Bitcoin Forum
May 06, 2024, 11:22:15 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Coinbase.com and Blockchain.info Bitcoin Wallet Phishing Scam Exposed  (Read 1283 times)
bitcomsec (OP)
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile WWW
November 04, 2014, 02:01:35 AM
Last edit: November 04, 2014, 02:20:53 AM by bitcomsec
 #1

Hi all,

My name is Mike and I am with the BITCOMSEC (Bitcoin Community Security) Project and we are a team of dedicated security researchers and developers who take our spare time in doing security research, audits and investigative reports that aim to bring security awareness to the Bitcoin and OSS communities.

Last time we did a report on the CryptoRush.in hack which I think was a major blow to the entire altcoin scene: https://bitcomsec.true.io/bitcomsec/tracking-a-bitcoin-thief-cryptorush-hack/

This week we have done an in depth investigative report into an elaborate and effective Coinbase.com and Blockchain.info based Phishing scam that many of you may have seen throughout the blockchain. It basically involved the use of sending bits of dust to a large number of addresses associated with Coinbase.com/Blockchain.info/BTC-e and other misc wallets.

We studied the phishers methodology, monitored their activity, and discovered their logs of compromised accounts (all the while reporting the compromised accounts/passwords/GUIDs/IPs to Blockchain.info and Coinbase.com). Finally, after exhaustive research we communicated with all of the VPS companies that the phishers used and effectively shut the entire operation down.

You can read all the details, with logs, evidence and screenshots of how we managed to infiltrate the phishing network:

https://bitcomsec.true.io/bitcomsec/coinbase_com-and-blockchain_info-bitcoin-wallet-phishing-scam-exposed/

Thanks all.

And if you'd like to support us check out https://bitcomsec.true.io for our donation address or upvote the following to help spread awareness:

http://www.reddit.com/r/Bitcoin/comments/2l7tk1/coinbasecom_and_blockchaininfo_bitcoin_wallet/
https://news.ycombinator.com/item?id=8554708

Regards,
Mike

EDIT: Typos
1714994535
Hero Member
*
Offline Offline

Posts: 1714994535

View Profile Personal Message (Offline)

Ignore
1714994535
Reply with quote  #2

1714994535
Report to moderator
1714994535
Hero Member
*
Offline Offline

Posts: 1714994535

View Profile Personal Message (Offline)

Ignore
1714994535
Reply with quote  #2

1714994535
Report to moderator
TalkImg was created especially for hosting images on bitcointalk.org: try it next time you want to post an image
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Maged
Legendary
*
Offline Offline

Activity: 1204
Merit: 1015


View Profile
November 04, 2014, 02:14:23 AM
 #2

Good on 'ya for immediately bringing this to the attention of those services. When it comes to this kind of issue, time is of the essence. Everyone did a great job of handling this!

bitcomsec (OP)
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile WWW
November 04, 2014, 02:23:08 AM
 #3

Good on 'ya for immediately bringing this to the attention of those services. When it comes to this kind of issue, time is of the essence. Everyone did a great job of handling this!

Thank you so much for the kind words. We hope by doing these reports, and shutting down these operations people will break out of the apathy in regards to Bitcoin thefts and begin pursuing it more often than not.

A bit shout out to BitcoinVPS and Apexy.com for shutting down the phishers networks. Also a shout out to Blockchain.info staff for working with us and quickly handling the information we were able to provide them as we followed the phishers from server to server.

reg.ru/2domains.ru however is blatantly accepting of this behavior and have ignored my emails regarding the attackers use of their domain registrar and VPS servers for the scams.
H.W.Z
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
November 04, 2014, 02:06:11 PM
 #4

Well done. Once issues come out, the ppl in this great community will stand up to fight against these type of phishing scams or other scams.

Piston Honda
Legendary
*
Offline Offline

Activity: 2702
Merit: 1064


Juicin' crypto


View Profile
November 04, 2014, 03:41:45 PM
 #5

Wow, you'd would have thought (or hoped) that larger legit sites like this wouldn't be pulling this sort of thing...disturbing.

$ADK ~ watch & learn...
BittBurger
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1001


View Profile
November 04, 2014, 03:59:15 PM
 #6

Is Changetip supported on this forum software?

Is anything supported on this forum software?

-B-

Owner: "The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
View it on the Blockchain | Genesis Block Newspaper Copies
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!