Weird, did you change whonix default system's password of "changeme" to something else?
did you frequently install appimage or other type of standalone executables on your whonix machine?
I installed atomic wallet. I found the time when the attack started. I was just doing my regular vendor job. I did not install anything extra. I tried to install simplex a few days ago, but I did it with chat gpt and through my terminal. I did not download it directly from the internet
I suggest you use Qubes OS for work.
If you use it properly, this will never happen again.
Use exclusively split wallets for BTC and XMR :
forum.qubes-os.org/t/how-to-set-up-a-split-bitcoin-wallet/19017
www.getmonero.org/resources/user-guides/cli_wallet_daemon_isolation_qubes_whonix.html
Always use disposable VM to open PDF files and download pictures.
Always use a function Convert To Trusted PDF.
This is a built-in function of Qubes OS.
Just right click on the PDF file and you will see the "Convert To Trusted PDF" function in the opened menu.
Conversion will happen in a disposable virtual machine.
I advise you a close look at Qubes OS.
You will find a lot of unique and useful features.
I'm sorry this has happened to you. Steps to make sure this doesn't happen again:
Don't download anything from anyone.
Make sure antivirus is up to date.
Use strong passwords.
Make sure you have a good firewall setup to block all inbound traffic.
Remember to always keep your wallet seed encrypted!
Yes, that was my mistake. I did not encrypt the feather wallet. but neither did I with electrum. But nothing happened with this.
I was already scared that LE got me. But they would not drain my wallet and leave me hang to dry for months? Or drain my wallet at all. How can you get access to a computer and send tor ips there? I was almost about to commit suicide, because that was not only my money, also from somebody else
did you frequently install appimage or other type of standalone executables on your whonix machine?