/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How hackers used rogue Tor exit relays to steal Bitcoin and rob Blockchain.info

How Hackers Abused Tor To Rob Blockchain, Steal Bitcoin, Target Private Email And Get Away With It  —  Across October and November of last year, some unlucky users of the world's most popular Bitcoin wallet … Thanks: @thealexknapp

Forbes Thomas Fox-Brewster

Context & Ripple Effects

This 2015 Forbes report is the earliest data point in a pattern the corpus keeps confirming: attackers compromising the shared plumbing between crypto users and their wallets rather than the wallets themselves. Blockchain.info users routing through volunteer-run Tor exit relays had their sessions intercepted mid-flight.

The playbook did not die with the disclosure. A group later hijacked enough Tor exit relay nodes for SSL stripping to peak at nearly a quarter of all nodes, and by 2021 more than a quarter of Tor's exit capacity was known to be malicious and aimed at crypto-related sites. The same era also saw $50M+ stolen via fake Blockchain.info domains bought through Google Search ads — different vector, same target.

First-order effects

  • Blockchain.info users who accessed their wallets over Tor during the October–November window had login credentials and session traffic exposed to the rogue operators, with private email accounts targeted alongside.
  • Blockchain.info, as the world's most popular Bitcoin wallet at the time, absorbed both the direct theft losses and the reputational cost of its users being robbed through infrastructure it did not control.

Second-order effects

  • Wallet providers were pushed toward transport-level hardening — certificate pinning and strict HTTPS enforcement — because the attack surface proved to be the network path, not the application.
  • Tor's volunteer exit-node model came under scrutiny from exactly the communities it served: if any operator can run an exit, crypto sites become a standing target, forcing Tor and site operators into adversarial node vetting.

Third-order effects

  • The corpus shows the pattern compounding rather than fading — rogue exit campaigns recurred in 2020 and 2021 at scale — suggesting anonymity infrastructure will remain a persistent, low-cost interception layer against crypto users unless exit-node trust is structurally reformed.
  • As long as high-value credentials transit shared middleman networks, attackers will keep choosing the pipe over the vault, pushing the industry toward defaults that assume hostile paths end-to-end.

The trend: Attacks on cryptocurrency users are converging on shared intermediary infrastructure — Tor exit relays, search ads, DNS — making the path between user and wallet a recurring battleground across a decade of incidents.