Pages:
Author

Topic: I was hacked (1170btc stolen) - 500btc max BOUNTY - page 19. (Read 35693 times)

legendary
Activity: 2646
Merit: 1137
All paid signature campaigns should be banned.
Are we sure the btc isn't in some tumbler by now?
Yes we know exactly where they are, see my previous posts.

@Wulfcastle, but why would the thief amass all of the stolen btc in the same address? It would be that much easier to connect him to other events and hoard some more evidence. Maybe the address belongs to a mixing service?
The hacker is the same guy who stole the funds from Silk Road. The address he sent some BTC too is the same address that over 5,000 BTC stolen from the Silk Road hack was sent to. He could be either

1) The guy who stole the original Silk Road's funds and the proposed Silk Road 2's Funds

2) One of the owners of SK who stole their own users funds and make it seem as if a hacker took them


http://www.deepdotweb.com/2014/02/20/here-is-the-stolen-silk-road-wallet/

Could be someone relatively "close" to Klee, an owner of Silk Road 2(defcoin for example), or the hacker who stole from Silk Road


the 5K BTC may be unrelated to this hacker.  He just donated some of my tag BTC and a small bit of the stolen BTC to that address, maybe to try to throw us off.  It is only interesting that he donated my tag BTC there.

0.00112233 + 0.00011122 from me, 0.0006 from klee
hero member
Activity: 770
Merit: 500
The hacker is the same guy who stole the funds from Silk Road. The address he sent some BTC too is the same address that over 5,000 BTC stolen from the Silk Road hack was sent to. He could be either

1) The guy who stole the original Silk Road's funds and the proposed Silk Road 2's Funds

2) One of the owners of SK who stole their own users funds and make it seem as if a hacker took them


http://www.deepdotweb.com/2014/02/20/here-is-the-stolen-silk-road-wallet/

Could be someone relatively "close" to Klee, an owner of Silk Road 2(defcoin for example), or the hacker who stole from Silk Road
sr. member
Activity: 266
Merit: 250
Dear HEADHUNTERS,

43% of any btc I will be able to get back IF you find the identity of the thief!

If the whole amount will be returned to me (1170BTC) that would be 500BTC.

https://blockchain.info/nl/address/1GwNLwoCQiobJzmURSAq54vH4BYjFkwaxr

FIND HIM!!!

http://blockr.io/issue/1

Make a report!

https://blockchain.info/nl/tx/800ee228491d8591fd9da880c6d88d4c901ed1697e0aa43c010d7b0eafd796da

IP ADDY on here. Lives in France.

https://blockchain.info/nl/ip-address/46.105.103.92
The IP address is just the IP address of the node that relayed the transaction first. When using multibit, your IP address can show up as being in several countries across the planet when you do not even leave your home. 
hero member
Activity: 508
Merit: 500
Well, this suck big time. I hope klee gets the money back, even if there's not a fat chance. I wouldn't like to see the thief getting hurt, maybe just brought to justice.
Are we sure the btc isn't in some tumbler by now?

@Wulfcastle, but why would the thief amass all of the stolen btc in the same address? It would be that much easier to connect him to other events and hoard some more evidence. Maybe the address belongs to a mixing service?
full member
Activity: 328
Merit: 100
i'm sure there are many very smart individuals who are highly motivated to find this person's identity for that kind of reward. share every lead and piece of evidence you can muster. good luck man
hero member
Activity: 546
Merit: 500

Now this is getting interesting, 5000 BTC in one account, when klee only lost 1170 BTC, looks like this guy has hacked other people too. Also was it you who left the note there BurtW, when you say "your tag"?
sr. member
Activity: 336
Merit: 250
Send money? That $500,000 US he stole isn't enough?

OOPS, was in a hurry, the note went with the previous transaction, not the theif's, my post has been corrected, please delete your response to my error.

I made the same mistake last week. Started a thread about over 150K moved from an address with a cryptic note attached but the note was from the previous tx. The placement of these notes are misleading if one doesn't know better or doesn't dig deeper.
legendary
Activity: 2114
Merit: 1040
A Great Time to Start Something!
I'm not good at this type of hunt, but I hope the OP gets it all back.
That is a generous bounty let's see someone earn it by recovering all the stolen coins.  Smiley

dropbox was compromised (with plain txt for the pwd, I know I know..)


sorry, but ... it's a EPIC fail ... my lord.


I've never seen that one before, it is really cute and funny.  Smiley
full member
Activity: 168
Merit: 100
Send money? That $500,000 US he stole isn't enough?

OOPS, was in a hurry, the note went with the previous transaction, not the theif's, my post has been corrected, please delete your response to my error.

The dude lives in France. His IP points at least one of the addys over there.

https://blockchain.info/nl/inv/fec490fa9b022f280c41522d7d0fc5ebb46556f1b264dd0124e408c1b154b5b1
full member
Activity: 168
Merit: 100
legendary
Activity: 2646
Merit: 1137
All paid signature campaigns should be banned.
full member
Activity: 168
Merit: 100
Dear HEADHUNTERS,

43% of any btc I will be able to get back IF you find the identity of the thief!

If the whole amount will be returned to me (1170BTC) that would be 500BTC.

https://blockchain.info/nl/address/1GwNLwoCQiobJzmURSAq54vH4BYjFkwaxr

FIND HIM!!!

http://blockr.io/issue/1

Make a report!

https://blockchain.info/nl/tx/800ee228491d8591fd9da880c6d88d4c901ed1697e0aa43c010d7b0eafd796da

IP ADDY on here. Lives in France.

https://blockchain.info/nl/ip-address/46.105.103.92
legendary
Activity: 1092
Merit: 1010
I'm not convinced that is what happened. Someone brought it up on NXT forum that he hadn't changed his password since they updated their cert after that heartbleed scare of 2014. But, that doesn't mean it was the attack vector. But, if it was, dropbox logs will show it.

Of course if someone at dropbox went to work in a new Ferrari today, then well, there you go.

It is not certain what happened exactly.

Fact: security was very bad, so we know that.

There is a possibility that the laptop he was using at the Bitcoin Conference in Vienna about a month ago was compromised (why these conferences keep using open WiFi is a mystery to me).

Also, of course, someone close (a terrible thing to contemplate, but a possibility).

legendary
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf

It's a pity that this seems to happen to the best. OP seems to be a great guy who donated to the best causes.

Please do help him if you can.



I feel so bad for you OP, I haven't been able to get this out of my head all day Sad
sr. member
Activity: 266
Merit: 250
Wow... that's a freaking theft...  The wallet was online I assume?
Electrum - dropbox was compromised (with plain txt for the pwd, I know I know..)

plain txt .... and on dropbox ...

I am sorry to hear this but good luck buddy !
It looks like that you only had the coins at the address for two days.

Do you think it would be possible that you accidentally marked the file as public so anyone with the link could access it?
hero member
Activity: 742
Merit: 500

It's a pity that this seems to happen to the best. OP seems to be a great guy who donated to the best causes.

Please do help him if you can.

legendary
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
Are you able to get the i.p addresses of the most recent log ins to your dropbox account?  If it was someone on their end, that is definitely grounds for a massive lawsuit
legendary
Activity: 1736
Merit: 1001
Wow... that's a freaking theft...  The wallet was online I assume?
Electrum - dropbox was compromised (with plain txt for the pwd, I know I know..)

plain txt .... and on dropbox ...

I am sorry to hear this but good luck buddy !

plain txt...

so it was all essentially sitting in a dropbox with no 2FA... just a single dropbox password?

how was the dropbox compromised?

I'm not convinced that is what happened. Someone brought it up on NXT forum that he hadn't changed his password since they updated their cert after that heartbleed scare of 2014. But, that doesn't mean it was the attack vector. But, if it was, dropbox logs will show it.

Of course if someone at dropbox went to work in a new Ferrari today, then well, there you go.
hero member
Activity: 658
Merit: 501
I wonder what percentage of these hacks are merely attempts to document publicly that a fortune was lost for tax and legal purposes?

Working in IT I'm sure that a majority of them are indeed real as most humans in general are horrible at security. The quicker we get cheap and secure hardware wallets the better.

I suppose their have been a few instances where people were able to DOX the culprit.
legendary
Activity: 1498
Merit: 1000
Wow... that's a freaking theft...  The wallet was online I assume?
Electrum - dropbox was compromised (with plain txt for the pwd, I know I know..)

plain txt .... and on dropbox ...

I am sorry to hear this but good luck buddy !

plain txt...

so it was all essentially sitting in a dropbox with no 2FA... just a single dropbox password?

how was the dropbox compromised?
Pages:
Jump to: