Be careful! / How hackers stole my coins and still are doing it with NEX EXTENSION...

in #crypto6 years ago (edited)

NOW step by step. Read it carefully for Your safety!

From begining, I wanted to get into NEX ICO, so I installed NEX EXTENSION as they demanded to do the KYC, it is a Google Chrome, after filling the KYC (I think i was the next day) I got information I have positive passed the KYC and entered the first round. I knew I'll need 1000$ deposit on the wallet to get into they ICO, so I send there my NEO coins and also TNC and TKY. After some time I had a bug/issue with the NEX Extension - a blank white screen so I couldn't login. I have checked into Google and I found such article:

But even after cleaning the cache it didn't work. I knew I have still my coins on the wallet because I has also O3 wallet on my phone so I could check it any time. On wednesday (02.05.2018) I've heard that new version of extension has came out so I wrote in the Google - "Nex Extension" and found:

nex.png

I have add it to my Chrome and it worked, I have login to it and everything looked as usual. On thursday I checked my balance on O3 wallet and there where no coins on it - someone stoled them. After that I fast wrote to NEON support on: [email protected] and the O3 wallet suport: [email protected].

Meanwhile I did my own investigation.

The thief has stolen all my coins:
20 NEO:
https://neoscan.io/transaction/2434feccb63ba03f02ccfae0de0329d3800929b39cb05783b11f4e0265992576
1718 TRINITY:
https://neoscan.io/transaction/746e0d668334dabd5e6fde604ec83edd34dde1288ce4759d43be954accfd47ce
25177 THEKEY:
https://neoscan.io/transaction/e910e2888ee202ac4ae76bf5710c5b803b286e1f0cc32c5ef2098624752ad7dd

image1.png

I have checked the thiefs wallet and there are still my coins:
https://neoscan.io/address/ARUiXMo1nUbthfDPp56WxSrT7H1prPogu3/1

neowallet.png

I also checked in Google that there was a fake Google Chrome Extension made by mike.anderson12288 (which I unfortunatly added) - about which NEX didn't informed on any official channel like - Twitter.

The fake Extension is here from 12 April (today we have 4 May), I ask how such thing can still be able to add to Google Chrome browser after almost a month!

I found an article about it on REDDIT

It's very wierd that they didn't remove this extension with Google - this is an obvious thief. Who i stealing coins/tokens all the time. I saw that he have stolen some more not far time ago - like almost 300 NEO!

The NEX Exchange is promoted as something innovative/safe, and here such a situation...

I don't want to spread FUD, but there was similar situation with the MEW (not long time ago) and it was not good for Etherium...

I still do my investigation, and I found another clue, on the bitcointalk.org (https://bitcointalk.org/index.php?topic=3065514.280), russian page - thay say that the third chain adres where the thief send the coins/tokens is: https://neoscan.io/address/AJdZA4UftshLwVAS4YAc9k274GmwDmkJgj / look at the amounts!!!

secadress.png

Imagine now - if they have now so many accounts hacked also theese with accepted KYC they can participate in the ICO and get the NEX tokens. So NEX EXCHANGE will privatize stolen money.

The worst thing about it is that it NEX cuts itself off from all the situation, they just wrote to me "That is a fake extension! This is ours!". Only the O3 wallet support tried to help me in this matter and spoke to me...

I tried to contact directly with all the founders of the NEX EXCHANGE (contact You can find in theirs whitepaper (https://neonexchange.org/pdfs/whitepaper_v2.pdf) - also no respond at all...

The fake extension is still there and still more people accidentally add it and get robbed like me. Be careful.

I hope that someone can help me.

Sort:  

Thanks for informing us buddy, i hope your article could save some people and i feel very sorry for your loss buddy 😐

Thanks for sharing, it seems Google chrome extension wallets are no longer safe.

Sorry for your loss but you can't blame NEX team for this. It's just like blaming someone because you transferred coins to fake address on those scam twitter post that annoys everyone. Thank you for sharing this so other people don't fall for that scam.

Congratulations @kasjan! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 1 year!

Click here to view your Board

Do not miss the last post from @steemitboard:

Carnival Challenge - Collect badge and win 5 STEEM
Vote for @Steemitboard as a witness and get one more award and increased upvotes!

Congratulations @kasjan! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Do not miss the last post from @steemitboard:

Use your witness votes and get the Community Badge
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.17
TRX 0.13
JST 0.027
BTC 59139.97
ETH 2676.50
USDT 1.00
SBD 2.44