Top

KISA to establish blockchain trust framework for public services

Policy & Regulation·November 16, 2023, 9:21 AM

The Korea Internet & Security Agency (KISA) is developing a system called the Korea-Blockchain Trust Framework (K-BTF) to facilitate the development and operation of blockchain-based public services, said Lee Kang-hyo, a senior official at KISA, during the 2023 Blockchain Grand Week on Wednesday (local time).

Blockchain Grand Week is an event hosted by the Ministry of Science and ICT and jointly organized by the National IT Industry Promotion Agency (NIPA), the Korea Internet and Security Agency (KISA) and the Institute of Information and Communications Technology Planning and Evaluation (IITP) to promote the value of blockchain technology in enhancing trust in the digital age.

Photo by Philipp Katzenberger on Unsplash

 

Previous roadblocks

KISA has executed over 100 blockchain pilot projects over the last five years, but only a few have been carried out due to significant costs and interoperability barriers between services. According to the agency, it costs KRW 450 million (approximately $348,000) to carry out one project. Therefore, it has shifted its focus to making development easier and supporting data interoperability between services.

“Developing blockchain-based public services entails building a blockchain platform, developing services and connecting them with government legacy systems,” Lee explained. “Blockchain developer APIs are becoming standardized overseas, and we thought it was time for us to leverage such advantages as well.”

Another challenge was that previous blockchain-based public or governmental services did not offer smooth user experiences (UX), often requiring the installation of separate wallets or applications with each use.

 

Bringing cost-efficient, user-friendly public blockchain services

To address these issues, KISA decided to focus on three key areas for building K-BTF — cost reduction, convenient development and usability — with an overall groundwork that covers interfaces, services and security while minimizing intrusion into the private sector.

Once the K-BTF is established, government agencies will be able to easily plan and operate blockchain-assisted services such as decentralized identifiers (DIDs) and non-fungible tokens (NFTs). The costs for development will be determined based on how much a given service is used instead of the original base cost of KRW 450 million.

Also, public institutions tend to go through staffing changes quite often, and building services under K-BTF will enable governmental operations to run normally without any roadblocks or inconveniences caused by such changes.

Lee went on to mention that although a wide array of services can be built on the framework, there will be basic requirements in terms of functionality, performance and security that must be fulfilled for a service to run on it. To verify this, the KISA established a testing and certification system that utilizes its Cloud Security Assurance Program (CSAP) certification system and the Information Security Management System (ISMS).

To improve usability, the framework will require users to install only one digital wallet that stores digital forms of identification and various authentication certificates.

The KISA is set to start working on the K-BTF next year. Notably, it plans to create a governance system consisting of government agencies — those that are the demand clients for the framework –, private corporations and related experts. Six core services that will employ K-BTF have already been selected after a review of 34 pilot projects proposed in 2021 and 2022 and major national blockchain projects from six overseas countries. These six services are NFTs, DIDs, data origin authentication, data history tracking, Blockchain as a Service (BaaS) and digital wallets.

Lee emphasized that the goal of the K-BTF is to derive services that can be used by the public sector within regulatory and technological boundaries.

More to Read
View All
Web3 & Enterprise·

Nov 23, 2023

Me2on launches P2E game ‘Solitaire Crypto War’ with crypto integration

Me2on launches P2E game ‘Solitaire Crypto War’ with crypto integrationMe2on, a Seoul-based game developer, revealed the launch of its new game, Solitaire Crypto War, a play-to-earn (P2E) tournament game developed internally and published by its subsidiary, Memoriki. This Android game will be available globally, excluding South Korea and China. Memoriki, established in 2009 and originally based in Hong Kong, was acquired by Me2on earlier this year, broadening Me2on’s reach in the gaming market.Photo by Erik Mclean on UnsplashPVP card gameSolitaire Crypto War, developed from Me2on Group’s Solitaire IP, is a card puzzle player-versus-player (PVP) game that has amassed over 130 million global downloads. Players can engage in the classic Solitaire game against multiple opponents, competing to achieve the fastest clear times. The game ensures fair competition by matching players under identical conditions, with the highest scorer emerging as the winner. Designed for fast-paced gameplay, it pairs players of similar skill levels. Additionally, each season introduces unique events like puzzle piece collecting, Monopoly, and Powerball games, offering various rewards.Available in both free and paid optionsSolitaire Crypto War is a free game, but it also offers a feature where users can opt to use cryptocurrencies like ETH, USDT, USDC, UNI, LINK, MATIC and MEV to participate in competitions against other players and win prizes. The game boasts a variety of modes, including PVP battles, challenges and tournaments, enhancing its appeal. Additionally, its integration with Face Wallet enables users to log in using their social accounts, eliminating the need for a separate wallet installation, thus simplifying the gaming experience.Event running until Dec 28In celebration of the official launch of Solitaire Crypto War, Me2on has planned an opening event running until Dec. 28, providing various benefits to its users. Everyone accessing the game during this event period will receive a welcome package. Additionally, players can engage in various activities such as the game review challenge, ticket triumph challenge, and community quest takedown to receive items daily, enhancing their gaming experience and rewarding their participation.Cho Choong-hyeon, who leads Me2on’s Blockchain Game Division, expressed that the company has integrated blockchain technology to bring the classic card game Solitaire into the Web3 realm. He emphasized that this move allows Solitaire to evolve into a play-to-own (P2O) game, where users can directly own their gameplay achievements. Cho also highlighted Me2on’s dedication to being at the forefront of the Web3 market, which he believes is set to transform the paradigm of the gaming industry.

news
Web3 & Enterprise·

Sep 27, 2023

Crypto Exchange HTX Reports $8 Million Hack Over Weekend

Crypto Exchange HTX Reports $8 Million Hack Over WeekendCrypto exchange HTX confirmed on Monday that it fell victim to a hack over the weekend, resulting in losses amounting to 5,000 ETH ($8 million).HTX stakeholder Justin Sun, Founder of layer one blockchain TRON, disclosed the breach via an X post. In a series of subsequent X posts, Sun assured users and stakeholders that the exchange had promptly covered the losses, and current user deposits remained secure. He also emphasized that the platform was operating normally despite the security incident.Photo by GuerrillaBuzz on UnsplashHacker incentiveThe TRON Founder also extended an offer to the hacker responsible for the breach. He proposed a 5% reward for the return of the remaining funds, a figure notably lower than the 10% often offered to hackers in similar situations. Additionally, Sun dangled the possibility of a job at the exchange. That’s an unusual response to a cryptocurrency hack and one that had one commentator speculating upon the notion that the hacker belonged to the notorious North Korean Lazarus hacking group, pondering the prudence of such a move.Data from DeFi data aggregator DeFiLlama revealed that Seychelles-based HTX, formerly known as Huobi, witnessed nearly $10 million in outflows, with a remaining $2.73 million in customer deposits as of the latest data.Hacker’s identity may be knownThe hacker, who received a series of messages from an address identified as an HTX hot wallet by Nansen, was presented with a stark choice. The messages, written in both English and simplified Chinese, claimed to have uncovered the hacker’s true identity and urged the return of the stolen funds to the address 0x18709E89BD403F470088aBDAcEbE86CC60dda12e. In return, HTX offered a 5% “white hat bonus” valid until October 2, 2023. If the funds were not returned by that date, law enforcement would be involved, the message warned.The hack came shortly after Justin Sun shared a promotional video in which he depicted himself defeating a hooded figure symbolizing a hacker “shorting crypto” with a single punch while on a spaceship journey to what appeared to be Mars.Insolvency fearsOn Tuesday, Sun outlined that the exchange had established a “SAFU” (Safe Asset Fund for Users) fund for platform users. However, taking to X on Monday, Adam Cochran, Managing Partner at Cinneamhain Ventures, claimed that there was a likelihood that the HTX business is insolvent. Cochran maintains that available data suggests a shortfall in crypto holdings relative to HTX users' assets.Travis Kling, Founder and Chief Information Officer of Ikigai Asset Management, went one further on X, stating:”Not “probably”. Huobi is insolvent.”Kling, a long-time critic of Binance, went on to suggest that if Huobi were to collapse, that event would likely lead to Binance unraveling also.HTX originated in China and nowadays maintains offices in Singapore, Japan, South Korea, Hong Kong, and the UK. It has long been speculated that Justin Sun has a controlling stake in the HTX business. Sun has denied that assertion, instead suggesting that he is a member of HTX’s “Global Advisory Board.”

news
Policy & Regulation·

Feb 02, 2024

Singapore police suggest hardware wallets to combat malware

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks. The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.Photo by Junrui Wu on UnsplashDrainer-as-a-service threatOf particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider. The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers. Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization. MS Drainer and Inferno DrainerWhile no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023. Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November. In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days. Hardware walletsTo counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers. In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem. As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.  

news
Loading