Close Menu
    Facebook X (Twitter) Instagram
    Thursday, December 18
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Security alert [12/19/2016]: Ethereum.org Forums Database Compromised
    Ethereum

    Security alert [12/19/2016]: Ethereum.org Forums Database Compromised

    Olivia MartinezBy Olivia MartinezDecember 16, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On December 16, we were made aware that someone had recently gained unauthorized access to a database from forum.ethereum.org. We immediately launched a thorough investigation to determine the origin, nature, and scope of this incident. Here is what we know:

    • The information that was recently accessed is a database backup from April 2016 and contained information about 16.5k forum users.
    • The leaked information includes
      • Messages, both public and private
      • IP-addresses
      • Username and email addresses
      • Profile information
      • Hashed passwords
        • ~13k bcrypt hashes (salted)
        • ~1.5k WordPress-hashes (salted)
        • ~2k accounts without passwords (used federated login)
    • The attacker self-disclosed that they are the same person/persons who recently hacked Bo Shen.
    • The attacker used social engineering to gain access to a mobile phone number that allowed them to gain access to other accounts, one of which had access to an old database backup from the forum.

    We are taking the following steps:

    • Forum users whose information may have been compromised by the leak will be receiving an email with additional information.
    • We have closed the unauthorized access points involved in the leak.
    • We are enforcing stricter security guidelines internally such as removing the recovery phone numbers from accounts and using encryption for sensitive data.
    • We are providing the email addresses that we believe were leaked to https://haveibeenpwned.com, a service that helps communicate with affected users.
    • We are resetting all forum passwords, effective immediately.

    If you were affected by the attack we recommend you do the following:

    • Ensure that your passwords are not reused between services. If you have reused your forum.ethereum.org password elsewhere, change it in those places.

    Additionally, we recommend this excellent blog post by Kraken that provides useful information about how to protect against these types of attacks.

    We deeply regret that this incident occurred and are working diligently internally, as well as with external partners to address the incident.

    Questions can be directed to [email protected].



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleA crypto invoice generator built for online businesses
    Next Article Pump Fun taps high-profile lawyers to battle Burwick lawsuit
    Olivia Martinez

    Related Posts

    Dev Update: Formal Methods | Ethereum Foundation Blog

    December 18, 2025

    Security alert – All geth nodes crash due to an out of memory bug

    December 18, 2025

    The Ethereum network is currently undergoing a DoS attack

    December 18, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Web3’s real ‘TCP/IP moment’ hasn’t happened yet

    Andrew Tate went 25X long on Hyperliquid, got liquidated

    Dev Update: Formal Methods | Ethereum Foundation Blog

    Dogecoin price forms bullish reversal setup as whales buy and exchange balances drop

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Web3’s real ‘TCP/IP moment’ hasn’t happened yet

    December 18, 2025

    Andrew Tate went 25X long on Hyperliquid, got liquidated

    December 18, 2025

    Dev Update: Formal Methods | Ethereum Foundation Blog

    December 18, 2025
    Lithosphere News Releases

    AI Crypto Platform Lithosphere (LITHO) Introduces Ignite, an Automated Launchpad for Ecosystem Discovery

    December 16, 2025

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 2025

    AGII Deploys Adaptive Integrity Core for Autonomous Contract-Level Verification

    December 10, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.