Back to Glossary

DDoS Attack

DDoS Attack Definition: A DDoS (distributed denial-of-service) attack is an attempt to make a website, server or network unavailable by flooding it with traffic from many compromised devices at once. The target does not get hacked in the usual sense; it simply runs out of bandwidth, memory or processing capacity, so real users cannot get through.

What Is a DDoS Attack?

Picture a shop whose entrance fills with thousands of people who have no intention of buying anything. Real customers can’t get in, and the shop loses business without a single item being stolen. That is what a denial-of-service attack does to an online service.

The “distributed” part is what makes it hard to stop. Instead of one computer sending junk requests, an attacker controls a botnet, a network of thousands or millions of infected devices such as home routers, cameras and servers. Because the traffic comes from everywhere, the target can’t simply block one address.

In October 2016, the Mirai botnet, built largely from hijacked cameras and routers, hit the DNS provider Dyn. Sites that relied on Dyn, including Twitter, Netflix and Reddit, became unreachable for large parts of the United States for hours, even though none of them was attacked directly.

How Does a DDoS Attack Work?

Every online service has a ceiling: a maximum amount of data its network link can carry and a maximum number of requests its servers can answer. A DDoS attack pushes traffic past that ceiling. Once the pipe or the servers are full, legitimate requests queue, time out or get dropped.

Attackers often multiply their firepower with amplification. They send small requests to public servers, such as DNS or memcached servers, while faking the victim’s IP address as the sender. The servers send much larger replies to the victim, so a modest botnet produces a flood many times its own size.

Consider an attacker with 1 Gbps of outgoing capacity who uses a service with a 50x amplification factor. The victim receives about 50 Gbps of traffic. If the victim’s connection is rated at 10 Gbps, four-fifths of the incoming data cannot even arrive, and real customers’ requests are lost in the flood.

Amplification produced one of the largest recorded attacks. In February 2018, GitHub absorbed a 1.35 Tbps flood that abused misconfigured memcached servers, and it stayed online only by routing traffic through a mitigation provider that filtered out the junk.

Types of DDoS Attacks

Volumetric attacks fill the target’s bandwidth with raw data, often through amplification. Their size is measured in gigabits or terabits per second.

Protocol attacks exhaust the resources of servers, firewalls or load balancers by abusing how connections are opened. A SYN flood, for example, starts thousands of connections and never finishes them, leaving the server holding open slots.

Application-layer attacks send requests that look legitimate, such as repeated logins or price queries, to the most expensive parts of a website. They need far less traffic, which makes them harder to tell apart from real users.

Network-level spam is the blockchain version. Attackers submit huge numbers of cheap transactions to fill the mempool and crowd out real ones. In September 2021, bots flooded Solana with transactions during a token launch, and the network stopped producing blocks for about 17 hours.

DDoS Attack vs. Hack

DDoS Attack Hack (Intrusion)
Goal Block access Steal data or funds
Method Overwhelm with traffic Exploit a vulnerability or credentials
Effect on funds None directly Can drain wallets and accounts
Duration Ends when the flood stops Damage is often permanent

Why Is a DDoS Attack Important for Traders?

An outage at the wrong moment can cost more than the attack itself. Attackers often strike during sharp price moves, when exchange traffic is already high. If a centralized exchange goes offline, you cannot close a position, move collateral or cancel an order while the market keeps moving elsewhere.

For leveraged traders, that gap can decide the outcome. A position that could have been cut during the outage may reach its liquidation price before the platform comes back. Stop orders held on the exchange’s servers help only if the matching engine keeps running, so outage risk is one reason traders keep collateral buffers above the minimum.

On blockchains, spam attacks raise costs instead of shutting doors. A flooded network pushes up the transaction fee needed to get included in a block, and on chains with low fees, validators can struggle to process the backlog at all.

Mitigation has limits. Filtering services and spare capacity absorb most attacks, but application-layer floods can still slip through because they look like real users. Some attackers also send ransom notes threatening a DDoS unless paid, which turns the attack into an extortion tool.

Key Takeaways

  • A DDoS attack makes a service unavailable by flooding it with traffic from many compromised devices, not by breaking into it.
  • Botnets and amplification let attackers generate floods far larger than their own capacity, which is why a single source can’t simply be blocked.
  • Attacks target bandwidth, connection handling or the application itself, and blockchains face a version built on transaction spam.
  • For traders, the main danger is losing access during volatile markets, when open positions cannot be managed.
  • A DDoS attack does not steal funds directly, but it can be combined with extortion or used as a distraction for a real intrusion.
FAQ section

Can a DDoS attack steal my crypto?

Not by itself. A DDoS attack blocks access rather than breaking into accounts, but attackers sometimes use one as a distraction while they attempt a separate intrusion.

Can a blockchain be hit by a DDoS attack?

Yes, although it looks different. Attackers flood the network with cheap transactions or requests, which can clog the mempool, raise fees or, on some chains, stall block production.

What is the difference between DoS and DDoS?

A DoS attack comes from one machine, so the target can block it by filtering a single source. A DDoS attack comes from thousands of machines at once, which makes simple blocking useless.

How long does a DDoS attack last?

Most last minutes to a few hours, though some campaigns run for days. Duration depends on how long the attacker keeps paying for or controlling the botnet and how fast the target's defences adapt.

FATF
FATF Definition: The Financial Action Task Force (FATF) is a...
KYC/AML Compliance
KYC/AML Compliance Definition: KYC/AML compliance is the set...
Malware
Malware Definition: Malware (malicious software) is any prog...
MiCA Regulation
MiCA Regulation Definition: The MiCA Regulation, formally Re...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.