Security Advisory: Wallet Account Login Protection
Recent reports indicate a surge in bulk scanning attacks targeting digital wallets, causing temporary login failures for many users. We would like to bring the following to your attention:
I. Cause of the Issue
Hackers are using automated tools to probe accounts in bulk. By analyzing login error messages to identify valid accounts and exhausting the daily limit of five login attempts, they are causing account holders to be temporarily locked out.
⚠️ Please rest assured that the assets within your wallet remain secure and are not at risk of theft.
II. Security Upgrades
Optimized login error messages, All login errors now display a generic "Account or password verification failed" message to prevent hackers from enumerating valid accounts.
IP-based risk control, Implemented malicious access blocking mechanisms, while retaining security logs to trace attack activities.
III. Solutions
Re-import your account using your original mnemonic phrase and change your account name to a more complex one (combining uppercase/lowercase letters, numbers, and special symbols); avoid using simple identifiers like mobile numbers or QQ IDs.
Set a strong login password to reduce the risk of brute-force attacks. Account + Password (increased complexity) to prevent enumeration attacks.
Note: Wallet functions will be decoupled later this year, with support for integration with familiar third-party wallets, no dedicated client installation required.
https://voidchain.net/zh/news?type=updates&article=edge-trusted-device-wallet-function-split-full-chain-wallet-open-source-declaration
Post #105
164