Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Funds are gone!? #6580

Closed
aradour opened this issue Sep 13, 2020 · 15 comments
Closed

Funds are gone!? #6580

aradour opened this issue Sep 13, 2020 · 15 comments
Labels
maybe-malware user story which might be a result of malware

Comments

@aradour
Copy link

aradour commented Sep 13, 2020

I just left my wallet open with my laptop closed
How this happened? I have all my funds gone, 55$ are gone! https://www.blockchain.com/btc/tx/dd5e692b1fc09174d74af4312f1eeca0d385cdec4b01c3f0c2414ce592517ee7

I never paid anyone. How this happened? Someone hacked me?

@aradour
Copy link
Author

aradour commented Sep 13, 2020

https://www.blockchain.com/btc/address/1DEo9tqDLFEsoJJVN1EiGm8tdMzKsH9Sb6

This wallet has them, unspent its not in my wallets. What happened? I just cant believe what happened im having literally a crisis

@verretor
Copy link
Contributor

Did you verify the GPG signature of Electrum?
https://electrum.readthedocs.io/en/latest/gpg-check.html

@aradour
Copy link
Author

aradour commented Sep 13, 2020

No, I've been using it since 2015/2016 and i've never had a problem like this! It's shocking. Okay so its obvious I can't' take my coins back, they're already spent, idk how this happens tho?
Anyway I created new with 2FA security, and i have gpg and kleopatra, now i'll verify the signature. But how come for years was so safe. If I verify now would it make my new wallet safer at least? its really putting me down, i'm afraid to deposit...

@verretor
Copy link
Contributor

verretor commented Sep 13, 2020

Did you update Electrum recently?
What version are you using now?

@aradour
Copy link
Author

aradour commented Sep 13, 2020

I just verified it too. I always used the last version of Electrum, so 3 days ago I used the previous last one before updating it now to the newest. I just opened my laptop this night and saw " new transacction " and all my funds went away. I always update everything.
I heard there are attacks recently? Is it possible because of this? With 2FA is it more stable now if i deposit? :(

@SomberNight
Copy link
Member

A month ago you have had clipboard malware on your PC (#6506).
You might have had another piece of malware now.

  • 2FA is more secure than just a standard hot wallet, but you should generate the 2FA seed on an offline PC (or at least the PC must not be malware infested when the seed is generated as it is vulnerable at that point).
  • Or you could buy a hardware wallet and use it with Electrum.
  • Or you could use 2of2 multisig between your PC and your phone.
  • Or you could use an online machine with a watch only wallet to generate unsigned transactions, and use an offline machine to sign them.

@SomberNight SomberNight added the maybe-malware user story which might be a result of malware label Sep 13, 2020
@aradour
Copy link
Author

aradour commented Sep 13, 2020 via email

@aradour
Copy link
Author

aradour commented Sep 13, 2020

A month ago you have had clipboard malware on your PC (#6506).
You might have had another piece of malware now.

  • 2FA is more secure than just a standard hot wallet, but you should generate the 2FA seed on an offline PC (or at least the PC must not be malware infested when the seed is generated as it is vulnerable at that point).
  • Or you could buy a hardware wallet and use it with Electrum.
  • Or you could use 2of2 multisig between your PC and your phone.
  • Or you could use an online machine with a watch only wallet to generate unsigned transactions, and use an offline machine to sign them.

Can you suggest me any program that I can use on my pc to clean all malwares? And If I set up already 2FA with the Authenticator, and put a multisign wallet instead of standard is it more secure now? I'm really afraid to deposit now. I don't know if its better to have a clean full installation of my Windows again?

@SomberNight
Copy link
Member

Frankly I would format the disk and reinstall the OS.

Again, the 2FA seed should ideally be generated on an offline PC or at least the PC you generate it on should not have malware at the time you do it. So if you generate a 2FA seed right now on this machine, that cannot be considered secure.
This is because when you generate the 2FA seed, it is displayed on the screen for the user to write down: it contains 2 keys for a 2of3 multisig, i.e. the seed itself is enough to spend the coins. After the user writes down the seed and clicks next, only 1 of the keys will be kept in the wallet file, the other one is not kept. So during wallet creation, when the seed is displayed, the 2FA wallet is briefly completely vulnerable to malware. (also see https://api.trustedcoin.com/#/electrum-help)

@aradour
Copy link
Author

aradour commented Sep 13, 2020

Frankly I would format the disk and reinstall the OS.

Again, the 2FA seed should ideally be generated on an offline PC or at least the PC you generate it on should not have malware at the time you do it. So if you generate a 2FA seed right now on this machine, that cannot be considered secure.
This is because when you generate the 2FA seed, it is displayed on the screen for the user to write down: it contains 2 keys for a 2of3 multisig, i.e. the seed itself is enough to spend the coins. After the user writes down the seed and clicks next, only 1 of the keys will be kept in the wallet file, the other one is not kept. So during wallet creation, when the seed is displayed, the 2FA wallet is briefly completely vulnerable to malware. (also see https://api.trustedcoin.com/#/electrum-help)

Okay so the wallet that I had before, i will just close it. And what Its best to do is to reinstall the whole OS cancelling all files, I Wouldnt keep anything. Then after that you suggest me to create a new wallet Electrum but multisign or I can put standard? i think the second is more secure. So after that i'll generate a 2FA seed as it'll be on clean installation. While I Was verifying electrum on the guide. Is it necessary to install the tar file for linux? I didnt get this part of the guide? Because it gave me error when I put it in the cmd so is it enough just to verify the one for windows? https://electrum.readthedocs.io/en/latest/gpg-check.html

this step

" Download Electrum and signature file (asc)
Download the Python Electrum-.tar.gz or AppImage file

Right click on the signature file and save it as well "

I didnt get it! Should I do it as I'm using Windows?

And the link you attached thank you very much! I will see the guide, but im confused, when I install everything, trusted coin for electrum is what? Sorry for the questions!
and thank you for helping me out!

@SomberNight
Copy link
Member

See this page re how to verify your download.

And the link you attached thank you very much! I will see the guide, but im confused, when I install everything, trusted coin for electrum is what? Sorry for the questions!

A 2FA wallet uses 2of3 multisig, where there is one hot user key, one cold user key, and one hot server key.
The hot server key is handled by a central server operated by TrustedCoin.
Note that this is a paid service that provides the security of multisig with the convenience of a standard single-sig.
Again, see https://api.trustedcoin.com/#/electrum-help

@aradour
Copy link
Author

aradour commented Sep 14, 2020

See this page re how to verify your download.

And the link you attached thank you very much! I will see the guide, but im confused, when I install everything, trusted coin for electrum is what? Sorry for the questions!

A 2FA wallet uses 2of3 multisig, where there is one hot user key, one cold user key, and one hot server key.
The hot server key is handled by a central server operated by TrustedCoin.
Note that this is a paid service that provides the security of multisig with the convenience of a standard single-sig.
Again, see https://api.trustedcoin.com/#/electrum-help

I installed full clean windows installation, checked for malwares, put on all security of the pc. Installed gpu and kleopatra and verified them too, now i'm going to install the standard electrum for windows, and verify it, then going to make 2FA making new multisign wallet right? And then i'll follow the link you sent me.

Thank you!

@aradour
Copy link
Author

aradour commented Sep 14, 2020

See this page re how to verify your download.

And the link you attached thank you very much! I will see the guide, but im confused, when I install everything, trusted coin for electrum is what? Sorry for the questions!

A 2FA wallet uses 2of3 multisig, where there is one hot user key, one cold user key, and one hot server key.
The hot server key is handled by a central server operated by TrustedCoin.
Note that this is a paid service that provides the security of multisig with the convenience of a standard single-sig.
Again, see https://api.trustedcoin.com/#/electrum-help

should I add also the LinuxAppi Image? It was in the instructions to verify electrum, so I have no idea here?

@aradour
Copy link
Author

aradour commented Sep 14, 2020

Offline PC means without internet or ?

@aradour
Copy link
Author

aradour commented Sep 14, 2020

Just did and put 100 pre paid transactions!

@aradour aradour closed this as completed Oct 24, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maybe-malware user story which might be a result of malware
Projects
None yet
Development

No branches or pull requests

3 participants