I 'm the victim.
using tor just want to anonymous.
I'm sure my PC is safe, have not any malicious software
Tor browser downloaded from official website.
I'm sure this is MITM attack.
once I using Tor Browser open BC.INFO, Warned the certificate error , the certificate is ***. cloudflare.com, because BC.INFO use cloudflare CDN service, I also used cloudflare SSL service , so I didnt care Certificate warning , and finally lead to the MITM , and I think the Hacker did not get my password, the transfer based on the transaction history of BC.INFO, and not a one-time sent all BTC of an address .
BTW I'm not the only Victim , You can check the hacker address : 1AaAYSunThcnsMdvgRqfCMKF68KacjM98f click some TXID, You will see all transactions Relayed by IP : Blockchain.info
Sorry for my english.
This is weird, i have some emperience in pen test, and im trying to find the way it happen.
Man in the middle attack is posible if the attack came from the LAN network:
192.168.1.x1 ----poison router ----> 192.168.1.254 -----Victim ----> 192.168.1.x2
But if you was using TOR a crazy idea came to my head, i dont know of is posible to make a MITM in the TOR network, but i think there is no way to make this. only if you are the FBI and you are making the "Operation Torpedo".