Data breach
BTC-E
- Records
- 551,855
- Breach date
- 1 October 2014Estimated
- Added
- 12 February 2025
What was exposed
4 types of data · 1 more reported
- Email addresses551,838
- Account balances1
- IP addresses1
- Usernames1
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In late 2014, attackers stole a large database of user records from BTC-e, a once-major cryptocurrency exchange based on btc-e.com that later became infamous in US money-laundering cases. The investigation team has indexed 551,855 records from the breach, including 551,838 email addresses, along with nicknames, IP addresses, and account balance information. The team estimates the attack took place around October 1, 2014.
The breach only became widely known years after the fact. In September 2016, the breach indexing service LeakedSource published an analysis of the stolen BTC-e data, reporting that the dataset covered 568,355 registered users. Reporting on that analysis by CCN and the Russian technology site Xakep described the stolen material in detail.
Breach Timeline
October 2014: The attack on BTC-e is estimated to have occurred, based on LeakedSource's later analysis of the stolen dataset.
September 2016: LeakedSource published details of the BTC-e breach, reporting that usernames, email addresses, passwords, IP addresses, registration dates, and bitcoin balances were among the stolen data.
July 2017: US authorities shut down BTC-e and charged alleged operators. The Financial Crimes Enforcement Network assessed a $110 million civil penalty against the exchange for anti-money laundering violations, and the Justice Department alleged it had processed funds stolen in the Mt. Gox hack.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, nicknames, IP addresses, and account balance information, drawn from 551,855 indexed records.
External reporting on the LeakedSource dataset adds further detail. According to CCN, the stolen data also included usernames, passwords, registration dates, and users' preferred language, and some profile records revealed how many bitcoins a user held. LeakedSource reported that BTC-e used an unusual, robust password hashing method, and that the passwords in the dump remained uncrackable when it reviewed the data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risks follow from the combination of email addresses and passwords. If an affected person reused a BTC-e password on other services, attackers could try those credentials against email, banking, and other exchange accounts, a tactic known as credential stuffing. Reused passwords remain one of the most common ways accounts are taken over.
The exposure of email addresses alone supports targeted phishing: criminals can send convincing messages that reference cryptocurrency, ask recipients to "verify" an account, or lure them to fake exchange login pages. The inclusion of IP addresses, registration dates, and bitcoin balance details gives criminals extra context to make those messages more believable, and can help them single out users who appeared to hold significant funds.
Because the exchange itself was shut down by law enforcement in 2017 and fined by FinCEN for facilitating ransomware and other criminal transactions, users should not expect any notification from the company. No breach notice from BTC-e was located in sources reviewed as of September 25, 2026.
What Should You Do If You Were Affected?
If you had a BTC-e account, take these steps:
Change your BTC-e password if you ever used that password anywhere else, and change it on every other account where it was reused.
Turn on two-factor authentication wherever it is offered, especially on email and any financial accounts.
Be wary of unsolicited emails that mention cryptocurrency, exchanges, or account verification, and never enter credentials through links in such messages.
Consider using a password manager to create a unique password for every account.
Watch for signs of account takeover, such as unexpected password reset emails or login alerts.
In the news
- CCN: Bitcoin Exchange BTC-E and BitcoinTalk Forum Breaches' Details Revealedccn.com (opens in a new tab)
- Xakep: BTC-E and BitcoinTalk breaches analysisxakep.ru (opens in a new tab)
- US Department of Justice: Russian Nationals Charged With Hacking Mt. Gox and Operating BTC-ejustice.gov (opens in a new tab)
- FinCEN: $110 Million Penalty Against BTC-efincen.gov (opens in a new tab)
