Author

Topic: Delete (Read 8076 times)

full member
Activity: 155
Merit: 100
March 03, 2014, 11:33:13 PM
#34
I have a few security experts working on it.  With any luck I'll track him down otherwise that was a very expensive lesson. I am going to have this thread removed in case he/she is monitoring it.
hero member
Activity: 742
Merit: 500
March 03, 2014, 10:49:47 PM
#33
If you had 2fa enabled on btce and gmail, there should be 0 chance of anyone hacking your account. Are you sure it was enabled on both?

I only had 2FA on BTC-e not on my gmail.  I just added 2FA to my gmail.  As far as I know BTC-e doesn't have SMS 2FA though only 2FA via e-mail which is pointless if someone has access to your e-mail.  I have heard they now have 2FA through Google Authenticator though.
They've had 2fa through gauth for quite some time now. At least a year, from what I remember. Either way, I am sorry to hear about your problems, I hope you're able to track this SOB down.
legendary
Activity: 1316
Merit: 1000
March 03, 2014, 07:59:23 PM
#32

i feel so bad reading this, i lost some in gox that feels bad. 

hope things work out for you
full member
Activity: 155
Merit: 100
March 03, 2014, 07:56:22 PM
#31
(removed)
hero member
Activity: 686
Merit: 500
March 03, 2014, 07:11:03 PM
#30
interesting read keep us updated and i hope you get the thief
hero member
Activity: 742
Merit: 500
March 03, 2014, 07:03:09 PM
#29
If you had 2fa enabled on btce and gmail, there should be 0 chance of anyone hacking your account. Are you sure it was enabled on both?
full member
Activity: 155
Merit: 100
March 03, 2014, 06:11:48 PM
#28
(removed)
newbie
Activity: 18
Merit: 0
March 03, 2014, 05:29:42 PM
#27
Your email has been hacked also. You should receive emails when you sign into BTC-E. The attacker used TOR to login to your accounts and take the money. When the money is missing but you still have access with same password means he is just waiting for you to come back so he can take more. There is no way for you to get your coin back. Get Kaspersky & Malwarebytes and safe guard your cold storage reserves. Good rule of thumb: 10% on exchanges, 10% on your computer, and 80% cold storage (offline). Oh and don't forget to use a token / multi-factor authentication when logging into your accounts.

IP:   62.210.129.149
Hostname:   afo2.torproject.afo-tm.org
full member
Activity: 155
Merit: 100
March 03, 2014, 05:23:44 PM
#26
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 04:08:43 PM
#25
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 04:07:31 PM
#24
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 03:37:11 PM
#23
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 03:20:45 PM
#22
No that was a unique password.  I don't use the same password on any accounts that have access to any sensitive information.
sr. member
Activity: 281
Merit: 250
March 03, 2014, 03:05:48 PM
#21
so many coins.. sorry for your loss.

Do you use same password in websites?
full member
Activity: 196
Merit: 100
★Bitvest.io★ Play Plinko or Invest!
March 03, 2014, 03:04:51 PM
#20
How would I go about getting the identity attached to this IP?

I, personally, am no good at this kind of thing - so unless you can present Cox with a subpoena, I'm afraid I'm beyond my level of experience Undecided
full member
Activity: 155
Merit: 100
March 03, 2014, 03:02:12 PM
#19
(removed)
full member
Activity: 196
Merit: 100
★Bitvest.io★ Play Plinko or Invest!
March 03, 2014, 02:58:40 PM
#18
It appears on February 28th someone hacked into my gmail account which then allowed them to gain access to my BTC-e account.  I show a number of tor nodes accessing my account from then until today.  I am still looking into what is involved with the sign in challenge.  I however did find on IP that wasn't me and is not a TOR node.  68.108.178.224  http://whatismyipaddress.com/ip/68.108.178.224  Any idea how I can track this IP down?

Vegas, Baby!

http://www.infosniper.net/index.php?ip_address=68.108.178.224&map_source=1&overview_map=1&lang=1&map_type=1&zoom_level=7
full member
Activity: 155
Merit: 100
March 03, 2014, 02:56:41 PM
#17
(removed)
newbie
Activity: 21
Merit: 0
March 03, 2014, 01:43:10 PM
#16
I believe BTC-e should have better security to withdraw those amounts.

Do you receive 2FA code via SMS?
as i see u never see btc-e, lol
newbie
Activity: 8
Merit: 0
March 03, 2014, 01:41:09 PM
#15
I believe BTC-e should have better security to withdraw those amounts.

Do you receive 2FA code via SMS?
newbie
Activity: 21
Merit: 0
March 03, 2014, 01:38:45 PM
#14
anyway to withdraw funds with 2f they must:
1. use 2f
or
2. disable 2f (its takes 2 weeks)

then if u used 2f from computer
1. local -> then u computer has been hacked etc
or
2. remote (2f online sites etc) -> that site was compromised or hacked
full member
Activity: 155
Merit: 100
March 03, 2014, 01:32:20 PM
#13
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 01:25:39 PM
#12
(removed)
legendary
Activity: 1554
Merit: 1222
brb keeping up with the Kardashians
March 03, 2014, 01:24:47 PM
#11
It looks like someone may have passed a sign in challenge on my gmail this morning then signed in.  

The challenge was passed from this IP:

72.52.91.19

Then the sign in I don't recognize is from this IP:

128.117.43.92

What does it mean to "pass a sign"?

Edit: Nevermind, I read that completely wrong.
full member
Activity: 155
Merit: 100
March 03, 2014, 01:22:18 PM
#10
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 01:17:58 PM
#9
(removed)
newbie
Activity: 21
Merit: 0
March 03, 2014, 01:12:18 PM
#8
I was using my computer for 2FA not mobile. 
then u must audit your computer fast, for reset 2f u must wait for 2 weeks. i suppose u used 2f for withdraw too?
legendary
Activity: 1311
Merit: 1000
March 03, 2014, 01:07:08 PM
#7
I was using my computer for 2FA not mobile.  I had just logged in yesterday.  I also get notifications of the IP when I log in.  I did not receive any e-mail notifications at all. 

It appears the LTC funds have already been transferred out of the wallet he sent them to:

http://ltc.blockr.io/address/info/LUwuDgK6qji89sQLkVtgBPUkzfYqVc7Gcq

The BTC funds are still in the address he sent them to:

https://blockchain.info/address/15kLxMTGjoU3Ym5621HjFVSVRZmovvnaEW

That's a lot of coins, I've seen these threads before, about btc-e.
full member
Activity: 155
Merit: 100
March 03, 2014, 01:04:39 PM
#6
(removed)
newbie
Activity: 21
Merit: 0
March 03, 2014, 01:01:55 PM
#5
do u using mobile or computer for 2f auth? for how much time u didn't use your acc?
full member
Activity: 155
Merit: 100
March 03, 2014, 12:58:27 PM
#4
(removed)
full member
Activity: 155
Merit: 100
March 03, 2014, 12:53:47 PM
#3
(removed)
legendary
Activity: 1554
Merit: 1222
brb keeping up with the Kardashians
March 03, 2014, 12:49:23 PM
#2
Did you have 2-factor turned on? Not only for login, but for trades?
full member
Activity: 155
Merit: 100
March 03, 2014, 12:48:22 PM
#1
(removed)
Jump to: