One Crypto Site, ShoppingBitcoins: 2,521 Plaintext Passwords Leaked
HEROIC analysts identified a data breach tied to ShoppingBitcoins, a US-based cryptocurrency shopping platform, dated September 28, 2015. The breach exposed 2,521 records, each containing an email address and a password. Notably, the passwords were stored and exposed in plaintext, meaning they were never hashed or encrypted.
Why Plaintext Passwords on a Cryptocurrency Site Are Especially Risky
On most platforms, a breached password still has to be cracked before it becomes useful to an attacker. That extra step does not exist here. Because ShoppingBitcoins stored these 2,521 passwords in plaintext, anyone who has this data can read each password exactly as the user typed it, with no cracking required. On a cryptocurrency-related site specifically, that raises the stakes, since accounts tied to crypto activity are often reused with other financial or wallet-related logins.
What Was Exposed
- Email addresses
- Passwords, stored and exposed in plaintext
Why This Matters
Because these passwords required no cracking, they are immediately usable in credential stuffing attacks, where criminals test known email and password pairs against other websites automatically. If any of these 2,521 people reused their ShoppingBitcoins password on an exchange, wallet, email account, or bank login, that account is directly at risk of takeover. Combined with an email address, a working plaintext password is one of the more dangerous things a breach can expose, since it removes every technical barrier between the leak and an attacker actually logging in somewhere.
How This Database Breach Happened
This incident is classified as a database breach, meaning the records were extracted directly from ShoppingBitcoins' stored user data rather than collected from individual devices. Storing passwords in plaintext is considered a serious security failure on its own, since it means that a single unauthorized access to the database instantly exposes every user's actual password, with none of the protection that proper hashing is designed to provide.
Check If You Are Affected
If you ever had an account on ShoppingBitcoins, it is worth finding out whether your email and password were part of this exposure. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, giving you an instant answer so you can change any reused passwords before someone else uses them first.
Breach Breakdown
2,521 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds