Earlier this evening, amid complaints of fraudulent withdrawals from many of our miners, we at Hackshard launched a full investigation into our databases, websites, and other software with the goal of identifying and eliminating the faulty code, hardware, or security. We discovered no fault in the cronjobs, databases, stratum servers, wallets, or any of the other various components of the Hackshard mining pools. While this did confirm that the Hackshard infrastructure was not at fault, our findings hinted at something perhaps even more worrisome. We found that several dozen miners had recently withdrawn to a single address: the same address as that which many of those claiming fraud had presented to us as having stolen their coins. Given the extreme unlikelihood of so many miners being host to the same keylogging virus, and given the complete lack of evidence that our own pools have been infiltrated by malicious agents, we have concluded that the issue could only have arisen from miners using identical login credentials with multiple pools. If this is the case, with a significant portion of our miners having been victims, we further conclude that only one with access to the database of a rather large pool could have been the thief. As such, we request that all miners who have been affected by this theft respond immediately with a full list of pools which they have recently used so that we may attempt to identify the malignant pool. We further request that all pool owners search their outgoing transactions for multiple usernames withdrawing to a few addresses.
We strongly urge everyone to use separate credentials on each and every pool he or she uses and to enable automatic payments.
All,
My career is in information security. I am not affiliated with, nor have I mined at Hackshard's pool, but what this gentleman (or lady) states does make sense. I urge you all to do as Hackshard recommends. Many other people here on this forum have given the same or similar advice:
Use different login credentials for each pool you visit - even for different coins.
Use a complex password - not from the dictionary, not your cat's middle name, not your mom's maiden name.
AGAIN, Do NOT reuse passwords accross different systems. Make your passwords are different for your mining accounts, your bank, your email etc. etc. I know it's a pain in the ass, but it is doable. Remember, the current recommendation is to write them down and put them in your (physical) wallet or purse. It is a lot easier to lose your passwords on your computer than to have a thief break into your home and steal your wallet. And, if your wallet is stolen, you will know about it and take action for your credit cards, driver license etc as well as your passwords. If a hacker steals your on-line password that is on your computer, you may not find out about it until he/she does a lot of damage.
Good luck and lets keep mining clean.
d