CSIDB logo
Incident

BitGo

Incident posture

Attack window
Jun 2016
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-10 00:00

Linked entities

Victim
BitGo
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A distributed denial-of-service (DDoS) attack targeted a prominent Bitcoin wallet provider, causing complete server downtime for approximately four to five hours and disrupting its transaction processing capabilities. The incident impacted numerous integrated platforms relying on the company's API for near-instant Bitcoin transactions, including major exchanges and payment services, leading to unresolved transaction issues across partner ecosystems. Service restoration delays prompted the provider to advise customers against initiating transactions until full operations resumed. The attack highlighted broader security vulnerabilities within cryptocurrency infrastructure, where DDoS incidents against payment portals are frequently exploited for financial gain alongside other prevalent threats like theft and data breaches.

Motives

Detailed motive labels are available to members.

6 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the afternoon of Saturday, June 4, 2016, BitGo—a prominent Bitcoin wallet service marketed as the industry’s most secure platform—experienced a massive distributed denial-of-service (DDoS) attack. The assault persisted for four to five hours, completely overwhelming BitGo’s servers and rendering its services inaccessible. The company acknowledged the incident publicly via Twitter approximately one hour after the attack began, issuing apologies to clients for the disruption. BitGo’s infrastructure was uniquely designed to enable near-instant Bitcoin transactions, a feature that distinguished it from competitors requiring hours for transaction validation. This capability had attracted integrations with major cryptocurrency exchanges and financial services, including Wirex, Bitstamp, Bitfinex, Unocoin, and Kraken, all of which relied on BitGo’s API to process real-time transactions for their users.

The immediate consequence of the DDoS attack was widespread operational paralysis across BitGo’s partner network. Companies integrated with BitGo’s API faced transaction processing failures, leaving them unable to fulfill their promised instant settlement services. Wirex, which had recently adopted BitGo to power its Bitcoin-based debit cards, proactively emailed customers advising them to halt transactions until BitGo restored functionality. The incident underscored the systemic risks posed by centralized dependencies within Bitcoin infrastructure, as a single point of failure disrupted multiple downstream services. While BitGo eventually resumed operations, the attack highlighted the profitability of DDoS campaigns targeting cryptocurrency platforms, with threat actors frequently offering such services for hire on dark web marketplaces. Broader industry vulnerabilities were also evident, as the article referenced prior security breaches at Gatecoin, Shapeshift, and other Bitcoin entities—though these were distinct incidents unrelated to the BitGo DDoS.

Sources

Sources available to members: 1 source.

CSIDB