Script Hack 2019-07-12
This new website is not affected, the only scripts this site loads are React, dashcore-lib, ledger-js and TrezorConnect, all from safe sources.Sadly on the old website an external site (greasyfork.org) got a user account hacked, which provided a CryptoJS script that was used early 2018 for decrypting byte data on mydashwallet.org, the code was already disabled in Q2 2018, but the script hasn't been removed from the old website in time. The old site also carries a lot of fluff from MyEtherWallet, which it was derived from, the new site is completely rewritten and doesn't carry any of the old messy code. In any case since our source code is freely available, our sites gets copied often, scammers are trying to trick users in similar looking websites with slightly different urls and due to the fact everything is out in the open and code is loaded from many places, there are many attack vectors and it is not easy keeping everything up to date. One little messup is all you need and other security goes into the toilet.
After Dash Core
found out about the script hack it was immediately removed.
There isn't much information about the actual hack on greasyfork.Some in the Dash Community are still watching the hacker addresses and funds, if you have any information or can help (e.g. contacting binance about the hacker deposit address XgR4yd8Cms5VwQioCh7ZNC7P4pWAdxf8u5, we can't get anyone to help or respond), please contact support@mydashwallet.org! We are also working together with law enforcement once contacted (only public information below goes to them, we keep all unaffected user data private and don't have much anyway as we don't see local wallets and don't track normal users)
So far we were able to recover the following funds, but that is only because the hacker(s) continued to use MyDashWallet Mixing service. Since the news has been out the hacker(s) seem to be silent and we haven't seen much activity since.
If you have more information, please contact Support@MyDashWallet.org. If you want to donate/recover funds you can use this address: XkY58UD6BnPauY9nCdZurgGsHcsRxeeaGF
We are very sorry if you have been affected, we have to remind everyone that every user is
his own bank and responsible for his funds, at no time did MyDashWallet have access to the user or hacker addresses or funds. Please contact Support@MyDashWallet.org with the following data to receive a percentage of any recovered funds. The percentage is based on how many people want to claim their funds back, every one that contacted us will be informed of this recovery fund.
- The exact transaction(s) to fund your wallet (we can only compare those if you used a MDW node and used the site before, many users send us unrelated transactions)
- The exact transaction(s) from the hacker stealing your funds (we can only send recovered funds from the actual hacker we tracked, if your transaction is unrelated we cannot help, sorry)
- The address you want your recovered funds go to (this will happen by end of August 2019)
- A screenshot from MyDashWallet or any more information would also help
Tracking addresses/ip addresses/etc. during July 2019