Post
Topic
Board Exchanges
Re: BTER account "hacked", coins drained, account locked, support unresponsive
by
emelac
on 28/08/2016, 01:33:15 UTC
They issued a "Security Alert" on august 24, and required users to change password as well as enabling google authentication. They suspect it was due to phishing sites from (Google, Yahoo, Bing, etc).

What did support say regarding the missing funds? Have you tried submitting a ticket directly from their site?


This is the "Security Alert", but I don't understand how asking everyone to change their passwords is going to solve the problem. You had to get an emailed code from bter to log in through any new IP since last year. Anyone stealing an account had to already control the associated email address to login, so changing a password won't help.

The whole thing sounds suspicious to me, like bter itself might be selectively stealing funds from accounts. Any customer located outside China would find suing bter difficult, or impossible, and all the "stolen" accounts are from customers outside China.

https://bter.com/article/7100

Quote
We recently detected many suspicious user account login attempts and we got several account stolen reports from our users.

Although BTER has a large portion of Chinese users, it's strange that all the affected users are from outside of China.

We suspect that it's related with the phishing sites appear in the English search engines ads (Google, Yahoo, Bing, etc)

or an account list from an English website.

We now require all our users to change the login password at

https://bter.com/resetpw

and the fund password at

https://bter.com/resetfpw

We highly recommend all users to enable Google Authentication to protect yourself from such attack at

https://bter.com/myaccount/totp



Best,

BTER