CSIDB logo
Incident

LocalBitcoins

Incident posture

Attack window
Jan 2019
Location
Finland
Status
Historical
CIA posture
Available to members
Updated
2025-11-05 00:00

Linked entities

Victim
LocalBitcoins
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A security breach at LocalBitcoins resulted in the theft of approximately 7.95 bitcoins from six user accounts after attackers deployed a phishing scheme redirecting victims to a fraudulent login page to harvest credentials and two-factor authentication codes. The platform mitigated the incident by temporarily suspending its forum and transaction services, attributing the compromise to a vulnerability in third-party forum software before restoring operations following an investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around January 26, 2019, LocalBitcoins experienced a security breach involving unauthorized access to user accounts through a phishing campaign targeting its online forum. Attackers compromised the platform by redirecting users to a fraudulent login page designed to mimic the legitimate LocalBitcoins interface. This fake page harvested login credentials and two-factor authentication (2FA) one-time codes entered by unsuspecting users. The phishing mechanism operated through vulnerabilities in third-party software that powered LocalBitcoins' forum feature, though the specific software vendor was not disclosed. During the attack window, six user accounts were compromised, resulting in the theft of 7.95205862 bitcoins valued at approximately $28,200 based on contemporaneous exchange rates. The incident caused service disruptions as affected users reported unauthorized transactions and account access issues.

LocalBitcoins responded by immediately taking its forum offline to terminate the attack vector and temporarily suspended all platform transactions to prevent further fund movements. The company conducted forensic analysis to identify compromised accounts and confirmed the breach originated from the third-party forum infrastructure rather than LocalBitcoins' core trading systems. After securing the environment, LocalBitcoins restored trading functionality and published a post-mortem report detailing the incident scope and remediation steps. No evidence suggested broader compromise of wallet systems or non-forum-related platform components. The company advised users to enable 2FA as a protective measure while emphasizing that standard account logins remained secure following forum deactivation. Financial losses were confined to the six identified accounts, with no additional breaches reported after service restoration.

Sources

Sources available to members: 1 source.

CSIDB