create account

Bitcoin Cash Reddit Tip App Users Hacked for Thousands by zahidhshabrani

View this thread on: hive.blogpeakd.comecency.com
· @zahidhshabrani · (edited)
$0.14
Bitcoin Cash Reddit Tip App Users Hacked for Thousands
![](https://steemitimages.com/DQmVpA45ABmyUokRwafsYYHsN8vkMx7J4uAhJVK5FXoNz5v/image.png)
An ongoing investigation has revealed multiple allegations that hot wallets from users of popular subreddit r/btc were hacked through Tippr, resulting in thousands of dollars worth of bitcoin cash (BCH) stolen. Early theories assumed this to be a new low in the so-called Civil War between supporters of bitcoin core and BCH. 

Bitcoin Civil War Might’ve Gotten Uglier
Using a previously unknown third-party vulnerability, users of Reddit’s increasingly popular subreddit forum, /r/btc, a discussion board which often features positive comments by bitcoin cash supporters, were hacked for thousands of BCH.

Reddit is a news aggregator fueled by subreddit discussion boards which fill every kind of topic niche. It is owned by media conglomerate Advance Publications, and is routinely in the top ten most visited websites.

Bitcoin Cash Reddit Tip App Users Users Hacked for Thousands

The attacks were seemingly so base, early thinking went toward an inside job. Perhaps a rogue Reddit admin had snatched bitcoin cash, came an initial theory. In the final month of last year, /r/btc’s moderator and a user who happened to work in the malware field were made vulnerable and hacked. For about half an hour, the subreddit itself was redirected to r/bitcoin. And then a half dozen other bitcoin cash-favoring forum users were compromised, especially those tipped through Tippr.

The conspiracies began. Obviously, bitcoin core supporters had taken to ire, doing so as a new low. They might hate bitcoin cash, but no one turns down free money.

50,000 USD of BCH Flowed Through Tippr in December
Tippr is a bot used on Reddit for the purposes of tipping users in BCH. Tippers send the bot a deposit, and then comment, noting they’re using u/tippr. An example might be: “Great point u/tippr $3.” The bot will chime in, confirming the tip. The recipient must have a BCH wallet, and then message the bot in return, listing the BCH wallet address and include the amount. The bot dutifully answers in confirmation, and so the recipient can now access funds. Estimates in the upwards of 50,000 USD worth of BCH has flowed through the bot in December of last year. The culprit evidently was tracking such public posts, causing Tippr to go dark, pending results, as the developer learned of the investigation.

The attack came as a reset from Reddit in email form. Immediately another email confirmed the password change…even if the email hadn’t opened for whatever reason. “My email provider is a very large provider with a name we all know,” a hacked user explained. “Logging is provided and there was no suspicious activity on my email account. My email account also has 2FA. The emails sent by reddit (first one ‘click here to change your password’ second one ‘your password has been changed) were unopened in my inbox.’”

Whatever the case, this does appear to be something of a new kind of attack allowing access to Reddit accounts, a vulnerability hitherto unknown. It now could at least be plausible NEITHER a Reddit employee was on the make or a dastardly bitcoin core jihadist was involved. 

It turns out one or the other might’ve been sufficient but not a fully necessary condition to launch the attacks. Tippr is the common denominator, and where there is money to be taken no other motive need be ascribed. Tippr is used not only on Reddit forums but also on Twitter.

Conspiracy Sufficient But Not Necessary
The bot’s creator, Rob Danielson, mused it was probably “someone [who] realized they had an opportunity to make a quick buck.” Through private messaging via Reddit, accounts gave up as much as $4,000 total worth of bitcoin cash. Once the incidents were discovered, Mr. Danielson disabled the bot for Reddit.

For its part, Reddit is pointing fingers at its automated email subcontractor Mailgun. Though the number of users impacted was roughly a dozen, someone could gain access to resetting emails through Mailgun, a potentially huge problem for Reddit going forward. The hacker could not access Reddit proper nor a user’s email account, they claim. Reddit has since dropped Mailgun in favor of its own server. Mailgun believes “less than 1% of our customer base was potentially affected.” Tippr is now available again on Reddit.

Bitcoin Cash Reddit Tip App Users Hacked for Thousands
A Reddit engineer did finally respond to multiple requests by users for public comment. “Thanks for reporting – we’re not ignoring. This was reported privately via security at [Reddit] and we’ve been investigating.”

Moderator of /r/btc, Bitcoinxio, noted Reddit maybe “needed a kick in the butt after all this publicity about the hacks in the past couple days, but we’ve been telling them about the hacks now for some time,” he wrote. “I wouldn’t be surprised if the other hacks are related in some way or there are other exploits which they haven’t even investigated because they are ignoring our concerns and just shrugging them off.”

@cyberblock
@ufxpression
@reidlist
@vogeltron1
@niem84
@anforo
@michiel
@temponaut
@tuvokhl
@morgandollar
@cryptosharon
@bigcripin144
@sirstacksalot
@sadamsasa
What are your thoughts on the bitcoin cash hacks? Let us know in the comments section below.

Source:
https://bitcoin-notes.com/2018/01/07/bitcoin-cash-reddit-tip-app-users-hacked-for-thousands/
[Image Source](https://www.shutterstock.com/image-photo/bitcoin-hacked-threescreen-computer-dark-background-742564786?src=HIeD29gjSzmqInJFBBu7zA-1-18)
👍  , , , , , ,
properties (23)
authorzahidhshabrani
permlinkbitcoin-cash-reddit-tip-app-users-hacked-for-thousands
categorycrypto-news
json_metadata{"tags":["crypto-news","bitcoin","blockchain","bitcoincash","hacked"],"image":["https://steemitimages.com/DQmVpA45ABmyUokRwafsYYHsN8vkMx7J4uAhJVK5FXoNz5v/image.png"],"links":["https://bitcoin-notes.com/2018/01/07/bitcoin-cash-reddit-tip-app-users-hacked-for-thousands/","https://www.shutterstock.com/image-photo/bitcoin-hacked-threescreen-computer-dark-background-742564786?src=HIeD29gjSzmqInJFBBu7zA-1-18"],"app":"steemit/0.1","format":"markdown","users":["cyberblock","ufxpression","reidlist","vogeltron1","niem84","anforo","michiel","temponaut","tuvokhl","morgandollar","cryptosharon","bigcripin144","sirstacksalot","sadamsasa"]}
created2018-01-07 09:36:54
last_update2018-01-07 09:42:27
depth0
children8
last_payout2018-01-14 09:36:54
cashout_time1969-12-31 23:59:59
total_payout_value0.133 HBD
curator_payout_value0.005 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length5,531
author_reputation153,551,475,832
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,722,241
net_rshares14,017,131,124
author_curate_reward""
vote details (7)
@cheetah ·
Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
https://bitcoin-notes.com/2018/01/07/bitcoin-cash-reddit-tip-app-users-hacked-for-thousands/
👍  
properties (23)
authorcheetah
permlinkcheetah-re-zahidhshabranibitcoin-cash-reddit-tip-app-users-hacked-for-thousands
categorycrypto-news
json_metadata""
created2018-01-07 09:48:42
last_update2018-01-07 09:48:42
depth1
children0
last_payout2018-01-14 09:48:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length191
author_reputation942,693,160,055,713
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,724,027
net_rshares571,250,771
author_curate_reward""
vote details (1)
@emonda ·
Am I missing something? How was the BCH stolen? Were people's private keys leaked? Were they tricked into sending BCH to the wrong address?
👍  ,
properties (23)
authoremonda
permlinkre-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t095226307z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"app":"steemit/0.1"}
created2018-01-07 09:52:27
last_update2018-01-07 09:52:27
depth1
children5
last_payout2018-01-14 09:52:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length139
author_reputation1,042,660,178
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,724,576
net_rshares1,116,218,386
author_curate_reward""
vote details (2)
@bithereum ·
I was under the impression that there was a security hole in the password-reset functionality on Reddit, which allowed hackers to reset passwords of accounts without access to the email address. 

The thing I can tell you is that the BCH wasn't stolen, the funds inside the tippr account was hacked (and not the central wallet), a bot was written to scan posts containing information about who got tipped - the users picked up by the bot had their funds stolen.
👍  
properties (23)
authorbithereum
permlinkre-emonda-re-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t131205238z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"app":"steemit/0.1"}
created2018-01-07 13:11:12
last_update2018-01-07 13:11:12
depth2
children1
last_payout2018-01-14 13:11:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length461
author_reputation72,316,962,103
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,757,791
net_rshares588,984,599
author_curate_reward""
vote details (1)
@zahidhshabrani ·
I think you are right @bithereum
👍  
properties (23)
authorzahidhshabrani
permlinkre-bithereum-re-emonda-re-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t151418367z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"users":["bithereum"],"app":"steemit/0.1"}
created2018-01-07 15:13:18
last_update2018-01-07 15:13:18
depth3
children0
last_payout2018-01-14 15:13:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length32
author_reputation153,551,475,832
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,781,674
net_rshares525,653,843
author_curate_reward""
vote details (1)
@raj2017 ·
No Idea @emonda
👍  
properties (23)
authorraj2017
permlinkre-emonda-re-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t100203392z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"users":["emonda"],"app":"steemit/0.1"}
created2018-01-07 10:01:54
last_update2018-01-07 10:01:54
depth2
children1
last_payout2018-01-14 10:01:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length15
author_reputation5,440,912,609
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,726,019
net_rshares581,829,489
author_curate_reward""
vote details (1)
@zahidhshabrani ·
@raj2017 be careful
👍  
properties (23)
authorzahidhshabrani
permlinkre-raj2017-re-emonda-re-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t100401010z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"users":["raj2017"],"app":"steemit/0.1"}
created2018-01-07 10:03:51
last_update2018-01-07 10:03:51
depth3
children0
last_payout2018-01-14 10:03:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length19
author_reputation153,551,475,832
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,726,335
net_rshares536,237,477
author_curate_reward""
vote details (1)
@zahidhshabrani ·
Also how the Hackers do kind of hacking, This news is disturbing
properties (22)
authorzahidhshabrani
permlinkre-emonda-re-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180107t100328906z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"app":"steemit/0.1"}
created2018-01-07 10:03:18
last_update2018-01-07 10:03:18
depth2
children0
last_payout2018-01-14 10:03:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length64
author_reputation153,551,475,832
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,726,245
net_rshares0
@sadamsasa ·
ooo my goodness
👍  
properties (23)
authorsadamsasa
permlinkre-zahidhshabrani-bitcoin-cash-reddit-tip-app-users-hacked-for-thousands-20180108t091137767z
categorycrypto-news
json_metadata{"tags":["crypto-news"],"app":"steemit/0.1"}
created2018-01-08 09:11:39
last_update2018-01-08 09:11:39
depth1
children0
last_payout2018-01-15 09:11:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length15
author_reputation4,806,353,138
root_title"Bitcoin Cash Reddit Tip App Users Hacked for Thousands"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id27,956,369
net_rshares564,460,502
author_curate_reward""
vote details (1)