SPOs, Do not repeat my mistakes, Keep your Core Node Safe

Yep, well said here @rin9s

@junada Would be happy to support you with a small ADA donation to help - and a larger delegation if you still decide to run a stake pool?

Security so key in every aspect of this world; such a shame. But I’m sure, one day in the future, you’ll look upon this same experience as a valuable life lesson - that you can, (and have begun to), pass onto others.

Many thanks my friend! :pray:t5: :ok_hand:t5:

4 Likes

I’m so sorry to hear this! Thank you for posting your experience and please persevere!

2 Likes

Sorry for your lost. I almost lost my SP pledge in the process of deleting keys of the sp server. Luckily, my co-operator had backup. SPOs need to be extra careful. Thanks for sharing

3 Likes

Thank you for sharing your story, a much needed wakeup call for everyone. I hope you recover from this as the community needs good people like you, hopefully we will all learn from your unfortunate experience.

3 Likes

Thank you for sharing and I wish you all the best moving forward. Stay strong!

2 Likes

Thanks for sharing your experience and sorry for your loss. This learning experience will help us make our pools’ security stronger.

2 Likes

Thank you for sharing Jun. I’ve been seriously hurting for you since I heard about the hack. There will definitely be some good that comes out of this in that the whole community of SPOs have been busy reviewing and re-reviewing their security practices and technology. If there is anything I can do to help during this time, feel free to reach out on telegram.

4 Likes

Thank you for sharing such mistake to us. We now know what is the weak spot of the security setting. And we’ll be more careful. Good luck…

1 Like

Its very disheartning to read this. I feel sorry for your loss mate. Hat’s off to your courage for bringing this up as well. Feel free to connect on my BubbaGanuStakePool Telegram if anything I can do to help you out.

My heart goes out to you man. You still have your health and more money can always be earned. Thank you for sharing your story

This is horrible to hear Jun … was this your full ADA stack taken from you?

Surely Cardano should reemburse you with these lost funds. There will be many others making the same mistakes.

Very sad experience. So glad you evaluated the situation and were able to so clearly define the problems. It’s a certainty that many other pool operators will benefit from your openness.

You’re a good community partner. Keep your pool running. Better days ahead.

Craig

Thanks for sharing your story so other cases like this might be averted, I hope you can recover from this @junada and continue to run a Cardano Stakepool.

thanks for sharing, I’m a newbie and posts like this are really going to help me…

Very sorry to hear this story. Thank you for deciding to share it with the community; hopefully, it will help others to protect themselves. Good luck as you work out what to do next, and best wishes for the future.

Sorry for your loss. Thank you for sharing your experience. It takes a lot of courage to do that. I wish you all the best.

I am really sorry this has happened to you. I want to make sure it doesn’t happen to anyone else, so I wrote an article on how SPO could employ various security measures to run their operation securely.

1 Like

Really terrible thing. Sorry for your loss. It’samazing how some one can live with themselves after destroying other people’s lives like that. It’s no different to murder.

This is how a disclosure should be performed. Well done, and thank you for being honest to the Cardano community and helping the SPOs. I encourage each stake pool to think about layered defenses, not only from a trust boundary such as a port/firewall but also monitoring and logging. Please SPOs use things such as deception and alerting to identify malicious actors on your machines. Canary tokens are a great way to get an alert when a file is accessed or someone has cloned your website trying to impersonate you. This is a free service. https://canarytokens.org/generate or if you would rather not click a link (this would be me) just google canary tokens and do some research on the subject.

Anyone have thoughts for the SPOs on using a honeypot node to see if there is malicious traffic specifically looking for relay/node architectures?

I’m interested in operating something like this and reporting to a close-knit group of SPOs on what kind of traffic/attacks are occurring.