On July 24, 2026, a disturbing post appeared on Hacker News. The title was direct: “Tell HN: Namecheap gave my account to an unverified third party.”
The poster, using the pseudonym Thrashed, said he had been a Namecheap customer for 13 years. During that time, he had been holding a .com domain on behalf of a university club — the domain was registered in his personal name, with his personal address and phone number.
It was a simple act of goodwill: student clubs have high turnover, and if someone forgot to renew the domain, it would get snatched up by a squatter. So he’d been quietly paying the renewal fees every year.
Then the club’s leadership changed.
The new club officer wanted to modify the domain’s DNS settings but had no idea who was managing it. They looked up the domain, found it was on Namecheap, and initiated a password reset through the “forgot password” flow. Thrashed received the reset email and immediately filed a support ticket: “I didn’t initiate this.”
Namecheap’s customer service did call him back — they verified he was the person who submitted the ticket, then sent a templated email suggesting he “check his antivirus software.”
So far, the story was routine.
But what happened next is the part that sends chills down your spine.
Thrashed’s post on Hacker News, which received 301 points and 105 comments. At time of writing, numerous users reported migrating their domains away from Namecheap.
One Phone Call. One Account.
The new club officer didn’t give up. They called Namecheap’s customer service line directly.
On the phone, they convinced the客服 agent that the domain — while registered in someone else’s name — actually belonged to their club.
Then Namecheap did something that left everyone in the tech community stunned:
Without any call-back verification. Without any additional identity check. Simply because “the caller sounded convincing,” Namecheap changed Thrashed’s account password AND updated the associated email address.
Yes, you read that correctly: they changed the password and the email in one shot.
Do you see what that means? Even if Thrashed knew the new password, he couldn’t log in — the password reset link would go to the new email address. His account was completely taken from his hands. And Namecheap never once called him to confirm.
“Namecheap clearly has the ability to pick up the phone and call me (they’d done it before),” Thrashed wrote. “But when someone calls them and says ‘I really want this account,’ they can’t be bothered to verify?”
He added a line that sent a chill through anyone reading: “I don’t even want to call this social engineering. This is obviously a massive security hole — any third party can take over your Namecheap account just by talking nicely.”
A Support System More Gullible Than a Scammer
Let’s break down exactly what happened here.
Namecheap’s security mechanism failed at the most critical link in the chain.
First, when Thrashed submitted the password reset ticket, Namecheap did call him back to verify. This proves they have a call-back verification process.
But when the “attacker” (in this case, a club officer with no malicious intent) called them, Namecheap had no process requiring the agent to call back the number on file for verification. The agent simply accepted what the caller said and performed the operation.
This reveals a systemic flaw: Namecheap’s security verification is one-directional. It verifies who submitted a ticket, but not who calls them.
Namecheap’s security is like a door with a lock on only one side:
- Pushing from the inside: requires verification (call-back confirmation)
- Pushing from the outside: no verification needed (anyone can talk their way in)
This asymmetric security design makes the entire defense system useless.
What’s even more disturbing is that Namecheap didn’t just change the password — they changed the associated email address too. This means even if the account had two-factor authentication (2FA) enabled, it wouldn’t have stopped this attack. Once someone controls the new email, they control the password reset flow. And 2FA actually becomes an obstacle for the legitimate owner trying to recover the account.
A commenter asked Thrashed whether he had 2FA enabled. He said yes — “but in this situation I’m not sure how much it would have helped.”
Why Your Domain Is Worth More Than Your Password
Let me explain something many casual users don’t fully grasp: your domain is worth far more than any single account password.
You might have dozens of online accounts — email, social media, banking, shopping — each protected by a password. If one gets compromised, the damage is limited to that platform. Change the password, call support, and you’ll probably get it back.
A domain is different.
Your domain is the master key to your entire digital identity. If you own example.com:
- All your email ([email protected]) depends on it
- Every website you run is controlled through it
- Every link anyone uses to find you goes through it
If someone takes your domain, they can:
- Redirect all your email to their own servers
- Use your email to reset passwords on every platform you use
- Point your website to a phishing page
- Sell your domain to the highest bidder
In other words, losing control of your domain ≈ losing your entire digital identity.
This is why domain registrars should have security standards higher than banks — but the reality is often the opposite.
Who’s Responsible? Three Broken Links in the Chain
Link 1: Inadequate Customer Service Training
Namecheap’s support agents appear to have received no training whatsoever on “account takeover prevention.” An agent was convinced by a complete stranger on the phone to change an account password and email address. This exposes a complete absence of standard operating procedures for handling third-party account takeover requests.
Any competent domain registrar should have an ironclad rule: any request to modify core account information (password, email) received by phone must be verified by calling back the registered phone number on the account.
That’s the most basic line of defense. Namecheap didn’t have it.
Link 2: Systemic Design Flaw
Thrashed noted that Namecheap’s password reset page allows reset requests using just the domain name — no username, no email, nothing that only the account owner would know. It’s like a safe that asks “don’t know the combination? Just tell us the safe’s serial number.”
Several commenters pointed out that Namecheap offers WHOIS privacy protection (which hides domain registration details), but that’s completely irrelevant here — the attacker didn’t need to look up WHOIS data. They just needed to know the domain name to initiate a reset.
This means Namecheap’s password reset logic is inherently insecure.
Link 3: The Private Equity Aftermath
Multiple commenters flagged an important piece of context: in September 2025, private equity firm CVC Capital Partners acquired a majority stake in Namecheap at a $1.5 billion valuation. The founder and CEO stepped down in December 2025.
The private equity playbook is simple: increase profits, cut costs. Security is a cost center. Cutting the security budget rarely causes problems immediately — until it does.
Why Ordinary Users Pay the Price
There’s a subtle and heartbreaking detail in this story: Thrashed was fundamentally a good guy. He held the domain for the club out of kindness, paid renewal fees out of his own pocket for years. He was even willing to transfer the domain to the new club leadership when asked. But Namecheap didn’t know any of that. In their system, Thrashed was a loyal customer who had paid his bills for 13 years. When someone called asking to take over the account, Namecheap chose to believe the caller.
One commenter put it bluntly: “Support agents in third-world countries don’t care who really owns the domain. They just want to close the call and get their five-star rating.”
This is the real core of the problem: when agents are measured on “resolution rate” and “call handling time” rather than “security,” satisfying the person on the phone becomes the only goal.
The Domain Exodus
At time of writing, Thrashed’s HN post had 301 points and 105 comments. The thread is filled with similar stories:
- One user said Namecheap erroneously suspended their domain due to a bug that enabled unsupported WHOIS privacy features
- Another said they lost their domain at Namecheap simply because they lost the phone with their 2FA app
- Several reported that Namecheap’s payment flow now forcibly redirects to third-party payment processor Link, requiring registration and SMS verification
Tons of users said they were migrating their domains. Cloudflare emerged as the most popular destination — it offers domain registration at cost ($10.46/year for .com) and has a stronger security reputation. Porkbun, NearlyFreeSpeech, and Dynadot were also mentioned frequently.
But there were also sobering counterpoints. One user cautioned: “Cloudflare has a restriction — you can’t change nameservers. You have to use Cloudflare’s own DNS. That means you’re giving up control.”
Another raised an even deeper issue: “We need a non-profit domain registrar so we don’t have to move every few years.”
The reality is that domain registration is a low-margin, high-responsibility business. Google shut down Google Domains (sold to Squarespace). Cloudflare treats it as an ecosystem accessory. The companies that actually focus on domain registration either get bought by private equity or have to raise prices to stay afloat.
The HN discussion thread, where numerous users reported similar security issues and began comparing migration options.
What You Can Actually Do
The purpose of this article isn’t to drag Namecheap through the mud — though it certainly deserves criticism. The bigger point is: your domain security cannot depend on your registrar’s goodwill.
Here are some steps you can take within the current system:
1. Don’t Hold Domains for Other People
If you’re managing a domain on behalf of someone else, formally transfer it as soon as possible. Holdership arrangements are legally ambiguous and security-wise fragile.
2. Enable Two-Factor Authentication
2FA is still your best defense against password compromise. Prefer hardware security keys or TOTP authenticator apps over SMS.
3. Use Registry Lock
Registry Lock is the strongest domain protection available. Any modification requires additional offline verification. For critical domains, it’s worth the cost.
4. Choose Registrars Based on Security Reputation
Look at their customer verification processes, security history, and attitude toward private equity acquisitions before signing up.
5. Use a Dedicated Email for Your Registrar Account
Don’t use a domain email to register your domain account. If the domain gets taken over, you’ll have no way to recover the account.
Epilogue
Thrashed eventually got in touch with the new club officer and they resolved the matter amicably. The domain was formally transferred to the club. “I was happy to give it to them anyway,” he said, “but Namecheap had no way of knowing that. As far as they were concerned, this was my personal account.”
That sentence captures the absurdity of the entire situation: a user who did everything right (paid his bills, renewed on time, enabled 2FA, filed a support ticket promptly) lost a 13-year-old account because of a single phone call from a third party.
This isn’t about social engineering. It isn’t about password strength. It isn’t about anything the user did wrong.
This is a systemic security failure — and the price was paid in user trust.
References:
- HN Discussion: Namecheap gave my account to an unverified third party (item?id=49028037)
- Namecheap Official Security Advice: Two-Factor Authentication and Account Protection
- Cloudflare Domain Registration Security Best Practices
- Namesilo Blog: Social Engineering Bypasses Domain Locks
- dn.org Report: 2026 Top 10 Domain Account Hijack Scams Analysis