In early November, the BTC-Alpha cryptocurrency exchange was attacked with ransomware. The incident caused a stir after the analytics company DarkTracer published an image from the LockBit group’s website claiming that BTC-Alpha’s data had been encrypted. The criminals threatened to make the stolen information public if the ransom was not paid by December 1.
On the same day, BTC-Alpha founder and CEO Vitaly Bodnar published a press release on the PRLeap platform accusing a rival crypto company of the attack. However, no statement was made on the exchange’s official website.
Later, in a discussion on Telegram, BTC-Alpha confirmed the hack “in early November” but emphasized that the British platform had already resumed operations. Company representatives clarified that Bodnar does indeed believe the attack was the work of competitors, but did not name who exactly they suspect. More details were disclosed on the exchange’s official Telegram channel.
After resuming operations, BTC-Alpha recommended that customers take additional security measures:
- update the application,
- undergo re-verification when withdrawing funds,
- regenerate API keys (the old ones have been revoked).
In addition, the exchange announced that two-factor authentication (2FA) is now mandatory for all users. It is also strongly advised not to use old passwords, as they may have been compromised.
Emsisoft expert Brett Callow noted that ransomware attacks on crypto exchanges are not that common, but the situation with BTC-Alpha is not unique. Questions remain as to whether encryption software was actually used and how much data may have been stolen.