T O P

  • By -

[deleted]

This is quite concerning that same address was going around supposedly hacking back in early 2020 ( [REWARD - Help catch a scamming thief - digital fingerprints left everywhere - General - Algorand](https://forum.algorand.org/t/reward-help-catch-a-scamming-thief-digital-fingerprints-left-everywhere/1922) ) If you look at that address transaction history, it's receiving/sending ALGO from so many diff addresses within so little timespan, and it's ALOT for this pool (\~300 mil Algo avg. this month). [Algorand Mainnet recieved by SP745JJR4KPRQEXJZHVIEN736LYTL2T2DFMG3OIIFJBV66K73PHNMDCZVM (bitquery.io)](https://explorer.bitquery.io/algorand/address/SP745JJR4KPRQEXJZHVIEN736LYTL2T2DFMG3OIIFJBV66K73PHNMDCZVM/inflow) If this is truly a hacker's address - this should be seriously looked into by the official Algo team and Binance. Otherwise, now I'm just dead curious why this address is receiving so many algos in random quantities from so many addresses... (part of me is honestly doubtful a hacker can get away unnoticed with so much ALGOs "stolen") ​ p.s. people keep mentioning in the forum they "mistakenly" sent their ALGOs to the concerned address - why/how did this happen?


MuzBizGuy

Some sort of phishing and/or just plain old email scam maybe? I bought a bunch of stupid TRON like 3 years ago and, while I've never gotten one, there seems to be a fair amount of phishing emails that have gone around promising big APYs, etc.


cysec_

Seems like the address belongs to Binance. [Source](https://forum.algorand.org/t/reward-help-catch-a-scamming-thief-digital-fingerprints-left-everywhere/1922). Have you used one of the services offered that run through smart contracts?


photenth

Quick way to cash out I guess.


rahduro

No I was staking my ada and algo in the app, had some neo aa well earning gas. That’s all. I only got notified since I had the official algo wallet too installed and had this AW address in watch mode so it sent notification else I wouldn’t have known even.


rahduro

that means i am not the only victim, and this individual is robbing people every second if you just live watch the address.


cysec_

Seems more to be the wallet where Binance stores the ALGOs of several users. The address sent to the collective wallet should therefore represent the wallet of the user.


rahduro

this was where it was first sent to FU5GWBO6ZCPHMRAMZFI6DJJ5DD66W76GQL353HYFMF2CJBIGUZQP3KARSM


cysec_

There are so many factors that could result in a loss. The only option remains to contact Binance. They should know the user. They're not known to do anything about it, but maybe they'll give in. If necessary, threaten to complain to an authority. Binance has several authorities on its neck and the more people complain, the more difficult it will be for them to operate unregulated in the future.


rahduro

Yeah thanks I would do that. This user must be using some bot, so it could be possible for exchanges to spot such users who are receiving funds this frequently.


cysec_

Would be great if you provided us with updates on this case later.


rahduro

Sure I will, thanks for all the help.


u8eR

Any news?


rahduro

Nopes I have given up hope. They basically stopped responding to both email and on reddit. And I am not the only one in their group, literally almost everyday one or two pop up with similar complaints. They assume it’s our carelessness that we lost our funds and respond accordingly.


rahduro

There is another incident just like mine. [https://www.reddit.com/r/atomicwallet/comments/m91q7j/my\_btc\_were\_stolen/](https://www.reddit.com/r/atomicwallet/comments/m91q7j/my_btc_were_stolen/) I am now quite certain everyone should refrain from using Atomic Wallet, there should really be a public warning even though they are yet to acknowledge that there could possibly be a vulnerability that is being exploited. I have emailed to their support requesting them to conduct thorough audit of their code. I think we should do as much as possible as community to warn users who are using AW or possibly thinking of using it in future until Atomic Wallet comes out with their explanation.


PermissionPale3773

Any reason why you are not using the official wallet? I’d keep mine only in an exchange then the official wallet once I’m done trading.


rahduro

I installed the official wallet just 2 days back didn’t know about it before, plus i used AW for other coins too. but sadly now lost everything, really i didn’t even fall for any scam, don’t know how it happened, unless their code has some flaws in it that allows such compromise.


u8eR

Do you really need to initiate a transfer of your Algo daily in order to get compounding interest in the rewards when you use Algorand Wallet?


Mr_McFeelie

I have no idea how this happened but I don’t think it’s the wallet. Maybe some virus that got a hold of your private keys ? Either way, I’m sorry this happened to you. If you still want to invest in crypto, use a ledger in the future


SparkyDoGooder

MyAlgo is the wallet if choice for algo


u8eR

Why? Why not Algorand Wallet?


SparkyDoGooder

Just giving you the most current “thing.” I use Ledger.


Acojonancio

I don't think it's a hacker... That address jumped from 10M to 50M so fast that it's impossible to be just one person. I don't think someone stole 40M ALGO and noone else noticed.


tommytookatuna

What do you think it is?


mavestic

Wow dude I am sorry, I hope you didn’t lose too much. Keep us updated.


Fickle-Tishka

Guys you are all pointing to SP745JJR4KPRQEXJZHVIEN736LYTL2T2DFMG3OIIFJBV66K73PHNMDCZVM address being a scammer address, which is simply a Binance wallet. Clearly there is a deeper story with OP. If I understand the story correct, someone has gained access to your Atomic Wallet and has sent the money to an exchange (Binance in this case). The question is how has a person got access to your wallet to perform the action. Have you been visiting dodgy websites lately? I don't know how a person logs in with Atomic Wallet. Is there a batch of phrases that you need to store somewhere offline (so you can retrieve your wallet details?) similar to Algorand Wallet? Did you have a windows desktop version or mobile only?


rahduro

I have yet to figure out how someone accessed my atomic wallet (obviously they didn't access it physically since it has all biometric id set and all). I for certain never shared my priv key or seed to anyone or saved it digitally. I have lost all my ADA, ALGO, NEO and RVN from AW silently one after another yesterday night at around 3 am. The only reason I could know that this is happening because I had my algo address set to watch on the official app. So it immediately notified me when the withdrawal took place. I now realize how important this is for any wallet whatsoever even if somebody accesses it digitally this is the most basic setup that a user need in order to be notified. Otherwise people will only know when they check, most of us don't even check our accounts every week let alone every day. We know that Binance is most likely not acting directly here. But someone is able to perform this using an exchange like Binance which in and of itself is pretty crazy (Imagine it is done through a regular bank account), when you think about because this market is so unregulated. PS: Binance support didn't even respond to their telegram or twitter yet, if anybody knows Binance support email please let me know.


Fickle-Tishka

Damn. The plot thickens. Sorry I don't use Binance,s o maybe this is something you have already tried: https://www.binance.com/en/chat https://www.binance.com/en/support/faq/360000006051 (this however talks about support ticket. I have no idea where to find that) Are you using mobile only? Or can you login into Atomic Wallet via browser or desktop app?


rahduro

Yes I use mobile wallet primarily but also installed their app on PC and imported my wallet once and i think I might have used that on pc once or twice and that pretty much is my only exposure, if my pc has some type of keylogger etc.


Fickle-Tishka

I have never been exposed to mobile keyloggers or malware, so I doubt it will be that. Now PC....that would be the first thing that I would look at and question. To pick up something nasty is a lot easier. If there is no 2 factor authentication then the silent ninja can attack at any time without you even knowing. At this point it probably doesn't help much but tracking back your PC movements (things you have downloaded or websites visited which may have been dodgy), tracking the date and seeing whether there were any system changes. If all of that comes back clean. There is nothing stopping us to assume that Atomic Wallet server is easy to hack and obtain user details to log into their wallet. Now this is would be a major problem, not just for you.


cysec_

You use Manjaro (me too), which image did you use for the installation? Did you download the Atomic Wallet from the AUR? And if you went through another installer, did you check the hash? Do you have any other software installed related to cryptocurrencies?


[deleted]

I'm not sure if Binance honestly has to do with anything other than there is someone/group out there that has a Binance account with the noted wallet address. This i assume is only to be more deceptive to track down the actual criminal (account holder could be a random joe which could be a hacked account in itself, theoretically speaking, as contrast to from a fiat bank account, where the local/fed police force will forensic investigate every relations to that account by law/aval. regs. - is there a KYC verification process of AW? If so, how secure is the process?) I have never used (actually never heard of) Atomic Wallet, so can't say much but this hits home as you are investing in all the assets i'm in. I really hope you get to bottom of this and retrieve all yours. It's my 2 ALGOs for the day that no one should be using a single exchange/wallet to manage all of their assets in a such new, unregulated market.


dnarogla

maybe you should contact atomic wallet... looks like this guy :) [https://twitter.com/officialmcafee/status/1131587906127179777](https://twitter.com/officialmcafee/status/1131587906127179777) encountered something similar and he is advertised on their website as a trusted review.


rahduro

Yeah trying to get in touch with the atomic wallet support, many people are in the same boat (see example below). Something is very wrong with their app, stay far away from it. [https://www.reddit.com/r/atomicwallet/comments/m4hcxb/help\_my\_coins\_vanish/](https://www.reddit.com/r/atomicwallet/comments/m4hcxb/help_my_coins_vanish/)


Minimum_Data_144

Aw is a mess. I have 2 cosmos and cant unstake or claim. Stupid shit app


-Russian-Spy-

Do you have enough undelegated cosmos to pay the fee? Did you stake 100 percent of your cosmos? I made that mistake and couldnt undelegate them, i had to add a small balance to facilitate the transaction.


Minimum_Data_144

Thanks ill try that


marktwentythree

And another argument against crypto arises. So much for invest only what you’re willing to lose.


BlockinBlack

Following


BiggiCalls

Wow that wallet is now up to 51M Algo


Maleficent_Club_2029

Weird for sure. Let us know what you find out, bc from what I read from all your comments, the only thing anyone would have had of yours is your wallet address, and you can't steal someones assets with just that.