Reposted from FA discord: FA is under a domain hijacking attempt and has not been fixed yet. (The domain for now redirects to the real site, but this may change later.)

Probably do not use it right now.

EDIT: Luffy on Discord claims to have the domain back. Site currently directs to an image of Fender lazing about and a notice that further updates will be delivered at https://discord.gg/furaffinity .

EDIT: Site is fixed! You're good.

Join the Fur Affinity Official Discord Server!

The official Discord community for the largest online furry art gallery website. | 42189 members

Discord

FurAffinity update: They've convinced L1 support this is a problem, but L1 support is asserting that L2 support will not be available to help for 24 to 48 hours.

Network Solutions is a great platform and probably in a better world would be sued for this.

Netsol has replied, but it's visibly L1 support who are unfamiliar with the issue.

My current suspicion is that Network Solutions has a policy of offering a ~48 hour dispute window on account transfer attempts.

They presumably notified Dragoneer that someone was attempting to take ownership of the account, and no one saw it because Dragoneer is dead.

FurAffinity would have therefore missed its ~48 hour dispute window.

By intentionally delaying their response, Network Solutions would presumably be granting the attackers the same ~48 hour dispute window they grant anyone else.

As of right now I see no evidence in Certificate Transparency ( https://ui.ctsearch.entrust.com/ui/ctsearchui ) that any new *.furaffinity.net certs were minted.

So, I don't think the attackers have successfully impersonated any actual FA site yet. (They have broken the link a bunch of times, but that's _failed_ impersonation.)

EDIT: I take it back, there's this dubious-looking cert: https://crt.sh/?id=14214084757

Entrust Certificate Search - Entrust, Inc.

Luffy asserts: the FurAffinity twitter is now compromised.

I still feel bad about that cert I identified, so I think it's possible that if the website reopens, it could be a phishing attempt.

All existing logins were closed out. Don't re-login until FA's _Discord_ says so (I will mirror that when it happens)

This tweet just appeared, presumably from the attacker:
WE. 🀜. WANT. 🀜. FURRY. 🀜. NFTS. 🀜.
Based on RTs -- out with Fender. In with, apparently, this AI generated cryptocurrency fox?
Felix just deleted all his tweets because he's a _coward_
Felix is apparently suspended now. New link goes to this crypto scam.

Update: they shock therapied Dragoneer back from the dead so his unliving corpse could scam you.

Horrifying. Kinda hot. Mostly horrifying.

They appear to have deleted the crypto tweets. Not sure why. I'm sure they've done this more than once and therefore have good reasons to.
Oh, they're mad.
They haven't stopped posting, BTW, it's just content that I would never boost in my life even to make fun of it.
@pyrex wow, that's fucking vile.
@pyrex
It'd be kinda funny if this wasn't such a horrifying security fuckup.
@pyrex Not just mad, coping and seething.
It would be mildly funny watching them throw a temper tantrum if it wasn't for the sheer inconvenience they were causing with all this.

@gatrnerd

I don't understand why they're mad!! They got what they wanted!

@pyrex They're probably mad because everyone's beating their ass in the replies, as well as the fact no one is buying their shitty crypto scam.
@pyrex God this sure reveals the kind of people that hacked (let's be honest, probably just found out the password and found they're shared everywhere) the accounts and registrar though.
@pyrex Pretty much the same reaction as discord scammers when you don't fall for their scam. They get pissed and go scorched earth and call you all kinds of names then hang up the phone. It's so sad lmao
@pyrex i'm pretty sure that crypto account got mass reported to the point it caused an automatic suspension, from my understanding of how this could happen so quickly
@pyrex sheesh this is a shitshow, i hope they can get out of this
@pyrex I wonder what the audience intersection is for FA and Solana
@pyrex And there's the crypto grift showing up
@pyrex Thank you for the updates! Guess I'll wait with visiting FA for now. I'll also keep distance from judging either party early on, FA has a not so great track record.
@pyrex Oh my god, people are still using Network Solutions? And I thought it was enough of a struggle trying to get people off of GoDaddy...
@pyrex Tbh when I worked for Hostgator back in 2012 to 2014, Network Solutions really smacked to me as having big corporate energy that could screw customers around with asinine support because they could get away with it.

@pyrex hopefully FA has insurance to cover this because FA is likely going to get sued for damages.

Especially since it looks like whoever hijacked the domain has set it up to redirect to the shop to phish for credentials

@pyrex how could that happen? did someone get hold of their Cloudflare credentials?

@me @pyrex Network Solutions

bringing you such hits as

Important: β€―As part of our continuous security updates, we have temporarily turned off the 2-Step Verification feature. If you have enabled 2-Step Verification and would like to disable it, follow the steps provided below. Please note that once you disable 2-Step Verification, you will not be able to turn it back on.Source

@miawgogo @me @pyrex
Network Solutions is ass. Kinda surprised they used that of all things considering how big the site is.
@dushman @miawgogo @me @pyrex considering how old of a company network solutions is, i wouldn't be surprised if that was where the domain was registered in the early days and nobody ever bothered to change it because you usually don't think about the domain registrar much after registering

network solutions truly seems like a D tier company though (most domain registrars aren't that great either tbf)
@delta @miawgogo @me @pyrex
I usually recommend 1984, gandi or porkbun. Had a p good experience with those. Network Solutions is absolute shit tier in comparison.
@pyrex
It's DNS, it's *always* DNS
@Hiro
@Enalys @pyrex @Hiro don't blame DNS (despite the meme) for people not using 2FA and domain lock and not properly securing their stuff. Not the first time for FurAffinity either.

@basisbit @Enalys @pyrex @Hiro I dont think they can, given their registrar is network solutions with this giga brain idea

Important: β€―As part of our continuous security updates, we have temporarily turned off the 2-Step Verification feature. If you have enabled 2-Step Verification and would like to disable it, follow the steps provided below. Please note that once you disable 2-Step Verification, you will not be able to turn it back on.

@Enalys @pyrex @Hiro one of the third parties my company used for polls got DNS hijacked once, and made our site look like it had been defaced (it hasn't) so I know what this is like.

The worst part though is that you can't control how long it takes for some servers to read the DNS updates. So even if the admins fix the issue, it may take way longer for the DNS change to propagate everywhere 😭

@pyrex FA will never run smoothly, ever. Problem wasn't just Dragoneer but the whole damn team.
@pyrex Do the hijackers have access to the old SSL certificate?
@pyrex
I guess my question is, would a direct IP address bypass this issue, (if so, what is FA's,) or is it something deeper than that?
@pyrex Oeff. Well good to know. Hope they will be able to fix it!