Menu
Browse

Cyber Incident Victim: Bitfinex

Date:

Dec 2017

Location:

Hong Kong

Summary

A major cryptocurrency exchange experienced significant operational disruptions due to a series of distributed denial-of-service (DDoS) attacks, forcing temporary shutdowns and degrading API functionality. This marked the platform's second such incident within a week, following earlier prolonged server targeting. Concurrent DDoS activity affected another prominent exchange, though potential connections between these events remained unconfirmed. Service restoration occurred gradually with performance limitations, though no customer fund losses resulted from these availability-focused attacks, distinguishing them from contemporaneous breaches involving direct cryptocurrency theft at other firms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 12, 2017, Bitfinex, a Hong Kong-based cryptocurrency exchange, experienced severe operational disruptions due to sustained distributed denial-of-service (DDoS) attacks. The attacks overwhelmed the platform’s infrastructure, forcing a temporary shutdown of services. Bitfinex confirmed the incident via its official Twitter account, stating it was under "heavy DDOS" and that its application programming interface (API) was non-functional. Technical teams initiated immediate mitigation efforts to restore access. This marked the second major DDoS incident targeting Bitfinex within a week, following an earlier attack that began on December 4 and persisted intermittently until December 7. The exchange’s service status page indicated gradual but partial recovery, with some functionalities returning at reduced performance levels while mitigation work continued.

Cyber Incident Image

The attacks coincided with a period of heightened cryptocurrency market activity, as Bitcoin’s value reached record highs. While DDoS incidents typically disrupt service availability without compromising user funds—unlike the contemporaneous $70 million Bitcoin theft from Slovenia’s NiceHash platform—the operational impact on Bitfinex was significant. Notably, another exchange, Coinbase, reported similar DDoS disruptions on the same day, though no confirmed link between the two incidents was established. Bitfinex’s public communications emphasized ongoing efforts to stabilize services but did not disclose technical specifics of the attacks or the exact scope of affected systems beyond the API outage. The recurrence of attacks within a short timeframe highlighted persistent vulnerabilities in the exchange’s infrastructure amid escalating threats to cryptocurrency platforms.

Sources
Sources available to members
1 source