Menu
Browse

Cyber Incident Victim: Voyager

Date:

Dec 2020

Location:

United States of America

Summary

A cryptocurrency brokerage platform experienced a cyberattack targeting its DNS configuration, prompting an immediate halt to trading and cancellation of all limit orders. The incident led to a temporary platform shutdown initially described as maintenance, with users subsequently logged out as a precaution and advised to reset passwords and enable two-factor authentication. While described as a "DNS threat," the attack was reportedly contained without compromising customer assets or cryptocurrency holdings, though operational disruptions occurred during the response. Trading functionality was restored after security measures were implemented, with the company emphasizing no successful fund exfiltration occurred during the intrusion.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 28, 2020, Voyager Digital LLC, a cryptocurrency brokerage platform managing $200 million in assets, abruptly halted trading and canceled all limit orders following a cyberattack targeting its DNS configuration. The company initially described the disruption as routine maintenance before disclosing the security incident. Voyager CEO Steve Ehrlich confirmed the platform was taken offline immediately after detecting the attempted intrusion to protect customer assets and information, emphasizing that no funds or cryptocurrency were compromised despite the operational shutdown. The attack occurred during a period of significant growth for the broker, which had reported a 40-fold increase in business over the preceding 12 months. Trading remained suspended for an unspecified duration while the company addressed the DNS-related threat, though technical specifics about the attack vector or perpetrators were not disclosed. Voyager maintained that the intrusion attempt was unsuccessful due to their rapid response, though the incident forced a complete suspension of core platform functionality.

Cyber Incident Image

Voyager restored service to its mobile application following the containment measures, requiring all users to log back into their accounts as a security precaution. The company advised customers to reset their passwords and implement two-factor authentication (2FA), though no evidence of credential compromise was stated. Trading activities resumed after the temporary shutdown, with Voyager reiterating that customer assets remained secure throughout the incident. No data breaches or financial losses were attributed to the attack, according to official statements. The organization did not provide additional details about the DNS threat's nature, scope, or mitigation steps beyond confirming the infrastructure intervention. Media inquiries from outlets including BleepingComputer regarding attack specifics received no response from Voyager following the initial disclosure.

Sources
Sources available to members
1 source