HomeEthereumSecurity alert : Ethereum.org Forums Database Compromised

Security alert [12/19/2016]: Ethereum.org Forums Database Compromised

-


On December 16, we were made aware that someone had recently gained unauthorized access to a database from forum.ethereum.org. We immediately launched a thorough investigation to determine the origin, nature, and scope of this incident. Here is what we know:

  • The information that was recently accessed is a database backup from April 2016 and contained information about 16.5k forum users.
  • The leaked information includes

    • Messages, both public and private
    • IP-addresses
    • Username and email addresses
    • Profile information
    • Hashed passwords

      • ~13k bcrypt hashes (salted)
      • ~1.5k WordPress-hashes (salted)
      • ~2k accounts without passwords (used federated login)

  • The attacker self-disclosed that they are the same person/persons who recently hacked Bo Shen.
  • The attacker used social engineering to gain access to a mobile phone number that allowed them to gain access to other accounts, one of which had access to an old database backup from the forum.

We are taking the following steps:

  • Forum users whose information may have been compromised by the leak will be receiving an email with additional information.
  • We have closed the unauthorized access points involved in the leak.
  • We are enforcing stricter security guidelines internally such as removing the recovery phone numbers from accounts and using encryption for sensitive data.
  • We are providing the email addresses that we believe were leaked to https://haveibeenpwned.com, a service that helps communicate with affected users.
  • We are resetting all forum passwords, effective immediately.

If you were affected by the attack we recommend you do the following:

  • Ensure that your passwords are not reused between services. If you have reused your forum.ethereum.org password elsewhere, change it in those places.

Additionally, we recommend this excellent blog post by Kraken that provides useful information about how to protect against these types of attacks.

We deeply regret that this incident occurred and are working diligently internally, as well as with external partners to address the incident.

Questions can be directed to security@ethereum.org.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

HTX 2025 Mid-Year Security Report: Upgrading a Multi-Layered Defense for a Safer Crypto Ecosystem

PANAMA CITY, July 9, 2025 /PRNewswire/ — HTX, a leading global cryptocurrency exchange, acknowledges the significant security challenges that impacted the crypto industry in...

WSPN Website Expands to Full Platform, Showcasing Enterprise-Ready Stablecoin Infrastructure

TORTOLA, British Virgin Islands, July 9, 2025 /PRNewswire/ — Following its homepage redesign in May, Worldwide Stablecoin Payment Network (WSPN, collectively referring to the WSPN Group...

DNSBTC Launches Its Best Free Cloud Mining Platform

Cryptocurrency users and passive income searchers have long coveted a mining solution that gives flexibility, simplicity, and control over how they earn and withdraw...

G-Knot Appoints Fintech, Crypto Veteran Wes Kaplan as CEO to Launch the First Finger Vein Biometric Wallet

New York, New York, July 8th, 2025, ChainwireStrategic leadership appointment positions G-Knot to redefine digital security and identity management G-Knot, a pioneering biometrics technology company...

Most Popular