>> (p.1)
    Author Topic: Remember: Wallet encryption is only good if you don't have keyloggers!  (Read 2173 times)
    SgtSpike (OP)
    Legendary
    *
    Offline Offline

    Activity: 1400
    Merit: 1005



    View Profile
    April 19, 2013, 04:28:31 PM
    Last edit: April 19, 2013, 04:43:51 PM by SgtSpike
     #1

    Be careful out there...

    Quote
    Reposting this because I think this needs to be addressed as an exploit.

    Last night around 9PM PDT, I clicked a link to go to CoinChat[.]freetzi[.]com - and I was prompted to run java. I did (thinking this was a legitimate chatoom), and nothing happened. I closed the window and thought nothing of it.

    I opened my bitcoin-qt wallet approx 14 minutes later, and saw a transaction that I did NOT approve go to wallet 1Es3QVvKN1qA2p6me7jLCVMZpQXVXWPNTC for almost my entire wallet (2.07 BTC).

    I had something like 2.07225 BTC.

    This is an exploit that was able to steal BTC from an encrypted wallet without having my password - how is this possible? I thought for the most part that bitcoin-qt was safe against these types of attacks as long as the wallet is encrypted.

    This legitimately happened to me and I think this exploit needs to be given some attention, please do not downvote as I want to figure out why this exploit was able to access my encrypted wallet without having my password.

    So,r/bitcoin - what happened here?

    More info: Browser - Chrome OS - Windows Wallet Version - 0.8.0beta
    http://www.reddit.com/r/Bitcoin/comments/1cokps/java_exploit_stole_all_my_btc/
Page 1
Viewing Page: 1