Author

Topic: Purse.io HACKED.. (Read 4061 times)

legendary
Activity: 1168
Merit: 1049
October 13, 2015, 04:37:51 PM
#38
it seems everything is back to normal with my account.. the funds are back in my wallet.. it shows up as a refund.. so they were withdrawn..
they are still sitting in the wallet they went to..





 i give them props for a quick and speedy recovery.. i hope they didnt lose too many bitcoins and i hope they fixed whatever issue they had.

Yeah. Their Reddit account (PurseIO) updated that they successfully reimbursed everyone and fixed the issue.

https://www.reddit.com/r/Bitcoin/comments/3oex4p/purseio_denies_bitcoin_theft_despite_compromise/cvx2nzj
legendary
Activity: 1736
Merit: 1006
October 13, 2015, 04:24:15 PM
#37
it seems everything is back to normal with my account.. the funds are back in my wallet.. it shows up as a refund.. so they were withdrawn..
they are still sitting in the wallet they went to..





 i give them props for a quick and speedy recovery.. i hope they didnt lose too many bitcoins and i hope they fixed whatever issue they had.

legendary
Activity: 910
Merit: 1000
October 13, 2015, 11:16:03 AM
#36
Haven't had a problem with them either. What a shame  Angry
legendary
Activity: 994
Merit: 1000
October 13, 2015, 01:45:43 AM
#35
I doubt the coins are in the safe side as they say. If their support email is hacked than there is lots of chances the hacker may have got panel to send bitcoin. Lets see what happen after their mainatainance period.
legendary
Activity: 896
Merit: 1000
Louis Vuitton
October 12, 2015, 11:11:02 PM
#34
Aww man that sucks to hear. I've been using Purse and haven't had a problem
legendary
Activity: 1736
Merit: 1006
October 12, 2015, 11:03:23 PM
#33
Still locked out of my account and waiting to hear from Purse.

me too.. altho i did get an automated email saying possibly tomorrow they will send out a form or something to reply to get your account unlocked..

also the bitcoin is still here
https://www.blocktrail.com/BTC/address/1fZisbHc6rGRoWmMet7n15Sficng5YWbQ

which i dont think is a purse wallet.. as they use wallets that start with 3
legendary
Activity: 1868
Merit: 1023
October 12, 2015, 10:53:24 PM
#32
Still locked out of my account and waiting to hear from Purse.
legendary
Activity: 1736
Merit: 1006
October 11, 2015, 07:01:56 PM
#31

I've never used the site because it doesn't make sense, so forgive me for all the questions. You have your coins on there, and then send them to people who are willing to send you an amount of stuff worth more than the bitcoins are worth off of an amazon wishlist? Can't you just keep the coins yourself until there is a person willing to make a purchase for you?

It seemed to me like people buying coins would be the people with coins on the site, it did not occur to me that people looking to sell coins would leave them there.

how it works is i want something on amazon i make a wishlist for it.
then i put the wishlist on that site and put up an offer based on how much i want to spend basically. i can choose up to 50% off the retail price altho you probably wont ever actually complete that order.
then you fill the order with how many bitcoins you wanted to spend. i usually chose 30% off...

so then someone wants to buy your order they accept the offer and buy your items. then they give the site the tracking info and you wait till it arrives.
then you push the button on the site that says you received items and the system sends them your bitcoins.

it seemed all automated..

your items come with a full warranty, and you get a card in the box with a buy order number that amazon accepts so you can even return them.. altho probably not for cash back.. maybe credit?
ive only had to warranty out one item i got so far and it went smoothly.. i contacted amazon they contacted the supplier and he sent me out a new one.. even got to keep the broken one.
legendary
Activity: 1526
Merit: 1000
October 11, 2015, 06:51:02 PM
#30

yeah i strictly believe in 2fa.. i love it and i wish everyone had at least the text option.

the only email i got from them so far was the canned response they probably sent everyone.

ive contacted support but its the weekend.. i might just make a new account and start over with a fresh email.

i like the site.. its a great idea.. i saved tons of money i would have spent otherwise.

im sure they will send me back the bitcoin.. eventually..

I've never used the site because it doesn't make sense, so forgive me for all the questions. You have your coins on there, and then send them to people who are willing to send you an amount of stuff worth more than the bitcoins are worth off of an amazon wishlist? Can't you just keep the coins yourself until there is a person willing to make a purchase for you?

It seemed to me like people buying coins would be the people with coins on the site, it did not occur to me that people looking to sell coins would leave them there.
legendary
Activity: 1736
Merit: 1006
October 11, 2015, 06:29:55 PM
#29
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?


wonder if they say the coins are safe were to those that didnt lose any Sad


They said they have secured all funds, so i think users funds are safe.
I hope they didn't lie about it

This is impossible.

The OP posted the transaction of coins leaving purse to an address that isn't his that matches up with a transaction that matches the amount in his confirmation email (that he never confirmed). those coins can be replaced, but they can not be secured by purse.

here is the email



the funds are still there
https://www.blocktrail.com/BTC/address/1fZisbHc6rGRoWmMet7n15Sficng5YWbQ

and i still have NO access to purse. the site wont recognize my username.

i know its not safe to leave funds in an online wallet.. but i had active orders and you have to secure them..
also, i have 2fa enabled.. on both purse AND gmail.

nobody can login my email without having to input a code.


was 2fa enabled on purse before this incident?

I believe they are completely at fault, but just to be sure, are there any responses in your sent mail folder responding to these messages?

yeah i strictly believe in 2fa.. i love it and i wish everyone had at least the text option.

the only email i got from them so far was the canned response they probably sent everyone.

ive contacted support but its the weekend.. i might just make a new account and start over with a fresh email.

i like the site.. its a great idea.. i saved tons of money i would have spent otherwise.

im sure they will send me back the bitcoin.. eventually..
legendary
Activity: 1526
Merit: 1000
October 11, 2015, 06:21:50 PM
#28
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?


wonder if they say the coins are safe were to those that didnt lose any Sad


They said they have secured all funds, so i think users funds are safe.
I hope they didn't lie about it

This is impossible.

The OP posted the transaction of coins leaving purse to an address that isn't his that matches up with a transaction that matches the amount in his confirmation email (that he never confirmed). those coins can be replaced, but they can not be secured by purse.

here is the email



the funds are still there
https://www.blocktrail.com/BTC/address/1fZisbHc6rGRoWmMet7n15Sficng5YWbQ

and i still have NO access to purse. the site wont recognize my username.

i know its not safe to leave funds in an online wallet.. but i had active orders and you have to secure them..
also, i have 2fa enabled.. on both purse AND gmail.

nobody can login my email without having to input a code.


was 2fa enabled on purse before this incident?

I believe they are completely at fault, but just to be sure, are there any responses in your sent mail folder responding to these messages?
legendary
Activity: 1736
Merit: 1006
October 11, 2015, 06:15:56 PM
#27
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?


wonder if they say the coins are safe were to those that didnt lose any Sad


They said they have secured all funds, so i think users funds are safe.
I hope they didn't lie about it

This is impossible.

The OP posted the transaction of coins leaving purse to an address that isn't his that matches up with a transaction that matches the amount in his confirmation email (that he never confirmed). those coins can be replaced, but they can not be secured by purse.

here is the email



the funds are still there
https://www.blocktrail.com/BTC/address/1fZisbHc6rGRoWmMet7n15Sficng5YWbQ

and i still have NO access to purse. the site wont recognize my username.

i know its not safe to leave funds in an online wallet.. but i had active orders and you have to secure them..
also, i have 2fa enabled.. on both purse AND gmail.

nobody can login my email without having to input a code.

its a good chance i was one of the first ones to contact support in the chat they have to say my funds just left my wallet.. because as soon as he replied we will check it out, the site went offline for "maintenance"
legendary
Activity: 1526
Merit: 1000
October 11, 2015, 12:38:03 PM
#26
My coins are still in my purse wallet. No 2fa on there. I do have 2fa on my email tho.

It could be possible that the coins are still under Purse's control in that they had the accounts set up in multi-sig so the money could not be transferred off-site, only to another wallet under their control. Until we know more we can't say either way what the status of those 'hacked' coins are.

So they received a withdrawal request, then moved the coins to a wallet they control and sent a notification that the withdrawal was successful? On what planet does that come close to making sense?
legendary
Activity: 924
Merit: 1000
October 11, 2015, 12:18:22 PM
#25
Always stick to the cardinal rule never trust any website with your coin. Only keep your coin on the site while using its services never for storage.
newbie
Activity: 43
Merit: 0
October 11, 2015, 10:17:30 AM
#24
My coins are still in my purse wallet. No 2fa on there. I do have 2fa on my email tho.

It could be possible that the coins are still under Purse's control in that they had the accounts set up in multi-sig so the money could not be transferred off-site, only to another wallet under their control. Until we know more we can't say either way what the status of those 'hacked' coins are.
legendary
Activity: 1526
Merit: 1000
October 11, 2015, 09:43:40 AM
#23
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?


wonder if they say the coins are safe were to those that didnt lose any Sad


They said they have secured all funds, so i think users funds are safe.
I hope they didn't lie about it

This is impossible.

The OP posted the transaction of coins leaving purse to an address that isn't his that matches up with a transaction that matches the amount in his confirmation email (that he never confirmed). those coins can be replaced, but they can not be secured by purse.
legendary
Activity: 1736
Merit: 1006
October 11, 2015, 04:24:33 AM
#22
unfortunately i still cant log in. it says i need to contact customer support.. i sent them an email but no reply yet.
my bitcoin hasn't moved from the wallet it got sent to, so who knows.
legendary
Activity: 1694
Merit: 1003
October 11, 2015, 04:18:51 AM
#21
Hope purse.io don`t GOX away with your BTC or Money but its a serious matter that needs to be taken care off quickly.
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 08:32:06 PM
#20
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?


wonder if they say the coins are safe were to those that didnt lose any Sad
legendary
Activity: 1526
Merit: 1000
October 10, 2015, 08:19:40 PM
#19
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..


That was sarcasm. How can all the coins be accounted for if the transaction of your coins leaving your account i real?
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 08:10:17 PM
#18
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
yeah, i guess we will see.. its good news tho..
legendary
Activity: 1526
Merit: 1000
October 10, 2015, 07:58:21 PM
#17
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.



All accounted for, even though the transaction ids in the emails appear to be legitimate. Of course.
hero member
Activity: 798
Merit: 1000
Move On !!!!!!
October 10, 2015, 07:53:38 PM
#16

yep. specially since they took the site down..

usually when you email support and say hey someone stole my password they email you back saying too bad..
not pull the plug Sad

I don't know if they're pulling the plug. The site itself is still up. I think they are just trying to fix the problem. What I am concerned is the lack of a public notice that they have been hacked. At this point, it looks a little scammy.

Well maybe it's not fair to blame them yet for the lack of communication. In the midst of the crisis you are trying to save what you can save, and you leave public notices for later. At least I would do it like this. When you get hacked, every second is important.

Edit: There you go a post above mine, a public notice!
newbie
Activity: 3
Merit: 0
October 10, 2015, 07:51:45 PM
#15
from Reddit:

We have received word today of unauthorized password reset notification emails. We are aware of the issue and have secured all funds. All user balances are accounted for and upon completing our investigation, service will resume shortly.

hero member
Activity: 728
Merit: 500
October 10, 2015, 07:41:05 PM
#14
it just happened.. like literally 5 minutes before i posted..

i watched my bitcoins leave my wallet Sad

I guess that's not enough time for them to put up an official response.
legendary
Activity: 1526
Merit: 1000
October 10, 2015, 07:35:17 PM
#13
I'm shocked that this carders paradise would eventually steal everyone's coins get hacked.
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 06:21:40 PM
#12
This sounds like a very serious security flaw and I'm willing to bet that all your bitcoins wind up in the same wallet. I would suggest we all sit back and watch cautiously at Purse, because this is no slight issue .
OP I am sorry for your loss, and everybody else who's experienced loss. thank you for informing the community!

the wallet that my coins went to has just 2 transactions.
https://www.blocktrail.com/BTC/address/1fZisbHc6rGRoWmMet7n15Sficng5YWbQ

looks like they both came from purse hot wallets.
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 06:18:57 PM
#11

yep. specially since they took the site down..

usually when you email support and say hey someone stole my password they email you back saying too bad..
not pull the plug Sad

I don't know if they're pulling the plug. The site itself is still up. I think they are just trying to fix the problem. What I am concerned is the lack of a public notice that they have been hacked. At this point, it looks a little scammy.

it just happened.. like literally 5 minutes before i posted..

i watched my bitcoins leave my wallet Sad
hero member
Activity: 518
Merit: 500
October 10, 2015, 06:14:23 PM
#10
This sounds like a very serious security flaw and I'm willing to bet that all your bitcoins wind up in the same wallet. I would suggest we all sit back and watch cautiously at Purse, because this is no slight issue .
OP I am sorry for your loss, and everybody else who's experienced loss. thank you for informing the community!
hero member
Activity: 728
Merit: 500
October 10, 2015, 06:11:44 PM
#9

yep. specially since they took the site down..

usually when you email support and say hey someone stole my password they email you back saying too bad..
not pull the plug Sad

I don't know if they're pulling the plug. The site itself is still up. I think they are just trying to fix the problem. What I am concerned is the lack of a public notice that they have been hacked. At this point, it looks a little scammy.
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 06:06:48 PM
#8
My bitcoins were also withdrawn, as was another person on reddit/r/bitcoin.

https://www.reddit.com/r/Bitcoin/comments/3o9ju8/my_purseio_account_was_compromised/
Well this is weird then. I would have called this a classic "my computer got hacked but I blame the service provider" scenario but it's unlikely that you all got compromised at the same time so im calling a security issue on their part. This, or its an inside job and someone inside purse is running with your money.


yep. specially since they took the site down..

usually when you email support and say hey someone stole my password they email you back saying too bad..
not pull the plug Sad
legendary
Activity: 1610
Merit: 1183
October 10, 2015, 06:02:24 PM
#7
My bitcoins were also withdrawn, as was another person on reddit/r/bitcoin.

https://www.reddit.com/r/Bitcoin/comments/3o9ju8/my_purseio_account_was_compromised/
Well this is weird then. I would have called this a classic "my computer got hacked but I blame the service provider" scenario but it's unlikely that you all got compromised at the same time so im calling a security issue on their part. This, or its an inside job and someone inside purse is running with your money.
legendary
Activity: 1868
Merit: 1023
October 10, 2015, 05:56:30 PM
#6
My bitcoins were also withdrawn, as was another person on reddit/r/bitcoin.

https://www.reddit.com/r/Bitcoin/comments/3o9ju8/my_purseio_account_was_compromised/
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 05:53:30 PM
#5
I've used Purse.io a few times and I haven't had any problems but i don't know maybe your computer has been compromised?
nope.. the site is down for maintenance now..


it uses google authy to log in.. so i cant see how my computer would generate the withdraw link and then use my phone to authenticate it..


i might add that my google authy phone is NOT my current in use phone but a backup phone that i use just for google authy. it has no sim card in it.
Well that's a problem, isn't it? The site itself is up, but when I try to log in, I get an error "Server down for maintainence. Please check back shortly"

yes and my bitcoins were withdrawn from my account on that site.. per the email i got, that i didnt do.


 logo
Withdrawal

You withdrew 171.152 mBTC.

34208cb232c35717820c72ea7b1c76f6874b6cda6f12a946f91e628754719ccb
View transaction

i checked the transaction and its real. Sad
hero member
Activity: 728
Merit: 500
October 10, 2015, 05:49:44 PM
#4
I've used Purse.io a few times and I haven't had any problems but i don't know maybe your computer has been compromised?
nope.. the site is down for maintenance now..


it uses google authy to log in.. so i cant see how my computer would generate the withdraw link and then use my phone to authenticate it..


i might add that my google authy phone is NOT my current in use phone but a backup phone that i use just for google authy. it has no sim card in it.
Well that's a problem, isn't it? The site itself is up, but when I try to log in, I get an error "Server down for maintainence. Please check back shortly"
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 05:24:24 PM
#3
I've used Purse.io a few times and I haven't had any problems but i don't know maybe your computer has been compromised?
nope.. the site is down for maintenance now..


it uses google authy to log in.. so i cant see how my computer would generate the withdraw link and then use my phone to authenticate it..


i might add that my google authy phone is NOT my current in use phone but a backup phone that i use just for google authy. it has no sim card in it.


legendary
Activity: 1445
Merit: 1000
October 10, 2015, 05:23:29 PM
#2
I've used Purse.io a few times and I haven't had any problems but i don't know maybe your computer has been compromised?
legendary
Activity: 1736
Merit: 1006
October 10, 2015, 05:13:25 PM
#1
so i had a few purchases up and i was waiting for a buyer when i just received an email saying i requested to withdraw all of my funds.
now, in this email it says to click the link or use the code to complete the withdraw, or email support.. which i did contact support..

a few seconds later i get an email saying thanks for withdrawing my funds.. WHAT?? i didnt click any links or typed in any codes.. i contacted SUPPORT.. which wasnt a website LINK its [email protected]


now my account with PURSE has EVERY security thing turned on.. even 2fa..


so it looks like someone has figured a way to generate these links.. probably a security flaw or something..


EDIT.. it seems they are working to fix the issue.. they also say the coins were sent to a safe wallet.. and not lost.
Jump to: