Weakaura Scamming

#1 - Jan. 19, 2016, 12:49 a.m.
Blizzard Post
Found this on the US forums thought it might be useful for everyone here to know as well.

Well, the thread that was on front page last night isn't there now, so I want to get word out to as many as people as possible. Scamming with WeakAuras is a scam once again, and if you don't know how it works, it's not as difficult as you might think.

WeakAuras is an add-on that can execute certain game that the API allows them to, and is widely used for raiding. Currently, that code is actually allowing malicious players to scam people - they will link you a WeakAuras script in-game - you're not downloading anything from any external site. This script will force you to trade the scammer all of your gold if a trade is initiated, regardless whether it is you or the scammer who initiates the trade. You won't see a trade screen. You won't get to click a button to confirm it. All you will hear is the sound of coins, and your gold will be gone.

Don't trust a WeakAuras script from ANYONE that you do not trust explicitly - even if it's some guy in trade chat who just wants someone to help him with his WeakAuras - that's a very common way to scam people. I want to get word out to as many people as possible - tell your guildies - tell your friends - I don't want to see anybody get scammed by this - this is something that so many people don't even realise is possible - so the more awareness that exists for this, the better.
Forum Avatar
Community Manager
#10 - Jan. 20, 2016, 10:43 a.m.
Blizzard Post
Thank you for bringing this to our attention!

An update to WeakAuras was released during the night which should have resolved this issue. However, please always remaing vigilant when importing any AddOn settings or scripts from players you do not know.

We are also working on preventing this type of situation in the future by adding an extra step of security for all gold transfers.

In general, please avoid discussing or theorizing, on the forums, how an exploit works. This can lead to other players "testing" the exploit which can lead to more players falling victim. If you want to post an exploit report on the forums you can post the details and then edit your post to hide them. We can check the edit history so we will be able to see your report. That being said, the best way of reporting any exploit is sending it to our hacks team via the following form: http://eu.blizzard.com/en-gb/submit/hacks.html