Cell Phone Repair Shop Theft hoangs2k
Notice: This page is a new case study and some aspects have not been fully researched. Some sections may be incomplete or reflect inaccuracies present in initial sources. Please check the References at the bottom for further information and perform your own additional assessment. Please feel free to contribute by adding any missing information or sources you come across. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
On November 9th, Reddit user hoangs2k took his cell phone with a broken screen to get repaired at the UBreakIFix cell phone repair shop. He reported finding that a new device had been hooked up to his Google account on November 9th, the same day that his cell phone was being repaired. On December 26th, he found that his HotBit account and MetaMask wallet were both emptied out. His HotBit account was protected by his Google Authenticator with the backup information stored on his cell phone. It's unclear where the MetaMask wallet was accessed from, but conceivable it may have been on his phone as well.
$73k was taken between the Hotbit and MetaMask wallets. It is possible that the information on the phone was extracted during the repair process, with the new device added to the Google account, and this was later used to perform the theft. hoangs2k reportedly has not filed any police report, and it appears no funds have been recovered in this case.
This exchange or platform is based in Canada, or the incident targeted people primarily in Canada.[1][2][3][4][5][6][7][8][9][10][11]
About hoangs2k
hoangs2k is a Reddit user and Canadian citizen.
About UBreakIFix
UBreakIFix runs a series of cell phone repair shops throughout Canada.
[12].
The Reality
Unfortunately, when sending in a cell phone to get repaired, physical access to the device is required. They may also require the ability to unlock the device to validate various fixes.
This access allows the repair shop to obtain sensitive information. Therefore, caution is necessary and it's likely a best practice to wipe any sensitive secrets from any devices under repair.
What Happened
Reddit user hoangs2k took their cell phone to be repaired as a ubreakifix repair shop. Shortly afterward, all of their cryptocurrency which had been stored on the phone was stolen.
Date | Event | Description |
---|---|---|
December 26th, 2021 2:20:59 AM MST | Main Event | Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. |
December 26th, 2021 5:48:10 AM MST | ShibaSwap Post Attempt | hoangs2k attempts to post his story on ShibaSwap, however the post is rejected by Reddit spam filters[13]. |
December 27th, 2021 2:09:52 AM MST | SatoshiStreetBets Post Attempt | hoangs2k attempts to post his story on SatoshiStreetBets, however the post is rejected by Reddit spam filters[14]. |
December 27th, 2021 2:23:55 AM MST | SatoshiStreetBets Post Attempt | hoangs2k again attempts to post his story on SatoshiStreetBets, however the post is still rejected by Reddit spam filters[15]. |
January 1st, 2022 4:22:45 PM MST | Reddit Comment | hoangs2k shares his story again in a Reddit comment. |
April 3rd, 2022 5:09:58 PM MDT | Incident Referenced | The incident is referenced (without details) in another Reddit thread[16]. |
Technical Details
"I feel your pain. The morning after christmas 12/26/21, I got hacked as well for 73k." They took "62k from my metamask + an additional 10k from my hotbit account." "They did try to get into my coinbase account as well, which i dont use anymore and is pretty empty." "But I do have my bank account linked on there, so that worries me. I got the text for the code. I immediately changed my password via desktop pc." "Like many of you, I thought my funds were safe." "Thought my metamask was safe. My fault."
"The only thing I can think of is that the cell phone repair shop, cloned my phone (my touchscreen needed a replacement)." "I remember when I dropped my phone the screen broke and i got it repaired at a ubreakifix shop. Its showing the same day Nov. 9 it first connected, as my [PayPal] receipts." I "still don't know how they got into my metamask and my hotbit account as it requires fingerprint and 2fa for funds going out."
Total Amount Lost
The total amount lost has been estimated at $73,000 USD.
Immediate Reactions
Comment Posted On Reddit
I feel your pain. The morning after christmas 12/26/21, I got hacked as well for 73k.
Hackers address 0x13B6804Ae6c55fD34E3d994dbAdB4a1c1c183642
The only thing I can think of is that the cell phone repair shop, cloned my phone (my touchscreen needed a replacement). There was unrecognized phoned signed into my google email account, I signed that out immediately and changed the password. Still don't know how they got into my metamask and my hotbit account as it requires fingerprint and 2fa for funds going out.
I tried to search for a crypto recovery solution. Checked out cncintel, spoke to them on the phone. But I fear that it is a scam. They wanted $5500 upfront and 20% of recovered funds. I told them I dont have that much, then they asked for $1500 upfront and 10% for the basic plan.
I already lost all hope. I dont make much, those were all gains, after I took my initial 5k investment out. I felt lucky for awhile. But it doesn't hurt any less, 73k is a lot. I had a feeling it's going to 4x by end of 2022.
It's all gone now. Still feeling it. Discouraged from future crypto investments, but I will find my way back in, somehow, someway.
If I were to do it again, I would make multiple wallets, split up funds. Like many of you, I thought my funds were safe.
"Woke up to a notification from hotbit saying that I have a withdrawal success for 6k. Went to go check it and there was another one that was made for 4k a few minutes earlier. So I changed my hotbit password and email as well. Went to follow the tranasction id, found that address. Looked at it. Showing 62k in shib. Which i had in my metamask. Opened my metamask and there it wasnt. Gone 62k, just like that." "They sold assests in hotbit, converted it and withdrew it to that address. In metamask they unstaked my xshib to shib, and moved that as well."
"There was unrecognized phoned signed into my google email account, I signed that out immediately and changed the password." "I checked my google account to see what device was connected. And there was this ROG phone 2 connected on Nov. 9 that i dont recognize. I only owned samsung phones." "My google 2fa is strictly on my phone, so it has to be where they gained access. Downloaded and scanned for spyware, but didnt find anything."
"I also had a weird phone number text me the same day my account got hacked. It was in croation. I googled translated it, but didnt reply back to the text. (585) 733-8815 Tata samo da vam javim da nisam kod kuce That was the random text at 7:49pm EST. Translates to 'Dad just to let you know im not home.' Didnt think too much of it, as it was the same area code. Must be a wrong number im thinking. Too many coincidences."
"You phone/pc was hacked. Your email was hacked. Most likely they screen logged your 2fa seed for your metamask or exchange. Since you didnt use a hardware wallet the funds were easier to steal from metamask. Since they have your email, password and 2fa they have everything. I've heard people getting hacked in 2021 despite using google 2fa. This is why I have disabled google 2fa, moved to yubikey and whitelist address only for withdrawals."
Ultimate Outcome
"I tried to search for a crypto recovery solution. Checked out cncintel, spoke to them on the phone. But I fear that it is a scam. They wanted $5500 upfront and 20% of recovered funds. I told them I dont have that much, then they asked for $1500 upfront and 10% for the basic plan." "I tried to recover my hotbit funds, but they said they couldnt do anything."
"I already lost all hope. I dont make much, those were all gains, after I took my initial 5k investment out. I felt lucky for awhile. But it doesn't hurt any less, 73k is a lot. I had a feeling it's going to 4x by end of 2022." "If I were to do it again, I would make multiple wallets, split up funds.
"I haven't tried fil[l]ing a police report. I wouldn't know where to begin, what to say, or how I can prove anything..."
"It's all gone now. Still feeling it. Discouraged from future crypto investments, but I will find my way back in, somehow, someway."
"Anyways, easily the worst christmas present for me or a great one to whoever owns that address. Learn from my mistake get a hard wallet. I dont even know what I did wrong. This sucks man, really does."
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
Ongoing Developments
TBD
Individual Prevention Policies
Keep the majority of funds stored offline with all seed phrases and private keys in your possession. It is also a good idea to remove wallets or two-factor authentication from any devices being sent for repair.
Store the majority of funds offline. By offline, it means that the private key and/or seed phrase is exclusively held by you and not connected to any networked device. Examples of offline storage include paper wallets (seed phrase or key written down and deleted from all electronic media), hardware wallets, steel wallet devices, etc...
Private keys can be obtained through seed phrases, mnemonics, private key files, mobile synchronization screens, wallet export features, wallet backups, etc... Never ever send these to anyone else who you do not intend to allow to take all of your money. Attackers will use a wide variety of tactics to convince you like pretending to be your wallet software, pretending they work for the wallet software, or asking you to screen share. Don't fall for them.
Set up separate email addresses for each service, and avoid providing your phone number whenever possible. Any received emails or phone calls must be viewed with scrutiny, especially if unsolicited. Interact with companies only through their official websites and confirm anything with the company directly via multiple official sources, especially if it promises a significant incentive to take an action or threatens access to your funds if an action is not taken. It would be recommended to also establish a network of multiple trusted individuals who use the same services and have a strong level of security knowledge.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Greater education is needed about the risks which can happen from anywhere. And industry insurance fund could be set up to assist users.
Never take for granted the limited knowledge of users of your service and their tendency to skip past provided information. It is recommended to design a simple tutorial and quiz for new users which explains the basics of seed phrases, strong password generation, secure two-factor authentication, common fraud schemes, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space. This tutorial and quiz should ensure their understanding and be a standard part of the sign-up or download process which is difficult or impossible to skip.
Work with other industry platforms to set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
Greater education is needed about the risks which can happen from anywhere. And industry insurance fund could be set up to assist users.
Create a standard tutorial and quiz for all new cryptocurrency participants, which is required to be completed once per participant. This tutorial and quiz should cover the basics of proper seed phrase protection, strong password generation, secure two-factor authentication, common fraud schemes, how to detect and guard against phishing attacks, how ponzi schemes work, as well as other risks which are unique to the cryptocurrency space.
Set up a multi-signature wallet with private keys held separately by delegate signatories from seven prominent platforms and services within the industry. Establish requirements for contributions by all platforms and services within the country, designed to be affordable for small platforms yet large enough to cover anticipated breach events. Any breach event can be brought forth by a member platform or a petition of 100 signatures for consideration by the delegate signatories. A vote of 4 or more delegate signatures is required to release any funds, which could partially or fully restore lost funds based on their assessment.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ Got compromised and lost over $120k in crypto; AMA : CryptoCurrency (Jun 1, 2022)
- ↑ Got compromised and lost over $120k in crypto; AMA : CryptoCurrency (Jul 5, 2022)
- ↑ https://etherscan.io/tx/0x1e0a1e2b75b0230e962f617e6f3759777e4221bc50bba55a19d7c7e5999b3011 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0xd539dfa08a1714ba2f1f7c991a8fd3ed767081f5ee8857c9c224277fd396bae7 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0xd8683405db99b7224b7c88433bf4bb2dd8208743d7db5b399e6534a7a7fb3594 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0xd6aa5436bc37b8f70788e8df9e0ad3aec074e714d014f18c519163230ac4ca31 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0xd43ab0a2416ef63147527066453365a0502af4e0bb14c00ecf9dde4396cb85e7 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0x407743f09bbb2840583f7b494e761821c025bd1592e1b3064257b27e1bb0b9b7 (Jul 6, 2022)
- ↑ https://etherscan.io/tx/0x34804087a17bd819069dd57e2fcced2a9cc6afe0f4e0fa2eb945e18664af212e (Jul 6, 2022)
- ↑ https://etherscan.io/address/0xa6025e4efcaee6c4cc6ee97692a31c27fd44b8d1 (Jul 6, 2022)
- ↑ Daily Discussion - December 26, 2021 (GMT+0) : CryptoCurrency (Jul 6, 2022)
- ↑ Repair Locations Nationwide | uBreakiFix (Jul 6, 2022)
- ↑ Just got hacked for 72k. I think im done with crypto. : SHIBArmy (Jul 6, 2022)
- ↑ I got hacked for 72k. I think im done with crypto. : SatoshiStreetBets (Jul 6, 2022)
- ↑ I Think im done with crypto. : SatoshiStreetBets (Jul 6, 2022)
- ↑ Idgaf... I'm leaving my coins on an exchange where it is insured... Too many scams out there that even crypto vets are falling for. : CryptoCurrency (Jul 6, 2022)