Share this article

LocalBitcoins Releases Investigation Report on Site Wallet Issues

Updated Sep 11, 2021, 10:40 a.m. Published Apr 18, 2014, 5:00 p.m.
Report

Following yesterday's statement from LocalBitcoins regarding issues with its wallet service, the website has released its follow-up investigation report.

The report focused in part on claims that the site's two-factor authentication failed to prevent a wallet breach. LocalBitcoins also addressed the cause of withdrawal delays that took place as users tried to move their bitcoins away from the site following the posting of user concerns on reddit.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The LocalBitcoins team wrote in the report's introduction:

"LocalBitcoins team did not found any evidence of compromised site security."

Report walks through hack claims

LocalBitcoins presented an activity timeline of user don4of4 (who initially posted on reddit), including 17th April when the wallet intrusion took place.

The site's team identified that unlike previous logins by the user, someone accessed the site via a Tor browser and had access to don4of4's two-factor authentication key generator.

LocalBitcoins surmised that whoever accessed the user's account had gained access to his mobile device, which don4of4 told the team was used to store the two-factor codes.

The report read:

"In this case if the user used this particular Android device to access LocalBitcoins and the device was compromised, the attacker gained access to user password, user session ID and two-factor codes. Furthermore, it was reported on the reddit that the credentials of this particular user have been found on known compromised user account lists spreading in the internet."

LocalBitcoins added that it does not currently offer session fixation as a security measure. However, the development team will look into the matter as a possible future offering for users.

LocalBitcoins addresses withdrawal problems

As stated previously, concerns regarding the site's integrity resulted in increased withdrawal traffic. Withdrawal delays led to increased anxiety among the site's users.

LocalBitcoins said in its report:

"When the LocalBitcoins hot wallet was being emptied due to high volume of withdraws, the withdraws started to delay. LocalBitcoins choose not to top up the hot wallet until the incident is investigated."

The site added that the majority of its bitcoins are in cold storage.

Wallet malware issues detailed

LocalBitcoin's initial 17th April statement suggested that a malware intrusion had resulted in the loss of some users' wallet credentials.

The investigation report elaborated on this point, saying:

"In all of these cases the user account had no two-factor authentication and had a login coming from an IP address not associated with the users prior behavior pattern. We believe this was an incident either with reused passwords or malware-infection on the use computer."

The report also recommended that all users adopt two-factor authentication for its account, saying that the site is unable to tell the difference between a user login and one from an unauthorised source.

Tough landscape for wallet owners

Malware targeting bitcoin wallets have increased in number significantly in the past year, posing problems for users who don't keep their bitcoins in cold storage.

A recent report by cybersecurity firm Kapersky Labs showed a sharp increase in bitcoin wallet intrusions and attempted intrusions in 2013, compared to 2012 levels.

A separate study conducted by digital security firm Dell SecureWorks found that nearly 150 strains of malware were currently circulating the internet as of February 2014.

Meer voor jou

Protocol Research: GoPlus Security

GP Basic Image

Wat u moet weten:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

Meer voor jou

Bitcoin Faces Japan Rate Hike: Debunking The Yen Carry Trade Unwind Alarms, Real Risk Elsewhere

japan, flag. (DavidRockDesign/Pixabay/Modified by CoinDesk)

Speculators maintain net bullish positions in the yen, limiting scope for sudden JPY strength and mass carry unwind.

Wat u moet weten:

  • Impending BOJ rate hike largely priced in; Japanese bond yields near multi-decade highs.
  • Speculators maintain net bullish positions in the yen, limiting scope for sudden yen strength.
  • BOJ tightening may contribute to sustained upward pressure on global yields, impacting risk sentiment.