On October 25, 2024, at 9:03:54 PM UTC, our @sports-gov account was compromised, resulting in the theft of 0.01615126 BTC and 0.001 Hive. The stolen funds were transferred using the ARCHON system under the account authority of @tmholdings, which managed the @sports-gov proposal system. Importantly, this transaction was unauthorized and unrelated to any active community proposal, indicating that an individual—likely @taskmanager—was draining the account.
The attacker’s actions involved sending 0.001 Hive to @gwbush, followed by a transfer of the BTC equivalent to the wallet address: bc1qz5ve8mwtcxt38hymstx2xhakh7jwjqwnpve5ct
Upon discovering the breach, we took immediate action to secure the account. The authority previously granted to @tmholdings has been revoked to mitigate further risk. Additionally, we are in the process of cycling the keys for @sports-gov to ensure that there is no possibility of key leakage.
Fortunately, the attacker did not claim the 8.6k HP still held in the account. As we evaluate our governance options, we will determine the most effective way to safeguard and utilize these remaining funds for the community’s benefit.
We have submitted a request to the Hive Engine team to investigate the transaction. However, we recognize that the likelihood of recovering the stolen funds is slim. We have also reached out to @taskmanager to request the return of the funds, but we have yet to receive a response.
We will continue to keep the community updated on any developments and our plans for the future management of the @sports-gov account. Thank you for your understanding and support during this time.
Posted using SportsTalkSocial