[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 65 KB, 285x276, click me.png [View same] [iqdb] [saucenao] [google]
8927681 No.8927681 [Reply] [Original]

i was hacked gg /biz/
this guy got all of my 33 000 REQ
https://etherscan.io/address/0x1ae4df1b75513179f383bc9845450fd76fcf640f

is there anything at all to do? some people filed a police report and said they contacted binance and kraken
kraken already launched an investigation apparently
i dont even have any idea how thats possible i got a MEW paperwallet and didnt even log into it to check my balance i just checked on ethscan
jesus fucking christ i hate this life

>> No.8927692

I feel for you anon.

But i cant emphasize this enough. BUY A FUCKING LEDGER.

>> No.8927704

>>8927692
the sad part is i got one a few days ago and just today realized this all happened 20 days ago

>> No.8927722

>>8927704
Yeah anon i cant even imagine what you are going through atm. Well thats the + and - of crypto. Anonymous but you cant refund.

Ledger is just byfar the best technology atm. Dont be greedy and buy a security.

My advice would be to start thinking about some extra jobs to earn back that REQ (by doing wagecucking). Put things on hold in life and focus on 2 jobs at the same time until you get your stuff back.

I dont know if you will get some help from exchanges but you can try.

I know this sounds depressing but if you work back your money then you will get some kind of peace.

>> No.8927729

Blame the Ethereum developers for making Mist so fucking terrible that people gleefully manage their coins on some shitty 3rd-party website.

next time just use Mist in light mode and wait 500 years for the client to connect to an actual working node

>> No.8927730

>>8927681
Fuk i wish i could murder that cunt. I'm sorry mate.

>> No.8927753

>>8927681
>i got a MEW paperwallet
how did this happen then? did you leave on your computer?

>> No.8927759

>>8927753
>MEW

That's his problem.

>> No.8927769

>>8927753
no i didnt even log into it as i said i just used ethscan for checking if everything is ok with my wallet

>> No.8927789

>>8927759
an addendum

some browser add-ons inject code into MEW and log your wallet information so if MEW didn't rob him some chink add-on dev probably did

seriously if you use an online-based wallet you should neck yourself this is basic security

>> No.8927819

>>8927681
Fuck that sucks.
>>8927759
I have my funfair coins on my exodus wallet. How fucked am I?

>> No.8927850

Thats why you should keep your funds on binance idiots. When has binance ever pulled an exit scam, huh? Thats fucking right. Idiots.

>> No.8927874

>>8927789
>seriously if you use an online-based wallet you should neck yourself this is basic security
DESU i never have, i bought a trezor a while back, have both a trezor + ledger.
I did wonder how this happened, thanks for explanation.
so he did not use a fresh (Linux) installation as they say to create a paper wallet.
>>8927850
just wait till the admins families get kidnapped, don't fuckin trust anyone else.

>> No.8927875

everyone in this thread

get used to the ethereum mist wallet if you're still using MEW

download it off the official website over https and verify the file's hash

then start up the wallet and enable light mode and wait patiently for it to work

make new wallets in mist (it also makes you encrypt with password) and transfer all your junk over to your new addresses

then back up all the wallet files in your keystore folder. the files are small enough that you can print them on paper or QR code them, they're encrypted

once you verify that you've backed everything up multiple times (flash drives, CD/DVDs, paper) you may clear the keystore folder

disclaimer: not responsible if you mess any of this up

>> No.8927910

>>8927681

>$200,000+ in wallet

Am I missing something?

>> No.8927916

>>8927910
He robbed other people with a similar trick. Read the comments.

https://etherscan.io/address/0x1ae4df1b75513179f383bc9845450fd76fcf640f#comments

>> No.8927918

>>8927681
your printer has its own cache, and is potentially a security threat that son of a bitch used

>> No.8927919

‘It won’t happen to me’, yes it will.

>> No.8927950

>>8927918
That's why you should only print encrypted QR codes. I'm the guy that keeps shilling running your data through AES before you print them if the wallet doesn't already do that.

That gives an additional layer of security to the paper wallet but burdens you with remembering passwords.

>> No.8927965

>>8927918
Just fucking write shit down and lock it in a safe and fuck that QR shit

>> No.8927980

>>8927759
does that mean you shouldn't use MEW even with a trezor?

>> No.8927983

this is why i use a mac

>> No.8927989

>>8927965
This. It's really not that hard

>> No.8927992

>>8927681
Sorry to hear but at least it’s not that much money in the long run.

>> No.8928008
File: 26 KB, 713x611, 1490267302984.png [View same] [iqdb] [saucenao] [google]
8928008

>>8927789
>browser add-ons
Using a browser addon on your crypto computer.

>> No.8928015

>>8927992
i bought those req at 4 cents and it will take me at the very least 10 months to get those req back and thats assuming it stays under 20 cents
by the time i have it back i could have already sold tax free
i was trying to hold for a year and then start selling my first few reqs

>> No.8928027

>>8927681
How did it happen

>> No.8928031

>>8928015
Well you could use those 33000 in a way. Say you buy in now and it balloons to $1 you could say you sold those 33k for a long term gain

>> No.8928036

anyone care to explain what kind of exploit was used here?

>> No.8928038

>>8928015
Maybe but unfortunately for you you're an absolute moron like most people in crypto.

>> No.8928048

thats what you get for holding a memecoin

>> No.8928051

>>8927681
The good news is that REQ is a shitcoin and wouldn't have ended up making you any real money anyway

>> No.8928056

>>8928036
It's larp, the link in the OP shows no such thing.

>> No.8928073

>>8927681

How exactly can this happen?!

>> No.8928096
File: 54 KB, 531x720, 345364543534934.jpg [View same] [iqdb] [saucenao] [google]
8928096

Also, an idea I just thought for inheritance issues.

Instead of encrypting your paper wallets with AES, use PGP. Encrypt your wallet information using your own public key and your spouse's public key
>implying women can into PGP

Then specify in your will that when you die, your spouse gets access to a bank deposit box the paper wallet is in.

I don't have anyone to give an inheritance so maybe in the future I guess.

>> No.8928103

>>8928073
malware changed the bookmarked legit MEW site to a phishing MEW site

high tech stuff

>> No.8928113

>>8927819
Why would you care about bags

>> No.8928115

>>8927681
because you've been on too many weird porn sites and a lot of them are phishing sites.

>> No.8928122

tldr; always google search MEW, then go to the 1st link.

>> No.8928126

>>8928115
i rarely use xvideos or pornhub but honestly rarely and no other websites
>>8928103
i didnt even log into MEW

>> No.8928132

>>8928122
What if I get cat pictures instead?

>> No.8928161

>>8928132
then you go allin on cryptokitties. it's a sign.

>> No.8928172

>>8928126
maybe you have a RAT on your PC and they cracked your keystore with hashcat

how complex was the password?

>> No.8928174

>>8928161
Did tron release crypto kitties or dogs? Justin Sun could of be telling us something....

>> No.8928185

>>8927681
Don't forget to pay your taxes :)

>> No.8928193

>>8928126
maybe your favorite shitting street is compromised?

>> No.8928217

>>8928126
>i didnt even log into MEW
Do you store your private key on any electronical data?

>> No.8928228

>>8928126
Alternatively, where is your written private key? Who has access to it? How many men does your wife see per week?

What OS did you use? How much proprietary cracked software from the darknet did you install lately?

>> No.8928254

>>8928185
You mean write it off as a loss?

>> No.8928261

Did you accidently enter your private key anywhere ever by copying and pasting?

>> No.8928285

i just looked at the compromised accounts
most look like they were generated in august of last year

I'm guessing they all signed up on a cloned MEW site then the perp waited for them to accumulate before stealing everything

case closed

>> No.8928308
File: 410 KB, 869x500, 1518533718409.png [View same] [iqdb] [saucenao] [google]
8928308

2FA identification you cunts. Sending a confirmation text to your phone makes it virtually IMPOSSIBLE for hackers.

>> No.8928348

>>8928285
Sounds good. Wonder why he didn't steal OP's other $27 though.

>> No.8928389

Ive got about 5k worth of coins on Binance and the rest of my portfolio on my Ledger.

Please buy one guys.

>> No.8928393
File: 51 KB, 720x719, 1519913296868.jpg [View same] [iqdb] [saucenao] [google]
8928393

The only way you get hacked in the year 2018 is by visiting phishing sites. This thread sounds like a RuneScape thread where they complain they got hacked and it turns out they we're sharing their account or some shit.

>> No.8928432

>>8928172
password was randomly generated 16 letters
>>8928193
im german i use toilets
>>8928217
no got it on a piece of paper in my closet
>>8928228
on a piece of paper in my closet nobody has access to it i live alone and use windows 10
>windows 10
yes i fucking know
>>8928228
none i use my ps4 to play videogames

>> No.8928457

what’s wrong with metamask?

>> No.8928465

>>8928393
Shouldn't 2FA prevent you from losing your info to phishing sites anyway?

>> No.8928488

>>8928465
Sophisticated sites can serve as a malicious proxy between you and the real website.

>> No.8928563

>>8928308
Your google 2FA can be easily compromised, the mobilephone is big weak spot

>> No.8928567

>>8928432
>password was randomly generated 16 letters
We got a weak point here already, you should have changed the generated password. The dude offering the tool could have made a copy.

But most likely you used a phising site as the other guy said.

>> No.8928568

>>8928563

Authy my dude

>> No.8928575

yo is metamask safe or not?

>> No.8928580

>>8928567
yea possible
man i feel so incomprehensibly retarded you guys cant imagine it
i hope my thread at least warns a few people on here

>> No.8928584

>>8928563
how?

>> No.8928588

>>8928563
>>8928568

You can do TOTP with a Yubikey NEO. I'm still trying to research how well it works before I buy one.

>private key storage is write-only
>generate TOTP keys by tapping yubikey on phone and using NFC app
>private keys never exposed

Should be reasonably secure.

>> No.8928599

>>8928432
>>windows 10
>yes i fucking know
I guess the implication is that you also used your pc to do other things. A windows pc, especially one that's also used for other tasks, simply can't be considered clean. It's too late for you but people should really invest into a small Linux box... just get a raspberry pi for 50€ if you don't have spare equipment laying around.

>> No.8928610

>>8928588
And now the only problem with this is, now someone can steal your Yubikey NEO to get access to your TOTP keys. Now it becomes an issue of physical security.

Your phone can be encrypted if it's relatively recent. So you usually have to enter a passphrase before you can even get to the 2FA app.

>> No.8928614

>>8928580
>man i feel so incomprehensibly retarded you guys cant imagine it
Oh I can, I recently threw the paper with my seed away and the only way I could get it back was to use file recovery on a usb stick and being really incredibly lucky. You must be living in hell now. It sounds like you have a job so at least you're not totally fucked. :l

>> No.8928621

This thread is making me so paranoid idk what to do

Honestly, I’ve left my funds on the exchanges (binance, GDAX) bc I just figured it’s more secure than the ledger I bought (and they usually post about protecting users funds when they are hacked)

Now idk wtf to do

>> No.8928633

if you just write down the 2fa backups on paper can you really get hacked?

>> No.8928634

>>8928621
>This thread is making me so paranoid idk what to do
A linux computer that's not used for anything else will protect you from most attack vectors. There's also the Ledger but I don't trust their factories desu.

>> No.8928649

>>8927704
>>8927722
Get your kneepads

>> No.8928651

>>8928599
partition the drive? use Qubes

>> No.8928663

>>8928621
Nobody can definitely tell you what to do. Shitcoins have been a thing for years and people still get their shit jacked for some reason.

I've never gotten my shit jacked before but I try to prevent it.

>> No.8928665

>>8928621

You probably need to get a digital wallet for a majority of your portfolio. about 25% of mine is on a "reputable" exchange and the rest on Jaxx.

>> No.8928668

>>8928614
yea it was money i could "afford" to lose
it was literally everything i had but i wont lose my flat or anything like that

>> No.8928674

soooooooo is metamask safe or not?

>> No.8928677

>>8928651
>partition
I'd use another one and only have that one plugged in. Why be less paranoid than the absolute maximum? This is the sector of life where it's the most useful.

>> No.8928686

>>8928621
Same
I just generated a MEW address to participate in the linkpool crowdsale, this is the address they’ll send my profits to, apparently. I keep all my linkies on Binance. Now I’m worried about MEW.

>> No.8928688

>>8928674
Use Mist wallet. It's the only wallet the Ethereum foundation kind of endorses. Don't bother using full node mode, it will never sync. Go to the options and enable light node mode.

>> No.8928694

>>8927681
Stop feeling sorry for yourself and buy some more crypto.

>> No.8928697

Honestly, for the average joe with less than desirable IQ, JUST...

>keep windows updated
>do a malware scan once in a while with malwarebytes and maybe an online av tool
>use Ublock Origin in whatever fucking browser you use
>if your browser doesn't support Ublock Origin, stop being a retard and move to one who does
>use the offline version of myetherwallet https://github.com/kvhnuke/etherwallet/releases (download the zip and run index.html on your browser)
>optional, switch DNS to OpenDNS which usually blocks reported phishing websites
>also optional, install metamask

All of this doesn't guarantee anything of course, but you have better chances to be safe.

>> No.8928719

>>8928697
>windows
MEEEEEEEEEEEP

>> No.8928729

>>8928697
>malware scan
MEEEEEEEEEEP

>using a browser
MEEEEEEEEEEP

Holy shit you're retarded.

>> No.8928770

I'm so poor that if I got hacked I wouldn't even care about it

>> No.8928812

>windows
lol
you must be a baby gamerfag because that's literally the only reason to use that garbage os
windows in 2018, lol
no wonder you got your shit stolen, op

>> No.8929372

guys im a little paranoid right now, because i store my tokens on a paperwallet too

I created it offline on a virtual machine with linux installed. My private key is safed with keepass.

Am i safe?

>> No.8929564

>>8929372
nobody is safe the best you can do is hope you dont get hacked. its as simple as that. if you paint a target on your back you will get hacked sooner or later

>> No.8929633

>>8929372
Your storage is safe.
However most people are not getting rekted from their storage, they seem to be getting hit with phishing attacks or some kind of malware browser add-on that steals your privkey when you use MEW.

Using MEW with a Linux vm would be much more secure. I still recommend getting a hardware wallet though

>> No.8929640

>>8927875
>use mist
>have all your money frozen because a random teenager initiated the kill() contract command on accident

>> No.8929660

>>8929640
Dumb faggot
You fundamentally don't understand ethereum.
>What is a faulty multisig smart contract
>What is parity

>> No.8929705

>>8927681
Sorry man. I didn't even think about malware being able to change my bookmarked pages. I guess I need to start being more careful as well with all of my login security information.

Hope you recover.

>> No.8929707

>>8929660
You must be fun at parties.

>> No.8929714

>>8929707
Not as fun as your mom

>> No.8929734
File: 1.53 MB, 1280x720, sayori crash.png [View same] [iqdb] [saucenao] [google]
8929734

>>8927681

>> No.8929884

>>8929714

I manually type in huobi.pro and binance.com

will this prevent phishing?

I either keep my shitcoins on binance or ledger. this seems optimal?

>> No.8929941

>>8927681
>some people filed a police report and said they contacted binance and kraken
>kraken already launched an investigation apparently
?????????????????????? what

>> No.8929973

>>8929884
Yes as long as you type it correctly.
Just bookmark it bro, the bookmark FUD is speculative and as long as you have 2fa, phishing isn't the end of the world.

>> No.8930006

>>8929640
Mist wasn't even the wallet that had the multisig shit.

>> No.8930018

>>8930000

>> No.8930064

>>8927681
33000 REQ? what's REQ?

>> No.8930154

>>8927681
you should keep half on the exchange (yes fuck 4chan they literally don't know shit, btw if you had it on an exchange and they were hacked you could get a fucking re-imbursement like I did numbnuts) and use 2fa SMS. not fucking google authenticator lol i had fun breaking that in first week my friend showed it to me.

2fa SMS.

and buy a a fucking desktop that has nothing on it but the client for your wallet/exhcange.

yes exchanges CAN get hacked, but then there is fucking liability, especially if you're not on a shifty one.

I got 3000 Litecoin taken, got them all back now.

>> No.8930179

>>8930018
what a fucking waste.

>> No.8930206

>>8930154
So why does every exchange “strongly recommend” instead to use the separate authentication? What’s so bad about Google and are Authy/Duo better?

>> No.8930212

>>8930154
What exchange anon

>> No.8930279

>>8927916
Who robbed the people and how did they do it?

>> No.8930296

>>8930206
That guy is retarded.
SMS is weaker than Google auth.
An attacker just needs to port your number to get in, where as Google auth requires them to have physical access to your phone.

Authy is the same as Google auth but has a cloud backup feature. If you use it, make sure you set a decent password on the cloud backup. Google auth has no backup feature so you can't lose your phone.

>> No.8930361

>>8930279
i think they used a fake mew site to create their wallet. but thats just my assumption

>> No.8930364

>>8930296
>Google auth has no backup feature so you can't lose your phone.
yeah but all the 2fas you link on it have a backup key

>> No.8930387

only thing i use metamask for is ethercraft

>> No.8930412

>feeling sorry for a literal retard
MEW has warnings all over the place, if you got hacked it's your own fault, I hope you learned from that mistake faggot, no sympathy.

>> No.8930501

>Hi, you stole my Zilliqa and Ether. I do not know how you did this. I applaud your skills but want to let you know that you are harming real people's lives here. I am expecting my first kid to be born this week. You stole the money that is meant to support this baby. You are hurting my family and I cannot think of someone who enjoys that.

These comments kek

>> No.8930623
File: 195 KB, 2318x514, Screen Shot 2018-04-16 at 13.47.32.png [View same] [iqdb] [saucenao] [google]
8930623

>>8930501
comments on scam addresses are the best part of etherscan

>> No.8930642

>>8928457
Nothing. I use MetaMask and am fine. Just don't visit dangerous websites and download random stuffs.

>> No.8930668

>>8930642
also noscript is a good add-on

>> No.8930676

OP you fuckin retard, tell me how you got hacked so I can protect myself!

It's over for you, but I still have a chance!

>> No.8930684

guys, wtf is "REQ" ?

>> No.8930683

>>8930668
>noscript is a good add-on
Care to explain to a brainlet?

>> No.8930698

D9nt worry OP , req was useless anyways not like you lost anything

>> No.8930699

>>8930683
check https://noscript.net/

, basically an addon that disables javascript... and makes most sites load wrong/not work correctly. VM>noscript tho

>> No.8930711

>>8930684
Just some Pajeet coin. OP should be happy.

>> No.8930740

>>8929941
im not really sure whats that about i just got it from the comments of the scammers adress

>> No.8930745

>>8930699
Alright thanks. I believe MetaMask is safe, but still threads like this scare me.

>> No.8930873

I think one is safe if he had downloaded the script to create his wallet and did this offline

OP created his wallet online in MEW, that was probably his mistake

>> No.8930879

Really fucking wish exodus would just add 2FA already

>> No.8930903

>>8930623
There is still so much dumb money to take. Really makes me feel better.

>> No.8931133

>>8928122

GET IT RIGHT ONE TIME AND BOOKMARK THE FUCKING MEW WEBSITE

>> No.8931416

is MEW unsafe?

>> No.8931497

I'm using Exodus

Is it a good idea to just buy a cheap laptop, install exodus on there, configure it for that, etc. and then just let the thing sit in a corner while I use another computer for vidya and browsing?

Or does this have some secruity problem I'm unaware about.

>> No.8931561

>>8931497
well, don't keep the computer running when it's not needed. that's a waste of electricity better spent mining.
what happens when Exodus becomes compromised/corrupt and bundles wallet-stealing malware in their distribution? and why is this shit apparently closed-source?

>> No.8931636

>>8930623
>invested money not considered 0 in value
Classic

>> No.8931710

>>8928008
metamask?

>> No.8931845

>Ethereum, MyEtherWallet.com & MyEtherWallet CX, and some of the underlying Javascript libraries we use are under active development. While we have thoroughly tested & tens of thousands of wallets have been successfully created by people all over the globe, there is always the remote possibility that something unexpected happens that causes your ETH to be lost.
>Please do not invest more than you are willing to lose, and please be careful. If something were to happen, we are sorry, but we are not responsible for the lost Ether.
kek why did anyone use this shit

>> No.8931907

this is why I unironically keep all my money on binance

IP verification + 2FA + 2BTC withdrawal limit (meaning I can only lose 10% of my stack before I find out)

Binance spends millions on security, uses deca layered cold wallets, and they would be able to bail everyone out in the event of a hack

cold storage fags BTFO. People have their personal wallets hacked every day. Binance has never been internally compromised

>> No.8931958

this shit have me worried now how is even possible to hack if they never stored private keys virtually

>> No.8931973

>>8931907
yeah unitl binance gets fucked mate. I have my bitcoin address safe in various drives, encripted over the encription it already has. That's the best way to keep it safe. Also, Bitcoin is the most secure chain. Etherum is full of bugs.

>> No.8932320

I got mewed too. And I know I didn't fall for the phishing meme. Mew is compromised

>> No.8932447

>>8927681
OP probably bought ATH too

>> No.8932594

>Having funds in Tokens
>running on a network in gamma stage
>with an unknown amount of attack vectors
why the hell are you in crypto. Vegas is less risky with a higher ROI

>> No.8933090

>>8931958
>>8931973
im pretty clueless but obviously i must have made some mistake
all i know is next time i just put that shit on a ledger and by my next paycheck i will have switched to a linux os

>> No.8933196

>>8927681
>it's another thread full of faggots who didn't ledger
it's sad how misunderstood ledger is.
probably 90% of biz doesn't even understand how it works and you think your paper wallets and airgapped usb are in any way equivalent.