Post
Topic
Board Service Discussion
Re: BeCareful guys someone Hack My LocalBitcoin Account & withdraw 0.78BTC
by
singpays
on 18/05/2015, 12:21:48 UTC
Sorry for your loss buddy, it is always advised that never keep your coins in an exchange for too long, just get in and get out. LBC usually is very safe and I know people who have been using it from a long time and never had any problems or theft.

Tell me something..Do you use VPN/Tor or something like that?

Because I just learned this recently that even if you had 2fa enabled and you use VPN or TOR your account may still get compromised through MITM (Man-in-the-middle) attack.

Read this:
I could come up with 10 ways to "hack" 2FA, but the relevant risk for VPN is the man-in-the-middle attack (MITM) and 2FA does not help for that. Basically all the traffic goes through the VPN so if the hacker controls the VPN he could show you a fake PD site (copy) and see the passwords you fill in, but also the 2FA code. Both can be send to the real PD site under the attackers control - and he can make withdrawals etc. Basically 2FA does not help at all against MITM. This is the same reason 2FA doesn't work against phishing sites (also fake site that gets your password/2FA code and uses it immediately.)

HOWEVER, the description in https://bitcointalk.org/index.php?topic=1043827.0 seems pretty correct. All you have to do is make 100% sure you are connected to https://primedice.com and there is nice little lock icon next to it. That topic has some more details. This way the traffic is encrypted between you and the real PD site.

Still I do recommend everyone to use 2FA whenever there is a decent amount of money involved (or your account is worth a lot to you.)
no im not using vpn and others services . only for hack my localbitcoin account and not touch any folder and browers  , hackers using on Mozilla , im using on chroma i contact support on localbitcoin he reply me your withdraw same ip Sad that wrong investigation Sad