from #Bitcoinmovement https://ift.tt/300YHrr
via IFTTT
from #Bitcoinmovement - The hub of Bitcoin and Crypto media https://ift.tt/3eB15Jh
via IFTTT
There are so many benefits to using a cryptocurrency, that it would seem foolish to neglect such an invention. For example, it allows you to send money anywhere in the world in an instant, with basically no fees involved. Everyone can be included in the financial system, it will change the way we interact with money, it can prevent fraud, and much more.
We are now seeing the ICOs of the new decade, it's no longer self-made projects grab money from investors to then let them fail and close shop, now we have big money getting involved, the banks, and governments trying to get their piece of the cake.
That is BloxRoute (to name one) looks like to me, a new project launched for a private company to do that same that they've always, but now with blockchain, the problem is that they will have full control (in time), so what is the point of using them instead of a regular private network? They aren't trying to solve the economic problems and the vulnerabilities in the blockchain tech, their "solution" is only something momentary, and it only serves THEIR needs.
Banks must be eager as well to jump in and use their reputation to keep using their customer money as theirs.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
BTC supporter here since 2014.
When my son was 1 year old back in late 2016, I used up all his birthday money to buy bitcoin for him. Put it on a ledger and kept it away since. My wife told me to sell at $5000, at $10000 and $18000, but i hold it ever since, now she already know I will keep my promise to just give it to him when it is time (probably not at 18, because most youngsters are still retarded at that age)
Anyway, I am so anxious to see his reaction when I tell him he has a certain amount of btc :D and that his 'old fashioned' dad was good for something :P
I hope it will make him instantly financially stable/independent. Or maybe I will get to hear why I didn't sold at $18000 back in 2017! You should have listened to mum!
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Posted this on r/Coinbase and someone recommend it also be posted here. The information below on an attempted SIM swap attack was pieced together through a combination of login and security logs, recovering emails initiated by the attacker that were deleted and then deleted again from the trash folder, and learning from AT&T’s fraud representatives. The majority if this is factual, and we do our best to note where we are speculating or providing a circumstantial suspicion. TLDRs at the bottom.
The full story:
We were going about our business and received a text from AT&T that says “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” We did not request this, and were suspicious that the text itself could be a phishing scam since we searched the phone number and it wasn’t overtly associated with AT&T. Thus, we tried calling AT&T’s main line at 611 but all we hear is beep beep beep. The phone number is already gone. We use another phone to call AT&T and at the same time start working on our already compromised email.
While we didn’t see everything real time, this is what the recovered emails show. In less than 2 minutes after receiving the text from AT&T, there is already an email indicating that the stolen phone number was used to sign into our email account associated with Coinbase. 2 minutes after that, there is an email from Coinbase saying:
"We have received your request for password reset from an unverified device. As a security precaution, an e-mail with a reset link will be sent to you in 24 hours. Alternatively, if you would like your password reset to be processed immediately, please submit a request using a verified device.
This 24 hour review period is designed to protect your Coinbase account."
This is where Coinbase got it right to have a 24 hour review period (actually a recovery period) before allowing the password to be reset. However, the attackers knew this and planned to steal the second email from Coinbase by setting email rules to forward all emails to a burner address and also have any emails containing “coinbase” re-routed so they don’t appear in the Inbox. 5 minutes later, they request a password reset from Gemini and the password was reset to the attacker’s password within a minute after that. The next minute they target and reset DropBox’s password followed immediately with Binance. Less than 2 minutes later, an email from Binance indicates that the password has been reset and another email arrives a minute later indicating a new device has been authorized.
It’s at this point that we begin locking the attacker out by (1) removing the phone number as 2FA (2) changing the email password, (3) and three forcing a logout of all sessions from the email. There was a bit of back and forth where they still had an active login and re-added the stolen phone number as 2FA.
They added only one more password reset to a gaming account that was not deleted. I can only suspect that was a decoy to make it look like the attack was directed at gaming rather than finances.
The Gemini and Binance accounts were empty and effectively abandoned, with no balances and inactive bank accounts (if any), and no transactions in 1-3 years. DropBox had no meaningful files (they probably look for private keys and authenticator backups) and the phone number they stole from us was suspended, so as far as the attacker is concerned, there is no meat on this bone to attack again… unless they had inside information.
This is where I suspect someone internal at Coinbase receiving wire deposits has been compromised in tipping off ripe accounts – accounts with new and somewhat large balances. We had completed a full withdrawal of funds from Coinbase earlier in the year, and had a balance of less than $20 heading into May. Deposits to Coinbase staggered in to get above six figures through mid-May then stopped. The attack occurred 7 days after the last large wire deposit was made to Coinbase.
From the perspective of an attacker that had no inside information, we were a dead end with abandoned Gemini and Binance accounts with zero balances and stale transactions, no DropBox information, and the suspended phone number access. Our Coinbase deposits were known to no one except us, Coinbase, and our bank. We were also able to stop the hacker’s email forwarding before Coinbase’s 24 hour period to send the password reset, so this one didn’t work out for the attackers and it would make sense for them to move on to the next rather than put efforts into a second attack only for Coinbase - for what would appear to be a zero-balance Coinbase account based on the other stale accounts.
Then…23 hours and 42 minutes after the first attack, another message from AT&T “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” Here we go again. We had been confident in AT&T’s assurances that our account had been locked and would not be SIM swapped again, so we unwisely added the phone number back to our email account as a backup (it’s now removed permanently and we use burner emails for account recovery like we should have all along).
Upon seeing that our phone number had been stolen again I knew they were after the Coinbase reset email that was delayed by 24 hours from Coinbase as part of their security. We did 4 things within 2 minutes of that text: (1) removed the phone number again from the email account – this time for good, (2) market sell all Bitcoin on Coinbase, (3) withdraw from Coinbase, (4) have AT&T suspend service on the phone line.
In speaking with AT&T, they were floored that our SIM would be transferred again in light of all the notes about fraud on the account and the PIN being changed to random digits that had never been used by us before. Based on the response of disbelief from AT&T on the second port, I suspect that this attack also involved a compromised AT&T employee that worked with the attacker to provide timely access to the Coinbase password reset email. Apparently, this has been going on for years: https://www.flashpoint-intel.com/blog/sim-swap-fraud-account-takeover/
with phone carrier employees swapping SIMs for $80s a swap.
Remember that most of this was hidden in real time, and was only known because we were able to recover emails deleted from Trash by the attacker.
Since we require any withdrawals to use Google Authenticator on Coinbase, our funds may have been secure nonetheless. However, under the circumstances with attackers that were apparently working with insiders to take our phone number twice in attempts to steal Bitcoin, and it being unknown if they had additional tools related to our Google Authenticator, we decided it was safer on the sidelines. The coins were held on the exchange for a quick exit depending on whether Bitcoin was going to break up or down from $10,000. A hardware wallet is always safest, but we were looking to time the market and not have transaction delays.
For some some security recommendations:
AT&T: If you are going to send a text saying that calls and texts are moving to a new number, provide a 10 minute window for the phone number to reply with a “NO” or “STOP” to prevent the move. This can escalate the SIM dispute to more trusted employees to determine who actually owns the line. Don’t let entry level employees swap SIMs.
Coinbase: Do not default to phone numbers as 2FA. Also, if someone logs in successfully with the password before the 24 hours are up, the password is known and there is no need to send the password reset email again for attacker to have forwarded to them. At least have an option to stop the password reset email from being sent. We did not tag our account at Coinbase with fraud because of the stories of frozen funds once an account is tagged. I’m not sure what the solution is there, but that is another problem.
Being a trader, it would be nice to think of Coinbase as any other type of security brokerage where your assets are yours (someone can’t steal your phone number and transfer your stocks to their account). We fell into that mindset of security, yet this experience has reminded us of the uniqueness of cryptocurrency and the lack of custodial assurance and insurance from exchanges because of the possession-is-everything properties of cryptocurrency.
As many have said before, 2FA with a phone number quickly becomes 1-factor authentication as soon as that phone number is associated with password recovery on your email or other accounts. Our overall recommendation is to avoid having a phone number associated with any recovery options across all your accounts.
TLDR on the process:
Scammers will steal your phone number (in our case twice in 24 hours) and use your phone number to access your email and accounts. They will use your email to reset passwords at financial accounts and file hosting such as DropBox. They will then use that combination to transfer any assets they can access from your accounts to theirs. They will do their best to hide this from you by
(1) not resetting your email password so as to raise suspicion,
(2) immediately delete any password reset emails you may receive from financial accounts to hide them from you,
(3) attempt to forward all emails sent to your address to a burner email, and
(4) set email rules to forward emails containing “coinbase” to an email folder other than your Inbox so that you don’t see the transactions and password reset emails that arrive to your inbox.
TLDR on defense tips: If your phone stops working or you receive a text of your number being ported do the following as soon as possible:
(1) log into your email account(s) associated with your financial accounts and remove your phone number as 2FA immediately
(2) change your email password,
(3) force a logout of all sessions from your email (at this point you have locked them out), then
(4) check your mail forwarding settings for forwards to burner addresses,
(5) check your mail rules for rerouting of emails from accounts such as Coinbase, and
(6) call your carrier to have them suspend service on your lost phone number and ask them to reinstate your SIM or get a new SIM. This will require a second phone because your personal phone number has been stolen.
We hope this helps some others be safe out there in protecting their coins. The more we know, the more we can protect ourselves. Wishing you all the best!
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
As the title states, last year my goal was to have 1 BTC. To everyone who are working on their way to a full BTC, just be patient and you will accomplish your goal. The problem is that once you have one BTC you'll want more lol. As of right now I have more than one and still keep buying. My goal is to have at least 5 BTC before we go over $20k. It will be hard to accomplish that goal but I will be fine if I don't achieve it. Good luck to everyone and make sure you place your BTC on a ledger. Do not leave it in exchanges. $HODLTHATBTC
Welcome to the Daily Discussion. Please read the disclaimer, guidelines, and rules before participating.
Disclaimer:
Though karma rules still apply, moderation is less stringent on this thread than on the rest of the sub. Therefore, consider all information posted here with several liberal heaps of salt, and always cross check any information you may read on this thread with known sources. Any trade information posted in this open thread may be highly misleading, and could be an attempt to manipulate new readers by known "pump and dump (PnD) groups" for their own profit. BEWARE of such practices and exercise utmost caution before acting on any trade tip mentioned here.
Rules:
To see prior Skeptics Discussions, click here.
The cryptocurrency community has noticed a number of bitcoins from the August 2, 2016, Bitfinex breach has been moved. A small 30 BTC transaction ($282,000) from the stash has moved from the hacker’s address to an unknown bitcoin address. The last time coins from the Bitfinex incident moved was June and August 2019, as the bitcoins hadn’t transferred for three years since then.
On August 2, 2016 the popular cryptocurrency exchange Bitfinex was hacked for approximately 119,756 BTC, which is worth a touch over $1 billion using today’s exchange rates. The breach crippled trader confidence that day, and the price per BTC slid 22% immediately after the event.
After the incident, the value of bitcoin staged a modest comeback a week later and Bitfinex promised customers they would be paid back. Those stolen coins were moved to an address that anyone can follow using a standard blockchain explorer. The bitcoins sat for three years and didn’t move until June and August 2019. When a BTC transaction in August took place, the transaction monitoring account Whale Alert notified the public on Twitter that roughly 300 BTC ($2.7M) was moved in ten transactions.
During the first week of June 2019, the hackers also moved around 170 bitcoins worth more than $1.5 million using today’s exchange rates. At the time, BTC prices were much higher and came awfully close to touching $14,000 per coin. It is common for hackers to move digital assets when prices are higher than usual.
Armchair sleuths and observers have noticed this type of trend taking place with the Plustoken scammers as well. When the prices of bitcoin and ethereum are higher, the Plustoken bandits start moving coins to different wallets. No one knows if these stolen coins are being exchanged on a well known trading platform, but it is suspected that it’s more likely coins like these are sold using an over-the-counter (OTC) desk after being mixed.
On May 21, 2020, 30 coins from the August 12, 2019 move, had been transferred once again to another unknown address. Back when Bitfinex was breached in 2016, the going exchange rate for BTC was around $600 per unit. The moved coins on Thursday saw approximately 30.66754180 BTC or $282,000 moved and back then they would only be worth $18,000.
It is also common for hackers to move coins into smaller increments and they may not have been sold on the market. This type of method is noticed because the 30 coins moved on Thursday, stemmed from the 300 BTC ($2.7M) transfer that was done in 10 separate transactions.
Blockchain surveillance firms and law enforcement officials have these addresses flagged and it becomes difficult to move a stash of 119,756 BTC without being seen. Unless of course you split up the stolen bitcoins and possibly mix the UTXOs using the Coinjoin process.
What do you think about the recent 30 bitcoin ($282,000) move from the 2016 Bitfinex hack? Let us know what you think in the comments below.
The post Bitcoin Worth $282K from the 2016 Bitfinex Hack on the Move appeared first on Bitcoin News.
🚧🛑🚧🛑🚧🛑🚧🛑🚧🛑🚧🛑🚧🛑🚧 Bitcoin Cash: Forked at Block 478558, 1 August 2017, For each 1 BTC you get 1 BCH Bytether: Cross for...