First I want to know if Poloniex is the only account affected by this.
The same thing can happens on other account.
In fact, I've heard it happens in binance.
The way it works it the following.
Hackers, got a hold of your trading API.
Once it got there, it moved all money from lending to trading (I am not sure why this is do able via API).
Then hacker will choose a small market. The hacker will repeatedly do losing trade. For example, buy at 4 sell at 3. Of course, the hacker will be the recipient on the other end.
Poloniex can actually detect this by seeing that the portfolio value of the victim drop a lot within minutes due to trading. This is not the first time it happens. However they do not seem to have bot to check this.
Poloniex is able to freeze my account. I think they managed to detect this. I don't know if they can save my money. Most likely not. I will be there again if they can.
I will show evidences.
This is not the first time
It happens here
https://bitcointalksearch.org/topic/m.19800513https://www.reddit.com/r/CryptoMarkets/comments/6kv2p4/poloniex_account_hacked_25000_stolen/ So it happens at least 3 times already in poloniex. I have never heard something like this happens in other exchange. I checked google.
Someone else have that problem.
The hacker most likely have access to my API. I allowed trading even though I don't trade via API and rarely do so manually. BIG MISTAKE.
Only 2 people have access to my API. My self. And cryptolend. They are 2 different API. I have never heard any case cryptolend accounts got compromised.
I think the hacker use another API. How the hacker got the API and password is beyond me. It's safely stored on my computer. People need 2FA and email to access that.
I am not blaming polo. However, I've heard this sort of thing happens only in polo. If you have any other cases, please let me know. Also this thing is preventable. People buying and selling huge money repeatedly depleting his account is something normal people won't do. I hope poloniex fix that thing and I hope stuff like this never happen again.
Then, and only then, I will start using poloniex again. Which is quite decent. If you use API please
DISABLE TRADING unless you really have to trade.
Polo, I hope you can detect this kind of hack. If only I can get 50% of what I lost I will be very happy. Also I hope polo is cooperative enough to display all those info about the hacker.
I want to know the IP, the country, the Know your customer data stored in the hacker account. The hacker account must be the one benefiting from this trade.
If I am happy enough I will play polo again. If not, I think I will use binance. Binance managed to block this sort of thing.
https://cointelegraph.com/news/binance-reverses-irregular-trades-resumes-trading-amidst-community-confusion-about-hackI am pretty sure the money is gone. However, I will be very happy if this thread is spread toward so many exchanges so
the same thing does not happens again.I think exchanges should implement "honey pot" API. The API can be used for trading but will trigger alarms if is used for such.
Exchanges can also have alarms. If a user heavily trade at a lost for 20% of his income even though there is no significant "real" price movement, it should trigger at least withdraw ban among all traders that trade with the compromised account.
I also wants to talk to attorney general. I hope they help polo prevent this things from happening again.