HACKER ALERT! PLEASE CHANGE YOUR PASSWORDS STEEMIANS!!

in Steemit Feedback3 years ago (edited)


Hacker GIF from Dribbble

When I checked my steemworld a few mins ago, I was confused why there was a powerdown notice/warning on it. I never initiated a powerdown on my account because I'm accumulating Steem Power.

So, I noticed that there was indeed a powerdown on my wallet and I checked the wallets of my family and friends who are in Steemit and they have power downs too, and transfers of Steem and SBD to an account I don't know:

image.png

These are the funds that was hacked from me, my friends, and our charity group!

image.png

The account is still receiving Steem and SBD from others as of this moment. As of 11am EST this is the hacker's wallet:

image.png

Secure your accounts!

The account is still receiving funds from multiple Steemit accounts, some were even inactive for 2 or 3 years:

image.png

The worst thing is that the funds from @creativestreet was for our charity works for street children. This hacker literally stole from street kids!

I also had to update all of my logins and friend's logins, including Steemit, Hive, Facebook, basically all my logins all over the internet, and I had to activate 2FA on all of them that has 2FA. I think we also need 2FA function on Steemit.

I'm not tagging the hacker's account so they will not be notified.

To be safe, since we don't know where they actually got our passwords, possible from saved logins on browsers or from previous dapps that we used in Steemit, please update your passwords guys.

Someone please freeze their account! And also return the funds if possible. Thanks!

Tagging @steemitblog, @steemcurator01, @steemcurator02, @executive-board for awareness!

Sort:  

Hope everyone will change their passwords.

Take a look at this post from @cryptokannon in case it is of help...

And check if you have given authorities to any old apps.

This is very informative. Thanks for sharing.

I hope everyone would. And also update their recovery accounts just in case. Thanks!

Quien me puede guiar cómo cambiar mi contraseña?????

Go to steemitwallet.com
Login
Under Wallet
Go to Change Password
Put your current password
Click on Generate Password
Make sure to save the new password
Paste new password
Check the boxes then continue


La traducción puede estar mal

Ir a steemitwallet.com
Acceso
Debajo de la billetera
Ir a Cambiar contraseña
Pon tu contraseña actual
Haga clic en Generar contraseña
Asegúrate de guardar la nueva contraseña.
Pegar nueva contraseña
Marque las casillas y luego continúe

Hola gracias ya la cambie, 😁 aunque al principio no me dejaba accesar luego encontré el error

It's sad how people can be so heartless. Is there a two step authentication method on steemit? I don't know if there is one. But honestly, it would help if we had one.

There's none. I think we need that, will definitely help with the security.

I believe so as well. I'm not really familiar with how steemit runs, but is there a forum to make suggestions?

I guess the Steemit Feedback community is where you can make posts about it. Other than that I don't know where else.

Thanks for sending me a PM about it Dev.

Voting does not need your active key. There shouldn't be anything supported that asks for your active key. Steem is a one-trick pony.

Saying "Don't give out your private key" is not enough. The piranhas will always be successful knowing people are not adept at these vulnerabilities.

To this day I still can't say with 100% this is a serious project because of how the "decentralization" looks.

It has been ridiculous folks. Fucking ridiculous.

Hopefully, working on the structural issues solve these recurring events.

is there many PH user got hacked brother ?
because i get this info from your friend @ruah

yes there is brother, and most of them are inactive but we have a very active friend that are affected of this hack, some of them lost morethan 200steem dm me on facebook. also their charity account has been hacked the fund was supposed to help street childrens but this hacker get those funds.

@arie.steem more like all around the world, not only in PH. the hacker is not stopping

yeah.. i see some user from indonesia also got hacked
many unactive user is the target . I still don't know where he can get their many passwords

some old dapps have been exploited, a dapps that asking for transfer request as steem-engine or steemauto. or something likethat that exploit it.

Yeah, I informed @ruah about it. I think this is global. My biggest concern was our @creativestreet charity account. Also the other people who may be part of the list that they have. So it is highly suggested for everyone to change their passwords since we don't know where the hacker got them. Hive should be notified as well, since they use the same passwords. I cannot access my Hive account anymore btw. It seems my password was changed.

Hope the steemit will be able to give the stolen steems and sbds into their rightful owner

How this hacker got the passwords from so many users?

thats the first thing you will think, we've been experience this before in different scenario, the hacker got access on the exploited dapp and use it to vote and flag, the dapp only authorized to do posting vote flag and comment, if dapp cause this then that dapp have an access to wallet transactions.

Which dapp was it? And is this still going on? Can you post the hacker's account?

upon further investigation this is the real account of the hacker @anthonyj

Thanks for this hacker alert, @deveerei.
If you look a bit further, there was now a re-transfer via another account and then to @deepcrypto8, a deposit account for a Binance exchange.

ScreenHunter 82.png

ScreenHunter 84.png

ScreenHunter 83.png

upon further investigation this is the real account of the hacker @anthonyj

Is this the hacker?

Coin Marketplace

STEEM 0.28
TRX 0.12
JST 0.034
BTC 63138.90
ETH 3290.65
USDT 1.00
SBD 3.89