HomeinetThe social network Steemit was hacked | DDoS attack followed

The social network Steemit was hacked | Followed by a DDoS attack

Steemit, a relatively small social network, announced last Thursday, July 14, that an unknown intruder had managed to hack its network and steal some of its users' funds.

Steem is a new type of technology that powers the Steemit social network and works by rewarding users who publish popular content with Steem Power and Steem Dollars—a custom crypto‑currency with a one‑to‑one ratio to the US dollar.

The network works just like Reddit or Hacker News, except there is also the possibility of earning money from curating and creating new content.

The social network Steemit was hacked | Followed by a DDoS attack

Steemit user, dragonslayer109, was the first to notice the attack, after reporting mysterious transactions that transferred funds from his account to another Bittrex account, a Bitcoin exchange that Steemit partners with to allow users to “withdraw” Steem dollars as Bitcoin.

Other users also noticed the same thing and the company became aware of the incident and started an investigation after it closed the ability to transfer funds on Bittrex and later notified the FBI and other authorities.

The investigation revealed that the attack affected fewer than 260 users, but managed to steal $85,000 worth of Steem Dollars and Steem Power.

CEO Ned Scott said that all affected users created their Steemit accounts through Facebook or Reddit. In a later update published over the weekend, Scott maintained that “the Steem blockchain was never hacked. Likewise, our servers were never hacked. Instead, the hacker exploited vulnerabilities on the browser side.”

Furthermore, Scott said that they were able to contain the attack on the same day and that Steem Dollars and Steem Power will be refunded to all users, courtesy of Steemit itself.

After fixing the issues in the Steemit website code, the network now asks all users to change their passwords. The Steemit social network is different from other online services because users have three passwords, an owner key, an active key, and a posting key, each used for different activities.

Coincidentally or not, immediately after this announcement by the company, a DDoS attack hit its servers.

Steemit used this attack to shut down its servers for maintenance and upgrading its services, adding something called "blockchain-based multi-factor authentication" to strengthen account security even further.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS