I just checked email, got one yesterday saying my ozcoin wallet address had changed (?!?!?). Just went into ozcoin website and it shows withdrawal made of all my remaining coins to this other (Unknown) address. I haven't logged into the ozcoin website in months. Not sure who/how my address could have been changed and then all coins withdrawn in a 24hr timespan.
I use a > 15 digit alphanumeric pwd that is not repeated at any other site, and I don't have any other indications I might have been compromised. Am I missing something obvious? I haven't been on the forums or paying alot of attention lately, so this is possible, but I'm still somewhat troubled. Given the current exchange rate of Bitcoin this represents a nontrivial amount of currency.
Thanks
some info on your account would be nice.
I sent that in a PM to Graet 6..ish days ago. Understood he's been away/busy. I'll PM you as well if you like if I can verify you are a legitimate support person for the site. Unfortunately there isn't much listed on the site for support except this forum.
It is good for you to report here, but it is probable that nothing is wrong with the site - your credentials for the pool website were likely obtained by a cracker, by your computer, email accounts, or network connection being Pwned. With Bitcoin, you are responsible for your own security; there is no bank to call that can give you your money back when you got scammed. There is also no way to prove it wasn't you that withdrew the money.
You can report the theft to Police who will be glad to chuckle; with someone willing enough to file a police report because a theft actually happened, a site admin may be able to turn over what forensic evidence there is, likely just a Tor exit node IP address or an IP address of one of over 9000 rooted machines under a hacker's control (if there even is any logging - many users might prefer no logging of their pool connections if given the choice...)
I take this as well meaning (but somewhat condescending) advice. In my mind, there are at least 2 plausible scenario's:
1) My personal security has been, as you put it, Pwned. In this case I would be missing several orders of magnitude more coins, from other sites, in addition to at least some token amounts of fiat currency. To date, this has not happened. Just this one site, and just the coins available at this one site, where there is a single, non-repeated pwd on my account. If just this site's password was compromised, I would think the site operators would have interest in this, as I've stated it's a nontrivial password hack.
2) During one of the several documented breaches of infrastructure/security, someone harvested passwords. When the withdrawal limit was lowered, they went back and cashed out all they could.
A response from the site operator(s) would be helpful in determining which of the above 2 are more likely.
Of course there are probably several other scenarios that may be in play here, but that is why I asked the question, rather than pointing fingers and getting fired up.