OceanAltOceanAlt

Security incident · 2020-07-11

Cashaa

According to the public DefiLlama incident dataset, Cashaa (Bitcoin) suffered a security incident on 2020-07-11, with about $3.1M reported lost.

Date2020-07-11
Reported loss$3.1M
ChainBitcoin
Target typeCEX
Technique classFrontend & Infrastructure
TechniqueKey Leaked via Infrastructure
Bridge incidentNo
Within 2020#20 by loss that year, 0.1% of all reported losses that year

How this kind of attack works

The website, domain or hosting was hijacked, and users signed transactions that sent funds to the attacker from a page that looked normal.

Would a pre-payment check have helped

Partly applies

When a frontend or domain is hijacked the payee address is freshly generated and on no list, but the hijacked host is often already in public phishing feeds, so endpoint screening catches part of this class.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents