Post
Topic
Board Service Announcements (Altcoins)
Re: [ANN] OnionWallet - DeepOnion Web Wallet with 2-FA & Auto-Staking! Earn ONION
by
fitbobcat
on 14/08/2017, 16:49:49 UTC
DeepOnion comrades, we are devastated to announce that OnionWallet has been tampered with / hacked this morning [we are in GMT+3 timezone]. As far as we can see now approximately 5000 Onion have been sent to unknown addresses. All funds have been drained...

If you had a balance please PM us your info and-or post it here - we have to track who lost what.

We will update you as soon as we have more information to share.

We are deeply sorry.

Onionminer.club

WARNING: piWallet is not secure software apparently!

piWallet is a very secure software, what happened is an administrator had a very weak password and did not have 2Factor Authentication enabled which led to someone logging in to an admin account and spending all the coins. Thank you for your concern, and please secure piWallet properly next time.
Alright, yet how can you know, sir? Of course our Admin account's password had 32+ chars, very complex, and it had 2-FA enabled. Someone gained root access... This could mean that it may be unrelated to piWallet itself - but the server was secured with extremely complex passphrase and only allowed root ssh connections temporarily.
We have lost some of our own ONION funds as well. Either way: we are to blame and we are deeply sorry for this loss.

Why wasn't 2Factor enabled on the server?