Bitfinex database breach ‘seems fake,’ says CTO

As an experienced cybersecurity analyst, I find it highly unlikely that FSOCIETY successfully hacked Bitfinex’s database based on Paolo Ardoino’s statements. Bitfinex has a robust security infrastructure, and they have repeatedly emphasized their commitment to protecting user data. The fact that only 5,000 of the leaked records matched with Bitfinex users further supports this theory.


According to Bitfinex CTO Paolo Ardoino, the allegations made by hacking group FSOCIETY about breaching Bitfinex’s database and releasing 22,500 customer emails and passwords appear to be unfounded.

As a crypto investor, I can tell you that if there were any legitimate information to share, they would have reached out through our bug bounty program, customer support tickets, emails, or Twitter for inquiries. Unfortunately, we didn’t receive any such requests.

“We don’t store plaintext passwords, nor 2FA secrets in clear text,” he added.

Among the 22,500 emails and password combinations, just 5,000 were found to correspond with Bitfinex users, according to Adoino’s explanation. It seems plausible that the hackers obtained this information from multiple other crypto-related data breaches instead.

“Most users unfortunately use the same email and passwords across multiple sites,” he explained.

A security researcher, who is convinced that the hackers were attempting to publicize their data recovery hacking tool, reportedly passed on a message to him about the supposed hack of Bitfinex.

“So by creating a buzz about successfully hacking wellknown companies / a university, it is an advertisement of how good their tool is and others should buy it so they can make millions of dollars by using it to exploit companies using this tool.”

Ardoino reassured users that they were actively looking into the issue, but no security breach had been identified yet. Rest assured, all funds remain secure.

This is not the first time Bitfinex has faced scrutiny over data breach concerns.

In November 2023, I, as a crypto investor, came across news from CryptoMoon about a small-scale security breach at Bitfinex. It appeared that one of their customer support representatives had been compromised.

A string of phishing attacks aimed at Bitfinex users ensued, according to Bitfinex’s announcement, with minimal damage reportedly inflicted.

In 2016, I came across an unfortunate incident where Bitfinex, a cryptocurrency exchange platform, experienced a security breach. As a result, approximately 119,576 customers lost their Bitcoin (BTC), equivalent to around $70 million at the time of the breach. However, considering the current value of Bitcoin, this loss amounts to a staggering $7.6 billion.

Read More

2024-05-05 08:51