Coindesk Logo

Tor Network Compromised by Single Hacker Stealing Users' Bitcoin: Report

Tor Network Compromised by Single Hacker Stealing Users' Bitcoin: Report

Tor Network Compromised by Single Hacker Stealing Users' Bitcoin: Report

The unknown hacker is using Tor exit relays to remove encryption on bitcoin mixer services and change wallet addresses from users to their own.

The unknown hacker is using Tor exit relays to remove encryption on bitcoin mixer services and change wallet addresses from users to their own.

The unknown hacker is using Tor exit relays to remove encryption on bitcoin mixer services and change wallet addresses from users to their own.

AccessTimeIconAug 12, 2020, 5:50 PM
Updated Aug 19, 2021, 3:38 AM

Presented By Icon

Election 2024 coverage presented by

Stand with crypto

A single malicious entity controls nearly a quarter of all nodes used on the anonymous internet provider Tor Network and is using its position to steal bitcoin and other cryptocurrencies.

  • A cybersecurity analyst, using the pseudonym "nusenu," said in a report this week a hacker now controls approximately 23% of the Tor Network's exit relay capacity.
  • The Tor Network provides anonymous internet access with voluntarily run relays that route traffic in order to obfuscate users' traceable and identifiable IP addresses.
  • The exit relay is the final stage that connects users to their requested websites.
  • Per the report, the hacker is using her/his position as a major exit relay host to stage sophisticated person-in-the-middle attacks, stripping websites of encryption and giving her/him full unrestricted access to traffic passing through her/his servers.
  • The malicious agent primarily focused on bitcoin mixer services, replacing wallet addresses so the mixer returns "clean" funds to the hacker rather than the original user.
  • A lack of enforcement on the Tor Network means the hacker has more than doubled her/his share of exit relays from under 10% last December, nusenu said.
  • It's unclear how much cryptocurrency has been stolen and whether the malicious agent is engaged in other attacks.
  • At least one bitcoin mixer service has added an additional security layer preventing hackers from removing their website's encryption.
  • The identity of the hacker remains a mystery and it isn't clear if there's any added motivation is for the attack besides stealing cryptocurrencies.

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information have been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.