Calling the attention of @executive-board! please beware of the hack happening right now!

in hive-153176 •  4 years ago  (edited)

Screenshot_247.png

Some of the passwords in steemit community has been exploited and maybe your password is listed!

The account @molly2 is created 23 hours ago and upon checking many users have been affected!
these need to stop right now!

So if you are still using your old password in steemit please be advised to change your password now!

calling the attention of @steemcurator01

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

@steemchiller - do you think this hack might be due to Authorities left on some old app?

SteemWorld has the facility for checking Authorities.

Do you have any tool that could scan all the accounts being hacked (see the list on the wallet of molly2) and see if there any common Authorities are left on all / most of them?


Or do you think the hack might have some other cause?

I checked a few of the hacked accounts and most of them don't have any external Authorities set, so the hacker must have access to the private keys of those.

Strange about this is the fact that most accounts are very old accounts that have not been active for a long time. To me it looks like it is an old Steem user who created many accounts in the past and is now selling the collected/farmed tokens. But this theory does not fit in all cases, because @freshstuff was active.

But...

@freshstuff was active the first time since 4 months directly after the hack happened. This is highly suspicious and tells me that all this may have been created by the victim himself to produce drama/fear:

Thank you for checking on this.

My opinion about this fake 'hack' did not change.

FYI:
https://steemit.com/@steemchiller/qrc05c
https://steemit.com/@steemchiller/qrc0g1

  ·  4 years ago (edited)

I recommend you to check the robertl13 account.

image.png

anthonyj and robertl13 use the same memo id. anthonyj is an account opened in 2016. They have many posts.

Interesting! One of the first Steem accounts. They transferred it to one of their more trustworthy accounts to confuse us (they expected someone like you to find the identical memo id).

It stems from apps that are authorized in my opinion. I suspect the developers on the other side. The hacked accounts are all old accounts.

These are very interesting, thank you.

Strange about this is the fact that most accounts are very old accounts that have not been active for a long time. To me it looks like it is an old Steem user who created many accounts in the past

the problem is few of my friend is in the list and even the charity account they running is hacked. so i dont think thats the case. maybe save password in a browser or something like that.

Also the charity account's last action on Steem was exactly 4 months ago. That are a few 'random' happenings too much to be random.

4 months ago | Start power down of 32.034 STEEM

that charity account is about 1 year inactive now, but still have 200+ steem funds on it before the hack, btw one of the managers of that account that also been hacked will not create dramas as you said.

Can you show me one account that has been 'hacked' and still believes in Steem? I say this, because it looks like all those accounts decided to leave Steem a while ago.

You yourself have a reputation of 67, but also you have nearly no SP in your account (1.20 SP). Why are you even here?

Hi the charity account is @creativestreet, we haven't cashed out the earnings because the amount in peso isn't substantial to help out with our charity works, and with the pandemic going on our country is in lockdown and we cannot do workshops. The head of the group @aalagenesis is trying to be active in Steemit but she's not getting much traction.

Thank you for considering our charity @deveerei !

I was invited by my old friend to be active and promote steem once again thinking to give it a go, don't worry, with the cancerous mindset and response i receive from witness itself i will leave steem for good. you can also tell @steemcurator01 to remove the vote i receive before this post.

  ·  4 years ago (edited)Reveal Comment

It's quite obvious that this case was created to shine a bad light on Steem.

my friend @deveerei is an active user for steemit and i don't think he will have time doing drama, but since the hacker never move any funds yet we can tell he has other things on his mind or want a smooth scape to this.

The same as I stated in my other comment goes for this account. He has a reputation of 68, but also he has nearly no SP in his account (186.15). For a developer who believes in Steem that amount is a joke.

You all decided to leave Steem prior to the 'hack'.

No, I did not leave Steem - we just lost community support that's why we're not that active. We also have jobs to focus on and other real life stuff. Us cashing out our earnings does not mean we're leaving Steem - it just means we need the money. We're from a 3rd world country some people here just earns 100usd for 2 weeks or less. For someone who lost his work due to the pandemic 186 Steem will actually pay my electricity bill for 3 to 4 months if I cash that out now. Check your privilege.

same man, I lost around 150$ during this hack and this is pretty big amount where I live. Guy with 100k in his wallet never gonna understand this. Only he can see that we are "suspicious " and making a drama. this is nonsense, only joke here is steemchiller. How we can defend ourselves then? This is how support working on steem?

Also selling steem/sbd is not a bad thing, it was rewarded to people for a purpose. It depends on that person how they will use it. If I was able to get those by giving my time and talent to produce good content then it's my right to do whatever I see fit with it. As far as I know, we're not abusing anything, and we got hacked. Since, I was responsible with the keys for the charity account I am intending to pay them back so we can have funds for our future workshop when this pandemic is over. Some of us are just doing our best to earn and we're thankful Steemit is here to help us out as long as we do our part, not everyone can be as rich as you so I'm sorry if we spend our hard-earned money.

  ·  4 years ago (edited)

keep doing those good arts dev, i will leave steem for good. I have 200+ people to recruit for hive and i will going to do the job there instead of here. witness dont care with small accounts losing their assets and even accusing those active who lose their funds to be part of the drama, that sounds ridiculous to me.

This happened before in utopian the accounts are exploited and uses to vote and flag. but in this scenario its different, if the dapp causes this, that dapp must have control over the wallet transaction and only few dapps can do that.

  ·  4 years ago (edited)

That account is one of the old accounts which was created in 2017 or before the last hard-fork so I think all of the accounts that are old and have the same password on both blockchains might be in danger. Unfortunately my account is also one of them but I don't have anything in my account.
Most of the keys are save in old Dapps and who knowa which one was not encrypted.

Better thing is to change the Master-Pass and other keys.

yes, I still waiting for the hacker to transfer it out so we may have a small chance to trace his main account.

Let's hope for good...!

Sorry we are not able to 'freeze' accounts.

The witnesses would need to implement a soft or hardfork for that.

@steemcurator01 he venido pensando en este tema de que personas que creamos cuentas en tiempo antiguo podemos estar en riesgo por la generación de nuestras mismas cuentas en la colmena con las mismas claves, Con respecto a este tema cree conveniente que haga un aviso a la comunidad pidiendo que renueve sus claves en el caso de ser cuentas creadas en el 2017, 2018 o creadas antes del hardfork con la colmena?

That could be useful.

In the meantime it would be useful to start telling those in your communities.

@steemcurator01 man this hack is going on out of control - all stolen funds are sent to @deepcrypto8 and I guess all money that he stole is outside the steemit already . can you see which exchange gonna receive that money?

nothing gonna changed after 10 days. hackers still stealing from users. nobody give a shit at all. I bet this is inside job. fuck this

  ·  4 years ago Reveal Comment

hopefully, @executive-boards can freeze that account and hold it to return the lost funds to its rightful owners. if you have hive account please do generate your new key asap the hacker may still find it ways to get those hives of yours. reblog this post so others may know whats happening

this hardly sucks. I really hope somebody gonna fix it asap. but nobody talk about this , only you and me. I will reblog.

some of the big guys didnt notice it yet, and no big holder posting this to remind others. the hacker stops 2 hours ago, hopefully, the account get freeze.

I bet all my coins are gone forever. I dont think so they gonna give them back....

if someone with good knowledge can freeze and recover that account then there still hope.

I sent a email to steemit support, will see then. I dont know what i need to contact to fix this.

just to make sure the case... did you login steemit using Master Password ? or you have posting key and active key ?

and maybe can remember , did have click suspicious link and log in your steemit from there ?