No, they really did get hacked- or at least someone leaked their accounts. Find yourself here:
redacted
Then, someone started cracking the MD5 password hashes and then, with passwords in hand, trying various accounts until they found one with lots of money. There is a $1000 per day withdrawl limit, so in order to get more bitcoins out, they had to crash the market close to 0 first. And that is what happened today.
The End.
I wish people would stop linking that file. Mods are removing posts relating to it, just not fast enough.
But yes this is what happened.
Once it's on the internet it can't be taken off. The only thing unlinking it from here will do is keep legit users from knowing about it quickly and changing their info on related sites (if it's reused). This is especially bad since the Mt.Gox hacked/CSRF threads tell which/where pw's might be reused. Time to get as much info as possible and mitigate the risk as much as possible. I'd assume it's torrented by now and being downloaded by all sorts of malicious people NOT affliliated with this site.
Also: just when finishing this post up I got this email:
Dear Mt.Gox user,
Our database has been compromised, including your email. We are working on a
quick resolution and to begin with, your password has been disabled as a
security measure (and you will need to reset it to login again on Mt.Gox).
If you were using the same password on Mt.Gox and other places (email, etc),
you should change this password as soon as possible.
For more details, please see this:
https://support.mtgox.com/entries/20208066-huge-bitcoin-sell-off-due-to-a-compromised-account-rollbackThe informations there will be updated as our investigation progresses.
Please accept our apologies for the troubles caused, and be certain we will do
everything we can to keep the funds entrusted with us as secure as possible.
The leaked data includes the following:
- Account number
- Account login
- Email address
- Encrypted password
While the password is encrypted, it is possible to bruteforce most passwords
with time, and it is likely bad people are working on this right now.
Any unauthorized access done to any account you own (email, mtgox, etc) should
be reported to the appropriate authorities in your country.
Thanks,
The Mt.Gox team