Finance Magnates met with cyber security expert Alex Heid to talk about threats and protection.
Photo: Bloomberg
The cryptocurrency market is gaining traction in the financial industry as the price of Bitcoin goes through the roof and attracts more and more public interest. Now even institutional players have hopped on the bandwagon.
These dangerous occurrences not only affect the pockets of customers and the reputations of firms - they undermine the stability of the entire crypto market.
Therefore, we approached two leading cyber security specialists who have special expertise in the Blockchain industry. They provided us with the answers to all the questions that you didn’t know how to ask.
In the second of two interviews, Finance Magnates sat down with Alex Heid, white hat hacker and chief research officer at SecurityScorecard – a leading cybersecurity rating and monitoring platform.
What are the security measures that large crypto exchanges should undertake to prevent hacks / attacks and are they doing that?
Alex Heid
A centralized repository of large volumes of BTC that belong to the platform users. Attacks against centralized repositories of Bitcoin storage have been commonplace as long as the concept of cryptocurrency has been around. Emerging technologies that handle data of significant value is likely to be targeted by malicious individuals seeking to take advantage of weaknesses in order to steal.
It is recommended that companies retain some form of insurance coverage as well to cover any losses that may take place. Insurance providers will oftentimes require this cold wallet storage methodology as well, as a way to mitigate the risk of a catastrophic event that would requires an excessively large payout.
What should a company do when it finds that it has been hacked (both from the service provider side and the user side)?
It is important for a service provider to immediately notify users of the breach so that they can take basic precautions against followup attack - such as changing passwords and implementing 2 factor authentication controls. The service provider must also attempt to identify the indicator of compromise (IoC) that lead to the breach, remediate the vector and implement mitigating controls to prevent future similar incidents.”
Taking the NiceHash case as an example, is there any way to retrieve the money?
No. The nature of cryptocurrency means once coin is transferred into another wallet, it's gone. There is no way to retract a transaction on the Bitcoin network. Users who were affected by the Nicehash breach are still technically owed their pending payouts for mining efforts, and the Nicehash company is the one responsible to ensure all debts owed are paid in full despite the loss of their wallet.
What are DDOS attacks? How do they differ from other hacks? Are they typical of blockchain-based products?
DDoS attacks against Bitcoin exchanges have been a tactic used in previous years as a way to manipulate the marketplace to game favorable buying/selling conditions for the attackers. In the early days of Bitcoin, the now defunct Mt. Gox exchange would come under attack frequently as attackers would use DDoS as a way to 'freeze' market prices, either low or high depending on the motivation of buy or sell. In recent times, it has been reported that the majority of Bitcoin themed websites experience a DDoS attack of some sort. Motivations for the attacks are varied, but are still revolve around the primary original motivations of a standard DDoS: extortion, revenge, and/or market manipulation.
There is a claim that some exchanges are using hacks as an excuse to make up for infrastructure problems or other flaws in their systems. Is there any basis to those claims?
This idea has been floated in the past, both for exchanges that claim losses from a hack, as well as for illegal darknet marketplaces that suddenly disappear without warning. Users are oftentimes frustrated by their losses and this allows for unfounded speculation and paranoia run amok in the various comment threads of Twitter, Reddit, and similar social media outlets. While the scenario of a fake hack to provide a cover story for an 'inside job' heist of cryptocurrency is plausible as human nature does allow for 'cut and run' behavior - it has not been proven that this is the case with the Nicehash breach or similar exchange shut downs.”
The cryptocurrency market is gaining traction in the financial industry as the price of Bitcoin goes through the roof and attracts more and more public interest. Now even institutional players have hopped on the bandwagon.
These dangerous occurrences not only affect the pockets of customers and the reputations of firms - they undermine the stability of the entire crypto market.
Therefore, we approached two leading cyber security specialists who have special expertise in the Blockchain industry. They provided us with the answers to all the questions that you didn’t know how to ask.
In the second of two interviews, Finance Magnates sat down with Alex Heid, white hat hacker and chief research officer at SecurityScorecard – a leading cybersecurity rating and monitoring platform.
What are the security measures that large crypto exchanges should undertake to prevent hacks / attacks and are they doing that?
Alex Heid
A centralized repository of large volumes of BTC that belong to the platform users. Attacks against centralized repositories of Bitcoin storage have been commonplace as long as the concept of cryptocurrency has been around. Emerging technologies that handle data of significant value is likely to be targeted by malicious individuals seeking to take advantage of weaknesses in order to steal.
It is recommended that companies retain some form of insurance coverage as well to cover any losses that may take place. Insurance providers will oftentimes require this cold wallet storage methodology as well, as a way to mitigate the risk of a catastrophic event that would requires an excessively large payout.
What should a company do when it finds that it has been hacked (both from the service provider side and the user side)?
It is important for a service provider to immediately notify users of the breach so that they can take basic precautions against followup attack - such as changing passwords and implementing 2 factor authentication controls. The service provider must also attempt to identify the indicator of compromise (IoC) that lead to the breach, remediate the vector and implement mitigating controls to prevent future similar incidents.”
Taking the NiceHash case as an example, is there any way to retrieve the money?
No. The nature of cryptocurrency means once coin is transferred into another wallet, it's gone. There is no way to retract a transaction on the Bitcoin network. Users who were affected by the Nicehash breach are still technically owed their pending payouts for mining efforts, and the Nicehash company is the one responsible to ensure all debts owed are paid in full despite the loss of their wallet.
What are DDOS attacks? How do they differ from other hacks? Are they typical of blockchain-based products?
DDoS attacks against Bitcoin exchanges have been a tactic used in previous years as a way to manipulate the marketplace to game favorable buying/selling conditions for the attackers. In the early days of Bitcoin, the now defunct Mt. Gox exchange would come under attack frequently as attackers would use DDoS as a way to 'freeze' market prices, either low or high depending on the motivation of buy or sell. In recent times, it has been reported that the majority of Bitcoin themed websites experience a DDoS attack of some sort. Motivations for the attacks are varied, but are still revolve around the primary original motivations of a standard DDoS: extortion, revenge, and/or market manipulation.
There is a claim that some exchanges are using hacks as an excuse to make up for infrastructure problems or other flaws in their systems. Is there any basis to those claims?
This idea has been floated in the past, both for exchanges that claim losses from a hack, as well as for illegal darknet marketplaces that suddenly disappear without warning. Users are oftentimes frustrated by their losses and this allows for unfounded speculation and paranoia run amok in the various comment threads of Twitter, Reddit, and similar social media outlets. While the scenario of a fake hack to provide a cover story for an 'inside job' heist of cryptocurrency is plausible as human nature does allow for 'cut and run' behavior - it has not been proven that this is the case with the Nicehash breach or similar exchange shut downs.”
First-Ever Prediction Market ETFs Let You Invest in Election Outcomes
Featured Videos
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.