Data breach
bitcoinsec.com
- Records
- 10,835,888
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses10,835,888
- Passwords10,832,731
About this breach
The investigation team has indexed a large credential listing tied to bitcoinsec.com, a website associated with the Bitcoin and cryptocurrency security community. The team estimates the attack date as January 1, 2020, though no individual or group has claimed responsibility for the data. The listing contains roughly 10.8 million records, and it was added to the database on December 1, 2024. The scale and structure of the data suggest this is a compilation of email and password pairs rather than a documented hack of a single company's systems.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords. The listing includes 10,835,888 email addresses and 10,832,731 passwords, meaning nearly every record pairs an email with a password.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from a credential compilation like this is credential stuffing. Attackers take leaked email and password pairs and automatically try them on other websites, banking on the fact that many people reuse the same password across multiple accounts. If you used the same password on bitcoinsec.com or a related forum that you used elsewhere, accounts on those other services could be at risk.
Phishing is a secondary concern. With a valid email address in hand, scammers can send convincing messages that reference cryptocurrency topics, since the email addresses in this listing come from a Bitcoin-focused community. Recipients may be more likely to trust a message that appears to come from a service they recognize.
What Should You Do If You Were Affected?
Take these steps:
Change the password on any account connected to this breach, and change it anywhere else you reused that password.
Use a unique password for every account. A password manager can generate and store them for you.
Turn on two-factor authentication wherever it is offered, especially on email, financial, and cryptocurrency exchange accounts.
Be cautious with unsolicited emails about Bitcoin or cryptocurrency services, and avoid clicking links or entering credentials through emailed links.
Because this appears to be a compilation, the passwords in it may be old. Even so, people frequently keep the same passwords for years, so treating the exposure as current is the safer approach.
