Need Help Please!

Posts 16 of 6 · Page 1 of 1
Need Help Please!
So yeah I have no idea how this is possible I know the hacker took control of my computer and saw the browsing history he first started searching my email for "coinbase" and unfortunately that account was banned many months ago but then he searched for binance and this is where I stupidly store most of my bitcoin although it's not much he was able to somehow get .6 btc withdraw started even though only on my iphone I have google authenticator enabled for binance this was around today 7:42 EST time I was in bed and saw the email right after so at about 7:44 the account was disabled by disabling from the same email withdraw request.



I send out an email to binance support already but I would really like to know:



How is it possible a hacker accessing my computer can start a withdraw when google authenticator is enabled?

What are the chances of me disabling the account 2 mins after the hacker confirming the email withdraw request that those funds still remain in the account?


I know my deposit address is the following address: 17vAHXQoCmuWKZs9CBLDt8EbiJWj4JgMnr
Is it the same for withdraw?

- - - Updated - - -

I just notice that the withdraw request was for this ID: 1PkYjzNbmBSTfrv2KW5vWyNKKc46EgVDLS

And he received the BTC already so yeah fuck binance
Quote Originally Posted by lanfeust11 View Post
How is it possible a hacker accessing my computer can start a withdraw when google authenticator is enabled?
If you are 100% sure he took control of your computer (and didn't just hack your e-mail/binance account), then I recommend you reset/reformat your computer. It means you have a virus/malware on your computer
I also recommend you change the password to all your accounts (crypto and non-crypto related).

Quote Originally Posted by lanfeust11 View Post
How is it possible a hacker accessing my computer can start a withdraw when google authenticator is enabled?
If he has access to your email, they can reset google auth.

Quote Originally Posted by lanfeust11 View Post
I know my deposit address is the following address: 17vAHXQoCmuWKZs9CBLDt8EbiJWj4JgMnr
Is it the same for withdraw?
Most likely no. Usually the withdraw and deposit addresses are not the same on any platform.

Quote Originally Posted by lanfeust11 View Post
I just notice that the withdraw request was for this ID: 1PkYjzNbmBSTfrv2KW5vWyNKKc46EgVDLS
Your bitcoins are now gone forever. Binance cannot do anything

The lesson is, never store your bitcoin in an exchange. You always have to avoid them. An exchange can get hacked at any point. Or you can. Its always best to create a wallet (not coinbase) where you own the private keys. Someone would have to break into your house to get those private keys.
Quote Originally Posted by Allura View Post
If you are 100% sure he took control of your computer (and didn't just hack your e-mail/binance account), then I recommend you reset/reformat your computer. It means you have a virus/malware on your computer
I also recommend you change the password to all your accounts (crypto and non-crypto related).


If he has access to your email, they can reset google auth.


Most likely no. Usually the withdraw and deposit addresses are not the same on any platform.


Your bitcoins are now gone forever. Binance cannot do anything

The lesson is, never store your bitcoin in an exchange. You always have to avoid them. An exchange can get hacked at any point. Or you can. Its always best to create a wallet (not coinbase) where you own the private keys. Someone would have to break into your house to get those private keys.
If they manage to reset the google authenticator, would it mean I lost access to the google authenticator shown in my phone?
Quote Originally Posted by lanfeust11 View Post
If they manage to reset the google authenticator, would it mean I lost access to the google authenticator shown in my phone?
It means the google auth which is linked to your Binance account is essentially useless (not hacked). It doesn't mean all your google auth codes for other websites are "hacked".
I'm assuming all they did was click on "Forgot 2FA" on binance. They got a reset link sent to your email (which they had access to also). They reset your 2FA code to one they owned. Then withdrawed.

Note that these are all assumptions. I'm not sure what really happened
Quote Originally Posted by Allura View Post
It means the google auth which is linked to your Binance account is essentially useless (not hacked). It doesn't mean all your google auth codes for other websites are "hacked".
I'm assuming all they did was click on "Forgot 2FA" on binance. They got a reset link sent to your email (which they had access to also). They reset your 2FA code to one they owned. Then withdrawed.

Note that these are all assumptions. I'm not sure what really happened

You can't reset binance google authenticator that way. You have to send documents of you in RL and takes several days to process in order to reset the google authenticator.

I know this because a few months ago I lost my phone and I couldn't login because of I did not have access to my google authenticator. So I had to send in proof it was me and it took around a week for a response back. The guy did not have access to my computer for more than 20 minutes total, and only 2 mins pass from the hacker click on verify withdraw > for me to disable from the same email. This proves that not only the authenticator has a major flaw, but they should definitely make improvements with giving a few minutes to allow someone to disable the account before sending the payment to another random account never used before.
Quote Originally Posted by lanfeust11 View Post
You can't reset binance google authenticator that way. You have to send documents of you in RL and takes several days to process in order to reset the google authenticator.

I know this because a few months ago I lost my phone and I couldn't login because of I did not have access to my google authenticator. So I had to send in proof it was me and it took around a week for a response back. The guy did not have access to my computer for more than 20 minutes total, and only 2 mins pass from the hacker click on verify withdraw > for me to disable from the same email. This proves that not only the authenticator has a major flaw, but they should definitely make improvements with giving a few minutes to allow someone to disable the account before sending the payment to another random account never used before.
The verification software is automated. It’s only not automated if you fail the automated tests. If you have your documents on your email (for example you sent your documents when you were applying for a job) and it is in your sent box. The hacker had access to that. If you have a Facebook account with pictures of yourself, your photo can be edited in for the facial recognition.

I highly highly doubt they hacked google and your case does not mean there is a flaw in google auth. There are so many other things that could have happened. If they hacked google, why are they asking accounts with $1500? There is so many other things they could have done. For example if you really believe they hacked your computer, they probably hacked your wifi network too. Then they probably sent a mirror malware to your phone. Then from that, now they have access to your phone and can control your phone. Google did not get hacked, otherwise there would be some big news right now.

Or maybe they didn’t even hack your computer. Maybe they just hacked your phone directly.
Posts 16 of 6 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?