SECURITY WARNING — Real WordPress Hack Story — Crypto Payments Stolen

ItsMeFox

Elite Member
Jr. VIP
Joined
Aug 20, 2015
Messages
1,874
Reaction score
710
Hey everyone — I’m posting this because I really don’t want to see anyone else lose their money the way I almost did.


I just went through a real WordPress hack on my WooCommerce store — the hacker targeted my crypto payment wallets and tried to silently steal my payments.


I’m sharing exactly what happened, how they did it, and how I fixed it — so YOU can take action now and protect your site and your money too.




REAL WORDPRESS HACK STORY — Crypto Payments Theft Attempt
Here’s exactly what happened...




✅ How they entered:
➡️ Brute force on admin account (weak password — my mistake).
➡️ They used xmlrpc.php (which was OPEN — I didn’t know it was dangerous).
➡️ They logged in as admin.




✅ What they did after entering:
➡️ No deface, no obvious malware.
➡️ They silently replaced my crypto wallets inside my MyCryptoCheckout plugin.
➡️ If I hadn’t caught it → ALL my crypto payments would have gone to them.




✅ How I caught it:
➡️ Wordfence alert — Admin login from strange IP. (( @TheMarquis Thank you bro for installing this plugin to me 2 years ago ))
➡️ Full manual check → found a hidden backdoor file + changed wallets.




✅ How I fixed it:
✔️ Blocked xmlrpc.php — very important!
✔️ Changed all admin passwords + added 2FA.
✔️ Cleaned backdoor + malware.
✔️ Restored MY crypto wallets.
✔️ Now monitoring daily.




✅ Lessons for you — PLEASE DO THIS NOW:


⚠️ Block xmlrpc.php → don’t leave this open!
⚠️ CHECK your crypto payment plugin — verify YOUR wallets.
⚠️ Don’t rely only on Wordfence — manual checks are key.
⚠️ Add 2FA to all admin accounts.
⚠️ Monitor admin logins — daily.




I was lucky to catch it in time — but many will not.


Please take a few minutes today to check your site — it could save you a LOT of money.



Stay safe — hope this helps someone here!


Huge thanks to ChatGPT — not only for helping me write this post, but also for walking me through every step of cleaning my hacked site.
This time... AI really saved my wallet! =))
 
➡️ Wordfence alert — Admin login from strange IP. (( @TheMarquis Thank you bro for installing this plugin to me 2 years ago ))
Thanks for quoting me. I hope your site and assets are safe now :cool: :cool:
 
Damn, that’s brutal. These hacks are getting smarter—especially when crypto’s involved. I’d definitely check for any sketchy plugins or code injections, and maybe run a full scan with something like Wordfence. If you’ve got a clean backup, might be safest to roll back and lock everything down tight.
 
Back
Top