$250 000 USD

APRIL 2020

UNKNOWN

BISQ

DESCRIPTION OF EVENTS

“Decentralized exchange (DEX) Bisq rang the alarm bells last night after a hacker exploited a significant software flaw to steal more than $250,000 worth of cryptocurrency from users.” “Monero (XMR) valued at $230,000 and bitcoin (BTC) valued at $22,000 was taken in the thefts, per the report. Overall, the value of the stolen cryptocurrency exceeds $250,000.”

 

“The hacker set other users’ default fallback address, posing as a seller they would start a trade with a buyer and wait for the time limit to run out.” “Rather than going to the legitimate owner, the digital assets arrived with the attacker, along with the buyer's payment and security deposit too.” “About 24 hours ago, we discovered that an attacker was able to exploit a flaw in the Bisq trade protocol, targeting individual trades in order to steal trading capital. We are aware of approximately 3 BTC and 4000 XMR stolen from 7 different victims. This is the situation as we know it so far. The only market affected was the XMR/BTC market, and all affected trades occu[r]red over the past 12 days.” “Security has always been a top priority for Bisq, but this incident shows it wasn’t perfect. The project is evaluating several approaches to strengthening security reviews and practices even more, and will detail them soon.” “Bisq took action right away upon discovering the attack, and the trading flaw was rectified with the release of Bisq v1.3.0. The exchange has resumed trading on Wednesday.”

 

“Many users have since reported failed trades and disappearing funds after upgrading to the latest version, 1.3.1, which contains the hotfix.” “In most cases of an exchange hack, the attacker can be booted off the trading platform for good. Not so with Bisq. One of the DEX's associated developers told CoinDesk that although the flaw was fixed, there was nothing to prevent the attacker – whose identity cannot be known – from accessing and trading on the platform again.” Bisq said it planned to make good on the losses. "A proposal will soon be created in the Bisq DAO, Bisq’s funding mechanism, that will aim to repay the 7 victims from future trading revenues," Jain explained.

This is an excellent example of why decentralization is not a simple “silver bullet” solution. Bisq presents an interface that can be complex and overwhelming for first-time users, the RAM-intensive software must be left running continuously in order to set up any limit orders, and the escrow system means that a trader must already have cryptocurrency, so it’s not suitable as the first ever on-ramp of a new cryptocurrency user. A software upgrade provided by the centralized software team through their centralized distribution network introduced a vulnerability which required the same team to issue a centralized warning to all users and then issue another centralized software upgrade. In order to make things right for the small group of otherwise helpless users who had more funds than they intended to trade sent to an untraceable stranger, the centralized software team is now running a centralized fundraiser to provide some funds from a centralized pot in order to assist the victims over time.

HOW COULD THIS HAVE BEEN PREVENTED?

This is an excellent example of why decentralization is not a simple “silver bullet” solution. Bisq presents an interface that can be complex and overwhelming for first-time users, the RAM-intensive software must be left running continuously in order to set up any limit orders, and the escrow system means that a trader must already have cryptocurrency, so it’s not suitable as the first ever on-ramp of a new cryptocurrency user. A software upgrade provided by the centralized software team through their centralized distribution network introduced a vulnerability which required the same team to issue a centralized warning to all users and then issue another centralized software upgrade. In order to make things right for the small group of otherwise helpless users who had more funds than they intended to trade sent to an untraceable stranger, the centralized software team is now running a centralized fundraiser to provide some funds from a centralized pot in order to assist the victims over time. Decentralized exchanges are a new technology that continue to develop over time.

 

Check Our Framework For Safe Secure Exchange Platforms

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.