Categories: PSA

Bitcointalk emails and passwords compromised due to a Social Engineering attack

As the title suggests the #1 bitcoin forum bitcointalk.org  is currently down. A tweet from the official bitcointalk twitter  explains why the forum is down:

UPDATE:

According to a message on reddit from theymos it looks like the attacker only had access for 12 minutes and it is unlikely that he was able to get a complete dump of the db.

The forum’s ISP NFOrce managed to get tricked into giving an attacker access to the server. I think that the attacker had access for only about 12 minutes before I noticed it and had the server disconnected, so he probably wasn’t able to get a complete dump of the database. However, you should act as though your password hashes, PMs, emails, etc. were compromised. The forum will probably be down for 36-60 hours for analysis and reinstall. I’ll post status updates on Twitter @bitcointalk and I’ll post a complete report in a post in Meta once the forum comes back online. – theymos

UPDATE 2:

Another message was posted on the bitcointalk twitter account:

Related Post

Compromised password hashes means that your actual passwords have not been revealed but their hash has. What that can do is link passwords across different accounts. For example the most common password hash algorithm is the md5 which is used to store a one way hash of a password. The md5 hash of the password “abc123” would be “e99a18c428cb38d5f260853678922e03”. It is a good idea to change the password on any accounts that used the same password as your bitcointalk account because an attacker can try to access your alternate accounts by authenticating to the server by sending packets of your hashed password and username.

What is a Social Engineering attack?

A Social Engineering attack against the ISP means that the attacker was able to obtain the administrator’s personal information and used it in order to compromise the admin’s account. Such attacks are common against celebrities whose personal information is commonly leaked. This article

from the washing post shows how easy it is to hack someone’s iCloud. It is actually how most if not all celebrity photos were obtained.

How to Protect yourself from such an attack?

Some ways to protect yourself from a Social Engineering attack is by safeguarding even inconsquential information about yourself, lie to security questions so that the answer comes form memory and not from an event. View any password reset email with skepticism even ones that say “If you didn’t request it, don’t do anything”. Try to find a way to watch you account’s activity and log such infrmation as logins + IP address. Gmail already does that and you can view your login history + IPs used from the account settings. Last but not least diversify your passwords, critical services, and security questions. Don’t use the same password for multiple sensitive accounts and have a unique password to any important account.

Mark Arguinbaev

I'm a 29 year old cryptocurrency entrepreneur. I was introduced to Bitcoin in 2013 and have been involved with it ever since. Fun Fact: I mined cryptocurrency using my college dorm room's free electricity.

Share
Published by
Mark Arguinbaev

Recent Posts

Cardano-Trump Rumors Pump Prices as Fintech Investors Bolster LINK and Lunex Network 

While unconfirmed, speculations about US President Donald Trump and Cardano's founder have prompted many investors…

18 mins ago

Polkadot Price Flashes Bullish Signal Amid DeFi Investment Surge 

Polkadot's price predictions are bullish after DOT breached its $5 resistance. So far, DOT's price…

26 mins ago

Kaspa Price Prediction: Can Kaspa Reach $1 In Bull Run As JetBolt Smashes Milestones

With the entire crypto market bustling with bullish sentiment, analysts speculate with bold price predictions…

35 mins ago

DOGE Technicals Signal Correction: $50M Capital Might Rotate Into Ripple and DTX Exchange This Week

Dogecoin (DOGE) Technical Analysis: About To Correct? Today, Dogecoin (DOGE) is trading at $0.39, currently…

4 hours ago

Ethereum Reaches Yearly High Amid Bullish Sentiment, But Whales Signal Caution

Ethereum (ETH) has surged to its highest price of the year, supported by positive funding…

4 hours ago

Bitcoin Surges To $93K As New Addresses And Institutional Investments Hit Record Highs

Bitcoin has reached a new all-time high of $93,000, rising by 30% since the U.S.…

4 hours ago