Share this article

Bitcoin.org Briefly Shut Down by Denial of Service Attack; Bitcoin Not Affected

While the site was inaccessible, bitcoiners shared the software to newcomers wanting to download Bitcoin's code.

Updated Sep 14, 2021, 10:45 a.m. Published Dec 19, 2020, 2:21 p.m.
do not enter

Bitcoin.org, the website that hosts bitcoin’s code, is back up after a distributed denial of service attack (DDoS) took the site down in the early hours of Saturday morning.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The website is home to Bitcoin Core, the most popular software version of bitcoin’s code. To be clear: Bitcoin’s blockchain itself was not attacked, only the website hosting one copy of its open-source code.

Read more: What Is Bitcoin?

While the site was inaccessible, bitcoiners disseminated the software to newcomers wanting to download the code via a torrenting service, an open-source marketplace for sharing data. Bitcoin Core’s client includes a “magnet link” (that random alphanumeric string in the below tweet) which can be manually shared to download Bitcoin Core from services like uTorrent and BitTorrent. From this link, the user can locate the hash for where Bitcoin Core is stored on these services and download the software.

Called “distributed denial of service,” a DDoS attack occurs when a person or group uses multiple devices to spam a server or system with data requests, clogging its bandwidth and typically rendering a website inaccessible.

DDoS attacks common during Bitcoin price spikes

Bitcoin.org is now live again. Cobra, a pseudonymous developer who helps maintain Bitcoin.org, told CoinDesk that DDoS attacks are not uncommon during hot price action and that this specific attack may not be over.

“Basically, we got hit with a large DDoS, which is quite common around ATHs (all-time highs) and bull markets. It took us down for a while but for now we're back up, but we might go down on and off periodically depending on how long the attackers want to continue attacking.”

Cobra told CoinDesk that the IP traffic from the attack is Russian, but it’s anybody’s guess where the attackers are actually located. That’s because, in addition to the attackers using privacy preserving tools like virtual networks, most attackers launch DDoS attacks remotely from malware-infested devices, pseudonymous and independent researcher 6102 told CoinDesk.

A DDoS against a distributed network like a blockchain--called a sybil attack--has never occurred on Bitcoin’s blockchain.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

The Protocol: Stripe’s Tempo Testnet Goes Live

Contactless payment via a mobile phone (Jonas Lupe/Unsplash)

Also: ZKSync Lite to Sunset, Blockstream App Update, Axelar’s AgentFlux

What to know:

This article is featured in the latest issue of The Protocol, our weekly newsletter exploring the tech behind crypto, one block at a time. Sign up here to get it in your inbox every Wednesday.