How the Zillas Top Swap Database Breach Led to 3,775 Stolen Logins
HEROIC analysts found a database breach affecting Zillas Top Swap, a US-based cryptocurrency exchange platform for Zillas tokens, with a leak date of August 7, 2024. The incident exposed 3,775 records from the topswap.cash platform. The compromised data included email addresses, phone numbers, password hashes, usernames, and IP addresses — a combination that puts cryptocurrency holdings and linked accounts at direct risk.
For cryptocurrency users, the exposure of password hashes alongside usernames and email addresses is a serious threat. Unlike traditional bank accounts, transactions on cryptocurrency platforms are typically irreversible. An attacker who cracks a password hash and gains access to a Zillas Top Swap account can drain holdings with no possibility of recovery. IP addresses add another layer of risk: they reveal the approximate geographic location of users and can be used to craft geographically specific phishing lures or to identify VPN usage patterns that reveal a victim's identity.
What Was Exposed
- Email addresses
- Phone numbers
- Password hashes
- Usernames
- IP addresses
Why This Matters
Cryptocurrency account breaches carry a uniquely severe consequence: stolen funds cannot be reversed or recovered. Credential stuffing using cracked password hashes from this breach can unlock wallets, exchange accounts, and DeFi platforms wherever victims reused the same credentials. Phone numbers enable SIM swapping attacks, where criminals convince a mobile carrier to transfer a victim's phone number to an attacker-controlled SIM — giving them full access to SMS-based two-factor codes. IP address data helps attackers determine a victim's time zone and location, making social engineering calls more convincing and targeted.
How a Database Breach Works
A database breach occurs when an attacker bypasses an application's access controls and directly queries or exports the underlying data store. Common methods include SQL injection, exploitation of unpatched vulnerabilities, and use of stolen administrative credentials. Cryptocurrency platforms are high-value targets because their users hold liquid, transferable assets. Once a database is exported and password hashes are cracked offline using GPU-powered tools, attackers can attempt to log in to the platform and any other service where victims reused their credentials.
Check If You Are Affected
HEROIC's free scanner checks your email across more than 400 billion exposed records, including the Zillas Top Swap breach. Visit heroic.com to run a free search and find out whether your credentials are at risk.
Breach Breakdown
3,775 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds