I've been researching this project and posting many threads and posts with genuine info.
I was the OP for these threads for instance: And now this is what I got.
I am heartbroken. christ
Dylan Long
I'm not sure how to check for a withdrawal history. Here's the thread where the link was posted.
DO NOT OPEN THAT LINK
I posted this in that thread:
Christopher Evans
You mean the etherdelta address that was hacked?
Brayden Anderson
I found a section in etherdelta that says "my transactions" Is any withdrawal supposed to show up here? Because it doesn't. There's nothing in that section.
I can prove I sent 20k LINK to that etherdelta address from my MEW, if you want.
Looks like he got a few people. Including 6 billion dollars worth of AMIS tokens.
Cooper Sullivan
I'm fucking sick.
All I ever did was be constructive and inform people about what I researched.
Matthew Ward
WHY DID YOU KEEP YOUR TOKENS ON ETHERDELTA FFS? Sorry for your loss OP, but why wouldn't you just withdraw to your MEW? Holy fuck.
Gavin Martin
what a smart
James Morgan
the fuck is this for real? How the fuck does it open etherdelta if you're not logged in, or were you? And how the fuck does it withdraw it?
Kevin Ramirez
thank you for warning others did it steal from your Etherdelta balance or from your associated wallet?
Justin Scott
a lot of people keep etherdelta logged in, it just transferred the tokens to his wallet using the script. ez gains
Asher Scott
I'd be in for setting up a discord finding this guy Alternatively we could do it in this thread, but I think it might be against the rules
Parker Murphy
so if I'm not logged in any wallet I should be safe if I ever dun goof like OP right? This shit is 2 spoopy 4 me
Carson Mitchell
It was supposed to be as secure as a wallet. But now that I think of it, the LINK was in the "balance" section.
I think it took everything from the balance, but not from the actual account. There's still some ETH dust in there.
Apparently the tokens don't fit in the Etherdelta "wallet".
Evan James
Havent invested in link, how much in btc did you lose bro?
Connor Gray
He'll make a mistake and we'll find him when he tries cashing out. I'm already betting on his first mistake.
Isaiah Sanchez
It was pretty much exactly 4,000 dollars. 20k LINK at 0.2 cents.
Cooper Nelson
Sorry man, but the site looks and functions like Pajeet cancer. You should have been very cautious.
Ryan Edwards
wasn't finding where the tokens went his first mistake? forgot to give condolences OP
Joshua Clark
lol you can't find him guys, just give it up. ahahahaha. you're all wealthly anyways from crypto
William Murphy
Damn homie user that's rough, if I hit jackpot with link, I'll donate some btc to you to get you back on your feet.
Charles Morales
There's a sucker born everyday
Lucas Walker
very shit thing to have happened but as long as you don't let it put you off crypto altogether you'll bounce back before you know it m8, i'm sure of it
Henry Gutierrez
AAAAAAAAAAAAAAAAAA
Cameron Bailey
this is a fresh exploit, link looked innocent and instantly redirected to a legit etherdelta URL but with a script injected in
not much OP could have done, never seen any sort of warning against keeping a balance on ED, obviously this will change now
Jacob Allen
I sold off my BTC and XMR for this user.
Lost a bunch in the January 5 crash, so I only invested 500 dollars. I grew that a little, and threw all of it into the Chainlink ICO because I researched it and believed in it.
All I had otherwise was some TNT.
Isaiah Roberts
LITERALLY ALL MY ETHER, ETH TOKENS, AND EVEN UNRELATED COINS LIKE NEO ARE FUCKING GONE. AND MY BANK JUST CALLED AND SAID THERE HAVE BEEN SUSPICIOUS WITHDRAWALS OUT OF MY ACCOUNT. FUUUUUUUUUUUUCK
Kevin Perez
fuckin hell this exploit is genius and simple- nefarious as fuck though and will have me thinking twice about clicking links here.
Veeky Forums isn't a secret club anymore and there are faggots out to scam us.
Jacob Hill
This.
DON'T OPEN ANY LINKS BEFORE TESTING
This blew a fucking hole in my soul.
Owen Hall
1. Buy Monero. (Hacker will convert when done)
2. Buy a hardware wallet if you have loads of money in crypto. NanoS is great.
Also prepare for more FUD from the media. My condolences to everybody who last a large sum of his wealth.
Leo Ortiz
Is there a dev. dude that can explain how this works for a brainlet? I get that the link could redirect me anywhere but how the fuck do they auto transfer link from my etherdelta?
Christian Anderson
>never seen any sort of warning against keeping a balance on ED I think you can only keep tokens in the balance.
So NEVER keep any tokens on etherdelta.
Adam Stewart
>etherdelta once proving itself to be shit at everything
Evan Roberts
Code injection. They have JavaScript commands in the url that you execute when you open the url.
Daniel Allen
Veeky Forums has never been a secret club. It's kinda an open house party that lets strangers in 24/7. We got some regulars but you can tell by how people talk (e.g. random shillers who appear to be into the crypto scene yet can't recognize any of the memes) that we're constantly getting newfriends here.
Brayden Ramirez
If you didn't want this to happen disable javascript
Austin Sullivan
I'm not getting back up from this. This was simply too much money for me.
Nolan Myers
if you disable javascript etherdelta will stop from functioning.
Chase Barnes
how much did you lose?
Zachary Perry
damn.. I mean this rly fucking sucks for everyone who lost money with this but at the same time whoever did this is a clever fucker.
Joseph Thompson
Damn OP I feel so sorry for you, you got more link stolen than my entire portfolio. Is it time to liquidate LINK until the fire settles?
Brandon Edwards
one would think any modern browser would drop all urls with "script" on them.
Benjamin Russell
So where should i keep my LINK?
Henry Walker
SO did anyone try the address just cause fuck you? I'l curious, why would the OP give the full address?
Cooper Lopez
yeah no, this is untraceable only way to find this guy is to somehow hack into the transaction data, which is what cryptocurrency is heavily armed against...
Isaac Ross
I wonder who could be making this post!
Dylan Cook
why isn't this way more common? like why aren't thousands of scripts being listed every day? or why aren't thousands of hackers attempting to hack into thousands of reputable sites and upload malicious scripts every day?
Landon Bennett
4,000 dollars in LINK and one ETH in TNT. Literally everything I had outside of my bare necessities.
Nothing wrong with LINK at all, just move your shit out of etherdelta.
MEW Open the "ethplorer.io" somewhere to the right to view your tokens
Carson Nelson
The guy will convert it all to ether via etherdelta (chance to buy cheap) and then convert it to Monero to make untraceable.
Screencap this.
Gabriel Gray
If I understand how this worked correctly it would only work if:
- You are keeping balances on ED - You are using ED as a wallet (letting them manage your private key
NO ONE should be doing either of these things
Josiah Sullivan
I didn't have anything on ED. Am I safe?
Did it put a keylogger on? I don't get howt his works
Should I log on my ED? and transfer my stuff?
Sebastian Johnson
Does etherdelta not use a 2FA or passphrase system?
Angel Wilson
You manage your own private keys on ED.
Sebastian Collins
want to know this aswel
Bentley Lewis
the script looks for .pks (private key) and sends it to his website.
he does the rest. RIP to everyone who lost their shit.
Evan Rodriguez
If you don't have anything on ED what exactly are you planning on transferring?
Blake Rogers
Sorry, my meant should I log on My Ether Wallet and tranfser my stuff to a new wallet?
Ethan Perez
doesn't really take brains, it's more a case of it being insane that etherdelta wouldn't have that shit sanitized
Wyatt Davis
i'm not a fucking begging man, but oh my god am i desperate right now
Robert Nelson
Did you use metamask or what?
Connor Rodriguez
Well you can trace the person who posted the link on Veeky Forums. Veeky Forums has his IP address so maybe you have a chance. Thought I don't think what he is doing is illegal so tough luck
Nathaniel Foster
no
Xavier Gonzalez
I just checked it out in a VM. It's a javascript injection attack in the URL after it redirects from the fake tumblr URL. There is no keylogger from this exploit.
Luke Stewart
ok. I didn't have anything on ED and didn't associate anything to my MetaMask (dont know if that matters?)
So I'm bascially safe right
Jason Hill
if i clicked the link, should I clear cookies and stuff? what do
Carson King
Is etherdelta not open source? How the fuck does this shit happen.
Grayson Kelly
What did you typically use to authorize transactions? If the answer is just ED then your private key is managed by them or stored in browser data, both of which are bad and should never be done.
Nathan Wood
send ur etherdelta stuff away and make new private key and account
Lucas Baker
i was just trying to withdraw my link to my mew, opened my mew and copied my address
and then i went to etherdelta and suddenly the 20000 just turned to 0
Jaxon Butler
You just gotta love Java for that... I could´ve be fucked if i weren´t lazy as fuck.
Logan Gutierrez
If you had nothing on ED, you should be fine.
Not necessary. The script only executes when the URL is loaded.
They only have their minified source on their github IIRC.
Jacob Anderson
>lta stuff away and make new private key and
yeah already did that, even though i quickly closed the link even before anything could happen
Gabriel Scott
it's a scam because some clever boy was able to execute JS when you click the link he sniff the pw and sends to some php server
Nicholas Collins
to send a message to the hacker do this: requestb.in/19nxov41?1= "insert your message here"
Charles Stewart
Javascript, not java. But this was a very amateur error on ED's part.
Jayden Reyes
You know Veeky Forums is usually filled with autism and cancer, but sometimes you guys are alright.
Michael Cox
is there a whale here who would like to save a life?
I tried. I posted a bunch of threads and posts with legit info about LINK. I think I swayed a lot of minds.
I posted these, and they got linked a bunch of times: (You) (Cross-thread) (You) (Cross-thread)
I'm pretty sure I helped a lot of people make money on LINK.
Mason Sullivan
how a company moving millions has an xss vulnerability
these are the retards you are making rich, Veeky Forums
Robert Cook
>If the answer is just ED then your private key is managed by them or stored in browser data, both of which are bad and should never be done. so wat do? please help poor brainlets out, we need to make crypto theft prevention generals for this shit now
Ayden Baker
wtf is that?
Gavin Garcia
someone read the script and find out where it's sending the private keys to
Hudson Myers
Am I safe if I clear all cache, passwords, cookies, everything stored in my browser then click on that link?
Jack Ortiz
Anyone that has clicked the link should at this point remove any association with your private key and your coins. The script injection searches for your private key(s) and forwards them to the attacker. At this point he can technically continue to steal coins as long as you're still using the same private key.
Jaxon Miller
only the etherdelta one though, right?
Brody White
Rotate metamask keys. Don't keep anything of value on any web-connected exchange or interface, period.
It is going to some server he owns.
Rotate metamask keys.
Oliver Rogers
Jokes on the scammer, those tokens are worthless hahahaha
Luis Harris
Any private keys saved on Etherdelta are compromised.
Cooper Evans
HOLY SHIT! my shit just got hacked too! All my shit went to that same fuking ED address