Hi, my dear virtual friends of the hive. I am pleased to be with you again after the events of the last few days. The house loses and laughs, is a saying we apply to cope with adverse situations where we have lost, for example, some money. I thought it wouldn't happen to me -who thinks so?- And it happened to me, I tell you. In advance I thank @tarazkp for allowing me to leave this post in this growing community.
Last Monday, when I was making my usual publication, I noticed a strange behaviour in Ecency.com as well as in Pead.com, everything was slow, if I made a vote, the marked publication did not appear, if I made a comment it did not appear, I refreshed the page several times… Worse was on Tuesday, I could no longer enter through Pead.com or hive.blog, I have entered through Ecency.com, and I noticed the following details:
My Hive account had been hacked. It started a week of failed recovery attempts, of setting up a technical team, in order to investigate what happened and find the person or persons responsible. And a week later, with the account recovered, I would like to report this incident so that you can take the necessary measures to protect other users.
My user dates back to 15 January 2018, it was created on the old network. Three times I have been attacked, always when I reach the reputation of 60. The first two attacks consisted of downvote to bring the reputation of the account to 42; in this last attack, they tried to caravel, but did not succeed. I know, and understand, that the information I will provide throughout this post makes me susceptible to the displeasure of the users I will mention, but I must do so and take the consequences for the sake of strengthening the hive.
You can see in the image above, what happened to my user, from this first public information, we started an investigation and follow the traces of the user @sepa666. It is to alert, that EVERYTHING that receives the account
@sepa666 is product of hacked accounts. The date of creation of the user is recent, January 2023.
EVERYTHING THAT STEALS @sepa666 passes it to
@bdhivesteem and this in turn passes it to
@binance-hot2 where we can find interesting user-accounts that feed on it, I show you screenshots of the wallets of these accounts:
wallet.hive.blog/@sepa666/transfers
wallet.hive.blog/@bdhivesteem/transfers
wallet.hive.blog/@binance-hot2/transfers
Important detail to consider:
The user @sepa666 joined in January 2023.
User @bdhivesteem joined in April 2023
The user @binance-hot2 joined in March 2023
From here on, the funds are transferred to accounts of important power in the Hive, and it is here where I start to have problems, since by mentioning them, I am not saying that these accounts are part of the fraud, but they are consciously or unconsciously benefiting from these funds that come from different hacked accounts. The following is the list of users who benefit directly and can be detailed in the @binance-hot2 portfolio. The order is alphabetical, but these are the repetitive users of accounts that have benefited since
@binance-hot2 has been in existence:
Material removed at the request of some users in the hive.
The history of hacked accounts can be seen in each of the accounts you transferred to @sepa666. These accounts have the same procedure, they are stripped of everything they have in their wallet, be it Hives or Dollar Hives. The user of the account,
@sepa666, converts the Hives Dollar into Hives and retransfers them to the account
@bdhivesteem, who does the same to
@binance-hot2. Below is the list of accounts hacked in the last seven days:
@theresa16,
@shahriearhasan,
@one-manul,
@axe-capital,
@manolium,
@emilylinge,
@beautiful.life,
@feellike,
@armanmahy,
@amigoponc,
@miheer.edits,
@gastruk…
This figure is verifiable if we add up what has been handled since the creation of the @binance-hot2 account, which dates back barely six months. I invite you to have a look at the account's portfolio.
After several attempts, I managed to recover my account. I did it through Hive Account Recovery
This procedure was useful in my case because some time ago I changed the recovery account, which is nothing more than a trust account, which you assign for eventual cases as it happened to me. To assign the trusted recovery account, you can go to the following link @yonnathang. So if you don't have a recovery account, I advise you to do so. In my case, I chose the account of my first wife who is based in Argentina and her user is @atreyuserver.
To recover my username, you can use -si eres de habla Hispano-, I recommend you the procedure well explained by @enmysplinter in his video:
In three simple steps, you can fully recover your account, I'll explain. Remember that you must have the trusted recovery account.
Go to portal Hive Account Recovery and select the first option in the image, the blue box:
Notice that you have the “new private MASTER key” and you have generated a ”new owner key”, copy both keys and save them very well. You should hurry, because whoever hacked my account noticed the generation of the new public key and used it against me, so it took me several tries before I was able to beat him.
Now let's go to the second step, this step is done by the person holding the recovery account that you have previously assigned, you can do it in the RED box on the same portal. For the second pass, the person of the trusted account goes to the home portal and selects the GREEN box that says “Request Recovery”, remember to pass the public key that you generated.
As requested by the portal, the owner of the recovering account provides the name of the account to be recovered, the public key generated in step one, then enters his username and the private MASTER key of the account that serves as a trust or fiduciary account. For security reasons, I leave the data indicated, but I will not click on the green button labeled “Submit Recovery Request”, this is just an illustrative example.
We go to the third and last step, return to the BLUE BOX, as you know, and go down to where the third step indicates. There we are going to write the information requested in each of the fields. I remind you that this process must be done quickly, because the hunter is doing the same as you.
The last MASTER key that is requested and that will be deleted, replaced by the new one you saw in step 1 and that always starts with a "P", is the private master key that you originally had for your account. When it indicates that it should not be older than 30 days, it refers to the process initiated by the hacker, if the hacker hacked your account more than 30 days ago, you will not be able to recover the access, that is to say, the recovery process must be done before 30 days have passed since the hacker got hold of your user.
Once you click on "Recovery Acont", you will receive a green notification that your account has been recovered, if failed, you will receive the denial in a red box. Once you have generated and certified your PRIVATE PROPRIETARY MASTER KEY, you will be able to log in to your hive.block account and the next step is to generate the new keys and store them in a safe place and use them according to the particular power of each key.
****🔆****🔆****🔆****🔆****🔆****🔆****🔆****🔆****🔆****🔆****🔆****