Exodus Malicious Torrent File ColonelGray: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Completion.)
(Another 30 minutes complete. All sources merged in. Prevention added.)
 
(20 intermediate revisions by the same user not shown)
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/exodusmalicioustorrentfilecolonelgray.php}}[[File:Exodus.jpg|thumb|Exodus]]Reddit user ColonelGray stored a screenshot of their seed phrase on their PC when setting up their wallet. Some time later, they downloaded a malicious torrent file which ended up running a larger program. This resulted in the hacker gaining access to the seed phrase and using it to withdraw from their wallet.
{{Case Study Under Construction}}[[File:Exodus.jpg|thumb|Exodus]]Reddit user ColonelGray stored a screenshot of their seed phrase on their PC when setting up their wallet. Some time later, they downloaded a malicious torrent file which ended up running a larger program. This resulted in the hacker gaining access to the seed phrase and using it to withdraw all funds from their wallet.
 
== About ColonelGray ==
ColonelGray is a Reddit user. TBD
 
After setting up his Exodus wallet, ColonelGray stored a screenshot of his seed phrase.


== About Exodus ==
== About Exodus ==
Exodus is an online web wallet which allows the storage of over 260 cryptocurrencies as well as NFTs<ref name=":0">[https://www.exodus.com/ Best Crypto Wallet for Desktop & Mobile: Altcoin & Bitcoin | Exodus] (Jul 3, 2022)</ref>.<blockquote>"Exodus Bitcoin & Crypto Wallet - Manage and swap 260+ cryptos and NFTs on your web browser, mobile, desktop, and hardware wallets."</blockquote>All user assets are stored within the wallet and backed by a seed phrase, which the user is required to secure<ref name=":0" /><ref name=":1">[https://www.exodus.com/support/article/925-everything-you-need-to-know-about-the-secret-recovery-phrase Everything you need to know about your 12-word secret recovery phrase - Exodus Website] (Feb 28, 2023)</ref>.<blockquote>Your secret recovery phrase is the key to your wallet and controls access to all your funds, so write it down and keep it safe!
<ref name="exodus-8331" />TBD


Exodus users are responsible for storing their own recovery phrase. If the recovery phrase is lost, the user might not be able to retrieve their private keys.</blockquote>
== The Reality ==
TBD
 
== What Happened ==
ColonelGray downloaded a malicious torrent file onto their computer which stored a screenshot of their seed phrase. The malware was able to retrieve the seed phrase and the attacker was able to extract their funds from the wallet.
{| class="wikitable"
|+Key Event Timeline - Exodus Malicious Torrent File ColonelGray
!Date
!Event
!Description
|-
|January 2nd, 2022 7:27:02 AM MST
|Reddit Comment Posted
|ColonelGray shares his main comment on Reddit with the details of what happened in [[Ledger/MetaMask Hack PowerOfTheGods|another loss post by PowerOfTheGods]]<ref name="reddit-8330" />.
|-
|
|
|
|}


"Cut to a few months ago and I accidently clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files."
== Technical Details ==
TBD
 
== Total Amount Lost ==
The total amount lost has been estimated at $5,000 USD.
 
== Immediate Reactions ==
 
 
 
"Cut to a few months ago and I accident[al]ly clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files."


"So I called it a goodnight and was just grateful I had not suffered for it."
"So I called it a goodnight and was just grateful I had not suffered for it."
== Ultimate Outcome ==


"Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before."
"Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before."
Line 20: Line 57:
"Perhaps if I had not been so grief stricken I might have acted fast enough."
"Perhaps if I had not been so grief stricken I might have acted fast enough."


"But now it is just a cautionary tale, just like the ones I used to read and ignore lol."


This is a global/international case not involving a specific country.
"So from what I’m hearing, a screenshot is a bad idea. Cool. Good thing I’m a crypto peasant."
 
"Hey, I'm willing to come out admit that I was one of those idiots who screenshotted my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK."
 
=== Post Shared On Reddit ===
ColonelGray later shared his post on Reddit<ref name="reddit-8330" />.<blockquote>Hey, I'm willing to come out admit that I was one of those idiots who screenshotted my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK.
 
Cut to a few months ago and I accidently clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files.
 
So I called it a goodnight and was just grateful I had not suffered for it.


The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before.


Include:
I immediately wiped all my drives and did a fresh install of windows.


* Known history of when and how the service was started.
I felt like such a fool. I was presented with SO MANY chances to secure my crypto and I didn't even think to do one of them.
* What problems does the company or service claim to solve?
* What marketing materials were used by the firm or business?
* Audits performed, and excerpts that may have been included.
* Business registration documents shown (fake or legitimate).
* How were people recruited to participate?
* Public warnings and announcements prior to the event.


Don't Include:
It damn near threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs.
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.


== About ColonelGray ==
Perhaps if I had not been so grief stricken I might have acted fast enough.
ColonelGray has been a user of Reddit since __. He has a background in hospitality<ref>[https://old.reddit.com/r/CryptoCurrency/comments/rkkew5/are_you_invested_in_crypto_cool_dont_be_a_vegan/hpabs1h/ ColonelGray - "someone who has worked in hospitality for years" - Reddit] (Feb 28, 2023)</ref>.
 
But now it is just a cautionary tale, just like the ones I used to read and ignore lol.</blockquote>


He report that early in his bitcoin journey he took a screenshot of their seed phrase, and they've learned from this lesson<ref name="reddit-8330" />.<blockquote>"Hey, I'm willing to come out admit that I was one of those idiots who [screenshot] my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK."
== Total Amount Recovered ==
There do not appear to have been any funds recovered in this case.


"Good thing I’m a crypto peasant."</blockquote>At the time of the theft, he reports that his mother had just been diagnosed with cancer<ref name="reddit-8330" />.
== Ongoing Developments ==
ColonelGray's story will continue to live on and hopefully warn others about the dangers of saving a screenshot of a seed phrase.<blockquote>"But now it is just a cautionary tale, just like the ones I used to read and ignore lol."</blockquote>


== The Reality ==
== Individual Prevention Policies ==
ColonelGray left a screenshot of their recovery phrase on their computer<ref name=":2">[https://old.reddit.com/r/CryptoCurrency/comments/rgck4r/got_hacked_for_about_175k_is_there_any_recourse/hojzzq8/ ColonelGray - "Just about £6,000 gone because of my stupid mistakes." - Reddit] (Feb 28, 2023)</ref>.<blockquote>I had stupidly left a copy of my recovery phrase on my computer after printing it out.</blockquote>This goes against Exodus' specific guidance for users of their wallet on their website<ref name=":1" />.<blockquote>Do not store your 12-word phrase on the notepad of your computer, as a digital image, in a file-sharing service like Dropbox, MegaBox, OneDrive, Google Drive, iCloud, etc., as an e-mail draft, any kind of file on your computer or phone, including password-protected files, or on a USB drive.
The situation could have been prevented by properly storing the seed phrase or avoiding running untrusted software in the same environment as the cryptocurrency wallet. Never screenshot the seed phrase. Always store it offline, and only offline.


Because the threats are digital and online, the best way to protect your 12-word phrase is to store it on paper and offline.</blockquote>ColonelGray additionally used torrent to download files from untrusted sources<ref name="reddit-8330" /><ref name=":2" />.
=== Storage Of Seed Phrase ===
The primary problem was in regards to the storage of the seed phrase. The seed phrase should never be stored in any online form such as a screenshot. Instead, all copies of the seed phrase should be stored offline, disconnected from any online devices.


== What Happened ==
{{Prevention:Individuals:Store Funds Offline}}
ColonelGray reports that they downloaded and ran a malicious torrent SCR file<ref name="reddit-8330" /><ref name=":2" />. The SCR file format is typically used for a screensaver<ref>[https://docs.fileformat.com/system/scr/ What is an SCR file? - FileFormat Docs] (Feb 28, 2023)</ref><ref name=":3">[https://fileinfo.com/extension/scr What is an SCR file? - FileInfo.com] (Feb 28, 2023)</ref>, however they can often contain malicious payloads<ref name=":3" /><ref>[https://www.reddit.com/r/GlobalOffensive/comments/2rmb3k/watch_out_for_scr_files/ Watch out for .scr files. - Reddit] (Feb 28, 2023)</ref><ref>[https://www.quora.com/What-is-the-scr-virus-and-how-do-you-remove-it What is the ".scr" virus and how do you remove it? - Quora] (Feb 28, 2023)</ref>. After downloading the file, they then ran their anti-virus software<ref name=":2" />. They describe that either one or two days later, their wallet was emptied out. They did not share the story online until a few months later.
{| class="wikitable"
|+Key Event Timeline - Exodus Malicious Torrent File ColonelGray
!Date
!Event
!Description
|-
|December 14th, 2021 1:25:00 PM
|First Reddit Post
|ColonelGray posts some details in response to the Reddit user [[MetaMask Wallet Funds Taken anonymizeme|anonymizeme's hack for $175k]] about their own loss<ref name=":2" />.
|-
|January 2nd, 2022 7:27:02 AM
|Main Event
|ColonelGray responds to [[Ledger/MetaMask Hack PowerOfTheGods|PowerOfTheGods theft]] with an expanded post with additional details on their situation and timeline. In this post, they claim the theft happened "a few months ago"<ref name="reddit-8330" />.
|}


== Total Amount Lost ==
=== Execution Of Malware ===
ColonelGray reported their lost funds as "£6,000"<ref name=":2" /> and as "5k"<ref name="reddit-8330" />.
In addition, untrusted software was run by ColonelGray. Any environment where cryptocurrency is involved should only have fully trusted and verified software running there. If ColonelGray had exercised more diligence in software downloading, or used a separate computer for their cryptocurrency activity, they would also have avoided this loss.


The total amount lost has been estimated at $5,000 USD.
{{Prevention:Individuals:Always Verify Executables}}


== Immediate Reactions ==
{{Prevention:Individuals:End}}
ColonelGray describes a strong emotional reaction to the loss of his funds.<blockquote>It [nearly] threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs.


Perhaps if I had not been so grief stricken I might have acted fast enough.
== Platform Prevention Policies ==
Increased user education can help users properly store seed phrases and avoid using the same environment as their active cryptocurrency wallet to download untrusted software. An industry insurance fund can provide assistance for users who are affected.


But now it is just a cautionary tale, just like the ones I used to read and ignore lol.</blockquote>The only action they are reported to have taken was to wipe their hard drive and freshly reinstall Windows<ref name="reddit-8330" /><ref name=":2" />.<blockquote>I immediately wiped all my drives and did a fresh install of windows.
{{Prevention:Platforms:Cryptocurrency Safety Quiz}}


</blockquote>
{{Prevention:Platforms:Establish Industry Insurance Fund}}


== Ultimate Outcome ==
{{Prevention:Platforms:End}}
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?


<blockquote>Learnt my lesson and bought a Ledger cold storage. Also formatted and reinstalled everything on my pc.</blockquote>It also appears that they have learned their lesson on keeping the screenshot online.<blockquote>"So from what I’m hearing, a screenshot is a bad idea. Cool."</blockquote>There is no indication that
== Regulatory Prevention Policies ==
Increased user education can help users properly store seed phrases and avoid using the same environment as their active cryptocurrency wallet to download untrusted software. An industry insurance fund can provide assistance for users who are affected.


== Total Amount Recovered ==
{{Prevention:Regulators:Cryptocurrency Education Mandate}}
There do not appear to have been any funds recovered in this case.


== Ongoing Developments ==
{{Prevention:Regulators:Establish Industry Insurance Fund}}
What parts of this case are still remaining to be concluded?


== Prevention Policies ==
{{Prevention:Regulators:End}}
Never screenshot the seed phrase. Always store it offline, and only offline.


== References ==
== References ==
<references>
<references>
<ref name="reddit-7894">[https://www.reddit.com/r/CryptoCurrency/comments/rts1w2/got_compromised_and_lost_over_120k_in_crypto_ama/ Got compromised and lost over $120k in crypto; AMA : CryptoCurrency] (Jun 1, 2022)</ref>
<ref name="reddit-7894">[https://www.reddit.com/r/CryptoCurrency/comments/rts1w2/got_compromised_and_lost_over_120k_in_crypto_ama/ Got compromised and lost over $120k in crypto; AMA : CryptoCurrency] (Jun 1, 2022)</ref>
<ref name="reddit-8330">[https://www.reddit.com/r/CryptoCurrency/comments/rts1w2/comment/hqxq6tg/?utm_source=reddit&utm_medium=web2x&context=3 ColonelGray - "I check my exodus wallet and the balance was 0 whereas it had been 5k the day before" - Reddit] (Jul 3, 2022)</ref>
<ref name="reddit-8330">[https://old.reddit.com/r/CryptoCurrency/comments/rts1w2/got_compromised_and_lost_over_120k_in_crypto_ama/hqxq6tg/ ColonelGray - "I'm willing to come out admit that I was one of those idiots who screenshotted my seedphrase... I accidently clicked on a malicious file from a torrent. I saw a command window appear for a millisecond... Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before." - Reddit] (Jul 3, 2022)</ref>
<ref name="exodus-8331">[https://www.exodus.com/ Live charts & portfolio] (Jul 3, 2022)</ref>
<ref name="exodus-8331">[https://www.exodus.com/ Live charts & portfolio] (Jul 3, 2022)</ref>
</references>
</references>

Latest revision as of 14:52, 30 August 2023

Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Exodus

Reddit user ColonelGray stored a screenshot of their seed phrase on their PC when setting up their wallet. Some time later, they downloaded a malicious torrent file which ended up running a larger program. This resulted in the hacker gaining access to the seed phrase and using it to withdraw all funds from their wallet.

About ColonelGray

ColonelGray is a Reddit user. TBD

After setting up his Exodus wallet, ColonelGray stored a screenshot of his seed phrase.

About Exodus

[1]TBD

The Reality

TBD

What Happened

ColonelGray downloaded a malicious torrent file onto their computer which stored a screenshot of their seed phrase. The malware was able to retrieve the seed phrase and the attacker was able to extract their funds from the wallet.

Key Event Timeline - Exodus Malicious Torrent File ColonelGray
Date Event Description
January 2nd, 2022 7:27:02 AM MST Reddit Comment Posted ColonelGray shares his main comment on Reddit with the details of what happened in another loss post by PowerOfTheGods[2].

Technical Details

TBD

Total Amount Lost

The total amount lost has been estimated at $5,000 USD.

Immediate Reactions

"Cut to a few months ago and I accident[al]ly clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files."

"So I called it a goodnight and was just grateful I had not suffered for it."


Ultimate Outcome

"Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before."

"I immediately wiped all my drives and did a fresh install of windows."

"I felt like such a fool. I was presented with SO MANY chances to secure my crypto and I didn't even think to do one of them."

"It damn near threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs."

"Perhaps if I had not been so grief stricken I might have acted fast enough."


"So from what I’m hearing, a screenshot is a bad idea. Cool. Good thing I’m a crypto peasant."

"Hey, I'm willing to come out admit that I was one of those idiots who screenshotted my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK."

Post Shared On Reddit

ColonelGray later shared his post on Reddit[2].

Hey, I'm willing to come out admit that I was one of those idiots who screenshotted my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK.

Cut to a few months ago and I accidently clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files.

So I called it a goodnight and was just grateful I had not suffered for it.

Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before.

I immediately wiped all my drives and did a fresh install of windows.

I felt like such a fool. I was presented with SO MANY chances to secure my crypto and I didn't even think to do one of them.

It damn near threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs.

Perhaps if I had not been so grief stricken I might have acted fast enough.

But now it is just a cautionary tale, just like the ones I used to read and ignore lol.

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

Ongoing Developments

ColonelGray's story will continue to live on and hopefully warn others about the dangers of saving a screenshot of a seed phrase.

"But now it is just a cautionary tale, just like the ones I used to read and ignore lol."

Individual Prevention Policies

The situation could have been prevented by properly storing the seed phrase or avoiding running untrusted software in the same environment as the cryptocurrency wallet. Never screenshot the seed phrase. Always store it offline, and only offline.

Storage Of Seed Phrase

The primary problem was in regards to the storage of the seed phrase. The seed phrase should never be stored in any online form such as a screenshot. Instead, all copies of the seed phrase should be stored offline, disconnected from any online devices.

Store the majority of funds offline. By offline, it means that the private key and/or seed phrase is exclusively held by you and not connected to any networked device. Examples of offline storage include paper wallets (seed phrase or key written down and deleted from all electronic media), hardware wallets, steel wallet devices, etc...

Execution Of Malware

In addition, untrusted software was run by ColonelGray. Any environment where cryptocurrency is involved should only have fully trusted and verified software running there. If ColonelGray had exercised more diligence in software downloading, or used a separate computer for their cryptocurrency activity, they would also have avoided this loss.

Any time untrusted software is being run is an opportunity for abuse. It is recommended to always interact with cryptocurrency in a fully controlled environment, which is an environment where you have understanding of every piece of software running there. Using a hardware wallet, spare computer with all software wiped, and/or virtual machine with only the needed software greatly reduces your attack surface. Take the time to verify downloaded files come from the correct and expected source and match available hashes if provided. Any time you encounter a new file, always check if it can contain executable code prior to using it.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Increased user education can help users properly store seed phrases and avoid using the same environment as their active cryptocurrency wallet to download untrusted software. An industry insurance fund can provide assistance for users who are affected.

Never take for granted the limited knowledge of users of your service and their tendency to skip past provided information. It is recommended to design a simple tutorial and quiz for new users which explains the basics of seed phrases, strong password generation, secure two-factor authentication, common fraud schemes, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space. This tutorial and quiz should ensure their understanding and be a standard part of the sign-up or download process which is difficult or impossible to skip.

Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

Increased user education can help users properly store seed phrases and avoid using the same environment as their active cryptocurrency wallet to download untrusted software. An industry insurance fund can provide assistance for users who are affected.

Create a standard tutorial and quiz for all new cryptocurrency participants, which is required to be completed once per participant. This tutorial and quiz should cover the basics of proper seed phrase protection, strong password generation, secure two-factor authentication, common fraud schemes, how to detect and guard against phishing attacks, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space.

Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

Cite error: <ref> tag with name "reddit-7894" defined in <references> is not used in prior text.