Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Several people have lost Neo due to a fluke in the Neon wallet and Ledger Nano S. #524

Closed
OrEagle97327 opened this issue Jan 13, 2018 · 386 comments

Comments

@OrEagle97327
Copy link

OrEagle97327 commented Jan 13, 2018

I came from - https://discord.cityofzion.io to make this post. ...We need support.

I ask all that experienced this problem, join this thread so we can compare notes.

Hopefully; we can get Neo and Ledger to join the support, instead of claim 3rd party software.


On December 22, I installed Neon Wallet 0.0.7. After connecting to Ledger Nano S, I transferred 108 Neo from the Bittrex exchange, using copy/paste of public key in Neon wallet. ...I kept the wallet open until I saw the transaction complete. It showed my transfer as expected. I closed the wallet and went to bed. (1:00 AM)

The next morning, I opened the Neon wallet to check it out. There was a ZERO balance. After more examination, I realized, the public key was different. That makes two public keys, and only one being addressed by Neon wallet attached to Ledger.

In my search for support, I found my way here on gethub ... #416. The person who posted that thread invited me to "discord.cityofzion.io" We are getting referred back here.

Coranos got involved in that discussion, and finally gave up. I quote him here:
"Sir, your neo is gone.
Finding the defect that caused your car to explode is not the same thing as un-exploding your car.
Simmilarly, imagining ways a car can explode is not helpful, when trying to find why a specific car exploded in a specific way.
Best I can do at this point is to warn people that at some point, their car may explode, and they better test their recovery process at least once before putting more than 2 NEO in any address.
I've muted this thread."
I feel like it is something else that blew up like a car. My "bullion/Neo" in the car/wallet is still lost. Where can we go to find the answer to recover the missing Neo? There is more than just a couple of us.

To add chaos to the problem; On Jan 10, I upgraded to the Neon wallet from 0.0.7 to 0.0.9. Now I have another public key. That makes three, the one that got the Neo, the new one I had the next morning, and the one I have now. I have uninstalled the Neon wallet and reinstalled, still the third public key. Even if I uninstall ver 0.0.9 and reinstall 0.0.7, I get the third key. (I have reinstalled it back to 0.0.9) When I run my 24 Ledger phrase, through https://coranos.github.io/neo/ledger-nano-s/recovery/, it now returns the third public key at the top of the list.

ATTENTION: All who suffered this loss; join this conversation here, Let us all compare notes, so we can get to the bottom of what happened.

@Evgeny1986
Copy link

Hello, I have also disappeared today 19 coins.
My topic: #523

@MorganLester
Copy link

This happened to me a few days ago. Setup my wallet connected to nano fine. sent a few tests before sending the rest (only 7 coins). Yesterday reconnected app and zero balance with a 100% new address. Is there anything we can do? I can see my coins sitting in the public address (the original one created). I am guessing these are gone. I have tried recovering from 24 pass etc and nothing.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 13, 2018

Looking at the immediate responses; it appears this issue is at least a month old, and still occurring.

What can be done to get the word to new and other users?
CAUTION: watch out until we get to the bottom of this!!!
Can we ask Neo to post their website, the source of my Neon wallet?
Can we get Ledger to post a warning on the Ledger manager?
Can we post the Neon wallet with better instructions?


Let me re-post Coranos:
I've done my best to raise awareness:
https://www.reddit.com/r/RaiBlocks/comments/7mij5j/ledger_nano_s_app_update/drx1566/

I've also created a walkthorugh of the steps people usually take to verify the ledger is working correctly:
https://www.reddit.com/r/NEO/comments/7l1yil/instructions_on_how_to_test_your_neon_wallet_with/

also posted about the other bugs I've found:
https://www.reddit.com/r/NEO/comments/7i3zcg/bug_in_neo_ledger_app_related_to_nep5_and_change/


I sure wish I had seen these sites about a month before they were even posted.
Wild and crazy ride we are on!!

@MorganLester
Copy link

Update: I had in fact had a temp passphrase. After recovery > entering old passphrase I got the original address!

@OrEagle97327
Copy link
Author

What is a "temp passphrase" and where did you insert it?

@lostis4d
Copy link

this has just happend to me, I had 10 Neo, and someone just sent me 3 NEO, and my wallet balance has changed to 0 and no transaction history, I am using the Ledger nano S

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 14, 2018 via email

@Evgeny1986
Copy link

How can we return your coins? where to turn to? I am willing to write to any authority.

@jon85943
Copy link

Have tried recovering your private key and public key pairings that are able to be produced from your 24 word phrase? I had issues that were never resolved with no transactions ever confirming and decided to try and get my private key using the BIP-39 Recovery Tool offline. When I used the tool it gave me a bunch of public/private key pairings, you may be able to find the matching keys. My key was first in the list and I just opened it in Neotracker.io.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 14, 2018

Thanks Morgan for the private response we had on Discord
I have been doing some review - Earlier Caronos commented:
"Based on the nature of the problem, it seems to be only a ledger device problem. So as far as I know, wiping your device and resetting it should show the glitch."

I missed it back then, but I am "gun shy" - Should I empty wallet first for safety? (6figures-HotCrypto)
When is it "NOT" safe to Un-plug USB connection to Ledger?

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 14, 2018

jon85943 - yes I have run bip-39 recovery tool - and another by someone else - plus I have come across a generic one for many coins. ( iancoleman's version)
Mine returns the last address I got (in my case a third public address)

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 14, 2018

Do I dare reset my Nano with lots of asset out there?

@OrEagle97327
Copy link
Author

Evgeny1986 - Are trying to return coins or recover some?
The reason we are into crypto so no authority need to be involve.
There are forums to go to like this one or reddit or discord, or others.

@Evgeny1986
Copy link

OrEagle97327 - Clear. I'm just very upset. Any experts can help me? as it happened, that my tokens are on a different wallet. For me it is a very large sum.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 15, 2018

Evgeny1986 - I still do not understand the question.
Can you describe the issue?

@stevesbrain
Copy link

@OrEagle97327 I have reset my Nano many times and recovered with the mnemonic seed. I did this before being "comfortable" storing my Neo there (i.e. I sent some testnet GAS to it, then reset it, recovered from my passphrase, and verified the testnet GAS was still there - it was). Provided your mnemonic seed is correct, you run zero risk resetting your device. The only time it should change/disappear is if you've set a passphrase on top of this (so 24 word seed + single word for an "extended" seed). Then, if you wipe the device, you'll have to restore your seed and set up the passphrase as well.

@Evgeny1986
Copy link

Evgeny1986 commented Jan 15, 2018

OrEagle97327
Yes. Now I will describe the problem.
I have in my wallet Neon was 19 coins.
The address of my purse: AN4FMbGefBGpBYCMJW1dKjEbm9kPjdghao
A couple of days ago I went to the purse and found I had no coins.
I went to https://neotracker.io/tx/8202dc123540d009c20ce3b7eb1b4e6944b39ad7b4a5074cfaf1a026f7ec0c37
I discovered that my coins transferred to the wallet AKL1VMWPsW9qHWrwh8TYz9NJGU6GC561ca

I coins never been transferred!!!
my coins stolen.

@shrwnsan
Copy link

shrwnsan commented Jan 15, 2018

Paranoid about this now. I downgraded from 0.0.9 to 0.0.7. What should I do to prevent this from happening?

I have already signed some transactions earlier today. Am on the latest macOS as well. Greatly appreciate the insights.

Looking forward. Thanks!

@seinwave
Copy link

Echoing @stechico's comments. I haven't experienced the issue, but I'm running 0.0.9 on latest macOS.

I've seen that @coranos has tried valiantly to reproduce the bug, without success. That's encouraging to me.

All the same, would love a security blanket here. Has there yet been a successful diagnosis of the problem?

Thanks for all of your input, guys. Obviously a legitimate concern.

@ghost
Copy link

ghost commented Jan 15, 2018

So, @stechico this is not the same problem as the problem I've been looking at.

Your coins were stolen. Your ledger address remained the same, but the coins were transferred elsewhere. The problem I was looking at is where your ledger address changed, and the coins were still at the old address.

For anyone that had the address change on them, were you able to claim gas at the first address, before it changed?

The only way I've been able to reproduce the problem is by creating noise on the USB line which flipped a few bits. That shouldn't be considered a "normal" scenario.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 15, 2018

@seinwave I do not know of a solution yet. Still believing one will be found.

I lost my Neo while using Neon wallet, ver 0.0.7. Wallet ver 0.0.9 has some good upgrades.

@coranos Would unplugging the USB from the Ledger at the wrong time, create the noise you refer to?

I am maintaining this thread to post warning and support to others who follow. One user whom has been in these conversation has lost 1900 Neo or more. Make my 108, kinda paltry. (still painful)

@ghost
Copy link

ghost commented Jan 15, 2018

Unplugging the USB or just having it not fully seated would cause the noise, yes, or a frayed wire.

Claiming gas would test that scenario, as you can only claim gas with a valid key combination.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 15, 2018

I hate to ask this.... (shuda,kuda,wuda)(undocumented feature)

Is there a possibility, ...one of these "scenario" creates 'paraphrase" wallet without-paraphrase?
...Has the symptoms!!

This comes to me while reading the Ledger page on advanced techniques
https://ledger.zendesk.com/hc/en-us/articles/115005214529-Advanced-Passphrase-options


PASSPHRASE ATTACHED TO A PIN

In your Nano S, go to SETTINGS > Security > Passphrase > Attach to a PIN

With this feature, you can create, open and manage a second (and hidden) wallet attached to a specific passphrase, wallet accessible when you connect your Nano S with another PIN code. As long as your session will be open with this PIN code, you will be able to access it. When you disconnect your Nano S or when you quit the standby mode, you will be asked a PIN code, then you can choose to reopen this one or enter the main PIN code.

Open the "Settings" of the Nano S
Select "Security"
Select "Passphrase"
Select "Attach to a PIN"
Enter a second and new PIN code
Confirm this new code
Enter and confirm a secret passphrase (100 characters max)
Enter your first main PIN code to validate

Then during the rest of your session until the Nano S is disconnected, you will run an hidden wallet. Next time you will enter your PIN code, you will choose which PIN code you want to enter, main one or second one.
You can't set a third PIN code. If you ever set a new PIN code attached to a passphrase, it would erase the first one. To manage more than 1 hidden wallet you need to use the "temporary passphrase" option.


Got lottsa experience and knowledge over the last several days, guess I paid for an education.
(noStudentLoan)

@ghost
Copy link

ghost commented Jan 15, 2018

you could definitely have done that, but then to recover you should be able to just use the same pin and it'll use the same hidden wallet. or just use the same passphrase.

I don't know much about the "hidden passphrase" options, but messing with it and forgetting what you did would definitely screw you over.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 15, 2018

I am theorizing, ...there is a wallet on the Ledger "without" a passphrase. (the first public key)
...Has the symptoms!!

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 16, 2018

Juss thinkin outside the box...

Can bip-39 recovery tool be used to attempt to return the wif on;
"...second (and hidden) wallet..." not " ...attached to a specific passphrase..." ??

be a murukal wudeniit

@ghost
Copy link

ghost commented Jan 16, 2018

Uh, um, that's quite a box.

By default, the recovery tool does not require a passphrase. So by default it returns the wallet not attached to a passphrase.

There is no second hidden wallet with "no" passphrase, it's a second hidden wallet "with" a passphrase.

The first wallet, the one you see by default, is the one "without" a passphrase.

@OrEagle97327
Copy link
Author

OrEagle97327 commented Jan 16, 2018

I have been conferring with others who have suffered loss due to this fluke.
I did "not" do any of the steps to set up a passphrase. Others say the same.

As I study this; ...the symptoms are just like there is a "passphrase" wallet just waiting for us to access.

Am I too far outside the box, for this to be possible?
With my limited experience, I know not, how to test or search this kind of theory.
I would like to hear Ledger has looked into this kind of possibility.
Does the CityOfZion community, have specialist in the Ledger security settings, willing to consider this?

Is this a matter of; Who pays for the research?
...I have 108 Neo, to donate to the community, as a reward fund, when the solution is found.
Tell me what more I can do to keep the community involved in finding the solution.
Others have suffered also. While painful, I will be fine.
Just has to be worth someone's time. Neo should be all over this.
The others will appreciate it, I am sure.
I have read that over 3000 Neo has been lost to this "undocumented feature"
That is just the ones we have heard about.

@shrwnsan
Copy link

@coranos Yah, what I've mentioned in terms of precaution was in the scenario of this problem,
"where your ledger address changed, and the coins were still at the old address."

From what I gather so far from the thread:

  1. Don't set a passphrase on the default, first one that comes "without".
    Does that mean leaving it alone, its more likely to be recovered with the linked recovery tool?

  2. Make sure to have the USB wire and the Ledger be in a position that's stable when in use with the computer; to avoid freakish bit updates caused by faulty wires, etc.

Anything else for those of us that are in the high-level area of this subject? Thanks

@scriptonum
Copy link

scriptonum commented Sep 25, 2018

Hi Right now, all the efforts of this thread are directed to SOLVING a problem. Could we have some advice on PREVENTING a problem? I have a Nano S that I haven't used in over a month. I have some NEO that appeared on the Nano S app ..... last time I looked. I seem to understand I might have to update the NEO/NEON wallet and I seem to understand that i might have to update the Nano S software .. and that might cause a problem because my PC uses Windows 7 ?? Can anyone give some advice that even I can understand on how to not become one of the people with a problem? Peter

Hi Peter,

I did this to prevent it from happening again: I sold my NEO and bought some BTC instead.
But I guess you want to keep your NEO, so this is what I would do next time:
IF I buy NEO, I would not keep them save using my Ledger, but I would keep them on an exchange.
Yes, exchanges can be hacked, but it appears that one can lose NEO as well using a Ledger.

If you do want to use a Ledger, then I strongly advise you to regularly update the software of your Ledger as well as the NEO software. As for me an update was the solution. It made me rather nervous as I didn't know I had to update, it was all new to me. Then updating the Ledger software was not enough: had to update the NEO software as well.

But for me, I may buy a few NEO again, but I will keep them on an exchange. Maybe that's like 'swearing in the church', but it's what I'd do.

@WilburT55
Copy link

WilburT55 commented Sep 25, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 25, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 25, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 25, 2018 via email

@stevesbrain
Copy link

@WilburT55

I appreciate the detailed response. Right now I am in the middle of attempting some other fixes proposed by another member on this chat.

No worries at all - I hope it works out for you :)

On a general note. your in Australia? I had a favorite Aunt who lived in Syndney but retired to Gold Coast years back. Both her and my mom were born in England, raised in NZ. My dear mother had the misfortune of meeting and marrying my American Marine Corp father during WWII. She went from living in near paradise in NZ to moving to Brooklyn NY (Borough of NYC) which from a beauty standpoint is on the opposite side of the spectrum.

I am indeed :) Gold Coast is a beautiful place, and a great place to retire, I'm sure! I would love to visit NZ one day though; it looks beautiful indeed!

So I assume your a big believer in the NEO project then. So perhaps you can give me your views from an IT standpoint.? As much as I liked all the info I read about NEO, I always had in the back of my head, what happens if USA and China continue to have trade war and possibly other major conflicts? Would the Government of China somehow step in and be able to stop NON Chinese citizens from accessing their NEO or other Chinese blockchain projects, such as ONTOLOGY? Elastos etc. Again I am not an IT guy but I have heard about the "Great Firewall of China" Your thoughts.?

The Great Firewall of China primarily applies to its citizens, rather than to outside traffic accessing Chinese stuff. However, I guess there is always potential for the Chinese Government to forbid foreigners access to NEO. I'd see that playing out one of two ways:

  • We legitimately lose access to the "mainstream" NEO project, but fork off an international chain
  • NEO project continues on, running servers inside + outside of China, and we see a little price dip but not much else

I don't see the Government targeting NEO specifically - not unless things got really bad - as it'd be a small blip on their radar, at this stage at least. Time will tell!

@chexx42
Copy link

chexx42 commented Sep 25, 2018

WilburT55 You did read my comment from a few days ago with the info and the pic of the settings?

For ETH select BIP32 (You get a slightly different layout) as the Derivation Path instead of BIP44 and setting the BIP32 Derivation Path to m/44'/60'/0'/

Not sure the TOR browser would help the security in this situation, if you have a Mac or Windows 10 you can just go to Airplane mode or disconnect Internet in anything that doesn't.

@WilburT55
Copy link

WilburT55 commented Sep 26, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 26, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 26, 2018 via email

@stevesbrain
Copy link

@WilburT55 Indeed, there are so many coins around now it is very time consuming to keep track! Regarding ONT vs. NEO, I don't have a lot of opinion yet. Whilst I have moved my airdropped ONT to the ONT chain, I haven't done a great deal of research into ONT (nor have I accumulated any more than I have been dropped).

Just keep in mind that it would only be ONT you were airdopped initially, or purchased early when ONT was still on the NEO chain that you would potentially lose. I presume this is what you are specifically worried about?

@WilburT55
Copy link

WilburT55 commented Sep 27, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 27, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 27, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 27, 2018 via email

@WilburT55
Copy link

WilburT55 commented Sep 29, 2018 via email

@WilburT55
Copy link

Hi chexx42,

I been sending other messages to you via Gmail. Just saw that its not getting to this github for some reason. So this might be a redundant message? IDK I did as you suggested with the ETH and Ledger and I was able to access my old ETH MEW address. Just dont know why its not working for my NEON wallet. IDK. MOST frustrating. I just got another response from Ledger support.
Their standard response is. IF a person chose "restore configuration" you can get your coins back. If you chose "New configuration" you get nothing back.
Wiped clean.
I knew that when I had to reboot my NANO S.
Its my understanding that the assets are never lost on the Blockchain, so if for some ODD reason I really did chose "new"by some God awful mistake,
Is there any point in attempting to regain those assets using the BIP39 Mneumonic phrase. ?
Any thoughts on the topic???

@chexx42
Copy link

chexx42 commented Sep 29, 2018

WilburT55 Is your ETH MEW address your MEW address or your Ledger address? I'm assuming it's a bit like Neon wallet as I haven't used MEW. Have you loaded ETH app on to ledger with the Ledger Live manager to enable you to get the ETH public address and hopefully authenticate your seed phrase.

I have just had a reply back from Ledger after asking if their were different parameters for coins and got back an answer saying to use the normal parameters, looks a bit like a stock answer, even though I pointed out that I had found diferent parameters for ETH.

My email is "info(at)caffcor.net" if you want quicker response for next 24 hours

@WilburT55
Copy link

WilburT55 commented Sep 30, 2018 via email

@cryptomitchman
Copy link

I am using a ledger nano to login and I cant get my balances to show on Neon Wallet. I do see it on the blockchain. I am using 0.2.8. Any work around? I am trying to move ONT quickly..

@chexx42
Copy link

chexx42 commented Sep 30, 2018

cryptomitchman do you have the latest firmware, think it's 1.4.2, Ledger Live displays it and as you cannot see what version of Neo App is on the Ledger, use Ledger Live manager to remove the neo app and then re-install it so you have the latest version.

@cryptomitchman
Copy link

Thanks so much Chexx42. It had to update the firmware. But I also had a bad hash for a coin I tried to add. I had to remove the hash I entered. I finally got it done!

@Gazby
Copy link

Gazby commented Oct 2, 2018 via email

@chexx42
Copy link

chexx42 commented Oct 2, 2018

Do you have the latest Ledger nano s Firmware 1.4.2,
Latest Neo app installed via Ledger Live Manager (You can't see what the current version is, so un-install it and load the latest version)
and latest Neon Wallet 0.2.8

@WilburT55
Copy link

WilburT55 commented Oct 2, 2018 via email

@comountainclimber
Copy link
Member

@Paynebutler2229 you have been reported. This issue is being closed due to inactivity.

@GoannaStew
Copy link

GoannaStew commented Jan 22, 2019

Hey folks, only just noticed I lost 140 NEO back in Nov ... I opened a NEON wallet so I could store my NEO safely and deposited 140 but it went out as soon as it went in or so it seems ....
https://neoscan.io/transaction/59433421a0b26f9bf3407826ff18f278fc6274b742cec7e68b7437fcda93b147
Using latest MAC OS Version
screen shot 2019-01-22 at 6 28 45 pm

@GoannaStew
Copy link

GoannaStew commented Oct 31, 2020 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests