Now I feel left out ![]()
I’ve worked with computers for over 35 years, I’m very careful and conscious of security, privacy, scams, etc. I keep somewhat up to date on the various little tricks and latest developments in technology, social engineering and just plain stupid behavior.
I have various features and system changed and disabled (like before even using a new modem to connect online, I change the admin password, I disable any remote admin features, limit and secure Wi-Fi, etc). I run secure and encrypted DNS look up, I even have to login, with a password, to my desktop PC (which also has any guest, etc acounts removed/disabled).
I keep Windows updates current, anti-virus is updated at least once a day, I’m careful with what software I download and where I download it from. Needless to say my web browser hasn’t been used without UBlock Origin and NoScript for years (with the default to block everything unless I unblock, yes that gets very annoying on any new install, since it means nothing works at first).
For decades I’ve always had some sort of off-line backups, so in the event of any hardware failure (not happened till it was old and largely no longer in use anyway) or some sort of malware attack (also never happened so far), then I can just nuke the whole system and still have my data.
I’ve gone so far in the past that I won’t just throw out an old hard drive, I will take it to the shed and totally destroy it. Crack it open and half smash those platters, just to make sure that no one can pull any of my personal data off it.
Having said all that, with the level of attacks nowdays, the amount of data leaks from companies that one just have to deal with in some cases, yet still couldn’t secure ones personal info. The growing ease and improved accuracy of AI generated scams, etc.
I am personally getting to the point that I’m starting to think my paranoia level isn’t high enough.
They were links, not files. They hired more developers a while ago so hopefully we’ll see more improvements to the site soon.
Another good option if it is necessary to download a file from a potential customer (link or attachment), is to speak to them first, to gauge if they actually know anything about Blender. I suspect a scammer wouldn’t even respond, and almost certainly wouldn’t be able to describe anything about Blender.
Blender Market have also implemented human verification tests prior to sending messages now, so it will most likely be a human, and not an AI that can respond with a thesis on path tracing.
Ooo, so rather then the Turing Test for AI, maybe we need a standard Blender test…
- Who or what is a Suzanne?
- Name three uses for the Cursor.
- Is Ton a unit of mass, a Person or a Crypto coin?
Ha, well I’d try and not be that obvious to avoid offending legit enquirers ![]()
These tests can easily be cheesed though because all of the answers can already be found in many places online.
Random questions and a retry limit might ameliorate this, but research of Blender trivia is easy and VPNs exist.
and
- Is it ‘vertices’ or ‘vertexes’?
- Which came first, the Subdivision Surface Modifier or the Subsurf Modifier?
- What mouse button is the Blender Program known for?
This is pretty important legally and makes sure that the customer’s privacy is protected. As much as it would be nice to have all those emails, not everyone will use that well. But when you use the Superhive inbox, it says right at the top if and when the person purchased the product.
![]()
OK. I haven’t received that yet so I wouldn’t have known. Thanks.
Also, I would like to point out that this pinned post has an incorrect title. No spam email has been sent from a Blender Market seller. Rather it is the sellers who have received the spam. While that’s still obviously bad, market customers are not affected. I see this causing a lot of misunderstandings in the comments.
in that case, you could try firewalling the python exe out…
can be found under:
Blender 4.4\4.4\python\bin
Yes that needs changing, because I don’t believe it’s possible for a non-creator to be contacted via the inbox by anyone other than a seller they’ve initiated a conversation with.
Good catch, updated
They are attacking CGTrader website as well it seems
This attack is not exclusive to SuperHive
Hey folks, just chiming in here during a brief break to say that we all really appreciate the community vigilance. Spam prevention is a constant game of whack-a-mole. This one is different in that it’s absolutely targeted at Creators on Superhive. We’re suspicious it’s also targeting CG Trader sellers but I can’t confirm that. We’re talking with the team at CG Trader about it, though.
We’re also working to add more preventative tools right now to catch these kinds of messages before they’re sent.
I can also say that this is absolutely automated and the scammer is actively adapting their methods. Just yesterday we deployed much better email verification tools for all Superhive accounts and the scammer has already updated their system to work around this. They’re using new emails every time yet clearly monitoring those emails in order to work through confirmation processes.
Thanks for your work on BlenderMarket generally and your vigilance here, the proactive communication from SuperHive has been very much appreciated during this incident
It probably is targeted specifically at Blender users, because it’s an easy access point to automatically run python on a users machine, even if they don’t have python installed. Perhaps a good solution would be for the Blender Devs to make it mandatory to reconfirm if you want scripts to run every time a previously unopened blend file is opened. That way it would be less of an inviting target to hackers.
On the plus side, now that it’s become obvious blender is being targeted, users will be terrified of getting torrent site versions, so creators might get a little extra bump towards their ongoing product maintenance and customer support.
@filedescriptor thoughts?
That is correct @Michael_Campbell. Only creators may be contacted. There is no public capability for user to user messaging.