From Hodl to Heist

Analysis of Cyber Security Threats to Bitcoin Exchanges

Conference Paper (2020)
Author(s)

Kris Oosthoek (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Christian Doerr (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1109/ICBC48266.2020.9169412 Final published version
More Info
expand_more
Publication Year
2020
Language
English
Research Group
Cyber Security
Article number
9169412
Pages (from-to)
1-9
ISBN (print)
978-1-7281-6681-0
ISBN (electronic)
978-1-7281-6680-3
Event
2nd IEEE International Conference on Blockchain and Cryptocurrency, ICBC 2020 (2020-05-02 - 2020-05-06), Virtual, Online, Canada
Downloads counter
200

Abstract

Bitcoin is gaining traction as an alternative store of value. Its market capitalization transcends all other cryptocurrencies in the market. But its high monetary value also makes it an attractive target to cyber criminal actors. Hacking campaigns usually target the weakest points in an ecosystem. In Bitcoin, these are currently the exchange platforms. As each exchange breach potentially decreases Bitcoin's market value by billions, it is a threat not only to direct victims, but to everyone owning Bitcoin. Based on an extensive analysis of 36 breaches of Bitcoin exchanges, we show the attack patterns used to exploit Bitcoin exchange platforms using an industry standard for reporting intelligence on cyber security breaches. Based on this we are able to provide an overview of the most common attack vectors, showing that all except three hacks were possible due to relatively lax security. We also show that while the security regimen of Bitcoin exchanges is not on par with other financial service providers, the use of stolen credentials, which does not require any hacking, is decreasing. We also show that the amount of BTC taken during a breach is decreasing, as well as the exchanges that terminate after being breached. With exchanges being targeted by nation-state hacking groups, security needs to be a first concern.