15.9 C
Manchester
June 18, 2025
Safety alert [12/19/2016]: Ethereum.org Boards Database Compromised
BlogEthereum

Safety alert [12/19/2016]: Ethereum.org Boards Database Compromised

[ad_1]

On December 16, we have been made conscious that somebody had lately gained unauthorized entry to a database from forum.ethereum.org. We instantly launched a radical investigation to find out the origin, nature, and scope of this incident. Here’s what we all know:

  • The data that was lately accessed is a database backup from April 2016 and contained details about 16.5k discussion board customers.
  • The leaked info contains

    • Messages, each private and non-private
    • IP-addresses
    • Username and electronic mail addresses
    • Profile info
    • Hashed passwords

      • ~13k bcrypt hashes (salted)
      • ~1.5k WordPress-hashes (salted)
      • ~2k accounts with out passwords (used federated login)

  • The attacker self-disclosed that they’re the identical particular person/individuals who recently hacked Bo Shen.
  • The attacker used social engineering to realize entry to a cell phone quantity that allowed them to realize entry to different accounts, one in every of which had entry to an previous database backup from the discussion board.

We’re taking the next steps:

  • Discussion board customers whose info could have been compromised by the leak shall be receiving an electronic mail with extra info.
  • We have now closed the unauthorized entry factors concerned within the leak.
  • We’re imposing stricter safety tips internally similar to eradicating the restoration telephone numbers from accounts and utilizing encryption for delicate knowledge.
  • We’re offering the e-mail addresses that we imagine have been leaked to https://haveibeenpwned.com, a service that helps talk with affected customers.
  • We’re resetting all discussion board passwords, efficient instantly.

In the event you have been affected by the assault we advocate you do the next:

  • Make sure that your passwords are usually not reused between providers. In case you have reused your discussion board.ethereum.org password elsewhere, change it in these locations.

Moreover, we advocate this excellent blog post by Kraken that gives helpful details about the way to defend in opposition to some of these assaults.

We deeply remorse that this incident occurred and are working diligently internally, in addition to with exterior companions to handle the incident.

Questions may be directed to security@ethereum.org.

[ad_2]

Related posts

eth2 fast replace no. 18

crypto

Is it Too Late To Purchase GME? GameStop Value Surges 25% And This May Be The Subsequent Crypto To Explode

crypto

Ethereum Execution Layer Specification | Ethereum Basis Weblog

crypto

Leave a Comment