Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All the hacked accounts seem to have had the associated email changed. I think the attack goes admin panel -> change email -> reset PW -> tweet bitcoin scams.

https://twitter.com/sniko_/status/1283485972286656517



if this were true, youd think itd be trivial to review changelog for two affected users and deactivate the in-common admin account. not sure why this would take hours to solve.


You're assuming this internal tool was built securely and was feature complete.

My experience with internal tooling in general suggests otherwise.


changing emails is a common way to keep account owners out of their accounts. might not have anything to do with the mode of entry.


Given the number of accounts that were taken over, there must have been many people conducting the hack. Also considering that tweets were being deleted then re-tweeted, others must have been monitoring the tweets. Seems somewhat well coordinated.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: