Categories: Uncategorized

Coinbase Merchant Error Causes Major Exploit on Overstock

Recently, it was made public that retail giant Overstock.com had fallen victim to a huge exploit involving Coinbase’s merchant API. This is another issue on top of many others that customers and businesses have made apparent affecting the leading Bitcoin exchange.

On January 5, independent researchers discovered a massive exploit in Overstock’s cryptocurrency payment gateway, which is offered through Coinbase’s merchant functionality. This exploit allowed Overstock customers to purchase items with Bitcoin Cash (BCH) instead of Bitcoin, which effectively resulted in an almost 85% discount.

The even greater issue that emerged was the ability to return purchases made with the discounted BCH and receive Bitcoin in return. Malicious users could pay for an order in Bitcoin Cash and be refunded an equal amount of Bitcoin. This exploit emerged when Coinbase first implemented Bitcoin Cash support on December 19, and existed for almost three weeks.

Coinbase claims that the bug emerged due to improper implementation of its merchant API by Overstock. According to the exchange, Overstock was the only partner out of dozens of merchants that experienced this issue. Furthermore, Coinbase stated that it worked alongside Overstock to solve the problem.

Related Post

However, Overstock’s statement contradicted Coinbase, asserting that the issue was entirely the fault of the exchange. The online retailer asserted that it had changed no code on its website, and that only Coinbase’s merchant API had been tweaked.

It is unclear to what extent this bug was exploited, if at all. However, if just one malicious user came across this bug during the time it existed, they would have the potential to steal hundreds of thousands or even millions of dollars worth of Bitcoin from the retailer.

Overstock.com represents one of the first major companies to support Bitcoin. Since 2014, it has accepted cryptocurrency as payment for any of its items. Additionally, Overstock accepts Ethereum, Litecoin, Monero, NEM, and Dash. Overstock’s CEO has been outspoken about cryptocurrency throughout this time period, and has even considered liquidating the retail portion of the business to fund blockchain-based ventures.

Since first accepting Bitcoin in 2014, Overstock has held onto a portion of its Bitcoin profits, seeing the coin rise from just a few hundred dollars to a high of US$20,000 during this time period. As an outspoken Bitcoin supporter, Overstock’s stock has also performed incredibly in conjunction with the ongoing cryptocurrency surge.

 

Zane Huffman

Zane is a crypto enthusiast who has been involved since August 2013. He is a trader and writer of all things cryptocurrency. He is very excited for the role cryptocurrency will play in the future, especially in regards to the videogaming industry.

Share
Published by
Zane Huffman

Recent Posts

The Calculated Collapse of $TG: How a “Utility” Token Was Engineered for a Rug Pull

In the unpredictable world of cryptocurrency, new tokens launch daily, each one a shining beacon…

23 hours ago

Staked Ethereum Hits Record High as Whale Accumulation Signals Bullish Long-Term Sentiment

Once more, Ethereum is commanding the spotlight as fresh figures indicate that the amount of…

23 hours ago

Arbitrum Sees Surge in Protocol Revenue and EIP-7702 Adoption Following ArbOS 40 Upgrade

The ecosystem on Arbitrum keeps flaunting its robust foundations, with a steady incline in the…

23 hours ago

Ethereum Whale Accumulation Surges as Long-Term Confidence Outweighs Short-Term Volatility

Once again, major market players are focusing on Ethereum. The whale activity surrounding the second-largest…

4 days ago

Week in AI: Fartcoin Steals the Spotlight Amid Market Turmoil

It has been a tumultuous week for the artificial intelligence sector in crypto. Sharp valuation…

5 days ago

BSC Foundation Resumes Strategic Accumulation: VIXBT, CAKE, LISTA, and MOOLAH Under Spotlight

Following a brief stint of dormancy, the BSC Foundation is back in action, reestablishing its strategic…

6 days ago