‘Bitexlive’ Exposed Sensitive User Information to Site Visitors

  • Turkish crypto-exchange ‘Bitexlive’ has exposed highly sensitive user data to any visitor of the site.
  • The information comes from support tickets, so it includes PII, KYC documents, and other details.
  • The platform never responded to the reporters and hasn’t sent notifications to the exposed users.

Researchers from the CyberNews team have discovered a serious blunder on the Turkish cryptocurrency exchange platform ‘Bitexlive.’ Due to a configuration error, user support tickets were exposed to every visitor of the site via the socket, so depending on what the users exchanged with the support agents of the platform, the exposure level and severity varies. In most cases, though, the support tickets concern sensitive information that could be used to compromise the users.

Bitexlive offers 24/7 support, two-factor authentication, and secure storage, but the bug that CyberNews investigators found should be trivial for the website’s operators to discover and fix. When informed about it by the publication, they quickly proceeded to fix it, but never answered to the researchers to thank them or assure them that the userbase would be notified of what happened. This just adds another reason not to trust the platform, as the lack of transparency combined with a lack of security is a dangerous mix.

By looking at data samples, the researchers found the following things:

  1. The time of request
  2. Name of the ticket creator
  3. Email of the ticket creator
  4. Extra information, like Telegram handle or addresses
  5. Full text of the ticket
  6. Image locations (if attached)
Source: CyberNews

Of all the above, the “full text of the ticket” is the worst kind, as this is where highly sensitive PII and documents may be shared as “Know Your Customer” and identity validation proof. There, one could potentially find passports, national IDs, and driver’s licenses.

According to ‘CoinGecko,’ the daily trading volume on Bitexlive is estimated to about $19 million, so this is not a minor platform we’re talking about. Also, accessing the exposed data wouldn’t require amazing hacking skills, but only minimal technical data.

Thus, if you are a user of Bitexlive, you are advised to do the following:

  • Review your communication with the support team and determine if you have shared any sensitive information through this channel.
  • Set up an identity theft monitoring service that covers the dark web too.
  • Watch out for incoming phishing and scamming attempts via email, and don’t click on links and embedded buttons.

Read More:

REVIEW OVERVIEW

Latest

Intel Revises Manufacturing Process Development Roadmap and it Looks Promising

Intel declares ready to leave the ear of massive delays behind and finally get back on track.The American chipmaker promises to release...

Kazakhstan Blocks LinkedIn Over Illegal Casino Advertisements and Fake Accounts

Kazakhstan says LinkedIn violated its online advertisement rules and posted casino ads on the platform.For this reason and also for the existence...

Monero Bug May Have Exposed the Privacy of Transactions for a Small Number of Users

Monero transactions could be de-obfuscated thanks to a nasty bug in the decoy algorithm.The flaw affects transactions made quickly after a user...