Bitstamp Hack
What happened
On January 4, 2015, attackers compromised Bitstamp operational hot wallets and stole 18,866 BTC, worth roughly $5.3 million at the time. Bitstamp confirmed the wallet breach and temporarily suspended service. Subsequent reporting based on a leaked forensic report described a targeted phishing campaign that installed malware on employee systems and ultimately exposed hot-wallet files and credentials.
The incident was an exchange operational-security compromise, not a smart-contract or Bitcoin-protocol exploit. Bitstamp said customer balances held before the suspension would be honored in full.
How it happened
- Attackers reportedly targeted Bitstamp staff through tailored email and Skype phishing.
- A malicious document infected an employee endpoint; according to the later forensic-report account, this enabled access to the exchange's online hot-wallet file and its passphrase.
- The attacker then transferred BTC from the operational wallet.
- The security failure was credential and endpoint protection around an online exchange wallet, rather than an on-chain vulnerability.
Protocol details
Evidence
- report Report coindesk.com
- report Report money.cnn.com
- analysis DeFiLlama defillama.com
- analysis Bitstamp is open for business - better than ever! blog.bitstamp.net
- analysis Details of $5 Million Bitstamp Hack Revealed coindesk.com
- analysis Bitstamp exchange temporarily suspends service after hack wired.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.