Threat Bulletin 1097: GRE flood against a crypto exchange platform in the UK

On Saturday 10 May 2025 at 20:14 UTC, a GRE flood targeted a crypto exchange customer in the UK. The attack peaked at 239.4 Gbps and lasted 175 minutes. Traffic originated from 1866 autonomous systems in 90 countries, predominantly a Mirai-derived IoT botnet.

Vector GRE flood
Peak 239.4 Gbps
Duration 175 min
Time to mitigation 0.471 s
Attack traffic reaching origin 0.063%
Legitimate traffic challenged 0.41%

Timeline

The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 32 points of presence.

What the customer saw

A brief increase in p99 latency of 63 ms during the first minute, then normal service.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Enable authenticated origin pulls.
  • Review allow-listed partner ranges quarterly.

10 thoughts on “Threat Bulletin 1097: GRE flood against a crypto exchange platform in the UK”

  1. Carlos Horvat

    How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?

  2. Quentin Schmidt

    We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.

  3. How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top