Top

Kronos Research experiences significant cybersecurity breach

Web3 & Enterprise·November 21, 2023, 12:16 AM

Kronos Research, a Taipei-based crypto trading, market making and venture capital firm, has found itself in the crosshairs of a cyber attack.

Photo by FLY:D on Unsplash

 

$25.6 million loss

Hackers gained unauthorized access to the company’s API keys, resulting in losses exceeding $25.6 million spread across various cryptocurrencies, prompting a concern within the crypto community.

The breach was detailed by the company in a social media post on the X platform on Saturday. That post read:

“In the interest of transparency Around 4 hours ago, we experienced unauthorized access of some of our API keys. We paused all trading while we conduct an investigation. Potential losses are not a significant portion of our equity and we aim to resume trading as soon as possible.”

 

On-chain sleuthing

Investigations by crypto community members have followed, led by blockchain researcher ZachXBT. ZachXBT is a well-known anonymous persona in the crypto space, having earned a reputation for uncovering hacks, scams and unethical practices within the crypto sector.

In this instance, ZachXBT uncovered a trail of transactions originating from a Kronos Research account. The meticulous execution of the cyber attack was evident in six transactions involving 2,780 ETH, 2,540 ETH (repeated twice), 2,636 ETH, 4.93 ETH and 2,507.52 ETH, all directed to addresses controlled by the hacker.

Kronos Research has followed up with a tweet thread on X, acknowledging the gravity of the situation and confirming losses of approximately $25.65 million in crypto assets. Despite the alarming figures, the company sought to reassure stakeholders by emphasizing that the losses represent a relatively small fraction of its total equity. In a commendable display of accountability, Kronos Research pledged to absorb all losses internally, shielding its partners from the financial ramifications of the breach.

The Taiwanese firm posted:

“Our team has been working round the clock to minimize the impact and resume trading operations, following a hacking incident that involved unauthorized access to our API Keys.”

 

Implications for Woo X

The operational repercussions were swift and impactful, with Kronos Research opting for a temporary suspension of all trading operations. This decision rippled through to Woo X, the affiliated Taipei-based exchange and liquidity provider created by Kronos, which temporarily blocked specific asset combinations due to liquidity concerns. Importantly, Woo X assured users of the security of their funds and later announced the resumption of spot and perpetual trading.

Looking forward, Kronos Research outlined its intention to resume trading operations in the coming days, contingent on favorable conditions.

The cyber attack on Kronos Research occurred against the backdrop of heightened cybersecurity concerns within the crypto space. According to blockchain security firm Certik, approximately $173 million was lost to crypto attacks in November alone. The Kronos Research breach follows on the heels of Poloniex’s $131 million hack, highlighting the persistent challenges faced by crypto platforms in securing user assets.

More to Read
View All
Policy & Regulation·

Oct 26, 2023

Korean Financial Authorities to Provide Support for Security Token Market

Korean Financial Authorities to Provide Support for Security Token MarketAmid growing calls for accelerating the growth of the emerging security token (ST) market, the South Korean government is preparing to introduce supportive measures. The security token market is powered by blockchain technology which allows fractional investment in real world assets (RWAs) such as real estate and artwork.Security tokens are digital assets that represent securities generated through a process called security token offering (STO). These tokens, backed by RWAs, can be traded similarly to traditional securities. Investors can use these tokens to obtain shares, voting rights, interest, or profits.Photo by Philip Jang on UnsplashSupport measures for security token IndustryNext month, the Financial Services Commission (FSC) will draw up support measures and policy improvement plans to bolster the nascent security token industry. An FSC representative mentioned that the agency intends to work with the National Assembly to finalize the legislation of security token-related bills by November. Furthermore, the government official said the FSC will actively seek input from industry stakeholders to formulate strategies for enhancing policies designed to promote the growth of the security token market.To align with the national objective titled “The Establishment of Digital Asset Infrastructure and Regulatory Framework,” the FSC revealed regulatory guidelines for security token issuance and distribution in February. These new guidelines are centered around the establishment of institutions responsible for account management and entities engaged in over-the-counter (OTC) trading. Subsequently, in July, lawmaker Yun Chang-hyun, a member of the National Assembly’s National Policy Committee, proposed a bill to amend the Electronic Securities Act and the Capital Markets Act with the aim of ensuring that these Acts are consistent with the new regulatory guidelines.Security token market’s growth potentialWith growing anticipation that the security token market could rival the size of the exchange-traded fund (ETF) stock market, securities firms, banks, and blockchain companies have been eager to carve out a niche for themselves since the start of the year. However, their progress has been hindered by a potentially extended period of higher interest rates in the US and the slow advancement of security token-related legislation. While these organizations tried to explore opportunities through the financial regulatory sandbox, their endeavors proved more or less fruitless. An official from a securities firm voiced concerns over the escalating costs of setting up security token infrastructure, especially with legislative delays.On this matter, the Korea Financial Investment Association (KOFIA) has emphasized the urgent need to pass security token legislation to clear up regulatory ambiguities. They’ve also called for measures to stimulate market growth, such as relaxing regulations related to token issuance and distribution and increasing investment caps.At a seminar hosted by the Korea Capital Market Institute, Ahn Hyuk, Head of the Platform Division at Korea Investment and Securities, highlighted that the rigorous review of security registration applications by the Financial Supervisory Service (FSS) might impede the security token market’s growth. Responding to this, Jang Young-shim, Head of the Corporate Disclosure Department at FSS, said that both the FSC and FSS will carefully listen to industry feedback, addressing a range of topics from regulatory relaxation to investor protection.

news
Policy & Regulation·

Apr 28, 2023

Hong Kong to Issue Digital Asset Licensing Guidelines in May

Hong Kong to Issue Digital Asset Licensing Guidelines in MayAccording to Hong Kong’s Securities and Futures Commission (SFC), the Commission will issue new guidelines for virtual asset exchanges within the Chinese autonomous special administrative region (SAR).© Pexels/Jimmy ChanSFC CEO Julia Leung made that announcement while speaking at an event in the city on Thursday, indicating that the guidelines are due to be released next month. Additionally the autonomous region intends to introduce a new licensing system from June 1 onwards, enabling the retail investors among Hong Kong’s populace to trade leading cryptocurrencies like Bitcoin and Ethereum.Hong Kong authorities had provided an insight into this approach back in February, when plans to provide retail access to digital assets were first set out. At the time, they outlined the need for retail customers to pass a knowledge test relative to digital assets or otherwise only being allowed to trade such assets once the customer had completed a certain level of training relative to digital assets, provided by a regulated crypto service provider.This latest announcement has arrived amid a backdrop of a series of recent indications that signify the intent of authorities in Hong Kong to make the autonomous region a major financial hub centered around digital assets.Leung articulated that the further development of this digital assets framework follows a consultation process that attracted more than 150 responses. Although virtual asset service providers (VASPs) will need to await the complete rollout of the licensing system, a handful of crypto businesses such as OSL and Hashkey, under the supervision of the Hong Kong regulator, have already started to offer their services.Crypto as propertyA Hong Kong court recently recognized cryptocurrency as property. The ruling emerged in a bankruptcy hearing pertaining to failed cryptocurrency exchange Gatecoin. In presiding over the case, Justice Linda Chan outlined that the autonomous region takes a broad view of what constitutes property. In finding crypto to meet the definition of property, she went on to clarify that it therefore has the capability of being held in trust.The finding has particular relevance in the crypto world right now given the consequences of an “in trust” custodianship of customer’s digital assets relative to numerous ongoing bankruptcy processes involving failed crypto businesses, and the pecking order of creditors in those instances, in their efforts to recover their digital assets.Positive approachWhile mainland China remains an adverse territory relative to digital assets, Hong Kong has taken to welcoming the sector and with that, enticing crypto firms to relocate to the autonomous region from the mainland. Leadership in the city has been making all the right soundings to demonstrate that it is actively trying to nurture the nascent sector.While recent months have seen the Biden administration in the United States attempt to close off banking from the crypto sector, in contrast, Hong Kong’s largest virtual bank, ZA Bank, was recently given permission to act as a settlement bank for regulated Web3 businesses located within Hong Kong.

news
Policy & Regulation·

Jul 18, 2023

MAS Offers Guidelines for Banks Handling Crypto-Related Clients

MAS Offers Guidelines for Banks Handling Crypto-Related ClientsThe Monetary Authority of Singapore (MAS) has released a comprehensive set of guidelines to assist banks in managing clients who are involved in digital assets, such as cryptocurrency exchanges or individuals whose wealth is derived from cryptocurrencies.Photo by Meriç Dağlı on UnsplashIndustry working groupAccording to a report in local media source, The Straits Times, these non-mandatory guidelines, developed by an industry working group, aim to provide best practices for financial institutions to address concerns related to money laundering, terrorism financing, and sanctions risks associated with cryptocurrencies.The working group suggests that enhanced due diligence may be necessary for firms closely connected to facilitating crypto transactions. For instance, conducting site visits or walk-throughs of a client’s anti-money laundering and anti-terrorism financing processes and controls could be required.During the onboarding process, banks should request information documenting the customer’s crypto exposure and the intended usage of the account. Additionally, banks are advised to establish the source of the client’s funds or wealth.To evaluate the regulatory status of a merchant customer’s crypto-related counterparties, especially if they contribute significantly to the merchant’s transactions, banks should conduct thorough assessments.The working group also highlights the use of blockchain screening tools to review the on-chain activity of digital token payment service providers. Regular screening of new and existing wallet addresses owned or controlled by these providers against the sanctions list and designated wallets is also recommended.Comprehensive guidelinesLoretta Yuen, Head of Legal and Compliance at Oversea-Chinese Banking Corp (OCBC), a Singapore-headquartered bank, describes the guidelines as one of the most comprehensive in the world, providing insights into banks’ management of crypto-related money laundering, terrorism financing, and sanctions risks.She believes the guidelines will raise awareness among prospective customers regarding the key risk considerations banks prioritize and enable customers to proactively fulfill banks’ customer due diligence requirements during the onboarding process.Evy Theunis, DBS Bank’s Head of Digital Assets, views the guidelines as a codification of best practices across the industry, aligning with the bank’s existing protocols. United Overseas Bank (UOB) also acknowledges the benefits of the best practice paper, particularly given the diverse range of digital assets with varying levels of risk.Eight participating banksThe working group responsible for developing these guidelines includes representatives from eight banks, MAS, the Commercial Affairs Department, and Big Four audit firm Ernst & Young. Formed in August 2022 under the anti-money laundering and countering the financing of terrorism industry partnership (ACIP), the group aims to identify, assess, and mitigate money laundering and terrorism financing risks in Singapore through a collaborative private-public partnership involving the financial sector, regulators, law enforcement agencies, and other government entities.Singapore is vying to establish itself as a hub for digital asset business in Asia, alongside other centers such as Hong Kong. The Chinese autonomous territory has been making greater progress over the course of the past year.However, a report in The Wall Street Journal on Monday suggests that banking remains a difficulty for crypto businesses in Hong Kong. Hong Kong’s difficulty may be Singapore’s opportunity, given the work that this working group has carried out in smoothing the way for the banking of digital asset-related businesses.

news
Loading