Seems like it's similar to the attack reported in this other HN post: https://news.ycombinator.com/item?id=48409869