Daily Archives: January 5, 2018
Get Trading Recommendations and Read Analysis on Hacked.com for just $39 per month.A Friday Reddit post by u/gooeyblob confirmed the vector of attack used to rob users of Bitcoin Cash funds tied to their accounts. Just days ago, posts complaining of missing Bitcoin Cash funds began surfacing in the r/btc subreddit, as victims noticed that their Tippr balances were emptied following emails of account password changes. Tippr, a popular bot used in Reddit’s cryptocommunities, allows users to tip other users in Bitcoin Cash for posts, comments, and content they appreciate, a practice similar to gifting Reddit Gold.
Hacker Goes Through Mailgun to Nab Funds
In the post on r/bugs, moderator gooeyblob indicated that the attack was carried out through Mailgun, a third party software provider. Reddit uses Mailgun to process platform-wide email services like password resets.
As such, the “malicious actor targeted Mailgun and gained access to Reddit’s password reset emails,” the post explains. “The nature of the exploit meant that an unauthorized person was able to access the contents of the reset email,” thus allowing the individual to breach user accounts to withdraw their Bitcoin Cash balances. The admin continues to reassure …
View Full Article