Before I get to the drama part, the amount is only about 260$ and I still have other funds in safer places than the address that got hacked.
Now let's get to the drama.
The address that got hacked is the one I whitelisted for the Runi minting, about 250$ was paid in vouchers in order to get that address whitelisted. That too is probably lost.
Splinterlands' team gave me hope that they might be able to whitelist another address instead. Cause, well, I still want to mint a Runi. wouldn't miss the chance for anything.
How did it happen?
That's the mysterious part. I guess someone has had access to the address for a long time and set a bot or something to automatically send eth to himself. The address was empty and inactive for nearly two years so the hacker was very patient or they only recently gained access.
How and when I knew about the hack:
On Sep 25th, I was preparing for the Runi mint. I sent 0.188 Eth from hive-engine (Tribaldex) to my (ex) Ethereum wallet 0xD3db849D7FDA42f16B37cB14840CBF6E1C9b4643 . I was watching the transaction and saw that it was confirmed but the Eth didn't show up in my balance. At first, I thought it was a bug from Metamask. I kept refreshing and rechecking. It took me more than two hours to get suspicious. Then I checked my wallet on Etherscan. There was a transaction I didn't sign, seconds after my withdrawal from hive-engine, that emptied my wallet and sent everything to this address (meet my hacker) 0x057576D81E5083A7cB507A480285A95Db693B39C
I don't know if there's anything that can be done about it now.
How did they have access?
According to Etherscan, I don't have any suspicious permissions. It has to be that someone had the private key. No idea how they got it, but I have some theories. Too many theories to actually know what really happened. I wasn't using the best strategies to keep that key safe. Maybe cause the wallet only had small amounts in it for over a year.
The purpose of this post
is more than ranting and playing the victim. I need advice about what precautions to do to avoid such unfortunate events in the future. I created a new Eth address so I won't have to use the hacked one again. But, is it safe to still use Metamask? is there a safer way? I'm gonna probably send another amount to the new Eth wallet (if the Splinterlands team accepts my request) to mint a Runi. So I wanna be sure this time.