Default avatar
npub1ld5x...x4yp
npub1ld5x...x4yp
Baixei o qwen local e coloquei ele para ler a biblioteca do instituto Rothbard toda em PDF. Será que amanhã ele estará dizendo que imposto é roubo, o estado é uma máfia e é para comprar bitcoin? 😂 Grandes esperanças!
Compass mining was hacked: To Our Customers, On the evening of August 10, we identified unauthorized activity involving Compass Mining marketplace accounts. The activity included attempts to change passwords, two-factor authentication settings, and backup codes without account holders' authorization. We want to be clear about what happened, what was accessed, what was not affected, and what we are asking you to do now. What happened An unauthorized party exploited a weakness in the authentication system supporting our marketplace. This allowed them to reset login credentials and access a number of customer accounts. Our team identified the activity that evening, activated our incident response process, and disabled the affected functions within hours. The activity stopped, and we have seen no further unauthorized attempts since. What was accessed Our technical review found that the unauthorized party was able to access the following information on affected accounts: Account email addresses. Invoice and transaction history, including payment amounts, invoice amounts, and associated dates. The following information and systems were not affected: No payment card numbers, bank account details, or stored payment credentials. No wallet balances or wallet information. Attempts to access wallet-related functions returned no data. No mining pool changes were pushed to machines. Customer hardware continued operating without service interruption. About your mining pool settings The unauthorized party removed mining pool information stored on affected accounts and attempted to replace it with their own pool as the default in the Compass Mining dashboard. The attempt did not redirect any hashrate. Changing a pool setting in the marketplace does not, by itself, change where a machine points. Pool changes must pass through a separate validation process before taking effect, and that process prevented the attempted change from reaching customer machines. We identified every pool entry altered during the incident and separated those changes from legitimate pool updates already scheduled during the same period. We are now restoring the affected settings. Once that work is complete, please review your pool configuration and open a support ticket if anything does not look correct. What we have done Terminated all active account sessions. Reset all customer passwords, two-factor authentication settings, and backup codes as a precaution, whether or not an account showed unusual activity. Closed the path used to access the accounts and strengthened the surrounding security configuration. Applied current security updates to the affected system and established an ongoing patching and vulnerability review schedule. Increased monitoring across our authentication systems. Preserved technical evidence and initiated efforts to identify those responsible for the activity. What we are asking you to do Reset your credentials. You should have received an email with instructions, which are also available on our login page. If you did not receive the email or are having trouble completing the reset, contact our support team. Review your account. Check your dashboard, account settings, and mining pool configuration to confirm everything looks as expected. Change reused passwords. If you used your Compass Mining password on any other account, change it there as well. Be cautious with unexpected messages. Security incidents are often followed by phishing attempts. Because email addresses and billing amounts were accessed, a fraudulent message may appear convincing. Do not click links or open attachments from senders you do not recognize, even if a message appears to come from Compass Mining. When in doubt, visit our website directly instead of following a link. Report anything unusual. If you see account activity you did not authorize, open a support ticket immediately. What happens next Our investigation and remediation work are ongoing. Once the investigation is complete, we will share additional details, including further measures for continued prevention.