[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance

View post   

File: 136 KB, 1280x825, photo_2020-09-23_00-34-03.jpg [View same] [iqdb] [saucenao] [google]
22742536 No.22742536 [Reply] [Original]


This guy's transferring small fractions of eth into seemingly random wallets and then completely draining them of their ethereum but leaving all the other tokens. Any idea what exploit he's using to get into people's wallets, or how to guard against the vulnerability? I can't find any sort of common thread between the cracked wallets

>> No.22742599


>> No.22742649


>> No.22742660

He just sent eth to his other wallets to sell UNI

>> No.22742689

scratch that i can find one commonality and it's the UNI token, all the wallets have had all their UNI swapped for eth before they get drained.

>> No.22742749

no because one of "his" other wallets was my fuckin wallet lol and all my eth is gone

>> No.22742789

Give us more details, Sir.

- hardware wallet?
- was there ETH in it before the bot added some?
- Did you try to trade on Uni in the last days?
- OS?

>> No.22742817

Totally unrelated but I am a fucking noob and I want to claim some tokens from an airdrop. I got the contract address what the fuck do I do?

>> No.22742884

-no (but im getting one now lmao)
-yes but he didnt add any to mine, im guessing the ones he sends the .1 eth to is gas money for empty wallets with UNI in them
-yes but some of the wallets have been inactive for 30+days, most of them relatively low balance (<5 eth, roughly the balance of 400uni, hmmm)

>> No.22742917

what wallet were you using

>> No.22742929


>> No.22742949

lmao wtf did you go on any dodgy websites?

>> No.22742957


>> No.22742983

plus look at all the different wallets he's hit, it's a lot for it to be a malware attack isnt it?

>> No.22743000

metamask is fucking unsafe
who the fuck would use a online browser plug in wallet
even worse to trade defi scam tokens for 40 bucks per transaction

>> No.22743032

He got phished. be more careful next time. When you go to uniswap make god damn sure it's uniswap. Get an adblocker. Get 2 ad blockers. It's fucking 2020

>> No.22743071

Unlikely. How did the guy phish inactive wallets lmao. This is clearly an exploit of some sort.

>> No.22743176

i've got adblock and i use the correct address for uniswap lmao. they're leaving sometimes thousands worth of altcoins and just swapping the uni and cleaning out the eth. if it was phishing why not swap everything, and like the other anon said how are they getting wallets that haven't been touched recently

>> No.22743254

It mines Safex for the great uprising of 2021.

>> No.22743285

Are all ur coins gone or just the eth?

>> No.22743344

just eth, i had already swapped my uni and spent the eth on other erc20 tokens which werent touched. other wallets are having their uni swapped immediately before the eth is emptied into the bot wallet, but likewise all their other tokens are untouched

>> No.22743385

check'em also you can check the etherscan link in the op for yourself if you're curious, open a couple of the addresses that the eth is coming in from. uni swapped, eth taken, other coins left

>> No.22743399

yeah you probably got phished or some shit

>> No.22743431

Damn, funds are really not safu. But I'm wondering how it could be Metamask's fault. Where you save your private keys/seed?

>> No.22743449

He is just claiming uni u larping nigg

>> No.22743455

Still waking up lmao

>> No.22743477

a piece of paper in my desk drawer
from MY wallet? no.

>> No.22743497

check the etherscan the first transaction on the wallet was 2 days ago and he's "claimed" 150k usd worth of fuckin uni lol teach me how to do that

>> No.22743525

Have you connected metamask to ANY sites other than uniswap? List everything you have connected to

>> No.22743537

what projects, smart contracts have you interacted with in the last 2 months?

>> No.22743541

It is safe with a hardware wallet only

>> No.22743542

kye.fi lol that's literally it

>> No.22743569

phished keys is the most reasonable explanation, the address thats recieving the eth is just an address not a contract.

>> No.22743572

just get to uniswap.org/swap and hit claim button

>> No.22743574

First transaction has fake adress id wtf https://etherscan.io/tx/0x6cb74d0fc3f678397523ac20f6ef24d42dd64b9c8ff58830291d891cc172794b

>> No.22743587


How is it possible to drain the metamask wallets without notifying their respective users to approve the transaction, and then to approve the swap?

>> No.22743594

nothing really that far out there. xmm, pnk, undb, kye, uni. some dumb trades and memecoins but nothing abhorrently sketchy

>> No.22743609
File: 39 KB, 1243x358, bot1.png [View same] [iqdb] [saucenao] [google]

i'll post caps of the most recent 5, the bots claiming uni on untouched wallets approving it swapping it and transferring the eth balance

>> No.22743632
File: 49 KB, 1235x422, bot2.png [View same] [iqdb] [saucenao] [google]


>> No.22743642
File: 39 KB, 1247x365, bot3.png [View same] [iqdb] [saucenao] [google]


>> No.22743655

just an owner of multiple wallets anon, post your wallet let's laugh at you

>> No.22743656
File: 38 KB, 1240x366, bot4.png [View same] [iqdb] [saucenao] [google]


>> No.22743716

Anyone know something about this? Can you post it on reddit or somewhere where people might figure it out?

>> No.22743771
File: 37 KB, 1229x357, bot5.png [View same] [iqdb] [saucenao] [google]

beating a dead horse i shoulda just gone with 3 and you'd get the point lol, but
>dead wallet
>gas in
>claim uni approve uni swap uni
>transfer eth balance

>> No.22743778

>might figure it out
anon it's either owner of multiple wallets or idiots getting into fake claim website, i saw one, it unironically asks you your PRIVATE key, then it just calls claim on distribution contract, then it dumps claimed uni on uniswap, then it sends tokens to phisher address
did OP posted private key somewhere? If he didn't then yeah, it might be metamask vulnerability

>> No.22743803

it could be "dead" wallet but not the dead users getting into phishing website to "claim", anon
tell us how you claimed your uni

>> No.22743828

didn't share private key anywhere, i might post on biz but i'm not a complete room temp iq retard lol

>> No.22743834

OP said it took his ETH though. Also why didn't it take all his ERC20 and just his ETH? Definitely might be useful to have more people looking at this.

>> No.22743841

but again if it was MM vulnerability then it would hit not just UNI holders

>> No.22743861

i went on uniswap and claimed it like everybody else lol

>> No.22743885

If it were a uniswap copycat phish, and you wanted to automate it, wouldn’t you program the script to just send eth, claim, swap, send.

Seems easier to get up and running than something that tries to send/swap a list of erc20 coins as well.

>> No.22743907

>might figure it out

>> No.22743915

yeah exactly
OP try remembering when you went to claim your uni and check the browser history on that date for suspicious URLs

>> No.22743919

for >>22743716

>> No.22743979

Im curious about something like this too

>see wallet i recognize send small amount of eth to another address
>the wallet they sent to transfers it to another wallet
>that wallet has a large $ in a single coin
>none of these transactions are interacting with a contract

>> No.22744053

nothing that stands out, lotta etherscan, youtube, twitter, medium. kye.fi which i connected my metamask to, but that's not a commonality with the other wallets

>> No.22744136

I cannot imagine this being some kind of metamask exploit. My guess is, someone took the UNI distribution as an occasion to go through their phishing logs and your keys have been in there.
However by the timestamps it doesn't look scripted to me, as it's done over hours and days. Seems like someone's working on it.

OP, you got your keys stored on your machine in cleartext? Or restored MetaMask with them recently? Any way they could have stolen your key?

>> No.22744152


What interactions with smart contracts have you had recently?

>> No.22744193

not unless they got me with a keylogger or some other malware but i can't imagine when/where they would've, the seed phrase and password are only stored on a piece of paper in my desk. haven't had to restore metamask at all that i can remember.

>> No.22744208

THIS is why you get yourself a hardware wallet as soon as you get a sizable stack of anything
Something similar happened to me, some dude somehow got into my wallet and took all my YFV

>> No.22744310

yeah lesson learned it's in the mail

uni v2 kye/xmm/undb/pnk/uni

>> No.22744315

This is really bad ain't it

>> No.22744322

usdc and byfi

>> No.22744372

post your address

>> No.22744392

i'd rather not until I can get the rest of my tokens onto a hardware wallet

>> No.22744423

Jist saying, there are probably leet hackers out there that can take advantage of smart contract coding flaws. We have yet to see anything like injections and whatnot. This is still early.

>> No.22744449

Its someone doing it manually. theres like 8 hour breaks, so it would seem they need to sleep or work

>> No.22744458

there is some weird shit going on with people having their shit stolen on metamask.

either it's a bunch of newfags being dumb or metamask has some holes.

>> No.22744496

Could it simply be that OPs password were bruteforced? Seems like the simplest answer

>> No.22744502

in the comments of one tx someone claims

>> No.22744559

could be but there's like 100 or more unique wallets in this guy's transaction history, wouldn't that take a huge amount of time to brute force all of them?

>> No.22744571

Do hw wallets only sign txs, not export the pk. Then is that why it’s specifically a metamask issue, cause otherwise it might be an exploit with uniswap

>> No.22744599

All this crypto stuff is based on the assumption that neither private keys nor proper passwords can be bruteforced. No.

If its malware related, it would have been easy to keylog the password or extract the unencrypted key from memory, when it was unlocked by the user. However that does not explain why there is a lot of 'dead' or inactive wallets in there, which seem like they haven't been unlocked recently.

>> No.22744632

Thats my point. Maybe OP didnt have a proper password

>> No.22744646

did you use twitter on your PC?

>> No.22744717

it was unique and made of a couple words no spaces few numbers and a punctuation mark, idk

i check some project devs twitters, but not the one that comment was posted on. didn't click any weird links on anyone's twitter either.

>> No.22745183
File: 36 KB, 734x506, 336650B9-4C94-4454-9275-CBF79C00635D.jpg [View same] [iqdb] [saucenao] [google]

sorry for your loss OP

>> No.22745566

He was standing behind you when you entered your password

>> No.22745798

OP how many ETH did he take from you? 4-5?
Did you have them because you sold UNI, did you ever possess UNI or did he sell your UNI?

>> No.22745933
File: 1.55 MB, 450x506, Pinky Dancing.gif [View same] [iqdb] [saucenao] [google]

I remain convinced you got phished. I'm sorry anon that's just how it be. They really do shit like take ads out on google/bing/etc. and bump their page to the top of the list. You click it because you think "oh it's uniswap, google wouldn't lie" and bam you go to a front end that looks exactly like Uni and you claim and you get fucked.

It happens all the time. Also the evidence you are posting
reeks of a phishing scam.
These wallets were untouched until they realized they had Uni in them. The owner went to google/bing, searched uni, got phished, game over.

Maybe I'm wrong and someone really has cracked MetaMask, but every time this happens it's proven that the owner got phished or leaked his private keys.

Show us your browser history.

It's because those are bait wallets for scrapers.

You might as well show us your address, it's compromised. If you showed us your address on etherscan then we can likely pinpoint where you got jacked if you interacted with a malicious contract.

>> No.22745971

would it be possible that claiming the tokens is insecure? maybe the free uni were given out to fish

>> No.22746083

There's no way claiming tokens from uniswap could expose your private keys, unless there was some flaw with uniswap. If there was, then it would have been exploited so far. What I'm thinking is the thief went manually checking addresses that haven't moved/claimed their uni, and somehow found their private keys online: https://medium.com/@parzival.is.sweet/hacking-uniswaps-uni-airdrop-434543b37d9a
I'm thinking OP's seed was somehow leaked somewhere and the guy managed to find it by doing some advanced google search of his address.

>> No.22746453

Im doing advanced google searches of your mothers pussy

>> No.22746549

That's no way to talk about Grandma, son.