create account

Update on Recent Player Account Hacks by splinterlands

View this thread on: hive.blogpeakd.comecency.com
· @splinterlands ·
$11.79
Update on Recent Player Account Hacks
On Friday, April 16th, 2021, Splinterlands became aware that a number of player accounts were accessed by an unauthorized attacker who transferred the game cards and other assets out of the accounts without the account owners' permission.

It appears that the attacker was using a very large list of email addresses - possibly obtained from a hack of some other website or service - and was using a script to try to determine whether any of those email addresses were also linked to a Splinterlands account. The attacker was then able to access some of the accounts via the email and password login mechanism provided by Splinterlands. It is important to note that the email/password login only provides access to the private posting key for the player's Hive account and not any other keys, which is why players who had enabled the setting to require the active key for transactions of monetary value were not affected.

We are still looking into how the attacker was able to access the accounts, however **there is no indication at this time that any Splinterlands systems or services were breached or compromised in any way.**

## Updated Security Measures

As a result of this attack, Splinterlands has implemented an additional security measure of requiring the private active key for each account to be used for any transactions that would transfer any assets out of the account. Please note that this only applies to accounts that have purchased the Summoner's Spellbook and have created their own Hive blockchain account.

Players may still play the game, combine cards, open packs, make purchases, and anything else that does not send assets out of the account using the posting key or email/password login, but any transactions that send assets externally, such as transferring cards, tokens, packs, and listing cards for sale on the market, will require the private active key for the account. Please note that this setting can still be disabled by players so that cards and assets can be transferred using the posting key, however we strongly advise that players do not disable this setting or they risk losing their assets.

While this may present an inconvenience for a number of players, especially initially as they get used to the change, we felt that it is necessary to prevent additional players from losing their assets as a result of their email/password login being compromised.

We plan to keep this change in place going forward and will be working on updating the UI and instructions, especially for new accounts, to make sure players understand the different blockchain account keys and how they can be safely used and stored.

This change will especially affect mobile app users as it is much more difficult to use private keys on mobile devices and tools like Hive Keychain are not available. We will be working on improving the mobile app UI to handle this as much as possible, but in the meantime mobile app users can switch to the desktop website when/if they need to transfer cards or other assets out of their account.

We have also implemented a number of changes that will make it much more difficult for a similar attack to be performed in the future, and we are actively reaching out to some third-party security experts to perform a comprehensive review of the entire application.

## "Locking" Cards & Other Assets

One other feature which has been suggested even before this incident is to allow players to "lock" cards and other assets for a period of time. This is something we think would be good to add into the game and the recent events have made implementing this feature a top priority.

This feature would allow players to choose certain cards and other assets in the game and lock them for a period of time chosen by the player. Those assets can then still be used as normal - cards can be used in battles, or delegated - but they will not be able to be transferred or listed for sale on the market until they are unlocked, which will take the amount of time specified when the assets were locked.

This way players can be assured that their locked Splinterlands assets will not be able to be transferred even if their Hive blockchain account keys were to be compromised, and they will have time to recover their account before the cards become unlocked. We also plan to provide a system so that players can receive a notification when their assets become unlocked so that they can respond to any unauthorized access to their account and respond accordingly.

## Affected Accounts

For any accounts that were affected by this attack, we recommend the following action items:

1. Contact [support@splinterlands.com](mailto:support@splinterlands.com) via email to report that your account was compromised. Please include your account name and what, if any, assets were stolen in the email.

2. Use the "Forgot Password" option on the login screen on the Splinterlands website or mobile app to change the password on your account to a strong password that you have not used on other websites or services.

3. Go to https://wallet.hive.blog, log in with your Hive account name and master password/key, and choose the "Change Password" option to change the master password and keys for your Hive blockchain account. Please understand that **once you change your Hive master password and keys WE CANNOT RECOVER THEM FOR YOU SO IF YOU LOSE THEM YOU WILL LOSE ACCESS TO YOUR ACCOUNT AND ALL OF THE ASSETS WITHIN IT**.

## Asset Recovery & Reimbursement

The Splinterlands team has been able to successfully recover a portion of the stolen cards and other assets and we will return those to the rightful owners' accounts as soon as they contact us and we can ensure that their accounts have been adequately secured.

We are still working with various third parties to see if there is a way to recover the remaining assets, however we are committed to reimbursing the players who had assets stolen as part of this attack from our own funds if we are unable to recover them.
 
We do not currently know the timing or additional details of the reimbursement and we ask that players affected by the incident be patient as it will take some time to get everything sorted out and resolved.
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 313 others
👎  
properties (23)
authorsplinterlands
permlinkupdate-on-recent-player-account-hacks
categorysplinterlands
json_metadata{"app":"peakd/2021.04.2","format":"markdown","tags":["splinterlands","steemmonsters","spt"],"users":["splinterlands.co"],"links":["https://mailto:support@splinterlands.com","https://wallet.hive.blog"]}
created2021-04-18 22:39:06
last_update2021-04-18 22:39:06
depth0
children18
last_payout2021-04-25 22:39:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value11.787 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length6,223
author_reputation1,502,753,868,681,844
root_title"Update on Recent Player Account Hacks"
beneficiaries
0.
accountnull
weight10,000
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,130,949
net_rshares47,785,338,644,807
author_curate_reward""
vote details (378)
@almightymelon ·
$0.12
Wow, "from our own funds".

You guys are seriously awesome and committed to maintaining good PR and a high reputation for the game. Well played.
👍  , , , , , ,
properties (23)
authoralmightymelon
permlinkre-splinterlands-qrso0j
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 04:48:21
last_update2021-04-19 04:48:21
depth1
children1
last_payout2021-04-26 04:48:21
cashout_time1969-12-31 23:59:59
total_payout_value0.058 HBD
curator_payout_value0.057 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length144
author_reputation7,905,136,847,802
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,135,558
net_rshares272,037,216,631
author_curate_reward""
vote details (7)
@anjanida ·
properties (23)
authoranjanida
permlinkre-almightymelon-qrtvau
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 20:23:21
last_update2021-04-19 20:23:21
depth2
children0
last_payout2021-04-26 20:23:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length6
author_reputation69,557,450,330,265
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,150,473
net_rshares3,346,261,855
author_curate_reward""
vote details (2)
@ash-petrol ·
This post can also help people who lost their keys and plans to change it. thanks for this information. got informed!
👍  
properties (23)
authorash-petrol
permlinkqyhr84
categorysplinterlands
json_metadata{"app":"hiveblog/0.1"}
created2021-08-27 09:19:24
last_update2021-08-27 09:19:24
depth1
children0
last_payout2021-09-03 09:19:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length117
author_reputation0
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id105,825,671
net_rshares0
author_curate_reward""
vote details (1)
@branders0n ·
I just started playing the other day but this is great to see from a community! 
Thank you for being so transparent 😅
👍  
properties (23)
authorbranders0n
permlinkre-splinterlands-qru5yd
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-20 00:13:24
last_update2021-04-20 00:13:24
depth1
children0
last_payout2021-04-27 00:13:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length117
author_reputation8,068,217,924,742
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,153,933
net_rshares0
author_curate_reward""
vote details (1)
@crystalpacheco30 ·
Best customer service there is! Also, love the new security feature!
properties (22)
authorcrystalpacheco30
permlinkqrsmu8
categorysplinterlands
json_metadata{"app":"hiveblog/0.1"}
created2021-04-19 04:22:57
last_update2021-04-19 04:22:57
depth1
children0
last_payout2021-04-26 04:22:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length68
author_reputation31,549,460,289,159
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,135,220
net_rshares0
@fighter4-freedom ·
$0.08
As always, #1 customer service in the Blockchain industry!!!
👍  , , , ,
properties (23)
authorfighter4-freedom
permlinkre-splinterlands-qrs7gi
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-18 22:50:45
last_update2021-04-18 22:50:45
depth1
children0
last_payout2021-04-25 22:50:45
cashout_time1969-12-31 23:59:59
total_payout_value0.040 HBD
curator_payout_value0.039 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length60
author_reputation4,993,464,972,746
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,131,084
net_rshares189,797,636,804
author_curate_reward""
vote details (5)
@gadrian ·
You're doing all that can be done and beyond under the circumstances. 

Asset locking will be a very powerful security feature.
👍  
properties (23)
authorgadrian
permlinkre-splinterlands-qrsz82
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 08:50:27
last_update2021-04-19 08:50:27
depth1
children0
last_payout2021-04-26 08:50:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length127
author_reputation379,304,988,115,453
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,138,886
net_rshares5,877,023
author_curate_reward""
vote details (1)
@maori4life ·
That is great customer service, trust the process and you even go above and beyond by personally reimbursing players - I am with a great organisation. I know breaches happen but very few times have I seen an organisation actually compensate people for their loss, thank you splinterlands for doing the right thing, thats why I love this game.
properties (22)
authormaori4life
permlinkre-splinterlands-qrsj0h
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 03:00:30
last_update2021-04-19 03:00:30
depth1
children0
last_payout2021-04-26 03:00:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length342
author_reputation1,929,406,673,085
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,134,264
net_rshares0
@marki99 ·
$0.04
Why not just hardfork and reverse all the transfers to the hacker's account? This is similar to the DAO hack on eth
👍  ,
properties (23)
authormarki99
permlinkre-splinterlands-qrtb7m
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 13:09:24
last_update2021-04-19 13:09:24
depth1
children0
last_payout2021-04-26 13:09:24
cashout_time1969-12-31 23:59:59
total_payout_value0.022 HBD
curator_payout_value0.022 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length115
author_reputation11,400,723,818,181
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,142,011
net_rshares108,774,144,515
author_curate_reward""
vote details (2)
@mattclarke ·
$0.11
Champion effort. Time-locking will make a huge difference. I know I'll have a lot more peace of mind. 
👍  ,
properties (23)
authormattclarke
permlinkre-splinterlands-qrsb41
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 00:09:39
last_update2021-04-19 00:09:39
depth1
children0
last_payout2021-04-26 00:09:39
cashout_time1969-12-31 23:59:59
total_payout_value0.055 HBD
curator_payout_value0.055 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length102
author_reputation114,607,271,004,073
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,132,013
net_rshares260,008,899,155
author_curate_reward""
vote details (2)
@mawit07 ·
Thanks for the efforts. I trust in Splinterlands.
properties (22)
authormawit07
permlinkre-splinterlands-qrsjc4
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 03:07:21
last_update2021-04-19 03:07:21
depth1
children0
last_payout2021-04-26 03:07:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length49
author_reputation695,797,972,791,408
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,134,346
net_rshares0
@maxim4444 ·
you guys are amazing 
properties (22)
authormaxim4444
permlinkre-splinterlands-qs2uf8
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-24 16:42:54
last_update2021-04-24 16:42:54
depth1
children0
last_payout2021-05-01 16:42:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length21
author_reputation572,787,270
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,261,757
net_rshares0
@michealb ·
$0.08
i like the card lock and  notification when unlocked idea
👍  ,
properties (23)
authormichealb
permlinkqrsqkp
categorysplinterlands
json_metadata{"app":"hiveblog/0.1"}
created2021-04-19 05:43:42
last_update2021-04-19 05:43:42
depth1
children0
last_payout2021-04-26 05:43:42
cashout_time1969-12-31 23:59:59
total_payout_value0.039 HBD
curator_payout_value0.039 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length57
author_reputation48,968,836,711,621
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,136,464
net_rshares188,141,632,232
author_curate_reward""
vote details (2)
@nullfame ·
$0.05
I also applaud the effort and dedication to the players!  Like the locking feature idea.  

As a new player I was surprised there is no 2FA.  Is that worth considering or does the "require active authority" setting effectively serve this purpose?
👍  ,
properties (23)
authornullfame
permlinkre-splinterlands-qrteut
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 14:28:12
last_update2021-04-19 14:28:12
depth1
children0
last_payout2021-04-26 14:28:12
cashout_time1969-12-31 23:59:59
total_payout_value0.023 HBD
curator_payout_value0.023 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length246
author_reputation72,380,048,745
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,143,497
net_rshares112,674,551,667
author_curate_reward""
vote details (2)
@transcript-junky ·
$0.05
Sorry to hear about this, and for anyone who lost assets. Kudos to admin for taking quick action, and going as far as offering to reimburse assets, and implement sensible changes to the system to prevent future issues - even if it will require some extra clicking on the player end. Safety first...
👍  
properties (23)
authortranscript-junky
permlinkqrvgwz
categorysplinterlands
json_metadata{"app":"hiveblog/0.1"}
created2021-04-20 17:07:48
last_update2021-04-20 17:07:48
depth1
children0
last_payout2021-04-27 17:07:48
cashout_time1969-12-31 23:59:59
total_payout_value0.023 HBD
curator_payout_value0.023 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length298
author_reputation35,468,732,167,881
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,168,396
net_rshares106,597,306,051
author_curate_reward""
vote details (1)
@unclebounce ·
$0.08
Seems like a good response and well resolved.  Good job!

Wouldn't it be safer/better, though, to implement a universal delay in trading ay assets out of the SLs/admin control and to somewhere unrecoverable?  sort of like a 48 hour delay on transferring out cards but not transferring in.  It don't think that would be terribly burdensome on players to wait 2 days to xfer assets to a another dex or something, and if something happened in the future and it was reported in time, devs should be able to track the card within their domain of control and recover it.  
👍  ,
properties (23)
authorunclebounce
permlinkre-splinterlands-qrts0k
categorysplinterlands
json_metadata{"tags":["splinterlands"],"app":"peakd/2021.04.2"}
created2021-04-19 19:12:21
last_update2021-04-19 19:12:21
depth1
children0
last_payout2021-04-26 19:12:21
cashout_time1969-12-31 23:59:59
total_payout_value0.043 HBD
curator_payout_value0.038 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length566
author_reputation677,877,583,652
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,149,034
net_rshares202,367,949,070
author_curate_reward""
vote details (2)
@vimukthi ·
I would love to see the locking feature. It will come in handy to a many of the users. 
properties (22)
authorvimukthi
permlinkre-splinterlands-2021421t161233189z
categorysplinterlands
json_metadata{"tags":["splinterlands","steemmonsters","spt"],"app":"ecency/3.0.16-vision","format":"markdown+html"}
created2021-04-21 10:42:33
last_update2021-04-21 10:42:33
depth1
children0
last_payout2021-04-28 10:42:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length87
author_reputation401,885,943,381,206
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id103,184,303
net_rshares0
@xykorlz ·
this articles should be shared to everyone specially newbies like me in the game.
👍  
properties (23)
authorxykorlz
permlinkqxs5oh
categorysplinterlands
json_metadata{"app":"hiveblog/0.1"}
created2021-08-13 13:43:12
last_update2021-08-13 13:43:12
depth1
children0
last_payout2021-08-20 13:43:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length81
author_reputation167,827,179,847,478
root_title"Update on Recent Player Account Hacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id105,508,328
net_rshares350,000,000
author_curate_reward""
vote details (1)