Pages:
Author

Topic: Blockchain.info Unauthorized Withdraw - page 2. (Read 3383 times)

member
Activity: 87
Merit: 10
April 25, 2013, 06:26:21 PM
#4
Sad that it cost me $200 to learn that lesson. 

Didn't relize/remember they would have access due to private keys.

Guess ill have to get new wallet and start fresh.

Such a kick in the balls though.  From what I learned they got over 500 coins in transactionsto the account that it was transfered too.

Grrr. 

Thanks anyways.  Lesson learned hard way.

Fyi parden any bad typing.  On with phone at work. 



donator
Activity: 1218
Merit: 1079
Gerald Davis
April 25, 2013, 06:11:00 PM
#3
Please tell me after the first compromise you threw away that entire wallet and started fresh?

If not the attacker didn't need to hack anything.  After the first attempt he had a copy of your wallet.  He just waited for you to put funds into it and stole it.  Once attacker has the wallet = has the private keys he doesn't even need access to the website anymore.  If you put more coins in there, once the attacker notices them he will transfer them out.  100 years from now he could still steal coins.

If your wallet is compromised, it is compromised.  Period.  You should assume all private keys connected to that wallet are totally and completely compromised.  Move funds out of the wallet (if any).  Destroy all copies and start fresh.
legendary
Activity: 1400
Merit: 1005
April 25, 2013, 06:10:43 PM
#2
Did you create a new wallet after the first hack?  The attacker still has access to the private keys of all the addresses from your old wallet, so you would want to immediately discontinue using that wallet, even if you did "resecure" it.
member
Activity: 87
Merit: 10
April 25, 2013, 05:55:25 PM
#1
Twice in two weeks I have had coins removed from my account.  First time I could understand cause my ema may have been comprimized but I changed all my passwords and added the ip address logging to blockchain and did two key on google.

Less then hour ago I get notification via txt that another withdraw was done.
Again only one coin but still that's $130.

I log in and check log and there is no isp entry for anytime for withdraw. Only my entries on phone and computer.

Is therr something else that I should know?  My only other options would be go back to old wallet or restrict the ip address for blockchaiblockchain.

Again I changed my password.  It uses a combo of cap and lowercase letters numbers and symbols.   

I have no virus on home computer. 

Its the no log that really irks me.  How can a withdraw be made without an entry made.?

Pages:
Jump to: