Poor Key Management
SIM hijacking, private key leak, hot wallet
Bitcoin Norway has shut down all operations according to its website and posts on Facebook. Bitcoin Norway is a cryptocurrency exchange that claims to have served over 25,000 Norwegians since 2013. On Monday last week, the customers of Bitcoins Norway’s crypto exchange were told that their crypto currency would be forcibly sold at a significantly lower price due to an alleged attack on the supplier Alphapoint. AlphaPoint reported to Bitcoins Norway on May 1, 2019 that a security incident had occurred. Bitcoins Norway’s original post reported the date as May 7, 2019. There are a number of other clarifications and corrections to the Bitcoins Norway report. There was no hack of the AlphaPoint software or technology. Rather, attackers gained access through a SIM swap enabled by exploiting a vulnerability in a telecom carrier, and sophisticated spear-phishing techniques which compromised sensitive credentials. The FBI is the sole and appropriate law enforcement entity to investigate this crime. AlphaPoint is fully cooperating with the investigation. AlphaPoint immediately notified Bitcoins Norway of the security incident, and provided as much information as it could without jeopardizing the investigation and without risking the spread of inaccurate information. On July 1, 2019, Bitcoins Norway made the decision to announce that it would sell end users cryptocurrency. AlphaPoint did not participate in that decision.
DISCLAIMER: While Zero Friction LLC has used the best efforts in aggregating and maintaining this database, Zero Friction LLC makes no representations or warranties with respect to the accuracy or completeness, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose.
Under no circumstances, shall Zero Friction LLC be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the dataset or information derived from our database.