked on the hashing algo code and you guys did what again ? lol so i guess just ignore me what do i know Oh man Spoetnik we'd been doing so good, you hadn't taken issue with any of my posts until this one (quite an achievment ). Anyway, the way I worked it out was pretty basic....take Hash@Me + miningpoolhub + cloudminers + minepit + hasharder + dwarfpool = ~30MH + ~5MH for solo mining. It was a guestimate, but I don't know a more accurate way. The pools take their net hashrate from http://explorer.jackpotcoin.info/stats/ but it's clearly wrong because if you add up the pools hashrate, which is one thing that's fairly accurate, it's higher than the net hashrate reported. So, basically I agree with you, the dev needs to fix the incorrectly reported net hashrate.
|
|
|
|
ltcnim
Legendary
Offline
Activity: 914
Merit: 1001
|
|
June 18, 2014, 08:51:08 PM |
|
dwarfpool is awesome. mining some good coins yepp, I like how everything is visible on the first look. The only thing missing for JPC would be to display the current jackpot also on the site with the personal data, and not only on the main site.
|
|
|
|
Spoetnik
Legendary
Offline
Activity: 1540
Merit: 1011
FUD Philanthropist™
|
|
June 18, 2014, 08:55:44 PM |
|
We patched heartbleed back in April when it was announced.
If the password was used on 2 sites I'd wager a fair amount it was used virtually everywhere. You either practice good password security or you don't.
Still haven't heard back from the user. We don't know his username to even begin to look. Not sure why someone gets hacked and does NOT contact the exchange. The same thing happened with the bittrex JPC 100mil hack. I spoke to the bittrex admin. He said that he still hadn't been contacted by the user.
yeah that so called Bittrex hack was fishy from the second i heard it.. a lot don't make any sense with that
|
FUD first & ask questions later™
|
|
|
kebabman
|
|
June 18, 2014, 09:02:28 PM |
|
dwarfpool is awesome. mining some good coins yepp, I like how everything is visible on the first look. The only thing missing for JPC would be to display the current jackpot also on the site with the personal data, and not only on the main site. No offense to dwarpool and all that but it seems pretty ugly on the information frony, and the fact you just provide a JPC address vs registering a username with workers makes looking at your stats pretty difficult. I don't get how that is 'visible on the first look'? Example; the jackpot block was hit in round X....tell me how you see how many shares you had in that round and therefore how much of the jackpot you are entitled to? Also, what's the pool efficiency? How many rejects did you workers have? There are pro's and con's to both approaches, but I prefer the more detailed historical statistics available from a registration pool personally.
|
|
|
|
|