create account

[Action required] Security attack on Reviewhunt.com by steemhunt

View this thread on: hive.blogpeakd.comecency.com
· @steemhunt ·
$2.59
[Action required] Security attack on Reviewhunt.com
Today, we noticed that there were security attacks on Reviewhunt website. We received a report at 12:49 am (KST) when a user discovered that his/her HUNT tokens were transferred without their knowledge. After receiving this message, we ran an investigation and found a server log that shows login attempts by an automated script using login pairs leaked from another website.

Based on our investigation, it appears that this security attack was carried out in the following ways:

1. The hacker may have attained thousands of email addresses and passwords from other websites.
2. The hacker ran an automated script that attempts to login to Reviewhunt by using the email-password pairs from the hacked websites.
3. Most of the email addresses that they attempted were not Reviewhunt accounts, but a few of the users’ account information matched. So far, we have received 4 reports from our Reviewhunt users that said their account has been accessed by the hacker and a total of 51,125 HUNT tokens were transferred (we presume that their login information was the same as the leaked information from the hacked websites).

As soon as we found out about the security attack, we halted all the withdrawal requests in order to prevent the hacker attempting more log-ins to our website with the email-password pairs leaked from outside sources. If the hacker tries after we have halted the transfer system, the withdrawal transaction becomes a β€œpending” status.

If you find any pending withdrawal transaction that is not attempted by you, please contact us via the #hunt-token channel on our [Discord group](https://discord.gg/mWXpgks). We will stop (rollback) the transaction. Unfortunately, we have no way to help you if the transaction has already been processed (it means that the hacker had already transferred tokens by using the login information leaked from an outside source before we halted the transfer system).

**We will keep maintaining this withdrawal suspension for all Reviewhunt users until January 28th (Tue), 2020, 6 pm KST just in case of rollback requests from pending transactions.** We will approve the transfer requests altogether after the time. 

As we [informed earlier](https://steemit.com/steemhunt/@steemhunt/all-new-reviewhunt-set-to-launch-simpler-but-greater), Reviewhunt will be relaunched on January 29th, 2020 with the new Blockstack authentication. All the user records will be reset and you need to join Reviewhunt again via the Blockstack system. Also, we strongly recommend that you use different password information on each website to prevent security breaches from other websites.
πŸ‘  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 87 others
πŸ‘Ž  
properties (23)
authorsteemhunt
permlinkaction-required-security-attack-on-reviewhunt-com
categoryreviewhunt
json_metadata{"tags":["reviewhunt","update","hunt-token"],"links":["https://discord.gg/mWXpgks","https://steemit.com/steemhunt/@steemhunt/all-new-reviewhunt-set-to-launch-simpler-but-greater"],"app":"steemit/0.1","format":"markdown"}
created2020-01-25 21:46:03
last_update2020-01-25 21:46:03
depth0
children7
last_payout2020-02-01 21:46:03
cashout_time1969-12-31 23:59:59
total_payout_value1.548 HBD
curator_payout_value1.045 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,621
author_reputation328,252,698,785,439
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,765,934
net_rshares12,307,461,657,297
author_curate_reward""
vote details (152)
@aamirijaz ·
There must be an extra security layer implemented which asks for a verification email  or a Google authentication code upon withdrawal.
properties (22)
authoraamirijaz
permlinkq4p3k0
categoryreviewhunt
json_metadata{"app":"steemit/0.1"}
created2020-01-26 03:40:48
last_update2020-01-26 03:40:48
depth1
children3
last_payout2020-02-02 03:40:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length135
author_reputation112,726,048,778,758
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,771,716
net_rshares0
@gentleshaid ·
I was going to say this

Posted using [Partiko Android](https://partiko.app/referral/gentleshaid)
πŸ‘  
properties (23)
authorgentleshaid
permlinkgentleshaid-re-aamirijaz-q4p3k0-20200126t065845261z
categoryreviewhunt
json_metadata{"app":"partiko","client":"android"}
created2020-01-26 06:58:45
last_update2020-01-26 06:58:45
depth2
children0
last_payout2020-02-02 06:58:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length97
author_reputation399,453,372,708,549
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,774,957
net_rshares7,434,377,984
author_curate_reward""
vote details (1)
@tabris ·
$0.02
We're going to use Blockstack authentication on the new version of Reviewhunt, which requires full seed phrase to login and I guess this can be much safer than Email/Password authentication.

We'll definitely do 2-factor auth too on our wallet in the future.
πŸ‘  
properties (23)
authortabris
permlinkq4s0ke
categoryreviewhunt
json_metadata{"app":"steemit/0.1"}
created2020-01-27 17:29:03
last_update2020-01-27 17:29:03
depth2
children1
last_payout2020-02-03 17:29:03
cashout_time1969-12-31 23:59:59
total_payout_value0.011 HBD
curator_payout_value0.011 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length258
author_reputation13,487,538,505,917
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,825,273
net_rshares141,019,990,784
author_curate_reward""
vote details (1)
@aamirijaz ·
That souds cool. Thanks for the reply.
properties (22)
authoraamirijaz
permlinkq4s38v
categoryreviewhunt
json_metadata{"app":"steemit/0.1"}
created2020-01-27 18:26:57
last_update2020-01-27 18:26:57
depth3
children0
last_payout2020-02-03 18:26:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length38
author_reputation112,726,048,778,758
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,826,532
net_rshares0
@gentleshaid ·
Kudos for swiftly responding before things got worse. I just checked my wallet and everything seems fine.

Posted using [Partiko Android](https://partiko.app/referral/gentleshaid)
πŸ‘  
properties (23)
authorgentleshaid
permlinkgentleshaid-re-steemhunt-action-required-security-attack-on-reviewhunt-com-20200126t065952121z
categoryreviewhunt
json_metadata{"app":"partiko","client":"android"}
created2020-01-26 06:59:51
last_update2020-01-26 06:59:51
depth1
children0
last_payout2020-02-02 06:59:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length179
author_reputation399,453,372,708,549
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,774,986
net_rshares7,287,408,259
author_curate_reward""
vote details (1)
@starworld ·
"The hacker ran an automated script that attempts to login to Reviewhunt by using the email-password pairs from the hacked websites."

This is a good reason for websites to use  two-factor authentication (2FA).
πŸ‘Ž  
properties (23)
authorstarworld
permlinkq4onfo
categoryreviewhunt
json_metadata{"app":"steemit/0.1"}
created2020-01-25 21:52:39
last_update2020-01-25 21:52:39
depth1
children0
last_payout2020-02-01 21:52:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length210
author_reputation-1,006,677,432,864
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,766,093
net_rshares-162,802,663,323
author_curate_reward""
vote details (1)
@tts ·
To listen to the audio version of this article click on the play image.
[![](https://s18.postimg.org/51o0kpijd/play200x46.png)](http://ec2-52-72-169-104.compute-1.amazonaws.com/steemhunt__action-required-security-attack-on-reviewhunt-com.mp3)
Brought to you by [@tts](https://steemit.com/tts/@tts/introduction). If you find it useful please consider upvoting this reply.
πŸ‘Ž  , ,
properties (23)
authortts
permlinkre-action-required-security-attack-on-reviewhunt-com-20200125t220114
categoryreviewhunt
json_metadata""
created2020-01-25 22:01:15
last_update2020-01-25 22:01:15
depth1
children0
last_payout2020-02-01 22:01:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length370
author_reputation-4,535,154,553,995
root_title"[Action required] Security attack on Reviewhunt.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id94,766,299
net_rshares-106,268,236,782
author_curate_reward""
vote details (3)