Author

Topic: Just got my LTC QT wallet hacked (Read 1052 times)

newbie
Activity: 36
Merit: 0
February 22, 2014, 08:07:59 AM
#14
Pro tip for windows users (oxymoron?) - restrict access on your user accounts

http://www.tomsguide.com/us/standard-accounts-stop-malware,news-18326.html

It's certainly a good idea to run with the least privilege possible, but the article isn't quite accurate. The report in question was speaking about Microsoft software exploit attempts being mitigated, not people just running malware they find posted on a web forum. Most modern malware has moved beyond requiring admin rights. The trojans install themselves to user-owned folders and persist via user-writable registry keys.

For a wallet stealer, persistence isn't even required, and your wallet.dat file is lying right there in a user folder for the taking. It might need to persist if it uses a keylogger to capture your passphrase since it doesn't know when you will be typing/pasting that in, but as I mentioned, malware can persist post-reboot without needing admin rights.

So even though the advice is good for some cases, in the case of running random programs posted to Bitcointalk, it won't help you at all.
legendary
Activity: 1456
Merit: 1001
This is the land of wolves now & you're not a wolf
February 21, 2014, 09:13:25 PM
#13
Has it completely synced? Seems like a hacker would wait until you have a larger balance than 1.99 LTC in your wallet before he stole it..
newbie
Activity: 56
Merit: 0
February 21, 2014, 03:46:43 PM
#12
It's happened to my other account before. It's a possible RAT on your computer and keylogger.

Download "darkcomet rat remover tool" on the googles.
Scan your system.
Let me know.
full member
Activity: 140
Merit: 100
February 21, 2014, 03:18:17 PM
#11
Pro tip for windows users (oxymoron?) - restrict access on your user accounts

http://www.tomsguide.com/us/standard-accounts-stop-malware,news-18326.html
newbie
Activity: 36
Merit: 0
February 21, 2014, 01:40:48 PM
#10
OSX and key logger... I hope that's not the case

Cross-platform keyloggers are already out there, I've seen someone using Adwind RAT to steal wallet files in this forum already (thread got removed).

http://www.crowdstrike.com/blog/adwind-rat-rebranding/index.html
newbie
Activity: 18
Merit: 0
February 21, 2014, 11:24:03 AM
#9
Possible keylogger?

Let me guess. The operating system is Microsoft Windows.

no its osx

it has to be a key logger


OSX and key logger... I hope that's not the case
legendary
Activity: 2674
Merit: 3000
Terminated.
February 21, 2014, 11:14:51 AM
#8
Possible keylogger?

Let me guess. The operating system is Microsoft Windows.
It is safe as long as you know how to correctly use it.
legendary
Activity: 2632
Merit: 1023
February 21, 2014, 11:05:45 AM
#7
Possible keylogger?

Let me guess. The operating system is Microsoft Windows.

no its osx

it has to be a key logger
newbie
Activity: 18
Merit: 0
February 21, 2014, 11:04:54 AM
#6
I just upgraded to the latest LTC client, from the beta and made a transfer.

is there an unconfirmed transaction that was sent without a transaction fee?
newbie
Activity: 40
Merit: 0
February 21, 2014, 11:04:11 AM
#5
I just saw 1.99 LTC get taken out of my wallet.

I just upgraded to the latest LTC client, from the beta and made a transfer.

Walked back into my room to see 1.99 LTC being transferred

I have an encrypted wallet, which means they must have seen my password as I typed it....or something else

weird thing is I use coin control and I can see where this coin came from as I have all coins of particle addresses

and the from address does not appear in my wallet that I can see?

I does appear to have decrimented my control though

freaking out now...!

Just consider this a lesson learnt. It could have been much worse - count your blessing you didnt have more stored on there. Always use paper wallets.
legendary
Activity: 2282
Merit: 1050
Monero Core Team
February 21, 2014, 11:03:43 AM
#4
Possible keylogger?

Let me guess. The operating system is Microsoft Windows.
legendary
Activity: 2674
Merit: 3000
Terminated.
February 21, 2014, 10:58:54 AM
#3
Possible keylogger?
legendary
Activity: 1260
Merit: 1029
February 21, 2014, 10:49:33 AM
#2
OR maybe it's just sync problem....
legendary
Activity: 2632
Merit: 1023
February 21, 2014, 10:47:55 AM
#1
I just saw 1.99 LTC get taken out of my wallet.

I just upgraded to the latest LTC client, from the beta and made a transfer.

Walked back into my room to see 1.99 LTC being transferred

I have an encrypted wallet, which means they must have seen my password as I typed it....or something else

weird thing is I use coin control and I can see where this coin came from as I have all coins of particle addresses

no located the address

and the from address does not appear in my wallet that I can see?

It does appear to have decrimented my balance though

freaking out now...!

transaction

http://block-explorer.com/address/LPuJg4jQniASXs3ahknmDJutijtog35SAp
Jump to: