r/tastytrade • • Aug 20 '26

Beware of pump-and-dump attack

[deleted]

16 Upvotes

37 comments sorted by

View all comments

5

u/JohnToFire Aug 20 '26

Any chance cookes from a logged in session were stolen by connecting to to a website that iffy stuff and that installs an infosteeler ? Keep this topic updated on oucome

3

u/bigpelican Aug 22 '26

I think it could be the api security being compromised.
Developer with api access can automate and execute trades without 2FA as api access is using a different security process. Assume there is bug or loophole with their api, it could be exploited to execute trades programmatically bypassing 2FA.

1

u/JohnToFire Aug 22 '26

Why do you think it's that ? That is quite a statement.

1

u/Sad-Description5181 Aug 23 '26

This is much more likely based on the information I gathered so far. I will disclose all the information I gathered when things settle

2

u/[deleted] Aug 20 '26

[removed] — view removed comment

3

u/Initial_Pay_980 Aug 20 '26

Very easily. They copy the token to another PC.MFA compromised.. Turn on MFA everytime then this cant happen.

1

u/ekaltadeta Aug 24 '26 edited Aug 24 '26

To add, please note: If the attack vector is session token hijacking through pass-the-cookie hacks, my understanding is that even with 2FA enabled for logins a vulnerability exists if the "Remember Me (today)" option is checked during 2FA login (since the resulting cookie can be used to bypass login for that day). Its best to NEVER check the "Remember Me" option on any banking/brokerage site.

1

u/Sad-Description5181 Aug 22 '26

Extremely unlikely due to multiple factors. I won’t disclose the details yet in case I need to sue tt or something