A possible data breach is being investigated at UK Bitcoin exchange CoinCut, which exposed sensitive customer data, including passport and card data, to the public.
Last week's visitors were apparently able to access directories that included images of passports, personal identification cards, and credit and debit cards.
Company spokesman Dax Chan said the company was treating the incident as "malicious."
“We are trying to understand how this particular directory became visible to the world – and how the problem leaked so quickly, given that we are a relatively small Bitcoin seller in a huge market,” he claimed, according to CoinDesk.
If he is right, CoinCut customers may be at risk of identity theft or even potential surveillance through phishing attacks, as stolen data will leak into the cybercrime underground and into the hands of online fraudsters.
Robert Hansen, vice president at WhiteHat Security, said the incident is not at all unusual.
“I’ve seen a number of applications that have similar vulnerabilities. It’s very common for websites to store sensitive information in publicly accessible Web directories,” he added. “It’s a trivial attack to create a traversal directory or to traverse the file names to determine what other things might be in the same directory.”
He added that it is strange for CoinCut to claim to have been surprised by the speed of the data leak.
“Information leaks from people who want to use a pseudo-anonymous currency are perhaps some of the most valuable data on earth for ghosters, competitors, and the security research community,” he claimed.
Security concerns remain one of the major obstacles to full Bitcoin adoption, with incidents like these only serving to reinforce second thoughts about the cryptocurrency.
