Search content
Sort by

Showing 9 of 9 results by CaLPaR
Post
Topic
Board Service Discussion
Re: Cryptsy account got hacked
by
CaLPaR
on 13/02/2014, 01:44:19 UTC
Quote
Any updates on this?
So far it looks like the guys on Crypty don't have any intention to respond to my support ticket.
As for the address I mentioned before, it seems to belong to Mtgox which isn't very helpful.

I included the original transactions of the withdraws from my account in case anyone is interested:

BTC transaction: 6bcb605dad4c252958c9e33d67fe7e3f91739db0fc126fc01a0ca528404066fa
DOGE  transaction: cda9f2e70c6c898ddb21447324563299e2e07099ab0b8aa21c9af16e8c573f43

Post
Topic
Board Beginners & Help
Re: Hashblaster.com SCAM transactions
by
CaLPaR
on 10/02/2014, 20:28:55 UTC
Quote
Are you sure this address belongs to Hashblaster?
I was wondering who owns this address since my Cryptsy's account balance got wiped out and all of the BTC were transferred to this address.
Post
Topic
Board Service Discussion
Re: Cryptsy account got hacked
by
CaLPaR
on 03/02/2014, 20:45:43 UTC
Quote
Unlike your misfortune, no BTC was actually withdrawn from our account.  2 Billion CENT was sold for LTC, then our ZET was sold for BTC.  The LTC balance was sold for BTC, all ending with a very large and expensive NMC purchase.  Then finally NMC was sold for BTC for a VERY TINY fraction of the worth of the rest of the coins.  The end result is our entire balances of alt coins and btc were essentially wiped out.  No withdrawals were made at all.
Wow, that's a pretty unusual way to steal one's coins. That's the only way I can think right now that would actually enable to deplete account's balance without needing to access its email address, which shows that having a secure email address won't always save you.
I think it's a shame that there is no option to require 2FA for every withdrawal and every trade that I make.
Post
Topic
Board Service Discussion
Re: Cryptsy account got hacked
by
CaLPaR
on 03/02/2014, 20:11:21 UTC
Quote
Once you login, you're asked to enter your two factor authentication details, right? After that, it doesn't ask you until your next login, correct? If this is the case, sounds like a piece of malware just stole the session authentication token (Cookie) and then used that (Maybe in conjunction with relaying the connection through your computer, in case Cryptsy checks the IP it was issued to).
Apparently 2FA is not as secure as I thought. That's probably what happened.

Quote
Do you mind testing something? Withdraw something, verify it, then, without logging out, withdraw something else, tell me if it makes you verify then, in if doesn't, my first theory is looking all the better, if it doesn't, what actually stops him from just deleting the mail after he's done? Do you host your own mail server? Can you get logs?
It requires email verification for every withdrawal. I'm starting to believe that whoever did that actually managed to access my email, verify the withdrawals, and then delete all the withdrawal emails. I'm using an email address from walla.com which turns out to be not so secure. I just was under the impression that by using 2FA my Crypty account is uncrackable. Well, so much for that...
Post
Topic
Board Service Discussion
Re: Cryptsy account got hacked
by
CaLPaR
on 03/02/2014, 13:24:32 UTC
It looks like my BTC went through several addresses and ended here:
1Facb8QnikfPUoo8WVFnyai3e1Hcov9y8T

Does anyone know anything about this address? Can I find where it's from?
Post
Topic
Board Service Discussion
Topic OP
Cryptsy account got hacked
by
CaLPaR
on 03/02/2014, 02:22:09 UTC
About 14 hours ago I had about 700 Cat coins and 500000 Doge coins on my Cryptsy account. I have sold 0.02725061 BTC worth of DOGE and withdraw it to another address. Soon after as expected I received an email to verify the withdrawal.

About 30 minutes later my account got hacked. All of my Doge coins ware withdrawn from my account, All of my Cat coins ware sold to BTC and then they were also withdrawn from my account.

All of this happened while I was using my PC, therefore it can't be a remote desktop program. Secondly, this account has two factor authentication which requires access to my phone, which means that simply having my user name and my password would not help in this case.

The most disturbing thing hare is that I did not receive a verification email for any of these 2 withdrawals. As far as I know after every withdrawal from Cryptsy I'm supposed to get a email to verify the withdrawal, which clearly did not happen. Whoever did this managed to withdraw from my account without needing to access to my email account, which indicates that there is a serious security hole in Cryptsy.

By the time I found out about this all of the transactions ware already confirmed. I opened a support ticket, but I did not receive an answer yet. I just can't wrap my mind around this. How on earth did this happen? He bypassed my two factor authentication, he did it while I way using my PC, and he did it without needing to access my email.

I'm posting this because I'm looking for ideas about how whoever did this managed to accomplish this taking into account everything that I have just said.
Secondly I would like to know if this is a single case, or whether more people have experiences similar to this from Cryptsy.

Post
Topic
Board Trading Discussion
Re: Gekko - a javascript trading bot for nodejs
by
CaLPaR
on 23/01/2014, 01:13:05 UTC
I don't know if this have suggested before, but I'm sure a lot of people would appreciate it you ware to add a support for the exchanges on cryptsy.com.
Cheers.  Grin
Post
Topic
Board Beginners & Help
Re: BTC Guild being DDos'd ?
by
CaLPaR
on 05/07/2011, 23:59:16 UTC
Took the day off from mining.  Smiley

BTW the USeast server if running. Never thought I'd see BTC Guild runing with 351 workers.
Post
Topic
Board Beginners & Help
Re: Introduce yourself :)
by
CaLPaR
on 05/07/2011, 23:40:52 UTC
I have been beating my head against the wall for about 20 minuts before I realized that I can post only in the NEWBIES section.

Just wanted to buy Bad Company 2 with BTC...  Cry