Scammers got $200K+ in 24 hours.

in #cryptocurrency7 years ago (edited)

This is for those who wants to secure their savings and investments.

This is my story. One of the victims of phishing attacks. I had 5 ICOs tokens namely Humaniq, Status-IM, Somn, Mysterium and Patientory kept in MyEtherWallet. No doubt MyEtherWallet is secured but when you are victim of phishing attack then its like you are having sex with a stranger.

How it happened ? Attackers hacked Status IM slack bot reminder and sent an update to all members of slack ICO community.

status-slack-bot.PNG

I clicked on MyEtherWallet blinding which took me to phishing site exactly same MyEtherWallet.

This is the link where I was taken

phishing-url.PNG

Note: Please don't visit this link

Most of the people overlook the website details and becomes victim of attacker as I did. One thing I noticed when I clicked on that link, it was slow. It took more than 10 seconds to load that's unusual. Whereas genuine MEW loads in less than 5 secs for me on my internet connection.

Till here my stars were shining and the last move robbed me. I entered my private key and nothing happened just a red label with some message at the bottom of page, which looked suspicious to me and I quickly looked at URL but it was too late. I said 'Oh shit'. Shit happens and now with me. I went to genuine MyEtherWallet.com and I still see tokens were present and I planned to move it to new wallet. I created a new wallet and came back to transfer but it was too too late. Everything was stolen.

I had 0 ether in my account so attacker transferred .2 ether to pay the ether transfer fee and after the transfer is completed, remaining ether also taken back.

ether-stolen-token-transfer.PNG

Game over. Please don't visit any link shared on Slack, Twitter, Facebook, Email ... etc Best way to access your online profile is from bookmarks.

This is address to which my tokens where transferred.

https://etherscan.io/address/0xc57f1148855e67763a694f7f2c0e68230adc686e

If you come across such phishing site then please report at

https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en

Please make internet safe for all.

Following that incident MEW team reported few other sites.

The safest way is to use hardware wallet. Your key stays safely on your device. That is why people love hardware wallets so much.

MEW team has released a chrome extension to spread awareness about phishing domains

Thanks to MEW team for writing the safe guide.

https://www.reddit.com/r/ethereum/comments/6lfy73/warning_stop_clicking_links_stop_sending_to/

Sort:  

Just scammed massively too - absolutely gutted. Years of work and LOTS of tokens. Don't know what to do with myself. Thinking of dumping the bits I have left and getting out of crypto. I feel sick right now.

Still happening to users of My Ether Wallet.

I just lost $100 in Ether while funding ICO for Cobinhood. A website copy was created with a .org address and I deposited into that phishing account accidentally. Guess there is no way to get the money back now. At least it was not a lot.

Congratulations @asifhj! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Do not miss the last post from @steemitboard:

SteemitBoard - Witness Update
Do not miss the coming Rocky Mountain Steem Meetup and get a new community badge!
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.31
TRX 0.11
JST 0.033
BTC 64275.02
ETH 3139.81
USDT 1.00
SBD 4.14