Bitcoin Forum
May 11, 2024, 05:48:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Africunia [AFCASH] website hacked - Users beware!  (Read 144 times)
Narcissistic (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 23
Merit: 5


View Profile
November 01, 2019, 11:03:14 AM
Last edit: November 02, 2019, 01:55:33 AM by Narcissistic
 #1

Hi guys,

Back with more bad news it seems, (been exposing multiple exchanges recently being hacked and admins giving zero f*cks) Africunia [AFCASH] website was hacked back in May, and contact was made to the admins on Telegram (see screenshots) on May 31st~ and they were informed that their website was hacked and all databases were dumped, with root access gained.

The admin responded with little to no care, with threats to finish off the conversation. It was my understanding the site was then taken down for "maintenance" AKA resolving the issue. I should have known better.





Fast forward 5+ months later, and their site is still as vulnerable as ever, with customers logging in as recently as 1-2 weeks ago to withdraw AFCASH. phpmyadmin mysql database user hash was cracked instantly and all database(s) are available for dumping.



This is a warning to anyone who uses https://www.africunia.com or who purchased in their ICO a while ago, change your passwords (especially if you re-use passwords) and so forth. I am going to submit this to https://haveibeenpwned.com/ so people have multiple chances to see their data was involved in a breach.

Chat soon.
1715449695
Hero Member
*
Offline Offline

Posts: 1715449695

View Profile Personal Message (Offline)

Ignore
1715449695
Reply with quote  #2

1715449695
Report to moderator
1715449695
Hero Member
*
Offline Offline

Posts: 1715449695

View Profile Personal Message (Offline)

Ignore
1715449695
Reply with quote  #2

1715449695
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, but full nodes are more resource-heavy, and they must do a lengthy initial syncing process. As a result, lightweight clients with somewhat less security are commonly used.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715449695
Hero Member
*
Offline Offline

Posts: 1715449695

View Profile Personal Message (Offline)

Ignore
1715449695
Reply with quote  #2

1715449695
Report to moderator
1715449695
Hero Member
*
Offline Offline

Posts: 1715449695

View Profile Personal Message (Offline)

Ignore
1715449695
Reply with quote  #2

1715449695
Report to moderator
1715449695
Hero Member
*
Offline Offline

Posts: 1715449695

View Profile Personal Message (Offline)

Ignore
1715449695
Reply with quote  #2

1715449695
Report to moderator
ajiz138
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 785



View Profile WWW
November 01, 2019, 10:13:22 PM
 #2

I still have around 1000 AFCASH but I have already transferred it to my ERC20 Wallet and not the AFCASH wallet. is it still not safe for now if I move it back to the AFCASH wallet. if the application for Android what is also vulnerable to use. how much Price for this coin now?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
Kemarit
Legendary
*
Offline Offline

Activity: 3080
Merit: 1353



View Profile
November 01, 2019, 10:27:20 PM
 #3

I still have around 1000 AFCASH but I have already transferred it to my ERC20 Wallet and not the AFCASH wallet. is it still not safe for now if I move it back to the AFCASH wallet. if the application for Android what is also vulnerable to use. how much Price for this coin now?

I can't find anything about AFCASH in either coingecko or cmc so we don't know if it still on ICO price or way below. Thanks to the OP for the warning though, if developers are not serious about fixing their vulnerabilities or at least admitting that something is wrong, then how can you trust this project in the first place? And the only thing we can do right now is just spread the word about it and I do hope that investors are going to listen.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
CjMapope
Legendary
*
Offline Offline

Activity: 1820
Merit: 1092


~Full-Time Minter since 2016~


View Profile WWW
November 01, 2019, 11:18:16 PM
 #4

Hi guys,

Back with more bad news it seems, (been exposing multiple exchanges recently being hacked and admins giving zero f*cks) Africunia [AFCASH] website was hacked back in May, and contact was made to the admins on Telegram (see screenshots) on May 31st~ and they were informed that their website was hacked and all databases were dumped, with root access gained.

The admin responded with little to no care, with threats to finish off the conversation. It was my understanding the site was then taken down for "maintenance" AKA resolving the issue. I should have known better.





Fast forward 5+ months later, and their site is still as vulnerable as ever, with customers logging in as recently as 1-2 weeks ago to withdraw AFCASH. phpmyadmin mysql database user hash was cracked instantly and all database(s) are available for dumping.



This is a warning to anyone who uses https://www.africunia.com or who purchased in their ICO a while ago, change your passwords (especially if you re-use passwords) and so forth. I am going to submit this to https://haveibeenpwned.com/ so people have multiple chances to see their data was involved in a breach.

Chat soon.

:O damn, i heard of that one, but remember i thought it was kinda shifty
now i wonder if that was a sign of their type of incompetence, or if it was their plan all along for some kind of "we lost our data" scheme in the end
thanks for the heads up man, hopefully noone's personal info or anything gets sold off : / (thats always my fear)

~Got this girl in my bed, a roof over my head, i mint a couple coins a week, and thats how i make bread~
~On the 12th day of Hatzvah, OGminer said to me: "compute root of the merkle hash tree!"~
Prohashing  -- Simply the best Multipool!
Baofeng
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
November 01, 2019, 11:40:22 PM
 #5

Being incompetent was a first sign that this project is not to be taken seriously. They have been called and didn't do anything about it? What are they waiting for? Until hackers took off all the money and then this blame those wallet holders? Glad I'm not into this shit coin, for those holders, I don't know if you can sell off, but expect for the worst here.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Twinkledoe
Full Member
***
Offline Offline

Activity: 1904
Merit: 138


★Bitvest.io★ Play Plinko or Invest!


View Profile
November 01, 2019, 11:41:01 PM
 #6


:O damn, i heard of that one, but remember i thought it was kinda shifty
now i wonder if that was a sign of their type of incompetence, or if it was their plan all along for some kind of "we lost our data" scheme in the end
thanks for the heads up man, hopefully noone's personal info or anything gets sold off : / (thats always my fear)

Seems I am with the 'plan all along thingy' here. I wonder where those personal info will end up with. It is really scary to send your vital info to websites that you have no strong knowledge of their foundation.

Being incompetent was a first sign that this project is not to be taken seriously. They have been called and didn't do anything about it? What are they waiting for? Until hackers took off all the money and then this blame those wallet holders? Glad I'm not into this shit coin, for those holders, I don't know if you can sell off, but expect for the worst here.

Incompetency at its best!
Narcissistic (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 23
Merit: 5


View Profile
November 02, 2019, 01:44:21 AM
 #7

I still have around 1000 AFCASH but I have already transferred it to my ERC20 Wallet and not the AFCASH wallet. is it still not safe for now if I move it back to the AFCASH wallet. if the application for Android what is also vulnerable to use. how much Price for this coin now?

Please. Do NOT do that.




And I put money on the fact it was a planned exit scam from the beginning. The developers password for admin panel was 123456.
ecnalubma
Sr. Member
****
Offline Offline

Activity: 1526
Merit: 420


View Profile
November 02, 2019, 03:03:22 AM
 #8

Damaged is already done, innocent investors are probably holding another worthless tokens now. Yet another reason why only few has the appetite to invest in ICO’s even the project name is not sound appealing to me. I hope poor investors will find justice for this.
NathanJB
Sr. Member
****
Offline Offline

Activity: 756
Merit: 251


View Profile
November 02, 2019, 03:21:48 AM
 #9

Being incompetent was a first sign that this project is not to be taken seriously. They have been called and didn't do anything about it? What are they waiting for? Until hackers took off all the money and then this blame those wallet holders? Glad I'm not into this shit coin, for those holders, I don't know if you can sell off, but expect for the worst here.

Holders should move their AFCASH now. They urgently need to evacuate. We should thank the OP for giving everyone here the heads up. This does not look good at all.

If the project is not doing something despite advance warnings, this means there are two possibilities. That the project is indeed incompetent and should not be trusted, or the attack is coming from someone from the inside or has links from the inside. The attack appears to be given open doors.
watergold
Sr. Member
****
Offline Offline

Activity: 1218
Merit: 251



View Profile
November 02, 2019, 03:23:00 AM
 #10

I still have around 1000 AFCASH but I have already transferred it to my ERC20 Wallet and not the AFCASH wallet. is it still not safe for now if I move it back to the AFCASH wallet. if the application for Android what is also vulnerable to use. how much Price for this coin now?

I can't find anything about AFCASH in either coingecko or cmc so we don't know if it still on ICO price or way below. Thanks to the OP for the warning though, if developers are not serious about fixing their vulnerabilities or at least admitting that something is wrong, then how can you trust this project in the first place? And the only thing we can do right now is just spread the word about it and I do hope that investors are going to listen.

I searched for the price of AFCASH on Google and didn't find it even in Coingecko deleted, it seems like this project is no longer profitable for investors, I just found out about this news and want to know how the platform is developing now, I also still have some AFCASH in my wallet.

         ▄▄▄███████▄▄▄
     ▄▀█▀█ █████████████▄▄
   ▄██ █ █▄████████████████▄
  ██ █ ██▀█ █████████████████
 █▀█▄█▄▀█▄██▄█████████████████
██ █ ██ ██ ██▄▀████████████████
███▀█▀██ ███▀███▀██████████████
███▄██ ██▄▀██▄███▄█████████████
 ███▄▀██▀██▄▀██▄▀██▄▀▀████████
  █████▀█▄█▀█▄▀▀██▄▀▀██▄▄▀█▀█
   ▀████▄███▄█▀█▄▄▀▀▀█▄▄█▀█▀
     ▀▀████▄▀██▄▄█▀▀█▄▄▄▀▀
         ▀▀▀██▄▄███▀▀▀
.
1xBit.com BENEFIT SEASON
       ▄▄███████████▄▄
    ▄███████████████████▄
  ▄██████████████████████▄
 █████████████████████████
██████████████████████████▌
████████████████████████████▄▄
███████████████████████████████
        █    █▄   █
        ▀▀▄    ▀▀▀█▀▀▀█▀▀▀▀▀▀▀█
           ▀▀▄    ▀▀▄▄█      ▄▀
              ▀▀▄     █▀▀▄▄  █
                 ▀▀▄  █   ▄█▀
                    ▀▀█▄▀▀
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
.
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
.
PLAY NOW
██████████
██
██
██
██
██
██
██
██
██
██
██
██████████
Drai
Sr. Member
****
Offline Offline

Activity: 567
Merit: 270



View Profile
November 02, 2019, 03:28:30 AM
 #11

I have an active post where I listed things to avoid if you do not want to get scammed and I would definitely add this to it, people should not repeat the same passwords in every website, they should have somewhere secure that they can store their used passwords (preferably offline) so that they wouldn't forget it, many a Cryptocurrency enthusiast has lost funds this way, my unsecured Bitmex account was hacked once, I had not t even set up 2FA or made any deposit to it, imagine if I had used the same password for my Binance and other cryptocurrency exchanges.

Narcissistic (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 23
Merit: 5


View Profile
November 02, 2019, 04:03:58 AM
 #12

Being incompetent was a first sign that this project is not to be taken seriously. They have been called and didn't do anything about it? What are they waiting for? Until hackers took off all the money and then this blame those wallet holders? Glad I'm not into this shit coin, for those holders, I don't know if you can sell off, but expect for the worst here.

Holders should move their AFCASH now. They urgently need to evacuate. We should thank the OP for giving everyone here the heads up. This does not look good at all.

If the project is not doing something despite advance warnings, this means there are two possibilities. That the project is indeed incompetent and should not be trusted, or the attack is coming from someone from the inside or has links from the inside. The attack appears to be given open doors.

Open doors, not quite, it's just incompetent retards putting next to no effort into their website as it is a scam from the beginning, so why bother having a secure website when you don't plan on being around long enough to give a shit?

They made roughly $317,000~ USD from this scam ICO (if the $1=1AFCASH) is the same price at the ICO as it is now (from what I can see on the backend).

Look at this shit lol







That's the developer ^
tbterryboy
Sr. Member
****
Offline Offline

Activity: 1918
Merit: 322


View Profile
November 05, 2019, 08:16:17 PM
 #13

What if it was eve the project that did that themselves because I have lost trust in the project ever since they have been dribbling us about the establishment of their exchange which could not even make people to withdraw this africunia cash, at first, they went to list coin on fork delta I think, or is it ether delta, one of these useless dex exchange that no one wants to pick interest in buying the coin, later they released a fake exchange that has no volume and since then , I have decided not to give a fuck to the project again, After all, the 4000 Africana cash that I have was from their bounty, thank God I did not put my personal money in there, so they can take their cash back, I have more better project to use my time for and get some benefits.
joinfree
Sr. Member
****
Offline Offline

Activity: 1246
Merit: 260

1A6nybMUHYKS6E6Z3eJFm4KpVDdev8BAJL


View Profile
November 05, 2019, 08:25:36 PM
 #14

This is quite unfortunate and it's so pathetic that the administrators of the platform don't show much concern about the problem. These series of hacks should send a strong warning to everyone out there not to hold their funds on very new platforms because they are quite susceptible to security breaches. Don't also forget to authorize 2FA and other secondary security mechanisms just to give extra security to you account on such platforms.

Crypto Enthusiast supporting innovative ideas for the Liberalization of the world from the Centralized Institutions.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!