Exchange QuickBit Confirms Data Breach May Impact 300K Users

The crypto exchange left a database open on the internet and leaked data for up to 300,000 users.

AccessTimeIconJul 22, 2019 at 11:30 a.m. UTC
Updated Sep 13, 2021 at 11:13 a.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global event for everything crypto, blockchain and Web3.Register Now

QuickBit, a Swedish cryptocurrency exchange listed on the NGM Nordic MTF market, allegedly leaked 300,000 customer records via an unprotected MongoDB database. The exchange confirmed the event in a series of updates on their investor relations board.

The leak, detailed by security researcher Paul Bischoff, first came to light after security aggregator Shodan noted the existence of the open database. QuickBit said that an outside contractor left the data unprotected while attempting a security upgrade.

A translated excerpt from their report:

QuickBit has recently adopted a third-party system for supplementary security screening of customers. In connection with the delivery of this system, it has been on a server that has been visible outside QuickBits firewall for a few days, and thus accessible to the person who has the right tools.

During the delivery period, a database has been exposed with information about name, address, e-mail address and truncated (not complete) card information for approximately 2% of QuickBit's customers.

Bischoff wrote that the QuickBit team pulled the database on or about July 3 after receiving notice that it was open. The records contained full names, addresses, email addresses, user gender, and dates of birth. QuickBit said it exposed no passwords or social security numbers and that no cryptocurrency keys leaked.

quickbit-database-2

Image via Comparitech.

"In addition to those records, we also discovered 143 records with internal credentials, including merchants, secret keys, names, passwords, secret phrases, user IDs, and other information," wrote Bischoff.

The company went public on July 11 with a market cap of about $22 million. We reached out to QuickBit for further comment. "Data security is of utmost importance for QuickBit," they wrote. "We will publish a public version of the incident report on our website shortly."

QuickBit image via Twitter

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.