Were any password hashes potentially compromised?
The reported hack is for a 3rd party server. The coin analyzer site that uses only public minted seat data. That server has no private data of nastyfans members.
The hacked server displayed a faked nastyfans sign in page. The images on that page were broken and it was not SSL secure. But it looked enough like real site for some members to try to sign in. By trying to sign in those members provided their clear text passwords that were sent to the hacker. A typical phishing attack.
After OgNasty notified me of incident I personally investigated nastyfans logs for any suspicious activity. There is no evidence that any component of the official nastyfans infrastructure is compromised in any way. The phishing attack was on a 3rd party server where I have no access. So I have no possibility to know which members were fooled and provided their sign in data to the foreign party. OgNasty and that server owner (naypalm) are doing their part to investigate the issue.
The advice of OgNasty to change your password is a extra precaution but certainly not necessary for most members. I am not changing my password because I know I never signed in to the phishing site. But I did see the site.
The best advice was from Quickseller. Never use the same password on different sites. Never.