- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Crypto exchanges are prone to attacks. Hereโs how to prevent them

Photo credit: Pixabay
The past year has seen the rise of cryptocurrencies. Bitcoin skyrocketed past US$19,000 and other platforms like Ethereum are experiencing significant growth as well. But this attracted not only investors but also cybercriminals.
In December 2017, a Seoul-based cryptocurrency exchange, Youbit (formerly Yapizon), was forced to shut down and filed for bankruptcy following a major cyberattack. The hack cost the platform 17 percent of its assets.
This is the second time the exchange has been hacked in less than eight months. In April, Youbit lost 4,000 bitcoins (now worth around US$73 million) to cybercriminals, causing many of its customers to lose confidence.
More hacks
Last year, hackers carried out a heist on NiceHash, one of the largest marketplaces for mining cryptocurrency, and stole more than US$70 million worth of bitcoins. Mt. Gox, a Tokyo-based exchange, filed for bankruptcy in 2014 after losing about 850,000 bitcoins during a cyberattack.
With more cyberattacks projected to occur in the future, many traders are starting to lose their nerve. Bitcoin prices plunged by 15 percent in Asian trade after news of the hacks spread.
The attacks are putting a spotlight on an area many investors are worried aboutโsecurity. Something needs to be done in order for cryptocurrency to maintain its growth.
I reached out to PolySwarm to know their thoughts on this matter. PolySwarm comprises of information security veterans. The team was recently awarded a contract by the US Department of Homeland Security to study confidentiality controls in a blockchain environment.
PolySwarm CEO Steve Bassi weighed in on the Youbit hack and shared some meaningful insights into its prevention.
Youbit infiltration
According to Bassi, Youbit is powered by an entire stack of software, just like any other exchange platforms. This stack ranges from operating systems that the Youbit servers run all the way up to the custom exchange application. There are millions of code within this stack. So, a flaw in any layer could be used to infiltrate the Youbit platform.
Bassi also noted that phishing could have led to the breach. Cybercriminals often create emails from supposed reputable organizations in order to trick recipients into sharing sensitive data such as login details and passwords.
In either case, the hackers were able to access private keys and/or the withdrawal system and used them to drain the platform of its funds.
โThe basic fact remains, however, that exchanges are complex pieces of software, and unless security is looked at holistically and consistently, this will continue to happen,โ says Bassi.
Ben Schmidt, the director of product security at PolySwarm, also shared some thoughts on the cyberattack.
Recommendations
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.







