Blockchain.info Wallet Emptied: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/blockchaininfowalletemptied.php}} thumb|Blockchain.infoA blockchain.info user reports that their wallet was emptied, and the transaction referenced has 8.4 BTC. Blockchain.info used to send backup information to people's email addresses, which is a possible way that the wallet was breached. Another possibility is that they were another victim of the failures in the Bloc...")
 
No edit summary
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/blockchaininfowalletemptied.php}}
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/blockchaininfowalletemptied.php}}
{{Unattributed Citations}}


[[File:Blockchaininfo.jpg|thumb|Blockchain.info]]A blockchain.info user reports that their wallet was emptied, and the transaction referenced has 8.4 BTC. Blockchain.info used to send backup information to people's email addresses, which is a possible way that the wallet was breached. Another possibility is that they were another victim of the failures in the Blockchain.info random number generator, with the attack sending funds to a second address.
[[File:Blockchaininfo.jpg|thumb|Blockchain.info]]A blockchain.info user reports that their wallet was emptied, and the transaction referenced has 8.4 BTC. Blockchain.info used to send backup information to people's email addresses, which is a possible way that the wallet was breached. Another possibility is that they were another victim of the failures in the Blockchain.info random number generator, with the attack sending funds to a second address.


This is a global/international case not involving a specific country.
This is a global/international case not involving a specific country.
<ref name="bitcointalk-7480" /><ref name="bitcointalk-7481" /><ref name="blockchaindotcom-4728" /><ref name="bitdegree-4729" /><ref name="blockchain-7482" /><ref name="investingdotcom-7203" />


== About Blockchain.info ==
== About Blockchain.info ==
Line 39: Line 41:


Don't Include:
Don't Include:
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Anything that wasn't reasonably knowable at the time of the event.
* Anything that wasn't reasonably knowable at the time of the event.
Line 61: Line 62:
|-
|-
|August 1st, 2013 11:27:22 PM
|August 1st, 2013 11:27:22 PM
|First Event
|Main Event
|This is an expanded description of what happened and the impact. If multiple lines are necessary, add them here.
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.
|-
|
|
|
|-
|-
|
|
Line 74: Line 71:


== Total Amount Lost ==
== Total Amount Lost ==
The total amount lost is unknown.
The total amount lost has been estimated at $2,000 USD.


How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Line 85: Line 82:


== Total Amount Recovered ==
== Total Amount Recovered ==
It is unknown how much was recovered.
There do not appear to have been any funds recovered in this case.


What funds were recovered? What funds were reimbursed for those affected users?
What funds were recovered? What funds were reimbursed for those affected users?
Line 96: Line 93:


== References ==
== References ==
[https://bitcointalk.org/index.php?topic=277595.msg2977194#msg2977194 <nowiki>Blockchain.info security [FUNDS STOLEN]</nowiki>] (Mar 19)
<references><ref name="bitcointalk-7480">[https://bitcointalk.org/index.php?topic=277595.msg2977194#msg2977194 <nowiki>Blockchain.info security [FUNDS STOLEN]</nowiki>] (Mar 19, 2022)</ref>


[https://bitcointalk.org/index.php?topic=266500.0 Hacked] (Mar 26)
<ref name="bitcointalk-7481">[https://bitcointalk.org/index.php?topic=266500.0 Hacked] (Mar 26, 2022)</ref>


[https://www.blockchain.com/wallet/ Blockchain.com Wallet - Store and Invest in Crypto] (Dec 23)
<ref name="blockchaindotcom-4728">[https://www.blockchain.com/wallet/ Blockchain.com Wallet - Store and Invest in Crypto] (Dec 23, 2021)</ref>


[https://www.bitdegree.org/crypto/blockchain-wallet-review Blockchain Wallet Review: Learn How To Buy Bitcoin On Blockchain] (Dec 23)
<ref name="bitdegree-4729">[https://www.bitdegree.org/crypto/blockchain-wallet-review Blockchain Wallet Review: Learn How To Buy Bitcoin On Blockchain] (Dec 23, 2021)</ref>


[https://blockchain.info/tx/1174e27cd6de043ec081a68b52f455ba1548f35949c2ba2ddd3abc60f5a29840 Transaction: 1174e27cd6de043ec081a68b52f455ba1548f35949c2ba2ddd3abc60f5a29840 | Blockchain Explorer] (Mar 27)
<ref name="blockchain-7482">[https://blockchain.info/tx/1174e27cd6de043ec081a68b52f455ba1548f35949c2ba2ddd3abc60f5a29840 Transaction: 1174e27cd6de043ec081a68b52f455ba1548f35949c2ba2ddd3abc60f5a29840 | Blockchain Explorer] (Mar 27, 2022)</ref>


[https://ca.investing.com/crypto/bitcoin/historical-data https://ca.investing.com/crypto/bitcoin/historical-data] (Mar 15)
<ref name="investingdotcom-7203">[https://ca.investing.com/crypto/bitcoin/historical-data https://ca.investing.com/crypto/bitcoin/historical-data] (Mar 15, 2022)</ref></references>

Revision as of 14:55, 15 February 2023

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Blockchain.info

A blockchain.info user reports that their wallet was emptied, and the transaction referenced has 8.4 BTC. Blockchain.info used to send backup information to people's email addresses, which is a possible way that the wallet was breached. Another possibility is that they were another victim of the failures in the Blockchain.info random number generator, with the attack sending funds to a second address.

This is a global/international case not involving a specific country. [1][2][3][4][5][6]

About Blockchain.info

"The world’s most popular crypto wallet. Over 80 million wallets created to buy, sell, and earn crypto." "As they say, not your keys, not your crypto. Blockchain.com Private Key Wallets are the most widely-used wallets for self-custody of your crypto. We make it easy for people who are ready to control their private keys to hold them with a Secret Private Key Recovery Phrase." "When it comes to ensuring that your crypto is secure, we think about every last detail so you don’t have to."

"My account was hacked on Aug 1st." "Someone was able to empty out my blockchain.info account." "It appears someone got into my blockchain.info account and transferred coins out of it just a few minutes ago." "Yes, it's an annoyance to lose the coins, but what I'm concerned about is understanding how this happened, because I thought things were pretty buttoned up." "Any help would be appreciated."

"I've found no evidence that my email was compromised, and was using two-factor authentication at the time." "I have 2 factor enabled. Was logged into btct and bitfunder at the time (but not blockchain.info)" "The coins were literally sitting in the online wallet for just a few hours, as well."

"I checked the ip address of recent logins. Everything seems to be in order. I don't have 2FA set in gmail, but my password is fairly strong."

"So many people don't realize that nearly every email they send bounces around the internet completely unencrypted in plaintext for hackers to read."

"If your password protecting your blockchain.info wallet was weak, then a hacker could capture it as it travels from blockchain.info to Google, and then check it against a rainbow table. The 2 factor is only for logging into the website to receive the encrypted wallet. Once they've got the wallet, they don't need the 2FA at all."

"My best guess would be a password that exists in a rainbow table, but I suppose there are other possibilities."

"How can I determine if this was caused by the rng exploit? I was using Chrome at the time."

"I do have the blockchain info wallet backup sent to my email. Even if they had this, would they be able to extract the private keys? I still had 2FA on." "[T]hey can empty your wallet without doing login on blockchain.info wallet by importing your backup wallet into any client that supports it."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - Blockchain.info Wallet Emptied
Date Event Description
August 1st, 2013 11:27:22 PM Main Event Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.

Total Amount Lost

The total amount lost has been estimated at $2,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

Prevention Policies

The blockchain.info wallet is web-based, which makes it a form of hot wallet. Hot wallets are vulnerable to breach, and should not be used to store large sums of money. Always store the vast majority of funds offline in a cold storage medium which is not connected to the internet.

References