MetaMask / metamask-extension

:globe_with_meridians: :electric_plug: The MetaMask browser extension enables browsing Ethereum blockchain enabled websites
https://metamask.io
Other
11.96k stars 4.89k forks source link

EOS AIRDROP PHISING HACK #3645

Closed filtr0w closed 6 years ago

filtr0w commented 6 years ago

so i was part of this scam

https://www.reddit.com/r/CryptoCurrency/comments/83fk6n/warning_sophisticated_email_scam_regarding_free/

you can see screeenshots of the whole process. the email, the fake news coindesk article, the fake myetherwalleet link, etc. the only thing i did was enter the fake coindesk article, that's all.

all my funds from myetherwallet were transferred that same day to other addresses. i have searched all my history, and the only thing i did was google about this eos aidrop, this led me to the fake coindesk article. however once i was there i realised that they were using a look alike domain for myetherwallet.

at that point i realised it was a scam

1) I DID NOT ENTER THE MEW fake address 2)I DID NOT login to MEW or metamask.

however my funds are gone as you can see here.

https://etherscan.io/address/0xa8e4437feb66e320a76ad0aa9e398716962a5116

things i have done wrong too :

1)i have used my private key to login to MEW wallet before. I DID NOT use it that day. 2)i have signed up for a fake ven airdrop google form where i provided my ethereum address and my email.

the only possible thing that i can think of is that somehow metamask was compromised by this site. however the person posting in reeddit was able to visit this sites without getting compromised. they just look like normal phising sites where they rely on the user providing the data.

jrmoreau commented 6 years ago

If you'd like us to help you review what happened you might want to open a ticket for this so your personal details about this are not discussed in public. support@metamask.io

sqwilso commented 6 years ago

I had the same issue as mentioned above - not sure if there is any feasible solution. All the contents of my ETH wallet were moved to this location - where they haven't been accessed since https://etherscan.io/address/0x98d67bc5ba8e43721972204e5e1e4eaef43cadb1

as a result of this transaction, plus the ones after moving over my tokens https://etherscan.io/tx/0x3b2f84fc6ecc2cdbc28cfa6238d3cc43024246d30faed61ef9f1fc0ee26d785e

I don't know if there is anyway of listing this ETH wallet as containing hacked funds...... 0x98d67bc5ba8e43721972204e5e1e4eaef43cadb1

filtr0w commented 6 years ago

helloo stuart

i am not sure what happened.

basically i havent used metamask in a while, and i was travelling. i opened it again and it didnt ask me for a password as usual, but to create a new wallet.

i used my seed phrase to restore my den but

i cannot access this wallet now

https://etherscan.io/address/0xe9b20242a31b9058bf7a1855ac176a61e1637b2e

what did i do wrong here?

thank you

n.


From: Stuart Wilson notifications@github.com Sent: Thursday, April 19, 2018 2:51 PM To: MetaMask/metamask-extension Cc: filtr0w; Author Subject: Re: [MetaMask/metamask-extension] EOS AIRDROP PHISING HACK (#3645)

I had the same issue as mentioned above - not sure if there is any feasible solution. All the contents of my ETH wallet were moved to this location - where they haven't been accessed since https://etherscan.io/address/0x98d67bc5ba8e43721972204e5e1e4eaef43cadb1

Ethereum Accounts, Address and Contracts https://etherscan.io/address/0x98d67bc5ba8e43721972204e5e1e4eaef43cadb1 etherscan.io The Ethereum BlockChain Explorer, API and Analytics Platform

as a result of this transaction, plus the ones after moving over my tokens https://etherscan.io/tx/0x3b2f84fc6ecc2cdbc28cfa6238d3cc43024246d30faed61ef9f1fc0ee26d785e

I don't know if there is anyway of listing this ETH wallet as containing hacked funds...... 0x98d67bc5ba8e43721972204e5e1e4eaef43cadb1

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/MetaMask/metamask-extension/issues/3645#issuecomment-382722303, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AieCI3xZc82bH7DouhwlhaLh8MYi6o_Iks5tqIhfgaJpZM4Sy9xG.