OK, just had something not very nice happen to me... someone stole my hashrate! I was getting a 4th pool entry in my GUI that was posting somewhere else. As I was filtering HTTP access I was confused as to where this was coming from. No issues for 3 months, suddenly my hash rate got diverted (only noticed after a few hours unfortunately).
Seems some versions of the antminer software have the API enabled by default. It runs on port tcp/4028, so make sure that you filter access to that port on your firewall/router/whatever. Probably you can fix it in the antminer itself as well, but I have not been able to find a proper description for this (have not looked very hard either).
https://imgur.com/a/Uq6TN
The user is 'xoox' on Antpool ... see screenshot.
Be warned!
If there is any access to it, that is not via a VPN, then sooner or later someone will hack it and change the settings.
For a home miner, it should be behind the router and not have any rules to access it from the net, ever.
If it's in a datacentre, it should be the same, no way to access it from the net, except via a secure VPN.
A miner in a datacentre is at risk to hacking by anyone who has access to the datacentre.
A miner visible on the net is at risk to hacking by anyone on the planet.
FYI: I wrote the API in the miners (it is completely disabled by default)
I told Bitmain they shouldn't leave them open as W:0/0 but they didn't give a shit coz that meant more work for them to change their original bad choice of doing that.
They made that choice coz they wanted to simplify setting up their own datacentres.
It would appear that they at least changed that finally in the S9s - though I'm not 100% sure.