Explained: The Blockfolio Hack (Feb 2021) (2024)

Blockfolio is a portfolio management application that allows no-fee trading of cryptocurrency and stocks. On February 9, 2021, the platform was hacked, causing it to send offensive and racist messages to its users.

Inside the Hack

The Blockfolio hack did not target the company’s trading infrastructure. No trading functionality was impacted by the incident, user funds are still safe, and the company is even providing a $10 credit to current and new users (for one week).

The target of this particular attack was Blockfolio’s customer communications infrastructure. The company uses Signal to broadcast messages to its users, enabling Blockfolio to provide direct updates to customers. Additionally, Blockfolio maintains a display and news section for customer interactions.

These customer-facing systems are what were compromised in the attack. With access to the company’s Signal submitter and other infrastructure, the attacker was able to push racist and offensive messages to Blockfolio users.

3 Key Takeaways from the Hack

Unlike many blockchain project hacks, this particular attack did not involve the theft of users’ money or even place it at risk. Instead, the attacker exploited a weak point in the company’s defenses to tarnish customer relationships. Analysis of this attack provides a few important takeaways for Blockfolio in particular and any blockchain company in general.

1. Strong Access Management is Vital

In this hack, the attacker was able to take control of Blockfolio’s Signal submitter to broadcast racist and offensive messages to its users. While the details of the incident are still unknown, it is likely that the hack was enabled by poor access management policies within Blockfolio.

Strong access management requires implementing least privilege and multi-factor authentication (MFA). Least privilege limits the access of a particular user to what is necessary, which limits the damage that a user account can do if compromised. MFA makes it harder for an attacker to compromise a user’s account by requiring access to the second authentication factor to log into the account. By implementing both of these policies, an organization limits its attack surface and makes account compromise much more difficult to perform.

2. Comprehensive Security Audits Are a Necessity

In response to the hack, Blockfolio CEO Sam Banman-Fried stated, “Over the next month I’ll be leading a security review of the old, non-trading-related parts of Blockfolio to bring them in line with the standards set by trading, and by FTX more generally.” While this is a good effort, it amounts to locking the barn door after the horse has escaped.

Cybercriminals commonly take advantage of the weakest point in an organization’s or system’s defenses. This means that true cybersecurity requires securing all aspects of an organization’s business. For many dApps, a common mistake is to audit only the smart contract, leaving potential vulnerabilities in the web front-end overlooked. In Blockfolio’s case of being a centralized app, a failure to secure its customer communications infrastructure led to an embarrassing security incident.

3. Reputational Damage Can Have Financial Impacts

The Blockfolio hack allegedly did not impact the trading-related components of the Blockfolio application, meaning that users’ funds are not at risk and Blockfolio won’t have to pay restitution. However, that doesn’t mean that this incident won’t hurt Blockfolio financially.

Reputation matters, and this hack may cause users to doubt Blockfolio’s ability to keep their money secure. While this hack may not have cost the company any money directly, it definitely hurt its reputation and may have cost it in the long term as investors look elsewhere.

Securing Blockchain Solutions

Blockchain infrastructure is complex, and that isn’t counting all of the blockchain-adjacent systems like an organization’s web front-end, communications systems, and other back-end infrastructure. As this incident – and numerous other blockchain hacks – have demonstrated, an end-to-end security audit is essential for maintaining customer trust and confidence in an organization’s products. Contact Halborn for help should your organization be in need: [email protected].

Explained: The Blockfolio Hack (Feb 2021) (2024)
Top Articles
Housing Market 2024 Predictions | Bankrate
Help And Training Community
Poe T4 Aisling
It’s Time to Answer Your Questions About Super Bowl LVII (Published 2023)
Gomoviesmalayalam
Winston Salem Nc Craigslist
Get train & bus departures - Android
Collision Masters Fairbanks
A Complete Guide To Major Scales
The Idol - watch tv show streaming online
The Pope's Exorcist Showtimes Near Cinemark Hollywood Movies 20
Bhad Bhabie Shares Footage Of Her Child's Father Beating Her Up, Wants Him To 'Get Help'
Drago Funeral Home & Cremation Services Obituaries
Learn2Serve Tabc Answers
10-Day Weather Forecast for Santa Cruz, CA - The Weather Channel | weather.com
Samantha Aufderheide
Culver's Flavor Of The Day Taylor Dr
Tripadvisor Napa Restaurants
Evil Dead Rise Showtimes Near Pelican Cinemas
Filthy Rich Boys (Rich Boys Of Burberry Prep #1) - C.M. Stunich [PDF] | Online Book Share
A Man Called Otto Showtimes Near Cinemark University Mall
Evil Dead Rise Showtimes Near Sierra Vista Cinemas 16
Chelsea Hardie Leaked
Ultra Ball Pixelmon
Riverstock Apartments Photos
Things to do in Pearl City: Honolulu, HI Travel Guide by 10Best
Craftsman Yt3000 Oil Capacity
Why Are The French So Google Feud Answers
Springfield.craigslist
Clearvue Eye Care Nyc
UPS Drop Off Location Finder
LEGO Star Wars: Rebuild the Galaxy Review - Latest Animated Special Brings Loads of Fun With An Emotional Twist
All Things Algebra Unit 3 Homework 2 Answer Key
Oreillys Federal And Evans
Reading Craigslist Pa
Domino's Delivery Pizza
How to Draw a Sailboat: 7 Steps (with Pictures) - wikiHow
Bernie Platt, former Cherry Hill mayor and funeral home magnate, has died at 90
D-Day: Learn about the D-Day Invasion
Indiana Jones 5 Showtimes Near Cinemark Stroud Mall And Xd
Discover Things To Do In Lubbock
Theater X Orange Heights Florida
Frequently Asked Questions
Market Place Tulsa Ok
Terrell Buckley Net Worth
Online College Scholarships | Strayer University
Nurses May Be Entitled to Overtime Despite Yearly Salary
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Lira Galore Age, Wikipedia, Height, Husband, Boyfriend, Family, Biography, Net Worth
Naughty Natt Farting
Obituaries in Westchester, NY | The Journal News
Latest Posts
Article information

Author: Melvina Ondricka

Last Updated:

Views: 5880

Rating: 4.8 / 5 (48 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Melvina Ondricka

Birthday: 2000-12-23

Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

Phone: +636383657021

Job: Dynamic Government Specialist

Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.