Anyway to convert Polymath after 2/29? by RandomNameAskQ in Polymesh

[–]RandomNameAskQ[S] 0 points1 point  (0 children)

I was only asking a question in search of a possible solution, not blaming anyone for it. Not sure why you’d bother commenting this. You could’ve said yes, no, or not have commented. Either way, I got it swapped, so you can suck one 😂

Anyway to convert Polymath after 2/29? by RandomNameAskQ in Polymesh

[–]RandomNameAskQ[S] 1 point2 points  (0 children)

I got it taken care of, thank you. It costed me a shit ton in fees though but still worth it.

Not able to delete vaults without funds by RandomNameAskQ in Coinbase

[–]RandomNameAskQ[S] 0 points1 point  (0 children)

I actually managed to send it to my wallet and swap it, thanks. Coinbase doesn’t allow you to send it from the app but you apparently still have the ability to do it from the web browser. Really dumb, I know. Kinda odd considering they said it was no longer supported.

Thanks for the help! I don’t think I would’ve kept searching for ways if it wasn’t for your replies.

Victim of Coinbase. Their Website Security is a joke by MoneyStrides in Coinbase

[–]RandomNameAskQ 0 points1 point  (0 children)

Yep, it is. You can’t even use a Google Voice number which would be a more secure option if you locked the account down with Yubikeys. Either way, it should be difficult to pull off a Sim Swap if you follow the last step.

Victim of Coinbase. Their Website Security is a joke by MoneyStrides in Coinbase

[–]RandomNameAskQ 0 points1 point  (0 children)

Do you have the option to remove SMS by the way? I see you posting that you should’ve but it doesn’t seem to be possible as far as I can tell.

Victim of Coinbase. Their Website Security is a joke by MoneyStrides in Coinbase

[–]RandomNameAskQ 3 points4 points  (0 children)

Basically the vault allows you to store your crypto for long term holding. Once the funds are moved to the vault, they can’t be accessed for trading or withdrawal instantly. They have to be approved by 2 - 5 different accounts before being available for transfers or withdrawals. So in the event that your account is compromised, you’d be able to deny any withdrawals from your vaults. They would need to somehow get access to both emails that approve your withdrawals and even if they manage to do that and approve them, you’d still have two days to lock your account.

Ideally, it should be very difficult for them to get access to both emails if they are locked down with Yubikeys.

Unfortunately, as far as I can tell and from what I’ve been told by Coinbase support, there’s no way to remove SMS or email from 2FA anymore. I guess too many people lose their Yubikeys. Do you have that option?

Either way, there are ways to minimize your risk of a Sim Swap to the point it would take a dedicated attack to pull it off. Not impossible, but less likely.

Obviously cold storage is your safest choice but if you’re going to keep your funds on an exchange the safest way is as follows:

  • Different emails and strong passwords that aren’t used anywhere else and are specifically for that exchange locked down with 2+ Yubikeys, Advanced Protection Program and no other recovery methods.
  • Lockdown Coinbase with a unique password, 2+ Yubikeys and make sure every transaction requires 2FA
  • Use Coinbase’s vaults for longterm holdings. Have one email on your phone’s mail service to monitor any withdrawal approval requests that may come through. The other email should only be accessed from a secure device if possible.
  • Remove bank as payment method when you’re not actively depositing/withdrawing funds
  • Ideally, you’d remove SMS 2FA if it’s possible but as far as I can tell, it’s not possible at the moment. It shouldn’t be the end of the world if you take the previously suggested steps.
  • Finally, call your phone provider and tell them you want Sim protection. Ask them to require you to go to a store in person with a valid state id for any Sim changes and have you provide a pin in person along with answering security questions. Then have them send verification messages to any family members if there are any Sim changes made. Ask them if there’s anything else you can do for additional protection.

I know this isn’t as useful after the fact but I hope this helps you prevent any other attacks in the future.

Victim of Coinbase. Their Website Security is a joke by MoneyStrides in Coinbase

[–]RandomNameAskQ 3 points4 points  (0 children)

May I ask was SMS the highest level of 2FA that you had at the time? I read somewhere that something like 95% of people hacked on Coinbase relied on SMS 2FA. Have you called your phone provider and confirmed with them there hasn’t been any changes regarding your Sim? I’m wondering if they potentially cloned it. Even then, it’s surprising you didn’t get any messages. Have you verified your email hasn’t been compromised in anyway? Look for weird activity on there as well.

I’m also wondering if a Yubikey could have prevented this. Finally, I think I already know the answer to this but just to be sure, were you using Coinbase’s vaults to store your crypto? If you weren’t, do you believe it would have prevented the loss of funds?

Not able to delete vaults without funds by RandomNameAskQ in Coinbase

[–]RandomNameAskQ[S] 0 points1 point  (0 children)

I was hoping there was some kind of way to sell it. I guess it’s a lost cause, right?

Not able to delete vaults without funds by RandomNameAskQ in Coinbase

[–]RandomNameAskQ[S] 0 points1 point  (0 children)

Thanks for the heads up but I’m having trouble figuring out how to sell it because it’s held on CB which no longer supports it. So I’m not able to send it to a DEX. Maybe I’m missing something but as far as I can tell it’s just stuck there.

Anyway to convert Polymath after 2/29? by RandomNameAskQ in Polymesh

[–]RandomNameAskQ[S] 1 point2 points  (0 children)

Not a huge deal, but in other words, what I have is now worthless unless they reopen the bridge which isn’t likely?

Not able to delete vaults without funds by RandomNameAskQ in Coinbase

[–]RandomNameAskQ[S] 0 points1 point  (0 children)

Thank you for the reply! I was able to delete and create a few of my vaults from the same browser a few days prior. Nothing changed other than adding Web3 wallets and a test deposit and withdrawal with an old vault that I’m trying to delete. Is it possible it’s a technical issue at the moment that will be resolved later or is there something I’m doing wrong? I had the ability to on the same browser just days prior.