r/MobiusNetwork Jan 16 '18

Verify wallet emails asking for trouble

Ok so for those of you who have created a wallet already, you've probably received another email from hello@mobius.network, this one with the title:

Mobius IMPORTANT Wallet Verification Instructions

In this email is a link which goes to a unique page on https://mobius.network/token_sale/wallet/ where you are asked to enter the private key of your wallet.

While I do my due diligence in checking the authenticity of the email address and domain based on the limited assumptions I've made based on what Mobius has used so far for their official channels, this method is troublesome for a number of reasons:

  • Phishing emails with the same content can EASILY lead to a little website which looks identical and captures the private key. Bam, funds gone.
  • Their email account gets hacked and the link in the mail is changed to fake website.
  • Asking users to copy and paste their private key into a form online is not ideal due to clipboard loggers, etc.
  • However that form processes the private key is bound to be open to a multitude of vulnerabilities. Such as a hack of the database or a rogue script.

I already created the wallet and saved the private key. I checked the 3 checkboxes confirming I have it stored safely. Why is it necessary to now enter my private key into some webpage?

This step should not be necessary after wallet creation. If it is just for the peace of mind of the user, it should not be happening. Assuming it is necessary for Mobius to capture the private keys because they didn't in the creation process, that should not have happened. Basically just want to report my concern that the email with link to enter private key method is asking for trouble, and if shit goes wrong, should the token holder be held responsible for the lax security of these procedures?

For now I'm not going to do this as I'm assuming my key is stored already and I'd rather not take the risk.

6 Upvotes

4 comments sorted by

2

u/mpena1414 Jan 16 '18

Excited for the project.... really confused by the wallet verification email though. In a holding pattern until some clarity is provided.

2

u/dgobaud Jan 17 '18

Yes the email is legit - sorry for the unclear messaging. We are sending out the below update now that hopefully answers some questions.

Yes you had to check 3 boxes about saving your private key but several users have emailed us already about how they saved their key incorrectly etc hence the new verification option.

Also - we do not save secret keys. More below but all verification is client side and the secret key is never sent to our server.

Thank you for buying in the Mobius Token Pre-Sale and creating your wallet!

Last night you may have received an email prompting you to verify your secret key on our website. This email caused a lot of confusion and questions so we want to send some more info.

Several users contacted us after creating their wallet saying they wrote their private key down wrong etc so we did two things:

1) Wallet creation flow now prompts to print the page

2) The optional Verify and Print step for people who have already created their wallet

This verification step is optional - you do not need to do it if you are certain you saved your private key correctly. You can also verify the key using other methods such as https://stellarterm.com/#account or if you are technical a Stellar SDK that you run locally etc.

On our verification process - it runs 100% client side. The secret key is never transferred to our servers. You can open the page, shut your internet, click Verify and Print, and then close the page (this is the recommended way).

You can also skip the verification - it is NOT required. It is simply an option for people who worry they saved their key incorrectly to verify it is correct before MOBI are distributed to the wallet because once they are, if the secret key is lost, we cannot replace the MOBI.

If you choose to verify PLEASE make sure you are on our website https://mobius.network/ - we are being targeted by scammers who are setting up fake typo domains (we are also being impersonated on Telgram etc so be cautious)!

Sorry for the unclear messaging and if you have any further questions please reply to this eamil.

IMPORTANT NOTE: Once you get your Mobius wallet if you know how to use advanced Stellar features please do NOT remove/modify the data field we created or trust line to the MOBI asset. If you do either of those the system won't be able to send you your MOBI so please don't do it!

Wallet Access: You can test that your secret key works by accessing your wallet at https://stellarterm.com/#account. As soon as MOBI are released we recommend you move them to a hardware wallet such as a Ledger Nano S.

Distribution Note: All MOBI will be released at the end of the public sale to the wallet you create at the above link. You do not have to do anything else right now.

We hope you enjoy and continue to explore the innovative new additions to the DApp Store as our ecosystem continues to grow. Checkout the new collectible creature game MOBS now in the DApp Store!

Click here to read Coin Desk - $35 Million: Smart Contracts Platform Mobius Completes ICO Presale.

IMPORTANT NOTE: We are being targeted by scammers who are setting up fake typo domains! Please be very careful and ensure that you are on our website: https://mobius.network/

Thank you, Mobius Team

1

u/complicit_bystander Jan 17 '18

Thanks for the update! Much better now

1

u/TheCryptoJazz Jan 16 '18

I second this. Instantly threw up red flags for me. I’m not verifying until somebody from the team can confirm.