Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Meta Mask Hacked? #3132

Closed
tarseb90 opened this issue Jan 30, 2018 · 61 comments
Closed

Meta Mask Hacked? #3132

tarseb90 opened this issue Jan 30, 2018 · 61 comments

Comments

@tarseb90
Copy link

tarseb90 commented Jan 30, 2018

Hello Metamask ,
i think that there is a security gap in your extension , someone stolen my money , he stole the 2 addresses registred in metamask ,
Despite the fact that I never saved my password anywhere ,i used the Metamask only , I saw that another account had taken all of the Ethereum out of my wallet and transferred it to his.

the transactions addresses is below :

https://etherscan.io/tx/0x1598105716b358e4c657ae162988af3dd41966a23723ec09fe191fe5d64ef502
https://etherscan.io/tx/0xfb2d5f1e73a435ca374f52cb2e814cbc203e8ff7bbfe468a3e273169e4486ffa

and this is the address that stoled my money 👍

https://etherscan.io/address/0x0a585000cee5d93e64dbc37a390f87b27bb41dd0

@tmashuang
Copy link
Contributor

tmashuang commented Jan 30, 2018

Without any additional information provided on a public thread, such as transaction logs or knowledge of phishing sites that may or may not have been visited, we are not able the pinpoint the cause of the issue. If you have any additional sensitive information please send it to support at metamask dot io

@iamjaime
Copy link

iamjaime commented Mar 2, 2018

I'm encountering the same exact issue! My account was completely emptied out! I got robbed for almost 1ETH.

It's happening ONLY to the non-loose accounts on meta mask!

@tmashuang
Copy link
Contributor

@leekt
Copy link

leekt commented Mar 16, 2018

I'm encountering same issue too. I've sent 48 ether to my wallet and someone sent 4.xx ether to another wallet and spent 43.xx ether as txfee and it was first use this time but transaction history says it has been used since 133days ago

0x627306090abaB3A6e1400e9345bC60c78a8BEf57
this is my wallet address

@tmashuang
Copy link
Contributor

tmashuang commented Mar 16, 2018

@leekt216 seems that is a Ganache address that is used for testing purposes. Which is the default seed phrase for Ganache and is available for everyone that has installed it.
http://truffleframework.com/docs/advanced/truffle-with-metamask
Around half way down, there is a warning when sending ETH to any addresses that are generated by this default seed phrase on the Main Ethereum Network.

@Mijako
Copy link

Mijako commented Apr 6, 2018

Hi guys, did you succeed to recover any tokens from your Metamask? It happened to me the same. First in the morning l realised l don’t have any Neurochain token that l have just bought, then within an hour after l opened my Metamask, the rest all disappeared, 0 balance. I am writing emails to support, l did whatever they suggested to me but nothing helped. I think they hacked me!

@tarseb90
Copy link
Author

tarseb90 commented Apr 6, 2018

i will never use Metamask for ever , and i will make a video in my youtube channel with 132k followers and beware them . Metamask not secure anymore . You have to resolve this big problem and compensate our money .

@Mijako
Copy link

Mijako commented Apr 6, 2018 via email

@leonlee723
Copy link

Me too. I trun in eth Metamask. At once these eth were truned out to 0x2d7311279A3ba818Db2aD84eED09324A2577188A. All records of 0x2d7311279A3ba818Db2aD84eED09324A2577188A on etherscan is in. 0x2d7311279A3ba818Db2aD84eED09324A2577188A is thife.

@Mijako
Copy link

Mijako commented Apr 10, 2018 via email

@tarseb90
Copy link
Author

can you give me the email that you used ?

@Mijako
Copy link

Mijako commented Apr 10, 2018 via email

@alacrity26
Copy link

@Mijako mind sharing your ticket number on support@metamask.io ?

@Mijako
Copy link

Mijako commented Apr 10, 2018 via email

@alacrity26
Copy link

@Mijako Thanks. From ticket number 12265, it seems like you were able to restore your MetaMask wallet, after (unintentionally I assume) creating a new wallet, and found your original accounts unseen. Glad you were able to restore successfully.
For future/user issues, you could send your queries to support@metamask.io again, (though I hope you'll not face any issues in your MetaMask transactions anymore). Thanks again to help clarifying!

@Mijako
Copy link

Mijako commented Apr 11, 2018 via email

@ProZack39
Copy link

I have had the Same thing Happen.. It even says Phishing address on the on the OUT address..

What can I do?

@Mijako
Copy link

Mijako commented May 7, 2018 via email

@ProZack39
Copy link

EVERYONE PLEASE EMAIL METAMASK!!!!

@Mijako
Copy link

Mijako commented May 7, 2018 via email

@Blackstuntman
Copy link

my metamask wallet was hacked also! I sent ethereum from stocks.exchange to my metamask wallet but only received a small portion of my withdrawal so I checked the etherscan transaction and noticed that over two hundred dollars $200.00 of my withdrawal had been sent to another ethereum address before it ever reached my metamask wallet. I contacted metamask about this matter and they are not taking responsibility for my fund's being stolen! stating that I must have visited a phished site, or I have malware installed on my PC which both are not true! I will not use metamask anymore until this matter is resolved and will continue to inform metamask & ethereum user's that metamask is not safe and obviously have a serious bug in they're security feature that they refuse to be held accountable for.

https://etherscan.io/tx/0xe1553296e99490d9f675f61c17a5db359ccbc6ca397368bfdb09a00319775cfb

https://etherscan.io/tx/0xe1553296e99490d9f675f61c17a5db359ccbc6ca397368bfdb09a00319775cfb

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman this is not enough information to determine what happened but when you say

noticed that over two hundred dollars $200.00 of my withdrawal had been sent to another ethereum address before it ever reached my metamask wallet.

This suggests that it's not an issue with metamask, as metamask cannot interfere with sent funds before their arrival.

If you want further diagnosis you'll need to provide more information about your accounts, which is for the exchange and which is from metamask. I recommend you do that privately via the support email thread you started.

Malware and phishing targeting cryptocurrency users are extremely common these days, we've seen many users with cases that were infected and did not realize it. While I'm not sure that's your case (they likely would have taken everything), you should take care to properly identify the source of the anomolous transaction to ensure you are safe.

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@prozak39

get them to lock my account

We do not control anyone's account and are unable to do this. This lack of centralized control is what draws a lot of people to cryptocurrency. However the responsibility of security and understanding comes with that, and it's a lot to take on. If you'd like someone to manage your private keys for you, I recommend a bank-like enetity such as coinbase.

@Blackstuntman
Copy link

Blackstuntman commented May 22, 2018 via email

@Blackstuntman
Copy link

Blackstuntman commented May 22, 2018 via email

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@Blackstuntman
Copy link

And the Thief's are now removing fund's from that account because now it only shows a little over 80,000.00 dollars in ethereum asset's where as two days ago it was over 1,000,000.00!

@Blackstuntman
Copy link

Blackstuntman commented May 22, 2018 via email

@Blackstuntman
Copy link

Blackstuntman commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

I really think Metamask has some involvement. They continue to let this Happen.

we don't have any control of user accounts or the blockchain

THESE PEOPLE STEAL FROM THIER CUSTOMERS

@ProZack39 we dont have any customers, we are an open source wallet
if you don't want to use metamask some other options are parity, mycrypto, myetherwallet, status.im, cipher, toshi

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman

Just simply check my etherscan activity!

its difficult to review etherscan without knowing what what addresses are what

is 0x0f85ffa9c291a2b4ee5f0647725c7c41e5d6981a your metamask address? or a different ethereum address you own?

@Blackstuntman
Copy link

@ProZack39 how do I move tokens from Dex without going through metamask?

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39 did you submit your metamask state logs to the support email? helps investigate what happened

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@Blackstuntman
Copy link

@kumavis yes that's my metamask wallet address. Just follow the most recent transactions from a couple of days ago, because I haven't used metamask since because I'm too afraid to, and you will see exactly what happened.

@kumavis
Copy link
Member

kumavis commented May 22, 2018

how do I move tokens from Dex without going through metamask?

@Blackstuntman likely the best way is to import your seed phrase into another ethereum browser like mist, status.im, parity

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman did you provide your metamask state logs to the support email thread?

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman having the state logs might help verify, but it looks like you might have approved the tx (the ~$200) earlier but it could not execute because you did not have enough ether. After receiving ether here, the tx was able to execute and went through.

That unexpected behavior is discribed here https://metamask.helpscoutdocs.com/article/37-ghost-accounts-ether-sending-away-whenever-funding-an-account

the empty account + sweep on retrieval seen here
https://etherscan.io/address/0x090b0ca0b824b1bc7e67df944fc9c63989e92ba0
is typical of a centralized exchange deposit flow. do you remember sending eth to an exchange recently?

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

State logs can be downloaded from the settings menu with the "Download State Logs" button

image

Be sure to email them to support and not post them in a public place like this github thread

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39 its really hard to follow your situation in this thread of lots of users. Please send your state logs to support@metamask.io

tell me your email so i can find your support thread

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39 does this "free airdrop" advertisement look familiar?

https://etherscan.io/address/0x903bb9cd3a276d8f18fa6efed49b9bc52ccf06e5#comments

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39 ok I've found the txs where your tokens were sent out

here is the first of them. Did you ever participate in an "airdrop" where you had to give your private key or seed phrase to the website? we've seen those before

this would have required either

  1. giving your seedphrase / private key to a website
  2. manually approving all of these transactions (possibly by being told they were doing something else)

@kumavis
Copy link
Member

kumavis commented May 22, 2018

Unless you think there may be a Ending where I get my funds back I'd rather not waist more time on it

there's no way to recover these funds. but learning what went wrong could help prevent this in the future.

@Blackstuntman
Copy link

@kumavis I've considered this explanation but can't see it being a valid reason for over $200.00 to have gone missing from my withdrawal of over $300.00 from stocks.exchange. because I only use idex and even if the miner fees pilled up causing 'ghost accounts' it would have never accumulated to over 200.00. I'm new to using metamask as well as ethereum so I don't have many transactions in etherscan, the transaction fees are only cents. You can add up all the transaction fees and it doesn't come close to over $200.00 in ethereum fees

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman not $200 in fees but just the amount required to pay for the tx ($6.57 fees + ~$200 value transfer) that you would have earlier approved, perhaps days before

basically the approved tx sits around waiting for you to be able to pay for it

i think its very likely that it was a late but successful deposit into an exchange like shapeshit/coinbase/poloniex/etc

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@Blackstuntman
Copy link

No not at all. Wouldn't the identity of the exchange be identified via etherscan if I had? The only exchange I ever sent anything to is idex and that show's where I sent the 0.1 whatever ethereum $131.00 to iDex. I don't know what the hell happened so what's up with the account that my 0.3 ethereum was sent to? Do you see anything abnormal about that account? And why would my 0.3 ethereum even go to that address it's not an exchange. Then they sent it to another ethereum address with over 1 million dollars in ethereum assets and now they are moving those assets in fear that they will be confiscated. Metamask really let me down they better step up! if they can't reimburse user's they should shut down or increase security. I want my damn fund's back!

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39
Ok so my current guess is that it was part of the 0-eth airdrop. You might have approved multiple 0-eth transactions that were actually each token transfers. This would have been subtle and hard to detect from the metamask confirmation screen as it only shows estimated cost of ether transferred. The new version of metamask has first-class support for tokens and shows a special token confirmation screen and attempts to estimate USD value of the token transfer.

If true, this is more advanced than your typical phishing scheme but entirely possible. The phishing arms race is really active right now in cryptocurrency and its hard to stay ahead. I would suggest staying away from sketchy "free money" websites while things are still wild-west.

@ProZack39
Copy link

ProZack39 commented May 22, 2018 via email

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@Blackstuntman

Wouldn't the identity of the exchange be identified via etherscan if I had?

no not necesarily. exchanges generate hundreds of thousands of temporary one-use accounts all the time, and don't publicly advertise that they belong to the exchange.

Metamask really let me down they better step up!

If you'd like additonal help, you'll need to submit your metamask state logs to metamask support

@kumavis
Copy link
Member

kumavis commented May 22, 2018

@ProZack39

It was an eos Airdrop.

Likely it was a fake site pretending to be an eos airdrop. There's a lot of those.

@kumavis
Copy link
Member

kumavis commented May 22, 2018

If you have further questions, please send a message to support@metamask.io and be sure to include your state logs.

@MetaMask MetaMask locked and limited conversation to collaborators May 22, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

10 participants