Hacker News new | ask | show | jobs
by ryanackley 2574 days ago
I'm genuinely curious. What type of fraud or abuse are you trying to prevent? Maybe cover that in the postmortem.
1 comments

If your DO (or other cloud provider) credentials are compromised, it's usually a matter of seconds before someone fires up the largest possible number of instances to start crypto mining.
Yup. LeonM, you are correct. In this case that was the cryptocurrency mining detector that was triggered. More details in the postmortem.