Cloudflare Bug Triggers Password Warnings from Bitcoin Exchanges
Users of bitcoin exchanges and other online services are being warned to change their passwords in light of a bug tied to Cloudflare.

Users of bitcoin exchanges and other online services are being warned to change their passwords in light of a newly discovered bug tied to web security firm Cloudflare.
Cloudflare, which provides denial-of-service protection, detailed the issue in a blog post published today. The company was first contacted about the bug last week by Google cybersecurity researcher Tavis Ormandy.
The so-called "Cloudbleed" bug – a reference to 2014's Heartbleed vulnerability – is believed to have begun affecting services as early as September 2016, enabling the leak of memory that included sensitive information such as passwords and authentication tokens. The firm said the bug has since been patched.
News of the bug has triggered warnings from exchanges like Poloniex and Kraken, which suggested that users change their passwords, two-factor authentication and API keys. More broadly, cybersecurity advocates have strongly encouraged users of any site that utilizes Cloudflare to change their passwords as a precaution.
According to Cloudflare’s blog post, the real threat to users came as a result of some of that information being captured by search engines.
The firm explained:
“The bug was serious because the leaked memory could contain private information and because it had been cached by search engines. We have also not discovered any evidence of malicious exploits of the bug or other reports of its existence. The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests).”
A user on GitHub has curated a list of sites potentially affected by the bug, which includes industry services like Coinbase, BitPay, Blockchain and LocalBitcoins.
Other major websites, including Reddit, Uber and OKCupid, are said to be affected as well.
CoinDesk will continue monitoring this developing story.
Image via Shutterstock
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
These Three Metrics Show Bitcoin Found Strong Support Near $80,000

Onchain data shows multiple cost basis metrics confirm heavy demand and investor conviction around the $80,000 price level.
What to know:
- Bitcoin rebounded from the $80,000 region after a sharp correction from its October all time high, with price holding above the average entry levels of key metrics.
- The convergence of the True Market Mean, U.S. ETF cost basis, and the 2024 yearly cost basis around the low $80,000 range highlights this zone as a major area of structural support.











