I just got hit for a ton of eth 3 meta wallets drained. Anyone heard anything or could help point me in the right direction of what to do? No idea how they accessed my funds.

  • jetlijonny@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    My metamask also got drained a while back. likely they have got access to your PC and hacked your metamask key and logged the password when you typed on keyboard. Could have been a malicious program or email phishing. This is what happened to me anyway.

  • baethovenbb@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    I see lots of inaccurate info or assumptions about what transactions/data that the OP signed in this thread

    Based on the native ether send in the tx hash OP posted, this is a private-key level compromise. Since the OP didn’t mention signing anything and said multiple wallets were emptied it’s most likely the seed phrase was exposed in some way. Could be related to the LastPass breach or maybe it was pushed to github accidentally.

  • leovin@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Another warning: do not use MetaMask or any browser extension wallet for anything other than screwing around or testing contracts. It is NOT secure.

  • symonym7@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Don’t keep all your crypto-eggs in one hot basket.

    The wallet(s) with the majority of my assets never touch contracts. I keep small amounts of ETH etc in browser wallets for interactions.

    Oh, and my keys are written on paper and stored in a titanium vault 300 meters underground.

  • james2020chris@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Op, is the list of smart contracts that you have used a long list?

    If you have had that much ether a long time, then I would suspect something more recent.

    After that, are there pics on your phone, that are backing up to a cloud?

    • telejoshi@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      To be fair, most of the time these are people who can’t even articulate what happened. They’d lose money in fiat, too.

      • KitchenItem@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        somehow these people were able to buy crypto and get it out of exchange so you need to have some general knowledge

        • telejoshi@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          It’s a step-by-step thing. People learn to operate washing machines, even if it takes 100% of their brain.

          • KitchenItem@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            “Quote by a forest ranger at Yosemite National Park on why it is hard to design the perfect garbage bin to keep bears from breaking into it: “There is considerable overlap between the intelligence of the smartest bears and the dumbest tourists.””

  • britishbengali007@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    You definitely turned on blind signing feature. It’s basically like how on every phone you have feature to turn on inorder to install third party apps that’d not from official sources as apks. But the crypto version blind signing

  • dericecourcy@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    The transaction 0xe5e7266bf6abb1babf4024373957f04f0c7c61eb14670502acf2374a4ed4e8e6 was a basic ether send, which means somehow you gave away your private key or signed a message [this transaction when] you should not have

    There are a few ways someone can get your private key. Physical access is one, but another is by signing messages with certain overlapping parameters, then some clever crypto math can be done to deduce your private key. https://medium.com/asecuritysite-when-bob-met-alice/cracking-ecdsa-with-a-leak-of-the-random-nonce-d72c67f201cd

  • GoCryptoYourself@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    this is almost always smartcontract related. Check your wallet spending permissions - i believe etherscan has a util for that

  • Red5point1@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    if you had given access to your wallet to apps in the past to take part in their project s then there’s potential for them to have the ability to drain your wallet.
    There have been some failed projects that resorted to do that.