Bitstamp Hack

Reported loss $5.3M
Bitcoin
Targeted phishing and endpoint compromise of hot-wallet credentials

What happened

On January 4, 2015, attackers compromised Bitstamp operational hot wallets and stole 18,866 BTC, worth roughly $5.3 million at the time. Bitstamp confirmed the wallet breach and temporarily suspended service. Subsequent reporting based on a leaked forensic report described a targeted phishing campaign that installed malware on employee systems and ultimately exposed hot-wallet files and credentials.

The incident was an exchange operational-security compromise, not a smart-contract or Bitcoin-protocol exploit. Bitstamp said customer balances held before the suspension would be honored in full.

How it happened

  1. Attackers reportedly targeted Bitstamp staff through tailored email and Skype phishing.
  2. A malicious document infected an employee endpoint; according to the later forensic-report account, this enabled access to the exchange's online hot-wallet file and its passphrase.
  3. The attacker then transferred BTC from the operational wallet.
  4. The security failure was credential and endpoint protection around an online exchange wallet, rather than an on-chain vulnerability.

Protocol details

Classification Operational wallet compromise
Protocol Type CEX
Protocol links Website @Bitstamp

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.