Hi,
A spanish user has recently seen his account "compromised" via secret question. The user is
Antuam and the related attack can be seen in the
seclog by searching his username. He contacted me in private asking for help. Now, I don't usually do this but this is quite a trusted member in the spanish community, the go-to escrow for many people. There was even a successful
gathering (in spanish) to collect some coins soon after he was scammed in an escrow operation.
I said "compromised" in quotes because I recently learned that accounts 0wned via secret question aren't actually recovered, but placed on hold. He claims to have sent a couple of emails to the address provided, to no avail.
Since the account wasn't actually hacked, I guess the address 1AV5KdgLzouXN5Zi4k6W3MzrA8wh43mHyF that can be seen in this user's profile is still valid, as the attacker wouldn't have had the choice of altering it. I asked him to sign a message using this address, and he sucessfully did so.
-----BEGIN BITCOIN SIGNED MESSAGE-----
Hi, this is Antuam, https://bitcointalksearch.org/user/antuam-88617.
I lost access to my account.
In this message I declare that I didn't try to answer the secret question to
my account. The attempt that appears in the seclog at 2015-07-25 09:18:53+0000
is not mine. I sent two emails to the address I was provided, but
unfortunately both went unanswered.
I'd like to regain access to my account, with my usual password. I'll change
my secret question as soon as possible.
I understand my account wasn't accessed by the attacker, thus the address I
have in my profile is valid for proving my identity. Therefore I'm signing this
message with that address.
Thank you,
-----BEGIN SIGNATURE-----
1AV5KdgLzouXN5Zi4k6W3MzrA8wh43mHyF
IDLc/ytA8XkO2cQmRJnzQZMvwAdjfd+BklPBckbeaioLMpNPJv8R4JsEJtIBXba4VmKxZPaw9Tjj/JhsG5lyRTw=
-----END BITCOIN SIGNED MESSAGE-----
The SHA256 sum of the message is cc7ada58bb79c3a8ff89001666acc1039813faa8b49409f173866b0e67a910d9. I verified it from a bash shell:
$ bitcoin-cli verifymessage 1AV5KdgLzouXN5Zi4k6W3MzrA8wh43mHyF 'IDLc/ytA8XkO2cQmRJnzQZMvwAdjfd+BklPBckbeaioLMpNPJv8R4JsEJtIBXba4VmKxZPaw9Tjj/JhsG5lyRTw=' "$(cat file)"
true
If an admin could step in and do the necessary magic for the account to return to its owner, or for allowing him to do a password reset, or whatever
I'm sure he'd be very grateful.
Thanks!