smoothy 711 Posted June 4, 2019 Share Posted June 4, 2019 (edited) So if I get it right, this is a summary of what happened: - The funds were stolen from ripple accounts (not hosted wallets) that had been imported into, or created on, gatehub - To move the funds out, no logins happened to the users gatehub accounts So to me there are only 2 possible explanations: - the secret keys were somehow hosted by gatehub and someone got access to those secret keys. - when someone asked to show their secret key on the gatehub site, the secret key somehow got intercepted. Damn, I feel for you guys, I really do. Edited June 4, 2019 by smoothy 2ndtimearound and LetHerRip 2 Link to post Share on other sites
pucksterpete 1,680 Posted June 4, 2019 Share Posted June 4, 2019 2 minutes ago, 2ndtimearound said: less likely for me, but possible - an exit scam I can tell you this, if it is an exit scam, the people that run Gatehub won't be too hard to find! Selective 1 Link to post Share on other sites
Hero_Member 120 Posted June 4, 2019 Share Posted June 4, 2019 28 minutes ago, pucksterpete said: If I was you, I would generate a new XRP address and activate it, then send your XRP from Gatehub to the new address https://bithomp.com/create/ https://bithomp.com/activation/ no real need to activate from bithomp. Yust send your XRP and it will be activated pucksterpete and LetHerRip 2 Link to post Share on other sites
jlripple 92 Posted June 4, 2019 Share Posted June 4, 2019 5 minutes ago, 2ndtimearound said: Having read through this sad thread....two possibilities come to my mind:- Possibility 1: incompetence on the part of gatehub.com only incompetence would make it possible that someone COULD somehow access 2FA private keys to bypass 2FA; that would mean the keys were not encrypted, or encrypted weakly and easy to crack, or that gatehub.com could allow an insider to access accounts through interal admin systems Possibility 2: inside job and gatehub.com are hiding it less likely for me, but possible - an exit scam I don't see any other possibilities (but open to suggestions). phishing? How do you phish a 2FA secret key? That's not something you would phish without SOMEONE noticing. So how did the "hacker" get past 2FA? Exit scam maybe unlikely cos Chris and Greg are shareholders? Why would they do that pucksterpete 1 Link to post Share on other sites
pucksterpete 1,680 Posted June 4, 2019 Share Posted June 4, 2019 We'll wait and see what Gatehub says in the next few days Link to post Share on other sites
BAX 514 Posted June 4, 2019 Share Posted June 4, 2019 3 minutes ago, 2ndtimearound said: Having read through this sad thread....two possibilities come to my mind:- Possibility 1: incompetence on the part of gatehub.com only incompetence would make it possible that someone COULD somehow access 2FA private keys to bypass 2FA; that would mean the keys were not encrypted, or encrypted weakly and easy to crack, or that gatehub.com could allow an insider to access accounts through interal admin systems Possibility 2: inside job and gatehub.com are hiding it less likely for me, but possible - an exit scam I don't see any other possibilities (but open to suggestions). phishing? How do you phish a 2FA secret key? That's not something you would phish without SOMEONE noticing. Either way, how on earth are the people who got robbed responisble in any way for this? They claim it's cold storage - so ... how did the "hacker" get past 2FA? Its gatehub.net And the thefts didn't need to bypass 2FA because most likely they got the secret keys somehow. All the victims never got emails that someone is logging from different IP. If all the victims here are imported wallets from RippleTrade, the problem might be coming from RippleTrade not Gatehub!!! Could guys share if your stolen wallets were imported from RippleTrade? pucksterpete 1 Link to post Share on other sites
iLeeT 2,538 Posted June 4, 2019 Share Posted June 4, 2019 6 minutes ago, 2ndtimearound said: How do you phish a 2FA secret key? That's not something you would phish without SOMEONE noticing. It happened before with Gatehub btw (there are some threads here as well) - but I doubt this is the case this time. Previously it was people that search for Gatehub through Google (e.g. if they are at work and the url isn't stored when typing) - the first search hit was a Google ad that was saying it's Gatehub (but the link actually was pointing to Getahub which was exact copy of Gatehub and as soon as you type in your 2fa code they use it to log in to the original site) Link to post Share on other sites
Hero_Member 120 Posted June 4, 2019 Share Posted June 4, 2019 (edited) 6 minutes ago, BAX said: Its gatehub.net And the thefts didn't need to bypass 2FA because most likely they got the secret keys somehow. All the victims never got emails that someone is logging from different IP. If all the victims here are imported wallets from RippleTrade, the problem might be coming from RippleTrade not Gatehub!!! Could guys share if your stolen wallets were imported from RippleTrade? A lot of wallets were imported, but I believe not all (account created in 2017) Mostly the imported wallets have bigger amounts of XRP.. Edited June 4, 2019 by Hero_Member Link to post Share on other sites
2ndtimearound 6,965 Posted June 4, 2019 Share Posted June 4, 2019 10 minutes ago, jlripple said: Exit scam maybe unlikely cos Chris and Greg are shareholders? Why would they do that Yes it's unlikely but kept as a possibility. Having said that, how can it be that gatehub.net are saying "you got hacked, sorry for your loss" before an investigation has taken place? Have they no responsibilities here? Link to post Share on other sites
2ndtimearound 6,965 Posted June 4, 2019 Share Posted June 4, 2019 8 minutes ago, iLeeT said: It happened before with Gatehub btw (there are some threads here as well) - but I doubt this is the case this time. Previously it was people that search for Gatehub through Google (e.g. if they are at work and the url isn't stored when typing) - the first search hit was a Google ad that was saying it's Gatehub (but the link actually was pointing to Getahub which was exact copy of Gatehub and as soon as you type in your 2fa code they use it to log in to the original site) Ah I see - they grab the code within the 30 second window and login? Link to post Share on other sites
iLeeT 2,538 Posted June 4, 2019 Share Posted June 4, 2019 Just now, 2ndtimearound said: Ah I see - they grab the code within the 30 second window and login? Yup, they get your email, pw credentials, then as soon as you type in your 2fa code they use that to login. Link to post Share on other sites
jlripple 92 Posted June 4, 2019 Share Posted June 4, 2019 3 minutes ago, 2ndtimearound said: Yes it's unlikely but kept as a possibility. Having said that, how can it be that gatehub.net are saying "you got hacked, sorry for your loss" before an investigation has taken place? Have they no responsibilities here? Then basically we're screwed 2x Once for migrating to gatehub another exit scam Link to post Share on other sites
BAX 514 Posted June 4, 2019 Share Posted June 4, 2019 (edited) Do we know if they stole other assets beside XRP, I see that Gatehub have also BTC,BCH,ETH,ETC,REP and Dash? The other assets are worth total $17 mil of today prices. https://gatehub.net/stats Edited June 4, 2019 by BAX Link to post Share on other sites
jlripple 92 Posted June 4, 2019 Share Posted June 4, 2019 2 minutes ago, BAX said: Do we know if they stole other assets beside XRP, I see that Gatehub have also BTC,BCH,ETH,ETC,REP and Dash? Mine only xrp eth untouched but cos my eth is small Link to post Share on other sites
Borry 56 Posted June 4, 2019 Share Posted June 4, 2019 (edited) One thing is noteworthy about GH. Under "show secret key" you can simply see / get the ripple secret key. So, yes its stored somewhere (encrypted I hope?) But its definitely going via GHs website. Maybe the hackers found a way to retrieve this information. Anyway, this should be changed or at least removed (or only sent to the confirmed mail address). Edited June 4, 2019 by Borry panmores and horax12 1 1 Link to post Share on other sites
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now