Home / History / Boom, Bust, Build / Security wars
2017–2019

Security wars

SIM swaps, exchange hacks, bug bounties become survival tools.

Boom, Bust, Build

Story beats & cast

OPSECCold storageBug bounty platforms
Events
  • Coincheck hack
  • SIM swap crime wave
  • Bug bounty culture grows
Actors
  • Security researchers — Bounty hunters

Security wars

Attack surface explodes

SIM swaps: identity built on sand

By 2017, carrier support desks became the weak link. Attackers phished or bribed reps to port phone numbers, intercepted SMS 2FA, reset exchange logins, and drained accounts before victims noticed. KYC photos and recycled passwords made targeting easy; Telegram groups even advertised “fullz” and carrier insiders for hire. The FTC eventually issued SIM-swap warnings (guide here ↗), but attackers were already way ahead.

Victims learned that “my phone number = my identity” was a dangerous default. Hardware security keys, app-based TOTP, and removing SMS recovery flows started to replace text codes, but many platforms lagged—leaving a window where one support call could nuke a life’s savings.

Hot wallets under siege

Exchanges still held large hot-wallet balances for fast withdrawals. Coincheck (2018) lost ~\$530M in NEM after a malware-laced employee PC exposed keys; Zaif lost \$60M later that year; smaller venues saw similar hits. The pattern: ops shortcuts, unsegmented networks, and unsigned withdrawals approved by human habit. Coincheck’s breach report (news coverage ↗) became a case study for regulators.

Public block explorers made thefts obvious in real time—another stress test for incident response. Some exchanges froze trading, some socialized losses, others spun up “SAFU” style funds to reassure users they wouldn’t be made whole only in press releases.

Malware, fake apps, and clipboard hijacks

Mass-market malware evolved to watch for crypto addresses and swap them in the clipboard. Fake mobile wallet apps slipped into app stores. Browser extensions mimicked Metamask prompts. Seed phrase “backup tools” phished newcomers. The newfound retail audience meant attackers could scale petty theft while waiting for a big whale SIM swap to land.

“Security is a process, not a product.” — Bruce Schneier, reminding teams there’s no one-time fix

Hacks, swaps, and exploits

Exchange breaches and aftermath

Coincheck’s NEM hack set a record; BitGrail, Bithumb, and others joined the casualty list. Investigations exposed flat networks, signing keys on internet-connected machines, and approvals happening in Slack. Insurance was rare; regulators in Japan and elsewhere began on-site inspections and mandated cold-storage ratios.

QuadrigaCX’s collapse (2019) wasn’t a hack but showed another failure mode: custodial opacity. The alleged “lost laptop keys” story devolved into evidence of missing funds long before the founder died. Users realized solvency and key management are inseparable risks; the Ontario Securities Commission’s investigation report ↗ reads like a noir.

Smart contract bugs and thieves-for-hire

Even before DeFi summer, contracts failed loudly: Parity’s 2017 multisig freeze trapped \$150M in ETH; smaller ICO contracts leaked funds through reentrancy or owner takeovers. Whitehats raced blackhats; some exploits were quietly patched, others became public spectacles with on-chain messages between attacker and victim. Parity’s postmortem (archived here ↗) fueled the push for better patterns and audits.

Security firms like Trail of Bits, Zeppelin/Consensys Diligence, and PeckShield expanded audits; bug bounty platforms paid six-figure rewards. Yet many teams shipped unaudited code under token-sale deadlines, keeping the exploit pipeline full.

SIM swap playbooks and laundering

Attackers refined scripts: scrape social media for targets, SIM swap, reset email + exchange, drain to mixers, and cash out via OTC desks. Some used deepfake audio to impersonate executives and request “urgent” transfers. Law enforcement responded with RICO charges and carrier fines, but deterrence lagged.

Incident response grows up

Postmortems stopped being optional. Exchanges published timelines, listed addresses, and requested blacklist flags. Chain surveillance firms traced flows; some funds were clawed back, most weren’t. Insurance funds (Binance SAFU, BitMEX insurance) and risk engines became selling points. Users began to ask, “Show me your controls, not just your logo.”

Defense, insurance, and culture shifts

Hardware keys and layered auth

YubiKeys and Ledger/Trezor devices moved from niche to default. Exchanges added WebAuthn, device binding, and session/IP alerts. SMS codes got demoted; recovery flows demanded stronger proofs. “Not your keys, not your coins” reappeared as both slogan and threat model.

Withdrawal controls and geo-fences

Address allowlists, time-locked withdrawals, and per-asset limits reduced blast radius. Some platforms enforced manual reviews for large wires or blocked withdrawals to newly created addresses. Travel rule prep (recording sender/recipient info) doubled as anomaly detection.

Custody bifurcates: DIY vs. institutional

Retail users leaned toward hardware wallets and multisig services; institutions adopted qualified custodians (Anchorage, BitGo, Coinbase Custody) with SOC reports and insurance. Insurance underwriters demanded evidence of HSMs, key ceremonies, and segregation of duties—security became a sales requirement.

Proofs, audits, and transparency

Calls for proof-of-reserves resurfaced after each breach. A few exchanges published Merkle proofs and auditor attestations; others resisted, citing privacy. Wallet providers open-sourced clients and signing flows to earn trust. Users learned to prefer verifiable claims over marketing pages.

Cultural shift: paranoia as UX

Security messaging became onboarding: “save your seed,” “verify domains,” “use a hardware key.” It made UX feel harsher, but it trained a generation of users to expect adversaries. Communities shared breach reports and playbooks; conferences added security tracks; founders budgeted for audits as a default line item.

Legacy

This period burned in the idea that crypto security is never done. SIM swaps killed SMS 2FA. Hot wallet raids birthed cold-storage mandates. Insurance funds and bug bounties became the price of admission. The scars shaped today’s defaults: hardware-first custody, layered approvals, and public postmortems when things break.