BTC
$117,674.77
-
1.02%
ETH
$3,773.40
-
2.04%
XRP
$3.0668
-
2.89%
USDT
$0.9999
-
0.00%
BNB
$783.84
-
4.71%
SOL
$177.32
-
3.54%
USDC
$0.9999
+
0.01%
DOGE
$0.2166
-
5.68%
TRX
$0.3257
-
4.27%
ADA
$0.7593
-
5.17%
HYPE
$42.32
-
5.74%
SUI
$3.7203
-
4.47%
XLM
$0.4070
-
4.81%
LINK
$17.36
-
4.90%
BCH
$562.49
-
1.14%
HBAR
$0.2543
-
7.31%
AVAX
$23.28
-
6.85%
WBT
$43.63
-
1.29%
LEO
$8.9599
-
0.09%
LTC
$108.37
-
1.55%
Ad
Logo
  • News
  • Cryptocurrencies
  • Data
  • Indices
  • Research
  • Events
  • Sponsored
  • Sign In
  • Sign Up
Finance
Share this article
X iconX (Twitter)LinkedInFacebookEmail

Crowdcurity brings crowdsourced hacker testing to bitcoin

Crowdcurity wants to reward those who find security holes in bitcoin sites.

By Danny Bradbury
Updated May 9, 2023, 3:02 a.m. Published Oct 16, 2013, 10:30 a.m.
Crowdcurity

Bitcoin websites are prime targets for cyber-attacks. Now, a company called Crowdcurity wants to apply the wisdom of crowds to make them more secure. How will it work?

Protecting against attacks isn’t optional if you want to keep your web-based bitcoin app in business. Bitcoin apps can often hold hundreds in individual coins, leaving their users incurring significant financial losses if they are compromised. This is particularly true in the case of exchanges.

jwp-player-placeholder
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
By signing up, you will receive emails about CoinDesk products and you agree to our terms of use and privacy policy.

For example, margin-trading site Bitcoinica was sued for $460,000 in 2012 after being hacked twice. US-based exchange BitFloor suffered major embarrassment after 24,000 bitcoins were stolen following a hack in September 2012 – a figure that represented almost ten years of transaction fees. That’s a difficult loss to bounce back from. This isn't the first instance, the problems go back further still: Vicurex saw its wallet compromised in 2011. And these are just examples from a far larger set.

Breaking into a web app

Not all of these bitcoin thefts are explicitly the result of website problems. Some stem from human error, and some are, as yet, unexplained. But one thing is for sure: badly-designed code doesn’t help, and is responsible for at least some of these issues.

How many ways can a person break into a web application? There are tens of them, but the Open Web Application Security Project (OWASP) breaks them down into ten broad categories. It updates the list each year, and 2013’s makes gruesome reading.

At the top of the list? Injection. This happens when someone injects code that shouldn’t be there into a web application, usually through a parameter passed to a URL. It can be used to execute unintended commands, including putting dangerous malware on a web page to infect visiting machines, or dumping customer details, for example.

Other potential attacks include exploiting poor security configuration (including configuration of hosting servers), and broken authentication, in which sessions are not properly managed, enabling attackers to hijack accounts. Another old chestnut is the cross-site scripting attack, in which bad data is sent to a browser using JavaScript, causing it to misbehave. The fact that these attacks are still possible years after they were first discovered is a discredit to the software development community.

The problem for a lot of software developers in the bitcoin space and elsewhere is that it is difficult to spot all of the bugs. Several bitcoin sites employ ‘bug bounties’ to solve the problem, offering eagle-eyed members of the community rewards to spot and fix problems.

Coinbase has one

, with a minimum payout of 5 BTC, and no maximum payout. At the time of writing, it had awarded bitcoins to 27 people, amounting to at least 135 BTC. Payward, which runs the Kraken margin trading site, is stingier about its bounty program, offering a minimum of a single bitcoin per bug. Another bitcoin trading site, 1Broker, also ran a program.

Enter Crowdcurity

Crowdcurity hopes to standardize the bug bounty concept by outsourcing the process. The online service connects companies that have software to debug with a community of around 250 software testers, which it has found via security forums.

 How Crowdcurity works
How Crowdcurity works

The firm isn’t solely bitcoin focused, as its process can be applied to any web-based application. Nevertheless, it’s an important market for the firm. “Bitcoin companies are already very focused on security and they know that they need to focus on it,” says Jacob Hansen, founder of Crowdcurity, who is already negotiating with at least one large bitcoin-based business. “Traditional e-businesses don’t always have the same awareness.”

[post-quote]

Customers can create a reward program with the site, setting rules and amounts for bug programs. The challenge is then sent to the testing community, which works on reporting vulnerabilities. The customer validates the bugs in conjunction with Crowdcurity, and payouts are awarded based on bug severity.

More than half of the payouts have been made in bitcoins for the single customer that the firm had dealt with as of last week. “Many of these payments may be $25-$50 if the bugs are low criticality, and with bitcoins you have lower fees, and it makes payments faster,” Hansen says.

The site’s testers can target a test site, or an operational site that is already processing live data, Hansen explains. But sites shouldn’t just rely on external testers, he argues.

Crowdcurity is effectively a penetration testing service, in which a crowd of testers tries to hack a website. But what they don’t do is look at a site’s code. In one sense, this is a good thing, because closed source sites won’t want people ogling their intellectual property. In another sense, it leaves the analysis of the code up to the company, which then has to find the skills to do it.

“They should do security reviews of their code internally. Then, there are a lot of automatic tools out there which can look at your code and discover common vulnerabilities.” Crowdcurity uses tools like Brakeman for its own site, which scans for vulnerability in Ruby on Rails apps. There are more for other languages – but companies have to have the skills and discipline to use them.

As bitcoin grows up and companies get better funding, software developers will hopefully be in a better position to cover all of their security bases. And maybe we’ll see fewer disaster stories like Bitcoinica or Bitfloor.

hackingSecurityCrowdcuritystartupsCompanies
Danny Bradbury

Danny Bradbury has been a professional writer since 1989, and has worked freelance since 1994. He covers technology for publications such as the Guardian.

Picture of CoinDesk author Danny Bradbury

More For You

Multisig Failures Dominate as $2B Is Lost in Web3 Hacks in the First Half

By Oliver Knight|Edited by Sheldon Reback
Jul 24, 2025
Alt

A wave of multisig-related hacks and operational misconfiguration led to catastrophic losses in the first half of 2025.

What to know:

  • Over $2 billion was lost to Web3 hacks in the first half of the year, with the first quarter alone surpassing 2024’s total.
  • Multisig wallet mismanagement and UI tampering caused the majority of major exploits.
  • Hacken urges real-time monitoring and automated controls to prevent operational failures.
Read full story
Latest Crypto News
Article image

lorem ipsum article 1

2 hours ago
CoinDesk

Multisig Failures Dominate as $2B Is Lost in Web3 Hacks in the First Half

Jul 24, 2025
JPMorgan CEO Jamie Dimon

Crypto Industry Asks President Trump to Stop JPMorgan’s 'Punitive Tax' on Data Access

Jul 24, 2025
WIF Experiences 11% Intraday Swing with Institutional Support Driving Recovery to $1.21 Amid Bullish Technical Signals

WIF Suffers Sharp 11% Decline Before Mounting Recovery to $1.21

Jul 23, 2025
A momentum indicator has turned green for BTC bulls. (geralt/Pixabay)

[Article test] Bitcoin Climbs to $105K; Crypto ETF Issuer Sees 35% Upside

Jul 23, 2025
(CJ/Unsplash)

[Test] Bitcoin Perp Futures Open Interest on Offshore Platforms Surges The Most Since Trump's Crypto Reserve Disclosure

Jul 21, 2025
Top Stories
JPMorgan Chase CEO Jamie Dimon (Photo by Kevin Dietsch/Getty Images)

JPMorgan To Allow Clients To Buy Bitcoin, Says Jamie Dimon

May 19, 2025
Consensus 2025: Anthony Scaramucci, Founder, SkyBridge Capital

Scaramucci Says Bitcoin Treasury Trend Will Fade Despite Saylor’s Success

Jul 2, 2025
A barman shakes a cocktail shaker with an array of drinks bottles behind him.

Crypto Daybook Americas: Bitcoin Whiplash Shakes Market as U.S. Yield Spike Threatens Bull Run

May 19, 2025
Mike Novogratz, Galaxy founder and CEO, speaks at Consensus 2024 (CoinDesk/Shutterstock/Suzanne Cordiero)

The Bull Case for Galaxy Digital Is AI Data Centers Not Bitcoin Mining, Research Firm Says

May 19, 2025
Tokyo, Japan (Jaison Lin/Unsplash)

Metaplanet Buys Another 1,004 Bitcoin, Lifts Holdings to Over $800M Worth of BTC

May 19, 2025
A roller coaster. (Mark Wilson/Getty Images)

Bulls and Bears Get Caught off Guard as Bitcoin Jumps to $106K, Then Falls Back to $103K

May 19, 2025

Only 1 article remaining this month.

Sign up for free

About

  • About Us
  • Masthead
  • Careers
  • CoinDesk News
  • Crypto API Documentation
  • Blog

Contact

  • Contact Us
  • Accessibility
  • Advertise
  • Sitemap
  • System Status
Disclosure & Polices
CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.
EthicsPrivacyTerms of UseCookie SettingsDo Not Sell My Info

© 2025 CoinDesk, Inc.
X icon
Sign Up
  • News
    Back to menu
    News
    • Markets
    • Finance
    • Tech
    • Policy
    • Focus
  • Cryptocurrencies
    Back to menu
    Cryptocurrencies
    • Data
      Back to menu
      Data
      • Trade Data
      • Derivatives
      • Order Book Data
      • On-Chain Data
      • API
      • Research & Insights
      • Data Catalogue
      • AI & Machine Learning
    • Indices
      Back to menu
      Indices
      • Multi-Asset Indices
      • Reference Rates
      • Strategies and Services
      • API
      • Insights & Announcements
      • Documentation & Governance
    • Research
      Back to menu
      Research
      • Events
        Back to menu
        Events
        • CoinDesk: Policy & Regulation
        • Consensus Hong Kong
        • Consensus Miami
      • Sponsored
        Back to menu
        Sponsored
        • Thought Leadership
        • Press Releases
        • CoinW
        • MEXC
        • Phemex
        • Advertise
      • Videos
        Back to menu
        Videos
        • CoinDesk Daily
        • Shorts
        • Editor's Picks
      • Podcasts
        Back to menu
        Podcasts
        • CoinDesk Podcast Network
        • Markets Daily
        • Gen C
        • Unchained with Laura Shin
        • The Mining Pod
      • Newsletters
        Back to menu
        Newsletters
        • The Node
        • Crypto Daybook Americas
        • State of Crypto
        • Crypto Long & Short
        • Crypto for Advisors
      • Webinars
        Back to menu
        Webinars
        Select Language
        English enEspañol esFilipino filFrançais frItaliano itPortuguês pt-brРусский ruУкраїнська ukDeutsch deNederlands nl한국어 ko中文 zh