Bitcoin Forum
June 03, 2024, 02:00:40 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: BEWARE OF FAKE WALLETS! Look carefully where you download from!  (Read 1148 times)
altcoin.center (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 101


View Profile WWW
January 24, 2015, 03:20:18 AM
Last edit: January 24, 2015, 03:56:36 AM by altcoin.center
 #1

Dear crypto community,

it has come to our attention that several crypto currency projects have been targeted with fake, trojaned coin-stealing wallets.

Someone or someones has/have compiled their own "fixed" version of the wallets, based on the original source code but building in couple of nasty features.

The fake wallets have installed a remote access backdoor to the PC they've been ran on.

In addition to that, they've also sent user's funds to attacker's addresses.

This far only Windows versions have been seen, but it would be stupid to assume fake Linux and Mac OS X wallets would not pop up eventually.

Altcoin.Center is working with the Finnish hard core anti-malware company F-Secure to come up with solutions to the problem.

F-Secure's anti-virus programs already detect the first trojaned wallet we found. If any new cases turn up, we would be very grateful to have samples of them available ASAP. In fact we're so keen to having new fake wallets analyzed right away that we offer a bounty: a fully free license of F-Secure Safe (1 year, 3 devices, value 59.95 €) for anyone who provides us with a previously unknown/undetected fake malware wallet.

Altcoin.Center is also looking into different ways of providing proof of wallet authenticity through a fully distributed process. Until that process is ready and usable, we'll bring in some temporary assistance by, for example, announcing valid wallet checksums (MD5 and SHA1) through our DNS system. Eventually, our goal is to create a P2P based trust solution that heavily uses PGP to do things such as sign all the blocks, sign other wallet's pgp keys, check file trust level using pgp signatures, and so forth.

We'll also be providing thorough yet easy to follow instructions on how to seriously harden the security of any Windows, Mac OS X or Linux machine. We have decades of experience of secure systems design in the company, and intend to share that information with everyone free of charge and free to use.

Remember: Always carefully check where you download your crypto wallets from! Always use only the download addresses announced by each crypto project's official developer(s). Beware forum posts with quotes - the links inside the quotes may have been altered.

The malware infected wallet phenomena appears to be rather new, and will in my educated guesstimate grow into a significant problem with nastier built-in "features" added to the wallets and more clever means crafted to make users fall into installing them.

Stay awake - no fear! Wink

- Jyri
--
Altcoin.Center

P.S. Serious anti-malware software is an unavoidable must these days. Altcoin.Center CryptoShop gives a 10% discount of F-Secure Safe and the Zemana AntiLogger for the BCT community members. Safe and AntiLogger play together beautifully, giving a very strong protection against all forms of malware attacks, including fake wallets. We accept Bitcoin, BitQuark, CannabisCoin, DarkCoin, Dogecoin, FreiCoin, GroestlCoin, GuldenCoin, IOCoin, LemurCoin, LimeCoinX, LiteCoin, MazaCoin, OpalCoin, SativaCoin, SecurityCoin, StartCoin, Syscoin and VidioShare. Just apply the coupon code SECURITY in your shopping cart and the 10% discount will be redacted from the final sum. There is only a limited number of licenses available. https://cryptoshop.altcoin.center/index.php?route=product/category&path=59

Altcoin.Center - Hard Core Crypto Professionals: https://altcoin.center/
Ridiculously Secure - The Ultimate Crypto Wallet Vault: https://altcoin.center/ridiculous/
Crypto Shop: Only the highest quality - only with cryptos! https://cryptoshop.altcoin.center/
Piston Honda
Legendary
*
Offline Offline

Activity: 2702
Merit: 1064


Juicin' crypto


View Profile
January 24, 2015, 04:03:15 AM
 #2

bitbay had a link with fake/hacker wallet it within their original thread.  no idea who posted it or if it's still there.  to those that do this...i hope you die a slow and painful death.

$ADK ~ watch & learn...
altcoin.center (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 101


View Profile WWW
January 24, 2015, 04:12:36 AM
 #3

bitbay had a link with fake/hacker wallet it within their original thread.  no idea who posted it or if it's still there.  to those that do this...i hope you die a slow and painful death.

Yeah, unfortunately it's not guaranteed that the posts are genuine either.

As irritating as it is that some actually do this kind of crap, it's after all good to have the problem solved anyways. If it wasn't coin-stealing punks then it would be organized crime, governmental agencies or someone else alike. To fight any and all fake wallet based attacks against cryptos and their users, some form(s) of new trust systems need to be created. Centralized approach would be easy, but developing a truly working and fully P2P version may take a while. PGP and asymmetric crypto in general can fortunately be applied to different proof of trust kind of issues rather easily.

- Jyri
--
Altcoin.Center

Altcoin.Center - Hard Core Crypto Professionals: https://altcoin.center/
Ridiculously Secure - The Ultimate Crypto Wallet Vault: https://altcoin.center/ridiculous/
Crypto Shop: Only the highest quality - only with cryptos! https://cryptoshop.altcoin.center/
Quartx
Hero Member
*****
Offline Offline

Activity: 1036
Merit: 504


Becoming legend, but I took merit to the knee :(


View Profile WWW
January 24, 2015, 04:17:32 AM
 #4

And thats precisely why I dont immediately download every new altcoin wallet that is compiled beforehand, I only ever compile from source and thats after briefing going through the code too

altcoin.center (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 101


View Profile WWW
January 24, 2015, 04:24:14 AM
 #5

And thats precisely why I dont immediately download every new altcoin wallet that is compiled beforehand, I only ever compile from source and thats after briefing going through the code too

Indeed!

- Jyri
--
Altcoin.Center

Altcoin.Center - Hard Core Crypto Professionals: https://altcoin.center/
Ridiculously Secure - The Ultimate Crypto Wallet Vault: https://altcoin.center/ridiculous/
Crypto Shop: Only the highest quality - only with cryptos! https://cryptoshop.altcoin.center/
twister
Hero Member
*****
Offline Offline

Activity: 672
Merit: 502



View Profile WWW
January 24, 2015, 07:03:49 AM
 #6

And thats precisely why I dont immediately download every new altcoin wallet that is compiled beforehand, I only ever compile from source and thats after briefing going through the code too

But all users are not apt to do this so maybe it's best if you must download use a virtual machine and keep anything related to bitcoin or important data elsewhere.

 

██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
 
Get Free Bitcoin Now!
  ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦    ¦¯¦¦¯¦   
0.8%-1% House Edge
[/
Quartx
Hero Member
*****
Offline Offline

Activity: 1036
Merit: 504


Becoming legend, but I took merit to the knee :(


View Profile WWW
January 24, 2015, 07:07:08 AM
 #7

And thats precisely why I dont immediately download every new altcoin wallet that is compiled beforehand, I only ever compile from source and thats after briefing going through the code too

But all users are not apt to do this so maybe it's best if you must download use a virtual machine and keep anything related to bitcoin or important data elsewhere.

Than again not everyone knows how to enable VT in bios, or use VMWare Player or VirtualBox hahas, probably why some newbies get tricked into installing trojans all the time

altcoin.center (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 101


View Profile WWW
January 24, 2015, 01:50:11 PM
 #8

And thats precisely why I dont immediately download every new altcoin wallet that is compiled beforehand, I only ever compile from source and thats after briefing going through the code too

But all users are not apt to do this so maybe it's best if you must download use a virtual machine and keep anything related to bitcoin or important data elsewhere.

Exactly. In the long run, easy and trustworthy solutions are needed if cryptos are to become mainstream.

- Jyri
--
Altcoin.Center

Altcoin.Center - Hard Core Crypto Professionals: https://altcoin.center/
Ridiculously Secure - The Ultimate Crypto Wallet Vault: https://altcoin.center/ridiculous/
Crypto Shop: Only the highest quality - only with cryptos! https://cryptoshop.altcoin.center/
Piston Honda
Legendary
*
Offline Offline

Activity: 2702
Merit: 1064


Juicin' crypto


View Profile
January 26, 2015, 01:47:07 PM
 #9

so true.  good post OP. i got burned before.

bitbay had one in its original link.  im not sure who posted it.

$ADK ~ watch & learn...
Ingramtg
Legendary
*
Offline Offline

Activity: 861
Merit: 1000



View Profile
January 26, 2015, 02:56:53 PM
 #10

I usually do not download the client's wallet, because takes up too much computer memory
The more convenient online wallet
biggus dickus
Sr. Member
****
Offline Offline

Activity: 310
Merit: 250


View Profile
January 27, 2015, 12:23:23 AM
 #11

If you decide to download and install a wallet always use a download link from a post by the dev. Never use a link in a post by someone else quoting the dev's post.
billotronic
Legendary
*
Offline Offline

Activity: 1610
Merit: 1000


Crackpot Idealist


View Profile
January 27, 2015, 01:55:06 AM
 #12

lol this post is HIGHlarious!

1. if you want to sell a/v software, just say so. save me the waste of time of reading your commercial

2. pushing third party software to protect people from themselves is not really a solution. if you want to help people, you should write a detailed and easy to follow guide on compiling wallets from source.

3. "The malware infected wallet phenomena appears to be rather new," yeah sure bud.

This post sums up why all this bullshit is a scam
Read It. Hate It. Change the facts that it represents.
https://bitcointalk.org/index.php?topic=1606638.msg16139644#msg16139644
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!