us

216.73.217.135

Back
News

Hacker steals $250K by exploiting Bitcoin exchange Bisq

Hacker steals $250K by exploiting Bitcoin exchange Bisq
R Richard M. APRIL 13, 2020 1 minute read

A hacker identified a significant software flaw on the decentralized Bitcoin exchange, Bisq, to steal more than $250,000 worth of cryptocurrency from users.

The exchange, which permits users to trade cryptocurrency anonymously, unexpectedly disabled trading late Tuesday night after it highlighted “a critical security vulnerability.” The exchange did not immediately release any information regarding the nature of the breach or whether user funds were secure. But 18 hours after it stopped the exchange, Bisq claimed it took the “unprecedented” step after locating an attacker who had identified a loophole in the software was stealing cryptocurrency from other users.

According to CoinDesk, Bisq officials stated, “About 24 hours ago, we discovered that an attacker was able to exploit a flaw in the Bisq trade protocol, targeting individual trades in order to steal trading capital. We are aware of approximately 3 BTC and 4,000 XMR stolen from 7 different victims. This is the situation as we know it so far.” Cryptocurrency worth $22,000 of Bitcoin (BTC) and $230,000 worth of Monero (XMR) were stolen. 

To conduct the thefts, the attacker was able to set other users’ default fallback address – the destination to which crypto is sent to if a trade fails – to his own. Posing himself as a seller, he would initiate an exchange with a buyer and simply wait for the time limit to run out. Rather than going to the legitimate owner, the digital assets arrived with the attacker, along with the buyer’s payment and security deposit too. The flaw was a result of a new update to the trading protocol, which was designed to improve decentralization and remove trusted third parties from the platform.

Bisq was able to manage the defect by 12:00 UTC Wednesday and informed CoinDesk that it has resumed its trading. Bisq allows each user to act as a node since the platform is based on a distributed network. In most instances of an exchange hack, the attacker can be knocked off the exchange for good. However, that is not the case with Bisq. One of the DEX’s associated developers told CoinDesk that although the flaw was managed, no steps were taken to prevent the attacker – whose identity is unknown – from accessing and trading on the platform again.

“Anyone can use Bisq, there is no censorship,” the developer said. “Just like anyone can use bitcoin, there is no way to ban someone from bitcoin.”

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.