Author

Topic: I was withdrawn from the BITTREX 0.5 btk exchange via API-keys (Read 327 times)

copper member
Activity: 9
Merit: 0
I had this same situation as well - my funds were stolen from API that did not have withdrawal abilities.

For others who had this, was the mechanism used via trades? Or, how?
sr. member
Activity: 1026
Merit: 280
🇧🇬 Crypto Since MMXIII
newbie
Activity: 27
Merit: 0
sr. member
Activity: 336
Merit: 250
Do the thing and you'll have the power.
I was warned against using Bittrex API for my trading bot.
The community of guys who got me into bots advised me well.
I am using Binance because they are much better at locking down their API.
Bittrex has and other exchanges too have API issues.
In the end I hope they refund. But ultimately no one should use the APIs until it's overhauled.
newbie
Activity: 27
Merit: 0
What should be done to draw attention to this problem? What do you think there is hope to return my funds?
sr. member
Activity: 742
Merit: 395
I am alive but in hibernation.
Bittrex is not going to recognize any responsibility. All answers are made from template "You were been hacked, and this is your own trouble".

My requests to escalate my ticket to another guy were ignored. Now they close tickets without any explanation.


 
I have the same problem - my deposit in Bittrex was stolen through API-keys without withdrawal enabled.
Bittrex techsupport closed my tickets with standard bla-bla about phishing, viruses, phone, e-mail ang 2FA hacking and so on.
After third attempt they had to agree, that withdrawals were made with API-key.
Next question - how it was possible - my keys were without withdrawing, I received answer, that thief changed API key (enabled withdrawal), stole deposit, changed API key again (now my API without withdrawal enabled again).
Have to note, that change API-key properties requires 2FA confimation at least. And my phone was with me all time long (protected by password/fingerprint)
And yes, I checked my phone and computer for viruses, trojans etc. - there was nothing, of course.

I'm not alone. a problem exists and BITTREX must recognize its imperfection in safety.


It feels to me that it is some insider job of someone in bittrex. Again it proves that exchange cannot be trusted for your balances.
newbie
Activity: 27
Merit: 0
I once again wrote in support. The problem is open and support does not want to solve it.
newbie
Activity: 3
Merit: 0
Bittrex is not going to recognize any responsibility. All answers are made from template "You were been hacked, and this is your own trouble".

My requests to escalate my ticket to another guy were ignored. Now they close tickets without any explanation.
newbie
Activity: 27
Merit: 0
I'm not alone. a problem exists and BITTREX must recognize its imperfection in safety.
newbie
Activity: 3
Merit: 0
I have the same problem - my deposit in Bittrex was stolen through API-keys without withdrawal enabled.
Bittrex techsupport closed my tickets with standard bla-bla about phishing, viruses, phone, e-mail ang 2FA hacking and so on.
After third attempt they had to agree, that withdrawals were made with API-key.
Next question - how it was possible - my keys were without withdrawing, I received answer, that thief changed API key (enabled withdrawal), stole deposit, changed API key again (now my API without withdrawal enabled again).
Have to note, that change API-key properties requires 2FA confimation at least. And my phone was with me all time long (protected by password/fingerprint)
And yes, I checked my phone and computer for viruses, trojans etc. - there was nothing, of course.
sr. member
Activity: 1026
Merit: 280
🇧🇬 Crypto Since MMXIII




























But the question is you disabled your api's withdrawal access but the hacker did a success withdraw, how is that possible.

The big question and very strange situation! Undecided

I spoke to Vitaliwit in the Russian section. There are more screenshots and from the support response makes it clear that they can not understand which API key has withdrawn the balance. They also talk only about 6 keys, but on the screenshots above they are more than 20. The activity log shows no changes to the key rights from the hack date to today and on the screenshots no keys with withdrawal rights...

Russian topic: https://bitcointalksearch.org/topic/bittrex-05-api-keys-1-5121306
copper member
Activity: 2142
Merit: 1305
Limited in number. Limitless in potential.
High chance that your account's api was compromised, base on your security log, this 210.161.230.17 was the hacker's ip right?
But the question is you disabled your api's withdrawal access but the hacker did a success withdraw, how is that possible.
legendary
Activity: 1932
Merit: 1273

I have access to the account only from my IP. API-keys without the right to withdraw funds. If I had been hacked, they would have changed the API -keys. But this was not. Dropped by the old keys. With keys without the right of withdrawal, you can only sell coins.
If you do believe you aren't getting hacked, then somehow there is a problem within the BIttrex system which is highly unlikely. However, I'd still believe you are getting compromised. And judging by your screenshot even though it's hard to analyze since I don't know which is your true IP address. You are highly likely being hacked.

Anyway, try to move your thread to more proper section like Beginners & help or Exchanges, you probably will get more response there.
newbie
Activity: 27
Merit: 0
Before we dig deeper Bittrex are scam shady exchanges (https://bitcointalk.org/index.php?action=trust;u=96390).

You are the only one who knows why you are being hacked, try to scan your PC from virus, malware, and etc. Also, What kinds of program that you use your API keys? does it open source or some closed-sourced trading bot scam. Try to remember step by step before your coin get lost.

After all, there is likely zero chance you could win back your coins.

I have access to the account only from my IP. API-keys without the right to withdraw funds. If I had been hacked, they would have changed the API -keys. But this was not. Dropped by the old keys. With keys without the right of withdrawal, you can only sell coins.

https://a.radikal.ru/a26/1903/3b/2c99f3f940e2t.jpg

https://d.radikal.ru/d21/1903/dc/30b5302cf7b6t.jpg

https://c.radikal.ru/c28/1903/43/38f26eac62d5t.jpg

https://a.radikal.ru/a35/1903/3d/bc463fc515b2t.jpg

https://a.radikal.ru/a31/1903/da/e66d24129edbt.jpg
newbie
Activity: 27
Merit: 0

It's very likely your API key and secret key was leaked or you have a malware on your computer stealing your private information.
Just out of curiosity, which website did you use the API keys on?

Also, why didn't you disable the withdrawal through API key... this is more secure in case someone lands on your keys because believe me, they will be able to withdraw from your account without even logging in or using 2FA


I have disabled API output. it can be seen in the screenshot.
legendary
Activity: 1932
Merit: 1273
Before we dig deeper Bittrex are scam shady exchanges (https://bitcointalk.org/index.php?action=trust;u=96390).

You are the only one who knows why you are being hacked, try to scan your PC from virus, malware, and etc. Also, What kinds of program that you use your API keys? does it open source or some closed-sourced trading bot scam. Try to remember step by step before your coin get lost.

After all, there is likely zero chance you could win back your coins.
copper member
Activity: 2128
Merit: 1814
฿itcoin for all, All for ฿itcoin.
-snip-












It's very likely your API key and secret key was leaked or you have a malware on your computer stealing your private information.
Just out of curiosity, which website did you use the API keys on?

Also, why didn't you disable the withdrawal through API key... this is more secure in case someone lands on your keys because believe me, they will be able to withdraw from your account without even logging in or using 2FA
newbie
Activity: 27
Merit: 0
I was withdrawn from the BITTREX 0.5 BTC exchange. Part of the deposit was in the coin. The part was transferred to the cue ball, and XRP, BCH, ETH were billed with coins. Displayed via API keys. All the keys I have without the right to withdraw. Worth 2fa. There were no rights changes to the keys. This is evident in the MY ACTIVITY account. Login was only from my IP. When outputting through the API-keys, the address of Japan appeared. I am writing in support. They accuse me, do not recognize this possibility of withdrawal. All transactions are. BITTREX does not want to admit his guilt and does not help solve the problem. I know four more people who have withdrawn funds from the exchange in the same way. Please help in the return of funds. Sorry for my English.


https://a.radikal.ru/a15/1903/ea/3acf1702cdbat.jpg

https://d.radikal.ru/d22/1903/93/0477385a74fct.jpg

https://d.radikal.ru/d14/1903/5e/db401381ccd4t.jpg

https://b.radikal.ru/b08/1903/9c/9718b4c408a7t.jpg

https://c.radikal.ru/c23/1903/b7/452d082c39f3t.jpg

https://d.radikal.ru/d00/1903/3f/64c5b7133b25t.jpg
Jump to: