How hackers used rogue Tor exit relays to steal Bitcoin and rob Blockchain.info
How Hackers Abused Tor To Rob Blockchain, Steal Bitcoin, Target Private Email And Get Away With It — Across October and November of last year, some unlucky users of the world's most popular Bitcoin wallet … Thanks: @thealexknapp
Context & Ripple Effects
This 2015 Forbes report is the earliest data point in a pattern the corpus keeps confirming: attackers compromising the shared plumbing between crypto users and their wallets rather than the wallets themselves. Blockchain.info users routing through volunteer-run Tor exit relays had their sessions intercepted mid-flight.
The playbook did not die with the disclosure. A group later hijacked enough Tor exit relay nodes for SSL stripping to peak at nearly a quarter of all nodes, and by 2021 more than a quarter of Tor's exit capacity was known to be malicious and aimed at crypto-related sites. The same era also saw $50M+ stolen via fake Blockchain.info domains bought through Google Search ads — different vector, same target.
First-order effects
- Blockchain.info users who accessed their wallets over Tor during the October–November window had login credentials and session traffic exposed to the rogue operators, with private email accounts targeted alongside.
- Blockchain.info, as the world's most popular Bitcoin wallet at the time, absorbed both the direct theft losses and the reputational cost of its users being robbed through infrastructure it did not control.
Second-order effects
- Wallet providers were pushed toward transport-level hardening — certificate pinning and strict HTTPS enforcement — because the attack surface proved to be the network path, not the application.
- Tor's volunteer exit-node model came under scrutiny from exactly the communities it served: if any operator can run an exit, crypto sites become a standing target, forcing Tor and site operators into adversarial node vetting.
Third-order effects
- The corpus shows the pattern compounding rather than fading — rogue exit campaigns recurred in 2020 and 2021 at scale — suggesting anonymity infrastructure will remain a persistent, low-cost interception layer against crypto users unless exit-node trust is structurally reformed.
- As long as high-value credentials transit shared middleman networks, attackers will keep choosing the pipe over the vault, pushing the industry toward defaults that assume hostile paths end-to-end.
The trend: Attacks on cryptocurrency users are converging on shared intermediary infrastructure — Tor exit relays, search ads, DNS — making the path between user and wallet a recurring battleground across a decade of incidents.