600K Crypto Base Leak: 547,926 Logins Risk Wallet Takeover
A Stealer Log Aimed at Crypto Users Exposes 547,926 Logins
On December 14, 2022, HEROIC analysts identified a stealer log file, labeled "600K Crypto Base target," being shared by a user on Telegram. The file contained 547,926 records, each combining an email address with a plaintext password and the web address the login was used on. The name indicates the log was assembled or filtered specifically to target individuals connected to cryptocurrency activity, rather than being a general, unsorted dump.
Why This Is Dangerous
Because the passwords in this file are stored in plaintext, they can be used the instant someone opens the log, with no cracking required. When a stealer log is specifically curated around crypto users, the risk moves beyond typical account takeover, since it can lead directly toward exchange accounts and wallet services where real financial value is at stake. Attackers targeting this kind of list are often looking for one thing: a login that leads to funds they can move or drain.
What Was Exposed
- Email addresses
- Plaintext passwords
- Website login URLs tied to each credential
Why This Matters
A stolen login connected to crypto activity creates a chain of risk that can move quickly from one exposed password to a drained account. If someone reused an exchange or wallet password on an email account included in this log, an attacker could use that email to intercept password resets and two-factor codes, working their way toward the accounts that actually hold value. Beyond financial loss, victims can also face identity theft if personal details are pulled from compromised inboxes along the way.
How Stealer Logs Work
Logs like this one come from infostealer malware, which infects a device, often through a malicious download or phishing link, and quietly copies saved credentials out of the browser. Criminals frequently filter these collected credentials by keyword or platform, pulling out entries connected to specific interests, such as cryptocurrency, to create a more valuable, focused list. That filtered file is then shared or sold through Telegram channels or dark web marketplaces where other criminals can put it to use.
Check If You Are Affected
Given the crypto focus of this log and its size of nearly 548,000 records, checking your exposure is worth doing right away. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, to show you if your email address has been compromised. Run a free scan, and if you find a match, change that password immediately, especially anywhere connected to a crypto exchange or wallet, and enable multi-factor authentication wherever it is offered.
Breach Breakdown
547,926 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds