• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

Chromecasts are hijacked by PewDiePie fans, exposing huge security flaw

News

Avatar for Fazeel Ashraf Fazeel Ashraf Follow Fazeel Ashraf on X Published: Jan 5, 2019 · 1:01 AM ET Updated: Jan 13, 2020 · 6:16 PM ET

Design contains Chromecast 3rd gen
Design by abdugeek | TechEngage
FacebookTweetPinLinkedInPrint
Forget printers getting hacked and informing users to subscribe to PewDiePie, its Chromecast’s turn. A couple of mischievous hackers have exploited thousands of Chromecast devices to promote Swedish YouTuber Felix “PewDiePie” Kjellberg’s channel. The hackers, known as “HackerGiraffe” and “j3ws3r” found a vulnerability in the router settings of smart devices hooked up to televisions. This vulnerability made Chromecasts and Google Homes publicly visible on the Internet. HackerGiraffe and  j3ws3r were able to exploit this to broadcast videos on connected televisions. The hackers had discovered 72,341 exposed devices at the time of writing. The hack is known as “CastHack” and the CastHack website is keeping the Internet updated on its success.
Pewdiepie Hack
via: TheHackerGiraffe
CastHack displays a message instructing viewers to subscribe to PewDiePie and KeemStar, another YouTuber who covers feuds and gossip news. The website also had links to the hackers’ personal Twitter accounts. It also provides information about the total number of devices renamed as a result of the hack as well as the “Total devices forced to play video,” “Total Google Homes devices,” and “Total SmartTVs/Chromecast devices” that were breached. The hackers exploited the routers’ Universal Plug and Play (UPnP) option. Google has admitted to the hacks. Chromecast Hack The website also had an FAQ section featuring questions like “What is going on?” “What information is being leaked?” and “What can hackers do with this?” HackerGiraffe and j3ws3r  provided information to the people they hacked and gave advice about how they can best protect their devices in the future. The answer: “Disable UPnP on your router, and if you’re port forwarding ports 8008/8443/8009 then STOP forwarding them.” The hackers informed those affected that they were able to wirelessly play media of their choice on users’ devices, erase Wi-Fi network setting, rename devices, and connect other devices wirelessly with Chromecast and Google Home. HackerGiraffe clarified that their intention wasn’t to cause real harm or steal data but to alert Google and its customers to the vulnerability. HackerGiraffe further added that the attack doesn’t gather or save any information from affected devices. Google told The Verge that many users reported: “an unauthorized video played on their TVs via a Chromecast device.” The company confirmed the hack was due to router settings. Both HackerGiraffe and Google told The Verge the best way to fix the issue is by turning off the Universal Plug and Play (UPnP) option on their routers. Since the hacked seemed not to have any malicious purpose, it might be a blessing in disguise for some users who are now aware of a security loophole. This will prevent malicious actors from using it for much more nefarious deeds. Since HackerGiraffe gave a solution to the security bug, some may even find humor in the situation. This isn’t the first time the hackers backed Kjellberg and promoted his YouTube channel. The duo admitted that they were behind the printer hacks that told users to subscribe to PewDiePie, back in November. HackerGirrafe gained access to close to 50,000 unsuspecting printers worldwide to promote PewDiePie and help him retain his position as the most subscribed YouTuber. At the time, he was facing tough competition from Indian music label T-Series’ YouTube channel. Just last month, PewDiePie was at the center of another controversial hack orchestrated by his fans. This time they targeted The Wall Street Journal, which posted a story about Kjellberg being anti-semitic after he had paid two strangers to hold up a sign reading “Death to all Jews” in a publicity stunt that lead Disney to cut all ties to the YouTube star. In response to the critical story, hackers replaced sponsored content on the website with calls for the newspaper to apologize for taking the stunt out of context. Kjellberg is the most subscribed YouTuber, currently having a whopping 79 million subscribers. The Swedish star has successfully maintained his position as the most subscribed YouTuber since 2013. It is highly impressive how many subscribers he gained after his “war” against the Indian music conglomerate, even adding a mind-blowing half million subscribers in one day back in October. The YouTuber himself had nothing to do with any of the hacks as far as we know. They were all conducted by members of his enormous fan base. It’s likely that the media will find a way to blame PewDiePie. He has made mistakes in the past, including his “all Jews must die” joke and saying the N-word during a live stream, for which he later apologized. It will be interesting to see how this whole hacking fiasco turns out. It will be in everyone’s interest, PewDiePie’s included, to prevent further hacks in the future.

Related reading

  • Israeli spyware, Pegasus, used to attack journalists, activists, government officials' phones
  • Twitter security flaw enables hackers access to UK accounts
  • Solving common PC security threats with Outbyte AVarmor
  • Cybersecurity Awareness Tips for Employees
Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy, Tech News & Analysis Tagged With: Chromecast, Google, Security, Security Breach

Related Stories

  • Googlebook Shows How Android 17 And Gemini Intelligence Could Reshape Google’S Ecosystem

    Googlebook Shows How Android 17 and Gemini Intelligence Could Reshape Google’s Ecosystem

    AIMay 16, 2026

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • Akamai’s $11.6 Billion Anthropic Cloud Deal: Costs, Timeline And Cpu Strategy

    Akamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategy

    Tech News & AnalysisSep 27, 2026

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
FacebookTweetPinLinkedInPrint
Avatar for Fazeel Ashraf

Fazeel Ashraf

Tech & Gaming Editor

Fazeel Ashraf is the Tech and Gaming Editor at TechEngage, covering global tech news, social media, gaming releases, and cybersecurity. An IT graduate of the National University of Sciences and Technology, he has written more than 230 articles across the site's news and features coverage.

Joined TechEngage September 2018First article on TechEngage September 2018

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Ethernet Adapters Techengage |
    Computing & HardwareBest USB-C Ethernet Adapters for MacBook and WindowsOct 8, 2026
  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Uk Twitter Accounts Hacked Abdugeek Jpg |
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

Download our apps

TechEngage app coming soon on App Store

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details