Silk Road forums

Support => Customer support => Topic started by: journeyman on June 03, 2013, 10:59 am

Title: [SOLVED] BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: journeyman on June 03, 2013, 10:59 am
Hello,

Could someone please help me with looking into what has happened on my account?!

I've just transferred in funds (1.08BTC); before I could even make a purchase, the funds have been withdrawn. Here is the transaction log:

Quote
action            notes                                                                                          amount   balance   date
withdrawal                                                                                                                 ฿-1.08   ฿0.00   June 3, 2013, 6:42 am UTC
deposit                1CYwVGLhJX85hPW9mZdkrV4gdkTkYhhBo9                   ฿1.08   ฿1.08   June 3, 2013, 5:31 am UTC

There is no description as to where the funds have gone (to another user, or to a bitcoin address?)

This is the first time I've put money into this account. I have not used a phishing site (the window was left open, I have SR bookmarked, and I did not at any time enter my PIN).

This sucks :(.

Can someone please help as soon as possible? thanks!!
journeyman
Title: Re: BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: Libertas on June 03, 2013, 12:46 pm
Hello,

Could someone please help me with looking into what has happened on my account?!

I've just transferred in funds (1.08BTC); before I could even make a purchase, the funds have been withdrawn. Here is the transaction log:

Quote
action            notes                                                                                          amount   balance   date
withdrawal                                                                                                                 ฿-1.08   ฿0.00   June 3, 2013, 6:42 am UTC
deposit                1CYwVGLhJX85hPW9mZdkrV4gdkTkYhhBo9                   ฿1.08   ฿1.08   June 3, 2013, 5:31 am UTC

There is no description as to where the funds have gone (to another user, or to a bitcoin address?)

This is the first time I've put money into this account. I have not used a phishing site (the window was left open, I have SR bookmarked, and I did not at any time enter my PIN).

This sucks :(.

Can someone please help as soon as possible? thanks!!
journeyman

Hi journeyman,

The only way for BTC to be removed from your account once it has arrived there is to be withdrawn by someone that is in possession of your PIN. How many characters do your passphrase and PIN consist of? If you have never entered your PIN at login and have always used silkroadvb5piz3r.onion then you should check your system for keyloggers, dataloggers and rootkits as any one of the three could log your information and send it back to a third party.

If you have ever accessed your Silk Road account using onion.to they will also have a log of your passphrase and password.

Libertas
Title: Re: BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: journeyman on June 04, 2013, 12:25 am
Thanks for the response Libertas.

I can confirm that I didn't enter my PIN at login, my password is at least 10+ characters, and my PIN code was 4. These codes were not changed between me finding the money missing and when I created the account. I did not enter my pin at login at any stage. The only time I reentered my PIN was to confirm that I knew it before making the deposit - I did this by updating my settings.

I can also confirm there are no rootkits on my computer (or that it is extremely unlikely- all binaries on my linux machine are md5 checked).

The thing that is most suspicious is that there is no destination for where the funds went. Could someone please look into that further for me?

Regards,
[REDACTED]
Title: Re: BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: Libertas on June 04, 2013, 12:42 am
Thanks for the response Libertas.

I can confirm that I didn't enter my PIN at login, my password is at least 10+ characters, and my PIN code was 4. These codes were not changed between me finding the money missing and when I created the account. I did not enter my pin at login at any stage. The only time I reentered my PIN was to confirm that I knew it before making the deposit - I did this by updating my settings.

I can also confirm there are no rootkits on my computer (or that it is extremely unlikely- all binaries on my linux machine are md5 checked).

The thing that is most suspicious is that there is no destination for where the funds went. Could someone please look into that further for me?

Regards,
[REDACTED]

Please check your system for keyloggers and dataloggers - there are a few well known loggers that target Linux specifically.

The PIN does not have to numeric, nor short - in fact, the longer and more convoluted it is, the better. When you make a withdrawal, the address that the Bitcoin were withdrawn to is not shown for security purposes.

Please check any BTC receiving addresses that you use to see if you may have withdrawn them. That may not seem likely, but possibilities need to be eliminated in order to draw the most likely conclusion.

You will have to open up a Support ticket on the main site if you want this looked into further; we have no access to the administrative sections of the site so can be of no more help from here.

You can reach SR Support by clicking the 'support' link in the bottom right corner of any page on the main site. You may be waiting up to 48 hours for a response depending on how busy they are so please include as much information as possible in your initial message.

Please refrain from signing anything here with your real name - the less you link to your real identity the better.

Libertas
Title: Re: BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: journeyman on June 05, 2013, 05:59 am
Thanks for the support Libertas.

I did run a full scan with multiple methods on my system to reconfirm no keyloggers etc; very unlikely unless it was a custom job, which would be even less probable.

I've checked my addresses to see if there was any withdraw to them; no joy. Also - as I noted - there is no withdrawal address specified in the transaction log.

I'll contact support.

Regards,
Someone Not Buying Illicit Materials On An Illicit Website?
Title: Re: BTC withdrawn out of account after 1hr of funding... wtf (not phishing)
Post by: Libertas on June 05, 2013, 09:17 am
Thanks for the support Libertas.

I did run a full scan with multiple methods on my system to reconfirm no keyloggers etc; very unlikely unless it was a custom job, which would be even less probable.

I've checked my addresses to see if there was any withdraw to them; no joy. Also - as I noted - there is no withdrawal address specified in the transaction log.

I'll contact support.

Regards,
Someone Not Buying Illicit Materials On An Illicit Website?

Best of luck with it, Someone Not Buying Illicit Materials On An Illicit Website! ;D Let us know how it works out.

Libertas