[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2nzr0lwiwrsz4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488251b3","ethereum","Ethereum Data Breach","ethereum.org","2016-12-16T00:00:00.000Z","2016-12-20T23:56:26.000Z","2026-07-09T23:10:41.746Z","2026-07-18T23:50:12.852Z","Forum database backup breach","https:\u002F\u002Fblog.ethereum.org\u002F2016\u002F12\u002F19\u002Fsecurity-alert-12192016-ethereum-org-forums-database-compromised",[15,17],"https:\u002F\u002Fwww.troyhunt.com\u002Fthe-ethereum-forum-was-hacked-and-theyve-voluntarily-submitted-the-data-to-have-i-been-pwned\u002F",16431,"known",null,"unknown","Medium",[24,25,26,27,28,29],"Email addresses","IP addresses","Passwords","Private messages","Usernames","Website activity","\u003Cp>\u003Cstrong>Ethereum data breach\u003C\u002Fstrong> concerns a backup of the database belonging to the old forum infrastructure running on forum.ethereum.org, rather than the Ethereum network itself or users' wallets. The incident was detected on December 16, 2016, and the number of verified accounts for the records affecting approximately 16,500 forum users was kept at 16,431. The exposed information is within the context of forum accounts and in-forum interactions: email addresses, IP addresses, usernames, private forum messages, website activity, and password hashes are considered in this scope. This distinction is important, as the incident should not be described as a compromise of the Ethereum protocol, blockchain, smart contracts, or crypto asset wallets.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>The verified data types consist of email addresses, IP addresses, passwords, private messages, usernames, and website activity fields. It has been noted that the majority of passwords are protected with bcrypt, while some are protected with WordPress-based salted hash structures; this does not mean that the password is directly readable, but the risk remains for weak or reused passwords on other services. When an email address and username are found together, attackers may try to associate the forum identity with accounts on different platforms. IP addresses, on the other hand, can provide clues about approximate connection location, service provider, or session context.\u003C\u002Fp>\n\u003Cp>Private forum messages are one of the areas of this record that must be handled most carefully. Forum messages can include technical discussions, project relationships, communication within the community, personal notes, or trust-based conversations with other users. Website activity can also help understand a user's behavior, interactions, and account usage patterns on the forum. While this data alone does not provide access to financial assets, it creates strong context for social engineering, targeted phishing, fake support messages, and password reuse attacks.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified number of affected accounts for this record is 16,431, and the incident date is used as December 16, 2016. The official statement indicated that the accessed data is a backup of a forum database from April 2016, contains records of approximately 16.5 thousand forum users, and the unauthorized access occurred as a result of a social engineering chain. Therefore, it is not correct to generalize the record to all users in the Ethereum ecosystem or all wallet holders. The scope is limited to individuals with forum accounts, and to the message and profile data on that forum.\u003C\u002Fp>\n\u003Cp>In this incident, no verified field should be marked as indicating that on-chain transaction history, wallet balance, private key, seed phrase, or smart contract asset have been leaked. Since there is a password field, there is a security risk for the account; however, the fact that most password hashes use modern and salted protection means that the risk should primarily be assessed based on weak password choice and password reuse. Technical fields present in the raw forum backup should not be presented as a new data type by removing them from verified data classes.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of individuals who opened an account on forum.ethereum.org before 2016 and used the same password on other services. For these individuals, the risk remains current if an old forum password is still used for email, exchange, social media, developer account, or community platform. Even if password hashes are not in plain text, over time weak passwords can be guessed, matched with other leaks, or used in automated login attempts. Protecting the email account is therefore a priority.\u003C\u002Fp>\n\u003Cp>Developers who exchange private messages on the forum, early-stage Ethereum community members, open-source contributors, and individuals using usernames recognized in the cryptocurrency ecosystem may also carry additional risk. If private messages contain project links, contact information, technical discussions, or social context, attackers could craft more convincing messages. IP addresses and website activity can provide limited insight into a user's time zone or access habits. Therefore, this breach not only requires a password change but also necessitates checking where the account identity has been reused.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>It should be immediately checked whether the password used for the forum account has been used elsewhere. If the same or a similar password has been used on email, developer platforms, cryptocurrency exchanges, cloud accounts, social media, or other community forums, unique and strong passwords should be set for all these accounts. Multi-factor authentication should be enabled wherever possible, with priority given especially to email and accounts linked to financial transactions. Reusing an old forum password with minor changes should not be considered secure.\u003C\u002Fp>\n\u003Cp>It should be assumed that private messages on the forum may contain sensitive links, old invitations, personal contact information, or hints about other accounts. Users should be cautious of fake Ethereum-themed support messages, wallet verification requests, individuals appearing as community moderators, and account update links. No legitimate service will ask for your private key, seed phrase, or wallet recovery information via messages. If you use the username from your forum history elsewhere, also review the visible profile information and recovery options on those accounts.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, using a separate password for each community account and managing critical accounts with separate email addresses is the most effective defense. Since usernames used in open source, forum, and cryptocurrency communities often remain unchanged for years, even an old forum record can link a person to their current accounts. Therefore, it is necessary to reduce unnecessary repetition between developer accounts, exchange accounts, email addresses, and social media profiles. A password manager is a practical solution both for generating unique passwords and for keeping track of accounts created years ago.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, the incident shows that the security of old backups and account recovery channels is as important as that of live systems. Unused database backups should be removed from access, accounts that access backups should be protected with multi-factor authentication, and phone number-based recovery mechanisms should be carefully restricted. For forums, the retention period of private messages, password hashing algorithms, access logs, and user notification processes should be regularly audited. On the user side, closing old forum accounts or simplifying profile information reduces risks that may arise years later.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you used the Ethereum forum before 2016, you need to check whether your email address is associated with this record. If there is a match, first secure your email account and any accounts that may have used the same password. Then, increase your vigilance against targeted messages, considering private messages in your forum history, usernames you shared, and connections you established with other platforms. Even if the incident is old, the risk can persist when the forum identity, email address, and password reuse come together.\u003C\u002Fp>\n\u003Cp>This record has been prepared to properly assess the Ethereum data breach in context: the incident is limited to the forum database backup, the number of verified accounts is maintained as 16,431, and the data classes consist of email addresses, IP addresses, passwords, private messages, usernames, and website activity fields. The basic actions for users are to use unique passwords, enable multi-factor authentication, be cautious of fake crypto support messages, and assess whether information previously shared in private messages still poses a risk today.\u003C\u002Fp>","","Ethereum Data Breach (16.4 Thousand Reported Records)","Ethereum Data Breach. 16.4 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fethereum_org.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":20},"Ethereum Foundation","Blockchain","Switzerland"]