Hackers Hijack DNS Server for Cyrptocurrency Wallet BlackWallet, Over $400K Stolen From Users

By CircleID Reporter

Unknown hackers (or hacker) have hijacked the DNS server for BlackWallet.co, a web-based wallet application for the Stellar Lumen cryptocurrency (XLM). Catalin Cimpanu reporting in Bleeping Computer: "The attack happened late Saturday afternoon (UTC timezone), January 13, when the attackers hijacked the DNS entry of the BlackWallet.co domain and redirected it to their own server. 'The DNS hijack of Blackwallet injected code [said Kevin Beaumont] a security researcher who analyzed the code before the BlackWallet team regained access over their domain and took down the site ... If you had over 20 Lumens it pushes them to a different wallet… the attacker collected 669,920 Lumens, which is about $400,192 at the current XML/USD exchange rate."

Related topics: Blockchain, Cyberattack, DNS


This article is insufficiently detailed Karl Auerbach  –  Jan 16, 2018 5:35 PM PDT

This article does not say enough to be useful.  Was a DNS server taken over via a penetration, or was the registrar/registry penetrated (e.g. a password or phishing attack) and the delegation changed to a masquarading DNS server, or some other attack vector?

Another point - Since we are talking security here - does CircleID support HTTPS?

Yes Roland Rocke  –  Feb 10, 2018 6:36 AM PDT

