iotaledger / legacy-wallet-use-trinity-wallet-instead

IOTA Wallet
GNU General Public License v3.0
2.08k stars 414 forks source link

They stole my iotas #424

Open aspinto opened 6 years ago

aspinto commented 6 years ago

I make tow transfers from bitfinex 2017-11-01 11:04 and 2017-11-01 17:36 Tow send in my wallet with the same values but in 2017-11-02 03:57 and 2017-11-02 03:57 captura de tela de 2017-11-02 15-47-03 captura de tela de 2017-11-02 15-47-23

Addresses that robbed me: TEPFXNMBDYESEAHXYYOSJFVSSCAQPZPZYRHKGKDUVEQQWYWWSNOJQIUNYPRXPMQBOFF9QBWIZYVRJKLCWVZDDHLRCW JDFYCEPAXVCTRFBX9REUGUJCBBKYQCSFXKOFRAARFECAGTCLSTQDWERYVXGLGEPYEVC9UBZVVSJJPSSZDSHKYOKGOC

Can you help me recovery my iotas. Please ! Thanks for any help

aspinto commented 6 years ago

Hi wonkytonky, I create the seed in https://iotaseedgenerator.com/

I have received and sended values before update 2.5.3 with this seed and nothing had happened

aspinto commented 6 years ago

Its like a program that get the transaction records e send to other addresses one by one. One person would have made only one single shipment with the total value.

aspinto commented 6 years ago

The desktop app not generate seed

The fowllowing links show to use https://iotaseedgenerator.com/ https://forum.iota.org/t/got-a-sudden-zero-balance-psa-for-aug-2017-snapshot-software-update/3476 https://forum.iota.org/t/problem-changing-from-wallet-2-3-to-2-4v/3484/2

I think a lot of people can be harmed for this problem (trouble)

Sorry! I just trying to recovery my iotas.

ghost commented 6 years ago

Hey, they stole my IOTA aswell:

I generated my seed 2 months ago over CLI on OSX: cat /dev/urandom |LC_ALL=C tr -dc 'A-Z9' | fold -w 81 | head -n 1

Yesterday I downloaded the iota light wallet from: https://github.com/iotaledger/wallet/releases and transfered IOTAS from bitfinex to my wallet. I did not reused any address.

10 min later after my bitfinex transaction someone transferred my IOTAS: https://iotasear.ch/hash/MNWHJJPPZXKNYPLYWMWXRXIADUCOCWABWUBCIRRGAMBYAIWIZFKYJMQYCXXDCAMZINJ9XLIEVXRHJIYBCUVNZQIYJD

looks like the official wallet is hacked. I checked sha256:

openssl sha -sha256 /Users/user/Downloads/IOTA.Wallet-2.5.3.dmg SHA256(/Users/user/Downloads/IOTA.Wallet-2.5.3.dmg)= 5a017f703baf1c0649c805aa9346d546305c4655716a1047fd57304d7815c340

alon-e commented 6 years ago

@zitlo , the address used to receive funds from Bitfinex to - MNWHJJPPZXKNYPLYWMWXRXIADUCOCWABWUBCIRRGAMBYAIWIZFKYJMQYCXXDCAMZINJ9XLIEVXRHJIYBC , was already used twice in the past (this is the third time):

'QAQUL9MREDAROJUATRWHOEIJTDIXVPHWWJZFWRJPDBWEHT9TBJZKRDAUQPKWPPFNVQTCLCNEMFJE99999', 'MNWHJJPPZXKNYPLYWMWXRXIADUCOCWABWUBCIRRGAMBYAIWIZFKYJMQYCXXDCAMZINJ9XLIEVXRHJIYBC', '-2500000', '2017-08-19 14:14:37', 'BT9PEVXE9MFUUOY9AUJCSGE9EHVNUULREBONZCBIEYVEKOSUHCULBHMTLVZHVUYSYIQNFSHYRWSTAWMMX'
'YTRMEEEYLZEOSDKWCQHCQCMYGGECMUITAC9WUNDRWGVXKCNSS9HXDLOBGKZUCHDZDRDBFUKCBAF999999', 'MNWHJJPPZXKNYPLYWMWXRXIADUCOCWABWUBCIRRGAMBYAIWIZFKYJMQYCXXDCAMZINJ9XLIEVXRHJIYBC', '-1721961324', '2017-10-13 00:56:08', '9YCIEBO9GJONFVCHQDBLXYNTPCCVNJTJRGFFWJWLNURZVYXU9H9QUUSAQRHTQNSIYJPCCXAALA9RKHDU9'

can you comment on this?

ghost commented 6 years ago

It looks like, but I know "never use a address twice", I generated a new receive address for every transaction. How can this happen? So someone used this transactions to calculate my private key, shit!

rotilho commented 6 years ago

If someone can calculate your private key they won't steal you they will steal the richest inputs.

Probably your computer is compromised or you used some not trusted seed generator.

ghost commented 6 years ago

yeah, bad bad luck... Shit happens, for me this looks like a bad designed iota app. The app should know this issue and user other receive addresses. My computer isnt compromised and I kept my private key safe. My seed gen is safe too.

hrkaviani commented 6 years ago

all my iota was stolen . what can i do now?