Hello IOTA Forum

Call to action: let's catch the thief

https://forum.helloiota.com/Topic9284.aspx

By Winston - 21 Jan 2018

Coordinate your home law enforcement's efforts:
https://forum.helloiota.com/11980/Catch-the-thief-Police-and-Law-Enforcement-coordination


iotawalletloss.claims
Ongoing compiled list of stolen addresses: https://docs.google.com/spreadsheets/d/1IOpYdi8x9R0ivpC2Fl75N9iVDXo82py0yybC9nsxV-I/edit?usp=sharing to th



Updated List of Addresses: January 30
https://forum.helloiota.com/10846/Updated-List-of-Stolen-Addresses
(Addresses from page 13 to 16 of this thread)



Update January 25:
David in an interview:

"I completely sympathize with the people that have lost their funds. We are doing everything we can in order to gather information to track down whoever this scumbag is, but of course, that is not easy, and we’ve seen before that it is borderline impossible.

But, if we are able to dig up any kind of information that will lead to something, we will, of course, hand that over to the police and assist with any kind of investigation that will happen in order to try to help these poor people that have lost their funds.
...
What we’re doing right now is gathering all the intel we can, we’re looking through all of the different leads that we have. In such situations, the community starts doing their own investigations, become the detectives out looking for clues–looking for IP addresses, seeing if this person has been in the community for a long time, if there is any correlation between these things.

We are trying to get an overview because it’s all very chaotic, and this is still ongoing, but that’s pretty much all we can do. All we can do is look through all of the information that is available to us, and of course report it to the registered domains, see if we can find some IP addresses."

Source: https://www.financemagnates.com/cryptocurrency/news/iota-founder-stolen-funds-lots-people-will-screw/ 

January 25:
Dom Tweet:

"We have actually already started filing a police report (the IOTA Foundation on behalf of the users) and are working on a bigger update blog post with some of the actions we're taking."
Source: https://twitter.com/DomSchiener/status/955134744034971648

-------------------------
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.

Here's a spreadsheet that's some community members are updating with information: https://docs.google.com/spreadsheets/d/1IOpYdi8x9R0ivpC2Fl75N9iVDXo82py0yybC9nsxV-I/edit?usp=sharing

And here's another website where information is being collected: https://www.iotawalletloss.claims/


-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and deleted their Reddit account: https://www.reddit.com/user/norbertvdberg/ 
and deleted github: https://github.com/norbertvdberg

btw- You can obtain a copy of the seed generation website from the internet archive here: https://web.archive.org/web/*/iotaseed.io Should be useful for any legal pursuits.
On that archive site at the bottom there are two donation addresses, one which is a bitcoin address. I'm not sure if they are this thieves addresses or the github author they are linking to. There may be more addresses that changed on different snapshots of the website in the archive or possibly other useful data.
The bitcoin and iota donation addresses that were listed on ioaseed.io on that last website snapshot on January 3 2018:
BITCOIN: 1BXaRLe4LMfYjH4vUSJxCy1eEBDxJqeHpc

IOTA: HCBLOBZQXDUWXKFJJXNKWQGSAFFNRY9NBBJGYAANWFIIJMGWZWUFVFIWYPIAFYVWBIEFBV9CQRDOOUU99LWEXAHWEW


Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(Thanks to Alexa, all addresses up to the bottom of page 12 have been included here. If someone can compile the addresses after that page, that list will be added here)

UPDATE (January 24) POSTED BY ALEXA:
Here's an update with new addresses from where you stopped at page 8 to the bottom of page 12.
I couldn't get to all of them, so someone else will have to take over from page 13, if they want more addresses on the list.
It would really be a lot easier it if people could stop posting empty addresses (as there's no use in getting those blacklisted) and instead track the transactions to the address that currently holds the balance. If that one is one the list already: don't post it again.

Listed as empty before, but has balance:
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9 133 Mi
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQW 461.04 Mi
________________________________________________________________________________________________________________
New with balance:
YLNHDBKQRQPHQZMF9ZOMZYQWQDYOFWXWJJENBLNJSRDPTIYMSZHMCYBKKQXEDW9APLMGHUEWRNUMS9OKD 900.02 Mi
KLG9ENXTJSGFXVGWDUIVIFI9FEOIYWHCLCRHHHUILGBQNEGTTBVBYCOPDZXGPAMQFNTGVYWAXXDKWORZ9 900.02 Mi
UZSDQHCJJQOMMCMGZIQLUYFBRTRSBTFNDVEDTIQDAH9RZFWPYTMDOYFJZPYXBKGYKNQQVJQGLLBNTLMQD 437.33 Mi
IJYISY9VXNKAKZJOPECRN9AXMXOYZMMEEDGJAQZZSPZIDDYOAHFXINNNUSWFXYS9UKWCQFJJOOSFZQQWX 875 Mi
HSGYF99IECBGVMOAKHOPVY9HCEWDNBXUTYZOJOTDRKMGAWM9GHWPVHDYNEIFXAP99JTKSBFBJEQLKRUSA 875 Mi
GEAREGFBVZHEQWWWCFZZYWXUJDFWWCQDNDFHSIZ9R9YKNIVHCEBREFKVHVE9MHZVFJC9QUPVARAYNFROA 449.27 Mi
NVPICEIEILQRJMOOHHVTBDLMSZTDIWYVYU9YGOGSAKLFTFCMJEMXBTFRFYWZQFXVKRVNGYOJASMDEQSKA 449.27 Mi
SQPZWLNF9DPKOIODYIHZW9SKWZWMUOHGVRKDKGVSUVOQNONNHGCGZCRBARGSPJZMJBB9NUPWBKIPSDOCC 132.75
SOY9WIIFUDBE9EITMOZZLXQYOUZRLKOMQZZOIURITCNHMTNYJLLUOCRRLBTXPTM9ZOLENVUEALJJXOOOX 132.75
XRJC9SBOVLCUUYLVJDGRRGKBPWIXEEMGOSLHNS9GBEDNGMQSEFYQEDDQIFOSKBAHCSPJTARDATVAFQUCY 2.6 Gi
UTPHDFSAOVPSZUVKIXWYMYTCKLJXZFEYKKQKLYBIMUOYNDOJFOHZEYFHZPDAYKJVFLURJHGWIUN9XSPVW 2.6 Gi
CRRAFWYRQ99SE9OYHZKIHKPDVGXKSSECOBZT9QRNLSSOAWULGPRXKHWHWGXJVUMGGXZQIXHTMEYKUN9PZ 23.23
ZLXHODYKFAWRGYGRYBBIMLNXLVYHRKPLTYQXYTWTHYYCTWJRGTZEWECPBINVRXCVXAKMDKLETZXLAFN9Y 2.48 Gi
ARFWJXIEMHZZBPDPNKCNZXOPEHFSICNDIXII9WAHW9KCEBRFPMZXNQ9RFASQGAUPDVKSYYJPGAZ9WABKA 199.5 Mi
ZLL9NIMGCWOFKXFWCXZMCASDIRNXHNJPXCXFKVHNWDFUYXUOXURGFOLQYCFZDCYSVDPSPHBJYNBOKIGAY 99.75 Mi
QAPBRALWDFFFZZBL9HTXVEEFATQUMZHPOXPSP9GTUZCPUL9NDDPHFNQXKTAXBLH9JPQVVPQGNPXICNWYD 99.75 Mi
TUQTHXOSHOQVTEIVEUHINYFDVPFQYRGKTDVADKY9IMIKYYTXJVJOPWUW9TIJULNCJZLZQWAFHCMWTVMW9 1.54 Gi
BZNVVFPPHIKTKLAMOCUAKTIOIGNEPZECDH9KSMPLKNIBIARGKVYPLQQEAGJTVDONNURMFFQYSBLUEBXWW 1.54 Gi
YONLPTJKJMONCXNNMTAQDUDTNCUBJPENQUKFADPMYNOFXWGUPUTEBXBVVDOGTEKSSSCZDWNYKGTPDMTSD 8.67 Gi
JQMGWWJYI9UNIRRTWGDIYCDNSPYPKFXHIYDXBOPXXGBHVXTBCUTXOM9ESNEOYIFGJYYXIGSSWGLYJYLSA 7.61 Gi
CE9XUYX9KSLEKFKKSMW9XRBMGLBJ9PRCMDGNV9GXZEKZQQEBJQEMXVCFTNOHZEZPSUZYUIDLTDNTDHIYA 162.12 Mi
9SKDUHUFCIRZSMJQKLAUC9AISRJWNCYMXTUSHBBZJKMTOBDN9GQIUGDX9SCDXGB9GNSAPTRMYLNHAKURX 162.12 Mi
UCMCYTMEKKUFQBKTFDHSVZWFGPAOXISIALVOZLUODQGQJOBHBPLACPR9NNJWQMSCBWHKEGUFOBJHETY9X 4.15 Gi
CTORMCUAAMTBPK9XPSQEHJPARDRA9XTPUWC9EEARSWMZNTYAWXGLEVXVKQDXKBHARUFZEKBGSVKFJYHMZ 2.75 Gi
KXUEFCAA9OLOPJXFBIN9YPFSDIWGCPPUQVJ9ACNADWUWSEYXWBDYQNHUYDHYJGZGFEPDNYGRHSD9UKFJD 11.4 Gi
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQW 461.04 Mi
ZUPLQWPGXGTWEFAXGXPYGCUFDDTJQTYLRNWUDNGYAONXPHFRJFYLMGLSCFOQKOPOHPIFQZJGCFYDWPIBD 3.21 Gi
F9FPU9DMTZEIG9HQVYQHUWXULRUHFYFS9ZHIOFGKGCJJXLDLMYCLXUVXFNVCJQBNVLYVTHZNEXBBFGUQB 721.04 Mi
SWHLVQBTESLTGQIOSKMCEJMAOEEORWSQSNIHHENRAHKCBDBWRGTTUFFRHMJQVLTJTJOYWBSHJPYFBFZUY 721.04 Mi
DVNCCLRSERRMRVSQFCBKYAEFHKOZSUGTVXUMQKKLUPMSBZUEPCGTBQBTLWXHAMZALZONVJJXJSENJIBBX 308.34 Mi
IVIFATZRJUWBDLTYLQHCNMCEGFGBZN99SAAVRDUVYTAAPLYLEGZPBCFFVAJXOGSYILSIOXWIENCCTFTZY 308.34 Mi
BESICQSDBXQEBCIZMKOFWOUOC9IJJDUR9JC9LJJKPRHFRGUAVJTKYJSG9FFATVX9KUIYOQPBHDT9XIFOD 4.44 Gi
LCDZEY9MGCUCB9PEYTWMVMZSXQVFMUZCDQHWBRVZQKYXXQORANTYZYDCCEEOWJGGOQIEXLQGWLGMBHRYX 11.64 Gi
XZ9OMFCMAPTMAUHPBFFNKSCXBD9TOTTIAUJRBRUNSJVDVRBQROCFOMHISYFHXNCDXYNIXFIIUAMFIMAKY 12.01 Gi
LCSPIPXZLJVNT9XUOEHEMXJVOFXOETELXTCNABPPODQPMYYRSDNKUTF9SEL9QLPSIXO9QAVPWOGHEICSD 7.37 Gi
ARBDBWY9DGEWXCCFWSXISLVOIPGR9AMVAHSZRXTKMMCEOT9BJACSVEKAKP9QIBZBEFHBVL9BOPABWDCUZ 7.27 Gi
HGKLYH9VELSHTUV9TFUJLZ9OE9TDUELKPYUAE9IPILFBOKQR9NLRWPUBXPINZGCPUGWOHRZFFXGEPIHFY 4.04 Gi
NNYOMYMLRYNOVLJBPHIIIQDTQHFXIVMTOYPTCHFIYUGBSCCUWBZYZYDVNZQMUZLIRNGGQNYPCBZNAPDQB 1.54 Gi
BLPVFPHBWJOFBEXNOCOWWCCENBVNSVPMZEWKEBWNQJZKNM9JJPATDLOYUOVSJAGJOHKZMLCUMJKMOHWVX 268.11 Mi
J9SICTLXMNWXBT9BKLVPFCJVJKGQCHVAHIPX9URBFVDFE9LNZNWQVRCAKSTHKFUGUWDXUOW9KNRTQKINB 152.2 Mi
K9MWGM9QYZHEAAMPYINRAEKVMNCWEKLZQYWNRTHQJUHJIMZGZPILGOJJNMLSQUDFSTDXHKNXBNHUSKHUD 1.15 Gi
PQJYSELQJTEEYCXFOYCTWOMBC9HDZBJMVVHOGGYEAPCGSAOYEDEZHEYEPFDBYCDXJAZ9DNVIPHIJWTY99 4.6 Gi
9WWDWLGC9MVAAQKANMHQSXHRXAGCPHSMPRPEZP9EOVKUJLKYCHPPFSGRIPXKHVNEWBIFLPWUG9JRUIZSW 1 Gi
BXEEYUTTPFZBSUHEXDHGERFP9OFOIOKJGCCFFLOZJOG9NDDEFWBJUNWTVW9YXZNBRYRBEAALEXLYOPNQD 1 Gi
ESXIEZHHLEYZJLXBWRLYAJECSHBUMXGZMBINNAWNPLIFRIFGNDPHZKJOACZNEXRKQBKKHBMLDKLWWTQYD 58.5 Mi
HMJGVWELDDZDEGVSTOPZ9SUEFMZCYOBRRFIZDNERCELDDUFIDIAXTTWPGUFGQVDAWGJDGSKSJVPXQWUJB 249.23 Mi
CGYTGBKLOJUZWVDXCKKZKDMSDVTEYDFGEDTWTMPMFJBRQPCUQSIACCXBDFZMBELYKQFTWYLVOPSQSJSEX 127 i
MV9HMDKLIQDEYEZWTYZVOLDYI9LPOMHKTZOEKEUKTQONFO9NZZOJYPCIAZKOBZIPQFQUQXVQJCEPVEPKD 4.84 Gi
T9PILZIWPQJUIYLSAAXHIYJAFCAYNKBILPKGPSZBXJVIMEDAPJGOSAUBCFQ9GKQDGBFNCHGZMIFNSXPBA 2.5 Gi
ZGRJDIIZXIBDZYWAKHZDGFQKFAADXOTWEVNXTBTVR9COAPGGEFLFZJWMISDWDT9LILYYYLZSPILSBXSFD 2.5 Gi
KRDTGTERZCIXCCAE9ERSLFD9UWIYSKKXALVUTDVAOGZLNOOTKVHRWWTNRPFPTWSQMRCYR9HGMCSATQUPY 9.49 Gi
WDLLKDTZTOFGQRTBUSTZOSZQYSUEBFQGOVFLHTTRSTZTRXDTTKRVG9I9YUE9VTUIE9NRWGSLTHWIUTPRX 9.1 Gi
FKBGLDFVBCBTQIX9QXKMDSPKWXO9FNATQWZHGAFNMNJVSYRKM9QSSEQYSEYEXQHQFSGVOSJTFQGNAOPDC 520.98 Mi
SXUMDYWTFWCUYEEOQGUXUP9CQA9NGUZQDTJBJCOSOKYRRDIFMLPEIBBQD99EZCBVQHPHVJA9ACTVBXGOZ 78.2 Mi
FPIBCILPJFRZAQRTSKNOVONZIKPIQEHQQIGL9MKYEDFAJXXOWNMVACKQDSFLCREYP9EYJJKG9BYIRLAUW 12.07 Gi
QUYCDCGDQQJQBXBYIGDLQFQQEYSNU9EALXPFMTUU9BLFAHETMQMLLINDMHEAFSMXRR9VGEVWVNFEHAHJD 3.18 Gi
YWYYOXSTN99BUCQGXLITLSABX9QUCWSCTZEVCKSDJLTGLHZIHGPGLEVWUAQIZUUURHZFQBZJYBWDJABDC 18.62 Gi
SHQGRZTMSELZSUVHWWZQGSDVWXOAQ9YWYWEDQSMPNXMUTASFSZWJDKDZXNENJJHHUSHPKWBTBQJIJQNVD 419.01 Mi
RYSSOMRMNCG9KRAUEGPURNWHPHBPKKLG9OWZNWXGLBCIWNECLA9WYSKYXHBJKSPLHXDQ9NMVORDCA99DA 4.34 Gi
________________________________________________________________________________________________________________
Now empty:
PZQRE9QMRPQZ9SMZRAEDGXFDQADBNMBUVHJPEOSECLKDCNETUYQMMBLLPPKCNBBWWLFXYKOUHEK9ZE9TDKXVQGMNTY
SGRLFSBORTTDTSNIQZIQPYGXRQSYVCPZWCH9ERPLRFHVMWRTIGNEIBWGUYRAGHHADSDNTMBOCE9RHNALCORRNDNOSD
XTWX9FDSWOCOJOKIJANSZUUBJLQVFXCSEMHTHHN9SBGEINJZRULXLGBFWRSBFKCNCCNZ9HAMY9CWYQLDBYISIJGYUY
KQAHUBAXMMFSPEDVMWNPULRNKQOVX9FEIYVXLLLHRPNGPWBQQECZXDL9CMVWTJOJGBXNQZKRYTBUILSHZLUGXUMTZZ
JQTKULYLUWAWOPIURRGVGOQAYVUHPSMAUGLIRQGUGUW9NZPCSREAKXUPCEYPIUHPVJEXACXJDYAEDJRVA
ILFHRYIJPWQ9HGCKRAOXEECZVKBPVKXDNTCKOOO9SITAGLZR9ASDTCMV9MEO9TGTRHONKEJIWEL9GAEAWFPWAJEOQW
BTRKYJCVBSFVMEJL9KSSJRTDQSAYCS9GJBLBKVEXWXNBFEDBEWQAITDPZCGDJQ9HHE9FDCIJNQAQB9RMWD9FK9QUMZ
PZQRE9QMRPQZ9SMZRAEDGXFDQADBNMBUVHJPEOSECLKDCNETUYQMMBLLPPKCNBBWWLFXYKOUHEK9ZE9TDKXVQGMNTY
ESWVKJWXTGIWBOSEREELRFWCFKZDEIOXJGGQGBUOJUBAGVFGARFDFZRPPIYVSINMVMHURNXUBSYAXYV9Y
VOC9TWBRQTEKAZOWCFDVAVJ9ILCLRWTGNWTHGKSNBHWCDNFLN9WDQCILQMXQNARCSISZDKWRRCMKPRK99NRNGGYYXD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
YEWQRBJMLTDKNUFAOEBPY9CHINLWAYQWWSJHNY9BBPMCBEOHLYZIACTGTHZUDTAQMRWQFK9RKJ9TSRJIANTQGCOKBZ
KQAHUBAXMMFSPEDVMWNPULRNKQOVX9FEIYVXLLLHRPNGPWBQQECZXDL9CMVWTJOJGBXNQZKRYTBUILSHZLUGXUMTZZ
DJHLLQBYDYTKGVOJRL9DCKYWVLVWAGAQSS9DQQMHVTSCDSYGHRXRXKPOELQZKNQENEKWCKMLHIPNK9XZW9EP9CWGUB
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZV
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA
LQ9STJCRQXTTIJAKZHRNGVBKYZW9VTKHSHQF9LFSII9UYOBDLSWYSUVXDZRGKCPDMJYFJDPXDEDXUAECAOBFKFKITB
YTJAXHWHZILUBVDKTPCGPNQJGJDBDDRPDVJKMAMQEVXSITKURZDAFZCFUT9WI9CHVBEFVMHULANFOMIFY
GZ9YXGWVZQHYRAEORBSONYWNSYGWBLCO9BUNTMEWKHKCDVTZLOOHJ9YSQTIQORFSAFUNCDKRKWHTKWNGYOC9NWEGID
RUPPRPDPAIRORAITFD9HVOGBMKBLMMZIHGOYAEZLMY99EPIJEEQNGOIWGDKIAIUYKBWMVNRYEUFLJGNLDGPUQHDHTB
VXKXKPAMRPKJKBJFEGEXSXVRPJLBMUBPUIJQLI9FGWAUPHJTGBCMPVRI9AOPOOQLNSYEGZHYOCOGGRSBCNIVFDGAZD
HPHQTRANKNABYOWJLS9OTAMRABRBQAAQA9LMIKVAZBNXUMAATDFPPWWJGGVQAOQJZJ9OAJHEQU9XPERPXJCVXIEQRW
UABWCOAOUM9MKDZPXSGEEEKTO9RUSROSPJWMPXZQBHWMRI9BZQKPRTTUPGOWGHUKQBRNWDHFOGLRUWTOWVRDLMYMOY
AFUKOEVPJLMVCSEAQIFZDXARCS9CEBGAHNWMJZQHQP9TLCLKUCFUSQZOZFGZKSLZSO9KNSPRKUOVMRVSXFVIETDGQW
GLQUHWHUQQRTJLTGWFWNTROJGUDVWDUMOMGMQKXUKEAVVURRQCUHIJMSSSBEKFBBPXQ9HZEIBVDEVBT9ZQZPWISPBW
XXRQ9DBYHCGEPOOAIEBEBVSSVTYJEJBEOXWDNNFCPDBYKZFGG9KPBEWVGCUUDZNBTAVXGOOHNSRJUGDOWITQOGEBZ9
YGCCEMWOJGEXFKHCWNNIGMFPIZDOYJYIJAOUAFGJVQUVVVODFOSFXYPWPI9UJNGQZXSXJVUPQQUKQFEWDX9YUZHCWD
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
JBEFKJZAMUZUYZOWKMSX9BKAYMZPCWWKRHQDGIJHHVL9NXARTFYRVJJUVQNHQGHM99BEPULISPCVYBHXCFZTRDL9EW
GHWQCDMSIGFISWBRZDLZLLFPYLPNKESLXHMWIMW9ZHOVSIOOCSY9YQNATAE9FLXEIJPATCXDBIINSRWECYNAUAUIP9
ALCBFBQ9BQYDSSWQHJLKFENDITLBYFXHMBSWFYVAZWGYJKEZGSOZJXE9BXKQZNOHVSRNQGUMDLIGGSIL9HTFSEIGCA
ERZFDGJYXTGUJ9SE99AFOFAXRSVFXVNKNBNIOLAUHRSYRALCSSBJOJOVB9BPQBYQTBRVNTDBZIAQSWYUXWGBLYCSHY
HMCTIZTDONLZUAAMEBIFHNLXQDFENUZZ9RCHOI9SAUEWSOTCYIGIMHXPWM9OVTNOERUZPSRJ9LDYN9RFA
BXZIGGDVGMVOWLSSISNWSCRAANCDHXXDYGTPYLVFVBAVGWJJZCIGP9VMBWDVTCRWBLEZHDFUPRRIKMAWYBESFKPNCZ
9UOWNHHYPEDTHXCBEKGLGORURZYJFOUZKZYMVBNRFYNWJZFJOGNB9UIPFNLWANVCSNW9GLJXENGT9LTOBCMLPBEEUA
MMAJPSFJCDFJIPFUYGYEPSLWUGQVP9SMTAGGQRWYZ9VHQPVZODAGYTMFKIPKPOLLYJONJROB9HP9HUBHDQNFXKJIL9
RFZQWLQRGMAIOTZSDOKGGQXLOHGPMWQPVLTLMNKAVODIERHRQIFDLKXXAGVHUUWU9FLYTHEALEWWMHBOWSHAMFWAUD
ULXCGRVWGFNUFXSRJRGKVJJUXYBWNTIORQAMQJQGVMDQYVOOOC9FUVHHVJIPBQ9ZYKLEOK9WFM9KBMMPXCANVZMXHY


=============================
OLD BELOW
=============================
Addresses as of January 23:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(Thanks to Alexa, all addresses up to the bottom of page 12 have been included here. If someone can compile the addresses after that page, that list will be added here)

4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(Thanks to Alexa, all addresses up to the bottom of page 12 have been included here. If someone can compile the addresses after that page, that list will be added here)

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD
AEYTTPPXPKVREJ9LGR9NU9KXCOFYDTJKWMNIWJTJBSRFFKDDSELFRAYKDHJIPWHUUYHWSQAEDUAJAQPTDZNARLX9TB

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(Thanks to Alexa, all addresses up to the bottom of page 12 have been included here. If someone can compile the addresses after that page, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.
By rajivshah - 21 Jan 2018

I sent an email to namecheap (the registrar), let’s see if we can get them to take the site down
By CryptoHamster - 21 Jan 2018

Here's another address he sent funds to (not mine): GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD  
By Winston - 21 Jan 2018

Alexa - 21 Jan 2018
Here's another address he sent funds to (not mine): GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD  

@Alexa
Thank you, Alexa. This address has been added to the list.
By proto - 21 Jan 2018

SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
This was reported as a thief address on Telegram January 18th around 8-9 pm PST

KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
This one was reported on Telegram shortly after the first one

By PickleNick - 21 Jan 2018

Mine was sent to:

https://iotasear.ch/address/OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUX

My stolen IOTAs: 551.4

https://iotasear.ch/transaction/NDRXQQDLTVMGHVFLGPIQEOYJJLGKCJFXKMUIWXIJLFOLJANSMIYBVKNUP9CFCUMIDROLPNKWGVIE99999



By Lazyrudi - 21 Jan 2018

Hi everybody, my 10GI have been sent to:
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
It is ok to put the reception-address on a blacklist, but I am more interested in the action IOTA is going to take to get the money back in my wallet. I have used the IOTA Seed-Generator (not a third party product) assuming that it is a internal and save system like the PIN / TAN generator from my Bank I have to rely on. 
Regard Rudi
By CryptoHamster - 21 Jan 2018

Winston - 21 Jan 2018
Alexa - 21 Jan 2018
Here's another address he sent funds to (not mine): GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD  

@Alexa
Thank you, Alexa. This address has been added to the list.

Thanks Winston!
Here's three more (picked from this thread: https://forum.helloiota.com/9019/HELP-my-IOTA-is-just-about-being-stolen) 
1. ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

2. BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

3. UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
By RFID - 21 Jan 2018

Thanks Winston,

I had 1.1Gi stolen that ended up at this address
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWW

Here is the TX if that is of any help
HWEPSMUGIOBBDKQ9YRQDNSLAFJELV9MIZRROEZTXYWEXBIPDAQGCGGO9CEECIULDDWNREGKVPAPI99999
By maxv85 - 21 Jan 2018

My 1.89Gi have been sent to

RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9

and

HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC

Thanks Winston
By fvantom - 21 Jan 2018

This should be automated. Via the tangle it should be possible to automatically tag and follow the progress of the stolen funds. Thus creating a list of addresses they are currently on based on a list of initial addresses they were taken from.

If I find the time in the next few days I will try to cook something up I can put online.

I encourage other developers to also implement this idea. Is there anyone interested in teaming up for this?
By FrankB - 21 Jan 2018

4.7 Gi
https://thetangle.org/bundle/9LKIEFANWKNDJFJIHVZHRZBJRQHIQGGBXJJHFEPHGHDEKKNT9GXKLQIJBXKGBRXQUVUHGPQFPDJYLHJSA
I tried to post but got a Spam notification. I tried to mention that I am on Reddit as HowAboutFrank
By Lazyrudi - 21 Jan 2018

Sorry when I disagree with @Ralf, but when opening an IOTA Wallet the IOTA-System (not a third party) is offering the opportunity, instead of typing 81 character in a specific order by yourself, to use an (from my point of view) approved, save and not traced random Seed-Generator. Therefore it is my responsibility to keep the generated seed in a save place, but it is also IOTAs responsibility to avoid misuse the generated seed.

From what I can see (using IOTAsear.ch) is that a lot of stolen coins are still at the thiefs-addresses, giving IOTA a chance to get the money back on an official way but I also expect that IOTA is bringing/giving back the money which the thiefs already transferred out of the IOTA environment.
By ezeee - 21 Jan 2018

Absolutely agree with Lazyrudi. Sure, i lost 56.7 gIOTA two days ago.. :-(

Here's the transaction:
https://thetangle.org/transaction/ZVPEVADAUMVFLENBFKKPMC9QPFXGJMLVMHQCQCS9UNS9ILQ9PWMLCQIOHCRIFMISEAIDNXQSESJNZ9999

The address my IOTAs sent to:
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA

Does anybody have another ideo how to get back my IOTAS??

Thanks, Thorsten
By Lazyrudi - 21 Jan 2018

By OpenMedia - 21 Jan 2018

Thanks for the heads up and your effort!
My 5 Gi were stolen and sent to FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA

By CryptoHamster - 21 Jan 2018

proto - 21 Jan 2018
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
This was reported as a thief address on Telegram January 18th around 8-9 pm PST

KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
This one was reported on Telegram shortly after the first one


@Winston @rajivshah
This second address' balance has been emptied and funds have been moved a few times. Everything ends up as the only Input in this bundle with 22 Outputs: 
https://thetangle.org/bundle/ULSVTFCLCK9IZOBJJIZQBUXUCFLF99RHBOLPWEEQZWFJWVTUGEEF9QBVORPKADJG9BLSKWFHAJYCQEFNW
From here, the last Output address always leads to a new bundle with again 22 Outputs...
To me it looks like what exchanges usually do, this guy is trying to move fast. Can we somehow tell which exchange it is and who can we contact to get at least those addresses blacklisted, that still do hold stolen funds (all of the four in your first post still do!)? 
By CocoPhoenix - 21 Jan 2018

Thanks for all the help!!
My 3.7 Gi was stolen and sent to this address

RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
By Frank - 21 Jan 2018

Mine was sent to:
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
4.512742493 Gi
There are not so many exchanges who have IOTA listed.

By FrankB - 21 Jan 2018

4.7 Gi
(3rd attempt to post). Earlier got messages of spam. I will remove URL''s
9LKIEFANWKNDJFJIHVZHRZBJRQHIQGGBXJJHFEPHGHDEKKNT9GXKLQIJBXKGBRXQUVUHGPQFPDJYLHJSA
Thanks for this initiative!
By Batis - 21 Jan 2018

And All my Iota was sent to this address without any permission :

NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX

, unfortunately my wallet was hacked too ! 
Please help !
By fglogowski18 - 21 Jan 2018

Thanks for help! Let's get him!
My 133Mi was stolen and sent to this adress:
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
??????
By vikingvp3 - 21 Jan 2018

I think i am one the victims too but before that time
here is transaction hash
MKXSNAESMYTPWWKUXGLPTDYOPWAUYWMWGR9WMNZXREPAIKSCKWJDSERKTJQRBOHAPGLFZKOPMQEYZ9999
and here is the address but it seems empty !
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
Sad
By CryptoHamster - 21 Jan 2018

@Winston @rajivshah I've tracked every address posted here so far and I think that the following should be added to be blacklisted and/or at least monitored for further movement (all of them still holds  the funds): 

https://thetangle.org/address/OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUX
https://thetangle.org/address/BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEB
https://thetangle.org/address/MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWW
https://thetangle.org/address/RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBB
https://thetangle.org/address/HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZD
https://thetangle.org/address/NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZ
https://thetangle.org/address/AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9
( this one is showing outgoing pending transactions already to PGIKMASIPBHZBMCSRZYEOHJOVWZPCWCBUAXSDI9YMNMQARZH9JKFBBZKNTUFZBUCYYPEVSZAZBZWYHGJZXSXKFYBZB and  SWVWNFSSGRRXSJTNFUATWQTCDANOLHXDUESVL9OGVL9QKMOXKJPXQDVVLTVTBZOY9PZZKUEITFFNQBJWWKRPHZJNTX )

All the other addresses end up on either one of the addresses above, one of the four in the initial post or in one of those bundles that I believe to be leading to an exchange:
(( https://thetangle.org/bundle/ULSVTFCLCK9IZOBJJIZQBUXUCFLF99RHBOLPWEEQZWFJWVTUGEEF9QBVORPKADJG9BLSKWFHAJYCQEFNW https://thetangle.org/bundle/VPHQKLFXLHUBNHYVHEUPDBKHEGWALLOPCLTHWTYHBNQKSIHEXGJAPYSKHE9OYC9SXAEITTZ9BEZAKKZJW https://thetangle.org/bundle/CN9GZSHAHBBYXRNWJI9AHLZWFIPFLJ9WCSZEHPRYFGSQV9FDFNCTWHWLZCTKJZXGCRJYKRPIIUQUYIVL9 ))
By mohammadalietebari - 21 Jan 2018

my iotas is gone
unfortunately transaction is confirmed
please help me

here is the hash

SMAQHHFMHGMGBEKREFKRCTXRYCTYMGTSWMKCYHD9VDBQKYTYSZUP9KULHDWPMNSNLIQMDSAGVCYSA9999



and i think this is the destination address:

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDB
By SupDeDup - 21 Jan 2018

Mine also got stolen.. They were sent to: JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA

Stolen amount: 345.11 MIOTA
Current balance while writing this: 4.082515795 Gi

https://iotasear.ch/address/JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA

*** Update ***
And the 4 GIOTA just left the address..
By CryptoHamster - 21 Jan 2018

SupDeDup - 21 Jan 2018
Mine also got stolen.. They were sent to: JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA

Stolen amount: 345.11 MIOTA
Current balance while writing this: 4.082515795 Gi

https://iotasear.ch/address/JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA

This one has been transferred here: https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW
Current balance:151.29 Gi
@Winston  @rajivshah Should also definitely be blacklisted! 
By rezatalebi - 21 Jan 2018

my iotas are in pending situation for sending but this is not my request.
the address is:
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
hash:
KFQX9BIIHVPMLWBYGVXQPBNAMNOPKCZJDNMTEJKGKMZLDDUEYQHTSXFMFMACBXJNXLPDQAESJASHZ9999
TAG:
VJ
By CryptoHamster - 21 Jan 2018

rezatalebi - 21 Jan 2018
my iotas are in pending situation for sending but this is not my request.
the address is:
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
hash:
KFQX9BIIHVPMLWBYGVXQPBNAMNOPKCZJDNMTEJKGKMZLDDUEYQHTSXFMFMACBXJNXLPDQAESJASHZ9999
TAG:
VJ

@rezatalebi You still have a chance to race the thief and safe you funds! You have to be quick now, please follow instructions / get help in this thread:
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances 
By CryptoHamster - 21 Jan 2018

rezatalebi - 21 Jan 2018
my iotas are in pending situation for sending but this is not my request.
the address is:
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
hash:
KFQX9BIIHVPMLWBYGVXQPBNAMNOPKCZJDNMTEJKGKMZLDDUEYQHTSXFMFMACBXJNXLPDQAESJASHZ9999
TAG:
VJ

The address posted above leads to this one: 
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBCurrent balance: 235.65 Gi 
@Winston @rajivshah 
blacklist, please! 
By kraro - 21 Jan 2018

H
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi Winston,

this action is bringing back confidence to IOTA. My 298.6 MI are on the way to the thief. Bundle started Friday 19.01.2018 at 20:18. Bundle is not confirmed yet.
Is this a good sign? I hope so.

Hash:
DSTJYEJ9TXFVRRCEJFCAFDUABJCZGZMHYJCHYGAZIUUFDZEPFGEWNABHMAIRFPXOEZYUGSMKTNRPA9999
EE:
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD

Thanks
Kraro
By mrpmorris - 21 Jan 2018

Are you certain about this? I saw iotaseed.net stealing funds, but was iotaseed.io stealing them too
By VivaLaViv - 21 Jan 2018

I had 871.7 Mi stolen and sent to the following address. The money appears to still be sitting in that account along with about 50 Gi:
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
Hash: BHRPH9S9SWFEXYVDLZDZOHOVKJKXIV9IVBUGWCRWOT9INQ99EUDC9DV9LSPUXIHGQHRVHGC9QPFVZ9999

The day before my funds were stolen, a transaction was attempted to send all my money to:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA

That transaction is still pending, but the second attempt did go through. So all my Mi are gone.
By CryptoHamster - 21 Jan 2018

kraro - 21 Jan 2018
H
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi Winston,

this action is bringing back confidence to IOTA. My 298.6 MI are on the way to the thief. Bundle started Friday 19.01.2018 at 20:18. Bundle is not confirmed yet.
Is this a good sign? I hope so.

Hash:
DSTJYEJ9TXFVRRCEJFCAFDUABJCZGZMHYJCHYGAZIUUFDZEPFGEWNABHMAIRFPXOEZYUGSMKTNRPA9999
EE:
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD

Thanks
Kraro

@kraro You still have a chance to race the thief and safe you funds! You have to be quick now, please follow instructions / get help in this thread:
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances
By mdmrecords - 21 Jan 2018

here another hacker addresses:
https://iotasear.ch/address/WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
https://iotasear.ch/address/LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
https://iotasear.ch/address/JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
Fuck iotaseed.io !!!

for all affected users, use this howto to try getting your IOTAS back:
https://coinforum.de/topic/6388-iota/?do=findComment&comment=206453
By CryptoHamster - 21 Jan 2018

VivaLaViv - 21 Jan 2018
I had 871.7 Mi stolen and sent to the following address. The money appears to still be sitting in that account along with about 50 Gi:
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
Hash: BHRPH9S9SWFEXYVDLZDZOHOVKJKXIV9IVBUGWCRWOT9INQ99EUDC9DV9LSPUXIHGQHRVHGC9QPFVZ9999

The day before my funds were stolen, a transaction was attempted to send all my money to:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA

That transaction is still pending, but the second attempt did go through. So all my Mi are gone.

@Winston  @rajivshah
Blacklist please: https://thetangle.org/address/TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKC
Current balance: 18.59 Gi
( UXVZ9... is not relevant, destination address has already qualified for blacklist )
By CryptoHamster - 21 Jan 2018


@Winston @rajivshah 
Blacklist please:
https://thetangle.org/address/WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIA...is leading to apending transaction (108.38 Gi) to:
https://thetangle.org/address/XUHWG9TD9GWPGZZACR9KOITEGENYIPEJUFBRHJMLJSVDYIITD9EUYOXLEUSTCLLJOCPMMQZQPZVWZDUOY 

https://thetangle.org/address/LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZ

https://thetangle.org/address/JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSW

By CryptoHamster - 21 Jan 2018

kraro - 21 Jan 2018
H
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi Winston,

this action is bringing back confidence to IOTA. My 298.6 MI are on the way to the thief. Bundle started Friday 19.01.2018 at 20:18. Bundle is not confirmed yet.
Is this a good sign? I hope so.

Hash:
DSTJYEJ9TXFVRRCEJFCAFDUABJCZGZMHYJCHYGAZIUUFDZEPFGEWNABHMAIRFPXOEZYUGSMKTNRPA9999
EE:
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD

Thanks
Kraro

@Winston @rajivshah
Blacklist please:
https://thetangle.org/address/9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGC
(currently 7.15 Gi)

By Bear_OO_ - 21 Jan 2018

Sent to:
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB

Stolen amount: 743,743 M
By CryptoHamster - 21 Jan 2018

Bear_OO_ - 21 Jan 2018
Sent to:
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB

Stolen amount: 743,743 M

Thanks for reporting! Destination address has already been reported for blacklisting.

By stoleniota - 21 Jan 2018

Same here.
My 1.75 Gi have been send to that address:
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWW
By CryptoHamster - 21 Jan 2018

stoleniota - 21 Jan 2018

@Winston @rajivshah
Blacklist please:
https://thetangle.org/address/VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWW
By Andre - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi everybody, my 77.2GI have been sent to:
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
Hope we can do something.

I repeat what i have read before:
It is ok to put the reception-address on a blacklist, but I am more interested in the action IOTA is going to take to get the money back in my wallet.
I have used the IOTA Seed-Generator (not a third party product) assuming that
it is a internal and save system like the PIN / TAN generator from my Bank I have to rely on
By stoleniota - 21 Jan 2018


How do I blacklist it?
By stoleniota - 21 Jan 2018

@Alexa How do I blacklist it? Thanks in advance. 
By Flexe - 21 Jan 2018

Hey, thanks for your efforts in this case.

My 3.69 GIOTA were transferred to the Adress: 9MWXDLVYGWYJGS9WHXFDBALEFPWCXETQDXUAWFNOUJ9MGGYREJPDRWLKD9ECYFPIHDFTTAHFFABUMQYBXRJBYSTHZB

This address is now empty as the Amount was transferred further to the Adress:
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
Which holds at this time around 26.3 GIOTA.
By ghillz - 21 Jan 2018

Hi I had 1.595 GI stolen to the following adress


UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
By CryptoHamster - 21 Jan 2018

stoleniota - 21 Jan 2018
@Alexa How do I blacklist it? Thanks in advance. 

@stoleniota I think you did everything you could by just reporting it here. As Winston said: "We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency", I believe he or someone else who can is going to do that. 
By stoleniota - 21 Jan 2018

Question:
Using thetanle.org it says that the transaction has been confirmed. (Mine as well as with the thief's address)
But using the IOTA Wallet it still says "pending". Any chances I can get my funds back? 
By CryptoHamster - 21 Jan 2018

Flexe - 21 Jan 2018
Hey, thanks for your efforts in this case.

My 3.69 GIOTA were transferred to the Adress: 9MWXDLVYGWYJGS9WHXFDBALEFPWCXETQDXUAWFNOUJ9MGGYREJPDRWLKD9ECYFPIHDFTTAHFFABUMQYBXRJBYSTHZB

This address is now empty as the Amount was transferred further to the Adress:
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
Which holds at this time around 26.3 GIOTA.

@Winston @rajivshah
Blacklist please:
https://thetangle.org/address/QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJY
By Guggivaz - 21 Jan 2018

My 786 Mi got Stolen and send to this Adress:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA
Hash:
IBTHMYDXTGYMLBNLBJJVDNDBTWLWBEGWGH9HXWSJIPYCWVKSOYRSHGUFGNORFPJXAOSVSEABRYFM99999

then transferred to:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVD

last Hash:
RIFS9EBTHXQJCD9SFZXYZAATRSANAFGWPJKWVVFTJBUWRLF9N9YHCHTSNN9JQZGRCPURKAFIFLPHU9DJD

there are already 235.646145369 stolen Gi on this Adress
https://iotasear.ch/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB
By CryptoHamster - 21 Jan 2018

ghillz - 21 Jan 2018
Hi I had 1.595 GI stolen to the following adressUCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC

Thanks for reporting! This one leads to one of the bundles I've posted before, so nothing new here. 
By My - 21 Jan 2018

Hi my 1,65 Gi was stolen to this adress, the hacker tried for different adresses but it seems like they got confirmed to this adress.


https://iotasear.ch/address/XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW

By Andre - 21 Jan 2018

IOTA's stolen
77.3GI to
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW


By CryptoHamster - 21 Jan 2018

stoleniota - 21 Jan 2018
Question:
Using thetanle.org it says that the transaction has been confirmed. (Mine as well as with the thief's address)
But using the IOTA Wallet it still says "pending". Any chances I can get my funds back? 

@stoleniota I think it's too late. Your wallet might show incorrect information if your host node is out of sync.
If you need any help, this thread might be better for further advice: https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances 
By CryptoHamster - 21 Jan 2018

Guggivaz - 21 Jan 2018
My 786 Mi got Stolen and send to this Adress:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA
Hash:
IBTHMYDXTGYMLBNLBJJVDNDBTWLWBEGWGH9HXWSJIPYCWVKSOYRSHGUFGNORFPJXAOSVSEABRYFM99999

then transferred to:
UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVD

last Hash:
RIFS9EBTHXQJCD9SFZXYZAATRSANAFGWPJKWVVFTJBUWRLF9N9YHCHTSNN9JQZGRCPURKAFIFLPHU9DJD

there are already 235.646145369 stolen Gi on this Adress
https://iotasear.ch/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

Thanks for reporting! The destination address hat already been posted for blacklisting.
By FrankB - 21 Jan 2018

stoleniota - 21 Jan 2018
Question:
Using thetanle.org it says that the transaction has been confirmed. (Mine as well as with the thief's address)
But using the IOTA Wallet it still says "pending". Any chances I can get my funds back? 

I had the same. But I am afraid your wallet still needs to be updated completely. When mine was done, my balance was gone. Sorry....
By Chrholl - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi, My 1.4Gi were sent to this address:
https://thetangle.org/address/ITFUGOZTDADQVRPXFMQUIDZQOBKXSA9RFTQFJWKSUXDQYRIZMLGSZ9XTQWUEZNIREFNIFRBDHAVOJGKAY
By CryptoHamster - 21 Jan 2018

My - 21 Jan 2018
Hi my 1,65 Gi was stolen to this adress, the hacker tried for different adresses but it seems like they got confirmed to this adress.


https://iotasear.ch/address/XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW


Thanks for reporting! This is a new one! 
@Winston @rajivshah
Blacklist please:
https://thetangle.org/address/XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLD
By CryptoHamster - 21 Jan 2018

Chrholl - 21 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi, My 1.4Gi were sent to this address:
ITFUGOZTDADQVRPXFMQUIDZQOBKXSA9RFTQFJWKSUXDQYRIZMLGSZ9XTQWUEZNIREFNIFRBDHAVOJGKAYUJYIY9EKC

Thanks for reporting! This one leads to one of the bundles I've already posted.
By Chrholl - 21 Jan 2018

Alexa - 21 Jan 2018
Chrholl - 21 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi, My 1.4Gi were sent to this address:
ITFUGOZTDADQVRPXFMQUIDZQOBKXSA9RFTQFJWKSUXDQYRIZMLGSZ9XTQWUEZNIREFNIFRBDHAVOJGKAYUJYIY9EKC

Thanks for reporting! This one leads to one of the bundles I've already posted.

Ok I just edited before I saw your comment, probably the new address I posted is already known, all these addresses get confusing
By CryptoHamster - 21 Jan 2018

Chrholl - 21 Jan 2018
Alexa - 21 Jan 2018
Chrholl - 21 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi, My 1.4Gi were sent to this address:
ITFUGOZTDADQVRPXFMQUIDZQOBKXSA9RFTQFJWKSUXDQYRIZMLGSZ9XTQWUEZNIREFNIFRBDHAVOJGKAYUJYIY9EKC

Thanks for reporting! This one leads to one of the bundles I've already posted.

Ok I just edited before I saw your comment, probably the new address I posted is already known, all these addresses get confusing

It is known. :-)
Thanks for the effort though, it's kind of hard to keep track of what's new and what's not...
By Frank - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hello
Mine was sent to:
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
4.512742493 Gi
By Guggivaz - 21 Jan 2018


I found some Action from Norbert on forum.iota.org

https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915/3

https://forum.iota.org/u/norbert/summary
By CryptoHamster - 21 Jan 2018


@Guggivaz Can you please edit this and tag Winston so it's easier to find for him in this mess of posts?
By OpenMedia - 21 Jan 2018

Please also follow the developing topics here.

https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

They are all linked, but different people share information on different platforms.
By Immutable - 21 Jan 2018

Hello,

I also got my IOTA stolen.

Here's the transaction: https://thetangle.org/transaction/9LDNAMVKWZDAZMD9IRXOELFGOMH9PBDHUXU9C9UMMYNVKYUIOHWF9JXFMCO9XSYIRPSDQS9ATQAIZ9999

And the receiving address: https://thetangle.org/address/JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUW

The are already trying to move the IOTA. :/
By gotlivm - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

YNAAPXAIKNPISKRJDZSDXD9INRNICHUQMWEVPSTACFKNAABNCIYF9IVVQBPBYSJMMKVZDTTPJQLAA9999
https://thetangle.org/transaction/YNAAPXAIKNPISKRJDZSDXD9INRNICHUQMWEVPSTACFKNAABNCIYF9IVVQBPBYSJMMKVZDTTPJQLAA9999
By CryptoHamster - 21 Jan 2018


Thanks for posting! The address where they're trying to send the funds to has been reported already, but as your funds are currently still on this one, let's blacklist this one too @Winston @rajivshah
https://thetangle.org/address/JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUW
By CryptoHamster - 21 Jan 2018

gotlivm - 21 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

YNAAPXAIKNPISKRJDZSDXD9INRNICHUQMWEVPSTACFKNAABNCIYF9IVVQBPBYSJMMKVZDTTPJQLAA9999
https://thetangle.org/transaction/YNAAPXAIKNPISKRJDZSDXD9INRNICHUQMWEVPSTACFKNAABNCIYF9IVVQBPBYSJMMKVZDTTPJQLAA9999

Thank you for posting! The destination address of this transaction has already been posted for blacklisting.
By MisterBrot - 21 Jan 2018

Hello,

1) https://thetangle.org/address/FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMB

my 855 miota still there.



2) https://thetangle.org/address/EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCA

2,2 Gi that have been forwarded to

https://thetangle.org/address/ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWD (1,1 Gi)
and 
https://thetangle.org/address/HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9D (1,1 Gi)

Both still there!

3)  
https://thetangle.org/address/URZCVP9WOKTMWURHMXLGMRFXPMBMLAJCINERYYTIPUJBIRQCRIJZWNMPYQQVYVDMJPLJWIMVOQ9RBDJTD

50 Mi that have been forwarded to

https://thetangle.org/address/UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYB (25 Mi)
and
https://thetangle.org/address/VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9 (25 Mi)

Everything is still on those addresses! If only the IOTA team would do something, a lot could be restored, but they simply don't care!
By Mason - 21 Jan 2018

I have 6.43 GI stollen from my light wallet. the receiver address is:     KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB

 
By Mason - 21 Jan 2018

I have 6.43Gi stolen from my wallet sent to this address: KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB 
By Nigl23 - 21 Jan 2018

IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX

This is the adress of where my IOTA went. I can see the transaction on the explorer. This is not okay. Never gave permission for that. Is there a solution to solve this?


By Mason - 21 Jan 2018

I have 6.43 Gi stolen from my wallet, sent to this address:  
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB


By Nigl23 - 21 Jan 2018


Exactly what I was thinking... My amount is still on this address: IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX

7 minutes ago the asshole tried to send all of that to another address, still unconfirmed.
By OpenMedia - 21 Jan 2018

It is a major design flaw to use the seed, which is the private key, to login to your wallet without any protection, no password, nothing. It is another major design flaw that the wallet is unable to create a seed locally, so one is always required to use a 3rd party solution. If they would have put a bit more brain into it this all could have been avoided. And it did not happen the first time, and likely will happen again..
By CryptoHamster - 21 Jan 2018


Thanks for posting! This looks a bit different than all the others. Did they take your funds from three different seeds?
 
By Cheeg - 21 Jan 2018

I know it is my own fault and I hate myself very much now.

Nevertheless all my funds were stolen and send to those two addresses

PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZW

V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9Y

If there is anything we can do about it, please let me know.
By MisterBrot - 21 Jan 2018

@Alexa: 

No. But curiously the amounts are the exact same amounts I've transferred to my seed (I made 3 transactions from bitfinex using exact those amounts: 2,2 Gi, 855 Mi and 50 Mi).

OT: In December I tried to split my IOTA and tried to send some Mi to a 2nd seed. But that transaction is still pending TODAY, so it never happened. The amount I've tried to move in December is now gone as the rest is gone. This is something I blame the IOTA team for.
By Lazyrudi - 21 Jan 2018

no, it's not your fault. IOTA encouraged us to use their seed-generator placed in their own wallet generator system. It is IOTA duty to make it safe for the user.

By the way were is "Winston"?
What is IOTA doing right now??
By Mason - 21 Jan 2018

I have 6.4 Gi stolen sent to this account: KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB



By Jefferson - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Good morning, they downloaded my wallet on the desktop today -127,38Miotas,  this address: LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA

By sun_in_the_city - 21 Jan 2018

[Zitat]
[b]Winston - 21. Januar 2018[/ b]
Lassen Sie uns alle Opfer des jüngsten Diebstahls ermutigen, die Verfolgung von rechtlichen Schritten gegen den Dieb in Erwägung zu ziehen. Da diese Veranstaltung nicht in den Zuständigkeitsbereich der IOTA Foundation fällt, müssen die Nutzer entweder einzeln oder gemeinsam einen Rechtsstreit führen (oder zumindest eine gewisse Beteiligung der Strafverfolgungsbehörden). Es ist einfacher, wenn alle zusammen arbeiten.

Das mag im Moment entmutigend wirken. Um den Prozess für alle einfacher zu machen, nutzen wir die Kraft und Breite dieser Community, um so viele Details wie möglich über die Situation zu sammeln. Hoffentlich kann dies dazu beitragen, den Umfang des gestrigen Ereignisses aufzuklären, und auch mehr von uns ermutigen, sich mit möglichen Rechtsstreitigkeiten zu befassen. Es könnte ein langer Schuss sein, aber lasst uns wenigstens versuchen, gestohlene Gelder wiederzubekommen und sicherzustellen, dass Gerechtigkeit gedient hat.
-----------------------------------------
Derzeit bekannte Details der Situation:
Hier ist ein wunderbare Zusammenfassung der Situation, geschrieben von Ralf -https://medium.com/@ralf/what-hapsed-last-night-on-iota-b6157ade1e03
Am 19. Januar 2018 verloren einige IOTA-Nutzer ihr Geld an einen unbekannten Angreifer.
Die Ursache, die dies ermöglichte, waren Benutzer, die sich entschieden, sich auf Online-Generatoren zu verlassen, um ihre Seeds zu erstellen.
Nach dem, was ich gehört habe, haben viele Benutzer, die ihr Geld verloren haben, ihre Samen bei iotaseed.io erstellt (aus offensichtlichen Gründen nicht hier verlinkt). Die Chancen stehen gut, dass die Leute hinter dieser und möglicherweise anderen Samengeneratoren eine Weile gesessen haben und Haufen von Samen gesammelt haben, obwohl die tatsächliche Anzahl der betroffenen Benutzer mir nicht bekannt ist. Die Tatsache, dass iotaseed.io zum Zeitpunkt des Schreibens noch online ist, könnte darauf hindeuten, dass die Seite selbst kompromittiert wurde und nicht die Leute hinter dem Dienst, der den Angriff ausgeführt hat.

Altes Forum postet die bösartige Webseite: https://forum.iota.org/t/iotaseed-io-now-also-for-genera-ing-paper-wallets/3915
Dieser Beitrag wurde erstellt von username: norbert
Dies kann dieselbe Person sein, die ihr Konto von Quora gelöscht hat:https://www.quora.com/profile/Norbert-vd-Berg/log
und Reddit:https://www.reddit.com/user/norbertvdberg/
und github:https://github.com/norbertvdberg
Domänenname: IOTASEED.IO
Registrierungsdomänen-ID: D503300000042872196-LRMS-
Registrierungsstelle WHOIS-Server: whois.namecheap.com
Registrierungsstellen-URL: www.namecheap.com
Aktualisiert am: 2017-10-15T20: 31: 54Z
Erstellungsdatum: 2017-08-16T12 : 11: 37Z
Registry Ablaufdatum : 2018-08-16T12: 11: 37Z
Registrar Registrierung Ablaufdatum :
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Missbrauch Kontakt E-Mail:
Registrar Missbrauch Kontakt Telefon: +1.6613102107
Reseller:
Domain Status: clientTransferProhibitedhttps://icann.org/epp#clientTransferProbibistr
Name des Registrierten: WhoisGuard Protected
Registrant Organisation: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: nicht signierte
URL des ICANN Whois Ungenauigkeitsbeschwerdeformulars :https://www.icann.org/wicf/
>>> Letztes Update der WHOIS Datenbank: 2018-01-20T23: 12: 39Z <<<


Lassen Sie uns dem Austausch helfen, die IOTA-Adressen des Diebes, die derzeit die gestohlenen Guthaben enthalten, auf die schwarze Liste zu setzen. Ich werde diese Liste auf dem

neuesten
Stand halten, wenn mehr Leute Adressen posten : 520 + Gi GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIIHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIIHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9SYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=========================== ==
Bitte geben Sie die Adresse an, an die Ihr gestohlenes Guthaben gesendet wurde.
Wir können die Börsen kontaktieren und versuchen, diese Adressen auf die schwarze Liste zu setzen, bevor der Dieb von IOTA in eine andere Währung wechseln kann. Die Zeit ist von entscheidender Bedeutung.

Lasst uns versuchen, die Details dieser Situation so gut wie möglich zu untersuchen. Wenn Sie beschließen, rechtliche Schritte einzuleiten, schreiben Sie bitte auch einen Hinweis für andere, die dies ebenfalls in Erwägung ziehen. Lasst uns alle gegenseitig helfen. Der Dieb wird damit durchkommen, wenn niemand etwas unternimmt.
[/Zitat]

In der Tat
By sun_in_the_city - 21 Jan 2018

QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ 137.3 Mi
am 19.01.2017 um 20:51 Uhr

Danke fürs Sammeln
By Nigl23 - 21 Jan 2018

Lazyrudi - 21 Jan 2018
no, it's not your fault. IOTA encouraged us to use their seed-generator placed in their own wallet generator system. It is IOTA duty to make it safe for the user.

By the way were is "Winston"?
What is IOTA doing right now??

Exactly! I see people saying stuff on social media like "Never do this and that..." and alright, I get their point. BUT, when I got into IOTA, I got their wallet and used their seed-generator. I didn't just use any shady website. 
By andiveze - 21 Jan 2018

HALLO. ALSO ON MY ACCOUNT IOTAS WERE STOLEN (8750iota). THEY WERE SEND TO THIS ADDRESS: ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW

HOPE I COULD HELP.
By OpenMedia - 21 Jan 2018

Lazyrudi - 21 Jan 2018
What is IOTA doing right now??

They do nothing, as before. That guy Ralf wrote it is the failure of the users, not their crappy design exposing private keys without any protection at all.
By Lazyrudi - 21 Jan 2018

Since IOAT is no longer responding to the many loss reports I do not know if IOTA is still active, or those responsible have already settled in the Bahamas.
I do not think IOTA voluntarily admit their mistake and refund our money. Therefore, we will need legal assistance. Does anyone know a lawyer (best from Germany, because jurisdiction is probably Berlin) who can represent our interests to IOTA? Otherwise, tomorrow I will contact some to see who can best represent us.
By JakeTehSnake - 21 Jan 2018

237.87 Mi stolen and sent to the following address:
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFA

By eltuga - 21 Jan 2018

520 Gi (1,425,702.337 USD) https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

a transaction that concentrates scammed wallets on 19th Jan
https://thetangle.org/bundle/9EARKHWOLK9PEIIDIQWXEGZBDTWDWIYIXGJDSQQDDIUTLVEGSFCITZZQPW99WHUTPSDBLATIZILETUIID
1.76 Ti (5,060,667.106 USD)
This value goes over dozens of subsequent transactions after start splitting in smaller wallets values

and another with that is distributing later to other transactions and wallets
1.11 Ti
https://thetangle.org/bundle/TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ
By vikingvp3 - 21 Jan 2018

I lost my IOTA to this transaction
https://thetangle.org/transaction/MKXSNAESMYTPWWKUXGLPTDYOPWAUYWMWGR9WMNZXREPAIKSCKWJDSERKTJQRBOHAPGLFZKOPMQEYZ9999
transaction hash:
MKXSNAESMYTPWWKUXGLPTDYOPWAUYWMWGR9WMNZXREPAIKSCKWJDSERKTJQRBOHAPGLFZKOPMQEYZ9999
Address:
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
but it is 0 know and i do not know where is forwarded to
By CryptoHamster - 21 Jan 2018

MisterBrot - 21 Jan 2018
@Alexa: 

No. But curiously the amounts are the exact same amounts I've transferred to my seed (I made 3 transactions from bitfinex using exact those amounts: 2,2 Gi, 855 Mi and 50 Mi).

OT: In December I tried to split my IOTA and tried to send some Mi to a 2nd seed. But that transaction is still pending TODAY, so it never happened. The amount I've tried to move in December is now gone as the rest is gone. This is something I blame the IOTA team for.

Yeah, it seems very strange that your addresses have been emptied one by one...
I'm not sure if your funds have been taken by the same thief that took the others, but I suggest the addresses for blacklisting. @Winston @rajivshah
https://thetangle.org/address/FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMB
https://thetangle.org/address/ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWD
https://thetangle.org/address/HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9D
https://thetangle.org/address/UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYB
https://thetangle.org/address/VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9

By Marshall07 - 21 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

This is the address where my stolen IOTAs was sent to:

https://thetangle.org/address/RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9

Please, add it in the OP.
I hope these criminals will get what they deserve!

Regards
Marshall
By EwingJR5 - 21 Jan 2018

Hi Everyone,

I lost 1.9 GI to this address: YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
The hash is: IPFY9EQJXQTBSAQEQVOOARKZPLQGXTRHOHWXUCPLAQWZMPSDQGKJJBUVBRKALUVCRRJJ9T9BAGLZA9999

The transfer is confirmed.

Is there anything one can do about?
By CryptoHamster - 21 Jan 2018

Cheeg - 21 Jan 2018
I know it is my own fault and I hate myself very much now.

Nevertheless all my funds were stolen and send to those two addresses

PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZW

V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9Y

If there is anything we can do about it, please let me know.

These also look a bit different than the other thefts, but please blacklist those too, @Winston @rajivshah:
https://thetangle.org/address/PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZW
https://thetangle.org/address/V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9Y
--> with an outgoing transfer currently pending to:
https://thetangle.org/address/XRJC9SBOVLCUUYLVJDGRRGKBPWIXEEMGOSLHNS9GBEDNGMQSEFYQEDDQIFOSKBAHCSPJTARDATVAFQUCY
and
https://thetangle.org/address/UTPHDFSAOVPSZUVKIXWYMYTCKLJXZFEYKKQKLYBIMUOYNDOJFOHZEYFHZPDAYKJVFLURJHGWIUN9XSPVW
By CryptoHamster - 21 Jan 2018

sun_in_the_city - 21 Jan 2018
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ 137.3 Mi
am 19.01.2017 um 20:51 Uhr

Danke fürs Sammeln

Thanks for posting! Haven't seen this one before.
@Winston @rajivshah Please blacklist: 
https://thetangle.org/address/QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99
By CryptoHamster - 21 Jan 2018

sun_in_the_city - 21 Jan 2018
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ 137.3 Mi
am 19.01.2017 um 20:51 Uhr

Danke fürs Sammeln

@sun_in_the_city
Your transaction is still pending, so you might still have a chance to safe your funds! You need to be really quick about it, please follow instructions here:
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances
By OpenMedia - 21 Jan 2018

Lazyrudi - 21 Jan 2018
Since IOAT is no longer responding to the many loss reports I do not know if IOTA is still active, or those responsible have already settled in the Bahamas.
I do not think IOTA voluntarily admit their mistake and refund our money. Therefore, we will need legal assistance. Does anyone know a lawyer (best from Germany, because jurisdiction is probably Berlin) who can represent our interests to IOTA? Otherwise, tomorrow I will contact some to see who can best represent us.

There certainly should and will be legal action, given a potential 1 billion + US$ theft. That can only be a class action, not limited to Germany. Let's gather resources and collect more information. Time is key. That IOTA is not doing anything and the seed/private key issue is still exposed does certainly not help them. I'd rather consider it completely irresponsible.
By CryptoHamster - 21 Jan 2018

andiveze - 21 Jan 2018
HALLO. ALSO ON MY ACCOUNT IOTAS WERE STOLEN (8750iota). THEY WERE SEND TO THIS ADDRESS: ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW

HOPE I COULD HELP.

Thank you for posting! This one leads to a bundle I've already posted before. 
By CryptoHamster - 21 Jan 2018

JakeTehSnake - 21 Jan 2018
237.87 Mi stolen and sent to the following address:
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFA


@JakeTehSnake Your transaction seems to be still pending, so you might have a chance to safe your funds!
You need to be really quick about it! Please follow instructions here: 
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances

@Winston @rajivshah
Please blacklist: https://thetangle.org/address/AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFA
By Lazyrudi - 21 Jan 2018

Of course, a class action lawsuit and of course not limited to Germany, but he should be familiar with German law and the same with the subject of cryptocurrencies. @OpenMedia Do you have a recommendation?
By Tigrafahrer - 21 Jan 2018

Hello,

I´ve got 186,6 Miota stolen. They were send to this adress:

UNXQSN9DOEYHUKNPCEQZWLDBDPNURKLSFEZYWIYNGRBMSZEWOFTCTOVDZCUU9YQPRNKNPYEJRCIT9PKHWZDOYPWKGW

It´s a shame the Iota foundation does not seem to care a bit about this mess. So how should anyone have trust in such shitty crisis management...
By CryptoHamster - 21 Jan 2018

eltuga - 21 Jan 2018
520 Gi (1,425,702.337 USD) https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

a transaction that concentrates scammed wallets on 19th Jan
https://thetangle.org/bundle/9EARKHWOLK9PEIIDIQWXEGZBDTWDWIYIXGJDSQQDDIUTLVEGSFCITZZQPW99WHUTPSDBLATIZILETUIID
1.76 Ti (5,060,667.106 USD)
This value goes over dozens of subsequent transactions after start splitting in smaller wallets values

and another with that is distributing later to other transactions and wallets
1.11 Ti
https://thetangle.org/bundle/TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

Thank you very much! Checked them and these transaction all go to either one of the addresses already posted for blacklisting or the bundles posted previously that I believe to be associated with transfers to an exchange.  
By CryptoHamster - 21 Jan 2018

Vahid Pur - 21 Jan 2018
I lost my IOTA to this transaction
https://thetangle.org/transaction/MKXSNAESMYTPWWKUXGLPTDYOPWAUYWMWGR9WMNZXREPAIKSCKWJDSERKTJQRBOHAPGLFZKOPMQEYZ9999
transaction hash:
MKXSNAESMYTPWWKUXGLPTDYOPWAUYWMWGR9WMNZXREPAIKSCKWJDSERKTJQRBOHAPGLFZKOPMQEYZ9999
Address:
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
but it is 0 know and i do not know where is forwarded to

Those already happened in November, not sure if they’re related to the recent thefts.
But the funds don’t seem to be transferred to an Exchange yet, so @Winston @rajivshah please blacklist:

https://thetangle.org/address/OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYC

https://thetangle.org/address/PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9
( this one bundling up 27 Inputs https://thetangle.org/bundle/RFK9NQBDBHGHSFWGINGBDGGFTVNWUNJUVHRLIRCRKKOHRVXBXXBJIBVERIJHXCJDYLKSFKINNHOOBDCCY )
By CryptoHamster - 21 Jan 2018

Marshall07 - 21 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.

That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD
=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

This is the address where my stolen IOTAs was sent to:

https://thetangle.org/address/RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9

Please, add it in the OP.
I hope these criminals will get what they deserve!

Regards
Marshall

@Marshall07 This address has many pending transactions. Please check if yours is pending too (don't know which it is). If it's pending, you might be able to still safe your funds if you're quick about it! Please, follow instructions here: 
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances

@Winston @rajivshah, please blacklist: https://thetangle.org/address/RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9
By CryptoHamster - 21 Jan 2018

EwingJR5 - 21 Jan 2018
Hi Everyone,

I lost 1.9 GI to this address: YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
The hash is: IPFY9EQJXQTBSAQEQVOOARKZPLQGXTRHOHWXUCPLAQWZMPSDQGKJJBUVBRKALUVCRRJJ9T9BAGLZA9999

The transfer is confirmed.

Is there anything one can do about?

Thank you for posting! Checked it and this one leads to a bundle that's been indentified before. 
By MisterBrot - 21 Jan 2018

SPIEGEL, one of the most read news magazines in Germany and whole Europe, might publish a story about the theft. I've contacted (and received an answer) from a journalist who reported about IOTA recently.

The reporter needs someone who has been robbed to tell the story based on that very person (it's more interesting that way for the reader, I guess)

Is there anybody from Germany here who was robbend and wants to cooperate with him and tell his story?

If he doesn't find anybody else and decides to publish a story, I'd do it myself, but I'm not very keen on that.
By CryptoHamster - 21 Jan 2018

Tigrafahrer - 21 Jan 2018
Hello,

I´ve got 186,6 Miota stolen. They were send to this adress:

UNXQSN9DOEYHUKNPCEQZWLDBDPNURKLSFEZYWIYNGRBMSZEWOFTCTOVDZCUU9YQPRNKNPYEJRCIT9PKHWZDOYPWKGW

It´s a shame the Iota foundation does not seem to care a bit about this mess. So how should anyone have trust in such shitty crisis management...

Thanks for posting!
@Winston @rajivshah Checked it, it leads to the following bundle (worth 108.3 Gi). I've suggested the Output for blacklisting already as well as some of the Inputs, but it's all still pending...
We'll should monitor this bundle and as long as it's not confirmed I suggest all the Inputs for blacklisting:
https://thetangle.org/bundle/LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW
By CryptoHamster - 21 Jan 2018

FrankB - 21 Jan 2018
4.7 Gi
https://thetangle.org/bundle/9LKIEFANWKNDJFJIHVZHRZBJRQHIQGGBXJJHFEPHGHDEKKNT9GXKLQIJBXKGBRXQUVUHGPQFPDJYLHJSA
I tried to post but got a Spam notification. I tried to mention that I am on Reddit as HowAboutFrank

Thanks for posting! Checked it and the receiving address has already been suggested for blacklisting.
By Lazyrudi - 21 Jan 2018

I would be glad to tell him my story and my view on the situation. I am from Germany and lost 10GI. He can contact me on r.passehl@gmail.com
By TigerDKO - 21 Jan 2018

Hello,

the Thief sent my 1386 MIotas to this address:
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

Greets
TigerDKO
By nematollahi - 21 Jan 2018

My 402.373+ Mi  IOTA  was stolen by below address:
IOTA ADDRESS:
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKED

TRANSACTION HASH
HILCOVRSHEHBEINVSCIPSIIGKPCOIN9RSEJAXVUTWQWHQKBQUAHTD9RSBVROUYRGMZRTTDA9YMEDZ9999

thanks for your effort,

what can i do  for returning me my lost IOTA  as soon as possible?

you can reach me by e-mail: nematollahi1359@gmail.com
By MisterBrot - 21 Jan 2018

Lazyrudi - 21 Jan 2018
I would be glad to tell him my story and my view on the situation. I am from Germany and lost 10GI. He can contact me on r.passehl@gmail.com

I've sent your reply to his email adress. Hope he answers you back. I'm gonna try to send you a private message with his email address, if you want to contact him yourself. Good luck!
By Lazyrudi - 21 Jan 2018

Wha doesn't IOTA shut down the Tangles/Notes to avoid further transfers??? Then they could clean up the mess. Most of the Tangles are still aktiv and running.
By CryptoHamster - 21 Jan 2018

TigerDKO - 21 Jan 2018
Hello,

the Thief sent my 1386 MIotas to this address:
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

Greets
TigerDKO

Thank you, the funds have been moved to an address already suggested for blacklisting.
By MisterBrot - 21 Jan 2018

Lazyrudi - 21 Jan 2018
Wha doesn't IOTA shut down the Tangles/Notes to avoid further transfers??? Then they could clean up the mess. Most of the Tangles are still aktiv and running.

Hello once again, I've got a reply by the reporter regarding your story (check your PM's, too)

"vielen Dank, wir werden uns Anfang der Woche bei ihm melden."


By OpenMedia - 21 Jan 2018

Please also follow the developing topics here.

https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

They are all linked, but different people share information on different platforms.
By CryptoHamster - 21 Jan 2018

nematollahi - 21 Jan 2018
My 402.373+ Mi  IOTA  was stolen by below address:
IOTA ADDRESS:
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKED

TRANSACTION HASH
HILCOVRSHEHBEINVSCIPSIIGKPCOIN9RSEJAXVUTWQWHQKBQUAHTD9RSBVROUYRGMZRTTDA9YMEDZ9999

thanks for your effort,

what can i do  for returning me my lost IOTA  as soon as possible?

you can reach me by e-mail: nematollahi1359@gmail.com

Thank you very much, it's been added to the list in the initial post. 
By Winston - 21 Jan 2018

Thank you everyone for all of the information that you've provided so far. The OP has been updated with every address that has been posted. Huge thanks to @Alexa who has done a great job of highlighting the blacklisted addresses in this thread.

Some posts in this thread have shown a concerning lack of understanding of the current situation, so let's clear up some of the misunderstanding before we go any further:

Here's one such concerning post:
"Since IOAT is no longer responding to the many loss reports I do not know if IOTA is still active, or those responsible have already settled in the Bahamas.
I do not think IOTA voluntarily admit their mistake and refund our money. Therefore, we will need legal assistance. Does anyone know a lawyer (best from Germany, because jurisdiction is probably Berlin) who can represent our interests to IOTA? Otherwise, tomorrow I will contact some to see who can best represent us."
------------------------------------
1. I am just a volunteer who spends my free time answering questions and helping out where I can.
2. Nobody presides over the IOTA protocol. It's simply open source software that's available for anyone to use. 
3. The IOTA Foundation is a small software non-profit foundation. The Foundation's scope is very narrow - it only does software development and business adoption. Legal action is completely outside of this scope, and it has been clear from the very start that the Foundation itself will not be able to pursue any legal action on behalf of victims of this theft.
4. It's important to reiterate the fact that the IOTA Foundation cannot pursue legal action in this case, and that any legal recourse is wholly dependent on individuals in the community. Please consider hiring a lawyer, reporting this crime to the authorities, and even banding together to form a class action lawsuit. Lots of people have been impacted by this, and there's strength in numbers.
5. The focus need to be on helping to figure out intricacies of the legal process and tracking down more details surrounding the criminal. A few of the IOTA higher-ups can make sure to report all of the blacklilsted addresses that have been compiled, but it's up to all of us (the community) to start looking into legal action against the criminal.

I think most people understand that the IOTA Foundation is a benevolent bystander in this whole thing, but the few posts seeking retribution from the Foundation are concerning nonetheless. As frustrating as this situation is, it's definitely understandable for people to be upset and lash out at everything/everyone involved. But let's try to make sure to focus our efforts on the task at hand - that is gathering details about the criminal(s) running the scam seed generator sites and beginning the process of legal action against said criminals.
By OpenMedia - 21 Jan 2018

Agree Winston, nevertheless they have to take immediate action to close that security hole, which is a black hole. This must be done now!
By CryptoHamster - 21 Jan 2018

mohammadalietebari - 21 Jan 2018
my iotas is gone
unfortunately transaction is confirmed
please help me

here is the hash

SMAQHHFMHGMGBEKREFKRCTXRYCTYMGTSWMKCYHD9VDBQKYTYSZUP9KULHDWPMNSNLIQMDSAGVCYSA9999



and i think this is the destination address:

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDB

Thanks for posting! This address is empty now, but the funds went to these two and I suggest them for our list: @Winston (my last post for today). 
CE9XUYX9KSLEKFKKSMW9XRBMGLBJ9PRCMDGNV9GXZEKZQQEBJQEMXVCFTNOHZEZPSUZYUIDLTDNTDHIYAVYIRYJKPX
9SKDUHUFCIRZSMJQKLAUC9AISRJWNCYMXTUSHBBZJKMTOBDN9GQIUGDX9SCDXGB9GNSAPTRMYLNHAKURXYGFVHNVMZ
By Thurim - 21 Jan 2018

- 100 Mi

ILFHRYIJPWQ9HGCKRAOXEECZVKBPVKXDNTCKOOO9SITAGLZR9ASDTCMV9MEO9TGTRHONKEJIWEL9GAEAWFPWAJEOQW

:-(
By Nigl23 - 21 Jan 2018


159.863635 Mi

Thief's address: IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
TxHash:HGCKKSNVIDJIDOQIHARBARJIHLZUVCVIYNLLSTNZDEJRYXMCYPBEF9D9X9IDJLVLPWTGTGFTUEOWZ9999

Thanks for trying to help
By Winston - 21 Jan 2018

Thank you everyone for all of the information that you've provided so far. The OP has been updated with every address that has been posted. Huge thanks to @Alexa who has done a great job of highlighting the blacklisted addresses in this thread.

Some posts in this thread have shown a concerning lack of understanding of the current situation, so let's clear up some of the misunderstanding before we go any further:

Here's one such concerning post:
"Since IOAT is no longer responding to the many loss reports I do not know if IOTA is still active, or those responsible have already settled in the Bahamas.
I do not think IOTA voluntarily admit their mistake and refund our money. Therefore, we will need legal assistance. Does anyone know a lawyer (best from Germany, because jurisdiction is probably Berlin) who can represent our interests to IOTA? Otherwise, tomorrow I will contact some to see who can best represent us."
------------------------------------
1. I am just a volunteer who spends my free time answering questions and helping out where I can.
2. Nobody presides over the IOTA protocol. It's simply open source software that's available for anyone to use.
3. The IOTA Foundation is a small software non-profit foundation. The Foundation's scope is very narrow - it only does software development and business adoption. Legal action is completely outside of this scope, and it has been clear from the very start that the Foundation itself will not be able to pursue any legal action on behalf of victims of this theft.
4. It's important to reiterate the fact that the IOTA Foundation cannot pursue legal action in this case, and that any legal recourse is wholly dependent on individuals in the community. Please consider hiring a lawyer, reporting this crime to the authorities, and even banding together to form a class action lawsuit. Lots of people have been impacted by this, and there's strength in numbers.
5. The focus need to be on helping to figure out intricacies of the legal process and tracking down more details surrounding the criminal. A few of the IOTA higher-ups can make sure to report all of the blacklilsted addresses that have been compiled, but it's up to all of us (the community) to start looking into legal action against the criminal.


I think most people understand that the IOTA Foundation is a benevolent bystander in this whole thing, but the few posts seeking retribution from the Foundation are concerning nonetheless. As frustrating as this situation is, it's definitely understandable for people to be upset and lash out at everything/everyone involved. But let's try to make sure to focus our efforts on the task at hand - that is gathering details about the criminal(s) running the scam seed generator sites and beginning the process of legal action against said criminals.
--------
This is a copy of my previous post. The last post was at the bottom of page 6, running the risk of nobody seeing it. :joy:
By Savinme - 21 Jan 2018

Hello,161.5 mi from our wallet had stolen by this adress.
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
By GregPol - 21 Jan 2018

Hello,
I lost 2.99Gi
first went to the following address:
BTRKYJCVBSFVMEJL9KSSJRTDQSAYCS9GJBLBKVEXWXNBFEDBEWQAITDPZCGDJQ9HHE9FDCIJNQAQB9RMWD9FK9QUMZ

Then he sent everything to this address:
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD

I am happy to join the lawsuit.
By faeze - 21 Jan 2018

HI
My 140 IOTA is stolen.
what should I do ?
You must support us.
Please help ...
By GeNiUs76 - 21 Jan 2018

Hi there.

From my Light Wallet the balance of 1 Gi were stolen. I dont get this Light Wallet at all.....sometimes I´ve got 11 transfers, then 7, then 5....right now there are 5 transactions, 3 ingoing from me, 2 outgoing that I didnt start at all!  
Here are the outgoing ones:

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC     (pending)
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA  (pending)

My address is: VPRWNGDEMJIPOVIRXUZHRILPTPCBGNWPVLPMLCCYHGCZRVYMXDPOCYREQDSVJP9JRVOBSPAXLXRDRAQQBPPPQFACKW

By Kaiblade - 21 Jan 2018

My stolen 111 Mi was sent to this address:
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPX

Here is the transaction hash:
ZQVDXKTXSMXOSYP9ZQRJKWAWYCZJYORWHYUQPJADFFPRDO9BFUEKKOCAONRGKMVXPH9EEBZEUEIJ99999

Thank you
By moonpie - 21 Jan 2018

I lost 973,972033 Mi to this address:
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9

and another 1Gi to this address:
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIB

Fortunately I was able to save another 274Mi before the transaction was confirmed - thanks to all of you guys.
By GeNiUs76 - 21 Jan 2018

GeNiUs76 - 21 Jan 2018
Hi there.

From my Light Wallet the balance of 1 Gi were stolen. I dont get this Light Wallet at all.....sometimes I´ve got 11 transfers, then 7, then 5....right now there are 5 transactions, 3 ingoing from me, 2 outgoing that I didnt start at all!  
Here are the outgoing ones:

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC     (pending)
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA  (pending)

My address is: VPRWNGDEMJIPOVIRXUZHRILPTPCBGNWPVLPMLCCYHGCZRVYMXDPOCYREQDSVJP9JRVOBSPAXLXRDRAQQBPPPQFACKW


Ok....now I have 11 transactions and one of them is confirmed. According to the cli wallet, my balance is 0.....the 1 Gi are gone. To this address:
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
Hash: NHLAJDKSZMBUVYTGWOZLUTCOCQKIYQAMNZRXNFQVWZARQPTPLIZSFPRXMBBUUTYLMCBOKMVUKCZU99999

By dontuseiotaseedio - 21 Jan 2018

I highlighted this address in the other thread and I can't see it mentioned here yet.

One of the attackers addresses currently with 804Gi  in it:

https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY
By yusuf - 21 Jan 2018

Hi,

is it possible to get back our coins?
I do not think so but I hope:-)

3 Gi
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9
By yusuf - 21 Jan 2018

yusuf - 21 Jan 2018
Hi,

is it possible to get back our coins?
I do not think so but I hope:-)

3 Gi
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9

Hash
9LAWF9RWLNMVKRXYTQGJJXJFNIHOWZUJBBN9SYIS9UKPSPJY9JFT9OQ9DQQMBTMOLKSFYDODCVGY999


By vamshi - 21 Jan 2018

JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
1.6Gi lost to this address on 18th 20:49
By Smooke - 21 Jan 2018

Hi everyone 
Stolen 109.4325
go to this address
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB

This is the HASH
RDHALMPVZGBNKLLBCUBPDWHRAZJOCJTEXKHZGSEXPAGMKWEXHQMMXMPZHFQYLLZGAMCOXQTAMFHK99999


By Francky16 - 21 Jan 2018

Hi, my 5500 iotas (5,5Gi) were stolen the 19 january at 12:46. It were transfered to this adress :  ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9

The hash is this one : RLALNSYZUECJNKNRQ9LPPJHXRORLZIRBAFXTDCHQOSBVVQKOCHVBGLYFZZYKSALZHCLESKYNXPEX99999

The state of the transfer is "Completed" ... Sad
By Nemesis_ch - 21 Jan 2018

1.883557352Gi were stolen from my wallet and sent to this address:

SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y

iotas are still there..

By iq34acal - 21 Jan 2018

As posted in the other blog about stolen IOTAs earlier this day, my 314.9 Iotas were stolen from following adress:

WPXKXBSSDWOUSXSKKPSXCCHFHLHKHKCVGFSLBWLFIJEWMJLCXCOALJNYOA9GJMUSNRCEJZXM9JJNZEPSD

They were transfered to:

OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB

How do I join legal actions? 
By twick - 21 Jan 2018

Hi guys i just found out i got hacked for  89.7 Gi sent to address
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
By AfroBlk - 21 Jan 2018

They stole 150 MIOTAs
TxID:
YFGALPRGAVKNBHFSCBQJI9PNZVZIDPFOMROHCYMWNFTUARDCXOWLTTIEJKDDSEGHJBXSFLVNJWBS99999

Address:
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HD

TxID:
TQCEYHXTLZXKQYAOHLHYZJGEWFBPNFQEDGLOJ9LIQAQXTUZWGJKWMMAQZPTALKAB9OVVUADIEWRWZ9999

Address:
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD
By Winston - 21 Jan 2018

All new addresses have now been added to the OP.

@GregPol
   @iq34acal
You guys both asked how you could join the legal actions. We need to have someone from the community initiate legal action, and then others can jump aboard. Hopefully someone is able to get this going.
By Jannemann - 21 Jan 2018

PZQRE9QMRPQZ9SMZRAEDGXFDQADBNMBUVHJPEOSECLKDCNETUYQMMBLLPPKCNBBWWLFXYKOUHEK9ZE9TDKXVQGMNTY


I was also stolen 3270 Iota.
By cryptobraintree - 21 Jan 2018

I had a total of 2,800 IOTA stolen in three separate transactions all from one IOTA wallet where I generated my seed in late November from iota seed dot io that was referenced by the IOTA main page! 


20/1/2018 9:28 2.48 gi (2,400) IOTAS sent to this address: ZLXHODYKFAWRGYGRYBBIMLNXLVYHRKPLTYQXYTWTHYYCTWJRGTZEWECPBINVRXCVXAKMDKLETZXLAFN9Y9BWCRQZTX
Hash: MFXTXUT9DOZATOCGGHIGLKOCEKKPLSIBJTUVQHELDQLRLZAWISCQRBPKTSOUVNVJVEG9JOMCMO9TA9999

20/1/2018 9:20 199.5 mi IOTAS sent to: ARFWJXIEMHZZBPDPNKCNZXOPEHFSICNDIXII9WAHW9KCEBRFPMZXNQ9RFASQGAUPDVKSYYJPGAZ9WABKAYFRFOJJBX
Hash: PQCTFCCLMUQ9UPGUDTPFKBZZTJ9QOFJYOURYJZRC9UWFOSGJLAVASNCVEPRGMGHDRFVWIRLGBY9Y99999

19/01/2018 18:34 199.5 mi IOTAs sent to: SGRLFSBORTTDTSNIQZIQPYGXRQSYVCPZWCH9ERPLRFHVMWRTIGNEIBWGUYRAGHHADSDNTMBOCE9RHNALCORRNDNOSD
Hash: 9WXQQEGRWZPWSPMPXOGVWAVTFXXEYTNVOKRGFAFJSPBGKLXSVSLMNBSYRAWQU9BKNHCC9JERZGQKZ9999

The strange thing is that the first address with 2.48 g IOTAS has not been moved to another address... and to add to something weirder, even thought my wallet had a zero balance they went back in last night and tried to make another transfer twice!
By roby123 - 21 Jan 2018

address:
XTWX9FDSWOCOJOKIJANSZUUBJLQVFXCSEMHTHHN9SBGEINJZRULXLGBFWRSBFKCNCCNZ9HAMY9CWYQLDBYISIJGYUY 
Transaction:
NLMKWKLJTMF9OVKOIHUXDYBEIZEBWJQQUXEJJMXKE9IZXGTMULDCCUANQDBSXSCSDPTTGKYCPPWPA9999
January 19, 2018 18:12:14
they stolen 3.079 Gi
By Rezz415 - 21 Jan 2018

1 Gig from wallet was sent to this address:
KQAHUBAXMMFSPEDVMWNPULRNKQOVX9FEIYVXLLLHRPNGPWBQQECZXDL9CMVWTJOJGBXNQZKRYTBUILSHZLUGXUMTZZ

Third attempt by me also as I keep getting flagged as spam!
By Savinme - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
161.5
By Rezz415 - 22 Jan 2018

Rezz 415 - 21 Jan 2018
1 Gig from wallet was sent to this address:
KQAHUBAXMMFSPEDVMWNPULRNKQOVX9FEIYVXLLLHRPNGPWBQQECZXDL9CMVWTJOJGBXNQZKRYTBUILSHZLUGXUMTZZ

Third attempt by me also as I keep getting flagged as spam!

Actually this is what I see completely if it helps:
BUNDLE DETAILS

Hash: QZVGGZ9PVFFQWYXVJFYPPRPSJEQZOGPJFGCIEXRVJEEELQBQVRZRMOIBW9HUDXTBENZZHKG9QYRFZ9999

LFAAYTEQQIFWWAMQDBBPEMXXG9JYLFBOAHJOUIUSTYBLRNNACCPMMAZIXTPFNRJVXXLOEOYAAVFNMKDHHOLDXGAFSPVSY
10.4+ Mi
RVTSRO9GHJRDSYHPDEBFJPVC9UQWBQLXHRQER9JKUCNVDUNVHFWSETUJYITPEENSQNIXCS9GRZHAA9OZ9WEP9CWMDC
1.0+ Gi
UZGIPPSZB9CJYHZWMGMXDJQKCVZZPJTHRMKTAVZNRHWNNIOFPZUMYIMNBRCMSMTOSYCH9PMVWJTMENSVWJRYDTPRFY
9.5 Mi
B9IL9EHUYGPNKGXEKYAFLWODLNZKIRRNYV9YXWIEGUGCZEVPDJPRTODJOKRQFXZUWWSVOWBCPOFDMLCWZJCEQPRWBZ
25.2+ Mi
GFGSSHMHPTDHSURTNKPBXQXUKFDDRUOWMZJMVJZDRSNMJKNYALLCYMAPVKRUYUMAOFLTOSFZMCLEFFIZWCYUFLPHXD
336.1+ Mi
VLMEOVJISBAFPGO9QLKFEZPAASYCENJTTPYTUMZJSXOLTIT9WFO9IXNA9KVRNILVJOZXUYVAA9KLWAFUDTSHFOQL9W
17.4+ Mi
CGTUNBHHHSMTRTVEXZUUCYBERWBXDHUVSKWGSHGITXCCYQCRQIGNMFSIPOTBJR9SMFAJGQJCSRHCKMITAKBPULQBEA
18.4+ Mi
PRCVUGCJEYPFJGKDHRNBEAEMHV9XBYVURKBNWTJJKSRLSSPJHBLQTMGSWQTDCHKPZTGOZCXRQUKTNOT9DSVSXXADRZ
50.4+ Mi
KMHQCPWEFYQCJNJCVKHSTWXWYWHWONKBDQTLQWPLKARBKEKWOCLXIDAMMMGOPUJDLEDXDUQZOPTFL9KNWWJETKLMGW
30 Mi
OJNYGAJPCBQJIXTEMUTRMWWJ9NBNNRHJBTSCM9BVLPXJQRBCCSNIZBKKHWF9P9GNWCUMULSGRRKTFZPHAKCXIQPHBW
10.5 Mi
DKLHYCWAXKPROXEXXUKYBKXZLSCZMS9KSIJFJOKMHUKGNX9YUVYXIYKYIUMWIFYNOZMCEQEHJUAAFMLHWAXMSDJSEA
300 Mi
EV9WUCVZSQDHKOMRKNETRZWNUSKLVWN9ORCCTEBOQLSTBWBTTIDDYQUNBGWSDPSOHDH9YTXV9OOHDBHAWQGPYSXWWY
24.4+ Mi
DKTJECGPAJDOQSAIPZOBJIPDU9LLXA9NHJWZ9QEGZGTQZCCNDWSBSHOFWEVID9OW9ET9ATOKKRUYBPHMBLZPGSLECC
100.3+ Mi
HMBTHZEYRJQMLRUY9BKQXDMVSLIT9QDAXIEMKRLNRSGLXPHHWRRVJXVJFZEVGQPL9WBGSUSPPRJCQHBBWDLYZGFHVY
220.1+ Mi
BKSQMREUBTSWIYGWOKYINFARUQSKDPWWTZZLQHBZYILILRFBEHJKGYASDPFSQUCWINNGJWJBFNHWSARXWI9KMGYFAW
114.3+ Mi
VFQACQMXVOAXCBZTQZSIXTIWEPULPIOGJGXZBZZMWTHEVMIWHYNEVWZHXSADFLNISNUZXDVSMFIFBWPOY9ITBFDNNW
-4.4+ Ti
VFQACQMXVOAXCBZTQZSIXTIWEPULPIOGJGXZBZZMWTHEVMIWHYNEVWZHXSADFLNISNUZXDVSMFIFBWPOY9ITBFDNNW
0
VFQACQMXVOAXCBZTQZSIXTIWEPULPIOGJGXZBZZMWTHEVMIWHYNEVWZHXSADFLNISNUZXDVSMFIFBWPOY9ITBFDNNW
0
ZWKSJBORA9TSVGLJMMNGLYZZGZKJJUXGXPJRXNVIWYMJEZOJEZWCKVLOXFC9ONO9BBMVFULOHVEODBMVWYUKOMCFTW
4.4+ Ti
Persistence: Confirmed
By DR - 22 Jan 2018

They stole my 1.53 Gi :-((

Thief's address: YONLPTJKJMONCXNNMTAQDUDTNCUBJPENQUKFADPMYNOFXWGUPUTEBXBVVDOGTEKSSSCZDWNYKGTPDMTSDOLVNHCJEZ

Thief's balance now on this address: 8.67 Gi

Hash: VEVAOVFKUUNYVZJOCYRYTPJMIHRPA9KIFHOSNVGELUFZIHWVIDVWHNLXXKEAMBCXKRNMVN9QJCNWA9999

Thank you!
By joelgus - 22 Jan 2018

Mine were stolen. Transaction Hash: KJRXNX9PMEPG9EB9HAWPOXHJPKOTZWFBAFXNXABKKLY9WRHWLYMF9QTWYX9TKRFXWFMM9VOCUQJJA9999: From Address: JQTKULYLUWAWOPIURRGVGOQAYVUHPSMAUGLIRQGUGUW9NZPCSREAKXUPCEYPIUHPVJEXACXJDYAEDJRVA
By joelgus - 22 Jan 2018

Question for those of you that are more tech savvy than i am. Couldn't the IOTA Foundation manually lockup the funds like they did months ago, when the system had a security flaw? 
By Mgreene923 - 22 Jan 2018

Hey Winston,
I had 326.02 Mi stolen on 1/20/18 2:09am EST
The address it was sent to is JQMGWWJYI9UNIRRTWGDIYCDNSPYPKFXHIYDXBOPXXGBHVXTBCUTXOM9ESNEOYIFGJYYXIGSSWGLYJYLSAJFXCMFVYW
Hash: KOYOSCQIJHVWPDMJCNFLPREZAHY9EJCIPUSMNJSEFYTZYGAH9JSFRSBEKIXEKRXQSU9UTULLZWON99999
By mohammadalietebari - 22 Jan 2018

mohammadalietebari - 21 Jan 2018
my iotas is gone
unfortunately transaction is confirmed
please help me

here is the hash

SMAQHHFMHGMGBEKREFKRCTXRYCTYMGTSWMKCYHD9VDBQKYTYSZUP9KULHDWPMNSNLIQMDSAGVCYSA9999



and i think this is the destination address:

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDB

@Winston please update your post with my replay
By danigg - 22 Jan 2018

1.6 Gi went to
VKOPFJYNPWOEQDDCYWZIANDOJQWKLUJFBXNUACBDLCSCVGWJKDGXLZPBGXAWYYZAKFQIY9HQEVPFOXQDYEUXSRLHWD
By Tigrafahrer - 22 Jan 2018

Please forget about any class action in Germany, german law does not know that instrument: https://de.wikipedia.org/wiki/Sammelklage#Deutschland

And I cannot imagine any police officer or judge to understand what has happened to me if I try to explain the "robbery". So realistically any legal steps won´t bring us much further.

I really do not understand that there´s no word from anyone from the IOTA foundation. Maybe they are only a few people but I would very much appreciate any official Statement and any effort to try and save the stolen IOTAs - it´s very easy just to say "impossible".

There are thousands of people who have been robbed, all of them are early adopters of IOTA. Imagine every single one of them spreading the word how unsafe IOTA is and how disappointed they are. The impact on IOTAs reputation will be devastating.

Once again: I do not understand it!
By Lazyrudi - 22 Jan 2018

I'm not a lawyer, but at least I'll try. https://de.wikipedia.org/wiki/Kapitalanleger-Musterverfahrensgesetz

By oyster925 - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

1440 IOTA stoken and sent to AREZKKAHHBJKBCWBOF9HOUACFACQCCFXKBOWZDFBIHY9TQAESSR9C9NVEUCQEVHWQSZVNPLGJLSDQYBD9
616 IOTA stoken and sent to ESWVKJWXTGIWBOSEREELRFWCFKZDEIOXJGGQGBUOJUBAGVFGARFDFZRPPIYVSINMVMHURNXUBSYAXYV9Y

before these transactions are confirmed, they also attempt to send to these address:

ZGJRFJZLJGXYBAJENJCVXUDXXIZFKGGVKDGYNDBCCHCNIGFFFEQXFABDXDTEUCVIXLTHLTEWISINKJXWC
ZVSU9NHGSTDLWVINR9ELZEGGGKPRLSJPYJEBOELHKYFAPAAWIHXGBRIMSAOQBW9TQKYIGLBJGQXGVBIKW
OZFBGFDJXYLPHEPANP9ZZIGEPJENEKWYIE9APHRRXCBBSPGLJURTRKZEOHGNDFZNFCRVXAGUYGHFKFYSX
JOCJKK9ZHEKEVFNUQEOTTDFGF9YGCILVPCOTIDFZKRDRJXHP9YIXFRB9WRIXQ9XYHFIKFZCCUIDEHAKEZ

many thanks, lets hunt these mofo down

By Tigrafahrer - 22 Jan 2018

Lazyrudi - 22 Jan 2018

This would only work if e.g. your bank tricked you into buying shares by lying to you about the economic fundamentals of the company or something like this (this was implemented after the disaster with the Deutsche Telekom stocks where many people lost tons of money). Does not help with our case, sorry to say that.
By cryptodom - 22 Jan 2018

4.54.Gi stolen and send to:
LCDZEY9MGCUCB9PEYTWMVMZSXQVFMUZCDQHWBRVZQKYXXQORANTYZYDCCEEOWJGGOQIEXLQGWLGMBHRYXSMZJZKTGD
They are still on the above address
By cosmic - 22 Jan 2018

hacked for 9.3Gi, sent to:
VOC9TWBRQTEKAZOWCFDVAVJ9ILCLRWTGNWTHGKSNBHWCDNFLN9WDQCILQMXQNARCSISZDKWRRCMKPRK99NRNGGYYXD
By marciho - 22 Jan 2018

My IOTAs are stolen too. Lost 1.6 Gi (1663 Mi) to this adress:
XZ9OMFCMAPTMAUHPBFFNKSCXBD9TOTTIAUJRBRUNSJVDVRBQROCFOMHISYFHXNCDXYNIXFIIUAMFIMAKY

Transaction hash:
RRDELBFD9LVUHDVRYUHACBDOCZSOIBSSIOKF9XAREGLNYFBLTVYBB9HKCJ9OVUPAC9XLNBNDGRMEZ9999

Thanks...
By perryano - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Hi, I was hacked for 750 miota's. The address used also took another 20 or so accounts. Thank you

TRANSACTION HASH
SDAOIDQGZZUNPAP9FGOXEMFQYPHESSMFBZYLWMHSQOSJHOCUOMRQMMTOTO9MTFK9O9VYFHKJVGFD99999
IOTA ADDRESS
LCSPIPXZLJVNT9XUOEHEMXJVOFXOETELXTCNABPPODQPMYYRSDNKUTF9SEL9QLPSIXO9QAVPWOGHEICSD
AMOUNT
750 Mi
TIME
1 day ago
STATUS
Confirmed
TAG
LE

NONCE
AZMZ9BYJ9PJXFUIMHGMBAGNPDUF

CONVERSION
$2,074.54
WEIGHT MAGNITUDE
16

INDEX
0 / 4

BRANCH
EKQGUSVEWVO9FMPHKQWSC9TXYCTOJKRJDBFTBPCSLBKDVQKKXAMTJKBEGIKNAFWGYLTWJNPFEMPFZ9999
TRUNK
EBSLGOSVCIUGH9JBZQZJKKWSDWSGRZPDSOJCKUSWOOUXHAQJADWEQMLLGGFFSFXHHTXQD9ERRBDD99999
BUNDLE
CZQOKBFYGLDIFLCJBNJ9T9GRUROQIUPAFGKODBCUIA9OKDQAZOZU9ANJRGVRHQTJDOKJDPHERLNYXQDWD
By Pintamonas - 22 Jan 2018

237.5 Miota.....Los this is the thief 

JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
By Savinme - 22 Jan 2018

Hi,
My 161.5 mi was stolen and sent to this address
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
By ensja540 - 22 Jan 2018

Hi,

I have had 1.59 Gi stolen from my account.

Transaction hash was: RPSZFXRLLKBYALTNXVCNNDSNWMXU9BBUTYIHFANW9FHSY9JAPFU9AESEWZBJSYJJJFXBDXSXSQGU99999
Address was: ARBDBWY9DGEWXCCFWSXISLVOIPGR9AMVAHSZRXTKMMCEOT9BJACSVEKAKP9QIBZBEFHBVL9BOPABWDCUZRJBGLXJOC
By Amfcoin - 22 Jan 2018

Address for the blacklist 4 Gi: HGKLYH9VELSHTUV9TFUJLZ9OE9TDUELKPYUAE9IPILFBOKQR9NLRWPUBXPINZGCPUGWOHRZFFXGEPIHFYNGKWULRQA

Stolen from amfcoin
By Soeren - 22 Jan 2018

Thanks for your help!
My 1.8955 Gi were stolen and sent to:
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
By nerdonacid - 22 Jan 2018

The stolen amount: 2,038,959,000 
To see details: https://thetangle.org/bundle/MDYFCLEBPJFFNTBAEAKGKAEXVR9PBTELAAZWUWKILGSBTVN9QYKPFPZLOKOIACBBTBJZHNJFKWTYOQWOA

Addess of the thief:
YEWQRBJMLTDKNUFAOEBPY9CHINLWAYQWWSJHNY9BBPMCBEOHLYZIACTGTHZUDTAQMRWQFK9RKJ9TSRJIANTQGCOKBZ
HASH:
ZKBVLJ9HEICCLAQOHKSHAOJOLFLKICPVF9TWHGUUXTWMYPWQPQ9TCARBCZSGVAZBNTFYHAJYQMAJZ9999
By Petmirk - 22 Jan 2018

[Zitat]
[b]Winston - 21. Januar 2018[/ b]
Lassen Sie uns alle Opfer des jüngsten Diebstahls ermutigen, die Verfolgung von rechtlichen Schritten gegen den Dieb in Erwägung zu ziehen. Da diese Veranstaltung nicht in den Zuständigkeitsbereich der IOTA Foundation fällt, müssen die Nutzer entweder einzeln oder gemeinsam einen Rechtsstreit führen (oder zumindest eine gewisse Beteiligung der Strafverfolgungsbehörden). Es ist einfacher, wenn alle zusammen arbeiten.
EDIT:
Es liegt an Ihnen, die Opfer dieses Verbrechens, die Einzelheiten dieses Ereignisses den Behörden zu melden. Dieser Thread ist ein "Aufruf zum Handeln", was bedeutet, dass wir uns alle zusammenschließen müssen, um Details zu sammeln und uns gegenseitig durch den rechtlichen Prozess zu helfen. Um dies noch deutlicher zu machen, ist die IOTA-Stiftung nicht in der Lage, rechtliche Schritte einzuleiten. 


Das mag im Moment entmutigend wirken. Um den Prozess für alle einfacher zu machen, nutzen wir die Kraft und Breite dieser Community, um so viele Details wie möglich über die Situation zu sammeln. Hoffentlich kann dies dazu beitragen, den Umfang des gestrigen Ereignisses aufzuklären, und auch mehr von uns ermutigen, sich mit möglichen Rechtsstreitigkeiten zu befassen. Es könnte ein langer Schuss sein, aber lasst uns wenigstens versuchen, gestohlene Gelder wiederzubekommen und sicherzustellen, dass Gerechtigkeit gedient hat.
-----------------------------------------
Derzeit bekannte Details der Situation:
Hier ist ein wunderbare Zusammenfassung der Situation, geschrieben von Ralf -https://medium.com/@ralf/what-hapsed-last-night-on-iota-b6157ade1e03
Am 19. Januar 2018 verloren einige IOTA-Nutzer ihr Geld an einen unbekannten Angreifer.
Die Ursache, die dies ermöglichte, waren Benutzer, die sich entschieden, sich auf Online-Generatoren zu verlassen, um ihre Seeds zu erstellen.
Nach dem, was ich gehört habe, haben viele Benutzer, die ihr Geld verloren haben, ihre Samen bei iotaseed.io erstellt (aus offensichtlichen Gründen nicht hier verlinkt). Die Chancen stehen gut, dass die Leute hinter dieser und möglicherweise anderen Samengeneratoren eine Weile gesessen haben und Haufen von Samen gesammelt haben, obwohl die tatsächliche Anzahl der betroffenen Benutzer mir nicht bekannt ist. Die Tatsache, dass iotaseed.io zum Zeitpunkt des Schreibens noch online ist, könnte darauf hindeuten, dass die Seite selbst kompromittiert wurde und nicht die Leute hinter dem Dienst, der den Angriff ausgeführt hat.
Andere Orte, die über die Situation diskutieren:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Altes Forum postet die bösartige Webseite: https://forum.iota.org/t/iotaseed-io-now-also-for-genera-ing-paper-wallets/3915
Dieser Beitrag wurde erstellt von username: norbert   https://forum.iota.org/u/norbert/summary
Dies kann dieselbe Person sein, die ihr Konto von Quora gelöscht hat:https://www.quora.com/profile/Norbert-vd-Berg/log
und Reddit:https://www.reddit.com/user/norbertvdberg/
und github:https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain - ID: D503300000042872196-LRMS
Registrar Whois Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Aktualisiert Datum: 2017-10-15T20: 31: 54Z
Erstellungsdatum: 2017-08-16T12 : 11: 37Z
Registry Gültig bis: 2018-08-16T12: 11: 37Z
Registrar Registrierung Ablaufdatum:
Kanzler: Namecheap, Inc
Kanzler IANA - ID: 1068
Registrar Abuse Kontakt E - Mail:
Registrar Missbrauch Kontakt Telefon: 1,6613102107
Reseller:
Domain Status: clientTransferProhibitedhttps://icann.org/epp#clientTransferProbibistr
Name des Registrierten: WhoisGuard Protected
Registrant Organisation: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: nicht signierte
URL des ICANN Whois Ungenauigkeitsbeschwerdeformulars :https://www.icann.org/wicf/
>>> Letztes Update der WHOIS Datenbank: 2018-01-20T23: 12: 39Z <<<


Lassen Sie uns dem Austausch helfen, die IOTA-Adressen des Diebes, die derzeit die gestohlenen Guthaben enthalten, auf die schwarze Liste zu setzen. Ich werde diese Liste auf dem neuesten Stand halten, wenn mehr Leute Adressen posten:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520 + Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIIHHCLVWD9UM9WYKJMBORNYOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235,65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1,11 Ti Bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi Bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4,24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99,5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7,15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2,08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4,27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5,359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1,75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3,26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898,55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1,1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2,76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265,5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2,14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1,72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3,56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6,22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1,47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8,87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6,22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2,08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9,43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3,02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1,88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1,75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

jetzt leer
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Bitte
geben Sie die Adresse an, an die Ihr gestohlenes Guthaben gesendet wurde. Wir können die Börsen kontaktieren und versuchen, diese Adressen auf die schwarze Liste zu setzen, bevor der Dieb von IOTA in eine andere Währung wechseln kann. Die Zeit ist von entscheidender Bedeutung.

Lasst uns versuchen, die Details dieser Situation so gut wie möglich zu untersuchen. Wenn Sie beschließen, rechtliche Schritte einzuleiten, schreiben Sie bitte auch einen Hinweis für andere, die dies ebenfalls in Erwägung ziehen. Lasst uns alle gegenseitig helfen. Der Dieb wird damit durchkommen, wenn niemand etwas unternimmt.
[/Zitat]

In der Tat
By MisterBrot - 22 Jan 2018

People here need to GO TO THE POLICE!

This is a multi multi million dollar theft. It can easily be a billion dollar theft, because I suppose a lot of people still didn't realise that their IOTAs are gone! And lots of people won't post here.
If the amount is high enough, chances are good that police departments cooperate. I've been to the police yesterday and they told me, if there is some crime that several police departments have to deal with it will go higher up the rank and the federal police might take over investigations.

So GO TO THE POLICE!

Another reason: taxation! At the end of the year you'll have to explain what happened to your IOTAs, you'll probably don't want to pay taxes on them. So you'll declare them being robbed and want to set the minus of the robbery against your winnings. But do you really think your tax authority is going to believe you've been robbed of thousands of Dollars if you've not even reported it to the police?

So GO TO THE POLICE!
By Petmirk - 22 Jan 2018

[Zitat]
[b]Winston - 21. Januar 2018[/ b]
Lassen Sie uns alle Opfer des jüngsten Diebstahls ermutigen, die Verfolgung von rechtlichen Schritten gegen den Dieb in Erwägung zu ziehen. Da diese Veranstaltung nicht in den Zuständigkeitsbereich der IOTA Foundation fällt, müssen die Nutzer entweder einzeln oder gemeinsam einen Rechtsstreit führen (oder zumindest eine gewisse Beteiligung der Strafverfolgungsbehörden). Es ist einfacher, wenn alle zusammen arbeiten.
EDIT:
Es liegt an Ihnen, die Opfer dieses Verbrechens, die Einzelheiten dieses Ereignisses den Behörden zu melden. Dieser Thread ist ein "Aufruf zum Handeln", was bedeutet, dass wir uns alle zusammenschließen müssen, um Details zu sammeln und uns gegenseitig durch den rechtlichen Prozess zu helfen. Um dies noch deutlicher zu machen, ist die IOTA-Stiftung nicht in der Lage, rechtliche Schritte einzuleiten. 


Das mag im Moment entmutigend wirken. Um den Prozess für alle einfacher zu machen, nutzen wir die Kraft und Breite dieser Community, um so viele Details wie möglich über die Situation zu sammeln. Hoffentlich kann dies dazu beitragen, den Umfang des gestrigen Ereignisses aufzuklären, und auch mehr von uns ermutigen, sich mit möglichen Rechtsstreitigkeiten zu befassen. Es könnte ein langer Schuss sein, aber lasst uns wenigstens versuchen, gestohlene Gelder wiederzubekommen und sicherzustellen, dass Gerechtigkeit gedient hat.
-----------------------------------------
Derzeit bekannte Details der Situation:
Hier ist ein wunderbare Zusammenfassung der Situation, geschrieben von Ralf -https://medium.com/@ralf/what-hapsed-last-night-on-iota-b6157ade1e03
Am 19. Januar 2018 verloren einige IOTA-Nutzer ihr Geld an einen unbekannten Angreifer.
Die Ursache, die dies ermöglichte, waren Benutzer, die sich entschieden, sich auf Online-Generatoren zu verlassen, um ihre Seeds zu erstellen.
Nach dem, was ich gehört habe, haben viele Benutzer, die ihr Geld verloren haben, ihre Samen bei iotaseed.io erstellt (aus offensichtlichen Gründen nicht hier verlinkt). Die Chancen stehen gut, dass die Leute hinter dieser und möglicherweise anderen Samengeneratoren eine Weile gesessen haben und Haufen von Samen gesammelt haben, obwohl die tatsächliche Anzahl der betroffenen Benutzer mir nicht bekannt ist. Die Tatsache, dass iotaseed.io zum Zeitpunkt des Schreibens noch online ist, könnte darauf hindeuten, dass die Seite selbst kompromittiert wurde und nicht die Leute hinter dem Dienst, der den Angriff ausgeführt hat.
Andere Orte, die über die Situation diskutieren:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Altes Forum postet die bösartige Webseite: https://forum.iota.org/t/iotaseed-io-now-also-for-genera-ing-paper-wallets/3915
Dieser Beitrag wurde erstellt von username: norbert   https://forum.iota.org/u/norbert/summary
Dies kann dieselbe Person sein, die ihr Konto von Quora gelöscht hat:https://www.quora.com/profile/Norbert-vd-Berg/log
und Reddit:https://www.reddit.com/user/norbertvdberg/
und github:https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain - ID: D503300000042872196-LRMS
Registrar Whois Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Aktualisiert Datum: 2017-10-15T20: 31: 54Z
Erstellungsdatum: 2017-08-16T12 : 11: 37Z
Registry Gültig bis: 2018-08-16T12: 11: 37Z
Registrar Registrierung Ablaufdatum:
Kanzler: Namecheap, Inc
Kanzler IANA - ID: 1068
Registrar Abuse Kontakt E - Mail:
Registrar Missbrauch Kontakt Telefon: 1,6613102107
Reseller:
Domain Status: clientTransferProhibitedhttps://icann.org/epp#clientTransferProbibistr
Name des Registrierten: WhoisGuard Protected
Registrant Organisation: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: nicht signierte
URL des ICANN Whois Ungenauigkeitsbeschwerdeformulars :https://www.icann.org/wicf/
>>> Letztes Update der WHOIS Datenbank: 2018-01-20T23: 12: 39Z <<<


Lassen Sie uns dem Austausch helfen, die IOTA-Adressen des Diebes, die derzeit die gestohlenen Guthaben enthalten, auf die schwarze Liste zu setzen. Ich werde diese Liste auf dem neuesten Stand halten, wenn mehr Leute Adressen posten:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520 + Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIIHHCLVWD9UM9WYKJMBORNYOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORNIHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235,65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1,11 Ti Bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi Bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4,24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99,5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7,15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2,08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4,27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5,359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1,75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3,26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898,55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1,1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2,76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265,5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2,14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1,72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3,56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6,22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1,47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8,87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6,22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2,08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9,43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3,02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1,88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1,75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

jetzt leer
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Bitte
geben Sie die Adresse an, an die Ihr gestohlenes Guthaben gesendet wurde. Wir können die Börsen kontaktieren und versuchen, diese Adressen auf die schwarze Liste zu setzen, bevor der Dieb von IOTA in eine andere Währung wechseln kann. Die Zeit ist von entscheidender Bedeutung.

Lasst uns versuchen, die Details dieser Situation so gut wie möglich zu untersuchen. Wenn Sie beschließen, rechtliche Schritte einzuleiten, schreiben Sie bitte auch einen Hinweis für andere, die dies ebenfalls in Erwägung ziehen. Lasst uns alle gegenseitig helfen. Der Dieb wird damit durchkommen, wenn niemand etwas unternimmt.
[/Zitat]

In der Tat
By Saen7 - 22 Jan 2018

Amount:
200.145384 Mi

Sent to this Address:
CTORMCUAAMTBPK9XPSQEHJPARDRA9XTPUWC9EEARSWMZNTYAWXGLEVXVKQDXKBHARUFZEKBGSVKFJYHMZ

Transaction Hash:
UNVBMBTCRRHEGFFHTIFCSZKMRBGDIKYP9ARTGJMWXWPQKI9I9JDDTGL9XCVYLJIONCUBOCEYCLMZ99999


Thank you!
By nerdonacid - 22 Jan 2018

Btw the IOTA online generator where I created my seed was made by this guy => norbertvdberg@tutanota.com
the site is taken down because it said that it's not legit. He also deleted his github, reddit account (under name norbertvdberg).
What are the chances that he could be one of the thieves?
By Petmirk - 22 Jan 2018

Hallo
hier ist die Adresse von gestohlenes Iota
KQAHUBAXMMFSPEDVMWNPULRNKQOVX9FEIYVXLLLHRPNGPWBQQECZXDL9CMVWTJOJGBXNQZKRYTBUILSHZLUGXUMTZZ
DJHLLQBYDYTKGVOJRL9DCKYWVLVWAGAQSS9DQQMHVTSCDSYGHRXRXKPOELQZKNQENEKWCKMLHIPNK9XZW
DJHLLQBYDYTKGVOJRL9DCKYWVLVWAGAQSS9DQQMHVTSCDSYGHRXRXKPOELQZKNQENEKWCKMLHIPNK9XZW9EP9CWGUB
Grüße
By MisterBrot - 22 Jan 2018

nerdonacid - 22 Jan 2018
Btw the IOTA online generator where I created my seed was made by this guy => norbertvdberg@tutanota.com
the site is taken down because it said that it's not legit. He also deleted his github, reddit account (under name norbertvdberg).
What are the chances that he could be one of the thieves?

High. Question is if it's his real name. But he is very very likely involved
By ian_a - 22 Jan 2018

I was scammed too

5.74 GIota gone to MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD

I think it's a major issue if you want to adopt your technology to all people then you have to make sure everyone can handle it. This shows again, that IOTA isn't ready to go public.
I'm also very disappointet from the reaction of IOTA itself. It's just a shame.
By Tigrafahrer - 22 Jan 2018

ian_a - 22 Jan 2018
I was scammed too

5.74 GIota gone to MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD

I think it's a major issue if you want to adopt your technology to all people then you have to make sure everyone can handle it. This shows again, that IOTA isn't ready to go public.
I'm also very disappointet from the reaction of IOTA itself. It's just a shame.

What reaction? There is none. Hope this coin goes down!
By qwerty878 - 22 Jan 2018

Address thief: NNYOMYMLRYNOVLJBPHIIIQDTQHFXIVMTOYPTCHFIYUGBSCCUWBZYZYDVNZQMUZLIRNGGQNYPCBZNAPDQBNLPBDHETX
By qwerty878 - 22 Jan 2018

Another address of the thief: UXVZ9NGZZVRGAOAV9OWT9SZGLXI9DQGIIEMGIVCPUB9CTLWRSIRQNRLOQ9AHZXJRBDGVGCSZFDRPUOPVDIDFJODMOA
By zolli12 - 22 Jan 2018

Help! Inquiry can anyone help me? I had in my IOTA Ligth Wallet more than 3 Gi Iota. Now my balance sheet shows NULL. In the course it is with date 19.1.2018 a red arrow to the left (address is unknown to me), with the designation TTA Bundle, confirmed -3,3+ Gi two days ago. But I don't know of any transaction. Where are my IOTA, where can I get information? I do not speak English only German. Thank you for your answer.



Translated with www.DeepL.com/Translator

Hilfe ! Anfrage kann mir jemand helfen? ich hatte in meiner IOTA Ligth Wallet mehr als 3 Gi Iota. Nun zeigt meine Bilanz NULL an. Beim Verlauf es ist mit Datum 19.1.2018 ein roter Pfeil nach links (Adresse ist mir unbekannt), mit der Bezeichnung TTA Bundle, Bestätigt -3,3+ Gi vor zwei Tagen. Mir ist aber keine Transaktion bekannt. Wo sind meine IOTA, wo bekomme ich Auskunft?? Ich spreche nicht Englisch nur Deutsch. Danke für Ihre Antwort.
By hamijam - 22 Jan 2018

4.78408 Gi stolen by iotaseed.io and sent to Addr.: https://thetangle.org/address/MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
By TReijnd - 22 Jan 2018

The address where mine was send to:
LQ9STJCRQXTTIJAKZHRNGVBKYZW9VTKHSHQF9LFSII9UYOBDLSWYSUVXDZRGKCPDMJYFJDPXDEDXUAECAOBFKFKITB
By mcnutz - 22 Jan 2018

My IOTA were sent to this adress: 

YCCFXCZHIUR9DUZOAIFHJGJRMGWAHTKGAOORVIYJYAKEAOWXFFJMY9GJCFLNSUCRMXUQCEMXYUIHLOCRA
and then from their to this adress: 

RIFS9EBTHXQJCD9SFZXYZAATRSANAFGWPJKWVVFTJBUWRLF9N9YHCHTSNN9JQZGRCPURKAFIFLPHU9DJD
and then to this adress: 

NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD

By stoleniota - 22 Jan 2018

zolli12 - 22 Jan 2018
Help! Inquiry can anyone help me? I had in my IOTA Ligth Wallet more than 3 Gi Iota. Now my balance sheet shows NULL. In the course it is with date 19.1.2018 a red arrow to the left (address is unknown to me), with the designation TTA Bundle, confirmed -3,3+ Gi two days ago. But I don't know of any transaction. Where are my IOTA, where can I get information? I do not speak English only German. Thank you for your answer.



Translated with www.DeepL.com/Translator

Hilfe ! Anfrage kann mir jemand helfen? ich hatte in meiner IOTA Ligth Wallet mehr als 3 Gi Iota. Nun zeigt meine Bilanz NULL an. Beim Verlauf es ist mit Datum 19.1.2018 ein roter Pfeil nach links (Adresse ist mir unbekannt), mit der Bezeichnung TTA Bundle, Bestätigt -3,3+ Gi vor zwei Tagen. Mir ist aber keine Transaktion bekannt. Wo sind meine IOTA, wo bekomme ich Auskunft?? Ich spreche nicht Englisch nur Deutsch. Danke für Ihre Antwort.




Leider kannst du da nichts machen - sie sind gestohlen und unwiederbringlich weg.
By louloops - 22 Jan 2018

I lost 268 Miota on the 20/01/18 @4.07PM.
Here is the addresse where my IOTA were sent to: BLPVFPHBWJOFBEXNOCOWWCCENBVNSVPMZEWKEBWNQJZKNM9JJPATDLOYUOVSJAGJOHKZMLCUMJKMOHWVXERWYJPTJB.

Also please find the Hash: 9WVNIRULDSFUPKBIDJHFEHR9DNHXWFCTASIPYUPSJESILQYJBUMVUTWDKOGHLPFLINDKDUKBJCQYA9999

Not good news Sad

Cheers for the initiative
L
By laurentB - 22 Jan 2018

151Mi
YTJAXHWHZILUBVDKTPCGPNQJGJDBDDRPDVJKMAMQEVXSITKURZDAFZCFUT9WI9CHVBEFVMHULANFOMIFY

I kwow there are lost but good luck for the community and the job you do Smile
By TechnoGizzard - 22 Jan 2018

230 Mi stolen by iotaseed.io on January 21, 2018 00:24:40. It was sent to the following address: K9MWGM9QYZHEAAMPYINRAEKVMNCWEKLZQYWNRTHQJUHJIMZGZPILGOJJNMLSQUDFSTDXHKNXBNHUSKHUDWVCZQZY9
Transaction hash: JMTJCQEI9LTIZGIKIONEXYFZAFOGZBYDCAEVTTDLIZFVFAWGSRLSAE9SLEPSEKMPBTXSG9JIGKHSZ9999





By Lazyrudi - 22 Jan 2018

@zolli12 Gehe mal davon aus, dass die Kohle weg ist. Von IOTA können wir auch scheinbar keine Hilfe erwarten. Bis auf das Sammeln der Adressen habe ich bislang keine Aktionen gesehen. Gleich habe habe ich eine Telko mit CMS, einer der größten Kanzleien in Süddeutschland, um zu prüfen ob es Möglichkeiten für Regressansprüche gegenüber IOTA gibt. Wenn es neues gibt, werde ich mich wieder melden.
By ian_a - 22 Jan 2018

Tigrafahrer - 22 Jan 2018
ian_a - 22 Jan 2018
I was scammed too

5.74 GIota gone to MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD

I think it's a major issue if you want to adopt your technology to all people then you have to make sure everyone can handle it. This shows again, that IOTA isn't ready to go public.
I'm also very disappointet from the reaction of IOTA itself. It's just a shame.

What reaction? There is none. Hope this coin goes down!

I thought there was some sort of statement like : "it's your own fault you served your seed on a silver tablet".
The robbery is still going on and they just sit there ans watch it happen.. absolutely inacceptable.
By stesy - 22 Jan 2018

here is another one 
PQJYSELQJTEEYCXFOYCTWOMBC9HDZBJMVVHOGGYEAPCGSAOYEDEZHEYEPFDBYCDXJAZ9DNVIPHIJWTY99KFWRUUK9Z
By ian_a - 22 Jan 2018

Lazyrudi - 22 Jan 2018
@zolli12 Gehe mal davon aus, dass die Kohle weg ist. Von IOTA können wir auch scheinbar keine Hilfe erwarten. Bis auf das Sammeln der Adressen habe ich bislang keine Aktionen gesehen. Gleich habe habe ich eine Telko mit CMS, einer der größten Kanzleien in Süddeutschland, um zu prüfen ob es Möglichkeiten für Regressansprüche gegenüber IOTA gibt. Wenn es neues gibt, werde ich mich wieder melden.

Hi Lazyrudi, super vielen Dank auch für deinen Einsatz.
Solltest du hier etwas rausbekommen bitte unbedingt um Info. Vielen Dank!

By ABBASKAR - 22 Jan 2018

the followings are my balance transfered to below addresses
the question is why they withdraw the amounts exactly as they have been received in my wallets . looks like some reverse engineering.
1 GI IOTA
9WWDWLGC9MVAAQKANMHQSXHRXAGCPHSMPRPEZP9EOVKUJLKYCHPPFSGRIPXKHVNEWBIFLPWUG9JRUIZSWTPQKPEGKB
1 G IOTA
BXEEYUTTPFZBSUHEXDHGERFP9OFOIOKJGCCFFLOZJOG9NDDEFWBJUNWTVW9YXZNBRYRBEAALEXLYOPNQDMBJPKHEWW
58.5 MI IOTA
ESXIEZHHLEYZJLXBWRLYAJECSHBUMXGZMBINNAWNPLIFRIFGNDPHZKJOACZNEXRKQBKKHBMLDKLWWTQYDFOAQUHJSW
294.2 MI IOTA
HMJGVWELDDZDEGVSTOPZ9SUEFMZCYOBRRFIZDNERCELDDUFIDIAXTTWPGUFGQVDAWGJDGSKSJVPXQWUJBTHXNLBZHD
By stesy - 22 Jan 2018

also this one , please check and add   Admin

CGYTGBKLOJUZWVDXCKKZKDMSDVTEYDFGEDTWTMPMFJBRQPCUQSIACCXBDFZMBELYKQFTWYLVOPSQSJSEXFUKEYXSRW
By ian_a - 22 Jan 2018

stesy - 22 Jan 2018
as I immediately stated I generated my seed here https://iotasupport.com/gui-newseed.shtml  BE AWARE My BALANCE is GONE as well 

Well, looks like this site doesn't exist anymore -404- maybe someone recognized he made shit and tries to disapear his tracks?
By MisterBrot - 22 Jan 2018

stesy - 22 Jan 2018
as I immediately stated I generated my seed here https://iotasupport.com/gui-newseed.shtml  BE AWARE My BALANCE is GONE as well 

Luckily enough there are possibilities to look how a site looked like a few weeks/months ago thanks to web.archive.org

Your site on Dec 6th 2017:
http://web.archive.org/web/20171206124148/https://iotasupport.com/gui-newseed.shtml

This sentence on the iotasupport website on Dec 6th is shocking after all we've now read from the IOTA team how dumb we've been to use online sites:
"If you don't know where/how to run these commands, you can use an online generator"
It must be said, that the didn't recommend iotaseed.io, but that sentence is far away from "Never ever use an online site, you've handed your seed over on a silver tablet!"

By isidore - 22 Jan 2018

1.449 GI went on 19 January 0234 to:

GZ9YXGWVZQHYRAEORBSONYWNSYGWBLCO9BUNTMEWKHKCDVTZLOOHJ9YSQTIQORFSAFUNCDKRKWHTKWNGYOC9NWEGID

Also used iotasupport.com.
By Jack_het - 22 Jan 2018

Here is another adress he sent my 1.6 miota. MV9HMDKLIQDEYEZWTYZVOLDYI9LPOMHKTZOEKEUKTQONFO9NZZOJYPCIAZKOBZIPQFQUQXVQJCEPVEPKDYQZVEUTIX
By Jack_het - 22 Jan 2018

Here is another adress where my 1600 iota went

MV9HMDKLIQDEYEZWTYZVOLDYI9LPOMHKTZOEKEUKTQONFO9NZZOJYPCIAZKOBZIPQFQUQXVQJCEPVEPKDYQZVEUTIX
By Jack_het - 22 Jan 2018

Can we sue iota for his poor wallet and misinformation concerning the set up wallet?
By vasichkin - 22 Jan 2018

430.5 Mi gone to 
RUPPRPDPAIRORAITFD9HVOGBMKBLMMZIHGOYAEZLMY99EPIJEEQNGOIWGDKIAIUYKBWMVNRYEUFLJGNLDGPUQHDHTB
By MisterBrot - 22 Jan 2018

Jack_het - 22 Jan 2018
Can we sue iota for his poor wallet and misinformation concerning the set up wallet?

Depends on the country you're living in. I highly doubt that for Germany (but I'm no lawyer, so I wouldn't rule anything out). In the USA, however, I'd see better chances.

However, everyone, first GO TO THE POLICE! Whatever you wanna do later, if you haven't been to the police to report the theft, it makes things really complicated.
By Jack_het - 22 Jan 2018

My account is stolen



Hash YEQIBIUIBQAJTDIXZDOFTJRWQVBDWHKFZALGCEEGEGNIPBIZPRMEOWQUNKLUWAVKIZVWAUTHXRYO99999

1.6 Gi

MV9HMDKLIQDEYEZWTYZVOLDYI9LPOMHKTZOEKEUKTQONFO9NZZOJYPCIAZKOBZIPQFQUQXVQJCEPVEPKDYQZVEUTIX

-1.6 Gi

CERRXNKNLWRFFVFBDTFTVHTRHUIDSS9ZGONQMCDCAU9IEWBQGOGAAGKNZQFNDRWJIUTYMHQI9HGYWYGLCQRRPTYAAX


0

CERRXNKNLWRFFVFBDTFTVHTRHUIDSS9ZGONQMCDCAU9IEWBQGOGAAGKNZQFNDRWJIUTYMHQI9HGYWYGLCQRRPTYAAX
By xhabit - 22 Jan 2018

here is my stolen Transaction ... 

https://thetangle.org/transaction/MJZQOLBXKUXREIIHQDLJIYR9NIUXADODXENQGKQSQHMFRCELNKALXZIQSSBJCOXJOKOOGGGEAPIBA9999

1,1Gi are gone ... 
By src - 22 Jan 2018

VXKXKPAMRPKJKBJFEGEXSXVRPJLBMUBPUIJQLI9FGWAUPHJTGBCMPVRI9AOPOOQLNSYEGZHYOCOGGRSBCNIVFDGAZD

10.3  GI

https://thetangle.org/transaction/RMSGYHMQXKDVIB9PLLYATLQRWLQPFUIXPPAGKMRCCWGNNUPYUUPWNUDHBCUDMBWIKOLZRWP9QV9PA9999
By DenisDub - 22 Jan 2018

my 20,97 Gi was sent to the address HPHQTRANKNABYOWJLS9OTAMRABRBQAAQA9LMIKVAZBNXUMAATDFPPWWJGGVQAOQJZJ9OAJHEQU9XPERPXJCVXIEQRW

Mine address was ZTBUUJLSVEPAUESGVYOSVGGUWAMHVDYLZJFPAXQSYYBRVTJAWYETDZABWAKSVWDJTJKLO9UAFNHMJJHSXUKYRDJNAB

it was on 19/01/2018 02:23

Thanks

I'm agree with a class action or a fork !!
By Lazyrudi - 22 Jan 2018

Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities.
By Halap - 22 Jan 2018


19/01/2018 2:52

1.52 Gi were sent to:

YEWQRBJMLTDKNUFAOEBPY9CHINLWAYQWWSJHNY9BBPMCBEOHLYZIACTGTHZUDTAQMRWQFK9RKJ9TSRJIANTQGCOKBZ

Thanks!
By dgensert - 22 Jan 2018

same here:

5GI each:
from UFDBFCPZA9LBPH9UDVWTQHB9OHO9FJXHRNQONXHUFCIVGXXWWNQGYCIP9THJJNGGAMIF9KLDNCOFSUGTCCMF9OXVUW to UABWCOAOUM9MKDZPXSGEEEKTO9RUSROSPJWMPXZQBHWMRI9BZQKPRTTUPGOWGHUKQBRNWDHFOGLRUWTOWVRDLMYMOY

from AEFRMRQHCNNCLLZSYHMPDZX9NIZRZDLAYQCLNXVWYUXNQPFKWYWZIAFW9PZRPIH9DFITIGLHWKERAFOMC9YQDBEYKD
to AFUKOEVPJLMVCSEAQIFZDXARCS9CEBGAHNWMJZQHQP9TLCLKUCFUSQZOZFGZKSLZSO9KNSPRKUOVMRVSXFVIETDGQW

from NGGTDTWDWFDELVLUTZAPXAMJSDZL9MAZROOAUQISNGLHVFVFBOFVGIKQZTEUJIJKYNDSOFQGTRXWJZLVBWQFMYOXJZ
to GLQUHWHUQQRTJLTGWFWNTROJGUDVWDUMOMGMQKXUKEAVVURRQCUHIJMSSSBEKFBBPXQ9HZEIBVDEVBT9ZQZPWISPBW

from U9TZGLGGOYBEACLCXBWIVAXJJNUCOTR9YLQHWBKPOKFLBMJ9GEKOGDDVMGBWYTX9YJCIOM9ZSGWZHX9C9U9CFSRRNC
to XXRQ9DBYHCGEPOOAIEBEBVSSVTYJEJBEOXWDNNFCPDBYKZFGG9KPBEWVGCUUDZNBTAVXGOOHNSRJUGDOWITQOGEBZ9
By joelgus - 22 Jan 2018

5.3 GI 

From: JQTKULYLUWAWOPIURRGVGOQAYVUHPSMAUGLIRQGUGUW9NZPCSREAKXUPCEYPIUHPVJEXACXJDYAEDJRVA
To: YGCCEMWOJGEXFKHCWNNIGMFPIZDOYJYIJAOUAFGJVQUVVVODFOSFXYPWPI9UJNGQZXSXJVUPQQUKQFEWDX9YUZHCWD
Then To: EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
By Marshall07 - 22 Jan 2018

Alexa - 21 Jan 2018
@Marshall07 This address has many pending transactions. Please check if yours is pending too (don't know which it is). If it's pending, you might be able to still safe your funds if you're quick about it! Please, follow instructions here: 
https://forum.helloiota.com/9100/To-everyone-posting-with-stolen-balances


Thanks @Alexa, but unfortunately my transaction is confirmed. In my wallet I saw 2 transactions: one at 4:00 pending and then one at 18:00 confirmed. And the Balance=0  Sad

This is the specific transaction:
https://thetangle.org/transaction/AGDHGNEQAEYFO9JWTRIIIVXTKHUASLYNODBCWLRFJDDJGUFJLDTZJWEVDERCQSUIQAFAH9XV9TEYA9999


By ezeee - 22 Jan 2018

56.7 gIOTA were stolen out of my light wallet on January, 19.
I used iotaseed.io, cause i read the advice on the iota-site to use online generators ('if you dont know how to generate a seed)! And i changed some numbers!!!
I'm so f... angry :-(( Separated from my wife, loose half of my pension, sold our house and now everything's gone. Could kill..

Here's the transaction:
https://thetangle.org/transaction/ZVPEVADAUMVFLENBFKKPMC9QPFXGJMLVMHQCQCS9UNS9ILQ9PWMLCQIOHCRIFMISEAIDNXQSESJNZ9999

The address my IOTAs sent to:
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA

Lets make a petition or something like that to reset the tangle to a point before thousends of us early adopters were robbed!! 
By OpenMedia - 22 Jan 2018

Looks like way more than just 4 million US$ worth of IOTA were stolen. And reports just keep coming in.
By MisterBrot - 22 Jan 2018

This is probably one of the biggest robberies in crypto currency since Mt.Gox. i don't understand why the media still don't report! This is f..in big news! Probably because the IOTA team tries to keep the topic down, but that won't work forever.
By OpenMedia - 22 Jan 2018

Lazyrudi - 22 Jan 2018
Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities.

Yes, that is what I said earlier. It is a huge design flaw in their system as there is no authorization (password at minimum) at all. People including myself were stupid to put money into this crappy flawed project. And we got burnt. Everybody should be warned about this and no one should buy IOTA until this is eventually fixed.

There is no info from the devs, no warning, no help, no nothing. Typical German way of fixing problems, sit them out and do as if nothing has happened
By niteC - 22 Jan 2018

-    2.3 Gi:

JBEFKJZAMUZUYZOWKMSX9BKAYMZPCWWKRHQDGIJHHVL9NXARTFYRVJJUVQNHQGHM99BEPULISPCVYBHXCFZTRDL9EW


-    1.8 Gi:

GHWQCDMSIGFISWBRZDLZLLFPYLPNKESLXHMWIMW9ZHOVSIOOCSY9YQNATAE9FLXEIJPATCXDBIINSRWECYNAUAUIP9
By AL15 - 22 Jan 2018

Hi,

814.804229 Mi gone to: KRDTGTERZCIXCCAE9ERSLFD9UWIYSKKXALVUTDVAOGZLNOOTKVHRWWTNRPFPTWSQMRCYR9HGMCSATQUPYQOOLZELAW

https://thetangle.org/transaction/J9YOTZLWPGDREDFAQPJZXRJQ9CMZNZOCBAPATIJYLK99LQEAMZGRKKWFGEEUSCUWGQLCHGBQGZLV99999

I really hope the IOTA Team finds a way to confirm and get back the stolen Mi as all transactions should be transparent and based on the timing and maybe a claim process it should be possible to identify the incorrect transactions.

THANKS
lg
AL
By 468stolen - 22 Jan 2018

Hi Guys,

first post....

So. like username says - 468.813938 MIOTA were stolen.. on 01/19/2018

From my walletadress:  XKHNFSSGKSXZGASVPMNAPSZTVJLOICDMUEFIVLZQBBFY9PFPCXPGFNMOAKWLXKPOLVGHNJAJCLBTCKHOALRSP9QLWW
by the wallet Adress: WDLLKDTZTOFGQRTBUSTZOSZQYSUEBFQGOVFLHTTRSTZTRXDTTKRVG9I9YUE9VTUIE9NRWGSLTHWIUTPRXXYXRCJHTX

With Hash: HJMCIODLHKGJOEPUEBZEEGZPJVJBICQPJZNQOVUOMDEYFZZM9ZPZJZCRKGNGMAMDZBMNHHDTNOMO99999,

And somehow he has this IOTA adress too (IOTASear.ch):  999999999999999999999999999999999999999999999999999999999999999999999999999999999A9BEONKZW

Currentyl the thief has 9098.884937 MiIOTA...Growing... just look in the pending List at his/her wallet... this has to stop.

Sucks..

Is tracking things like IPs possible with IOTA?
By miner_97 - 22 Jan 2018

My  544 Iota (Miota) were stolen and sent to: BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
The transaction is: https://thetangle.org/transaction/DZZFCX9YAMCHFZGDN9XIWSHKGKKTDCEK9CUECDTWNRBMUFGRSMXLMVWTKCLEBQDAAUGAGDXHFHMV99999
By Benyamin - 22 Jan 2018

HI

This is the address of the person who stole my money
FKBGLDFVBCBTQIX9QXKMDSPKWXO9FNATQWZHGAFNMNJVSYRKM9QSSEQYSEYEXQHQFSGVOSJTFQGNAOPDCNHVKPEEFD
pls see attach file

By Lazyrudi - 22 Jan 2018

From another attorney I got the information, that Ethereum got forced by the investors and lawyers to reset the system to an earlyer stage - before the fraud (hard-fork). Would this be possible with IOTA Tangles?
By Bear_OO_ - 22 Jan 2018

Lazyrudi - 22 Jan 2018
From another attorney I got the information, that Ethereum got forced by the investors and lawyers to reset the system to an earlyer stage - before the fraud (hard-fork). Would this be possible with IOTA Tangles?

Maybe....but then we / they should hurry up before the snapshot on 28th! At this time all historys are gone from the wallets. So make a screenshot and everything else for further file action.
By t7890 - 22 Jan 2018

My 78.2 MIOTAs were stolen too. But I did not use any online seed generator!

Receiving address: SXUMDYWTFWCUYEEOQGUXUP9CQA9NGUZQDTJBJCOSOKYRRDIFMLPEIBBQD99EZCBVQHPHVJA9ACTVBXGOZQNRXTIFSA

By vsreyes - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Could somebody track these guys?! They're trying to take my 330.9 Mi. It's still pending!  RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
By Bear_OO_ - 22 Jan 2018

t7890 - 22 Jan 2018
My 78.2 MIOTAs were stolen too. But I did not use any online seed generator!

Receiving address: SXUMDYWTFWCUYEEOQGUXUP9CQA9NGUZQDTJBJCOSOKYRRDIFMLPEIBBQD99EZCBVQHPHVJA9ACTVBXGOZQNRXTIFSA


Now it´s getting really interesting!!!
By 468stolen - 22 Jan 2018

vsreyes - 22 Jan 2018
Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.

Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Could somebody track these guys?! They're trying to take my 330.9 Mi. It's still pending!  RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB

Hi, do you believe your IOTA has been stolen? If so, you likely used a malicious online seed generator to generate your seed. If the stolen transaction is still pending (it'll say 'Pending' underneath the transaction in your wallet history), URGENTLY send your entire balance to an address in a different seed. Check here for more details. If the stolen transaction is confirmed, then unfortunately there is nothing that can be done.


By ilker - 22 Jan 2018

FPIBCILPJFRZAQRTSKNOVONZIKPIQEHQQIGL9MKYEDFAJXXOWNMVACKQDSFLCREYP9EYJJKG9BYIRLAUWJNNNMJTYD

this adress tooo...????
By t7890 - 22 Jan 2018

When you have a look at the tangle explorer, all transactions have one thing in common:

The signature/message contains all 9's

"Signature/Message 99999999999999999999999999999..........."

Maybe someone can filter out these transactions.
By stay_tuned - 22 Jan 2018

1.9+ Gi stolen
HASH
WQGXCLQFUXHEFBBERSHBTIAZLBQZGSIHRLZRLJGVIMWQPGIOMJSIRQIPKH9TQZTMZKRWWMGWNSRK99999

ALCBFBQ9BQYDSSWQHJLKFENDITLBYFXHMBSWFYVAZWGYJKEZGSOZJXE9BXKQZNOHVSRNQGUMDLIGGSIL9HTFSEIGCA
By libert010010 - 22 Jan 2018

These people also stole all my IOTA-token (475,02+ mi)...

HASH:SDOPULDIMSUNVASKLDMWPPRXEKTSXPPBSIRQQIELUMTCRNLFQIBVFPRJIMKTIGDTSHPMLCFAEDYHA9999
RECEIVING ADRESS: ERZFDGJYXTGUJ9SE99AFOFAXRSVFXVNKNBNIOLAUHRSYRALCSSBJOJOVB9BPQBYQTBRVNTDBZIAQSWYUXWGBLYCSHY

TRANSACTIONS:
January 19, 2018 03:45:54 - 3 days and 16 hours ago -9.5 Mi
JPTQZGTLLOBJOUJXTBOTNCOYDMTKS9EMANZ9TRNFZQGQUZAUKFKCBLVTAFUVDUURVVQCXGMNHTPCA9999
Confirmed

January 19, 2018 03:45:54 - 3 days and 16 hours ago -165.32 Mi
LNIQVWZQRJPBWNKWZGCXVHRANSUDSKLCKCTVAAHOXMF9YNPJCQBTOMXZSHE9JFEFSESEHGQGEYTFZ9999
Confirmed

January 19, 2018 03:45:54 - 3 days and 16 hours ago -300.2 Mi
ZZPOVMDU9CFMGRXQSQWWMLETDLHRJ9HKKBZHQDZFPBAXJGMPBHGAETZKFSJHQQHKODDDMKXZAMHY99999
Confirmed

Has anyone addressed the authorities so far? Do you think they can do something?



By Winston - 22 Jan 2018

Lazyrudi - 22 Jan 2018
Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities.

@Lazyrudi
"Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities."

It feels like a bunch of people are still aimed at the wrong target. The IOTA Foundation isn't the bad guy here. They didn't steal funds. The energy needs to be focused on catching the criminal -- the guy who actually came up with the scheme, built the websites, and then stole balances. It's apparent that some people are frustrated with the IOTA Foundation, but going after them does us no good.

The idea of this thread is to collect details on the thief so that everyone can go to their own authorities and figure out how to proceed with this information.
By adi_d_87 - 22 Jan 2018

998,5 MI stolen

sent to: QUYCDCGDQQJQBXBYIGDLQFQQEYSNU9EALXPFMTUU9BLFAHETMQMLLINDMHEAFSMXRR9VGEVWVNFEHAHJDRQSXCQJJD ....on 2018.01.22 9:27 confirmed

Hash: XYERJWGSTUDDMGZUVDNEOPSLVWWIJNNJSFEGNJYFCUTASWCHOKFKTHUNGKSBSCRWBCDIRCAQOQMOZ9999

THX !!
By Tigrafahrer - 22 Jan 2018

Winston - 22 Jan 2018
Lazyrudi - 22 Jan 2018
Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities.

@Lazyrudi
"Have just talked to the lawyer. Prospects are bad. IOTA can't be sueed, because they didn't forwarded us to the seed generator. The domain of "iotaseed.io" is registered in the USA. To the domain owner you might come through https://www.namecheap.com/support/knowledgebase/article.aspx/9196/5/how-and-where-can-i-file-abuse-complaints and https: // complaint.ic3.gov but that should be done by an American victim. You also can not even hold IOTA accountable for doing nothing at all. It is just a bad business practis, but not a crime. Only the way through the media might help other investors to avoid this crime in the future. And perhaps go to the police, to avoid trouble with the tax authorities."

It feels like a bunch of people are still aimed at the wrong target. The IOTA Foundation isn't the bad guy here. They didn't steal funds. The energy needs to be focused on catching the criminal -- the guy who actually came up with the scheme, built the websites, and then stole balances. It's apparent that some people are frustrated with the IOTA Foundation, but going after them does us no good.

The idea of this thread is to collect details on the thief so that everyone can go to their own authorities and figure out how to proceed with this information.

Sorry, that´s crap (don´t mind, I´m frustrated). But it´s much more promising to sue a foundation that has encouraged users to use extern seed generators knowing the risk of fraud. And AFTER the great theft has happend they play the three monkeys (don´t see, hear, speak).

I think there would be ways to fix the disaster (snapshot or something, I`m no technician). By not doing so or at least explaining why that would be impossible they do everything to make people feel absolutely ignored.

So my chances to pursue a existing company/foundation/whatever are way better than getting some phantom criminal. I spoke with my lawyer, we will file a law suit against the IOTA foundation. I will keep you informed. Good luck chasing your mystery criminal Sad
By gerstat1 - 22 Jan 2018

HMCTIZTDONLZUAAMEBIFHNLXQDFENUZZ9RCHOI9SAUEWSOTCYIGIMHXPWM9OVTNOERUZPSRJ9LDYN9RFA
^ address in which my iota was sent to

16.855 Gi
By stay_tuned - 22 Jan 2018

stay_tuned - 22 Jan 2018
1.9+ Gi stolen
HASH
WQGXCLQFUXHEFBBERSHBTIAZLBQZGSIHRLZRLJGVIMWQPGIOMJSIRQIPKH9TQZTMZKRWWMGWNSRK99999

ALCBFBQ9BQYDSSWQHJLKFENDITLBYFXHMBSWFYVAZWGYJKEZGSOZJXE9BXKQZNOHVSRNQGUMDLIGGSIL9HTFSEIGCA

hash
ZDNRABT9XM9CJJMJNBOSAXZJGGZUYBCPFHQUPVYFKRZSDHLCLYTQRDQSLKHUZXQLRZETAVVXBMSD99999
By AngryPanda - 22 Jan 2018

999.4 Mi stolen
20/01/2018 08:23

Sent to YWYYOXSTN99BUCQGXLITLSABX9QUCWSCTZEVCKSDJLTGLHZIHGPGLEVWUAQIZUUURHZFQBZJYBWDJABDCX9CG9OWNB

Hash: MQMZNICVZTOHCTOTUK9KIZULOEPIBCZNA9SWQOVUAZIYAYMIPLZWJMNMTKBBMWIWTEQIBVDNX9YE99999

By kubiczech - 22 Jan 2018

Address: SHQGRZTMSELZSUVHWWZQGSDVWXOAQ9YWYWEDQSMPNXMUTASFSZWJDKDZXNENJJHHUSHPKWBTBQJIJQNVDXYDULVGQC

Amount: 63.4+ Mi

Hash: NSTUCQFGTBZAUDEOLTBKCGUBM9TVQAHGEOZWVXPPDZCQWKOMKLJUUUSFMU9JXATGHMGOHZM9DHCDA9999

13/01/2018 13:47

NO SEED generator used!!!

contact me on ej.akub@seznam.cz if you can help, please.
By adamdrzazga - 22 Jan 2018

Hello guys,

These people also stole my IOTA-token

-3.0 + Gi ( -2.6 Gi -300 Mi - 55 Mi) GC 9UOWNHHYPEDTHXCBEKGLGORURZYJFOUZKZYMVBNRFYNWJZFJOGNB9UIPFNLWANVCSNW9GLJXENGT9LTOBCMLPBEEUA

HASH: RNYIKNIMKEAGQWQHZCSBLAUXEUFQCNXMA9JWJOJNMKQHLOWZHLNBBXJLCQ9ZTOAYPW9LMFFADQBT99999

- 2.6+Gi MMAJPSFJCDFJIPFUYGYEPSLWUGQVP9SMTAGGQRWYZ9VHQPVZODAGYTMFKIPKPOLLYJONJROB9HP9HUBHDQNFXKJIL9
- 300 Mi RFZQWLQRGMAIOTZSDOKGGQXLOHGPMWQPVLTLMNKAVODIERHRQIFDLKXXAGVHUUWU9FLYTHEALEWWMHBOWSHAMFWAUD
- 55 Mi ULXCGRVWGFNUFXSRJRGKVJJUXYBWNTIORQAMQJQGVMDQYVOOOC9FUVHHVJIPBQ9ZYKLEOK9WFM9KBMMPXCANVZMXHY

the beginning of the theft: 19/01/2018 02:30
the end of the theft: 19/01/2018 08:03

Please contact me on aadrzazga@gmail.com if you can help, please.

By gs1960 - 22 Jan 2018

100Mi stoled on 20/01/2018 from my address
BXZIGGDVGMVOWLSSISNWSCRAANCDHXXDYGTPYLVFVBAVGWJJZCIGP9VMBWDVTCRWBLEZHDFUPRRIKMAWYBESFKPNCZ
By Winston - 22 Jan 2018

kubiczech - 22 Jan 2018
Address: SHQGRZTMSELZSUVHWWZQGSDVWXOAQ9YWYWEDQSMPNXMUTASFSZWJDKDZXNENJJHHUSHPKWBTBQJIJQNVDXYDULVGQC

Amount: 63.4+ Mi

Hash: NSTUCQFGTBZAUDEOLTBKCGUBM9TVQAHGEOZWVXPPDZCQWKOMKLJUUUSFMU9JXATGHMGOHZM9DHCDA9999

13/01/2018 13:47

NO SEED generator used!!!

contact me on ej.akub@seznam.cz if you can help, please.

@kubiczech
This is something separate from what everyone else is experiencing. It looks like the online seed gen thief conducted the theft on January 19. Your balance was stolen on January 13, and you say you didn't use an online seed generator. This likely a different situation altogether (compromised computer or too short/simple of a seed).

This sort of calls into question the authenticity of the long list of addresses that the community has compiled so far. The list becomes much less useful if different events are all lumped into the same list. Hopefully some other members of the community are able to go through the addresses and do some forensics though.
By captain - 22 Jan 2018

500Mi
stolen from KHDIXZCXJEPJGHMLVGSJEWADYUZ9UUIWRVEFANMXFKEPAHAUXG9OODNFOYHWFLFYKNSUEJDP9DMXYKDRDFIFICFBFD
Theft Tx IDIZHPSHSJVOUZMUKJREXPPNPKXDAWXMJHAXX9UFKUNTTQIXPFSVTQEARLYBSHCOOMARIIUUUBRKZ9999
Theft Account AOCIBNIKQVTPVPWDZJHJGJDABVCQ9ZLQJCMQIGTBLDFTLRWQR9DTJHAKK99SGHVOLJYUHTAHISL9QKNWULGYNPRSD

226,98Mi
stolen from LYOVJFOSWFMPSRSLXIXLOPWASMBZ9DVPBJCJKVVUQNKTCGUVGJHBPFSVUVKSGUEJSUFGIBVXDVNNMCMNYQQEJVRBRD
Theft Tx: EU9FUG9TWZSMWVXKKSYGRN9PLUAFSEDWVYTAQCRGNLJNBZNTZNKJ9BTYHRYJZQUOUADIVATVGSENZ9999
Theft Account: GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD

Good luck, learned a lot :-(
By RPBMedia - 22 Jan 2018

67.3 Mi stolen to this address:
VFULZIKXFYSMM9WTSXEJKPEVPMJXFKRQXXYEZNVSTOYVMNIRCEECNSUQ99VZYBUAWIIVKRAU9DUBYKWBYXT9YQYRBX

366.7 Mi stolen to this address:
IEOO9BXAAQMJCTDNQRNUDTZXNQHGSHVXVPWDYQYFSLARCJPAWPMZ9XWLAQGTSGUTFCPFPMGJQGVBGKWFDVHWVAXHU9

2 Addresses... make them count.

It's hard to put into words how pissed off I am right now...
By Tigrafahrer - 22 Jan 2018

Wow, look at David Sonstebos reactions at twitter. To say that they are unprofessional would be an understatement. Maybe anyone here should reconsider investing in a crypto currency if the founder acts like a 12 year old bully on the schoolyard. If someone has nothing to hide wouldn´t he react professionally and keep calm?

There´s a saying in German "getroffene Hunde bellen", which is roughly "hit dogs bark" in English.
By vsreyes - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

330.9 Mi were just stolen to this seed: EXHALENCFIY9MRWETZALGIVJKPQYLDMIRSOXNXD9RTWXZJOFRGCZOUFLKEDQVFTYC9ZPBLQYJ9SUJILKDXBVQUYNGW
By nimsel182 - 22 Jan 2018

5.669522453 Gi stolen from:
QJTLVSPFIKBXNKY9YAOJ9IQWOUNTPECWKAWVCDQORWHMYNDTZDORG9AXMUALXBIRYEQAAC9XGTUGTPYMBYWYOCDJOW
Send to:
UVKRBOWCBW9ZZBZRRSGZJHWWCIFKVAOXOE9DHJHZRBGDQGVVVCZGBDZOZORX9BBFWQQSAUVNHIUHHOVAD
By jacksparrow88 - 22 Jan 2018

I was a victim as well! Clearly changing a couple of characters from the generated key was not enough for security. 

I got 2.0+ Gi stolen from NGVBJIKGJFSJFDMVYSVMAUMJIBOQ9ZTTWXHLXA9D9OYRJINXYBPCCUQSRJGEN9NYYZCKODTHSHKZTIP9ZJQPVUXFIA and it was sent to:
MXENGOPQCXRNNMFFLJCZWWMXZUBVKGXUOYUKXVDWKDSWFVYFWXCETYATTONMMMVJLYJWBEXTZ9FEJZILCPVAKXJMYC

Looks like this quantity, along with others (9.82G toal), was then emptied in transaction : 
XZXWQOJQBKCWVOQ9TMMURUAZOCOLHTOATIOKY9FHZLIKAAGRYEWJSJYDLNLQDQCDGPYEGAUOTG9ZA9999

I don't see the address on the list so far. Can this be added to help with the effort?

Realistically, is there a chance that the IOTA foundation can restore the ledger to pre-hack? Has anyone spoken to legal counsel about this? 
By MMkrypto - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.
My bundle detail
17.GI
Hash/ BNS9YQ9CLSBVZZZNHIPPJESHJWIBOJHTYUKAAZAGTMSGQNAIIHSJKCSMYJUWMOGLQGYBIOGOUTVB99999
17.3 GI / (DA) KBAPJHOGFIM9RKYPEJDDDPQK9SZYVLATOZKJEFZQJYLNWOXZRVLSABVZDX9FRMWAEPFGBQFQMHAMLHORDDZIAMXEVC 
(-9.5MI) / KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA 
0/ KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA 
(-17.3 GI)/ GIXMBCOPQ9SMRIATL9SMMIDUQJUAG9B9IOP9JQJYCDAETGBOJSFP9JWKDGQFWJLGQU9FVTNBBMWKXIKPYG9CSIUAAC 
0/ GIXMBCOPQ9SMRIATL9SMMIDUQJUAG9B9IOP9JQJYCDAETGBOJSFP9JWKDGQFWJLGQU9FVTNBBMWKXIKPYG9CSIUAAC
t
By MMkrypto - 22 Jan 2018

MisterBrot - 22 Jan 2018
Jack_het - 22 Jan 2018
Can we sue iota for his poor wallet and misinformation concerning the set up wallet?

Depends on the country you're living in. I highly doubt that for Germany (but I'm no lawyer, so I wouldn't rule anything out). In the USA, however, I'd see better chances.

However, everyone, first GO TO THE POLICE! Whatever you wanna do later, if you haven't been to the police to report the theft, it makes things really complicated.

what is your suggestion? go to the police and?
By joelgus - 22 Jan 2018

Hate to say it, but police action or 3rd party lawsuit has zero chance of helping. Too many different countries involved. 

The Foundation needs to take a closer look at anything they could do to assist. They were able to tie up investors funds when there was a security flaw in their system.

They are quick to point their finger and say "Investors fault." I wouldn't be surprised if someone on the Foundation is involved in this attack. Coincidence that it happened as soon as investors got their funds back from the Foundation? Coincidence that they allowed 3rd party sites to be linked to their Reddit Page? Coincidence they are 100% certain it's the 3rd parties website's fault and not their own?

 
By nimsel182 - 22 Jan 2018

Realistically, is there a chance that the IOTA foundation can restore the ledger to pre-hack? Has anyone spoken to legal counsel about this?

As I posted above, I'm also affected of the theft. I don't think that we can expect help from the IOTA foundation, because they advise against using online seed generators. However, does anyone know wether there is already an official statement from the IOTA team?
By Winston - 22 Jan 2018

nimsel182 - 22 Jan 2018
Realistically, is there a chance that the IOTA foundation can restore the ledger to pre-hack? Has anyone spoken to legal counsel about this?

As I posted above, I'm also affected of the theft. I don't think that we can expect help from the IOTA foundation, because they advise against using online seed generators. However, does anyone know wether there is already an official statement from the IOTA team?

@nimsel182
This official blog post was just published:
https://blog.iota.org/the-secret-to-security-is-secrecy-d32b5b7f25ef
By jutroncoso - 22 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

My 115.9 Mi where stolen and send to this adress
DYUKZTVVJCYJHI9EGDNIGPWVQIJEHCUSPBKPOHLYEDIGDTETC9JHCDVQPLDEILQYJLTUJAEHQUFLDKGHAXIULQWFWX
My wallet adress is :
IUTS9NDHQRCHJBGJUIRQWJQQCBZANHCO9MUITPOHHTWIPXTMAVIWMNQUFAUHTGONYDIWLJQQCIWMKOFXDAMXXOUHOB
By Nandon - 22 Jan 2018

Lost 3.9 GI to this adress
DSFWIU9HZ9RXYNVQQCQVMMLOPTOVINIOFPFRJBWMH9KGZJMJQSVVPNUXSOCTYYLQ9FMMOJQKSMEVRCQPXIGIYIZVGC

The funds are still there
https://iotasear.ch/address/DSFWIU9HZ9RXYNVQQCQVMMLOPTOVINIOFPFRJBWMH9KGZJMJQSVVPNUXSOCTYYLQ9FMMOJQKSMEVRCQPXIGIYIZVGC
By nimsel182 - 22 Jan 2018

Winston - 22 Jan 2018
nimsel182 - 22 Jan 2018
Realistically, is there a chance that the IOTA foundation can restore the ledger to pre-hack? Has anyone spoken to legal counsel about this?

As I posted above, I'm also affected of the theft. I don't think that we can expect help from the IOTA foundation, because they advise against using online seed generators. However, does anyone know wether there is already an official statement from the IOTA team?

@nimsel182
This official blog post was just published:
https://blog.iota.org/the-secret-to-security-is-secrecy-d32b5b7f25ef

Thanks for sharing! However, I expected a little bit more into the direction: "We're going to take a deep look into what happened to our community...". Or like: "We're going to take a closer look into the fact, that #1 result on google - search string "iota seed" - was an official looking scam site, which existed over a couple of months." :thinking:
By MMkrypto - 22 Jan 2018



Is this the same guy in the website, Aran Cauchi?

https://www.facebook.com/aran.cauchi


https://forum.iota.org/u/arancauchi/summary

By MMkrypto - 22 Jan 2018

By MMkrypto - 22 Jan 2018

I found the same picture in the facebook account. 
check it out. Is he really the guy who is related to this hacking?
so then, can we take any action for this?
checking the facebook page, believe or not, he is a ph.d candidate ....
By Seven - 22 Jan 2018

Add me to the list of losers...

SEED generated @ iotaseed.io

Stolen IOTA: 616.037 Mi

Time: 18 JAN 2018 @ 2252

Stolen From: NNMMYSYBXZDQHMGFXABJRDKFBSMUPOASMOAQYEYHJAQAYYNMEKHMUESYKXCAFCLQ9FZNTXWOVOVU9PWKXGVLJNSGPA

Sent To: RMHGFYXVBFFZUKITDQXBMNOWSFDREDAVNZJOUOIELEKJDQVKTXRGKAHYPERERUWDXZYOQVLVQOQBAEXBXMKSALGC9Y

Hash: EKI9ODKTWTIV9KPBYQT9TOVYW9EDLTNLGHOIXRMXA9IWNKJEXVGLQ9GOQRFCNGRSUTMBNNE9ULSWA9999

Several attempts made to send to this address after funds already stolen:

WDLLKDTZTOFGQRTBUSTZOSZQYSUEBFQGOVFLHTTRSTZTRXDTTKRVG9I9YUE9VTUIE9NRWGSLTHWIUTPRXXYXRCJHTX
By MMkrypto - 22 Jan 2018

His profile is from Tasmania not from USA. He might have used a VPN service to disguise his location.
 
By nimsel182 - 22 Jan 2018

MMkrypto - 22 Jan 2018
I found the same picture in the facebook account. 
check it out. Is he really the guy who is related to this hacking?
so then, can we take any action for this?
checking the facebook page, believe or not, he is a ph.d candidate ....

Well...
This is his original post:
https://forum.iota.org/t/paper-wallet-generator-for-iota/2360
... linking to this one:
https://arancauchi.github.io/IOTA-Paper-Wallet/

The link to iotaseed.io was posted by a profile named "Salomon". I don't see a clear connection between the guy you mentioned in your post and the hack.
By MMkrypto - 22 Jan 2018

MMkrypto - 22 Jan 2018
I found the same picture in the facebook account. 
check it out. Is he really the guy who is related to this hacking?
so then, can we take any action for this?
checking the facebook page, believe or not, he is a ph.d candidate ....

His profile is not from USA but Tamania near Australia. Any action can we take? Is he really the guy who is behind this?
By MMkrypto - 22 Jan 2018

nimsel182 - 22 Jan 2018
MMkrypto - 22 Jan 2018
I found the same picture in the facebook account. 
check it out. Is he really the guy who is related to this hacking?
so then, can we take any action for this?
checking the facebook page, believe or not, he is a ph.d candidate ....

Well...
This is his original post:
https://forum.iota.org/t/paper-wallet-generator-for-iota/2360
... linking to this one:
https://arancauchi.github.io/IOTA-Paper-Wallet/

The link to iotaseed.io was posted by a profile named "Salomon". I don't see a clear connection between the guy you mentioned in your post and the hack.

https://forum.iota.org/u/arancauchi/summary
this page I got from Winston's post shows iotaseed.io ad. why? if he was a computer science phd candidate, he might have known iotaseed.io to be fake.
but he clearly includes the ad multiply into his website. why?
By txkun - 22 Jan 2018

Hi all,

I'm sorry for your loss, as I have fallen to this scam as well. I lost 129.674794 Mi to this thief.
Transaction details:
https://thetangle.org/address/DNJKXFMGZIJFQVBCOK9FK9LGECUUIOFOBRZYCOCIFGRUELJBTHUUWOWQ9QDYNSSRXVOIBQXSBQLLONJSY
Address that MIOTA were sent to: DNJKXFMGZIJFQVBCOK9FK9LGECUUIOFOBRZYCOCIFGRUELJBTHUUWOWQ9QDYNSSRXVOIBQXSBQLLONJSYNWZHDDGUC

Hope this will help you to catch this thief.
By adi_d_87 - 22 Jan 2018

MMkrypto - 22 Jan 2018
nimsel182 - 22 Jan 2018
MMkrypto - 22 Jan 2018
I found the same picture in the facebook account. 
check it out. Is he really the guy who is related to this hacking?
so then, can we take any action for this?
checking the facebook page, believe or not, he is a ph.d candidate ....

Well...
This is his original post:
https://forum.iota.org/t/paper-wallet-generator-for-iota/2360
... linking to this one:
https://arancauchi.github.io/IOTA-Paper-Wallet/

The link to iotaseed.io was posted by a profile named "Salomon". I don't see a clear connection between the guy you mentioned in your post and the hack.

https://forum.iota.org/u/arancauchi/summary
this page I got from Winston's post shows iotaseed.io ad. why? if he was a computer science phd candidate, he might have known iotaseed.io to be fake.
but he clearly includes the ad multiply into his website. why?

there are more folks who are excited by the iotaseed.io site:
https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
By MMkrypto - 22 Jan 2018

https://www.facebook.com/aran.cauchi/about?lst=100000037395684%3A100005079487559%3A1516662847

Check this out. as you scroll down little bit, you will see the same picture of him posted on the iotaseed.io
By MMkrypto - 22 Jan 2018

MMkrypto - 22 Jan 2018
https://www.facebook.com/aran.cauchi/about?lst=100000037395684%3A100005079487559%3A1516662847

Check this out. as you scroll down little bit, you will see the same picture of him posted on the iotaseed.io
Alan Cauchi
https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915


Image may contain: 1 person, outdoor
By MMkrypto - 23 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

My stolen IOTAs 17.3GI not empty wallet confirmed at the date of 1/19

Confirmed
Hash/ BNS9YQ9CLSBVZZZNHIPPJESHJWIBOJHTYUKAAZAGTMSGQNAIIHSJKCSMYJUWMOGLQGYBIOGOUTVB99999
DA) 17.3 + GI  KBAPJHOGFIM9RKYPEJDDDPQK9SZYVLATOZKJEFZQJYLNWOXZRVLSABVZDX9FRMWAEPFGBQFQMHAMLHORDDZIAMXEVC
-9.5MI  KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA
0       KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA   
- 17.3+ GI     KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA
0GIXMBCOPQ9SMRIATL9SMMIDUQJUAG9B9IOP9JQJYCDAETGBOJSFP9JWKDGQFWJLGQU9FVTNBBMWKXIKPYG9CSIUAAC      

Pending 
Hash/ BNKZIKLIQJBALRXOO9QCR9VKUFEFIYH9LACYSNWOXNEAY9QXHSIQNVUJJNCTVCAXCHDA99QGKMRBZ9999
NB) 17.3+ GI     KBAPJHOGFIM9RKYPEJDDDPQK9SZYVLATOZKJEFZQJYLNWOXZRVLSABVZDX9FRMWAEPFGBQFQMHAMLHORDDZIAMXEVC
-9.5 MIKALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA     
0    KALDQEACIPNWLQLIGXBWPWPNVGVSINTPSBMYFBBFLAJQT9KLQHDOBRAFHAJGFSHAURUHPGIZWDFKZKUODSISQQIXAA
-17.3+ GIGIXMBCOPQ9SMRIATL9SMMIDUQJUAG9B9IOP9JQJYCDAETGBOJSFP9JWKDGQFWJLGQU9FVTNBBMWKXIKPYG9CSIUAAC       
0     GIXMBCOPQ9SMRIATL9SMMIDUQJUAG9B9IOP9JQJYCDAETGBOJSFP9JWKDGQFWJLGQU9FVTNBBMWKXIKPYG9CSIUAAC

THanks

By RJG - 23 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

I also was one of the victims, in my case the funds were sent to ?
By Ataurus27 - 23 Jan 2018

My 886.2Mi was sent to:

address:  ENNKBZQWPOHNOJBVRZPNAIW9KJQBVVCQQHOCCOH9ZPUT9DVEHAAMEGEKGBCRLYZSEJTICHVNAWVPCCVDBWVQTNF9VZ

tx hash:  NDVRYZSCXVDAUBKTJTVVLP9KKQFJEVGJPKTJGD9FTIHWAYMRSWGLYICXDRJ9QVMNUIGHXKRZ9JNGA9999

By RJG - 23 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and Reddit: https://www.reddit.com/user/norbertvdberg/
and github: https://github.com/norbertvdberg
Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

It looks like my money was sent to ?

19/01/2018 19:44
KZAIAMAELZSWBSCROVHFVMJZZPYWXRJTZNXODAZYLIVYABPMGPGNTMDQOJWAJML9LQYBHVYXSRVYCVBRYYFSBYWIEB
PAFAZQSVPVPUZZEBOUPBZXOTFZI
By Winston - 23 Jan 2018

MMkrypto - 22 Jan 2018

@MMkrypto
To the best of my knowledge, Aran has always been a super good and involved person with the IOTA. community He made a paper wallet generator. The bad actors probably modified his code for their seed gen. 
By Justgotscammed - 23 Jan 2018

576.6 Mi
RGCO9JAKEYANJQNBYAXIWXIMUYZKHWJEHQ9TMHCRZBJZMHTNHMYHDHW9SCDHOZNYMRNLZDECP9ZQRUJQXXTA9JNIWX 576.6 Mi
By MMkrypto - 23 Jan 2018

Winston - 23 Jan 2018
MMkrypto - 22 Jan 2018

@MMkrypto
To the best of my knowledge, Aran has always been a super good and involved person with the IOTA. community He made a paper wallet generator. The bad actors probably modified his code for their seed gen. 

How so? My understanding as I went through the iotaseed.io looked very well organized and well managed, and also operated by well knowledged individual (s).
As I found the facebook page and his location at the university of Tasmania, I decided to sent an email to the university provost to acknowledge her about this situation. With some attachments of your post, forum helloiota, some snapshots, my email includes some but brief information about what happened. I like to see how the provost deputy respond to this situation. This is a very bad situation for both IOTA growth and investors. I still hope a way to find the thief, retrieve everyone's fund, and IOTA to become a stronger community though it may sound stupid to you. 
By Justgotscammed - 23 Jan 2018


Spewing!!!  I understand that I shouldn't have trusted the seed generator but when you actually follow the advice offered by IOTA at the time and get scammed it leaves a sour taste.
576.6 Mi
RGCO9JAKEYANJQNBYAXIWXIMUYZKHWJEHQ9TMHCRZBJZMHTNHMYHDHW9SCDHOZNYMRNLZDECP9ZQRUJQXXTA9JNIWX
https://thetangle.org/transaction/UNCSHSADADTCBWQMFV9KMZSHWOTWEJMGRPMFLEUDAUAADNPJBAQWPAUSNVRNYCXMRVNHXHJSUHMV99999
By MMkrypto - 23 Jan 2018

Winston - 23 Jan 2018
MMkrypto - 22 Jan 2018

@MMkrypto
To the best of my knowledge, Aran has always been a super good and involved person with the IOTA. community He made a paper wallet generator. The bad actors probably modified his code for their seed gen. 

He was clearly related to the site iotaseed.io shown in the record of forum iota. He promoted online iotaseed generation and paper wallet. So then why IOTA team and people who support IOTA I met on cryptocompare iota forum blame and judge users who got seeds through online generator? If Aran was a super good and involved with IOTA but promoted iotaseed and paper wallet, why our users are blamed now because we got seeds from there? this is very confusing ;;
By Winston - 23 Jan 2018

MMkrypto - 23 Jan 2018
Winston - 23 Jan 2018
MMkrypto - 22 Jan 2018

@MMkrypto
To the best of my knowledge, Aran has always been a super good and involved person with the IOTA. community He made a paper wallet generator. The bad actors probably modified his code for their seed gen. 

He was clearly related to the site iotaseed.io shown in the record of forum iota. He promoted online iotaseed generation and paper wallet. So then why IOTA team and people who support IOTA I met on cryptocompare iota forum blame and judge users who got seeds through online generator? If Aran was a super good and involved with IOTA but promoted iotaseed and paper wallet, why our users are blamed now because we got seeds from there? this is very confusing ;;

@MMkrypto
I understand that there's a lot of frustration, but I disagree with the characterization that one group is blaming another group. The official correspondence so far only lays out facts and offers advice on how to avoid these situations in the future. There's no ill will toward, or derision of victims in this scenario (at least as far as I can tell).

Anyway, a lot of people made all sorts of different open source seed generation programs. This is a nuanced situation, so we can't even be sure that the guy who ran the website in question was the bad actor. It could easily have been a separate entity that hacked the otherwise benevolent website, ya know? Anybody can use anybody else's open source code, and there was a ton floating around. Also, the entire community was endorsing these seed generators *with the caveat that people should use them offline and change multiple characters after the seed was generated, warning that this exact scenario was likely to happen. Again, this is not to place blame on anyone, but I think it's important to avoid a blind witch hunt. The goal at this point should be to gather information and present this case to the appropriate authorities in your locale.
By MMkrypto - 23 Jan 2018

Winston - 23 Jan 2018
MMkrypto - 23 Jan 2018
Winston - 23 Jan 2018
MMkrypto - 22 Jan 2018

@MMkrypto
To the best of my knowledge, Aran has always been a super good and involved person with the IOTA. community He made a paper wallet generator. The bad actors probably modified his code for their seed gen. 

He was clearly related to the site iotaseed.io shown in the record of forum iota. He promoted online iotaseed generation and paper wallet. So then why IOTA team and people who support IOTA I met on cryptocompare iota forum blame and judge users who got seeds through online generator? If Aran was a super good and involved with IOTA but promoted iotaseed and paper wallet, why our users are blamed now because we got seeds from there? this is very confusing ;;

@MMkrypto
I understand that there's a lot of frustration, but I disagree with the characterization that one group is blaming another group. The official correspondence so far only lays out facts and offers advice on how to avoid these situations in the future. There's no ill will toward, or derision of victims in this scenario (at least as far as I can tell).

Anyway, a lot of people made all sorts of different open source seed generation programs. This is a nuanced situation, so we can't even be sure that the guy who ran the website in question was the bad actor. It could easily have been a separate entity that hacked the otherwise benevolent website, ya know? Anybody can use anybody else's open source code, and there was a ton floating around. Also, the entire community was endorsing these seed generators *with the caveat that people should use them offline and change multiple characters after the seed was generated, warning that this exact scenario was likely to happen. Again, this is not to place blame on anyone, but I think it's important to avoid a blind witch hunt. The goal at this point should be to gather information and present this case to the appropriate authorities in your locale.
I understand your points; yet I am still unsure of some things yet. how can his profile along with his online iotaseed promotion via his website be explained? If he did and was super involved in IOTA , his project actively informing online iotaseed generation via his website would be at least known by IOTA team. So then, putting the finger on users blaming solely for our online seed download seems simply scapegoating. Yes, as you said, "anybody can use anybody else's open source code," but this seems not a key point in this situation now because the IOTA team seems to set users to feel guilty, considering and describing us users stupid and ignorant. 
Using witch hunt in this situation sounds totally improper at all because I am not sure of who is hunting or who is hunted. With many users hurt and suffering with their losses only because they invested their hope, expectation on IOTA, I dont think we users deserve to be losers. The only thing we can focus on as community nown should be searching for ways to support and recover if possible. Regarding the guy Aran, if he was not the one bad guy, he should at least recognize why he was called out to this turmoil. I am not sure if IOTA foundation is now seeking to help its users as they have been supportive of its growth, but I hope i hope. Have I missed any supportive news for users with losses released from IOTA? thanks.

By BIGLEE68 - 23 Jan 2018

@Winston   @Rajivshah


BLACKLIST NOW PLEASE !

RSMSVJSQCM99ABSXTCSMHMDA9BHTWRXOHSZRYCEURSINMFAZHNARAWJPOGCPLWFUZFIJKHPTEEUVICUXDSIVHHDTB9

WHY IS EVERYBODY SO CALM ABOUT THIS , I WANT THERE BLOOD !

By BIGLEE68 - 23 Jan 2018

FUMING!!!!

FOLLOWED ADVICE FROM IOTA.ORG TO USE RECOMMENDED WALLET WITH GUIHUB, AND GENERATE SEED THROUGH WALLET,
IS ANYONE GOING TO EXCEPT RESPONSIBILITY FOR THIS !!!
By Winston - 23 Jan 2018

@BIGLEE68

"WHY IS EVERYBODY SO CALM ABOUT THIS , I WANT THERE BLOOD !"
Everyone here is super upset. We started this thread so that we can all gather details about the situation and help each other through the legal process of recovering the stolen funds. Many other people in this thread have offered to team up and figure out what needs to be done next. Nobody else is going to fix this for us, so jump in and do something. Nothing will come from being aimlessly furious.
By OpenMedia - 23 Jan 2018

Also check this one out and gather together

https://bitcointalk.org/index.php?topic=2791245
By Tokero - 23 Jan 2018

@Winston

Stolen ammount: 3.9995Gi
https://www.iotasear.ch/transaction/AMIO9EVFTEEUJ9NUZHODEGSIPPVRAEGDKBLSSRWKQHJSSLDKEFNTZZFYCRTUTQPKUDXXJHAXKKOF99999

was sent to
https://www.iotasear.ch/address/POVFMBADWK9IMETXLGDWTKJODZBKPABYONFALFSKTFV9LK9D9RJKFSUDJREPTLHEMKOAXKOJRXQ9MGDCCLFNXQVMF9

and finally sent to
https://www.iotasear.ch/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX
By rose - 23 Jan 2018

Thanks for organizing this, Winston.

These are the wallet addresses and the amounts of MIOTA that was stolen from me. I'm not sure which
addresses are the ones you need to track here so I have just included my originating wallet addresses:

Wallet 1: 462.85Mi
SQBIELOACSOXBEVGWPIXYWZGYLCOLJIVWIZKZKNUSKNLCGVB9GGJFUPMECTINBHZVYCASZYNTZWXZSTVBKLPQHFFOB

Wallet 2: 727.46Mi
QMDSYKWMGEYOPGOTPLSPMLZCIKLTKQXWKPXCUBZKPZ9TXRE9LIATEE9FHTGESGMJCTFMAQUWSGIRNQKMD9EZRLZJIC

Wallet 3: 410.04Mi
XGMAOXZJJMFPHDDENHMAYUUXWKIXOPO9CIBWJPZTDXZXDVL9WARLBJZRVBHXTAOGQHLDVTA9WIYUV9M9ZKQFBRWJCW

Wallet 4: 601.85Mi
KUWWWQYRFHRJQRTLNDL9VQXGLZKDZYHNYQGNVWOWNZFJ9DKBKHHBJKCSOEMAYJCIUFIAPPQLWUH9JMBG9PFREKCWBD

Wallet 5: 548.91Mi
AKKROUHLKIUDLVEFOCBNLFXYQWN9ANBHTEDJYIHZLEJB9BVALPJRTSPEIDEZEXUGJPQCHARGQDX9ZWI9CVKQRP9FXZ

As someone previously mentioned, the iotaseed dot io site was recommended by many sites and could have  also been listed on one of the main iota sites. I was reading on I believe reddit about people using the script offline as well and still had their wallets compromised so maybe all of the seeds generated were pregenerated to begin with?

btw- You can obtain a copy of the seed generation website from the internet archive here: https://web.archive.org/web/*/iotaseed.io  Should be useful for any legal pursuits.

On that archive site at the bottom there are two donation addresses, one which is a bitcoin address. I'm not sure if they are this thieves addresses or the github author they are linking to. There may be more addresses that changed on different snapshots of the website in the archive or possibly other useful data.
By Winston - 23 Jan 2018

rose - 23 Jan 2018
Thanks for organizing this, Winston.

These are the wallet addresses and the amounts of MIOTA that was stolen from me. I'm not sure which
addresses are the ones you need to track here so I have just included my originating wallet addresses:

Wallet 1: 462.85Mi
SQBIELOACSOXBEVGWPIXYWZGYLCOLJIVWIZKZKNUSKNLCGVB9GGJFUPMECTINBHZVYCASZYNTZWXZSTVBKLPQHFFOB

Wallet 2: 727.46Mi
QMDSYKWMGEYOPGOTPLSPMLZCIKLTKQXWKPXCUBZKPZ9TXRE9LIATEE9FHTGESGMJCTFMAQUWSGIRNQKMD9EZRLZJIC

Wallet 3: 410.04Mi
XGMAOXZJJMFPHDDENHMAYUUXWKIXOPO9CIBWJPZTDXZXDVL9WARLBJZRVBHXTAOGQHLDVTA9WIYUV9M9ZKQFBRWJCW

Wallet 4: 601.85Mi
KUWWWQYRFHRJQRTLNDL9VQXGLZKDZYHNYQGNVWOWNZFJ9DKBKHHBJKCSOEMAYJCIUFIAPPQLWUH9JMBG9PFREKCWBD

Wallet 5: 548.91Mi
AKKROUHLKIUDLVEFOCBNLFXYQWN9ANBHTEDJYIHZLEJB9BVALPJRTSPEIDEZEXUGJPQCHARGQDX9ZWI9CVKQRP9FXZ

As someone previously mentioned, the iotaseed dot io site was recommended by many sites and could have  also been listed on one of the main iota sites. I was reading on I believe reddit about people using the script offline as well and still had their wallets compromised so maybe all of the seeds generated were pregenerated to begin with?

btw- You can obtain a copy of the seed generation website from the internet archive here: https://web.archive.org/web/*/iotaseed.io  Should be useful for any legal pursuits.

On that archive site at the bottom there are two donation addresses, one which is a bitcoin address. I'm not sure if they are this thieves addresses or the github author they are linking to. There may be more addresses that changed on different snapshots of the website in the archive or possibly other useful data.

@rose
Thanks for this info. I've added the last two paragraphs in your post to the OP. Hopefully it's useful to people.
By rose - 23 Jan 2018

MisterBrot - 22 Jan 2018
stesy - 22 Jan 2018
as I immediately stated I generated my seed here https://iotasupport.com/gui-newseed.shtml  BE AWARE My BALANCE is GONE as well 

Luckily enough there are possibilities to look how a site looked like a few weeks/months ago thanks to web.archive.org

Your site on Dec 6th 2017:
http://web.archive.org/web/20171206124148/https://iotasupport.com/gui-newseed.shtml

This sentence on the iotasupport website on Dec 6th is shocking after all we've now read from the IOTA team how dumb we've been to use online sites:
"If you don't know where/how to run these commands, you can use an online generator"
It must be said, that the didn't recommend iotaseed.io, but that sentence is far away from "Never ever use an online site, you've handed your seed over on a silver tablet!"


THIS is what frustrates me the most out of all of this.
I used the online seed generator because I read the same thing at the iota site!!

It should be pretty easy to track the majority of these transactions considering IOTA is only available on a few exchanges to begin with.
By rose - 23 Jan 2018

Bear_OO_ - 22 Jan 2018
Lazyrudi - 22 Jan 2018
From another attorney I got the information, that Ethereum got forced by the investors and lawyers to reset the system to an earlyer stage - before the fraud (hard-fork). Would this be possible with IOTA Tangles?

Maybe....but then we / they should hurry up before the snapshot on 28th! At this time all historys are gone from the wallets. So make a screenshot and everything else for further file action.

But even after a snapshot wouldn't all transactions still be viewable on a tangle explorer like thetangle.org ?
Can you clarify why all history would be gone?
By vagethegx - 23 Jan 2018

Hi guys,

100,4 Mi were sent to:
NMT9MMETWRCKTZNXLAS9ZXCVPKDJJCNLMFZCAFLOWUVXUMKCPUWHY9RJFVQTXBRAD9ZU9UP9QMDXGVEDBDWETAOWMTIBMJHKCVZTXVMGQNCDZDQBKXKJZ
Hash:
DYQINEGGNTJMWHNPUEURWDJLPMMUQVRAMXQCYKVRMYY9FPKMLRMXPAUFZMJLOGQAUYMWSATIROWE99999
By rose - 23 Jan 2018

A couple other thoughts for everyone:

1. If you know of previous forum posts, social media threads/accounts, reddit, official sites etc that included communication from anyone at these online seed generation sites, the closed down github, sites like iotaseed, save copies of those web pages. If you had links or bookmarks that are now showing a "not found" error, try to use archive.org to pull up an archive copy of the websites. Save from there. It's likely these thieves have left trails. This all could be of use later for legal issues and even to help the iota foundation with investigation and hopefully some kind of recovery of users funds.

2. I noticed some people mentioned that even after changing a few characters in their generated seed or using offline seed generation that they still had their MIOTA stolen. What immediately comes to mind here is compromised nodes. Any tech guys out there, please investigate this. If a compromised node can some how lead to accessing and controlling wallets, this is a huge disaster on top of an already huge mess.

3. Contact exchanges, IOTA is only available a few places, these thieves are probably trying to dump/sell it all as fast as possible. The less they can sell the better for everyone, especially if there is some kind of recovery process that the iota foundation comes up with. Hopefully. 
By rose - 23 Jan 2018

More references to save and investigate related to iota seed io site:

https://forum.iota.org/u/norbert/summary

https://forum.iota.org/t/secure-iota-seed-generator-comments-welcome/3747

https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915

The bitcoin and iota donation addresses that were listed on ioaseed.io on that last website snapshot on January 3  2018: 
BITCOIN:  1BXaRLe4LMfYjH4vUSJxCy1eEBDxJqeHpc

IOTA:  HCBLOBZQXDUWXKFJJXNKWQGSAFFNRY9NBBJGYAANWFIIJMGWZWUFVFIWYPIAFYVWBIEFBV9CQRDOOUU99LWEXAHWEW

btw, I just verified they are the same donation addresses that were listed on the site as the earliest page snapshot, which is Oct 31 2017:https://web.archive.org/web/20171031191834/https://iotaseed.io/

Might not have anything to do with the the thieves, but it's here to investigate.
By Winston - 23 Jan 2018

stesy - 23 Jan 2018
I already asked on the official discord channel but seems no one care to answer so I will try here 

snapshot will happen in couple of days , what will happen to all hacked accounts ?? I mean 0 accounts will be deleted from the tangle  right , means  all hacked 0 account will be deleted and there will be no more evidence for further  investigation  right ???

@stesy
This is a good question. The current ledger will discard all addresses with 0 value, but many (read: most) full node operators keep a copy of their old dbs. The two major tangle explorers also both keep old dbs that go back many snapshots. So we'll still be able to trace all old transactions back through the tangle
By Winston - 23 Jan 2018

rose - 23 Jan 2018
More references to save and investigate related to iota seed io site:

https://forum.iota.org/u/norbert/summary

https://forum.iota.org/t/secure-iota-seed-generator-comments-welcome/3747

https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915

The bitcoin and iota donation addresses that were listed on ioaseed.io on that last website snapshot on January 3  2018: 
BITCOIN:  1BXaRLe4LMfYjH4vUSJxCy1eEBDxJqeHpc

IOTA:  HCBLOBZQXDUWXKFJJXNKWQGSAFFNRY9NBBJGYAANWFIIJMGWZWUFVFIWYPIAFYVWBIEFBV9CQRDOOUU99LWEXAHWEW

btw, I just verified they are the same donation addresses that were listed on the site as the earliest page snapshot, which is Oct 31 2017:https://web.archive.org/web/20171031191834/https://iotaseed.io/

Might not have anything to do with the the thieves, but it's here to investigate.

@rose
Awesome job, Rose. I've added the two addresses to the OP as well
By ezeee - 23 Jan 2018

Thats a shame! IOTA-people told me on their site to use an online-seed-generator, so i did and lost 56.7 gIOTA on january 19., and now they don't care, don't respond and seem to do nothing to us, who invested money and faith in this great idea. Is there nobody with relationships or contacts to the makers? Is there no sign from IOTA, that they are planing to do anything? I'm from germany and already wrote to Dominik Schiener on facebook, no response till now. Can we make it a reddit-thread they can't ignore?
By OpenMedia - 23 Jan 2018

That's the German way of fixing problems. They sit it out and do as if nothing has happened.
By rose - 23 Jan 2018

Winston - 23 Jan 2018
stesy - 23 Jan 2018
I already asked on the official discord channel but seems no one care to answer so I will try here 

snapshot will happen in couple of days , what will happen to all hacked accounts ?? I mean 0 accounts will be deleted from the tangle  right , means  all hacked 0 account will be deleted and there will be no more evidence for further  investigation  right ???

@stesy
This is a good question. The current ledger will discard all addresses with 0 value, but many (read: most) full node operators keep a copy of their old dbs. The two major tangle explorers also both keep old dbs that go back many snapshots. So we'll still be able to trace all old transactions back through the tangle

I'd hope the Iota Foundation would also keep a copy of all tangle transactions for all snapshots, that would be foolish to just dump everything, especially in situations just like this.
By tyro - 23 Jan 2018

Winston - 21 Jan 2018
Let's encourage all victims of the recent theft to consider the pursuit of legal action against the thief. Since this event is outside the scope of the IOTA Foundation, users are either going to have to individually or collectively proceed with litigation (or at least some sort of involvement of law enforcement authorities). It's easier if everyone works together.
EDIT:
It is up to you, the victims of this crime, to report the details of this event to authorities. This thread is a "call to action", meaning that we all need to join together to gather details and help each other through the legal process. To make this even more explicit, the IOTA Foundation isn't in a position to pursue legal action. 


That may seem daunting right now, so to make the process easier for everyone, let's leverage the power and breadth of this community to gather as many details about the situation as possible. Hopefully this can help elucidate the scope of yesterday's event, as well as encourage more of us to get involved with potential litigation. It might be a long shot, but let's at least attempt to retrieve stolen funds and ensure that justice served.
-----------------------------------------
Currently known details of the situation:
Here's a wonderful summary of the situation, written by Ralf -- https://medium.com/@ralf/what-happened-last-night-on-iota-b6157ade1e03
On January 19th, 2018, some IOTA users lost their funds to an unknown attacker.
The root cause that allowed this to happen was users who chose to rely on online generators to create their seeds.
From what I’ve heard, many users who lost their funds created their seeds at iotaseed.io (not linked here for obvious reasons). Chances are, the folks behind this and potentially other seed generators have sat tight for a while, collecting piles of seeds, though the actual numbers of users affected are not known to me. The fact, that iotaseed.io is still online at the time of this writing might suggest that the site got compromised itself, and its not the folks behind the service who ran the attack.
Other places that are having discussions about the situation:
https://bitcointalk.org/index.php?topic=2791245.0
https://steemit.com/iota/@madmac/iota-thousands-of-wallets-compromised-and-funds-stolen

Old forum post advertising the malicious website: https://forum.iota.org/t/iotaseed-io-now-also-for-generating-paper-wallets/3915
That post was made by username: norbert   https://forum.iota.org/u/norbert/summary
This may be the same person who deleted their account from Quora: https://www.quora.com/profile/Norbert-vd-Berg/log
and deleted their Reddit account: https://www.reddit.com/user/norbertvdberg/ 
and deleted github: https://github.com/norbertvdberg

btw- You can obtain a copy of the seed generation website from the internet archive here: https://web.archive.org/web/*/iotaseed.io Should be useful for any legal pursuits.
On that archive site at the bottom there are two donation addresses, one which is a bitcoin address. I'm not sure if they are this thieves addresses or the github author they are linking to. There may be more addresses that changed on different snapshots of the website in the archive or possibly other useful data.
The bitcoin and iota donation addresses that were listed on ioaseed.io on that last website snapshot on January 3 2018:
BITCOIN: 1BXaRLe4LMfYjH4vUSJxCy1eEBDxJqeHpc

IOTA: HCBLOBZQXDUWXKFJJXNKWQGSAFFNRY9NBBJGYAANWFIIJMGWZWUFVFIWYPIAFYVWBIEFBV9CQRDOOUU99LWEXAHWEW


Domain Name: IOTASEED.IO
Registry Domain ID: D503300000042872196-LRMS
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: www.namecheap.com
Updated Date: 2017-10-15T20:31:54Z
Creation Date: 2017-08-16T12:11:37Z
Registry Expiry Date: 2018-08-16T12:11:37Z
Registrar Registration Expiration Date:
Registrar: NameCheap, Inc
Registrar IANA ID: 1068
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +1.6613102107
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Name Server: DNS1.NAMECHEAPHOSTING.COM
Name Server: DNS2.NAMECHEAPHOSTING.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2018-01-20T23:12:39Z <<<


Let's help the exchanges to blacklist the thief's IOTA addresses which currently hold the stolen balances. I'll keep this list updated as more people post addresses:
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)

1.77 Ti
J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTXGXGRIBLTB
https://thetangle.org/address/J9JC9VSQCMAODPPDWOPPDTPBPUKSYTYGZKFWOKQABPK9OQJIIZYUKXNTKPHMOCXCY9ARMKP9JYXJBOWTX


804.79 Gi
OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLYWQKQHQFJW
https://thetangle.org/address/OKVDOXIKGRGRJQZTPVPWXZGXFQXEAKEFD9PIVZCVSWFXWIPVAOGABBNMIAVR9AMIUPAMFPMVDJIOJWZLY

520+ Gi
GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYXNWGUPOSDD
https://thetangle.org/address/GOBXTNODUGURNEESTGFVMGFBVBFGIXJLYPOUWMXTBMECORN9IHHCLVWD9UM9WYKJMB9YOFMUHZ9SJASYX

235.65 Gi
NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNBQKVQEYTYD
https://thetangle.org/address/NTPYIPERTMLJLNJVBAK9DQQQCZGMPQJXUAZIDPNSMEPXZWKBTMRTGPEVEWHQICSTKJSTBWULZPJOXZNNB

151.29 Gi
EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUWKSQDOXETB
https://thetangle.org/address/EFMEPAWSH9SOLQEMJHQBIXHCXVYKYGMUAMULAWMPZHHGPBMSLRXUSCOIZVXOZDXCRIAZJFNBNNMTXDPUW

1.11 Ti bundle:
TUAJSFJGPXKJRTXIGGVZZHWLLZCN9ZQMDDJNDZKVAZKWJZDVKDOGJDDCMEJSFHDETZYCFCXOGGHHYWDIZ

108 Gi bundle:
LQFIHCELYGCYAXFTWQGYPQK9SNUSN9F9ALPOBFJFUDCIW9HNHZVRDGKDUUAFJRRYUJZ9LTJKSNCFDPTLW

HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMADSCRBWLXW
https://thetangle.org/address/HURWQIBSAEVZSBCK9LSYCVR9ZGOCSHHQIENAZURGCVCKXEMYIGHTYQQDRHJNUNPEIKIDKQTABQNFOWUMA

9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSXOSKWAIDRW
https://thetangle.org/address/9NVYWFBV9HGFQWCNROMZIAOPGIHRUVPAURUKUGPWGBN9TQJFYJZJWBRHBG9YXTNTAESKHZFNOQAFIYRSX

GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBDVKRXUUFRD
https://thetangle.org/address/GAHJVAHMGEGOES9XECPGBUCYHETYGCPZX9EIHERQGXIHTFFWHY9FMUZCEGBZOBQRNJUEJOLKRPAZENDBD 

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


4.24 Gi
MYFQ9GTCQFLFAQEOXEVYNJSHYFQHGKE9HGWMZVR99BUZJWHYALUYMWYJEBTWGF99RCYZCBUVYMSCJEYWWWWZXYCHEB
1.8 Gi
RGAWHCLYZFLPHTALTVQAJDYPULAGVCNKNTJY9DQTSVHNYEHNGJLTLBNOWASQRYEGYOLWFBZSLGGVPWFBBRIOJKCNW9
99.5 Mi
HYIYQMPOZSQT9WBGANFMCAQUEMBA9VOYLLG9HXZIHBDRJRFWANEFWULW9PKHMONLUCMWYTLRQARZMKQZDPCADNUVKC
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
7.15 Gi
9C9OXMNORPVLFDXIMFENPFMKIBQLGWTNTBHQWEFQUIJNCERVGNHVPAVLQEHWPKZVSXQEUDDJQYGKCUVGCJRTRXPIKD
18.59 Gi
TMGWYV9F9YGQZ9LZARTUHQGIGCAHWCXYMAGZOXNGMZJBIMVOTIFWTVOZEKKWAOLPJCHGBJBPGGAYNBNKCCYSHIHB9W
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
4.27 Gi
LGGPTEXWGNXQYVELGFKNLCOEPYMUCVVARGIHAYUSFYHAHUPOEF9LLMV9KZLP9HDJXBKVDSCNPVZLPNJRZCOQZOEGXZ
5.359 Gi
JLGAOWMARSEHRGJFMLUXC9A9HATYLHMOAVOALKKYXANRYPKTWKGCDMHWYBRP9VLSNISWGLPZFMBIITUSWIUMSLJXPX
1.75 Gi
VJNG9HNAHGHCPCN9WXLUWXJD9LDNCRRHCOVFMDPJZPIE9OFVNXSRTIIBGCTYSGDHW9OLRIVRLRVIZDFWWAKDYCGXFD
26.31 Gi
QZZGNNFWYVVHLFLLSDDDBOLVUDDXRXLAMJDDUQWAQKRAPO9UCBRYZJXOMNABQYOOCKRZZVXUJKNHARYJYKIHTNQIJA
15.09 Gi
XGRAUZWMXEUEOACWQJVJYEDOWNBMHZPTFUTLHJAOTSOWGHIHIRYKPJZCNALHZUZQSEYUJXQHKXLIADCLDQEGCXEHPW
3.26
JAZDUF9HBORDBRWOTDPZVNJYHFIEANLXAIAZOJTVYCQWNZVHYBOAOPDORXEX9ZGIPNXIYHLTG9KXZLTUWJYPNGITFY
898.55 Mi
FBIZCBGVVMDLPVTXBKYPKYJZHYR99NNODBCQPJBNASLGDZXQFEDUSFGKBOZUISEAKQOCDPPBHZBZ9XAMBZVBMOOXTD
1.1 Gi
ZXUZETEZASYCNGMWOQBU99GKYVFVRIXKRVNGWE9KQMYXOHCH9IMLCBCTVZCBJMZT99Z9VQQXFQLJC9MWDETIX9SPRC
HUIHRYVVDPDAWMCBYUJXMSPYHPP9Z9ICFPKZOJYZRCWAPSAHSKCDQSIEKQEJYLTM9NIRONYFSPNVNQV9DTNLVYAWCZ
25 Mi
UUVTFPXPPGSULRHWFIHQFEVVRXMBPSFUEBHFPQPIFYUVAGANVDSTBGHUFEZ9QB9DQYJPMSYITZCYFBWYBBN9LNLWBC
VT9GRFJQRCZONDDFQPFJCKKAXW9XNLLCJVWRBMEGSYULKYRFGHUBZGYDPYHCLSAQONLPYDI9WYV9PVQI9MEZI9AUR9
2.76 Gi
IICPKFSGDXTBBGETTCIVDOOZQDVRDKYUTBEAIZBFLWKXZGIPHGMNXC9HKXU9EONFSVPMILYPVJFYHBUCWXG9UQUHUX
265.5 Mi
PTTZVFSMATHGRUAGGVUPHGZS9SUSKQCHISMCZCTKRHMOBOEV9JMYGHSYBPFAUGNWTIVPZH9MBQFNSCRZWAVGJEGCJD
5.2 Gi
V9XIXKTCMBNLAXE9AWCIZLWVUXECKEHAJFTFMPLCMBGCCCHFXRBSNHPLXOEEFEKKISKJHGSMHEAN9VJ9YVGNYIZPXX
2.14 Gi
LFIMYHCWXWVKDMIGKJBLJGEZUOUPESJLSJUNGUKTX99ZOFWBWBUCOQJSERJEGNDSQTLIWYVSWBOQKKDXD9LIEEALIA
1.72 Gi
QYWCHKZJU9SHPPEIDZVCXTGHIPP9LBIYRYJIQVVKLPXRUKJKPCLUZQUBAEXFSJRFDVSYV9FV9NOHWZG99NLUFJVKJZ
3.56 Gi
AJEROXILLAOYFWBRUAAWIW9G9OFZVPVCGVKHWLTNNXI9YJCSQVQVDYIKQDJIA9MVOCFDQYPQMNQSQKCFANAL9HRUMC
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
1.47 Gi
OIWECXNOHDHFTSPRXWHFCDPVTCYHJEMDANKUGHIJNFMERUDASQ9QZLRB9WONTCRRR9X9ZOCJVDXMXFNYCAUODTNJDA
8.87 Gi
PXTBVOQHXYBAJFLE9FPNMUEWZPMRBZQXWLCY9VYURXXCWPGPVEYAXTWCIBVOPAXVKYOCYIMKKRPCUEFJ9ALSLHFV9X
6.22 Gi
RCMBGJZDXKERJWLYEUEZYPYZQSS9OWESYVMFZTZRRHEFPGLRPDQLS9HQGJKTIEKVTVPFAQTYOOVFLMXR9RXRECDQKB
19.19 Gi
ALYRLA9RPAAAEHLFOPSOQMHFHMW9UNIOSNZXSXHLY9VGDGUVCBFCQEZQNBIFPVPQPKCBOFBVUZBZUZKEDXW9DXYEAZ
2.08 Gi
WVGPQSORGGDIEWORFYSTKHYGRKULRHFPEUPLTFGMMKYJJEWDESTGGBWSVPEMSYYYC9CWAMHFCHPVUAZIAHWJEKJCAW
9.43 Gi
LBHUVFYUJWXOYQEGLYAQPJYLNJAFKYINHBACITQVTNTAYHFLEQTBDWUDHSCLVPO9LARHBPN9FFNKHQPXWOBXEFVRRA
3.02 Gi
YUHHXDDIMNDLKDPSTBDYTKNY9PCBVCMSXECYVJTFIMMXEKVTWACDIWGZEOMN9CHDPMCD9AOXZOYAPFRCXGVJAAAAUB
1.88 Gi
SYLBJLPCHQMJPWCNUGRR9PQPJLFSKPTKFXLAF9DCKTJVQPLKEZAXGGLE9VXZWOLSYCCQUPUOCKRHIOKGDK99PTPV9Y
1.75 Gi
ZAYXJCLJVYYGFICBWTKMYCWHGVBLKNEMHOWGOVGXRIWGT9HKYZHWWPPDAKJJFQYPLLSDAZTOAYGEZG9HDQBTMAJSUY

(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Now empty
OEELSJPRYTWBKCAUPUSUDPUDCVBSRWFLIQQERDAEBUWKMFJLVHUNAWABRFHCWRIJBKYFQ9FNGGRVEUSUXAJXVSRLZW
KNHKJLETGSDLJSFFDSAAEGTEIHHLMWOGXVEDEPUPXTYMVHEVWLEBAABTNMFBEM9MDPONNJGY9WQCBFVNWFIRVDHRTW
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD
KGBJEUNTGKSUTV9QCRDYQTQFGNLKQXVFLJQUERTAPIGKYFVDXQRUHANJNMXLAQQAIMIGVTHKEKQNNN9EXDAVCZFBF9
SWBPUHLCUQYVWPRHMFMCPRYWUBCGK9OO9GPKB9BLQABGSZGKKUDEUJIIJLPQWSSJXGHJYHUHIBZLXROOYJKMKLSOZX
UBLQW9YPXHZ9ZOURWYWKSYFQEWFRYFIBJYXQQAYHOSQYGSLLRUNPNPPKIIAEET9WKF9RNTUIUFJVVV9YDLHKIRICLZ
HNECRND9HUSYPLIWULZKYQWLGZFMOVPTTWTNBOWAXFVXZW9HFPOYWIYIXFRZKDVATZJGJFDOECFSXSVVZZUPDHOPXA
FBA9KYTDEFIERJSYKSIMCBCZM9UKBCL9QKDTAPUHHVVAWMOGTDGNDRHIBDWTRGOWDOJDKYJFJCIPJNJH9SUOIKFBRA
RSWLBA9LDJH9FWFPTBRHDBAQAAH9DDWCVF9CVJIWNBYXMRYQPXZ9TIZOUEHLKRBJEYDAWSHMYBHL9AQZANBDKEQMOX
MKPMJQSEURTQMCFXBEIXAUXZRHYQCWTVOTROAUAZWPNZYJRSXGZHMHZIWWAEVHJVGV9TWLCOZUXBMETKXODAAODZVD
NPZKLK9UWWHXIYWFSSGZQKITTVST9EU9JRLZWRUFUOLGGELCFPN9BHKRVDIIQEYWGHMHCAVSRXQGHGOZZOFTHKLKEX
AVVTHJXO9BWDEGODGPQOWIQXCAIOZLGCIWNJVIDHWICRICIXQSJUBMZZGLREELE9U9KMMVPRBBHAKJIR9QQICHZCPX
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
ZPXFSDGOOWBWCNKAONOUZEEEZFPKCPMZZOZWWJLPHQKGRLBOAG9KMJLKXILSGTWZ9CNPMGWHTIDTFYQXYXOOVQFSOA

EIFSFHQYZEVKOJZOHFZHWKE9EXMREBVVPWMCKYMLPTQLGPO9AEKSACRO9AJTBXCUYTIVZOQATXLNDGBDBATGUTZRLB
JJW9VRRCSOCHQWPWDYHMHUXZCZQQQEPZCFOWJCHQAFGSMGVSMWLSCAKZTGSNUIAWBEGGMZXFWDFHBLIAWTHLHPDGGA
AZWBUGCURMQKZJYGZITN9QKKIGWHJA9GPVTYJC9CDUNWOCVJSOCSBILB9EAGUGXFCLOZKUSUJSVWHUZTWNJYGCOLKB
ERYQTLNVFFOGEHMALQJMRFISFUUIJPYIWKWFY9EQCUOAUZSGZP9THDRHFLCNFBEUITGLDQICHBVHELZXXETLKQSNBB
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
UCWBAYEGH9FBAQKKBVXKNGYSEFUBRGHKUNRWRSWT9AGMKVSBJKONZRTDQKPBIGEMCXVAZ9QBU9VEKUAPXKTYQHYOCC
GWB9FZUHPEPCRAMZJUTGPKRA9IRNIBPMYGFDEYEGXZGI9FZRDOQKZODXPRGEEKYZWYYWRBTHZUNLOIIR9RXDYBZGNW
EETIM9SRXXKPOV9NZEOFSBTILTSVIZPLBILGHGJAVLIPLCORBYFFBVLXVIJFDV9ODLRWVSFBSKWJSIBCALHXKJFYVB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
KHGEDPRIPVPZC9WCCATFXGAALCHSPHCRXIAGXDTYAVREUYGCR9SCKFZXP9SVCWNNSTTVRYCVQAQRJCWJWSPCZLLUNB
ZSDGSDXOIICJNTGLMFUIQLIBEEGVBOGMA9DNLQDTA9RGJHFPDAPADGUPUDL9VHFVACUWUGEVTCKPVUPI9SFWNFHXCW
ECEWVRSHLKRNZCROHBDUWPUKYJMIBTJBKWNYMIHHWFUHDLDCV9HNM9XOSUEBFDNDFQSC9TIOQCQKTJPFCTLLAPFSPD
YXRCTAVQTU9OSQBI9NYARSLBMATKROHJHCRX9IIPTMXXGFLDCOR9PIWDPCGTAGXZBYUPXUXRWZIK9GEBWIUHATXWMZ
BUEMMMQAGPKCCBSVFYVKOYGCBYHXLDAYTYOFRYYYJSBFVVWHEGPACPTVFOEFXVIDEEWGYZRWXXHHURYEBQPTUEM9OD

ARRHJ9V9ISMVZMTXCOBRKUEJZEIVRIZ9CWAR9TVROC9HRGLIQXWGEFSHDPTTPHGNDDPUATNIEAYLTSQACPHJFBHQTC
9OEXHTYHPEVBDTPBUZILWEUPIXIUIXKQRYNECJKBJFLAIDRWZNVQRBICQTVTVROUDEQQFQOVQMSUZUIPXUC9NMT9PW
E9MKOUWCYBWADYXGXDCGSGXRMWQIFVFBAWEZYJGEZOWSMUVAYCRD9ABDNJNYLASFAJKM9TIJFZAYLNQO9MRYCQ9KAD
AMIJVUGZDWDHKQRTIODEOGIRWOVWRXYVOQFK9TLETOMUQZVPQZKLEPHMRNKRBNHAMDUOUIURXPGLEJOIBNGPOMWYJX
BJFVIGKFWNJWSWSNZERCXAOGWDAKZGHLSATKVCMKPOO9ZOPQKRASJDBTNZEZGTWHLBFNPAWMKUD9CKTZ9ANXNISMRC
JMFSOIUAZHLQXSFNEQGDHRSSNTTHOXFRCUWU9ZNMUHCFGDLZQSGNEXGWNKXQKUCCOIIOHR9WJXDRBFSCCO9RMGJCUD
ZTSEF9HERSDQJIKGUL9HKRHJJTTAUBRGUZF9MCRJWAKAVPPQODSKXYUHUYYX9R9QEHPAOLIYCNTWONCIBIZKBJTBM9
OQRJJB9MJFOLGALRYNAUNZCRQOZGRQPHTRNGNWLPPNGETIU9JVQNRSOEICJOGLQVPLCMHEBZSHNI9UJQWQXVFENLBB
LDTTG9WKOACCGCPFZRPYAOYTRBVVOKC9QUKK9PVHCPKLQOVPSTJJZ9CPKETNCXDANPMQQPIKQTDJTDJY9VFCNZRVAB
ZRSUEFIEJJVMLGTLHWQ9JNXDIAGSESRMBJWWUD9UHBUOUI9BWDNTOZYUTYQHIWFNXXNUGEWWMCOFHRPKDAREL9RXAD

=============================
Please post the address to which your stolen balance was sent.
We can contact the exchanges and attempt to have these addresses blacklisted before the thief is able to move from IOTA into another currency. Time is of the essence.
(All addresses up @Winston 's post on page 8 have been included here. If someone can compile the addresses after that post, that list will be added here)


Also, let's try to look into the details of this situation as much as possible. If you decide to take legal action, please also post with advice for others who are considering doing the same. Let's all help each other out. The thief will get away with this if nobody decides to take action.

This is another address:

KY9KAQIGMNJMNMGFJDXZBZN9WFTEWXKRCQISIJFCNLNDNZXYYRVGE9UHQEBUPGKHBSSOMAOHKAMAWKWXD

https://iotasear.ch/bundle/SSVTWVBZJJZBBAXXOKBSXSHHJFFE9QPRTYWREEUELUSBGQFCJGKUJXH9HJWJPLPDBWJEITHXNOEJDZGBB
By alinarimani - 23 Jan 2018

@Winston
My 621.88 Mi IOTA has been stolen too.
Send to :
VYKHOHZDOFLXNTUGBGTJODSVJZOGSZYSUEIUOSDPEDWIOXSXARWBUARHKAM9TXVO9ZYAYHNOMAD9CDJIXLVCQ9RY9W

Transaction:
JWEOIGHWLMJPBOJLSDRSXCQSDN9TBQEEFPWWADJHXU9GVNRKQKKMCFUVFEPGCLXJPGCHBTKYEFB999999
Bundle:
ZOLIDZVJVPCIUCIZD9FTCFXJXLBAG9I99PNEKFIYWNJRVSHFYDUKRFBA9BTJBISKLWLTC9WZZJCICDZLB

https://iotasear.ch/transaction/JWEOIGHWLMJPBOJLSDRSXCQSDN9TBQEEFPWWADJHXU9GVNRKQKKMCFUVFEPGCLXJPGCHBTKYEFB999999

Thanks
By GregPol - 23 Jan 2018

Do not you find it strange that they are doing a snapshot at the moment? Lots of people have lost money, no reaction for those affected by IOTA. Where was the information a few months ago not to generate the seed online? This information SHOULD show up when you install the wallet!
It strangely stinks me of all this. Without the help of the foundation, we will not get the coins back. I believed in this technology and trusted the creators. Now there is no help. We can not do it alone.
By adamdrzazga - 23 Jan 2018

The rest of my iota was stolen by:

-880,5 Mioty

HASH:CJREZFXFWOOFQPFJYKMGLKDEN9STYFLSJTMT9ZEMKNVZKUZTKNCXCVAGTZC9QAMECMZ9KJNUSHHSZ9999

ADRESS: NMCVHOHKDLJFSBMLGX9XCNVPGMPYGMXOTZPH9REOPEURGQBLHDSNHRZQBJHDLDZZAZVAXACCYABLCBFDDIRUIXFCG9

Some hope....?
By CHiPo - 23 Jan 2018

-454 Miota

Address
WXAWWPYPECPCZABQAZPBIKNJPDUPDWDAIVGDBDBEMRMHWOPSKXRIBIWRPBCBOQGKEWYMGLOBLQPIHLZKZRBOYZMKEW

Bundle
LYYL9GUPHTRJUJGHWJGIPWELWJUEOTWJT9Z9AZFGYZIYCZQDZWJDKTKELGVTELGXNOQVKJSYHAUYKNSWA

Nonce
WDK9SUPYXOISMFEQEVMKMPDHQZO

Signature/Message
99999999999999999999999999999999999999999999999999999999999999999999999999999999999999

Tag
KH9999999999999999999999999
By iq34acal - 23 Jan 2018

https://bitcoinblog.de/2018/01/22/iota-vorsicht-mit-dem-seed-es-wurden-bereits-4-millionen-dollar-gestohlen/

It's saying without any doubt a failure and responsibility of the wallet-devs...that this gonna happen was only a matter of time

By CHiPo - 23 Jan 2018

stesy - 23 Jan 2018
IMPORTANT  ,I just notice just notice the 1.6ti collected from the hack are still on the tangle , they are smash the amount in different accounts but funds are still there ....I am not sure it may help please forward or check it out
https://iotasear.ch/bundle/KLDYFSOSH9LVDJ9PKFSVGDBUSZRQLGGQHKZFQZPHTLHYVBRNSAUAYLIMD9HHEOFTRWPIFERWZFKLDOWEY

they move the 1.6 ti form one address to another  smash a bit to many different addresses and move again what remain ...over over again

No possibilty from the foundation to catch them?!
By foerch - 23 Jan 2018

@Winston
also mine IOTA are stolen. I'm not totally sure what you need, so I post every information I have:

AMOUNT
-2.089716213 Gi

TRANSACTION HASH
VAGJSCITPRXBDGQPXZVVSZPEESPIKDJYIHBYNZRZY9YCERDFZWKPLQEOSDEWFROIBX9YJXFX99PTA9999

IOTA ADDRESS
KWSHRVXAHWBSXKXQSOHGMLXKTIIWYKXLTXLVWKCTGTUB9VNKS9HGGBQOGHNKUHWS99JUPCVXXKGQHCJLB

BUNDLE
MNZDF9GBYKSDHFXDGHYIZNDWRBXECJGAPYUO9AIDOZDVF9GPOJJXBDHYLSAIEYXKNOHIWVRDAUAEOAILW

https://iotasear.ch/transaction/VAGJSCITPRXBDGQPXZVVSZPEESPIKDJYIHBYNZRZY9YCERDFZWKPLQEOSDEWFROIBX9YJXFX99PTA9999

My wallet shows me also the following address:
OIQLGXQDYDGPOIZGRWLPLYUJN9JXAJNS9IFOJUSOVQUOLHHMKPVAVJRWKCFPMIOLMU9WBCXVVVCTHFNBCTKDITBTBX
https://iotasear.ch/address/OIQLGXQDYDGPOIZGRWLPLYUJN9JXAJNS9IFOJUSOVQUOLHHMKPVAVJRWKCFPMIOLMU9WBCXVVVCTHFNBCTKDITBTBX

I think this could be an address, which they have used to bundle some transactions!
Could you @Winston give me a short signal that you have every information you need!? Thanks a lot for your support!
By diyordie84 - 23 Jan 2018

I've found one transaction that were pending on 19/01, this one:

https://iotasear.ch/transaction/JWDNQTLIMGRPYMQPHWCEGBDTVY99FJWASIIJRYMMMPNQBFGUZEDZWDOAHKGJTDKUKQSRHJHBRADM99999

After seeing that, i setup a CLI wallet and tried very hard to sent my IOTA to binance, in this transaction.

https://iotasear.ch/transaction/STLNYDTYESHADFLJYPHXMOGSYEXTQCARDKZPWRDDYZEGDQMNZIGNQJMUPQUOYHXYRNSOAJTIMLGDZ9999

but things were not so fast and after all night up reataching and promoting this one, i found this...

https://iotasear.ch/transaction/NTWEWJHJABDXLALJINAXYUTGOCRKGDMBDPK99Q9HQAOQQK9NMTQNPMHKGXKIIWBEIPVCCVTCJOHFA9999

So i saw it going from my hands....
I used iotaseed.net to generate it, and i think that i linked it from the same page i downloaded the  2.5.5 wallet...very sad indeed



By GregPol - 23 Jan 2018

We must write not only here. We also write on fecebook, twitter other portals. Not all victims here reach. Can you also set up a group of victims on facebook?
By eid - 23 Jan 2018

7,850 MIOTA were stolen from my wallet and transferred to 
OLJQUGQZNBWKQFGDDXCEOXZGQJZDYATZTHKRHOAMMVEISYNFVGQCDUODRPCZVBK9HFCWMEQQEAAWD9JKAQNPAQT99C

Does anyone know what can be done or is there anything IOTA is doing to recover this mess ??
By Aca - 23 Jan 2018

Lost 5.082663813 Gi
Address:
HGAEPRBUGQFWSOVQDBWCVVECZGWCWOBERMABPCMFASUBMWR9ZRXDQQFWSKVZLUUSWOAGKZZEXZEADOGHCPH9KVSIMB

That one i now empty, it is transvered in this bundle:
FXX9SGTZBFUKXIABDZKUIKWBNBVGSJLSQT9YBGLAOSAOUIIEIGOJLYOSDRXBGIQFXCSWVSORWWLEKKA9D
By Lazyrudi - 23 Jan 2018

Help yourself, because nobody else - not even from the foundation - is doing it... or is IOTA doing anything else beside collecting the send-to-addresses? I have no idea. That is the reason I filed a criminal complaint with the police yesterday. Today I just got a call from the police that they have forwarded the case to the department of cyber-crime.
By iq34acal - 23 Jan 2018

I'll talked to the cybercrime department of the public prosecution in Hessen, Germany. They will start investigations as soon as I write them a mail with all required information. It seems like they take this theft very serious and that they will try to trace the scammers. I'll give them the link to this chat. If there are any additional information missing, please send me a message. I'll send my mail in 10 minutes!  There are cybercrime department in almost each federal state in Germany. If you are German, please contact them, e.g. if you live in Nordrhein-Westfalen. I can't do that in other states, since they are not responsible for me.

By iq34acal - 23 Jan 2018

iq34acal - 23 Jan 2018

I'll talked to the cybercrime department of the public prosecution in Hessen, Germany. They will start investigations as soon as I write them a mail with all required information. It seems like they take this theft very serious and that they will try to trace the scammers. I'll give them the link to this chat. If there are any additional information missing, please send me a message. I'll send my mail in 10 minutes!  There are cybercrime department in almost each federal state in Germany. If you are German, please contact them, e.g. if you live in Nordrhein-Westfalen. I can't do that in other states, since they are not responsible for me.


It is not mandatory to go to the police, you can start that investigation, by simply write a mail and report a criminal charge directly to the public prosecutor for cybercrime. I'll keep you updated about the status of my charge in Hessen. 
By foerch - 23 Jan 2018

@iq34acal

just send you a private message! would be great if you answer. thanks!
By ezeee - 23 Jan 2018

iq34acal - 23 Jan 2018
iq34acal - 23 Jan 2018

I'll talked to the cybercrime department of the public prosecution in Hessen, Germany. They will start investigations as soon as I write them a mail with all required information. It seems like they take this theft very serious and that they will try to trace the scammers. I'll give them the link to this chat. If there are any additional information missing, please send me a message. I'll send my mail in 10 minutes!  There are cybercrime department in almost each federal state in Germany. If you are German, please contact them, e.g. if you live in Nordrhein-Westfalen. I can't do that in other states, since they are not responsible for me.


It is not mandatory to go to the police, you can start that investigation, by simply write a mail and report a criminal charge directly to the public prosecutor for cybercrime. I'll keep you updated about the status of my charge in Hessen. 

Can you give me your mailtext and mailaddress so i can do the same in lower-saxony? Thank you!
Kannst du mir den Mailtext und die Emailadresse geben, so dass ich das gleiche in Niedersachsen machen kann? Danke!
By Lazyrudi - 23 Jan 2018

Do you have an "Aktenzeichen" I can forward to my police, so that they get in contact with their colleges in Hessen/Niedersachsen/...? My Aktenzeichen is: ST/0135642/2018, Herr Moessner, Polizeirevier Sindelfingen. Date: 22.01.2018
By Lazyrudi - 23 Jan 2018

If you give me your email, I send you the Information I gave to the police. Mine is lazyrudy@gmail.com
By Lazyrudi - 23 Jan 2018

sorry, lazyrudi@gmail.com
By ezeee - 23 Jan 2018

Lazyrudi - 23 Jan 2018
If you give me your email, I send you the Information I gave to the police. Mine is lazyrudy@gmail.com

sent you a private message here
By mskinnes - 23 Jan 2018

Hi,
First post, I'm from Norway

I lost 110.4Mi.

History
https://thetangle.org/address/YVCHZSTLNDPDCHIEVYYJBKESBFUELEMGCQSDQMLSOEBHFKZVZVHWYRAZRXYAUKYMGYFF9Z9ILFNKASCHC

My adress:
YVCHZSTLNDPDCHIEVYYJBKESBFUELEMGCQSDQMLSOEBHFKZVZVHWYRAZRXYAUKYMGYFF9Z9ILFNKASCHCWARFASZNW

The IOTA was sent here, and is still here:
NERSHKVMFVV9GPMSQRVDGUIQIDFOXJTOMWLWPPWYKBHGKITZTWFXBZ9ELYLJOKGJEWNYOORR9GJ9ZNVSBVCBFOFEEZ

By iq34acal - 23 Jan 2018

By talking to the police and/ or prosecutors, everybody increases the pressure on the authorities and underlines the big impact of this theft. --> GO TO THE POLICE OR START CRIMINAL CLAIM
By Lazyrudi - 23 Jan 2018

Just talked to the "Kriminalpolizei" who are now, due to the size of the case, are forwarding the deal to the LKA (Landeskriminalamt). Hope they could put more pressure on IOTA to do something, than we are able to.
By Lazyrudi - 23 Jan 2018

@Winston is it possible within the IOTA technology to reset the Notes or Hard-Fork, or however you name it, back to 18.01.2018?
By CHiPo - 23 Jan 2018

I can't imagine that they would do this.
By OpenMedia - 23 Jan 2018

Need more pressure, they certainly could roll it back and they did it before.
By mskinnes - 23 Jan 2018

OpenMedia - 23 Jan 2018
Need more pressure, they certainly could roll it back and they did it before.

That would be great
By mskinnes - 23 Jan 2018

mskinnes - 23 Jan 2018
Hi,
First post, I'm from Norway

I lost 110.4Mi.

History
https://thetangle.org/address/YVCHZSTLNDPDCHIEVYYJBKESBFUELEMGCQSDQMLSOEBHFKZVZVHWYRAZRXYAUKYMGYFF9Z9ILFNKASCHC

My adress:
YVCHZSTLNDPDCHIEVYYJBKESBFUELEMGCQSDQMLSOEBHFKZVZVHWYRAZRXYAUKYMGYFF9Z9ILFNKASCHCWARFASZNW

The IOTA was sent here, and is still here:
NERSHKVMFVV9GPMSQRVDGUIQIDFOXJTOMWLWPPWYKBHGKITZTWFXBZ9ELYLJOKGJEWNYOORR9GJ9ZNVSBVCBFOFEEZ


When the IOTA still is in the address, why isn't it possible to revert this?

Bets regards
By Vesko1984 - 23 Jan 2018

My iota gone too

they send my balance 6.460877828 Gi to this adress:
OWCSXZIMQRNOAINYDCTFLOIYBYIBFASPWZPSNMVBFXNIXNWVQHQDZLXEGFXOTCXLYUCBAHAGTOJUSUZKWAEABKTE9C
My balance is still on this adress. 

What can be done here?
By ezeee - 23 Jan 2018

Maybe it's a good idea for making more pressure to IOTA (in order to set back the related addresses/seeds) to send messages to Dominik Schiener and the foundation?! Can't get it, that they make no statement and do nothing!

https://www.facebook.com/dominik.schiener.140
https://iotasupport.com/disclaimer.shtml (contact@iotasupport.com)
By mskinnes - 23 Jan 2018

Vesko1984 - 23 Jan 2018
My iota gone too

they send my balance 6.460877828 Gi to this adress:
OWCSXZIMQRNOAINYDCTFLOIYBYIBFASPWZPSNMVBFXNIXNWVQHQDZLXEGFXOTCXLYUCBAHAGTOJUSUZKWAEABKTE9C
My balance is still on this adress. 

What can be done here?

Same signature/message as mine.
By GregPol - 23 Jan 2018

Is it technically possible to go back to the on 18.01.2018 at all?
By Flexe - 23 Jan 2018

iq34acal - 23 Jan 2018
iq34acal - 23 Jan 2018

I'll talked to the cybercrime department of the public prosecution in Hessen, Germany. They will start investigations as soon as I write them a mail with all required information. It seems like they take this theft very serious and that they will try to trace the scammers. I'll give them the link to this chat. If there are any additional information missing, please send me a message. I'll send my mail in 10 minutes!  There are cybercrime department in almost each federal state in Germany. If you are German, please contact them, e.g. if you live in Nordrhein-Westfalen. I can't do that in other states, since they are not responsible for me.


It is not mandatory to go to the police, you can start that investigation, by simply write a mail and report a criminal charge directly to the public prosecutor for cybercrime. I'll keep you updated about the status of my charge in Hessen. 


I would like to do the same for the Cybercrime Department of Hamburg, Germany. I already was at the police station. Is it useful to inform that department additionally? If yes, could you tell me what informations you gave them? (If you like PM me) @iq34acal @Lazyrudi
By Acaddo - 23 Jan 2018

Hi,
650,45 Miota stolen and send to this adress .
9FNRLKGUFXXRIWAVZFMIFWYAXGTIDSFAOKNDF9UFHDKJRSHHRHWESHLZHBHFBNRMNYYHOLIGYJVFEWA9DXOHUBSZBD
Im from Germany

By Lazyrudi - 23 Jan 2018

by the way, who designed this Forum-Webpage? I only occasional reply on a post and can't insert documents and fotos.... I am using a macbook with safari, but facing the same problem with google chrome.
By Lazyrudi - 23 Jan 2018

@GregPol  is question has to be answered by IOTA!!!!
By Lazyrudi - 23 Jan 2018

How long is IOTA able and willing to ignore us: http://www.pc-magazin.de/news/iota-kurs-vw-kooperation-shitstorm-wallet-diebstahl-folgen-stimmung-3198958.html
By mskinnes - 23 Jan 2018

https://www.ccn.com/a-number-of-iota-wallets-emptied-by-hackers-due-to-online-seed-generators/
By GregPol - 23 Jan 2018

I write on twitter. You also write, comment and place the tags #iota #blockchain #volkswagen #iotastolen
By mskinnes - 23 Jan 2018

I wrote on twitter. Getting flamed...
By MMkrypto - 23 Jan 2018

stesy - 23 Jan 2018
I already asked on the official discord channel but seems no one care to answer so I will try here 

snapshot will happen in couple of days , what will happen to all hacked accounts ?? I mean 0 accounts will be deleted from the tangle  right , means  all hacked 0 account will be deleted and there will be no more evidence for further  investigation  right ???

thats a good question. We need to be able to keep our wallet history at least.
By ian_a - 23 Jan 2018

i'm going to report the cybercrime in Switzerland, so is anybody here from Switzerland as well?
I guess the more authoritys from different countrys are involved the bigger gets the pressure..
By stesy - 23 Jan 2018

GregPol - 23 Jan 2018
I write on twitter. You also write, comment and place the tags #iota #blockchain #volkswagen #iotastolen

 I will , hope others will follow
By MMkrypto - 23 Jan 2018

iq34acal - 23 Jan 2018
By talking to the police and/ or prosecutors, everybody increases the pressure on the authorities and underlines the big impact of this theft. --> GO TO THE POLICE OR START CRIMINAL CLAIM
IOTA users are from all round the world.
I think the best way is IOTA foundation can put more effort to find out the hacker(s)
for example via namercheap which has a investigation dept. 
But IOTA foundation seems laying back and just watching doing nothing for its users
By MMkrypto - 23 Jan 2018

stesy - 23 Jan 2018
IMPORTANT  ,I  just notice the 1.6ti collected from the hack are still on the tangle , they are smash the amount in different accounts but funds are still there ....I am not sure it may help please forward or check it out
https://iotasear.ch/bundle/KLDYFSOSH9LVDJ9PKFSVGDBUSZRQLGGQHKZFQZPHTLHYVBRNSAUAYLIMD9HHEOFTRWPIFERWZFKLDOWEY

they move the 1.6 ti form one address to another  smash a bit to many different addresses and move again what remain ...over over again

hi quickly pass this information to Winston somewhere in this thread
By Guggivaz - 23 Jan 2018

ian_a - 23 Jan 2018
i'm going to report the cybercrime in Switzerland, so is anybody here from Switzerland as well?
I guess the more authoritys from different countrys are involved the bigger gets the pressure..


Ich bin aus der Schweiz.

Ich bin aus der Schweiz und betroffen.
By MMkrypto - 23 Jan 2018

GregPol - 23 Jan 2018
We must write not only here. We also write on fecebook, twitter other portals. Not all victims here reach. Can you also set up a group of victims on facebook?

yes. and also signature site
By ian_a - 23 Jan 2018

Guggivaz - 23 Jan 2018
ian_a - 23 Jan 2018
i'm going to report the cybercrime in Switzerland, so is anybody here from Switzerland as well?
I guess the more authoritys from different countrys are involved the bigger gets the pressure..


Ich bin aus der Schweiz.

Ich bin aus der Schweiz und betroffen.
Hab dir ne Nachricht geschrieben.
By MMkrypto - 23 Jan 2018

Winston - 23 Jan 2018
@BIGLEE68

"WHY IS EVERYBODY SO CALM ABOUT THIS , I WANT THERE BLOOD !"
Everyone here is super upset. We started this thread so that we can all gather details about the situation and help each other through the legal process of recovering the stolen funds. Many other people in this thread have offered to team up and figure out what needs to be done next. Nobody else is going to fix this for us, so jump in and do something. Nothing will come from being aimlessly furious.

Winston - 23 Jan 2018
@BIGLEE68

"WHY IS EVERYBODY SO CALM ABOUT THIS , I WANT THERE BLOOD !"
Everyone here is super upset. We started this thread so that we can all gather details about the situation and help each other through the legal process of recovering the stolen funds. Many other people in this thread have offered to team up and figure out what needs to be done next. Nobody else is going to fix this for us, so jump in and do something. Nothing will come from being aimlessly furious.

Is there at least any attempt from the IOTA foundation to help find out the hacker? Putting some fund for an investigation such as to namecheap.com?
Also, there seems signs that IOTAs are moving around one wallet to another in the tangle, one of the post here, why IOTA teach is quiet? Isnt it legally a customer service violation?  
By miner_97 - 23 Jan 2018

Komm auch aus Deutschland und habe heute bei der Polizei in Bayern eine Strafanzeige gegen Unbekannt eingereicht, kann andere Leute nur ermutigen das gleiche zu tun Wink
By MMkrypto - 23 Jan 2018

stesy - 23 Jan 2018
MMkrypto - 23 Jan 2018
stesy - 23 Jan 2018
IMPORTANT  ,I  just notice the 1.6ti collected from the hack are still on the tangle , they are smash the amount in different accounts but funds are still there ....I am not sure it may help please forward or check it out
https://iotasear.ch/bundle/KLDYFSOSH9LVDJ9PKFSVGDBUSZRQLGGQHKZFQZPHTLHYVBRNSAUAYLIMD9HHEOFTRWPIFERWZFKLDOWEY

they move the 1.6 ti form one address to another  smash a bit to many different addresses and move again what remain ...over over again

hi quickly pass this information to Winston somewhere in this thread

where should I find it , can you contact him ?I
go to the first page of this threads you will see the name Winston who is helping to organize this site right now
By Lazyrudi - 23 Jan 2018

If you follow the money it is still in the IOTA environment. The last big transaction were my money is in was to: https://iotasear.ch/bundle/VPHQKLFXLHUBNHYVHEUPDBKHEGWALLOPCLTHWTYHBNQKSIHEXGJAPYSKHE9OYC9SXAEITTZ9BEZAKKZJW
After this it was split up to 22 Outputs, form were the money wasn't transfered yet!! IOTA can you stop any further transactions?


By MMkrypto - 23 Jan 2018

stesy - 23 Jan 2018
MMkrypto - 23 Jan 2018
stesy - 23 Jan 2018
I already asked on the official discord channel but seems no one care to answer so I will try here 

snapshot will happen in couple of days , what will happen to all hacked accounts ?? I mean 0 accounts will be deleted from the tangle  right , means  all hacked 0 account will be deleted and there will be no more evidence for further  investigation  right ???

thats a good question. We need to be able to keep our wallet history at least.

to avoid the snapshot cancel my transaction "as I need the proof to submit a full Authorities report in my country when I go back" I send some iota  through mineiota.com