Binance hack: If bitcoin is so safe, why is it a target ...

$44 Million Binance Hackers Shuffle 7 Crypto Wallets with Stolen Bitcoin

$44 Million Binance Hackers Shuffle 7 Crypto Wallets with Stolen Bitcoin submitted by cryptosyringe to Bitcoin [link] [comments]

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin submitted by n4bb to CoinPath [link] [comments]

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin submitted by leftok to atbitcoin [link] [comments]

$44 Million Binance Crooks Shuffle 7 Crypto Wallets with Stolen Bitcoin

$44 Million Binance Crooks Shuffle 7 Crypto Wallets with Stolen Bitcoin submitted by THEZUKUS to VIRALNEWS_ZUKUS [link] [comments]

Binance Hackers Are Juggling the Stolen Bitcoin Between Multiple Wallets

Binance Hackers Are Juggling the Stolen Bitcoin Between Multiple Wallets submitted by MundoMoedas to Cryptochillout [link] [comments]

Binance Hackers Are Juggling the Stolen Bitcoin Between Multiple Wallets

Binance Hackers Are Juggling the Stolen Bitcoin Between Multiple Wallets submitted by n4bb to CoinPath [link] [comments]

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin submitted by cryptoallbot to cryptoall [link] [comments]

@WSJ: Binance discovered that 7,000 bitcoins were stolen from a single wallet, amounting to roughly 2% of the company’s total bitcoin holdings https://t.co/ZD6tZuyLpG

submitted by -en- to newsbotbot [link] [comments]

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin - CCN

$44 Million Binance Hackers Shuffle Seven Crypto Wallets with Stolen Bitcoin - CCN submitted by prnewswireadmin to cryptonewswire [link] [comments]

$5 million worth Bitcoin [BTC] stolen from Bitmain's Binance custodial wallet; transferred to Bittrex

$5 million worth Bitcoin [BTC] stolen from Bitmain's Binance custodial wallet; transferred to Bittrex submitted by ulros to fbitcoin [link] [comments]

I bought my 1st Bitcoin, now what?

HELLO BIITCONNEEEECT! (if you know you know)
I just bought my first bitcoin and I'm pretty happy with the outcome so far. I signed up for Binance and downloaded Exodus (cryptowallet).
Ideally I'd like to now move on with my life.
However, I've been told to send all my bitcoin into a wallet of my own, instead of leaving it in Binance's wallet. I'm not sure why, I'm assuming it's due to security concerns?
Anyway, I'm curious as to how do I send my bitcoin from Binance to my wallet?
Furthermore, what if my computer gets stolen or damaged? Can I still access my Exodus?
I tried searching Google before I came to you guys, but all the info is too much for me and I'm too old to get into this stuff, I just wanted to invest a bit given the following news:
"BANK OF ENGLAND IS SAID TO BE CONSIDERING A CONTROVERSIAL MOVE INTO NEGATIVE INTEREST RATES - THE TELEGRAPH"
Many thanks, everyone.
submitted by bigpappabelly to BitcoinBeginners [link] [comments]

Bob The Magic Custodian



Summary: Everyone knows that when you give your assets to someone else, they always keep them safe. If this is true for individuals, it is certainly true for businesses.
Custodians always tell the truth and manage funds properly. They won't have any interest in taking the assets as an exchange operator would. Auditors tell the truth and can't be misled. That's because organizations that are regulated are incapable of lying and don't make mistakes.

First, some background. Here is a summary of how custodians make us more secure:

Previously, we might give Alice our crypto assets to hold. There were risks:

But "no worries", Alice has a custodian named Bob. Bob is dressed in a nice suit. He knows some politicians. And he drives a Porsche. "So you have nothing to worry about!". And look at all the benefits we get:
See - all problems are solved! All we have to worry about now is:
It's pretty simple. Before we had to trust Alice. Now we only have to trust Alice, Bob, and all the ways in which they communicate. Just think of how much more secure we are!

"On top of that", Bob assures us, "we're using a special wallet structure". Bob shows Alice a diagram. "We've broken the balance up and store it in lots of smaller wallets. That way", he assures her, "a thief can't take it all at once". And he points to a historic case where a large sum was taken "because it was stored in a single wallet... how stupid".
"Very early on, we used to have all the crypto in one wallet", he said, "and then one Christmas a hacker came and took it all. We call him the Grinch. Now we individually wrap each crypto and stick it under a binary search tree. The Grinch has never been back since."

"As well", Bob continues, "even if someone were to get in, we've got insurance. It covers all thefts and even coercion, collusion, and misplaced keys - only subject to the policy terms and conditions." And with that, he pulls out a phone-book sized contract and slams it on the desk with a thud. "Yep", he continues, "we're paying top dollar for one of the best policies in the country!"
"Can I read it?' Alice asks. "Sure," Bob says, "just as soon as our legal team is done with it. They're almost through the first chapter." He pauses, then continues. "And can you believe that sales guy Mike? He has the same year Porsche as me. I mean, what are the odds?"

"Do you use multi-sig?", Alice asks. "Absolutely!" Bob replies. "All our engineers are fully trained in multi-sig. Whenever we want to set up a new wallet, we generate 2 separate keys in an air-gapped process and store them in this proprietary system here. Look, it even requires the biometric signature from one of our team members to initiate any withdrawal." He demonstrates by pressing his thumb into the display. "We use a third-party cloud validation API to match the thumbprint and authorize each withdrawal. The keys are also backed up daily to an off-site third-party."
"Wow that's really impressive," Alice says, "but what if we need access for a withdrawal outside of office hours?" "Well that's no issue", Bob says, "just send us an email, call, or text message and we always have someone on staff to help out. Just another part of our strong commitment to all our customers!"

"What about Proof of Reserve?", Alice asks. "Of course", Bob replies, "though rather than publish any blockchain addresses or signed transaction, for privacy we just do a SHA256 refactoring of the inverse hash modulus for each UTXO nonce and combine the smart contract coefficient consensus in our hyperledger lightning node. But it's really simple to use." He pushes a button and a large green checkmark appears on a screen. "See - the algorithm ran through and reserves are proven."
"Wow", Alice says, "you really know your stuff! And that is easy to use! What about fiat balances?" "Yeah, we have an auditor too", Bob replies, "Been using him for a long time so we have quite a strong relationship going! We have special books we give him every year and he's very efficient! Checks the fiat, crypto, and everything all at once!"

"We used to have a nice offline multi-sig setup we've been using without issue for the past 5 years, but I think we'll move all our funds over to your facility," Alice says. "Awesome", Bob replies, "Thanks so much! This is perfect timing too - my Porsche got a dent on it this morning. We have the paperwork right over here." "Great!", Alice replies.
And with that, Alice gets out her pen and Bob gets the contract. "Don't worry", he says, "you can take your crypto-assets back anytime you like - just subject to our cancellation policy. Our annual management fees are also super low and we don't adjust them often".

How many holes have to exist for your funds to get stolen?
Just one.

Why are we taking a powerful offline multi-sig setup, widely used globally in hundreds of different/lacking regulatory environments with 0 breaches to date, and circumventing it by a demonstrably weak third party layer? And paying a great expense to do so?
If you go through the list of breaches in the past 2 years to highly credible organizations, you go through the list of major corporate frauds (only the ones we know about), you go through the list of all the times platforms have lost funds, you go through the list of times and ways that people have lost their crypto from identity theft, hot wallet exploits, extortion, etc... and then you go through this custodian with a fine-tooth comb and truly believe they have value to add far beyond what you could, sticking your funds in a wallet (or set of wallets) they control exclusively is the absolute worst possible way to take advantage of that security.

The best way to add security for crypto-assets is to make a stronger multi-sig. With one custodian, what you are doing is giving them your cryptocurrency and hoping they're honest, competent, and flawlessly secure. It's no different than storing it on a really secure exchange. Maybe the insurance will cover you. Didn't work for Bitpay in 2015. Didn't work for Yapizon in 2017. Insurance has never paid a claim in the entire history of cryptocurrency. But maybe you'll get lucky. Maybe your exact scenario will buck the trend and be what they're willing to cover. After the large deductible and hopefully without a long and expensive court battle.

And you want to advertise this increase in risk, the lapse of judgement, an accident waiting to happen, as though it's some kind of benefit to customers ("Free institutional-grade storage for your digital assets.")? And then some people are writing to the OSC that custodians should be mandatory for all funds on every exchange platform? That this somehow will make Canadians as a whole more secure or better protected compared with standard air-gapped multi-sig? On what planet?

Most of the problems in Canada stemmed from one thing - a lack of transparency. If Canadians had known what a joke Quadriga was - it wouldn't have grown to lose $400m from hard-working Canadians from coast to coast to coast. And Gerald Cotten would be in jail, not wherever he is now (at best, rotting peacefully). EZ-BTC and mister Dave Smilie would have been a tiny little scam to his friends, not a multi-million dollar fraud. Einstein would have got their act together or been shut down BEFORE losing millions and millions more in people's funds generously donated to criminals. MapleChange wouldn't have even been a thing. And maybe we'd know a little more about CoinTradeNewNote - like how much was lost in there. Almost all of the major losses with cryptocurrency exchanges involve deception with unbacked funds.
So it's great to see transparency reports from BitBuy and ShakePay where someone independently verified the backing. The only thing we don't have is:
It's not complicated to validate cryptocurrency assets. They need to exist, they need to be spendable, and they need to cover the total balances. There are plenty of credible people and firms across the country that have the capacity to reasonably perform this validation. Having more frequent checks by different, independent, parties who publish transparent reports is far more valuable than an annual check by a single "more credible/official" party who does the exact same basic checks and may or may not publish anything. Here's an example set of requirements that could be mandated:
There are ways to structure audits such that neither crypto assets nor customer information are ever put at risk, and both can still be properly validated and publicly verifiable. There are also ways to structure audits such that they are completely reasonable for small platforms and don't inhibit innovation in any way. By making the process as reasonable as possible, we can completely eliminate any reason/excuse that an honest platform would have for not being audited. That is arguable far more important than any incremental improvement we might get from mandating "the best of the best" accountants. Right now we have nothing mandated and tons of Canadians using offshore exchanges with no oversight whatsoever.

Transparency does not prove crypto assets are safe. CoinTradeNewNote, Flexcoin ($600k), and Canadian Bitcoins ($100k) are examples where crypto-assets were breached from platforms in Canada. All of them were online wallets and used no multi-sig as far as any records show. This is consistent with what we see globally - air-gapped multi-sig wallets have an impeccable record, while other schemes tend to suffer breach after breach. We don't actually know how much CoinTrader lost because there was no visibility. Rather than publishing details of what happened, the co-founder of CoinTrader silently moved on to found another platform - the "most trusted way to buy and sell crypto" - a site that has no information whatsoever (that I could find) on the storage practices and a FAQ advising that “[t]rading cryptocurrency is completely safe” and that having your own wallet is “entirely up to you! You can certainly keep cryptocurrency, or fiat, or both, on the app.” Doesn't sound like much was learned here, which is really sad to see.
It's not that complicated or unreasonable to set up a proper hardware wallet. Multi-sig can be learned in a single course. Something the equivalent complexity of a driver's license test could prevent all the cold storage exploits we've seen to date - even globally. Platform operators have a key advantage in detecting and preventing fraud - they know their customers far better than any custodian ever would. The best job that custodians can do is to find high integrity individuals and train them to form even better wallet signatories. Rather than mandating that all platforms expose themselves to arbitrary third party risks, regulations should center around ensuring that all signatories are background-checked, properly trained, and using proper procedures. We also need to make sure that signatories are empowered with rights and responsibilities to reject and report fraud. They need to know that they can safely challenge and delay a transaction - even if it turns out they made a mistake. We need to have an environment where mistakes are brought to the surface and dealt with. Not one where firms and people feel the need to hide what happened. In addition to a knowledge-based test, an auditor can privately interview each signatory to make sure they're not in coercive situations, and we should make sure they can freely and anonymously report any issues without threat of retaliation.
A proper multi-sig has each signature held by a separate person and is governed by policies and mutual decisions instead of a hierarchy. It includes at least one redundant signature. For best results, 3of4, 3of5, 3of6, 4of5, 4of6, 4of7, 5of6, or 5of7.

History has demonstrated over and over again the risk of hot wallets even to highly credible organizations. Nonetheless, many platforms have hot wallets for convenience. While such losses are generally compensated by platforms without issue (for example Poloniex, Bitstamp, Bitfinex, Gatecoin, Coincheck, Bithumb, Zaif, CoinBene, Binance, Bitrue, Bitpoint, Upbit, VinDAX, and now KuCoin), the public tends to focus more on cases that didn't end well. Regardless of what systems are employed, there is always some level of risk. For that reason, most members of the public would prefer to see third party insurance.
Rather than trying to convince third party profit-seekers to provide comprehensive insurance and then relying on an expensive and slow legal system to enforce against whatever legal loopholes they manage to find each and every time something goes wrong, insurance could be run through multiple exchange operators and regulators, with the shared interest of having a reputable industry, keeping costs down, and taking care of Canadians. For example, a 4 of 7 multi-sig insurance fund held between 5 independent exchange operators and 2 regulatory bodies. All Canadian exchanges could pay premiums at a set rate based on their needed coverage, with a higher price paid for hot wallet coverage (anything not an air-gapped multi-sig cold wallet). Such a model would be much cheaper to manage, offer better coverage, and be much more reliable to payout when needed. The kind of coverage you could have under this model is unheard of. You could even create something like the CDIC to protect Canadians who get their trading accounts hacked if they can sufficiently prove the loss is legitimate. In cases of fraud, gross negligence, or insolvency, the fund can be used to pay affected users directly (utilizing the last transparent balance report in the worst case), something which private insurance would never touch. While it's recommended to have official policies for coverage, a model where members vote would fully cover edge cases. (Could be similar to the Supreme Court where justices vote based on case law.)
Such a model could fully protect all Canadians across all platforms. You can have a fiat coverage governed by legal agreements, and crypto-asset coverage governed by both multi-sig and legal agreements. It could be practical, affordable, and inclusive.

Now, we are at a crossroads. We can happily give up our freedom, our innovation, and our money. We can pay hefty expenses to auditors, lawyers, and regulators year after year (and make no mistake - this cost will grow to many millions or even billions as the industry grows - and it will be borne by all Canadians on every platform because platforms are not going to eat up these costs at a loss). We can make it nearly impossible for any new platform to enter the marketplace, forcing Canadians to use the same stagnant platforms year after year. We can centralize and consolidate the entire industry into 2 or 3 big players and have everyone else fail (possibly to heavy losses of users of those platforms). And when a flawed security model doesn't work and gets breached, we can make it even more complicated with even more people in suits making big money doing the job that blockchain was supposed to do in the first place. We can build a system which is so intertwined and dependent on big government, traditional finance, and central bankers that it's future depends entirely on that of the fiat system, of fractional banking, and of government bail-outs. If we choose this path, as history has shown us over and over again, we can not go back, save for revolution. Our children and grandchildren will still be paying the consequences of what we decided today.
Or, we can find solutions that work. We can maintain an open and innovative environment while making the adjustments we need to make to fully protect Canadian investors and cryptocurrency users, giving easy and affordable access to cryptocurrency for all Canadians on the platform of their choice, and creating an environment in which entrepreneurs and problem solvers can bring those solutions forward easily. None of the above precludes innovation in any way, or adds any unreasonable cost - and these three policies would demonstrably eliminate or resolve all 109 historic cases as studied here - that's every single case researched so far going back to 2011. It includes every loss that was studied so far not just in Canada but globally as well.
Unfortunately, finding answers is the least challenging part. Far more challenging is to get platform operators and regulators to agree on anything. My last post got no response whatsoever, and while the OSC has told me they're happy for industry feedback, I believe my opinion alone is fairly meaningless. This takes the whole community working together to solve. So please let me know your thoughts. Please take the time to upvote and share this with people. Please - let's get this solved and not leave it up to other people to do.

Facts/background/sources (skip if you like):



Thoughts?
submitted by azoundria2 to QuadrigaInitiative [link] [comments]

How DAO users can truly control their voting rights

How DAO users can truly control their voting rights
https://blockchaintopbuzz.medium.com/how-dao-users-can-truly-control-their-voting-rights-f945c9c6b65e
Aelf proposed a solution that gives the control of the voting rights back to users by classifying token permissions.
As of today, there are still few complete businesses. In addition to mining and building trading platforms, it is difficult to create a complete business model. Moreover, various trading platforms have gradually grown into enterprises with comprehensive products in the blockchain industry, including wallets, nodes, lending, mining pools, etc.
At the same time, cloud services can reduce the cost of building small exchanges, but they can also lead to big trading platforms monopolizing data. For example, some Internet companies provide free cloud services in order to collect more valuable data.
Currently, Ethereum, which has the richest DeFi ecosystem, is gradually upgrading to V2.0, and its consensus protocol will also be upgraded to PoS. Governance voting can be regarded as the most important feature in the PoS ecosystem.
This year, Yearn.Finance rose to sudden prominence. But due to the governance problem, its community members initiated a hard fork, resulting in YFII. Another DeFi project, YAM, had a unfixable rebase function error. The founding team apologized for the error and announced a ‘Migration Plan’, which will turn the project over to the community.
For a while, governance voting became all the rage. However, the increasingly bigger trading platforms have been criticized by users in governance voting. Is there a proper solution to handling the relationship between the trading platform and governance voting?

What will we lose when trading platforms monopolize the blockchain industry?

In June 2018, during the BP node election before the EOS mainnet launch, node voting began to have a crisis of confidence between token holders and the trading platform. it is widely believed that the top 20 holders of trading platform wallets held about 40% of all the EOS in circulation.
Since then, many trading platforms have enabled the “User Authorization” interface. EOS holders can authorize the token voting rights to the trading platform, who will vote on behalf of the users. The rule caused a backlash from users, forcing these trading platforms to change the rule immediately so that EOS holders could vote on their preferred BP nodes.
After the EOS BP node votes, whether the trading platform has the token voting right has been occasionally discussed, but fewhave noticed it.
Two years later, Justin Sun, founder of TRON, made a commercial acquisition of Steemit, a decentralized social networking platform. After the acquisition was announced, the Steemit community launched a soft fork to resist the project being controlled by TRON. However, Justin Sun voted with the support of trading platforms such as Binance, Huobi and Poloniex to prevent a soft fork.
After being questioned by users, Binance and Huobi said that they would no longer interfere in the voting of the Steemit community. However, hkdev 404 of the Steem community again reveived votes from Huobi accounts. It is said that nearly 40 million votes were cast during the incident, accounting for about 10% of the total circulation of STEEM tokens.
There is no doubt that when the trading platform monopolizes the industry, we will lose our voting right.
How do we defend our voting rights
The fact that the ownership of the tokens belongs to the holders is indisputable, but what about the voting rights of the tokens deposited on the trading platform? How can we defend our voting rights after trading platforms have monopolized the industry?

Trading Platform Model

Traditional centralized trading platforms will assign to each user a separate deposit address. After depositing, the depositedamount will be added into the cold wallet and hot wallet. When users want to withdraw their tokens, the trading platform will transfer the tokens out of the hot wallet. If there is insufficient balance in the hot wallet, then the tokens will be transferred from the cold wallet to the hot wallet, and then be withdrawn.
Under the traditional centralized trading platform model, once users transfer their tokens into a trading platform, it means thetoken ownership (including voting rights) is also transferred to that trading platform.
The aelf solution: classify token permissions and claim back voting rights
For the issue of “voting rights” between token holders and centralized trading platforms, aelf, a decentralized cloud computing blockchain network, has proposed a solution: to establish an aelf Centre Asset Management Contract on the chain. The contract can limit the funds entering the exchange and define different permissions to control the assets.
The main feature of the aelf Centre Asset Management Contract is to create the “Main Virtual Address of the Trading Platform”.
Each exchange has a main virtual address, which can only be used for transfer operation, but not for voting, trading and other operations. As a result, the exchange cannot misappropriate users’ assets for voting. At the same time, the assets of the primary virtual address are publicly available on the chain, which makes it more difficult for the exchange to misappropriate assets.
At the same time, the aelf Centre Asset Management Contract also has the function of “address definition”. The exchange can open different permissions to different addresses, such as opening different permissions according to the amount, transactions exceeding a certain amount can only be given the greenlight by using multiple signatures, and the assets can be frozen through the contract when the assets of the trading platform are stolen, etc.
For the users of the trading platform, the access of the trading platform to the aelf Center Asset Management Contract function will not undermine user experience. The virtual system address of the aelf Center Asset Management Contract will assign a virtual address to each user, which offers the same user experience as the traditional mode.
For the trading platform, each deposit address constructed by the virtual address system is generated by the algorithm and does not need to be carried out on the blockchain. This means that the trading platform does not need to manage a large number of private keys, and there is no risk that the private keys will be lost.
On the most important “voting rights” issue, the aelf Center Asset Management Contract will assign to each user a separate virtual address for voting:
Voting address = Hash (Exchange Main Address + Token + “VOTE”)
Voting process: the tokens are transferred from the main virtual address of the exchange to the special “voting address” for voting, and are then voted. After voting, the tokens are withdrawn from the voting address back to the main virtual address.
We can see that the aelf Centre Asset Management Contract proposed by aelf can improve the efficiency of the trading platform without affecting user experience. In addition, it solves the problem that users would lose their voting rights.
According to the data on Crypto Mode, the market value of PoS tokens has exceeded $33 billion without counting Ethereum. In the field of crypto, it is the biggest ecosystem next to Bitcoin. The most important function of PoS is vote staking. faced with bigtrading platforms, if the status quo continues, retail investors will gradually lose their “voting rights” that belong to them.

Comparison of Market Value of PoS tokens (Source: Crypto Mode)
The emergence of DAO offers an alternative to trading platforms who misappropriate users’ tokens, but it still can not change this situation. Of course, DAO will not die out. Small communities will still use DAO for community governance. The idea behind the design of aelf is to start from the underlying trading platform and solve this issue at the source. Whether the solution can work still takes time. However, as a member of the crypto industry, we should understand the importance of “voting rights”, and cannot allow the exchange to seize our rights at will.
Recently, aelf has also announced its DeFi plan, which includes a new blockchain 3.0 project with a large number of new technical features, such as cross chain function, virtual address and cloud services. Aelf also proposed a set of interoperability solutions with ERC-20 tokens. It can directly access the ETH ecosystem, allow ETH-based applications and wallets to directly access it, and maintain the interoperability with ETH. And aelf will provide a high-performance smart contract operation platform and cloud services that can support cross chain interaction. Users on major cloud servers can easily run aelf’s services and adjust the scale of cloud according to their own business needs.
The implementation of a slew of tools, cloud services and interoperability solutions developed by aelf means that centralized transactions can be directly connected to the aelf network, realizing one-click adaptation to the DeFi ecosystem. With aelf, CeFi and DeFi are able to learn from and complement each other.
submitted by Floris-Jan to aelfofficial [link] [comments]

How to purchase and exchange your litecoin! (longer read)

This post will show you the best ways to buy litecoins using many different payment methods and exchanges for each method.
Before you start, make sure you have a good litecoin wallet to store your LTC. NEVER store your litecoins on a crypto exchange.

Popular Exchanges

eToro
Coinbase
Coinmama

Buy Litecoin with Credit Card or Debit Card

Let’s dive into some of the exchanges supporting Litecoin credit card purchases.
These exchanges are our favorite ways to buy.

Coinbase

Coinbase is the easiest way to buy litecoins with a credit card.
Coinbase is available in the United States, Canada, Europe, UK, Singapore, and Australia.
The fees will come out to 3.99% per purchase.
Here is a good video that can help walk you through the process of buying on Coinbase, although it’s fairly easy.

Coinmama

Coinmama recently added the ability to buy litecoin directly on the platform. Users from nearly any country in the world can use Coinmama to buy litecoins.
Coinmama has some of the highest limits among credit card exchanges.

BitPanda

BitPanda is based in Austria and is a crypto brokerage service. You can buy using a credit card from most European countries.

CEX.io

CEX.io is based in the UK and is one of the oldest crypto exchanges online.
CEX.io supports litecoin and its users from nearly anywhere in the world can buy litecoin with credit card on the platform.

Buy Litecoin with Bank Account or Bank Transfer

Coinbase

Coinbase is the easiest way to buy litecoins with a bank account or transfer.
Coinbase, like is is for credit cards, is available in the United States, Canada, Europe, UK, Singapore, and Australia.
Coinbase is one of primary exchanges used to buy Litecoins.
Americans can use ACH transfer (5–7 days wait), and Europeans can use SEPA transfer (1–3 days wait).
The fees will come out to 1.49% per purchase.

BitPanda

BitPanda is based in Austria and is a crypto brokerage service. You can buy using SEPA transfer from most European countries. You can also use SOFORT, NETELLER, or GiroPay.

CEX.io

CEX.io also supports litecoin buys via bank account. This is via wire transfer for US citizens, SEPA for Europe, and SWIFT for the rest of the globe.

Binance

Binance is now one of the largest if not the largest cryptocurrency exchange in the world. It supports bank and card purchases of Litecoin as well as Litecoin trading pairs with Bitcoin and Etehreum.

Get a Litecoin Wallet

Before we move onto other options:
Never store your litecoins on an exchange!
Always withdrawal your litecoin to an offline cryptocurrency wallet like the Ledger Nano S or any other wallet that you control.
The Ledger Nano S and TREZOR are the best options for secure storage.

Other Methods to Buy Litecoin

If you don’t have a card or want to avoid the high fees, you can use the following methods to buy Litecoin as well.
Find out which one works best for you.

Buy Litecoin with PayPal

Unfortunately, there is no easy way to buy Litecoin with PayPal. Other sites will tell you that cex allows for this, but that is no longer the case.
You can, however, now use eToro to buy Litecoin, unless you live in the United States.
If you live in the US, the only way to buy Litecoin with Paypal is to buy Bitcoin using paypal, and then use the Bitcoins to buy Litecoin. You can easily buy Bitcoin using Paypal on Local Bitcoins. Once you have Bitcoin, you can use an exchange like Coinbase Pro to swap the Bitcoin for Litecoin.

Buy Litecoin with Cash

There is no good way to buy litecoins with cash. LocalBitcoins is the most popular way to buy bitcoins with cash, and it does not have Litecoin support. Other popular cash to Bitcoin exchanges like BitQuick and Wall of Coins also do not support LTC. So you will have to first buy bitcoins with cash then exchange them for LTC using the method described below.
The same goes for Bitcoin ATMs. Most do not support Litecoin. So if you want to buy litecoins at a Bitcoin ATM you first have to buy bitcoins and then trade the BTC for litecoins.

Buy Litecoin with Bitcoin

If you already have Bitcoins then it is VERY simple to convert some of your BTC to litecoins.
You just need to find an exchange with the LTC/BTC pair, which is most exchanges since LTC/BTC is a very popular pair to trade.

Buy Litecoin with Skrill

BitPanda, mentioned above, also accepts Skrill payments for LTC. The fees will vary and are simply included in your buy price.

Cryptmixer

Cryptmixer is probably the fastest way to convert BTC to Litecoin. You just enter the amount of LTC you want to buy, and give them a LTC address. Then they will tell you how much BTC to send to their address. Once your BTC is sent, you will have LTC delivered to your wallet very shortly after.

Buy Litecoin with Ethereum

Ethereum has experienced a massive price rise. Nearly a year ago it was $10, and now at over $500, many want to move some of their ETH gains into other coins like Litecoin.
Litecoin has very good liquidity, and is very popular among traders especially in China.
So this guide is going to show you how to buy litecoins with Ethereum. We will show some of the best exchanges you can use, and the pros and cons of using different types of exchanges over the other.

Cryptmixer

Cryptmixer is one of the most unique exchanges, and also one of the fastest ways to convert your ETH to LTC.
With Cryptmixer you do not even need to store your money with the exchange, meaning you are at very little risk of getting your funds stolen.
With Cryptmixer you simply specify the amount of LTC you want to buy, and specific the address to where your litecoins should be sent and within 30 minutes you will have LTC delivered to your wallet.

Poloniex

Poloniex is the world’s largest altcoin exchange. However, there is a huge downside to using Poloniex to convert your ETH to LTC:
Poloniex does not have a LTC/ETH market, meaning you have to first trade your ETH to BTC, and then trade your BTC for LTC.
While this method works, you will have to make multiple trades and also pay fees twice.

ShapeShift

Shapeshift is basically the same as Cryptmixer, and was actually the first company to come up with the concept of an exchange that does not hold your own funds.

Frequently Asked Questions About Buying Litecoin

Many of you may still have lots of questions about how to buy Litecoin.
Odds are we have answered almost any question you could think of below.
We will aim to answer many of the most common questions relating to buying Litecoin.

Why are there limited options to buying Litecoin using other altcoins?

The issue in all crypto markets is liquidity. As the space gets bigger, the liquidity also gets better. But as of now, the only VERY liquid cryptocurrency is Bitcoin. So exchanging two altcoins between each other is often harder than if BTC was involved on one side of the trade.

How much is a Litecoin worth?

Like all currencies, the value of Litecoin changes every second. The value of Litecoin also depends on the country you are in and the exchange you are trading on. You can find the most up to date price on Coinbase.

How do I buy Ripple (XRP) with Litecoin?

The best way to buy Ripple using Litecoin is to either use a non KYC exchange like Cryptmixer or start an account on Binance or Coinbase Pro and sell your Litecoin for Ripple. Look for LTC/XRP trading pairs, and make your trade.

How long does Litecoin take to confirm?

Litecoin blocks are added ever 2 and a half minutes. That means you should get one confirmation every two and a half minutes. This can vary if it takes miners longer to discover a block, but the difficulty of the finding a block should change proportionate to the hashing power on the network so that a block gets added approximately every 2.5 minutes.
If you are trying to send money to a merchant, they may require more than one confirmation before they send you products. If you are depositing on an exchange, they may also require three or more confirmations before they credit your account.

How many Litoshis make one Litecoin?

one hundred million (100,000,000) Litoshis make one (1) Litecoin.

Where do I store Litecoin?

The best place to store litecoin is on a hardware wallet. You can find the best one for you on our page dedicated to hardware wallets.

When is the Litecoin halving?

The expected date of the next Litecoin block reward halving is August 7th, 2023.

Why can litecoin take so long to buy?

Litecoin can take long to buy because the legacy banking system is very slow. If you are buying with another cryptocurrency, you will see how fast it is to buy!
Bank transfer in the USA, for example, take about 5 days to complete. So any purchase of Litecoin made with a US bank transfer will take a minimum of 5 days.

How do I buy Litecoin with Paypal?

Unfortunately, there is no easy way to buy Litcoin with PayPal. Other sites will tell you that cex allows for this, but that is no longer the case.
You can, however, now use eToro to buy Litcoineum, unless you live in the United States.
If you live in the US, the only way to buy Litcoin with Paypal is to buy Bitcoin using paypal, and then use the Bitcoins to buy Litcoin. You can easily buy Bitcoin using Paypal on Local Bitcoins. Once you have Bitcoin, you can use an exchange like Cryptmixer to swap the Bitcoin for Litcoin.

Can you buy partial litecoins?

Yes, litecoin, like Bitcoin, is divisible to many decimal places so you can buy 0.1 LTC, 0.001 LTC, etc.

Can you sell litecoin?

Yes, you can sell LTC on most of the exchanges mentioned above. The fees, speed, and privacy is the same in most cases.

Can anyone buy litecoins?

Anyone is free to buy litecoins, as long as you find an exchange that supports your country. Most cryptocurrency wallets do not require ID to sign up so you can always make a wallet and get paid in litecoin, too.

Which payment method is best to use?

For speed, credit card will likely be fastest. For larger amounts, bank transfer is best. For privacy, it’s best to buy bitcoins with cash and then trade for litecoins using Cryptmixer or Shapeshift.

Is it better to mine or buy litecoins?

If you have cheap electricity, it might be worth it to mine litecoins. If you have solar power or just want to mine for fun then it could be worth it. Otherwise, it’s probably better just to buy.
Mining is constantly changing and small changes in Litecoin price or electricity can greatly affect your profitability.

What should I do with my litecoins once I buy?

You should immediately move your litecoins into a secure wallet. You should never leave your litecoins on an exchange. There have been countless hacks in cryptocurrency since Bitcoin was created in 2009. Hundreds of thousands of people have lost money. So buy your litecoins, and then instantly send them into a wallet you control so you are not at risk of losing money to a hack or scam.
submitted by MonishaNuij to MonMonCrypto [link] [comments]

"Say we got hacked"

submitted by mushhhhh to Bitcoin [link] [comments]

Round up of Cryptocurrency News #10 Week 28/09 - 4/10

Hello and sorry all its been about a month since serious post. So what has happened this week? 1. Kucoin exchange was hacked for over $150 Million in Bitcoin. Bitfinex and Tether freezes $33 Million of stolen funds. Over this past week we have seen many cryptocurrencies on the exchange be released from the freeze. However, users are still waiting on the main cryptos to be released as KuCoin is working on their security of their platform to make sure it does not happen again. The hacker itself tried to dump his tokens over Binance... Good try lol https://news.bitcoin.com/kucoin-hack-17m-laundered-via-decentralized-exchanges-blockchain-analysis-firm-claims-this-can-still-be-traced/ (HOLY MOLY) https://news.bitcoin.com/kucoin-ceo-says-exchange-hack-suspects-found-204-million-recovered/ 2. Bitcoin outperforms Gold, Nasdaq, 10 year treasury and S&P 500. not surprising at all for us but still very interesting, Bitcoin is up 48% since the start of the year. It appears more people are becoming interested in cryptocurrency as Bitcoin continues to be the best performing asset not just in the past 10 years but of all time. On a more personal note, I was at a small gathering today (within covid restrictions) and I was just saying how i was really interested in cryptocurrency. For the first time ever everyone around me was really interested in what it was and how it worked also talked to a lot of my stock market friends and almost all have pulled out or thinking of pulling out. related: https://dailyhodl.com/2020/10/01/report-details-unprecedented-levels-of-wall-street-interest-in-bitcoin-and-cryptocurrency/ https://dailyhodl.com/2020/10/02/former-goldman-institutional-trader-says-large-investors-now-buying-bitcoin-and-gold-at-same-pace-heres-why/ 3. CBDC news - US federal reserve is actively working on the a digital dollar. From a previous post we know that the European Union is working on a Digital Euro and China is working on their own digital dollar. For me this is a bit of a worrying issue and seems like an upgrade for their own outdated systems completely removing the idea of decentralisation. In addition to this, I find it interesting that in Australia all cryptocurrency tax laws were written in late 2017/2018 and continues to be adapted. In Russia their are harsh penalties for unreported cryptocurrency holdings. In my controversial view I think the technology of blockchain can actually be used to recreate and rewrite a much better future through its innate abilities. we can avoid things like this: https://news.bitcoin.com/jpmorgan-fraud-billion-dollar-settlement/ 4. Highlights on cryptojacking - if you dont know what this is it is when a script or code runs on a computer to mine cryptocurrency using your computer resources. You can block these using other programs or scripts and being safe over the internet. 5. World economic forum names XRP as crypto asset most relevant in central bank digital currency space. Many partnerships in the space plus flare coming later. https://dailyhodl.com/2020/09/30/ripple-matchmaking-effort-discovered-featuring-170-financial-institutions-is-xrp-front-and-cente i definitely have a love hate relationship with XRP. 6. https://dailyhodl.com/2020/09/28/defi-movement-shatters-11000000000-in-total-crypto-assets-locked/ https://news.bitcoin.com/uniswap-captures-2-billion-locked-dex-volume-outpaces-second-largest-centralized-exchange/ 7. https://www.ey.com/en_au/blockchain/blockchain-platforms 8. https://dailyhodl.com/2020/09/29/twitter-ceo-jack-dorsey-says-bitcoin-and-blockchain-will-fuel-financial-freedom-and-transform-future-of-content-delivery/ 9. https://news.bitcoin.com/easily-spend-your-bitcoin-via-prepaid-debit-card-or-a-paypal-account-with-bitcoin-of-americas-easy-to-use-trading-platform/ 10. https://news.bitcoin.com/bitcoin-com-exchange-to-list-aspire-and-aspire-gas-as-newest-digital-asset-creation-platform-comes-to-market/ 11. https://news.bitcoin.com/onecoin-victims-petition-establishment-european-crypto-fraud-compensation-fund/ 12. https://news.bitcoin.com/atari-announces-ieo-collaboration-and-listing-of-the-atari-token-with-bitcoin-com-exchange/ Atari also partners with Cryptocurrency project ULTRA. Don't sleep on NFT projects, they may be a niche but they help with organisation, collectability and simplifies processes. 13. https://news.bitcoin.com/aurus-disrupts-the-gold-industry-today-its-ecosystem-lists-at-a-value-of-75m/ 14. https://dailyhodl.com/2020/10/01/irs-deploying-two-firms-to-track-crypto-transactions-in-million-dollar-deal/ 15. https://dailyhodl.com/2020/10/01/number-of-crypto-users-shatters-100000000-worldwide-cambridge-study/ https://news.bitcoin.com/bitcoin-posts-a-66-day-consecutive-streak-above-the-10k-price-range/ 16. https://news.bitcoin.com/cryptocurrency-exchange-diginex-trading-nasdaq/ 17. https://news.bitcoin.com/smart-contract-protocol-rsk-attempts-to-bring-defi-to-the-bitcoin-network/ 18. Bitmex news: https://news.bitcoin.com/bitmex-criminal-charges-prison/ well this happened. https://news.bitcoin.com/open-interest-on-bitmex-drops-16-investors-withdraw-37000-btc-in-less-than-24-hours/ https://dailyhodl.com/2020/10/02/bitmex-fires-back-after-us-accuses-crypto-exchange-of-failing-to-prevent-money-fraud/ https://dailyhodl.com/2020/10/03/440000000-in-bitcoin-exits-bitmex-as-crypto-traders-respond-to-cftc-allegations/ 19. Contract to break monero privacy: https://news.bitcoin.com/chainalysis-and-integra-win-1-25-million-irs-contract-to-break-monero/ 20. https://news.bitcoin.com/stacking-satoshis-leveraging-defi-applications-to-earn-more-bitcoin/ 21. https://dailyhodl.com/2020/10/02/bitcoin-whale-issues-big-warning-to-traders-heres-why-he-believes-group-of-crypto-assets-are-at-risk-from-regulators/ 22. https://news.bitcoin.com/venezuelas-state-run-defi-crypto-exchange-goes-live-after-maduros-anti-blockade-speech/ 23. https://news.bitcoin.com/crypto-exchange-coinbase-hands-over-customer-data-to-uk-tax-authority/ 24. https://news.bitcoin.com/jeff-booth-bitcoin-price-of-tomorrow/
25. https://news.bitcoin.com/eth-volumes-top-125-billion-in-q3-high-risk-dapps-dominate-tron-network/ 
Here is a small cross post for price movement: https://dailyhodl.com/2020/09/30/bitcoin-btc-tezos-xtz-cardano-ada-etoro-crypto-roundup/
Seems like everyone is bullish on bitcoin and leading crypto projects to make big gains over the next year, sooner rather than later. Bitcoin also holds above $10.5K with over 1Million wallets. Bitcoin interest is gaining throughout the world as many parts are hit by economic crisis.
Ethereum 2.0 roadmap updated, plans to exponentially increase scalability! VERY BULLISH. https://dailyhodl.com/2020/10/03/vitalik-buterin-updates-ethereum-2-0-roadmap-details-plans-to-exponentially-increase-scalability/
submitted by IOTAbesomewhere to Gravychain [link] [comments]

Where's My Money? Deposits And Withdrawals At Blockfi, Celsius, Crypto.Com And Nexo Compared

Does your crypto show up in your account? And can you get it back? Looking through 100+ complaints about deposits and withdrawals, the insights are obvious but good to know...
- They require additional information like tags (XRP, XLM)
- Had major software changes (BCH, BNB, DAI / MCD, ADA)
So if you're going to move one of these coins, make sure to not forget the extra information or wait a few weeks after the change (to give these companies time to get caught up).
Raw data is below, organized by company and whether it seems the complaint was resolved. Some important notes to consider
  1. Posts about waiting a few hours for a transaction to complete were not counted. Many times (most of the time?) when it takes more than 20 minutes, nothing is broken. E.g. High gas fees on the ethereum network will mean slower processing times for stable coins and other ERC-20 tokens. Less popular tokens, like GUSD, might require people manually going into cold storage. Large (> $30,000 USD) transactions require additional verification. If it takes > 8 hours then yes something is not right. And you should email support and start posting. Otherwise sit tight.
  2. Comments from different people on the same post saying they have the same problem were not counted for "scores". Most of these comments don't add useful information and make it harder to collect the data.
  3. Posts about fiat belong to a different category because a very different set of skills and software features are needed to safely move around dollars, euros, etc. This post is about whether or not your coins are likely to get lost or be unreachable.
  4. I asked "Did this get fixed?" to a lot of people who posted about problems. Not only to see how things turned out. Also to generate a possible data point about the quality of the post. I.e. Trolls and other "special" people venting online can be identified by not bothering to follow up or respond to questions. I also hope this encourages people to not forget to follow up a few weeks later and share a final outcome - good or bad.
Company Resolved Total complaints
BlockFi 50% 2 resolved, 2 not resolved
CDC 58% 29 resolved, 21 not resolved
Celsius 61% 23 resolved, 15 not resolved
Nexo 67% 8 resolved, 4 not resolved
BlockFi (Resolved)
https://www.reddit.com/blockfi/comments/hbcxqq/withdrawal_pending/
https://www.reddit.com/blockfi/comments/dkpy38/tx_confirmed_but_no_deposit/
BlockFi (Not resolved)
https://www.reddit.com/blockfi/comments/gvnbz0/withdrawal_of_large_requires_id_and_facial_scan/
https://www.reddit.com/blockfi/comments/hwqin8/refused_withdrawal_due_to_kyc/

CDC (Resolved)
https://www.reddit.com/Crypto_com/comments/grjphd/is_the_wallet_app_buggy_for_anyone_else_crashes/
https://www.reddit.com/Crypto_com/comments/gkduf8/unable_to_add_a_wallet_to_withdraw_funds/
https://www.reddit.com/Crypto_com/comments/cpaj2y/issues_with_crypto_invest_portfolio_and/
https://www.reddit.com/Crypto_com/comments/ceu0vd/1130pm_hkt_update_withdrawals_and_deposits_are/
https://www.reddit.com/Crypto_com/comments/gi62j3/missing_cro_sending_to_the_exchange/
https://www.reddit.com/Crypto_com/comments/d6qjtb/thank_you/
https://www.reddit.com/Crypto_com/comments/gjx3xp/where_are_my_coins/
https://www.reddit.com/Crypto_com/comments/ffiz9x/transfer_bch/
https://www.reddit.com/Crypto_com/comments/f7se85/usdt_delisted_on_cryptocom/
https://www.reddit.com/Crypto_com/comments/dw8vmn/my_funds_are_being_held_hostage_by_cryptocom_yes/
https://www.reddit.com/Crypto_com/comments/clg9r2/cryptocom_is_just_a_regular_bank_be_awared/
https://www.reddit.com/Crypto_com/comments/hqa0pm/btc_withdrawal_delay_5_hrs/
https://www.reddit.com/Crypto_com/comments/hmjq69/withdrawals_and_deposits_back_online/
https://www.reddit.com/Crypto_com/comments/hlro5y/ada_withdraw_erro
https://www.reddit.com/Crypto_com/comments/hlud4t/issues_since_app_update/
https://www.reddit.com/Crypto_com/comments/hlukqc/how_long_does_it_usually_take/
https://www.reddit.com/Crypto_com/comments/hm66xm/withdrawal_impossible/
https://www.reddit.com/Crypto_com/comments/hm81fj/no_bitcoin_withdrawals_since_saturday/
https://www.reddit.com/Crypto_com/comments/hm8irg/issue_with_withdrawing_eth/
https://www.reddit.com/Crypto_com/comments/hm8kn2/communication_near_to_0/
https://www.reddit.com/Crypto_com/comments/hmbo5a/cant_withdraw_any_bitcoin/
https://www.reddit.com/Crypto_com/comments/hikkx6/withdrawal_pending/
https://www.reddit.com/Crypto_com/comments/h91u4i/issues_on_cryptocom_app/
https://www.reddit.com/Crypto_com/comments/hb5fpusdt_withdrawal_from_exchange_doesnt_work_claims/
https://www.reddit.com/Crypto_com/comments/hdjrmz/keep_getting_a_withdrawal_erro
https://www.reddit.com/Crypto_com/comments/hebtyf/withdrawal_pending_taking_over_16_hours/
https://www.reddit.com/Crypto_com/comments/hgt61j/one_exchange_withdrawal_two_app_deposits/
https://www.reddit.com/Crypto_com/comments/htf578/withdrawal_dia_is_taking_8_hrs/
https://www.reddit.com/Crypto_com/comments/he151z/btc_withdrawal_delay/
CDC (Not resolved)
https://www.reddit.com/Crypto_com/comments/gx2oyo/pending_withdrawal/
https://www.reddit.com/Crypto_com/comments/gk8wlc/wont_let_me_buy_or_withdraw/
https://www.reddit.com/Crypto_com/comments/gh6v2c/usdc_withdrawing_to_external_address/
https://www.reddit.com/Crypto_com/comments/ggk51x/cryptocom_withdrawal/
https://www.reddit.com/Crypto_com/comments/g925xg/withdraw_blocked/
https://www.reddit.com/Crypto_com/comments/cfjess/withdraw_is_in_progress_from_23h/
https://www.reddit.com/Crypto_com/comments/gk8wlc/wont_let_me_buy_or_withdraw/
https://www.reddit.com/Crypto_com/comments/9xbi1c/withdrawals_delayed/
https://www.reddit.com/Crypto_com/comments/cga2eq/delayed_transfe
https://www.reddit.com/Crypto_com/comments/hd1to7/missing_funds_from_the_exchange_after_the/
https://www.reddit.com/Crypto_com/comments/grr4vh/crypto_wallet_scammed_me_beware/
https://www.reddit.com/Crypto_com/comments/cg5zfj/helpbnb_wallet_address_in_app_is_still_old_eth/
https://www.reddit.com/Crypto_com/comments/hrwpsq/btc_withdrawl_pending_for_24_hours_zero_custome
https://www.reddit.com/Crypto_com/comments/hpteje/how_to_withdraw_cro_from_the_exchange/
https://www.reddit.com/Crypto_com/comments/hottg4/cryptocom_app_is_not_working/
https://www.reddit.com/Crypto_com/comments/ha8o7v/problem_with_the_2fa_need_help_pls/
https://www.reddit.com/Crypto_com/comments/he3qco/btc_withdraw_pending_post_7_hours/
https://www.reddit.com/Crypto_com/comments/he45kj/withdrawal_stuck/
https://www.reddit.com/Crypto_com/comments/heb85q/btc_withdraw_pending_72_hours_now/
https://www.reddit.com/Crypto_com/comments/hhqruv/withdrawal_from_cryptocom_wallet_to_cryptocom_app/
https://www.reddit.com/Crypto_com/comments/hihl04/i_cant_withdraw_whats_happening/

Celsius (Resolved)
https://www.reddit.com/CelsiusNetwork/comments/gantb4/withdraw_delay/fp11iut/?context=3
https://www.reddit.com/CelsiusNetwork/comments/gb7c4t/withdrawal_still_pending_only_for_btc/fp4wmc3/?context=3
https://www.reddit.com/CelsiusNetwork/comments/gncvj9/my_withdraw_experience_with_celsius_network/
https://www.reddit.com/CelsiusNetwork/comments/fk844a/over_20k_withdrawals_processing_time/
https://www.reddit.com/CelsiusNetwork/comments/fhftgh/where_do_i_find_pending_or_past_withdrawals/
https://www.reddit.com/CelsiusNetwork/comments/epl29a/cant_withdraw_my_deposited_sai_as_a_texas_resident/
https://www.reddit.com/CelsiusNetwork/comments/dn0vg2/problem_withdrawing_eth_from_celsius_account/
https://www.reddit.com/CelsiusNetwork/comments/cw00t5/not_receiving_withdrawal_confirmation_email/
https://www.reddit.com/CelsiusNetwork/comments/ci3h6w/eth_withdrawal_appears_as_an_internal_transaction/
https://www.reddit.com/CelsiusNetwork/comments/c2w5gk/unable_to_withdraw_anything_from_the_app/
https://www.reddit.com/CelsiusNetwork/comments/br2v75/how_do_i_withdraw_the_interest/
https://www.reddit.com/CelsiusNetwork/comments/bqynbv/unable_to_withdraw_full_account_balance/
https://www.reddit.com/CelsiusNetwork/comments/a9d2vj/withdrawals_of_any_currency_are_not_currently/
https://www.reddit.com/CelsiusNetwork/comments/gfby9l/celsius_fixed_my_deposit_issue/fpw51u3/?context=3
https://www.reddit.com/CelsiusNetwork/comments/g9oiea/deposit_missing/
https://www.reddit.com/CelsiusNetwork/comments/dkb55t/deposit_not_showing_up/
https://www.reddit.com/CelsiusNetwork/comments/eudo3n/not_receiving_deposited_bitcoin/
https://www.reddit.com/CelsiusNetwork/comments/gepzpp/all_good_all_fix/
https://www.reddit.com/CelsiusNetwork/comments/hf334d/withdrawal_issue_trueusd_tusd_stable_coin/
https://www.reddit.com/CelsiusNetwork/comments/hiriqz/celsius_is_witholding_my_crypto/
https://www.reddit.com/CelsiusNetwork/comments/hjv0io/dai_withdrawal_pending_for_24hrs_subsequently/
https://www.reddit.com/CelsiusNetwork/comments/hme5xm/its_been_more_than_3_days_of_withdrawing_my_usdc/
https://www.reddit.com/CelsiusNetwork/comments/hvi45o/eth_and_cel_good_on_etherscan_not_show_in_app/
Celsius (Not resolved)
https://www.reddit.com/CelsiusNetwork/comments/fbpnw4/why_this_app_shutdown_when_we_try_to_change/
https://www.reddit.com/CelsiusNetwork/comments/f7i2f3/withdrawal_issues/
https://www.reddit.com/CelsiusNetwork/comments/f4ptd7/cant_get_my_crypto_not_getting_withdrawal_emails/
https://www.reddit.com/CelsiusNetwork/comments/ea3hi5/eth_withdrawal_made_from_a_smart_contract/
https://www.reddit.com/CelsiusNetwork/comments/cb08he/can_you_withdraw_to_a_bech32_btc_address/
https://www.reddit.com/CelsiusNetwork/comments/c8yovc/minimum_withdraws/
https://www.reddit.com/CelsiusNetwork/comments/bqqiqg/i_cant_withdraw_my_eth/
https://www.reddit.com/CelsiusNetwork/comments/askghy/what_is_the_withdrawal_fees_service_told_me_there/
https://www.reddit.com/CelsiusNetwork/comments/gtjoc9/btc_withdraw_transaction_still_pensing_after_1_day/
https://www.reddit.com/CelsiusNetwork/comments/g9f7ym/stolen_or_lost_deposits_hold_off_on_transferring/
https://www.reddit.com/CelsiusNetwork/comments/gf8v3i/mcdai_deposit_pending_for_days/
https://www.reddit.com/CelsiusNetwork/comments/d1sc3q/eth_deposit_address_is_a_contract_address/
https://www.reddit.com/CelsiusNetwork/comments/ca2wpd/warning_celsius_does_lock_up_your_funds/
https://www.reddit.com/CelsiusNetwork/comments/hnu53f/is_anyone_else_having_trouble_withdrawing_xrp/
https://www.reddit.com/CelsiusNetwork/comments/hv2czp/celsius_received_thousands_of_dollars_of_my_funds/

Nexo (Resolved)
https://www.reddit.com/Nexo/comments/gixzgu/cant_deposit_or_withdraw_stablecoins_right_now/
https://www.reddit.com/Nexo/comments/flshbb/my_withdraw_was_rejected/
https://www.reddit.com/Nexo/comments/fiit3u/nexo_withdrawal/
https://www.reddit.com/Nexo/comments/e2ij06/withdrawal_problems/
https://www.reddit.com/Nexo/comments/fhgmxg/missing_deposit/
https://www.reddit.com/Nexo/comments/f3z9kq/account_showing_no_balance/
https://www.reddit.com/Nexo/comments/gj3ub0/bnb_withdrawals/
https://www.reddit.com/Nexo/comments/hlxpnd/i_made_an_eth_deposit_36_hours_ago_the_txid_shows/
Nexo (Not resolved)
https://www.reddit.com/Nexo/comments/dpvrgj/nexo_withdrawal_pending_1_day/
https://www.reddit.com/Nexo/comments/dno3up/withdrawal_email_confirmation/
https://www.reddit.com/Nexo/comments/dm6nn9/withdraw_from_binance_dex/
https://www.reddit.com/Nexo/comments/c67gis/anyone_else_having_problems_with_loan_withdrawals/
submitted by thegoldlust to Crypto_com [link] [comments]

Where's My Money? Deposits And Withdrawals At Blockfi, Celsius, Crypto.Com And Nexo Compared

Does your crypto show up in your account? And can you get it back? Looking through 100+ complaints about deposits and withdrawals, the insights are obvious but good to know...
- They require additional information like tags (XRP, XLM)
- Had major software changes (BCH, BNB, DAI / MCD, ADA)
So if you're going to move one of these coins, make sure to not forget the extra information or wait a few weeks after the change (to give these companies time to get caught up).
Raw data is below, organized by company and whether it seems the complaint was resolved. Some important notes to consider
  1. Posts about waiting a few hours for a transaction to complete were not counted. Many times (most of the time?) when it takes more than 20 minutes, nothing is broken. E.g. High gas fees on the ethereum network will mean slower processing times for stable coins and other ERC-20 tokens. Less popular tokens, like GUSD, might require people manually going into cold storage. Large (> $30,000 USD) transactions require additional verification. If it takes > 8 hours then yes something is not right. And you should email support and start posting. Otherwise sit tight.
  2. Comments from different people on the same post saying they have the same problem were not counted for "scores". Most of these comments don't add useful information and make it harder to collect the data.
  3. Posts about fiat belong to a different category because a very different set of skills and software features are needed to safely move around dollars, euros, etc. This post is about whether or not your coins are likely to get lost or be unreachable.
  4. I asked "Did this get fixed?" to a lot of people who posted about problems. Not only to see how things turned out. Also to generate a possible data point about the quality of the post. I.e. Trolls and other "special" people venting online can be identified by not bothering to follow up or respond to questions. I also hope this encourages people to not forget to follow up a few weeks later and share a final outcome - good or bad.
Company Resolved Total complaints
BlockFi 50% 2 resolved, 2 not resolved
CDC 58% 29 resolved, 21 not resolved
Celsius 61% 23 resolved, 15 not resolved
Nexo 67% 8 resolved, 4 not resolved
BlockFi (Resolved)
https://www.reddit.com/blockfi/comments/hbcxqq/withdrawal_pending/
https://www.reddit.com/blockfi/comments/dkpy38/tx_confirmed_but_no_deposit/
BlockFi (Not resolved)
https://www.reddit.com/blockfi/comments/gvnbz0/withdrawal_of_large_requires_id_and_facial_scan/
https://www.reddit.com/blockfi/comments/hwqin8/refused_withdrawal_due_to_kyc/

CDC (Resolved)
https://www.reddit.com/Crypto_com/comments/grjphd/is_the_wallet_app_buggy_for_anyone_else_crashes/
https://www.reddit.com/Crypto_com/comments/gkduf8/unable_to_add_a_wallet_to_withdraw_funds/
https://www.reddit.com/Crypto_com/comments/cpaj2y/issues_with_crypto_invest_portfolio_and/
https://www.reddit.com/Crypto_com/comments/ceu0vd/1130pm_hkt_update_withdrawals_and_deposits_are/
https://www.reddit.com/Crypto_com/comments/gi62j3/missing_cro_sending_to_the_exchange/
https://www.reddit.com/Crypto_com/comments/d6qjtb/thank_you/
https://www.reddit.com/Crypto_com/comments/gjx3xp/where_are_my_coins/
https://www.reddit.com/Crypto_com/comments/ffiz9x/transfer_bch/
https://www.reddit.com/Crypto_com/comments/f7se85/usdt_delisted_on_cryptocom/
https://www.reddit.com/Crypto_com/comments/dw8vmn/my_funds_are_being_held_hostage_by_cryptocom_yes/
https://www.reddit.com/Crypto_com/comments/clg9r2/cryptocom_is_just_a_regular_bank_be_awared/
https://www.reddit.com/Crypto_com/comments/hqa0pm/btc_withdrawal_delay_5_hrs/
https://www.reddit.com/Crypto_com/comments/hmjq69/withdrawals_and_deposits_back_online/
https://www.reddit.com/Crypto_com/comments/hlro5y/ada_withdraw_erro
https://www.reddit.com/Crypto_com/comments/hlud4t/issues_since_app_update/
https://www.reddit.com/Crypto_com/comments/hlukqc/how_long_does_it_usually_take/
https://www.reddit.com/Crypto_com/comments/hm66xm/withdrawal_impossible/
https://www.reddit.com/Crypto_com/comments/hm81fj/no_bitcoin_withdrawals_since_saturday/
https://www.reddit.com/Crypto_com/comments/hm8irg/issue_with_withdrawing_eth/
https://www.reddit.com/Crypto_com/comments/hm8kn2/communication_near_to_0/
https://www.reddit.com/Crypto_com/comments/hmbo5a/cant_withdraw_any_bitcoin/
https://www.reddit.com/Crypto_com/comments/hikkx6/withdrawal_pending/
https://www.reddit.com/Crypto_com/comments/h91u4i/issues_on_cryptocom_app/
https://www.reddit.com/Crypto_com/comments/hb5fpusdt_withdrawal_from_exchange_doesnt_work_claims/
https://www.reddit.com/Crypto_com/comments/hdjrmz/keep_getting_a_withdrawal_erro
https://www.reddit.com/Crypto_com/comments/hebtyf/withdrawal_pending_taking_over_16_hours/
https://www.reddit.com/Crypto_com/comments/hgt61j/one_exchange_withdrawal_two_app_deposits/
https://www.reddit.com/Crypto_com/comments/htf578/withdrawal_dia_is_taking_8_hrs/
https://www.reddit.com/Crypto_com/comments/he151z/btc_withdrawal_delay/
CDC (Not resolved)
https://www.reddit.com/Crypto_com/comments/gx2oyo/pending_withdrawal/
https://www.reddit.com/Crypto_com/comments/gk8wlc/wont_let_me_buy_or_withdraw/
https://www.reddit.com/Crypto_com/comments/gh6v2c/usdc_withdrawing_to_external_address/
https://www.reddit.com/Crypto_com/comments/ggk51x/cryptocom_withdrawal/
https://www.reddit.com/Crypto_com/comments/g925xg/withdraw_blocked/
https://www.reddit.com/Crypto_com/comments/cfjess/withdraw_is_in_progress_from_23h/
https://www.reddit.com/Crypto_com/comments/gk8wlc/wont_let_me_buy_or_withdraw/
https://www.reddit.com/Crypto_com/comments/9xbi1c/withdrawals_delayed/
https://www.reddit.com/Crypto_com/comments/cga2eq/delayed_transfe
https://www.reddit.com/Crypto_com/comments/hd1to7/missing_funds_from_the_exchange_after_the/
https://www.reddit.com/Crypto_com/comments/grr4vh/crypto_wallet_scammed_me_beware/
https://www.reddit.com/Crypto_com/comments/cg5zfj/helpbnb_wallet_address_in_app_is_still_old_eth/
https://www.reddit.com/Crypto_com/comments/hrwpsq/btc_withdrawl_pending_for_24_hours_zero_custome
https://www.reddit.com/Crypto_com/comments/hpteje/how_to_withdraw_cro_from_the_exchange/
https://www.reddit.com/Crypto_com/comments/hottg4/cryptocom_app_is_not_working/
https://www.reddit.com/Crypto_com/comments/ha8o7v/problem_with_the_2fa_need_help_pls/
https://www.reddit.com/Crypto_com/comments/he3qco/btc_withdraw_pending_post_7_hours/
https://www.reddit.com/Crypto_com/comments/he45kj/withdrawal_stuck/
https://www.reddit.com/Crypto_com/comments/heb85q/btc_withdraw_pending_72_hours_now/
https://www.reddit.com/Crypto_com/comments/hhqruv/withdrawal_from_cryptocom_wallet_to_cryptocom_app/
https://www.reddit.com/Crypto_com/comments/hihl04/i_cant_withdraw_whats_happening/

Celsius (Resolved)
https://www.reddit.com/CelsiusNetwork/comments/gantb4/withdraw_delay/fp11iut/?context=3
https://www.reddit.com/CelsiusNetwork/comments/gb7c4t/withdrawal_still_pending_only_for_btc/fp4wmc3/?context=3
https://www.reddit.com/CelsiusNetwork/comments/gncvj9/my_withdraw_experience_with_celsius_network/
https://www.reddit.com/CelsiusNetwork/comments/fk844a/over_20k_withdrawals_processing_time/
https://www.reddit.com/CelsiusNetwork/comments/fhftgh/where_do_i_find_pending_or_past_withdrawals/
https://www.reddit.com/CelsiusNetwork/comments/epl29a/cant_withdraw_my_deposited_sai_as_a_texas_resident/
https://www.reddit.com/CelsiusNetwork/comments/dn0vg2/problem_withdrawing_eth_from_celsius_account/
https://www.reddit.com/CelsiusNetwork/comments/cw00t5/not_receiving_withdrawal_confirmation_email/
https://www.reddit.com/CelsiusNetwork/comments/ci3h6w/eth_withdrawal_appears_as_an_internal_transaction/
https://www.reddit.com/CelsiusNetwork/comments/c2w5gk/unable_to_withdraw_anything_from_the_app/
https://www.reddit.com/CelsiusNetwork/comments/br2v75/how_do_i_withdraw_the_interest/
https://www.reddit.com/CelsiusNetwork/comments/bqynbv/unable_to_withdraw_full_account_balance/
https://www.reddit.com/CelsiusNetwork/comments/a9d2vj/withdrawals_of_any_currency_are_not_currently/
https://www.reddit.com/CelsiusNetwork/comments/gfby9l/celsius_fixed_my_deposit_issue/fpw51u3/?context=3
https://www.reddit.com/CelsiusNetwork/comments/g9oiea/deposit_missing/
https://www.reddit.com/CelsiusNetwork/comments/dkb55t/deposit_not_showing_up/
https://www.reddit.com/CelsiusNetwork/comments/eudo3n/not_receiving_deposited_bitcoin/
https://www.reddit.com/CelsiusNetwork/comments/gepzpp/all_good_all_fix/
https://www.reddit.com/CelsiusNetwork/comments/hf334d/withdrawal_issue_trueusd_tusd_stable_coin/
https://www.reddit.com/CelsiusNetwork/comments/hiriqz/celsius_is_witholding_my_crypto/
https://www.reddit.com/CelsiusNetwork/comments/hjv0io/dai_withdrawal_pending_for_24hrs_subsequently/
https://www.reddit.com/CelsiusNetwork/comments/hme5xm/its_been_more_than_3_days_of_withdrawing_my_usdc/
https://www.reddit.com/CelsiusNetwork/comments/hvi45o/eth_and_cel_good_on_etherscan_not_show_in_app/
Celsius (Not resolved)
https://www.reddit.com/CelsiusNetwork/comments/fbpnw4/why_this_app_shutdown_when_we_try_to_change/
https://www.reddit.com/CelsiusNetwork/comments/f7i2f3/withdrawal_issues/
https://www.reddit.com/CelsiusNetwork/comments/f4ptd7/cant_get_my_crypto_not_getting_withdrawal_emails/
https://www.reddit.com/CelsiusNetwork/comments/ea3hi5/eth_withdrawal_made_from_a_smart_contract/
https://www.reddit.com/CelsiusNetwork/comments/cb08he/can_you_withdraw_to_a_bech32_btc_address/
https://www.reddit.com/CelsiusNetwork/comments/c8yovc/minimum_withdraws/
https://www.reddit.com/CelsiusNetwork/comments/bqqiqg/i_cant_withdraw_my_eth/
https://www.reddit.com/CelsiusNetwork/comments/askghy/what_is_the_withdrawal_fees_service_told_me_there/
https://www.reddit.com/CelsiusNetwork/comments/gtjoc9/btc_withdraw_transaction_still_pensing_after_1_day/
https://www.reddit.com/CelsiusNetwork/comments/g9f7ym/stolen_or_lost_deposits_hold_off_on_transferring/
https://www.reddit.com/CelsiusNetwork/comments/gf8v3i/mcdai_deposit_pending_for_days/
https://www.reddit.com/CelsiusNetwork/comments/d1sc3q/eth_deposit_address_is_a_contract_address/
https://www.reddit.com/CelsiusNetwork/comments/ca2wpd/warning_celsius_does_lock_up_your_funds/
https://www.reddit.com/CelsiusNetwork/comments/hnu53f/is_anyone_else_having_trouble_withdrawing_xrp/
https://www.reddit.com/CelsiusNetwork/comments/hv2czp/celsius_received_thousands_of_dollars_of_my_funds/

Nexo (Resolved)
https://www.reddit.com/Nexo/comments/gixzgu/cant_deposit_or_withdraw_stablecoins_right_now/
https://www.reddit.com/Nexo/comments/flshbb/my_withdraw_was_rejected/
https://www.reddit.com/Nexo/comments/fiit3u/nexo_withdrawal/
https://www.reddit.com/Nexo/comments/e2ij06/withdrawal_problems/
https://www.reddit.com/Nexo/comments/fhgmxg/missing_deposit/
https://www.reddit.com/Nexo/comments/f3z9kq/account_showing_no_balance/
https://www.reddit.com/Nexo/comments/gj3ub0/bnb_withdrawals/
https://www.reddit.com/Nexo/comments/hlxpnd/i_made_an_eth_deposit_36_hours_ago_the_txid_shows/
Nexo (Not resolved)
https://www.reddit.com/Nexo/comments/dpvrgj/nexo_withdrawal_pending_1_day/
https://www.reddit.com/Nexo/comments/dno3up/withdrawal_email_confirmation/
https://www.reddit.com/Nexo/comments/dm6nn9/withdraw_from_binance_dex/
https://www.reddit.com/Nexo/comments/c67gis/anyone_else_having_problems_with_loan_withdrawals/
submitted by thegoldlust to CelsiusNetwork [link] [comments]

The events of a SIM swap attack (and defense tips)

Posted this on Coinbase and someone recommend it also be posted here. The information below on an attempted SIM swap attack was pieced together through a combination of login and security logs, recovering emails initiated by the attacker that were deleted and then deleted again from the trash folder, and learning from AT&T’s fraud representatives. The majority if this is factual, and we do our best to note where we are speculating or providing a circumstantial suspicion. TLDRs at the bottom.
The full story:
We were going about our business and received a text from AT&T that says “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” We did not request this, and were suspicious that the text itself could be a phishing scam since we searched the phone number and it wasn’t overtly associated with AT&T. Thus, we tried calling AT&T’s main line at 611 but all we hear is beep beep beep. The phone number is already gone. We use another phone to call AT&T and at the same time start working on our already compromised email.
While we didn’t see everything real time, this is what the recovered emails show. In less than 2 minutes after receiving the text from AT&T, there is already an email indicating that the stolen phone number was used to sign into our email account associated with Coinbase. 2 minutes after that, there is an email from Coinbase saying:
"We have received your request for password reset from an unverified device. As a security precaution, an e-mail with a reset link will be sent to you in 24 hours. Alternatively, if you would like your password reset to be processed immediately, please submit a request using a verified device.
This 24 hour review period is designed to protect your Coinbase account."
This is where Coinbase got it right to have a 24 hour review period (actually a recovery period) before allowing the password to be reset. However, the attackers knew this and planned to steal the second email from Coinbase by setting email rules to forward all emails to a burner address and also have any emails containing “coinbase” re-routed so they don’t appear in the Inbox. 5 minutes later, they request a password reset from Gemini and the password was reset to the attacker’s password within a minute after that. The next minute they target and reset DropBox’s password followed immediately with Binance. Less than 2 minutes later, an email from Binance indicates that the password has been reset and another email arrives a minute later indicating a new device has been authorized.
It’s at this point that we begin locking the attacker out by (1) removing the phone number as 2FA (2) changing the email password, (3) and three forcing a logout of all sessions from the email. There was a bit of back and forth where they still had an active login and re-added the stolen phone number as 2FA.
They added only one more password reset to a gaming account that was not deleted. I can only suspect that was a decoy to make it look like the attack was directed at gaming rather than finances.
The Gemini and Binance accounts were empty and effectively abandoned, with no balances and inactive bank accounts (if any), and no transactions in 1-3 years. DropBox had no meaningful files (they probably look for private keys and authenticator backups) and the phone number they stole from us was suspended, so as far as the attacker is concerned, there is no meat on this bone to attack again… unless they had inside information.
This is where I suspect someone internal at Coinbase receiving wire deposits has been compromised in tipping off ripe accounts – accounts with new and somewhat large balances. We had completed a full withdrawal of funds from Coinbase earlier in the year, and had a balance of less than $20 heading into May. Deposits to Coinbase staggered in to get above six figures through mid-May then stopped. The attack occurred 7 days after the last large wire deposit was made to Coinbase.
From the perspective of an attacker that had no inside information, we were a dead end with abandoned Gemini and Binance accounts with zero balances and stale transactions, no DropBox information, and the suspended phone number access. Our Coinbase deposits were known to no one except us, Coinbase, and our bank. We were also able to stop the hacker’s email forwarding before Coinbase’s 24 hour period to send the password reset, so this one didn’t work out for the attackers and it would make sense for them to move on to the next rather than put efforts into a second attack only for Coinbase - for what would appear to be a zero-balance Coinbase account based on the other stale accounts.
Then…23 hours and 42 minutes after the first attack, another message from AT&T “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” Here we go again. We had been confident in AT&T’s assurances that our account had been locked and would not be SIM swapped again, so we unwisely added the phone number back to our email account as a backup (it’s now removed permanently and we use burner emails for account recovery like we should have all along).
Upon seeing that our phone number had been stolen again I knew they were after the Coinbase reset email that was delayed by 24 hours from Coinbase as part of their security. We did 4 things within 2 minutes of that text: (1) removed the phone number again from the email account – this time for good, (2) market sell all Bitcoin on Coinbase, (3) withdraw from Coinbase, (4) have AT&T suspend service on the phone line.
In speaking with AT&T, they were floored that our SIM would be transferred again in light of all the notes about fraud on the account and the PIN being changed to random digits that had never been used by us before. Based on the response of disbelief from AT&T on the second port, I suspect that this attack also involved a compromised AT&T employee that worked with the attacker to provide timely access to the Coinbase password reset email. Apparently, this has been going on for years: https://www.flashpoint-intel.com/blog/sim-swap-fraud-account-takeove
with phone carrier employees swapping SIMs for $80s a swap.
Remember that most of this was hidden in real time, and was only known because we were able to recover emails deleted from Trash by the attacker.
Since we require any withdrawals to use Google Authenticator on Coinbase, our funds may have been secure nonetheless. However, under the circumstances with attackers that were apparently working with insiders to take our phone number twice in attempts to steal Bitcoin, and it being unknown if they had additional tools related to our Google Authenticator, we decided it was safer on the sidelines. The coins were held on the exchange for a quick exit depending on whether Bitcoin was going to break up or down from $10,000. A hardware wallet is always safest, but we were looking to time the market and not have transaction delays.
For some some security recommendations:
AT&T: If you are going to send a text saying that calls and texts are moving to a new number, provide a 10 minute window for the phone number to reply with a “NO” or “STOP” to prevent the move. This can escalate the SIM dispute to more trusted employees to determine who actually owns the line. Don’t let entry level employees swap SIMs.
Coinbase: Do not default to phone numbers as 2FA. Also, if someone logs in successfully with the password before the 24 hours are up, the password is known and there is no need to send the password reset email again for attacker to have forwarded to them. At least have an option to stop the password reset email from being sent. We did not tag our account at Coinbase with fraud because of the stories of frozen funds once an account is tagged. I’m not sure what the solution is there, but that is another problem.
Being a trader, it would be nice to think of Coinbase as any other type of security brokerage where your assets are yours (someone can’t steal your phone number and transfer your stocks to their account). We fell into that mindset of security, yet this experience has reminded us of the uniqueness of cryptocurrency and the lack of custodial assurance and insurance from exchanges because of the possession-is-everything properties of cryptocurrency.
As many have said before, 2FA with a phone number quickly becomes 1-factor authentication as soon as that phone number is associated with password recovery on your email or other accounts. Our overall recommendation is to avoid having a phone number associated with any recovery options across all your accounts.
TLDR on the process:
Scammers will steal your phone number (in our case twice in 24 hours) and use your phone number to access your email and accounts. They will use your email to reset passwords at financial accounts and file hosting such as DropBox. They will then use that combination to transfer any assets they can access from your accounts to theirs. They will do their best to hide this from you by
(1) not resetting your email password so as to raise suspicion,
(2) immediately delete any password reset emails you may receive from financial accounts to hide them from you,
(3) attempt to forward all emails sent to your address to a burner email, and
(4) set email rules to forward emails containing “coinbase” to an email folder other than your Inbox so that you don’t see the transactions and password reset emails that arrive to your inbox.
TLDR on defense tips: If your phone stops working or you receive a text of your number being ported do the following as soon as possible:
(1) log into your email account(s) associated with your financial accounts and remove your phone number as 2FA immediately
(2) change your email password,
(3) force a logout of all sessions from your email (at this point you have locked them out), then
(4) check your mail forwarding settings for forwards to burner addresses,
(5) check your mail rules for rerouting of emails from accounts such as Coinbase, and
(6) call your carrier to have them suspend service on your lost phone number and ask them to reinstate your SIM or get a new SIM. This will require a second phone because your personal phone number has been stolen.
We hope this helps some others be safe out there in protecting their coins. The more we know, the more we can protect ourselves. Wishing you all the best!
submitted by etheregg to CryptoCurrency [link] [comments]

The events of a SIM swap attack directed at Coinbase (and defense tips)

The information below on an attempted SIM swap attack was pieced together through a combination of login and security logs, recovering emails initiated by the attacker that were deleted and then deleted again from the trash folder, and learning from AT&T’s fraud representatives. The majority if this is factual, and we do our best to note where we are speculating or providing a circumstantial suspicion. TLDRs at the bottom.
The full story:
We were going about our business and received a text from AT&T that says “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” We did not request this, and were suspicious that the text itself could be a phishing scam since we searched the phone number and it wasn’t overtly associated with AT&T. Thus, we tried calling AT&T’s main line at 611 but all we hear is beep beep beep. The phone number is already gone. We use another phone to call AT&T and at the same time start working on our already compromised email.
While we didn’t see everything real time, this is what the recovered emails show. In less than 2 minutes after receiving the text from AT&T, there is already an email indicating that the stolen phone number was used to sign into our email account associated with Coinbase. 2 minutes after that, there is an email from Coinbase saying:
"We have received your request for password reset from an unverified device. As a security precaution, an e-mail with a reset link will be sent to you in 24 hours. Alternatively, if you would like your password reset to be processed immediately, please submit a request using a verified device.
This 24 hour review period is designed to protect your Coinbase account."
This is where Coinbase got it right to have a 24 hour review period (actually a recovery period) before allowing the password to be reset. However, the attackers knew this and planned to steal the second email from Coinbase by setting email rules to forward all emails to a burner address and also have any emails containing “coinbase” re-routed so they don’t appear in the Inbox. 5 minutes later, they request a password reset from Gemini and the password was reset to the attacker’s password within a minute after that. The next minute they target and reset DropBox’s password followed immediately with Binance. Less than 2 minutes later, an email from Binance indicates that the password has been reset and another email arrives a minute later indicating a new device has been authorized.
It’s at this point that we begin locking the attacker out by (1) removing the phone number as 2FA (2) changing the email password, (3) and three forcing a logout of all sessions from the email. There was a bit of back and forth where they still had an active login and re-added the stolen phone number as 2FA.
They added only one more password reset to a gaming account that was not deleted. I can only suspect that was a decoy to make it look like the attack was directed at gaming rather than finances.
The Gemini and Binance accounts were empty and effectively abandoned, with no balances and inactive bank accounts (if any), and no transactions in 1-3 years. DropBox had no meaningful files (they probably look for private keys and authenticator backups) and the phone number they stole from us was suspended, so as far as the attacker is concerned, there is no meat on this bone to attack again… unless they had inside information.
This is where I suspect someone internal at Coinbase receiving wire deposits has been compromised in tipping off ripe accounts – accounts with new and somewhat large balances. We had completed a full withdrawal of funds from Coinbase earlier in the year, and had a balance of less than $20 heading into May. Deposits to Coinbase staggered in to get above six figures through mid-May then stopped. The attack occurred 7 days after the last large wire deposit was made to Coinbase.
From the perspective of an attacker that had no inside information, we were a dead end with abandoned Gemini and Binance accounts with zero balances and stale transactions, no DropBox information, and the suspended phone number access. Our Coinbase deposits were known to no one except us, Coinbase, and our bank. We were also able to stop the hacker’s email forwarding before Coinbase’s 24 hour period to send the password reset, so this one didn’t work out for the attackers and it would make sense for them to move on to the next rather than put efforts into a second attack only for Coinbase - for what would appear to be a zero-balance Coinbase account based on the other stale accounts.
Then…23 hours and 42 minutes after the first attack, another message from AT&T “…Calls & texts will go to your new phone/SIM card. Call 866-563-4705 if you did not request.” Here we go again. We had been confident in AT&T’s assurances that our account had been locked and would not be SIM swapped again, so we unwisely added the phone number back to our email account as a backup (it’s now removed permanently and we use burner emails for account recovery like we should have all along).
Upon seeing that our phone number had been stolen again I knew they were after the Coinbase reset email that was delayed by 24 hours from Coinbase as part of their security. We did 4 things within 2 minutes of that text: (1) removed the phone number again from the email account – this time for good, (2) market sell all Bitcoin on Coinbase, (3) withdraw from Coinbase, (4) have AT&T suspend service on the phone line.
In speaking with AT&T, they were floored that our SIM would be transferred again in light of all the notes about fraud on the account and the PIN being changed to random digits that had never been used by us before. Based on the response of disbelief from AT&T on the second port, I suspect that this attack also involved a compromised AT&T employee that worked with the attacker to provide timely access to the Coinbase password reset email. Apparently, this has been going on for years: https://www.flashpoint-intel.com/blog/sim-swap-fraud-account-takeove with phone carrier employees swapping SIMs for $80s a swap.
Remember that most of this was hidden in real time, and was only known because we were able to recover emails deleted from Trash by the attacker.
Since we require any withdrawals to use Google Authenticator on Coinbase, our funds may have been secure nonetheless. However, under the circumstances with attackers that were apparently working with insiders to take our phone number twice in attempts to steal Bitcoin, and it being unknown if they had additional tools related to our Google Authenticator, we decided it was safer on the sidelines. The coins were held on the exchange for a quick exit depending on whether Bitcoin was going to break up or down from $10,000. A hardware wallet is always safest, but we were looking to time the market and not have transaction delays.
For some some security recommendations:
AT&T: If you are going to send a text saying that calls and texts are moving to a new number, provide a 10 minute window for the phone number to reply with a “NO” or “STOP” to prevent the move. This can escalate the SIM dispute to more trusted employees to determine who actually owns the line. Don’t let entry level employees swap SIMs.
Coinbase: Do not default to phone numbers as 2FA. Also, if someone logs in successfully with the password before the 24 hours are up, the password is known and there is no need to send the password reset email again for attacker to have forwarded to them. At least have an option to stop the password reset email from being sent. We did not tag our account at Coinbase with fraud because of the stories of frozen funds once an account is tagged. I’m not sure what the solution is there, but that is another problem.
Being a trader, it would be nice to think of Coinbase as any other type of security brokerage where your assets are yours (someone can’t steal your phone number and transfer your stocks to their account). We fell into that mindset of security, yet this experience has reminded us of the uniqueness of cryptocurrency and the lack of custodial assurance and insurance from exchanges because of the possession-is-everything properties of cryptocurrency.
As many have said before, 2FA with a phone number quickly becomes 1-factor authentication as soon as that phone number is associated with password recovery on your email or other accounts. Our overall recommendation is to avoid having a phone number associated with any recovery options across all your accounts.
TLDR on the process:
Scammers will steal your phone number (in our case twice in 24 hours) and use your phone number to access your email and accounts. They will use your email to reset passwords at financial accounts and file hosting such as DropBox. They will then use that combination to transfer any assets they can access from your accounts to theirs. They will do their best to hide this from you by
(1) not resetting your email password so as to raise suspicion,
(2) immediately delete any password reset emails you may receive from financial accounts to hide them from you,
(3) attempt to forward all emails sent to your address to a burner email, and
(4) set email rules to forward emails containing “coinbase” to an email folder other than your Inbox so that you don’t see the transactions and password reset emails that arrive to your inbox.
TLDR on defense tips: If your phone stops working or you receive a text of your number being ported do the following as soon as possible:
(1) log into your email account(s) associated with your financial accounts and remove your phone number as 2FA immediately
(2) change your email password,
(3) force a logout of all sessions from your email (at this point you have locked them out), then
(4) check your mail forwarding settings for forwards to burner addresses,
(5) check your mail rules for rerouting of emails from accounts such as Coinbase, and
(6) call your carrier to have them suspend service on your lost phone number and ask them to reinstate your SIM or get a new SIM. This will require a second phone because your personal phone number has been stolen.
We hope this helps some others be safe out there in protecting their coins. The more we know, the more we can protect ourselves. Wishing you all the best!
submitted by etheregg to CoinBase [link] [comments]

Crypto Weekly News — September, 11

What important crypto events happened last week?
Cryptocurrencies
VeChain: New Consensus Algorithm Offers Strong Performance And Security
The VeChainThor blockchain will receive a new consensus algorithm called SURFACE or Proof of Authority 2.0 (PoA 2.0). The double consensus model gives users the ability to choose different levels of security for their transactions.
Chainlink Surges 25% Higher As Altcoin Market Recovers
Some altcoins have suffered in the past few days, dropping significantly from their recent highs. During this time, LINK underwent a strong leap that lifted the cryptocurrency by 25%. Analysts are divided on what comes next with Chainlink.
Monero Is Traceable Using New CipherTrace Tool
Analyst firm CipherTrace has unveiled a first-of-its-kind tool for tracking transaction flows in Monero (XMR) at the request of the US Department of Homeland Security. The new tool will allow tracking of stolen coins and those used for illegal transactions.
Updates
MetaMask Has Launched Its Ethereum Wallet For iOS And Android
Starting September 4, Android and iOS users are required to download a full mobile version with the ability to interact with dApps. To synchronize history and import existing wallets, the user just needs to scan the QR code.
Crypto Exchange Bitstamp Exploring 25 New Tokens For Listing
The list, published on September 3, includes Augur (REP), Maker (MKR), Polkadot (DOT), Chainlink (LINK), Tezos (XTZ), Cardano (ADA), Kyber Network (KNC) and others. Bitstamp is known for its extremely conservative approach to the listing of new coins. The marketplace currently supports only seven crypto assets.
OKEx Officially Ranked The World’s Largest Crypto Derivatives Exchange
CoinDesk Research analyzed and evaluated data from CoinGecko, according to which the value of outstanding contracts on OKEx at the end of last month was $1.6 billion, making it the largest crypto derivatives exchange in the world.
Binance Launches DeFi-Styled Automated Market Maker Pool
Binance Liquid Swap is based on a variety of liquidity pools, allowing crypto assets to be swapped using the Automatic Market Maker (AMM) pricing algorithm instead of the order book. This guarantees price stability and lower transaction fees. The new trading feature allows users to pool tokens for instant liquidity and earnings.
Law, Cybercrimes, Mass Adoption
Mastercard Releases Platform Enabling Central Banks To Test Digital Currencies
The project is a controlled environment in which banks can simulate the issuance of national digital currencies. The result will be an assessment of their compatibility with the existing payment ecosystem and the practicality of using CBDC.
Eterbase: A New Attack On A Crypto Exchange
On September 8, unknown persons hacked Eterbase cryptocurrency exchange located in Slovakia. The site announced the loss of user funds in Bitcoin, Ethereum, Tron, XRP, Tezos, and Algorand totaling over $5.3 million. Representatives of Eterbase said that they contacted all centralized exchanges to which the stolen funds were sent.
US Crypto Adoption Rate Lags Behind Russia and China
Recent data showed an astonishing first place for Ukraine in the 2020 Global Adoption Index, followed by Russia and Venezuela. The index considers the total cost of online transactions, the cost of online retail transfers, and the number of cryptocurrency deposits online. The index also takes into account the volume of transactions made on P2P cryptocurrency exchanges.
Just Eat In France Accepts Bitcoin, Bitcoin Cash And Ethereum
The integration of cryptocurrencies into more than 15,000 restaurants in France was carried out through the Bitpay payment service. This initiative can promote the use of cryptocurrencies among the general public in a more democratic manner. Bitcoin conversion will be carried out in accordance with Bitpay's own quotes.
That’s all for now! For more details follow us on Twitter, subscribe to our YouTube channel, join our Telegram.
submitted by CoinjoyAssistant to u/CoinjoyAssistant [link] [comments]

Reward of 1BTC: Need help Tracing 10.8 BTC that was stolen from my Binance account via a read only API key hack

This is where My BTC has ended up in seemingly As of Saturday 18th 7 2020
Ill offer a reward of 1 BTC for a solid lead that leads to me recovering the funds in both addresses. These were stolen from my Binance account recently And yes I have submitted a ticket to binance which was to no avail but Would like to see if any experts here get any insight.
I trust both these addresses are just off some hardware wallet but they'd eventually have to move it.

Presumably replying this thread

https://blockchair.com/bitcoin/transaction/b72ba8a38747472eebf710f93fc9371336de8db48181d049eb21a1b9c4a9beba#i=0
https://blockchair.com/bitcoin/transaction/da436ddef9998e03d3e69d4f7e666545c361f8308ccfc18b5be71fbd31dcf9f1#i=0
submitted by InteqaamOlajak to Bitcoin [link] [comments]

BREAKING: Binance hacked! 7000 BTC stolen... BITCOIN STORTEN OP BINANCE EXCHANGE  BNB COIN KOPEN - YouTube Bitcoin & Co. per Kreditkarte auf Binance kaufen ✅ How To Get Any Binance Coin Wallet Address To Send Funds ... Binance hacked! 7000 BTC Stolen Stolen Cryptopia Funds Land On Binance Japanese Exchange Is Suing Binance Over Stolen Bitcoin ... How to buy bitcoin on CEX.IO and send to external wallet ...

The hack impacted Binance’s so-called “hot wallet,” which is basically storage that connects to the internet and is used for liquidity so bitcoin can be exchanged. According to Binance, just ... Binance Hacked: $40 Million worth of Bitcoin stolen but funds are SAFU. coinguides Follow on Twitter May 8, 2019. 0 152 . Facebook Twitter LinkedIn Pinterest Reddit. The world’s largest cryptocurrency exchange Binance has been hacked. On May 07 2019: Binance, has suffered a large scale security breach where the hackers managed to stole around 7000 Bitcoin which is worth more than $40 Million ... On the 8th of May 2019, hackers have stolen $40 million worth of Bitcoin from the Binance exchange through “variety of techniques, including phishing, viruses and other attacks”, as said by ChangPeng “CZ” Zhao, Binance’s CEO, on their article publicized on the 7th of May 2019 . That should be enough for you to hopefully stop unnecessarily leaving funds on Binance or exchanges in general. Hackers who stole $40 million worth of bitcoin from Binance hot wallet are now juggling the stolen proceeds across multiple wallets by breaking them into smaller fragments, suggested a report from blockchain service company Coinfirm, May 08, 2019.. Erasing the Trace of Stolen Bitcoins. The disarray surrounding the year’s fourth major cryptocurrency exchange hack is anything but settled. Binance traced the cryptocurrency theft — more than 7,000 bitcoins at the time of writing — to a single wallet after the hackers stole the contents of the company’s bitcoin hot wallet ... 7000 Bitcoins von Kryptogeldbörse Binance gestohlen Über kompromittierte Nutzeraccounts bei der Kryptogeld-Börse Binance sollen Unbekannte Bitcoin im Wert von rund 36 Millionen Euro geklaut haben. However, there’s an ongoing Bitcoin wallet hack that regulators can’t do a darn thing about that has since stolen a total of $22 million in BTC and the number climbs with each passing day and unsuspecting user. Here’s what the hack entails, how to avoid it, and why it’s been so successful at stealing cryptocurrency for so long. Binance, one of the world’s largest cryptocurrency exchanges, said hackers withdrew 7,000 Bitcoins worth about $40 million via a single transaction in a “large scale security breach,” the ... The Binance hackers are moving their stolen BTC into smaller and smaller wallets in an effort to hide their tracks. News Learn Videos Podcasts Research. Trending. Bitcoin. US Banks May Seek to ... Binance, a major cryptocurrency exchange that suffered a $44 million USD hack in May, recently processed some of the Bitcoins stolen from it on behalf of the hackers, digital currency Regtech firm ...

[index] [12661] [11211] [5099] [17964] [8349] [9320] [18609] [5288] [18555] [2590]

BREAKING: Binance hacked! 7000 BTC stolen...

Japanese exchange zaif sues binance over not returning stolen bitcoin, microstrategy buys 17,000 bitcoin on Sept 14, And one billion dollars in bitcoin is no... Binance coin kopen of verkopen? Uitleg, review en ervaringen over de Binance-exchange, de crypto-exchange met de meeste Altcoins. ⇩ Gratis Bitcoin Cryptocurr... Auf Binance habt ihr jetzt auch die Möglichkeit Bitcoin, Ethereum, Litecoin und Bitcoin Cash per Kreditkarte zu kaufen. Binance: https://www.binance.com/de/r... stolen funds, buy bitcoin not lottery tickets, and more! Sign up with coinbase. buy or sell 100 dollars in crypto currency and get 10 dollars of bitcoin for free with this link to coinbase. This video explains how you can buy Bitcoin via credit card and send the Bitcoin directly to your favorite wallet. I used Binance BTC wallet as an example. O... Just announced, Binance was hacked today, 7000 BTC stolen, which is around $40 mil. Earlier today CZ tweeted: "Have to perform some unscheduled server maintenance that will impact deposits and ... Brief intro on how to get any coin wallet address to deposit funds to. In this example I'm using Binance Exchange and wallet address ETH- Ethereum In order t... My Hardware Wallets: ... Stolen Bitcoin Tracing - Computerphile - Duration: 8:52. Computerphile Recommended for you. 8:52. Inside the Story: We Go Deep On the Binance Hacker Story - Duration: 9:46 ...

#