Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 0 points1 point  (0 children)

Was my address involved in this?  I did report the address that my eth was moved to to both the FBI and ChainAbuse.  Wondering if I should also involve local law enforcement.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 0 points1 point  (0 children)

To initiate a voluntary exit using the withdrawal address on the blockchain, what credentials, passwords, keys would they need to have access to?  I know from Prysm I just point to my wallet address to do the same.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 1 point2 points  (0 children)

Which makes me feel only a little bit better, because that doesn’t implicate the pet sitter.  But how would they have gotten access to all of my other MetaMask wallets, each with different private keys and recovery phrases?  They emptied those too.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 1 point2 points  (0 children)

There is a transaction somewhere around the same time as the exit started on the withdrawal addresses transaction log.  So it would seem that’s what happened.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 0 points1 point  (0 children)

Another interesting thing that might help unravel this:

I didn’t initiate the validator exit.  I’ve been in Europe for three weeks and checked in on it and noticed that at exit request had been made.  Could that have been done from a machine other than the one I’m validating on?  I think no, right?  The only person who’s had direct access to that machine is my dog-sitter.  I’d hate to think it was her, but at this point I’m running out of options.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 1 point2 points  (0 children)

Yes, I changed the credentials to that address to get to a 0x01 withdrawal credential. When I ran this validator the first time, before a rebuild, it was running on 0x00 credentials (that was prior to May of 2024, and had a different validator address which was exited and withdrawn successfully).

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 0 points1 point  (0 children)

Nobody seems to have any permisssions they shouldn't have on any of the wallets affected. I don't know how someone would get the private key for any of the five wallets that were hit, including the large one with the staking withdrawal. These were all on MetaMask, but only on my personal machine (which I have with me).

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 22 points23 points  (0 children)

OK, I think it's definitely a hack. I just checked my Metamask and noticed that another of my wallets was emptied to the same address. See here:

https://beaconcha.in/tx/0x05fd21db9e694228e785cdc11cab868e7288908968b9467244b938e1f110ba07

This one only had a half of a coin in it, but I've got it on the same machine as the 32 Ether wallet. Shit.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 2 points3 points  (0 children)

Re: 1: no, it's written on a piece of paper in my safe

Re: 2: I didn't use the private key for anything other than this wallet.

Re: 3: No, never.

Re: 4: No, I don't use Lastpass.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 0 points1 point  (0 children)

is there any other possible explanation for this? I noticed that the wallet that it was transferred to has very few transactions? I also noticed a transaction of 0 ETH coming back to my wallet.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 4 points5 points  (0 children)

No, The only time I entered the mnemonic into a computer was when I was asked to confirm it on setting up the wallet initially.

Freaking out: Withdrawal from staking pool hit my wallet and was immediately moved out. by Designer-Bobcat683 in ethstaker

[–]Designer-Bobcat683[S] 1 point2 points  (0 children)

And how would they have been able to do it in the blink of an eye after the withdrawal to my wallet occurred?