It appears that the back end provider behind Betcoin.ag/PlayBetr.com/Coinbet.ag has suffered a data breach caused by a rouge employee. This breach happened in February of 2019, and the affected sites are currently investigating. It is currently believed that there were no cases of unauthorized access after February. Neither sites have delivered an official statement yet, but this thread will be updated once they do.
Disclaimer: This post contains information that I believe is true based on publicly posted information as well as private messages with Betcoin and
cheatedplayer. I strive to ensure the accuracy, however I cannot guarantee the accuracy of this information.
What was breached?It appears that the entire database of the provider was stolen. This includes:
- Usernames
- Emails
- Encrypted Passwords
- 2FA Info
- Account Balances
- Transactions
- Support Tickets
Account balances are
NOT at risk, barring any high difficulty bruteforce attacks against specific accounts without 2FA setup combined with email password reuse.
What actions should be taken?It is claimed that the database is
not for sale, however I would not be surprised if it becomes available in the future.
> Change Your PasswordFrom my understanding, passwords were properly stored as salted hashes. This prevents rainbow table attacks and requires that passwords be bruteforced individually. However, I would still recommend you change your passwords on the affected websites, as well as any sites you've reused the password on. This is especially important if you are using a weak password. It's unlikely that anything will come out of the encrypted passwords, but it doesn't hurt
just in case. > Be Wary of PhishingAnyone with access to the database now has a highly targeted email list of those who bet with crypto. There may be a rise in phishing attacks specifically targeting players on Bitcoin gambling sites.
Official Statement:
After an in-depth investigation into this matter, it was determined that a former programmer of the software provider, who had legitimate access was able to gain additional access,and download the database of Betcoin and several other licensees of the software. After this relationship was terminated, he no longer had any access to the database and at no time did he have access to any company or user funds. This is a very serious situation and we immediately devoted all resources to it once we were informed of it.
We are bombarded by threats, DDOS and extortion attempts on a daily basis and each one improves our security. We are extremely regretful that this incident took place, but at no time was anyone’s passwords or funds in jeopardy. We do recommend that all players use a high-level password for both their email and Betcoin accounts and that you activate 2fa for additional security. If anyone needs assistance with an email or password change or setting up 2fa, please contact us any time.
We wish to thank all of our players who have been so loyal to us since we first started in 2013. In this new age of technology, you often hear about some of the largest companies in the world having been breached and unfortunately, this is how new security methods are created. But we are happy to say that, throughout these 6 years, we have never had a player balance or password compromised. We will continue to improve and refine our security methods and we look forward to the next 6 years and beyond of serving our great players. If you have any questions or concerns, please let us know via DM, support ticket or email.
Self moderated to prevent signature spam. Local Rule: This thread is to discuss the data breach and not for scam accusations against either of the sites.