Bitcoin Forum
July 25, 2026, 09:20:18 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Someone's Namecheap account was handed over to a stranger, despite warning  (Read 126 times)
NotATether (OP)
Legendary
*
Offline

Activity: 2408
Merit: 9902


┻┻ ︵㇏(°□°㇏)


View Profile WWW
July 24, 2026, 02:50:05 AM
Merited by goldkingcoiner (1)
 #1

Lots of people here are using Namecheap for their domain registration, so I hope this incident wakes them up and makes them move their domains to somewhere safer!

A Namecheap customer of 13 years is appealing to the community after they changed his email and password at an unauthorized party's request.

The customer told them that this transfer request was unauthorized, but Namecheap performed it anyway.

The transfer request was apparently made over phone call.

This all could've been prevented by strong multi-factor authentication, so this wouleve definitely stopped the take over as long as the unauthorized party doesn't have access to the security keys.

The original topic: https://news.ycombinator.com/item?id=49028037

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
rat03gopoh
Legendary
*
Offline

Activity: 2744
Merit: 1093


NO KYC Exchanger☝️


View Profile WWW
July 24, 2026, 05:50:33 AM
 #2

This all could've been prevented by strong multi-factor authentication,
In a subsequent comment, the OP even admitted he had enabled 2fa, but it didn't actually work in that situation. https://news.ycombinator.com/item?id=49028795

There are several other stories from other commenters that I believe are rooted in Namecheap's security system being quite vulnerable.
https://news.ycombinator.com/item?id=49028523
https://news.ycombinator.com/item?id=49028910

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
eaLiTy
Hero Member
*****
Offline

Activity: 2926
Merit: 971


Have Fun )@@( Stay Safe


View Profile
July 24, 2026, 09:23:38 AM
 #3

~
A Namecheap customer of 13 years is appealing to the community after they changed his email and password at an unauthorized party's request.

The customer told them that this transfer request was unauthorized, but Namecheap performed it anyway.

The transfer request was apparently made over phone call.
It is completely irresponsible of Namecheap to change credentials simply based on a phone call.

A similar incident happened with our forum around 2015. The attacker was able to acquire KVM access and convince the ISP NFOrce to reset the server's root password, giving them complete access to the server. This sort of social engineering hack has been common for over a decade, making this a completely irresponsible move by Namecheap.

You can read the rest of the story about that hack here. : https://bitcointalk.org/index.php?topic=1067985.msg11445725#msg11445725

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Synchronice
Legendary
*
Offline

Activity: 1666
Merit: 1175



View Profile
July 24, 2026, 11:54:46 AM
 #4

I have a question which I always wanted to ask but for some reasons it was always in my mind but this topic gives me a good chance.

For example, if someone hacks my namecheap account or namecheap gets hacked and hackers gain access to my account, transfer my domain and so on, what happens then? If it wasn't my fault and if it was a Namecheap's data breach for example? Will I be able to reclaim my domain? The reason I have this question is that there are lots of pirate website domains registered and authorities aren't able to shut down those domains by just request, all they can do is to block them locally or seize the website.

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▀█▀████████████████▀████████████████▀█████████████████████████████▀████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████████████████████████▀██████▀█████▀████████▀█████
██████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████▄█▄████████████████▄████████████████▄█████████████████████████████████▄██████▄█████▄████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
 🍒   ⚽️    IIIIIFASTEST GROWING CASINO & SPORTSBOOK     Play Now    
examplens
Legendary
*
Offline

Activity: 4088
Merit: 4785



View Profile WWW
July 24, 2026, 01:31:11 PM
 #5

I have a question which I always wanted to ask but for some reasons it was always in my mind but this topic gives me a good chance.

For example, if someone hacks my namecheap account or namecheap gets hacked and hackers gain access to my account, transfer my domain and so on, what happens then? If it wasn't my fault and if it was a Namecheap's data breach for example? Will I be able to reclaim my domain? The reason I have this question is that there are lots of pirate website domains registered and authorities aren't able to shut down those domains by just request, all they can do is to block them locally or seize the website.
In the regular process, Namecheap should return the domain to you after submitting proof of previous ownership, paying for the domain renew... would be necessary. In case that doesn't work, ICANN is the next instance (if it is under their authority).
Unfortunately, this process can take some time

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
JeromeTash
Legendary
*
Offline

Activity: 2954
Merit: 1579


Heisenberg


View Profile
July 24, 2026, 01:57:09 PM
 #6

I have no experience with domain registration or having a Namecheap account in this case, but I guess the account is supposed to be one of those most secure accounts around to avoid any attacks, and Namecheap should be ensuring that the accounts are completely secure before anyone even thinks of using them.

I like how you can't just change your email address and 2FA on certain centralised exchanges until they are more than certain that it's actually you who wants to change the details through KYC, among other things.

By the way, @NotATether, the link doesn't seem to work. Could the posts have been deleted?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
PX-Z
Legendary
*
Online Online

Activity: 2254
Merit: 1352


Wallet Transaction Notifier - @txnNotifierBot


View Profile
July 24, 2026, 02:22:24 PM
 #7

I have a question which I always wanted to ask but for some reasons it was always in my mind but this topic gives me a good chance.

For example, if someone hacks my namecheap account or namecheap gets hacked and hackers gain access to my account, transfer my domain and so on, what happens then?
That won't happen especially if the domain is lock for transfer which it is usually is. Also, it means your email was hacked too as an authorization code is needed. And it will take days for the process to complete. Unless you're very busy and havent check your email or havent notice the notification. If it happens, then the above reply is the right track to do, and dispute it, registrars who value their users will eventually solve that problem.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
goldkingcoiner
Legendary
*
Offline

Activity: 2856
Merit: 3058


HoDL


View Profile WWW
July 24, 2026, 02:34:11 PM
 #8

Lots of people here are using Namecheap for their domain registration, so I hope this incident wakes them up and makes them move their domains to somewhere safer!

A Namecheap customer of 13 years is appealing to the community after they changed his email and password at an unauthorized party's request.

The customer told them that this transfer request was unauthorized, but Namecheap performed it anyway.

The transfer request was apparently made over phone call.

This all could've been prevented by strong multi-factor authentication, so this wouleve definitely stopped the take over as long as the unauthorized party doesn't have access to the security keys.

The original topic: https://news.ycombinator.com/item?id=49028037

Yeah multi-factor authentication is important (it can be a total pain if you lose it though). And a serious business enforces it on users.

Namecheap is possibly at fault here and should compensate any damages.

Going forward, I would avoid Namecheap. There are better alternatives which do not perform unauthorized requests.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
robelneo
Legendary
*
Offline

Activity: 4046
Merit: 1294


Crypto eXchange with zero traces


View Profile WWW
July 24, 2026, 08:01:02 PM
 #9

Lots of people here are using Namecheap for their domain registration, so I hope this incident wakes them up and makes them move their domains to somewhere safer!

As someone who has a number of domains under Namecheap, I find this alarming; they're an industry giant. This thing should not happen to any of their client. I would have to ask support personally about this issue because if your domain can be transferred by a simple phone call, what would stop scammers from stealing your domain?

Quote
This all could've been prevented by strong multi-factor authentication, so this wouleve definitely stopped the take over as long as the unauthorized party doesn't have access to the security keys.

They have a strict transfer protocol that takes days to complete; I believe the protocol was not followed, and Namecheap could be responsible for this.

Quote
Shortly after order submission, the transfer gets initiated at the Registry, and the domain acquires 'pendingTransfer' status. Transfers that have reached this stage are automatically confirmed within 5 days. Finally, it may take additional 24-48 hours for the Registry to complete the transfer.

How to Transfer a Domain

The Cryptovator
Legendary
*
Offline

Activity: 2968
Merit: 2598


Protect your privacy 🔏 it's very important


View Profile WWW
July 24, 2026, 08:11:50 PM
 #10

A Namecheap customer of 13 years is appealing to the community after they changed his email and password at an unauthorized party's request.

The customer told them that this transfer request was unauthorized, but Namecheap performed it anyway.

The transfer request was apparently made over phone call.

This all could've been prevented by strong multi-factor authentication, so this wouleve definitely stopped the take over as long as the unauthorized party doesn't have access to the security keys.
I have read the full story, but it's unbelievable. I have been using Namecheap for a domain as well as their hosting. Whenever I want to get support, they ask me my account PIN that I have on the account. How is it possible they changed the email and password without requesting it from the original email? If the story is true, then it's quite dangerous for us those who have been using Namecheap to register their domain and their hosting as well.

I can't even log in without verification if the IP or device has changed; it should be the same for every Namecheap user. But changing account credentials without authorization looks quite unrealistic to me. If it's not smear campaigns, then people may start leaving Namecheap and move to another platform. It was my favorite domain name provider for me due to crypto acceptance. Probably they will lose me if the story becomes true. I will try to take a deep look at that matter.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Stalker22
Legendary
*
Offline

Activity: 2310
Merit: 1603



View Profile
July 24, 2026, 08:20:43 PM
 #11

Lots of people here are using Namecheap for their domain registration, so I hope this incident wakes them up and makes them move their domains to somewhere safer!

As someone who has a number of domains under Namecheap, I find this alarming; they're an industry giant. This thing should not happen to any of their client. I would have to ask support personally about this issue because if your domain can be transferred by a simple phone call, what would stop scammers from stealing your domain?

No, I dont think domains can be transferred with a simple phone call.  But you have to think about the other side of the story: what if you actually lose access to your email address and need to change it, but you cant log in to Namecheap anymore?  Thats the nightmare scenario support teams deal with every single day.  They are constantly forced to walk a thin line between locking down security and actually helping legitimate account owners who completely locked themselves out.

If you make recovery impossible without access to your primary email or 2FA, you will inevitably end up permanently bricking thousands of real users businesses.  But if you leave any human backdoor open, like identity verification through support, clever hackers with social engineering skills will eventually find a way to exploit this.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
PX-Z
Legendary
*
Online Online

Activity: 2254
Merit: 1352


Wallet Transaction Notifier - @txnNotifierBot


View Profile
Today at 12:45:20 PM
 #12

... I have been using Namecheap for a domain as well as their hosting. Whenever I want to get support, they ask me my account PIN that I have on the account. How is it possible they changed the email and password without requesting it from the original email? If the story is true, then it's quite dangerous for us those who have been using Namecheap to register their domain and their hosting as well.
Right? It's their standard and many stuff for verification if done on email or live support as per my experience too. But i guess this is an isolated case on the specific support staff who bypass their standard way of verification but who knows. If there will be lots of case like this, then there's no way i will stay there as well. I have at least 5 domains there.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!