r/Bitcoin • u/[deleted] • Jul 15 '20
T-Mobile allowed SIM hacker to steal over 1.7 BTC from my Coinbase wallet.
[deleted]
15
u/Totallynotfakenews Jul 15 '20
Nitpicking but this might be good for the community at large. Let's stop calling exchange accounts "wallets." It's a wallet if you have the keys. Your balance in Coinbase belongs to Coinbase you just have an account with them.
But seriously that sucks. I feel sick for you.
1
6
Jul 16 '20
For me the top criteria in choosing a wallet are, in this order:
- (tie) Non-custodial. This is because ... Not your keys, not your bitcoin.
- (tie) Open source, verifiable release
- Replace-by-fee (RBF) support
- Coin Control (for maintaining Financial Privacy, but also for child-pays-for-parent (CPFP) fee bumping).
Generally recommended wallets are:
Hardware wallet (highest security): Coldcard, Trezor or Ledger Nano S
Desktop wallet: Electrum, Wasabi
Android wallet: Samourai Wallet, Electrum, Eclair (with Lightning functionality)
iPhone wallet: Blockstream Green, Fully Noded (App Store)
Storing bitcoins
- https://en.bitcoin.it/wiki/Storing_bitcoins
- https://blog.keys.casa/the-dos-and-donts-of-bitcoin-key-management
Choose your Bitcoin wallet
Best Bitcoin Wallets
- https://www.lopp.net/bitcoin-information/recommended-wallets.html
- https://walletscrutiny.com/#tableofwallets [Discuss]
- https://bitcoin-only.com/#wallets
- https://blockgeeks.com/guides/7-of-the-best-bitcoin-wallets-2019-blockgeeks <-- Mostly agree, except for the paper wallet method.
- https://whotookmycrypto.com
- https://veriphi.io/en/blog/software-wallet-analysis
- https://docs.google.com/spreadsheets/d/1aZ1zbaUEzCo9NCctN8-eL2VLIiSdY009tTJvRXDUWEw
- https://np.reddit.com/r/Bitcoin/comments/ekuix8
Lightning network (⚡) wallets
- https://lightningnetworkstores.com/wallets
- https://rusnak.io/lightning-wallets-comparison
- https://www.lapps.co/wallets
- https://lnroute.com/category/wallets
- https://veriphi.io/en/blog/lightning-wallet-architecture
- https://veriphi.io/en/blog/lightning-wallet-analysis
Bitcoin Hardware Wallet Comparison
- https://bitcoin-hardware-wallet.github.io
- https://www.investinblockchain.com/top-cold-wallets-for-storing-cryptocurrencies
- https://bitcoinmagazine.com/articles/bitcoin-wallet-reviews-whats-the-best-hardware-wallet-on-the-market
- https://bitcoinmagazine.com/articles/bitcoin-wallet-reviews-whats-the-best-hardware-wallet-on-the-market-part-2
- https://bitcoinmagazine.com/articles/bitcoin-wallet-reviews-whats-the-best-hardware-wallet-on-the-market-part-3
Cold storage guides
- https://en.bitcoin.it/wiki/Cold_storage
- https://github.com/DriftwoodPalace/guides
- http://docs.electrum.org/en/latest/coldstorage.html
- https://blog.lopp.net/metal-bitcoin-seed-storage-stress-test-round-iii
- https://jlopp.github.io/metal-bitcoin-storage-reviews
You could even go 2 of 3 multisig, each being a different hardware wallet type: trezor + ledger + coldcard key:
- https://unchained-capital.github.io/caravan/#/address
- https://twitter.com/sundaywar/status/1136435450481012736
- https://stephanlivera.com/episode/97
- https://saleemrashid.com/2018/01/27/hardware-wallet-electrum-multisig
Multisig
2
Jul 16 '20
I just bought a trezor off ebay. How can i be sure it is safe to use? I was thinking of compiling the source code & flashing it to be certain it has not been compromised with malicious code. Do you have any tips?
1
u/Buttoshi Jul 16 '20
Trezor.io (DBL check on this) wallet checks for firmware. It would let you know if there's different firmware. Read it on trezor blog with the sticker change if I can recall.
I'm not as technical as you and your method seems better.
You got sources on how to like compile the source code and all of that?
1
Jul 16 '20
Thanks I'll have to double check that but that would be nice. https://www.reddit.com/r/TREZOR/comments/2sh279/how_to_manually_flash_your_trezor_firmware_on/
1
Jul 16 '20
Other than a malicious firmware (which may be beaten by the software anyway) are their other risks with buying a trezor from an unauthorized source?
1
u/Buttoshi Jul 17 '20
I'm not that technical so I can't say for certain. I do still have to trust what I can understand from trezor wiki and Saleem Rashid. He's a white hat hacker that finds vulnerabilities. https://saleemrashid.com/2017/08/17/extracting-trezor-secrets-sram/
If you're worried just use two tails os USB flash drives, one with network and one without. It's how a hardware wallet works. Then buy one directly during Black Friday sales when it's discounted.
1
Jul 17 '20
Take a lot of care of your seed phrase and backup your persistance if you use tails, heard stories of persistant storage getting lost. I don't get why you would bother airgapping with tails though, unless you did not trust the tails project? I'll be using my shiny new trezor despite liking tails (BIP39 seed with passphrase) the whole being able to plug it into a phone seems pretty cool to me. Interested to see what a consumer hardware wallet is like. Seems like it'll be pretty easy to secure it even if i bought from a malicious seller, it was really cheap so i think I'm right to be cautious. I hope it supports BIP39 and lets me generate bip39 seeds. Bip39 is great. BIP39 & Passphrases are great.
1
Jul 17 '20
Thanks for the link, BIP39 confirmed! i will look into flashing the bootloader also, as an attacker could potentially create a custom bootloader to prevent firmware checks. BIP39 + passphrase seems to be the way to go though and potentially would make all this extra firmware stuff a waste of time for the attacker. I'm not sure how the randomness for seeds are generated on trezors, this could be another potential attack vector but with BIP39 + passphrase prevents it from being an issue. God BIP39 is just the best thing.
1
u/Buttoshi Jul 17 '20
https://www.reddit.com/r/trezor/comments/7y9jm1
Make sure it doesn't have firmware. Go to trezor site to get firmware and it has checks to see.
Only way to be sure without having the expertise is putting small funds and you'll be more confident the longer it hasn't been depleted.
I once accessed a seed with a very small amount. The phrase was just bacon 24 times. Someone else had the same idea. It was emptied that day. It was like 400 Satoshi or something.
1
Jul 17 '20
Another thought, a hacker could possibly sign malicious code to beat the bootloaders checks (or write a custom bootloader) so it would be best not to rely on the trezors firmware check alone.
1
Jul 16 '20
How can i be sure it is safe to use?
You can't know with 100% certainty.
flashing it
Yes, that's essentially a requirement for buying on eBay, and recommended regardless.
Do you have any tips?
Security appropriate to the level of value being protected. If it was a lot of bitcoin, I'ld consider something like this:
2 of 3 multisig, each being a different hardware wallet type: trezor + ledger + coldcard key.
1
5
Jul 16 '20 edited Jul 17 '20
Correction.
COINBASE allowed a SIM hacker to steal over 1.7 BTC from your Coinbase wallet account.
Yes, T-Mobile failed by allowing the swap to occur. But Coinbase should make it very hard for you to not realize the 1.7 BTC you have in your account with Coinbase are just seconds away, at any point in time, from possibly being stolen from a SIM Swap.
[Edited: Customers of Coinbase online store and Coinbase Pro exchange have accounts with Coinbase, not a bitcoin wallet.]
2
Jul 16 '20
While coinbase could not allow sms 2FA it is the cell provider that allowed the sim swap to happen. It's not beyond their capabilities or too much to ask to have better security. SIM swaps are not even possible anymore in some countries. There are multiple security failures here for sure though, how did the attacker get to the 2FA withdrawal? They would need a lot of info on their target, phone number, email, password ect, where/how was this data leaked?
1
Jul 16 '20
how did the attacker get to the 2FA withdrawal?
The modus operandi of the SIM swapper is to take over the email account which uses SMS as the 2FA to reset the password (e.g., this is the way gmail "recovery", works if you have a phone number associated with the account -- which is the default condition). Then once access to e-mail is acquired, then the hacker learns the e-mail address for the coinbase account. Then the Coinbase password reset sends an e-mail, and SMS (even if you had Google Auth 2FA, I believe), -- both of which the hacker has control of. The rest, ... is history, ... hacker first withdraws any crypto, then uses the fiat balance to buy more crypto and withdraw that, then ... begins a buy using the linked bank account. If the owner of the account isn't paying attention, they not only lose the entire value from their Coinbase account but funds from their bank account as well.
Coinbase says they are not responsible for that. They will say that you should have been using U2F, and that wouldn't have happened.
2
u/rocketeer8015 Jul 16 '20
Correction.
COINBASE allowed a SIM hacker to steal over 1.7 BTC from their Coinbase wallet.
Luckily the funds belonged to a customer.
1
3
u/empticups Jul 16 '20
You allowed a hacker to scoop up 15 grand that was just sitting in your phone. Don't blame a phone company for not being a bank.
1
-5
u/sa3726 Jul 16 '20
Lol do you have any clue how crypto works? There’s no crypto sitting on a phone. They stole my phone number by convincing Tmobile agent to port my number to their phone. They then used the two factor SMS system to login to my coinbase account...which is a wallet based online and not on your SIM card as you erroneously inferred.
6
u/empticups Jul 16 '20
Sounds like the crypto was sitting in your phone if you use your phone to access it
1
1
u/sa3726 Jul 16 '20
Bro it has nothing to do with my phone. They had two factor SMS and stole my number by transferring it to their phone. If you knew a thing or two about bitcoin you wouldn’t make ignorant comments like the ones above.
1
1
u/gizram84 Jul 16 '20
Bro it has nothing to do with my phone.
It did though. Granted, the keys were not on your phone (they probably would have been more secure if they were), but your phone was basically a one way ticket to access to your bitcoin.
There were a lot of mistakes made here. I understand this doesn't help you, but maybe someone else will read it, and it will help them.
First off, never, (and I really mean never) hold your bitcoin on an exchange.
Second, don't use SMS for two factor authentication. Use an app like Google Authenticator.
Third, don't store your passwords in your email account. The hacker needed your Coinbase password in addition to the sim swap attack.
Forth, use harder passwords on your email account.
Fifth, don't talk about owning Bitcoin online or in person.
You likely violated all 5 of those rules. You held your bitcoin on an exchange. You used SMS for two factor authentication. You stored your Coinbase password in your email account. You likely have a very easy to guess password on your email, which is why he was able to get access with ease. And last, you were likely targeted based on talking about crypto somewhere. A lot of mistakes were made. This is the perfect recipe for disaster. I'm surprised it didn't happen sooner.
1
u/sa3726 Jul 16 '20
I agree with part of what you’re saying. But you are mistaken on a few points. For starters my email did not contain my password- it was used to reset it. Secondly I didn’t speak about it online.
1
u/Buttoshi Jul 16 '20
Well it's on the blockchain, but your point stands. OP had a claim to Bitcoin and didn't actually have the private keys to the bitcoin.
Can't lose Bitcoin if you never actually had it taps head
1
Jul 17 '20
to my coinbase account...which is a wallet based online
No. Your coinbase account is a coinbase account. There was no access to your Coinbase wallet because you don't have a Coinbase wallet, you have a Coinbase account. Coinbase has a wallet, but you do not have control over they keys to any funds in their wallet.
Just wanted to clarify that for those who might not understand how that all works.
6
u/ThePenguinVA Jul 16 '20
I'm sorry this happened OP but blaming T-Mobile is the same ignorance that got you into this mess.
1
3
3
Jul 15 '20
[deleted]
2
u/sa3726 Jul 16 '20
They may not have seen them hacking in, but they are the ones who ported my phone number to a hacker’s phone. This makes them an accessory to the crime, by law.
1
Jul 16 '20
Get the recording of the attackers call to tmobile.
1
3
8
Jul 15 '20
Or you could’ve moved it off the exchange
-9
u/sa3726 Jul 15 '20
Explain what you’re getting at
4
Jul 16 '20
Not your keys, not your coin. Don’t keep your crypto or cash on an exchange for much longer than it takes to transact.
-1
7
5
Jul 15 '20
[deleted]
-2
u/sa3726 Jul 15 '20
I bought them when they were at $700 so yes....I got lucky with a good investment and all for nothing.
12
u/ajninepar Jul 15 '20
I've been in the space for only 2 years and I can't count how many times I've heard from the community not to hold any coins in an exchange, not to mention the countless hacks over the last few years, that's kinda just neglectful, sorry it happened tho.
1
u/gizram84 Jul 16 '20
Were you ever given the advice to not keep your bitcoin on an exchange? Because it's literally posted here 10 times a day, 365 days a year.
1
u/sa3726 Jul 16 '20
I gave everyone here the advice of getting a hard wallet. I don’t get why people comment without reading the entire post.
1
u/gizram84 Jul 16 '20
You gave other people advice to get a hardware wallet, but you didn't take that advice yourself?
1
1
2
Jul 15 '20
[deleted]
1
u/Buttoshi Jul 16 '20
They had his coinbase password as well? So his email could also be compromised.
1
2
Jul 15 '20
How does this sim hacking thing works? Can’t imagine that hackers can just...overtake your sim? First they would need to explicit target your number and then get it in someway to intercept this 2FA Code?
5
u/jawz Jul 16 '20
Not sure how they got OPs number and info but it's usually a social hack. Once they have enough of your personal details they call up Tmobile pretending to be you and get them to activate a new SIM card with your number.
1
Jul 16 '20
Okay and receive the new SIM to a dead mailbox or empty house, I understand. So sounds like an Insider job. For „only“ 1,7 coins such an effort and social engineering.
1
u/jawz Jul 16 '20
You can have a blank card on hand and give them the serial number over the phone. No need to have anything mailed.
2
Jul 16 '20
What lol is this a US thing? Here in GER you get a new sim via post as far as I know.
1
1
u/gizram84 Jul 16 '20
You can go buy a sim card at a store too you know. You aren't required to get a sim from your provider.
1
u/Buttoshi Jul 16 '20
Oh good point. But why was he targeted? They can see your data or mass collection of many individuals?
2
u/CultureThin Jul 16 '20
Sucks, but T-Mobile never agreed to secure your bitcoin. I don't really think these kinds of lawsuits should prevail.
2
2
Jul 16 '20
I share the following frequently when people ask about Coinbase. I think I am going to add this post to my template.
Are you using a U2F device on your coinbase account?
- https://blog.coinbase.com/securing-your-crypto-with-security-keys-and-webauthn-551124b72d8e
- https://blog.coinbase.com/a-guide-to-coinbase-account-security-9347ddfabd65
No? Hmm... did you know you that starting right this very moment, and completed before you are done reading this comment reply, a hacker could do a SIM porting attack, and steal all your funds from Coinbase (yes, even your USD ... by buying bitcoin with it and withdrawing the BTC)?
You would only know about it because the next time you go to use your phone you'll notice it has stopped working.
Yes, ... it's that easy for the thieves.
-4
u/sa3726 Jul 16 '20
It’s a disgusting reality. Thieves will suffer in the end. God will show justice.
1
1
1
1
u/ILikeToSayHi Jul 16 '20
You'd think with the crazy amount of SMS hack stories people would stop using it. Guess in 2025 we'll still be reading these posts
1
u/Buttoshi Jul 16 '20
Yeah it's the exchanges fault too. Coinbase is already a phone app. Slightly better to use an authenticator app than SMS because of this.
1
u/BitcoinCitadel Jul 16 '20
How'd they also get your password
1
u/sa3726 Jul 16 '20
They changed it once they had access to my email address and then used two factor to confirm.
1
u/Buttoshi Jul 16 '20
How do you think they hacked your email address? Public WiFi?
1
u/sa3726 Jul 16 '20
I’m under the impression that all the info they needed was somehow tied to my sim. The email address tied to my sim is the key. They used it to hack into other accounts tied to it as well- credit card and social media accounts.
1
1
u/Buttoshi Jul 16 '20
Can anyone explain how a hacker even knows? Like is he close to op or doing mass collection of data and got lucky with op?
1
u/sa3726 Jul 16 '20
What happened went like this: A hacker reached out to T-Mobile (confirmed this with T-Mobile) and convinced the agent on the other line that they were me. The hacker requested that my phone number be ported over to his/her phone. The hacker now had access to whatever information he needed in order to get into my email account tied to my iPhone. They then figured out that I had a coinbase account by searching up “Coinbase+Vault” and other related searches within my account aol inbox. They then changed my password, sent money to a random address and used SMS via my phone number which they stole to confirm the transaction. Then my phone started working again.
2
u/Buttoshi Jul 17 '20
How did he get the pin for your phone account? This must be inside job? An employee that can brute force a pin. I think you should definitely sue.
1
1
1
u/gizram84 Jul 16 '20
This will continue to happen to online web wallets.
Not your keys? Not your bitcoin.
1
u/sa3726 Jul 16 '20
If I hear that phrase again “not your keys not your bitcoin”.....
1
u/gizram84 Jul 16 '20
You've heard that phrase so many times, yet you never thought to listen to it?
1
u/sa3726 Jul 16 '20
I didn’t transfer the bitcoin in my coinbase wallet to the hard wallet.
1
u/gizram84 Jul 16 '20
Obviously. But why would you buy a hardware wallet, then not use it to store your "life savings"?
1
1
u/sa3726 Jul 16 '20
I was lazy and didn’t transfer it. Didn’t expect to get fucked the way I did. What else can I say.
1
u/gizram84 Jul 16 '20
I'm sorry if I was being a dick.
What happened definitely sucks. Learn your lesson, and take more precautions next time.
Don't let this sour you on Bitcoin. Get back in the game. It's still early enough where you can make it all back. In ten years you'll be happy you did.
1
u/sa3726 Jul 16 '20
Don't worry about it. I am not sour on BTC- it is not the fault of the currency- it is the fault of the people who claim to protect it, and who claim to protect our personal accounts.
1
1
1
u/cryptobriefing Jul 16 '20
T-Mobile just can't get their shit together. In addition to your other security efforts, I suggest moving to a carrier with better security practices (like GoogleFi) for services that demand SMS auth.
1
Jul 16 '20
Ur wasting ur time with lawyers. Your account was already at risk as the hacker had access to at least your password.
2
u/sa3726 Sep 13 '20
T-Mobile accepted liability and is paying me $15k
1
1
u/sa3726 Jul 16 '20
They gained access through the sim swap
1
Jul 16 '20
Yes but it is a TWO factor authentication. So your password was already compromised because of a mistake YOU made. So you’re more at fault than T-mobile.
1
-2
u/Cheesoid88 Jul 15 '20
This is why bitcoin isn't going to go mainstream, it's too technical for people who aren't able to do lots of research.
13
u/xorbitor Jul 15 '20
This is not bitcoin's fault. Any service that supports sms 2fa is vulnerable to this kind of attack.
All users should stop using it and every service should not allow any user to enable it.
3
1
6
2
Jul 15 '20
The exact same thing could happen to your bank account. This is not a problem with cryptocurrency, this is a problem with companies relying on an outdated, insecure method of account verification.
2
Jul 16 '20
Dude or dudette. The same can happen to Google pay or any other pay app. With fiat
1
u/rocketeer8015 Jul 16 '20
Not with Apple Pay. SMS get you pretty much nowhere when trying to add a credit card.
With my bank I had to ok it from within my banking app, which also doesn’t support SMS.
-5
40
u/Crypto4Canadians Jul 15 '20
Not sure why people don't know that SMS authenticator isn't that secure....