Exodus Malicious Torrent File ColonelGray

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Revision as of 18:00, 28 February 2023 by Azoundria (talk | contribs) (Completion.)
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Exodus

Reddit user ColonelGray stored a screenshot of their seed phrase on their PC when setting up their wallet. Some time later, they downloaded a malicious torrent file which ended up running a larger program. This resulted in the hacker gaining access to the seed phrase and using it to withdraw from their wallet.

About Exodus

Exodus is an online web wallet which allows the storage of over 260 cryptocurrencies as well as NFTs[1].

"Exodus Bitcoin & Crypto Wallet - Manage and swap 260+ cryptos and NFTs on your web browser, mobile, desktop, and hardware wallets."

All user assets are stored within the wallet and backed by a seed phrase, which the user is required to secure[1][2].

Your secret recovery phrase is the key to your wallet and controls access to all your funds, so write it down and keep it safe! Exodus users are responsible for storing their own recovery phrase. If the recovery phrase is lost, the user might not be able to retrieve their private keys.

"Cut to a few months ago and I accidently clicked on a malicious file from a torrent. I saw a command window appear for a millisecond and knew I'd fucked up. However, my last run in with a virus was just one of those 'buy our antivirus' malware deals. So I figured it would be much the same. I ran my antivirus and seemed to clear out some suspicious files."

"So I called it a goodnight and was just grateful I had not suffered for it."

"Then a couple of days later I check my exodus wallet and the balance was 0 whereas it had been 5k the day before."

"I immediately wiped all my drives and did a fresh install of windows."

"I felt like such a fool. I was presented with SO MANY chances to secure my crypto and I didn't even think to do one of them."

"It damn near threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs."

"Perhaps if I had not been so grief stricken I might have acted fast enough."

"But now it is just a cautionary tale, just like the ones I used to read and ignore lol."

This is a global/international case not involving a specific country.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

About ColonelGray

ColonelGray has been a user of Reddit since __. He has a background in hospitality[3].

He report that early in his bitcoin journey he took a screenshot of their seed phrase, and they've learned from this lesson[4].

"Hey, I'm willing to come out admit that I was one of those idiots who [screenshot] my seedphrase. This was when I was first getting into crypto so I did not really understand just how much of an foolish move that was, despite all the massive DO NOT DO THIS TURN BACK." "Good thing I’m a crypto peasant."

At the time of the theft, he reports that his mother had just been diagnosed with cancer[4].

The Reality

ColonelGray left a screenshot of their recovery phrase on their computer[5].

I had stupidly left a copy of my recovery phrase on my computer after printing it out.

This goes against Exodus' specific guidance for users of their wallet on their website[2].

Do not store your 12-word phrase on the notepad of your computer, as a digital image, in a file-sharing service like Dropbox, MegaBox, OneDrive, Google Drive, iCloud, etc., as an e-mail draft, any kind of file on your computer or phone, including password-protected files, or on a USB drive. Because the threats are digital and online, the best way to protect your 12-word phrase is to store it on paper and offline.

ColonelGray additionally used torrent to download files from untrusted sources[4][5].

What Happened

ColonelGray reports that they downloaded and ran a malicious torrent SCR file[4][5]. The SCR file format is typically used for a screensaver[6][7], however they can often contain malicious payloads[7][8][9]. After downloading the file, they then ran their anti-virus software[5]. They describe that either one or two days later, their wallet was emptied out. They did not share the story online until a few months later.

Key Event Timeline - Exodus Malicious Torrent File ColonelGray
Date Event Description
December 14th, 2021 1:25:00 PM First Reddit Post ColonelGray posts some details in response to the Reddit user anonymizeme's hack for $175k about their own loss[5].
January 2nd, 2022 7:27:02 AM Main Event ColonelGray responds to PowerOfTheGods theft with an expanded post with additional details on their situation and timeline. In this post, they claim the theft happened "a few months ago"[4].

Total Amount Lost

ColonelGray reported their lost funds as "£6,000"[5] and as "5k"[4].

The total amount lost has been estimated at $5,000 USD.

Immediate Reactions

ColonelGray describes a strong emotional reaction to the loss of his funds.

It [nearly] threw me over the edge as my mother had just been diagnosed with cancer and I was planning to sell a portion of it to help cover some costs.

Perhaps if I had not been so grief stricken I might have acted fast enough.

But now it is just a cautionary tale, just like the ones I used to read and ignore lol.

The only action they are reported to have taken was to wipe their hard drive and freshly reinstall Windows[4][5].

I immediately wiped all my drives and did a fresh install of windows.

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Learnt my lesson and bought a Ledger cold storage. Also formatted and reinstalled everything on my pc.

It also appears that they have learned their lesson on keeping the screenshot online.

"So from what I’m hearing, a screenshot is a bad idea. Cool."

There is no indication that

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

Ongoing Developments

What parts of this case are still remaining to be concluded?

Prevention Policies

Never screenshot the seed phrase. Always store it offline, and only offline.

References

Cite error: <ref> tag with name "reddit-7894" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "exodus-8331" defined in <references> is not used in prior text.