Share this article

Hacker Exploits Flaw in Decentralized Bitcoin Exchange Bisq to Steal $250K

The DEX revealed the hack 18 hours after it suspended trading.

Updated Sep 14, 2021, 8:26 a.m. Published Apr 8, 2020, 1:12 p.m.
Credit: Shutterstock
Credit: Shutterstock

Decentralized exchange (DEX) Bisq rang the alarm bells last night after a hacker exploited a significant software flaw to steal more than $250,000 worth of cryptocurrency from users.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Bisq, which allows users to exchange crypto anonymously, abruptly disabled trading late Tuesday night after it uncovered "a critical security vulnerability."

At the time, the exchange did not release any information regarding the nature of the flaw or whether user funds were safe. But 18 hours after it halted trading, Bisq said it took the "unprecedented" step after finding an attacker was exploiting a flaw in the software to steal cryptocurrency from other users.

"About 24 hours ago, we discovered that an attacker was able to exploit a flaw in the Bisq trade protocol, targeting individual trades in order to steal trading capital. We are aware of approximately 3 BTC and 4,000 XMR stolen from 7 different victims. This is the situation as we know it so far," Bisq said in a statement to CoinDesk.

The value of the crypto stolen was roughly $22,000 worth of bitcoin and $230,000 worth of monero , according to CoinDesk data at press time. In total, that comes to more than $250,000.

To carry out the thefts, the attacker was able to set other users' default fallback address – the destination to which crypto is sent to if a trade fails – to their own. Posing as a seller, they would start a trade with a buyer and simply wait for the time limit to run out. Rather than going to the legitimate owner, the digital assets arrived with the attacker, along with the buyer's payment and security deposit too.

See also: Binance’s DEX Now Supports AML Compliance Via CipherTrace

The flaw in question came as part of a recent update to the trading protocol, which was designed to improve decentralization and remove trusted third parties from the platform.

Bisq managed to fix the flaw by 12:00 UTC Wednesday and told CoinDesk just before publication that trading had just resumed again.

Bisq released onto testnet back in late 2018 as an exchange structured as a decentralized autonomous organization (DAO). It works in much the same way as other DEXs, but users can trade anonymously as there are no registration or identity verification requirements.

With the platform based on a distributed network, each user effectively acts as a node. Although Bisq's developers had suspended trading, the exchange's decentralized nature means users could override the suspension should they wish.

See also:New Crypto Exchange Altsbit Says It Will Close Following Hack

In most cases of an exchange hack, the attacker can be booted off the trading platform for good. Not so with Bisq. One of the DEX's associated developers told CoinDesk that although the flaw was fixed, there was nothing to prevent the attacker – whose identity cannot be known – from accessing and trading on the platform again.

"Anyone can use Bisq, there is no censorship," the developer said. "Just like anyone can use bitcoin, there is no way to ban someone from bitcoin."

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Solana’s Drift Launches v3, With 10x Faster Trades

Drift (b52_Tresa/Pixabay)

With v3, the team says that about 85% of market orders will fill in under half a second, and liquidity will deepen enough to bring slippage on larger trades down to around 0.02%.

What to know:

  • Drift, one of the largest perpetuals trading platforms on Solana, has launched Drift v3, a major upgrade meant to make on-chain trading feel as fast and smooth as using a centralized exchange.
  • The new version will deliver 10-times faster trade execution thanks to a rebuilt backend, marking the largest performance jump the project has made so far.