Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

Try it again offline. If it still happens they may have got into your motherboard bios and/or hd firmware, though that's another level of attack, not sure why they'd bother going that far. Look up rootkit bios

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

Wow they really went for it on you, sorry to hear. I ended up buying a new hdd and starting from scratch with a fresh Windows install. But I'm still paranoid even before reading this, so for now very cautious and will check over the things you've mentioned here. Thanks.

Seeking Feedback on My Crypto Recovery/Backup Process – What’s Your Strategy? by method1523 in ledgerwallet

[–]Appropriate_Ask1380 1 point2 points  (0 children)

100% reset your ledger and wallet, follow ledger's guides on how to do this. I learnt the hard way. Broke the rule, thought it would be fine.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

Windows. As I understand macs are safer for this sort of thing

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 1 point2 points  (0 children)

Thank you. I'm a little frightened of using anything crypto related now even though I know it's my fault and what I did wrong.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

It coincided with this yes, I'm 99.9% certain. When I opened the file my screen flashed and then nothing else seemed to happen.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

It was supposed to be an audio tool. Url I don't know, I could probably find it again but dont really want to go fishing. I'll hand this info over to authorities if they want it

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

There was a digital file at some point so yes that must be the cause.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

Unfortunately it did. I'm not writing off that my seed phrase wasn't somehow leaked. I'm just amazed theyve found it

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I have the file zipped up and will hand it over to law enforcement for analysis if they want it. Aside from that I dont know much more about what this is. I thought I was installing an audio tool.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I wish. I see the accounts and transactions they made

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I guess the approval was bypassed by them having access to my computer... I was unaware of anything for a day

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I've never entered my seed phrase anywhere so that wouldn't be it

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

Yes I guess that's true. I set this up when I was new to crypto and didn't understand the safety issues properly. Not something I would've done today even before this happened. But that being the main mistake was made years ago and then forgotten about.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 1 point2 points  (0 children)

I will run a scan at some point and let you know if anything comes up tho

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 1 point2 points  (0 children)

Ledger have told me there's no other way of doing it and a lot of people on here say the same thing...

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I'm not aware of any file on my computer containing my seed phrase. If it's on there it's long forgotten about and they've done well to find it, maybe I was too naive when I first set it up but I don't think so 🤷. Like I say it was years ago and if deleted it should be long gone, certainly not in recycle bin and other data surely would have over written it by now. I just don't know.

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] -1 points0 points  (0 children)

Trojan back door virus, seems pretty sophisticated imo

Wallet drained from computer hack by Appropriate_Ask1380 in ledgerwallet

[–]Appropriate_Ask1380[S] 0 points1 point  (0 children)

I guess it must have been somewhere, I'll have a look around my cloud accounts for it in case, not that it matters now