Some information here:
http://www.reddit.com/r/NZBitcoin/comments/2dak6a/bitnz_announcement/bitNZ Announcement (self.NZBitcoin)
submitted 14 minutes ago by djpnewton
On Monday, 11 August 2014 at 3am NZ time, ~39 bitcoins were stolen from bitNZ.
Our email relay service provider was hacked which enabled the attacker to view all outgoing emails. The attacker used this information to reset user passwords and intercept the password reset email. If the user did not have 2FA the attacker was able to log on as the user and initiate a withdrawal.
At the moment I am still analysing the the event and making sure the vulnerability is plugged (revoke email relay access, reset passwords/api-keys, purge sessions, check if user emails were modified etc).
I need to take the time to do this thoroughly so please have some patience. You can contact me at
[email protected] or ask questions on this thread.
I am going to cover the loss. If you would like to donate to help here is the address 1NAVXrA8NnXURzdFNLf79p8YoLPBBfwnFi (qrcode)