us

216.73.216.136

Hacker steals $250K by exploiting Bitcoin exchange Bisq

hacker

A hacker identified a significant software flaw on the decentralized Bitcoin exchange, Bisq, to steal more than $250,000 worth of cryptocurrency from users.

The exchange, which permits users to trade cryptocurrency anonymously, unexpectedly disabled trading late Tuesday night after it highlighted “a critical security vulnerability.” The exchange did not immediately release any information regarding the nature of the breach or whether user funds were secure. But 18 hours after it stopped the exchange, Bisq claimed it took the “unprecedented” step after locating an attacker who had identified a loophole in the software was stealing cryptocurrency from other users.

According to CoinDesk, Bisq officials stated, “About 24 hours ago, we discovered that an attacker was able to exploit a flaw in the Bisq trade protocol, targeting individual trades in order to steal trading capital. We are aware of approximately 3 BTC and 4,000 XMR stolen from 7 different victims. This is the situation as we know it so far.” Cryptocurrency worth $22,000 of Bitcoin (BTC) and $230,000 worth of Monero (XMR) were stolen. 

To conduct the thefts, the attacker was able to set other users’ default fallback address – the destination to which crypto is sent to if a trade fails – to his own. Posing himself as a seller, he would initiate an exchange with a buyer and simply wait for the time limit to run out. Rather than going to the legitimate owner, the digital assets arrived with the attacker, along with the buyer’s payment and security deposit too. The flaw was a result of a new update to the trading protocol, which was designed to improve decentralization and remove trusted third parties from the platform.

Bisq was able to manage the defect by 12:00 UTC Wednesday and informed CoinDesk that it has resumed its trading. Bisq allows each user to act as a node since the platform is based on a distributed network. In most instances of an exchange hack, the attacker can be knocked off the exchange for good. However, that is not the case with Bisq. One of the DEX’s associated developers told CoinDesk that although the flaw was managed, no steps were taken to prevent the attacker – whose identity is unknown – from accessing and trading on the platform again.

“Anyone can use Bisq, there is no censorship,” the developer said. “Just like anyone can use bitcoin, there is no way to ban someone from bitcoin.”

Related Posts

News

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Explore More

News

California enacts law requiring age input on devices and app stores from 2027

California enacts law requiring age input on devices and app stores from 2027

Explore More

News

Google to Block Access to Adult Apps for Under-18s in Singapore

Google to Block Access to Adult Apps for Under-18s in Singapore

Explore More

News

Malaysia to push mandatory ID checks on social media to curb online scams

Malaysia to push mandatory ID checks on social media to curb online scams

Explore More

News

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Explore More

News

Brazil enacts new law to regulate children’s use of social media and digital platforms

Brazil enacts new law to regulate children’s use of social media and digital platforms

Explore More

News

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

Explore More

News

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Explore More

News

California enacts law requiring age input on devices and app stores from 2027

California enacts law requiring age input on devices and app stores from 2027

Explore More

News

Google to Block Access to Adult Apps for Under-18s in Singapore

Google to Block Access to Adult Apps for Under-18s in Singapore

Explore More

News

Malaysia to push mandatory ID checks on social media to curb online scams

Malaysia to push mandatory ID checks on social media to curb online scams

Explore More

News

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Explore More

News

Brazil enacts new law to regulate children’s use of social media and digital platforms

Brazil enacts new law to regulate children’s use of social media and digital platforms

Explore More

News

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

Explore More

Take the next steps to better security.

Contact us

Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

Contact us

Request demo

Get free access to our platform and try our products today.

Get started