I just got hit for a ton of eth 3 meta wallets drained. Anyone heard anything or could help point me in the right direction of what to do? No idea how they accessed my funds.

  • AlabamaHaole@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Don’t sign shady smart contracts, enter your private key online, or store it using pictures on the cloud or a password recovery service.

        • GulibleFox@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          People can make mistakes with everything. It’s just about reducing the probability of making the mistake.

        • mjbmitch@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          That’s LastPass. That company has been plagued with security issues for years. Password managers as a whole aren’t anywhere close to what they are.

      • N_GHTMVRE@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Depends on the password manager. With something like KeePassXC, only you have the encrypted passwords file and it’s not on some server.

        • invaderdan@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          Nope no never absolutely not.

          Just a couple weeks ago I saw a thread where keepass was the culprit.

          NEVER USE A PASSWORD MANAGER

              • ScionoicS@alien.topB
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 year ago

                You went from saying “absolutely never use a password manager” and further down the thread you say you’re using your foreskin.

                Now you’re back tracking that all to pretend to be right?

                That’s absurd!

          • jeffreythesnake@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            You can just store a copy of keepass along with your file on a USB and access it that way, never has not be online.

          • Lifter_Dan@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            KeePass DB is vulnerable if they can crack the master password. If your master password has enough entropy that it would take so many million years to brute force, then you’ll be fine.

      • Fearless_Locality@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        They are generally secure. Any hack on them has never gotten clear text passwords.

        LastPass seems to be the one who gets hacked the most and I use that term very lightly because it’s usually just user emails

        Which don’t get me wrong is bad because then you can be at Target of spearfishing but you should not shy away from using a password manager because at the end of the day if you use it correctly it’s going to be more secure than whatever you’re doing now

      • AdZestyclose5199@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Being “secure” is relative. Would I store my Facebook password there? Sure. Would I store the password to my life savings there? Definitely not.

      • Neophyte-@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        no

        you might have a key logger on your pc, so the password manager is uselss

        never enter a seed phrase into a computer, always write them down fromm a hw wallet

        there is no real secure option for pc only unless you formatted, linux distro, crypto wallet software install with no internet, create the wallet, write the seed phrase down, format the drive / never use it again

        hw wallets just make this brain dead easy though, why is this still a conversation in 2023?

      • SnooCalculations1742@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Sadly no. LastPass was hacked last year, and a lot of people have had their wallets drained. So having your seed online is never truly safe.

        • mehdital@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          How is that? Even if I give you my password for Google you won’t be able to sign in to my account.

          • SnooCalculations1742@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            Yes, but if you have your seed phrase in an online container, and the container gets hacked, the 2FA doesn’t do anything. The hacker can recreate your wallet from the seed.

            • mehdital@alien.topB
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 year ago

              I am talking about storing the seed in the Google account, aka Google keep. The likelihood of Google getting hacked is much lower than my house burning down and taking with it all cold storage.

        • Crypto_Cat_34_32@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          What is the likelihood those people had either reused their master password elsewhere or that the password strength was very weak?

          • mehdital@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            Google will automatically block any sign in from a new device, so even with a compromised password, access is not granted.

            • Crypto_Cat_34_32@alien.topB
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 year ago

              Lastpass hack made 2FA completely irrelevant because hacker got access to the password databases directly. They can at their leisure try to bruteforce passwords for all of these accounts.

        • neb_flix@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          Lol, all you people parroting the LP hack… if any of you read the incident report, there was only very basic metadata like company names, veiling addresses, etc which was not tied to specific users. No encrypted notes or credentials were taken at all. That’s not how PWM’s work.

      • seems-unnecessary@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Im not sure if thats the stupidest thing you saod in your life. But it definitely is the most moronic thing i have heard all month. Cloud with auth? Lol idiot.

    • RelapseHS@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      I have no idea what meta mask is but I’m constantly seeing posts like this. What’s making it so easy for people to lose their eth? I only use crypto for gambling so I’m probably just ignorant to whatever meta mask is used for

      • AlabamaHaole@alien.topB
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Metamask is a popular wallet you can use to send/receive/store your crypto on their respective blockchains. Metamask isn’t the reason people are losing their funds. It’s because people don’t properly protect their private keys.

        • zac47812@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          And because they sign shady permissions left and right without thinking and/or revoking them when they are done using the platform.

            • jcpham@alien.topB
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 year ago

              pw *******

              Were we supposed to be able see a password, I think reddit blocked it out

          • I_Hate_Reddit_69420@alien.topB
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            The UX is terrible though. not necessarily the fault of metamask and more EVM related, but you mostly have no idea exactly what you are signing when interacting with contracts. Go tell your mom or grandma to revoke contracts after interacting with them. Is that really the web3 we want? This makes the web experience worse, not better.

        • CoolioMcCool@alien.topB
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          Yeah, the reason for all the posts mentioning metamask is simply that it is the most popular with wallet for people who use smart contracts, and using smart contracts can be risky.