Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

Where was this posted? Can you post a link?

edit:

if you're talking about https://twitter.com/LukeDashjr/status/1609661811455819776, my guess is that he's either omitting something (eg. the cold wallet was internet connected, or there was a backup of its wallet floating around somewhere), or suffered a stuxnet level attack.



sort by: page size:


https://twitter.com/brandontwall/status/1283525485440503811

Hours in, seems the vulnerability was not yet patched but simply blue-checks had posting rights pulled. Only non-verified accounts have been posting the wallet key for a while now (search new to find them).

I know it's easy to judge from afar but I can't believe they're leaving the site up during this.


Tweet author didn't thread tweets properly. Full 3-tweet sequence:

1/3 We have identified a large-scale security breach related to one of our ETH hot wallets and one of our BSC hot wallets. At this moment we are still concluding the possible methods used. The hackers were able to withdraw assets of the value of approximately USD 150 millions. https://twitter.com/sheldonbitmart/status/146731625285522636...

2/3 The affected ETH hot wallet and BSC hot wallet carries a small percentage of assets on BitMart and all of our other wallets are secure and unharmed. We are now conducting a thorough security review and we will post updates as we progress. https://twitter.com/sheldonbitmart/status/146731630643736166...

3/3 At this moment we are temporarily suspending withdrawals until further notice. We beg for your kind understanding and patience in this situation. Thank you very much. https://twitter.com/sheldonbitmart/status/146731636573223321...


Strange, a month ago he tweets about his server being compromised:

https://twitter.com/LukeDashjr/status/1593227756841578496

Go figure


This is the earliest non-deleted tweet I've found referencing the bitcoin address (or rather, noticing that an account got hacked). It was sent at 12:23PM Pacific time (more than 1.5 hours ago): https://twitter.com/lawmaster/status/1283481418518208513

It looks like it is just twitter hack. The wording in those tweets doesn't fit Luke's writing style.

This is his mastodon, let's see if he posts anything there:

https://bitcoinhackers.org/@lukedashjr


Could this be a "boating accident" since it's tax season? Or maybe only his Twitter was hacked? No info from him at his mastodon https://mastodon.social/@lukedashjr@bitcoinhackers.org

If true this is absolutely devastating. Somewhat funny too, but devastating.

edit: Well, it's confirmed. Insane.

https://twitter.com/peterktodd/status/1609655629903265795

https://twitter.com/peterktodd/status/1609666001251229696


In their statement they deny accessing bank details:

> The bug led to random user data being exposed to the wrong user when accessing our user interfaces. It is important to note that the access to data has been entirely random and not showing any data containing card or bank details (obfuscated data was visible). This means that it has been impossible to access a specific user’s data.

This is not the experience of the user in the OP: https://twitter.com/esraefe/status/1397843949985931265


Apparently, this wasn't a smart contract hack:

https://twitter.com/Mudit__Gupta/status/1425115177771405312


There is no indication that the accounts whose data was accessed were the accounts which tweeted the crypto scam.

Therefore, I'm not sure that's a straightforward explanation.


it was somebody else's account. Also, see @foone's thread here:

https://twitter.com/Foone/status/1346924327996772354

tl;dr: the government has appropriate computer security in place to prevent this sort of thing, and it's not clear what the deal was with that particular computer.


They’ve since said their website was hacked.

> The website was hacked yesterday and the message was shown by the hackers. It has been taken down.

https://twitter.com/defi100/status/1396361647149633537?s=21



Apparently his servers keep getting hacked, which doesn’t reflect well on his security practices: https://twitter.com/LukeDashjr/status/1606885577843957762

The "OpenSea" in the title is borderline clickbait. It was a phishing attack on users, not on OpenSea.

As someone has said on Twitter [1], blaming OpenSea is easy (and drives clicks), but wallet providers should be doing a lot more to protect users.

[1] https://twitter.com/SkiranoETH/status/1495485598940938241


https://twitter.com/petertoddbtc/status/509145414008725504

Peter Todd ? @petertoddbtc

"Interesting, got another forwarded email from "satoshi", from 2011 - indicates this was a hijacked account, not expired and re-registered."

----

Going to grab some popcorn, this might get pretty entertaining...


Could not find any official stories, but it happened. The offending tweets have been removed and his account restored. [1] Hackers made a lot of $ with crypto draining operation. This is the last person I would expect to be hacked...you would think he would have everything down pat. Maybe an inside job involving phone carriers or maybe even a disgruntled Twitter employee did it. Who knows.

[1] tweet removed https://twitter.com/VitalikButerin/status/170064387659025246...?

Shows how lucrative hacking twitter is. Forget hacking databases or social security numbers. or credit card numbers. meh. Or forget bank robbing. the real $ will always be hacking big twitter accounts to promote crypto scams.


Update: https://twitter.com/naka_frodo/status/1609655813789949959/ph...

Looks like possibly a supply chain attack targeted specifically at Luke Jr's server.


Judging by this, it looks like his account was hacked: http://twitpic.com/ehm2h.
next

Legal | privacy