Close Menu

    Subscribe to Updates

    What's Hot

    Pudgy Penguins partners with Lufthansa Miles program to expand PENGU utility

    June 13, 2025

    Here’s why WhiteBIT’s WBT hit a new all-time high while the crypto market crashed

    June 13, 2025

    Bitcoin options worth nearly $3B to expire on June 13

    June 13, 2025
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Security alert [12/19/2016]: Ethereum.org Forums Database Compromised
    Ethereum

    Security alert [12/19/2016]: Ethereum.org Forums Database Compromised

    Michael JohnsonBy Michael JohnsonDecember 20, 2024No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On December 16, we were made aware that someone had recently gained unauthorized access to a database from forum.ethereum.org. We immediately launched a thorough investigation to determine the origin, nature, and scope of this incident. Here is what we know:

    • The information that was recently accessed is a database backup from April 2016 and contained information about 16.5k forum users.
    • The leaked information includes

      • Messages, both public and private
      • IP-addresses
      • Username and email addresses
      • Profile information
      • Hashed passwords

        • ~13k bcrypt hashes (salted)
        • ~1.5k WordPress-hashes (salted)
        • ~2k accounts without passwords (used federated login)

    • The attacker self-disclosed that they are the same person/persons who recently hacked Bo Shen.
    • The attacker used social engineering to gain access to a mobile phone number that allowed them to gain access to other accounts, one of which had access to an old database backup from the forum.

    We are taking the following steps:

    • Forum users whose information may have been compromised by the leak will be receiving an email with additional information.
    • We have closed the unauthorized access points involved in the leak.
    • We are enforcing stricter security guidelines internally such as removing the recovery phone numbers from accounts and using encryption for sensitive data.
    • We are providing the email addresses that we believe were leaked to https://haveibeenpwned.com, a service that helps communicate with affected users.
    • We are resetting all forum passwords, effective immediately.

    If you were affected by the attack we recommend you do the following:

    • Ensure that your passwords are not reused between services. If you have reused your forum.ethereum.org password elsewhere, change it in those places.

    Additionally, we recommend this excellent blog post by Kraken that provides useful information about how to protect against these types of attacks.

    We deeply regret that this incident occurred and are working diligently internally, as well as with external partners to address the incident.

    Questions can be directed to [email protected].



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Michael Johnson

    Related Posts

    Now accepting interns – Join the Ethereum Season of Internships

    June 12, 2025

    Ethereum price prediction as ETH reclaims $2,800 level

    June 11, 2025

    Tickets are live for the Ethereum World’s Fair! And we’re launching the Supporter Program

    June 10, 2025
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Pudgy Penguins partners with Lufthansa Miles program to expand PENGU utility

    By John SmithJune 13, 20250

    Pudgy Penguins has partnered with Lufthansa’s Miles & More program, letting users earn airline miles…

    Here’s why WhiteBIT’s WBT hit a new all-time high while the crypto market crashed

    June 13, 2025

    Bitcoin options worth nearly $3B to expire on June 13

    June 13, 2025

    Altcoin ETF summer in limbo as SEC hits pause on DOGE, HBAR, and AVAX filings

    June 13, 2025

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (569)
    • Bitcoin (27)
    • Blockchain (136)
    • Crypto (8,626)
    • Ethereum (623)
    • Lithosphere News Releases (144)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.