Cryptocurrency users targeted by Tor network exit nodes cryptocurrency


Cybersecurity researchers have said a threat actor has been adding malicious servers into the Tor network to intercept traffic heading to cryptocurrency websites, perhaps to reroute the transaction to its own accounts.
A researcher known as Nusenu first highlighted this malicious behavior last year, and has now shared more details about the on-going malicious behavior in a follow-up post.
The Tor anonymous network relies on exit servers, or relays in Tor parlance, which are put up by individuals and organizations. These are final servers that Tor traffic passes through before it reaches its destination.
We’re looking at how our readers use VPN for a forthcoming in-depth report. We’d love to hear your thoughts in the survey below. It won’t take more than 60 seconds of your time.
The threat actor, through its exit relays, performed an SSL stripping attack on traffic headed towards cryptocurrency websites, downgrading the encrypted HTTPS connection to plaintext HTTP.
While the true intentions behind the attack remain unknown, it’s argued that this was perhaps done in order to replace the cryptocurrency address to reroute the transactions to the attackers cryptocurrency wallet.
Taken down
Following last year’s attack, the Tor Project published a set of guidelines for users that access cryptocurrency websites via its network.
According to the researcher, the threat actor managed to fly under the radar for more than a year because the malicious exit relays were added to the Tor network in small increments, until they made up more than 23% of all exit nodes.
Once the scheme was discovered, the exit relays were removed. However it only took a couple of days before the researcher started observing new relays exhibiting the same malicious behavior.
Despite being outed, the threat actor continues to add new malicious nodes and Nusenu estimates that between 4% and 6% of the Tor exit nodes are still under the control of the threat actor.
TechRadar is supported by its audience. TechRadar does not endorse any specific cryptocurrencies or blockchain-based services and readers should not interpret TechRadar content as investment advice. Our reporters hold only small quantities of cryptocurrency (under $100 in value), as is necessary to perform wallet and exchange reviews, and do not hold shares in any publicly listed cryptocurrency companies.
Via The Record
Cybersecurity researchers have said a threat actor has been adding malicious servers into the Tor network to intercept traffic heading to cryptocurrency websites, perhaps to reroute the transaction to its own accounts. A researcher known as Nusenu first highlighted this malicious behavior last year, and has now shared more details…
Recent Posts
- iPhones are replacing ‘Trump’ with ‘racist’ during dictation – but Apple is fixing the problem
- The 9 Best Mirrorless Cameras (2025): Full-Frame, APS-C, and More
- Framework Desktop hands-on: a possible new direction for gaming desktops
- ChatGPT is a terrible, fascinating, and thrilling to-do list app
- Satya Nadella says AI is yet to have its Excel moment
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010