Bitcoin Forum

Alternate cryptocurrencies => Mining (Altcoins) => Topic started by: tpd09 on February 07, 2021, 01:02:54 PM



Title: Hive OS weird events
Post by: tpd09 on February 07, 2021, 01:02:54 PM
Hello everyone - last night 2 of my 4 workers switched mining somehow to a different pool and wallet.

Had to delete the wallet.dat file and update my rig.conf files to get them back to my pools and wallets.

anyone had similar experiences?


Title: Re: Hive OS weird events
Post by: socks435 on February 07, 2021, 01:12:02 PM
I haven't experience the same thing. Maybe someone knows your password so change your password immediately. Or maybe you set it to auto switching pool.


Title: Re: Hive OS weird events
Post by: mak013 on February 07, 2021, 01:59:54 PM
Usually this is a user problem. Try to find how you can be hacked. Change passwords, check your main PC with different antivirus programs. I think HiveOS team have no necessity to steal your rigs.


Title: Re: Hive OS weird events
Post by: RabbiTANK on February 07, 2021, 03:12:35 PM
I don't get it, you aren't supposed to get hacked or anything since you are running on a Linux build mining OS, the culprit can't be hiveOS, may be your email is compromised, try changing your email password and activate 2FA, I use 2FA with nicehash on my PC


Title: Re: Hive OS weird events
Post by: P00P135 on February 07, 2021, 03:58:32 PM
I don't get it, you aren't supposed to get hacked or anything since you are running on a Linux build mining OS, the culprit can't be hiveOS, may be your email is compromised, try changing your email password and activate 2FA, I use 2FA with nicehash on my PC

You log into a website to make changes to your mining wallets, pools, ect.. which can be hacked if you use stupid passwords or the same email passwords that have been compromised in the past.


Title: Re: Hive OS weird events
Post by: Claudio99 on February 07, 2021, 04:05:10 PM
I don't get it, you aren't supposed to get hacked or anything since you are running on a Linux build mining OS, the culprit can't be hiveOS, may be your email is compromised, try changing your email password and activate 2FA, I use 2FA with nicehash on my PC

You log into a website to make changes to your mining wallets, pools, ect.. which can be hacked if you use stupid passwords or the same email passwords that have been compromised in the past.
Exactly, it's why its a bad idea to use same password for every single website you create account on, information might get leaked, email can be compromised and hackers will start inserting that same password into every websites you've visited before


Title: Re: Hive OS weird events
Post by: tpd09 on February 08, 2021, 05:46:58 PM
The most weird thing is I did not get any notification on telegram for "new device login". - Should my account been compromised. Im sure hiveos guys have nothing to do with this.


Title: Re: Hive OS weird events
Post by: HaloGenius on February 09, 2021, 10:56:52 PM
The most weird thing is I did not get any notification on telegram for "new device login". - Should my account been compromised. Im sure hiveos guys have nothing to do with this.
If your rig has a real IP address (direct connection) and you have not changed your SSH password than the attacker can SSHing into your rig (many bots constantly scan to get new victims) and change miner settings.
Generally, it's a bad idea mining on the rig with real IP ("white").


Title: Re: Hive OS weird events
Post by: tpd09 on February 11, 2021, 07:38:33 AM
thats what has been happening. they do it day after day at night.

so I need to white list my ip right? but if dynamic?


Title: Re: Hive OS weird events
Post by: tpd09 on February 12, 2021, 08:42:32 AM
for anyone facing the same issues with hacked rigs - refer to this:
https://hiveos.farm/guides-security/


Title: Re: Hive OS weird events
Post by: melpheos on February 12, 2021, 02:21:24 PM
thats what has been happening. they do it day after day at night.

so I need to white list my ip right? but if dynamic?
How come your rig(s) have a public IP address directly attached to it ???
This is extremly rare for an ISP to provide such service.
You should check your box/firewall settings as it's probably a DMZ which is configured