On January 31, 2023, cybersecurity researchers at GrayNoise revealed a staggering escalation in attacks targeting Fortinet SSL VPN devices. More than 13.5 million login attempts had been recorded exploiting CVE-2022-42475, a heap-based buffer overflow vulnerability in FortiOS SSL-VPN that allows remote unauthenticated attackers to execute arbitrary code. The scale of the assault, coupled with a newly discovered zero-day in GoAnywhere MFT file transfer software, painted a sobering picture of the threat landscape facing enterprises and crypto businesses alike.
The Threat Landscape
The Fortinet VPN vulnerability, disclosed in December 2022, became one of the most aggressively targeted flaws in early 2023. By January 31, GrayNoise observed 13,513,728 login attempts against devices running vulnerable FortiOS versions. The vulnerability exists in the SSL-VPN web interface, which is typically exposed to the internet to enable remote access. This makes it an ideal target for attackers seeking initial access to corporate networks, including those of cryptocurrency exchanges, wallet providers, and blockchain infrastructure companies.
Simultaneously, security researchers warned that a zero-day vulnerability in Fortra GoAnywhere MFT, a managed file transfer solution used widely in enterprise environments, was being actively exploited. The flaw resided in the administrative web interface and could be leveraged for remote code execution through specially crafted requests. No patch was available at the time, leaving organizations reliant on the platform exposed. The combination of these two attack vectors created a particularly dangerous window for organizations handling digital assets.
Core Principles
Defending against these threats requires adherence to several fundamental security principles. The first is timely patching. CVE-2022-42475 had a patch available for weeks before the January spike in exploitation, yet many organizations had not applied it. The second principle is network segmentation. VPN appliances should not be directly exposed to the internet without additional protective layers such as web application firewalls or access proxies. The third principle is credential hygiene. Many of the 13.5 million attempts were brute force attacks relying on weak or default credentials.
For cryptocurrency businesses, these principles carry additional weight. A compromised VPN gateway can provide attackers with a foothold into internal networks where private keys, hot wallet credentials, and administrative systems reside. The FBI had just days earlier announced its takedown of the Hive ransomware operation, which had extorted over 100 million USD from more than 300 victims. That success, while significant, did not eliminate the underlying vulnerabilities that ransomware groups exploit to gain initial access.
Tooling and Setup
Organizations looking to strengthen their defenses should implement a multi-layered approach to VPN and remote access security. Start with an inventory of all internet-facing remote access points, including VPN appliances, remote desktop services, and file transfer platforms. Apply all available patches immediately and subscribe to vendor security advisories for critical infrastructure components. Deploy multi-factor authentication on all remote access systems, preferably using hardware tokens or authenticator apps rather than SMS-based codes which are vulnerable to SIM swapping.
Network monitoring tools should be configured to detect anomalous login patterns, such as the high-volume brute force activity seen in the Fortinet attacks. Rate limiting and account lockout policies can mitigate automated credential stuffing. For GoAnywhere MFT and similar platforms, restrict access to the administrative interface to trusted IP ranges and consider placing it behind a VPN or zero-trust network access solution until patches become available.
Ongoing Vigilance
Threat landscapes evolve rapidly. The GoAnywhere zero-day demonstrated that even fully patched systems can be vulnerable to newly discovered flaws. Organizations must maintain continuous monitoring, threat intelligence feeds, and incident response readiness. Regular penetration testing of external-facing infrastructure helps identify weaknesses before attackers do. Bitcoin was trading around 23,139 USD on this date, and the broader crypto market recovery was attracting renewed attention from both investors and threat actors.
The convergence of IT and operational technology in blockchain environments means that a vulnerability in a traditional enterprise tool like a VPN can have outsized consequences when it provides access to cryptocurrency infrastructure. Security teams at crypto firms must extend their visibility beyond blockchain-specific threats to encompass the full spectrum of enterprise vulnerabilities.
Final Takeaway
The Fortinet VPN siege and GoAnywhere zero-day serve as a reminder that the basics of cybersecurity still matter enormously. Patching promptly, enforcing strong authentication, segmenting networks, and monitoring for anomalous activity remain the most effective defenses against both opportunistic and targeted attacks. As cryptocurrency markets grow and attract more institutional capital, the security expectations placed on crypto businesses will only increase. Those who invest in foundational security practices today will be better positioned to weather the next wave of threats.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified professionals for specific guidance.
13.5 million brute force attempts on fortinet ssl vpn. if your exchange runs unpatched fortios your private keys arent safe
CVE-2022-42475 was disclosed in december and by february there were still unpatched production VPNs at crypto companies. patching culture in this space is genuinely broken
Kerem A. quarterly patch cycles while sitting on customer private keys. crypto companies treat security like an afterthought until they get hacked
13.5 million login attempts and people still wonder why hardware firewalls are not enough. patch your stuff people
CVE-2022-42475 was a heap overflow in SSL-VPN. that is as bad as it gets for perimeter devices exposed to the internet
kex_zero heap overflow in a VPN that sits between the internet and your internal network. RCE on the perimeter device is game over before any auth happens
kex_zero a heap overflow in an SSL-VPN web interface is basically a free root shell. Fortinet took weeks to patch and enterprises took months after that. 13M attempts shows how fast threat actors weaponize these
gorblxo 13.5M attempts is just automated scanning. the real danger is the 3 or 4 attackers who actually know how to exploit the heap overflow
CVE disclosed in December 2022 and still millions of unpatched devices a month later tells you everything about enterprise patching cycles
enterprise patching being this slow while 13M+ attempts pile up is exactly why zero trust architecture exists. VPNs are the new moat and moats are dead
Sanja P. zero trust being the answer is correct but most enterprises are years away from implementing it. in the meantime unpatched VPNs are the front door for every attacker including Lazarus
13.5M attempts and most orgs patch cycle is measured in weeks. if your exchange or wallet provider runs fortinet you should be asking hard questions right now
patch_me_ weeks is optimistic. i know Fortune 500 crypto exchanges that run quarterly patch cycles. 13M attempts and they still havent fixed it
quarterly patch cycles are optimistic for most orgs. fortune 500 crypto exchanges running fortinet with known CVEs is terrifying
crypto exchanges running unpatched fortinet VPNs in 2023 is genuinely terrifying. your private keys are only as safe as the weakest link in your infra
the goanywhere zero day mentioned alongside fortinet means attackers were hitting two different entry points at the same time. coordinated and deliberate targeting of enterprise infra
crypto exchanges sitting on customer funds behind unpatched fortios SSL-VPN in early 2023 is still insane to me. CVE was disclosed in december and february still had unpatched production boxes
heap overflow in the SSL-VPN web interface exposed to the internet. if your crypto exchange runs FortiOS from 2022 you should move your funds today
Sigrun E. the scary part is how many crypto exchanges were running FortiOS SSL-VPN exposed to the open internet. private keys behind a CVE-riddled VPN login
hp_hostler the number of crypto exchanges running SSL-VPN exposed to the open internet in 2023 was genuinely scary. zero trust was a buzzword nobody actually implemented
13.5M automated attempts is just internet background noise. the 3 or 4 sophisticated actors behind those scans are the actual threat and they only need one unpatched box
aleks is right that 13.5M attempts is mostly noise but the 3-4 actors behind it only need one unpatched fortinet box to reach the internal network. then its game over for any hot wallet on the exchange