My Liqui account got hacked... maybe?
Hello everybody :)
I need to ask you an important question regarding Liqui... I think I got hacked and the situation doesn't look too good.
Here's a short recap of what happened:
- Yesterday night I got an email from Liqui where there was a request to change password on my account
- I logged in to my Liqui account by using a different laptop, and of course by inserting the URL directly (didn't click any link)
- Once in, I saw that there were 2 IP addresses connect to my account, both from Russia. I have removed them immediately
- I checked my balance account and majority of the coins were equal to zero
Till here it seems a classic hack, but now there is a bit of a twist:
- Every time you ask for a withdraw on Liqui you get an email that you need to confirm to execute the order. I didn't receive any email
- In the withdraws history the latest activity is 100% mine and there is nothing that shows the coins have been transferred
- Some values i.e. Bancor shows a value of 0.000000 but still the option to withdraw is available, while others with same value don't have that option (as it should be).
- Liqui is really not the best exchange in the market when we consider performance, it happens multiple time that pages were not being loaded in a proper way.
I open a ticket with the support team but still didn't get a reply.
I would like to know if this happened to others before, if you think is a bug or a hack, if there is a way to fix the issue (which in case of a hack we all know the answer is no) and etc. etc.
I was not keeping a lot of coins on that account, as said multiple times I store things offline, it was just waiting to accumulate a bit more to reduce fees... ICN for example you have 5 ICN as fees in case of withdraw... If I have 50 ICN would be quite bad to pay 10% of the total value just as fee...
Damn sorry for your loss ! Take my advice and use 2FA even on your shoes !
A similiar issue there is also with Bittrex !A friend of mine didn't use 2FA on his account and 10btc gone thru a pump and dump on ETH/GUP pair ...
Ive been struggling for weeks to get support to help with my withdrawals. I never receive the confirmation email and they say they can see that I did. Not in junk, it just doesn't arrive. All other email arrive OK, just not withdrawals. That was 2 weeks ago and nothing from them since. Very frustrating! I really hope they haven't scammed me or been hacked. Seems like delay tactics.
Not surprised at all about it. They are really bad.... best way of using LIQUI is to send, execute the trade and withdraw everything in the same hour... otherwise totally stay away from them!
Good luck with resolving your issues!
UPDATE: I finally managed to get my coins out. It was actually a spam filter running on my hosted server, that did not like the confirmation email's embedded links, and was putting them into quarantine. If you are not getting any confirmation emails, check your server spam, not email junk. If your server blocks it, then it will never hit your email in the first place.
This was the reason for the antispam block:
REJECTED
URLs in message content found on a DNS blacklist
I'm relieved that my issue is not a Liqui issue, but I must say that they really need to jack up support if they care about their brand at all. Communication goes a long way. Twitter is absolutely filled with unhappy customers.
Amazing to see you have fixed the problem and thanks a lot to share your solution. I'm sure if someone has the same problem, your message will save them a lot of time.
Regarding LIQUI, I don't think they will improve anything, all exchanges are really similar, they don't really care about users and they are just sending some pre-packed sentences....
Many indications that users that don't had activated 2fa where sadly hacked at liqui....
https://www.reddit.com/r/ethtrader/comments/6px8mq/35_btc_just_disappeared_from_my_liquiio_account/
https://themerkle.com/liqui-io-users-report-hacked-funds-and-blocked-withdrawals/
Unfortunately it confirmed... They sell the coins for super cheap prices, bo withdraws or anything.
For as much as it's not nice I need to admit they used a really smart technique.
Congratulations @cryptomarketer! You have completed some achievement on Steemit and have been rewarded with new badge(s) :
Award for the number of upvotes received
Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here
If you no longer want to receive notifications, reply to this comment with the word
STOP
Congratulations @cryptomarketer! You have completed some achievement on Steemit and have been rewarded with new badge(s) :
Award for the number of comments received
Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here
If you no longer want to receive notifications, reply to this comment with the word
STOP