Post
Topic
Board Project Development
Re: [coinb.in] Lost/Stolen BTC and BCH
by
hroub
on 21/05/2018, 23:16:11 UTC
I just got 0.048049 BTC lost/stolen because I entered my private keys online trying to sign transactions to spend 0.1999 BTC I had stuck in a 3-of-3 multi-sig address. I managed to receive only

0.131 and 0.008 from https://blockchain.info/tx/bcbd90c0a4d198206865b8cccb227d6166d9b78b3c45d4ee66f8d83c6b69422f

and then from the 0.06 (that wasn't created by me), I received 0.011951 from https://blockchain.info/tx/fea862bdc6e827a0b25ad2d53a64cc3b5d408e27011a01adfbef165b643e8219

The remaining 0.0480377 BTC was sent to https://blockchain.info/address/1KT7sG84birTF2YvW5yP7G4NPeMs7Fcdbh and is lost/stolen

Also, they stole ALL of my 0.1999 BCH that was in https://blockdozer.com/address/33RZTwkqqixKySFim1oSXVcFFBAPUiBwLG

2 out of 3 outputs are yours: 3Lzs3s6p (0.131 BTC) and 1MoTG1qn (0.008 BTC)
but the 3rd isn't? however you've received 0.011951 BTC back to your address 3Lzs3s6p
so the thief sent you back 0.011951 BTC and only stole 0.0480377 BTC
this just doesn't make sense, and why wouldn't he just steal all of them at the first chance he got?
I've been thinking about that and I have a few theories, but it doesn't change the fact that although 0.0480377 BTC was stolen, all the BCH was stolen!
One reason could be that the perpetrator was coinb.in site itself and did that so it can ask the same question you did as self-defense and keep me occupied (trying to figure out what happened) while they steal all the BCH and other forks.

how exactly you created the multisig address in the first place? in 2015
Using Dark Wallet stealth addresses. The three participants (not stealth) can be seen under RELATIONS tab in https://oxt.me/address/33RZTwkqqixKySFim1oSXVcFFBAPUiBwLG
BTW feel free to check out https://www.reddit.com/r/Bitcoin/comments/8i1ev8/help_please_i_have_btc_stuck_in_dark_wallet_080/ Your questions are answered here as well as more info.

why 3-of-3 multi-sig? do you hold all the private keys?
I was a newb back then (still not a pro currently) and was experimenting with Dark Wallet and multi-sig. Of course I have the 3 private keys and that's why I was able to sign and broadcast the transaction with all 3 private keys.

and how did you compose/sign the transaction before broadcasting it?
1) Samurai Wallet dev gave me a redeem script for my multi-sig wallet.
2) I went to https://coinb.in/#newTransaction
3) Entered the redeem script and clicked on Load
4) I entered my outputs and amounts as seen in this screenshot: (screenshot was taken during the process, as I was preparing a guide to help others trying to do the same as me in the future)

5) I recorded the encoded transaction from above and went to the Sign tab (https://coinb.in/#sign)
6) I signed my transaction with all three private keys, one-by-one
7) then I broadcasted the 3 signed transactions
8 ) 0.06 BTC went to the unauthorized output causing 0.0480377 BTC to go "poof" as well as the full 0.1999 BCH amount

edit: just noticed... both BTC and BCH transactions used the same tx fee of 0.0009
As seen in the above screenshot, the tx fee that I assigned was 0.00001 BTC which was supposed to be 4 sats/byte and more than enough at the time. 1 sat/byte would have worked too...
Thank you for your input.

EDIT May 23rd, 2018:

After some further research, I discovered that someone else other than coinb.in may have had access to a private key.
I will update here once I compile some proof and reveal the identity of the scam artist. Sorry if my original post implied that coinb.in was the perp as it doesn't seem very likely anymore.  Undecided