Abstract
Bitcoin is gaining traction as an alternative store of value. Its market capitalization transcends all other cryptocurrencies in the market. But its high monetary value also makes it an attractive target to cyber criminal actors. Hacking campaigns usually target the weakest points in an ecosystem. In Bitcoin, these are currently the exchange platforms. As each exchange breach potentially decreases Bitcoin's market value by billions, it is a threat not only to direct victims, but to everyone owning Bitcoin. Based on an extensive analysis of 36 breaches of Bitcoin exchanges, we show the attack patterns used to exploit Bitcoin exchange platforms using an industry standard for reporting intelligence on cyber security breaches. Based on this we are able to provide an overview of the most common attack vectors, showing that all except three hacks were possible due to relatively lax security. We also show that while the security regimen of Bitcoin exchanges is not on par with other financial service providers, the use of stolen credentials, which does not require any hacking, is decreasing. We also show that the amount of BTC taken during a breach is decreasing, as well as the exchanges that terminate after being breached. With exchanges being targeted by nation-state hacking groups, security needs to be a first concern.
Original language | English |
---|---|
Title of host publication | 2020 IEEE International Conference on Blockchain and Cryptocurrency (ICBC) |
Publisher | IEEE |
Pages | 1-9 |
Number of pages | 9 |
ISBN (Electronic) | 978-1-7281-6680-3 |
ISBN (Print) | 978-1-7281-6681-0 |
DOIs | |
Publication status | Published - 2020 |
Event | 2nd IEEE International Conference on Blockchain and Cryptocurrency, ICBC 2020 - Virtual, Online, Canada Duration: 2 May 2020 → 6 May 2020 |
Conference
Conference | 2nd IEEE International Conference on Blockchain and Cryptocurrency, ICBC 2020 |
---|---|
Country/Territory | Canada |
City | Virtual, Online |
Period | 2/05/20 → 6/05/20 |
Keywords
- attacks
- bitcoin
- cryptocurrency exchanges
- cyber security
- cyber threat intelligence