Top

Kronos Research experiences significant cybersecurity breach

Web3 & Enterprise·November 21, 2023, 12:16 AM

Kronos Research, a Taipei-based crypto trading, market making and venture capital firm, has found itself in the crosshairs of a cyber attack.

Photo by FLY:D on Unsplash

 

$25.6 million loss

Hackers gained unauthorized access to the company’s API keys, resulting in losses exceeding $25.6 million spread across various cryptocurrencies, prompting a concern within the crypto community.

The breach was detailed by the company in a social media post on the X platform on Saturday. That post read:

“In the interest of transparency Around 4 hours ago, we experienced unauthorized access of some of our API keys. We paused all trading while we conduct an investigation. Potential losses are not a significant portion of our equity and we aim to resume trading as soon as possible.”

 

On-chain sleuthing

Investigations by crypto community members have followed, led by blockchain researcher ZachXBT. ZachXBT is a well-known anonymous persona in the crypto space, having earned a reputation for uncovering hacks, scams and unethical practices within the crypto sector.

In this instance, ZachXBT uncovered a trail of transactions originating from a Kronos Research account. The meticulous execution of the cyber attack was evident in six transactions involving 2,780 ETH, 2,540 ETH (repeated twice), 2,636 ETH, 4.93 ETH and 2,507.52 ETH, all directed to addresses controlled by the hacker.

Kronos Research has followed up with a tweet thread on X, acknowledging the gravity of the situation and confirming losses of approximately $25.65 million in crypto assets. Despite the alarming figures, the company sought to reassure stakeholders by emphasizing that the losses represent a relatively small fraction of its total equity. In a commendable display of accountability, Kronos Research pledged to absorb all losses internally, shielding its partners from the financial ramifications of the breach.

The Taiwanese firm posted:

“Our team has been working round the clock to minimize the impact and resume trading operations, following a hacking incident that involved unauthorized access to our API Keys.”

 

Implications for Woo X

The operational repercussions were swift and impactful, with Kronos Research opting for a temporary suspension of all trading operations. This decision rippled through to Woo X, the affiliated Taipei-based exchange and liquidity provider created by Kronos, which temporarily blocked specific asset combinations due to liquidity concerns. Importantly, Woo X assured users of the security of their funds and later announced the resumption of spot and perpetual trading.

Looking forward, Kronos Research outlined its intention to resume trading operations in the coming days, contingent on favorable conditions.

The cyber attack on Kronos Research occurred against the backdrop of heightened cybersecurity concerns within the crypto space. According to blockchain security firm Certik, approximately $173 million was lost to crypto attacks in November alone. The Kronos Research breach follows on the heels of Poloniex’s $131 million hack, highlighting the persistent challenges faced by crypto platforms in securing user assets.

More to Read
View All
Policy & Regulation·

Aug 22, 2023

Bitget Adopts Stricter KYC Measures in Line with Global Regulations

Bitget Adopts Stricter KYC Measures in Line with Global RegulationsBitget, the cryptocurrency derivatives exchange registered in Seychelles, has announced a significant update to its Know Your Customer (KYC) requirements.Announced via a blog post published to its website on Sunday, the move is aimed at enhancing user security and ensuring compliance with evolving global regulatory guidelines, joining other exchanges like KuCoin and OKX in tightening its KYC policies.Photo by Brett Jordan on UnsplashChanges taking effect in SeptemberStarting from September 1, Bitget will enforce level 1 KYC verification for all new users accessing its services, including depositing and trading digital assets. Existing users are also required to complete this level 1 verification by October 1. After this deadline, users who have not completed the verification will have limited functionality on the Bitget platform, including only being able to withdraw, cancel orders, redeem subscriptions, and close positions. They will be unable to initiate new trading orders.The KYC process involves verifying users’ identities and is commonly used by regulated entities to assess risk. Bitget emphasizes the importance of this verification process to maintain a secure trading environment and comply with regulatory recommendations.Following an industry trendBitget’s decision to reinforce its KYC standards aligns with the broader trend observed across the cryptocurrency exchange landscape. In the wake of increased regulatory scrutiny earlier this year, many exchanges have taken steps to strengthen their verification procedures. KuCoin, for instance, introduced mandatory identity checks in July to align with global Anti-Money Laundering (AML) regulations. Similarly, OKX is implementing a KYC process for identity verification, with a deadline also set for September.As regulatory frameworks evolve worldwide, cryptocurrency exchanges are under increased pressure to align with stricter standards. Bitget’s decision to enhance its KYC measures signifies its intention to maintain a secure and compliant trading environment for users, and to appease global regulators. This announcement follows a series of proactive steps taken by the exchange this year, indicating its dedication to navigating the changing regulatory landscape and promoting user security.Bitget has made headlines throughout the year for various developments, including the inclusion of Liquid Staking Derivatives (LSDs) as a margin option for crypto futures customers. As recently as last week, the platform garnered attention within the crypto sector, having gotten itself embroiled in a legal dispute with crypto influencer Evan Luthra.Earlier this year the platform acquired the Singapore-based BitKeep cross-chain wallet business. It’s believed that acquisition has assisted the company in achieving further growth in 2023, with 20 million users.Bitget invested $10 million in Fetch.ai, an artificial intelligence platform, and launched a referral program to expand its user base. Moreover, Bitget’s collaboration with comedian Adam Devine for a promotional campaign underscored its innovative marketing strategies.Bitget’s adoption of stricter KYC measures reflects the broader trend of exchanges bolstering their verification procedures in response to global regulatory changes. As regulatory expectations continue to evolve, exchanges worldwide are revisiting their policies to ensure a secure and trustworthy trading environment for their users.

news
Policy & Regulation·

May 28, 2024

UAE agency applies fines amid ban on crypto mining on farms

The Abu Dhabi Agriculture and Food Safety Authority has announced a ban on cryptocurrency mining on farms, addressing concerns over the misuse of agricultural land.Photo by Kamil Rogalinski on UnsplashClaims of farm misuseAccording to the Khaleej Times, the Authority has informed UAE farmers that their lands are not to be used for Bitcoin and crypto mining. This activity is deemed a “misuse of the farm for purposes other than its intended use.” The new regulation aims to preserve the primary agricultural function of these lands and imposes penalties of up to 10,000 United Arab Emirates Dirhams (approximately $2,722) for violations. Cryptocurrency mining requires significant computational power and electricity, which conflicts with the farms’ intended agricultural use.  Broader support for miningDespite this specific restriction, the United Arab Emirates (UAE) maintains a supportive stance towards cryptocurrency and cryptocurrency mining beyond a farm setting. In 2023, the country emerged as a notable player in the global Bitcoin mining industry, with a combined mining capacity of around 400 megawatts, contributing approximately 4% of the global Bitcoin hash rate. It’s proven to be a popular place in which to locate a mining facility as the country has a robust infrastructure. Stable power is essential in order for miners to be able to run their machines in a sustainable manner. Additionally, the government has generally been supportive of the activity, fostering a conducive environment for both crypto and Bitcoin mining and blockchain technology more generally. Furthermore, the country occupies a strategic location at the crossroads of major trade routes. Regulatory clarity has also been provided by the authorities in the UAE with regard to how crypto mining activity is to be carried out. While this latest move against mining within a farm setting is a restriction, it still feeds into that overall framework of regulatory clarity and certainty. Attracting mining firmsGiven the aforementioned reasons in support of mining in the UAE, the Middle Eastern country continues to attract cryptocurrency mining firms.  In December of last year, a Dubai-headquartered Bitcoin mining company, Phoenix Group, struck a $380 million deal with Chinese mining equipment manufacturer MicroBT. That same month, the company was listed on the Abu Dhabi Securities Exchange (ADX). In May 2023, Abu Dhabi-based digital assets development company Zero Two entered into a partnership with North American crypto miner Marathon Digital with a view towards developing the region’s first large-scale crypto mining facility. Beyond mining, the location is also proving popular for crypto firms more generally. In May 2023, Chainalysis, a leading blockchain analytics company, established its regional headquarters in Dubai. Similarly, Blockdaemon, a provider of institutional infrastructure, expanded its operations in Abu Dhabi, facilitated by the Abu Dhabi Global Market (ADGM), a key financial regulator. Speaking at the Dubai FinTech Summit recently, Reece Merrick, Managing Director of enterprise blockchain company Ripple for the Middle East and North Africa (MENA) region, said that “the UAE has done a remarkable job in really putting itself in a position to be the global crypto hub.”

news
Web3 & Enterprise·

May 16, 2023

Japanese Firm Exec Underscores User Experience and Collaboration in Web3

Japanese Firm Exec Underscores User Experience and Collaboration in Web3Hiroshi Tsuruoka, the Chief Operating Officer (COO) of UNCHAIN, a Japanese company specializing in Web3 entertainment services, recently underscored the significance of unique experiences and collaboration in the Web3 space. He shared these insights during his conversation with Webmaster Forum, a platform offered by Japanese web content provider Impress Corporation.UNCHAIN, Tsuruoka’s employer, aims to assist companies in entering the Web3 sphere and developing entertainment services that offer users a secure and enjoyable experience. The company provides comprehensive support, including planning, development, and marketing, tailored specifically for the Web3 environment.Photo by Shubham’s Web3 on UnsplashImportance of content qualityDuring the interview, Tsuruoka said that Web3 seems to have lost some of its previous popularity in Japan. Initially, the market experienced rapid growth driven by highly speculative products like NFT artworks and Play to Earn (P2E) games, which attracted participation from many Japanese companies. However, the subsequent downturn of global projects prompted the Japanese blockchain industry to reassess its strategy, recognizing the paramount importance of content quality.Meaningful experiencesAccording to Tsuruoka, the appeal of blockchain games extends beyond their profit potential, deriving more from the unique, enjoyable experiences they offer. He believes that gamers find it meaningful when they play a pivotal role in expanding the gaming market and giving rise to new gaming cultures. Moreover, the incorporation of NFTs in games allows users to retain ownership of their in-game items even if a company discontinues its service, fostering a deeper emotional connection between users and their virtual possessions.This emerging trend fosters a culture of creation, where users, operators, and creators come together in a collaborative space to generate secondary creations and new services. Users delight in actively contributing to this ecosystem and helping it grow.Tsuruoka recognizes that decentralization presents both advantages and challenges. On one hand, it offers individuals greater freedom. However, it also places the full responsibility of data management on the users themselves, in contrast to a centralized environment where the game provider handles data management.Tsuruoka advises against placing excessive emphasis on speculation and financial gain when discussing Web3. Instead, he encourages companies to prioritize delivering meaningful and valuable experiences to users. Tsuruoka believes that emotional experiences, such as owning a distinctive avatar through digital assets, hold tremendous potential in the Web3 realm.Web2 success firstHe asserts that no Web3 project can guarantee success without proving its worth in the Web2 space. Services that proved valuable in Web2 could experience significant growth when combined with Web3 elements.Strong relationshipsTsuruoka highlights the importance of establishing strong relationships between companies and users in the Web3 environment. While platforms like Discord can facilitate these relationships, it is crucial to strategically design user engagement, motivation, and enjoyment before launching a service. Effective community management in the Web3 space requires deep user engagement, which entails ongoing and intensive communication between operators and users.Tsuruoka emphasized the need to heed user feedback. Regardless of the service type, incorporating user opinions and collaborating with them can result in significant community and project growth, with corresponding increases in asset values. He added that this is not limited to the Web3 domain.

news
Loading