UPDATE: @binance security team has investigated and found that the common address used is ChangeNow, a VPN IP was used to access Binance, and the funds were converted to XMR and withdrawn. I asked if they can be stopped and haven't received a reply on that. #TRX#TRON
We've been hacked. 530k #TRX transferred to a @binance account. PK has never been stored on this laptop - we were logged into #tronscan with a keystore. It's unacceptable that tronscan is not open source. This address has stolen 11 million TRX in 3 days. #TRON
Take a look at this guy's transactions. That's about 25 $TRON wallets a day that are getting cleaned out.
More than 15,000 transfers to/from this address. Many wallets (like ours) were emptied in multiple transfers. #TRX@Tronfoundation@justinsuntron
https://t.co/4JhIEzquKM
We've been hacked. 530k #TRX transferred to a @binance account. PK has never been stored on this laptop - we were logged into #tronscan with a keystore. It's unacceptable that tronscan is not open source. This address has stolen 11 million TRX in 3 days. #TRON
Take a look at this guy's transactions. That's about 25 $TRON wallets a day that are getting cleaned out.
More than 15,000 transfers to/from this address. Many wallets (like ours) were emptied in multiple transfers. #TRX@Tronfoundation@justinsuntron
https://t.co/4JhIEzquKM
@krazykewlgamez @Tronfoundation@justinsuntron The only way a database like that could exist is if there was a backdoor in java-tron, or if tronscan collected authorizations on the server side which I was assured they didn't.
@KinToshiGG @PiterSpain@cornycoin69@binance TRUE. I always use a bookmark. DNS spoofing is a possibility, although there's a lot of backend code which is brand new and would be difficult to replicate on such short notice.
It's safe to say he's hit THOUSANDS of wallets already. It's time to stop blaming the victims and figure out how it's being done. We might suggest enabling multi-signature to your accounts.
@NickiDotdk@binance I actually bought a ledger but stupidly bought it from Amazon. Even though ledger was the seller, if it comes from Amazon stock it gets comingled with the other sellers' items so there's no guarantee it didn't actually come from a scammer.
This has been going on for weeks, and continued all day and continues to happen RIGHT NOW to *hundreds* of accounts. Clearly the responsible thing would be for @justinsuntron and the other #TRONSR to HALT BLOCK PRODUCTION until the exploit is identified. #TRON#TRX
We've been hacked. 530k #TRX transferred to a @binance account. PK has never been stored on this laptop - we were logged into #tronscan with a keystore. It's unacceptable that tronscan is not open source. This address has stolen 11 million TRX in 3 days. #TRON
@PiterSpain I never said it was the vulnerability, I just said that for a site that is so important to the security of so many funds it really ought to be verified open source software. Shouldn't it?
We've been asked for proof.
https://t.co/oFvBrfX9Gf
https://t.co/4O6U6wsnOw
In the past 3 days, the receiving address has cleaned out 60 wallets worth more than 11 million TRX.
https://t.co/4JhIEzquKM
@john_skotts@JTS_Global@binance Well that's the mystery. Perhaps my laptop has spyware and they were able to get my PK from when I logged into wallet-cli with my keystore/password. Or somehow stole my creds while I was logged into tronscan.
@Smalls1139@binance 2 possibilities: Either the software I use to access my accounts (tronscan, wallet-cli) has been compromised, or my laptop has. With 60 victims in a matter of days I am leaning toward the former possibility.
@NickiDotdk@binance This is a distinct possibility that I have a keylogger installed and it recorded my wallet-cli password, and then stole the keystore. I have heard of Mac o/s hacks.... but 60 victims in 2 days is a lot.
@DekartX@binance No it has nothing to do with Binance other than it's a place where they can scrub the transactions by selling for BTC and transferring out.
@WolfHodl@PiterSpain That's definitely not a possibility. I use a bookmark to access tronscan with this browser, and I have a different default browser that I use for follow links.