Top

Mixin Network Suspends Services Amid $200 Million Hack

Policy & Regulation·September 25, 2023, 11:56 PM

On Monday, Mixin Network, a decentralized peer-to-peer network whose project team is based in Hong Kong, officially confirmed a substantial security breach that resulted in the loss of approximately $200 million in crypto assets from its mainnet.

Photo by GuerrillaBuzz on Unsplash

 

September 23 hack

This incident, disclosed via an X (formerly Twitter) post, prompted the immediate suspension of all deposit and withdrawal services on Mixin Network until further notice.

The project team outlined that the hack occurred on September 23, exposing vulnerabilities that allowed malicious actors to compromise the database of a third-party cloud service provider. Mixin Network has taken action to address the situation, enlisting the expertise of Singapore-headquartered blockchain security investigator SlowMist and the support of Google to conduct a thorough investigation and formulate a recovery plan.

At the time of the breach, Mixin Network’s holdings included $94.48 million in Ether, $23.55 million in Dai, and $23.3 million in Bitcoin, as reported in an independent investigation by PeckShield. The total value of assets affected amounted to $141.32 million.

Cyvers, an Israeli Web3 security firm, has also been looking into the matter on Monday. In a social media post, the firm stated:

”Our internal investigation has uncovered suspicious funding transactions involving @MixinKernel hacker addresses. Two of hacker addresses received 51 $ETH from 0x1795F0eBDa5A836aE63F28CE546E72de069A8bd2 who was interacted with @HuobiGlobal and @binance.”

The firm goes on to call on Binance and its CEO Changpeng Zhao (CZ) and Huobi to help identify the wallet address in question.

 

Halting withdrawals

In response to the security breach, Mixin Network has temporarily halted all deposits and withdrawals on its platform. These services will only resume once the vulnerabilities have been identified and fully resolved. On X, the project stated:

”Deposit and withdrawal services on Mixin Network have been temporarily suspended. After discussion and consensus among all nodes, these services will be reopened once the vulnerabilities are confirmed and fixed. During this period, transfers are not affected.”

Details regarding the plans to recover the lost assets for affected users have yet to be announced.

Despite initial promises that Mixin Network’s Founder, Feng Xiaodong, would address the incident in a public Mandarin live stream on September 25, links to the live stream were not provided on the official social media channels or the website mixin.network.

The incident has garnered criticism on the basis of a lack of decentralization. One commentator stated:

”Some of those blockchain protocols are so decentralized that when their cloud database is hacked, coins are also gone.”

 

Ongoing hacks

This security breach on Mixin Network is the latest in a series of high-profile crypto-related incidents. Ethereum Co-Founder Vitalik Buterin recently fell victim to a SIM swap attack, which resulted in the compromise of his X (formerly Twitter) account.

In a statement, Buterin revealed that the hackers had successfully executed a SIM swap, a type of attack that targets the victim’s mobile phone number to gain unauthorized access to various online accounts, including social media, banking, and cryptocurrency platforms.

The repercussions of the Mixin Network hack underscore the ongoing challenges faced by the crypto industry in ensuring the security and protection of digital assets. As investigations continue, affected users await further developments and the eventual resumption of deposit and withdrawal services.

More to Read
View All
Web3 & Enterprise·

Jan 18, 2024

Bitget pledges $10 million to empower women in Web3

In a bid to foster gender diversity and inclusivity within the blockchain industry, cryptocurrency exchange Bitget has committed $10 million to invest in women-led startups in the Web3 and blockchain sector. Blockchain4HerThe announcement, made at the Web3 Hub Davos event on Tuesday, a part of the World Economic Forum 2024, highlights Bitget's initiative in promoting equality in a rapidly advancing sector. Bitget's research reveals a stark gender bias within the blockchain sector, with only 6% of startup funding directed towards female-led projects. Bitget’s Blockchain4Her project has been established as a direct consequence, in order to address this imbalance. Blockchain4Her has been designed to provide crucial support, mentorship and recognition to women in the industry. The initiative will include tailored incubation programs, pitch competitions exclusively for women-founded startups and the Women in Blockchain Summit & Awards, aimed at acknowledging outstanding achievements by women in the blockchain space. Recognizing the need for comprehensive measures, Bitget aims to confront the gender disparity by creating a nurturing environment through these multifaceted efforts. By offering specialized support for female entrepreneurs, the initiative aims to encourage greater involvement and leadership roles for women in the blockchain space.Photo by Shubham Dhage on UnsplashIndustry ambassadorsAs part of the Blockchain4Her program, Bitget plans to invite industry leaders to serve as ambassadors, supporting gender diversity in the blockchain industry. These ambassadors will play a crucial role in advocating, engaging and driving positive changes, fostering an inclusive environment for women in the blockchain sector. Bitget's commitment to addressing gender disparity in the blockchain industry is further underscored by its recent report on Web3 venture capital funding by gender. The report, published on Jan. 11, revealed that less than 7% of VC funding in the industry went to female-led startups, emphasizing the need for comprehensive measures to increase inclusiveness and accessibility for women in the blockchain sphere. The company is itself leading from the front on the issue, with Gracy Chen as managing director, one of the few crypto exchange platforms headed up by a female executive. Blockchain4YouthIt’s not the first time that the company has embarked upon a corporate social responsibility-themed project. It follows Bitget's earlier commitment to nurturing talent through the “Blockchain4Youth” initiative, which was announced in May of last year. The $10 million initiative set out to serve the objective of “empowering and inspiring younger generations to use Web3 and crypto tools to create and engage in a decentralized space.” It focuses on providing courses through Bitget Academy, hosting university lectures on Web3, incubating innovative projects by young entrepreneurs and organizing hackathons for individuals under 30 to identify promising leaders. A by-product of Blockchain4Youth also involved the company commencing to invest in Indian blockchain startups in November. Bitget's Blockchain4Her initiative represents a significant step towards fostering a more equitable blockchain space. By championing inclusion and diversity, Bitget not only contributes to a fairer industry but also supports the sustainability and growth of the broader technology sector. 

news
Policy & Regulation·

Nov 10, 2023

India tightens control with 3,000 police officials trained in crypto investigations

India tightens control with 3,000 police officials trained in crypto investigationsAs the crypto sector continues to develop, authorities continue to get to grips with the new crypto innovation, with India’s law enforcement being the latest entity to look to clamp down.Photo by Naveed Ahmed on UnsplashCrypto forensics and investigation trainingAccording to the Ministry of Home Affairs (MHA) annual report, a comprehensive training initiative was undertaken during the financial year 2022–2023. The initiative, spearheaded by the Narcotics Control Bureau and the Indian Cyber Crime Coordination Centre (I4C), equipped over 2,900 officials with essential skills in cryptocurrency forensics and investigation.Under the aegis of the Narcotics Control Bureau, India’s central law enforcement and intelligence agency, 141 officers underwent specialized training in the investigation of darknet activities, cryptocurrencies and other pertinent areas such as digital footprints.The report stated that workshops were set up that covered techniques for gathering intelligence and evidence from open sources and social media platforms, reflecting a commitment to staying ahead in the ever-evolving landscape of cybercrime.There’s clearly a need for this level of expertise, given an uptick in crypto-related scams in India and the broader Asia region as a whole in recent times. Earlier this week, it emerged that the Indian authorities had arrested eight individuals in relation to a $300 million cryptocurrency scam.Raj Kapoor, the founder of the India Blockchain Alliance (IBA), recently called for greater control when it comes to crypto-related illicit financing. Kapoor stated:”It is a kick on the backside for most governments. All regulatory bodies will take a closer look at crypto regulation. Governments will need to start implementing new rules and regulations.”I4C played a pivotal role in training over 2,800 cyber police officials. The training encompassed crypto forensics, investigations and emerging technologies like anonymization networks. The focus extended to addressing the misuse of mobile applications in the cyberspace realm.Ongoing blockchain tech adoptionAs India proactively prepares to combat potential crypto-related crimes amidst increased adoption, the nation is also delving into mainstream blockchain applications. In a recent stride towards digital transformation, Hindustan Petroleum (HPCL), the state-run oil and gas company, partnered with blockchain software firm Zupple Labs. Together, they launched a blockchain system designed to automate the verification of purchase orders (POs).HPCL’s spokesperson outlined the significance of this implementation to Cointelegraph, stating that the integration helps automate the verification of HPCL POs to external parties, utilizing the blockchain system alongside HPCL’s internal e-PO. This generates tamper-evident, verifiable POs, enhancing efficiency and transparency within industry processes.In a separate development, it emerged on Thursday that India’s Central Bureau of Investigation has appointed Singapore-headquartered digital asset market intelligence outfit Liminal to manage seized digital assets.This holistic approach, combining advancements in law enforcement training and embracing blockchain applications, underscores India’s commitment to navigating the evolving landscape of digital technologies while looking to ensure a secure and transparent future.

news
Web3 & Enterprise·

Oct 07, 2024

Zetrix launches product to simplify KYC for Chinese nationals

Zetrix, a layer-1 blockchain project for real-world applications, has launched an electronic Know Your Customer (KYC) verification product for Chinese nationals. The Malaysian enterprise, which is a subsidiary of digital services company My E.G. Services Berhad (MYEG), has launched ZCert. The offering is available to Chinese nationals who opt to have their digital identities published to the Xinghuo BF network, a Chinese national blockchain infrastructure network developed under the guidance of China’s Ministry of Industry and Information Technology and managed by the China Academy of Information and Communications Technology.Photo by Diego Jimenez on UnsplashFirst-of-its-kind applicationZetrix acts as an international super-node relative to the Xinghuo blockchain. In a press release published by PR Newswire on Oct. 3, the company outlined that ZCert had been launched as a first-of-its-kind application, enabling Chinese nationals “to be authenticated and verified digitally overseas, paving the way for a seamless, efficient, and secure verification process for verifiers and identity holders. ” The service simplifies the issue of identity verification for verifiers located outside of China, as a consequence of Zetrix’s integration with the Xinghuo BIF network.  Connecting to ‘China Web3’Xinghuo signed a memorandum of understanding (MoU) with Zetrix’s parent company, MYEG, to establish the international super-node back in November 2022. The tie-up was seen as an opportunity to provide access to Chinese government agencies and businesses internationally.  At the time, MYEG Managing Director and Zetrix Co-Founder Wong Thean Soon said that “with the commencement of the Xinghuo International Supernode, the rest of the world can connect and be part of the China Web 3 evolution that will promote the establishment of international communities and facilitate global trade and finance.”  On this occasion, Wong said that the new product “enables a new wave of services powered by smart contracts.” He added that KYC processes can be simplified and automated, while “user data is retained by users at all times and only critical information is shared in an encrypted manner." The company has already digitized Chinese driving licenses for the purpose of overseas verification. Furthermore, it has plans to expand its offering beyond ID verification soon. In April of this year, Zetrix and MYEG signed an MOU with MaiCapital, a Hong Kong-based virtual assets manager, with a view towards collaborating on the launch of a digital asset fund or digital asset-based exchange-traded fund (ETF). Last year Zetrix engaged in a pilot project with the Bank of China with the aim of offering supply chain financing products. On a similar theme, its parent company entered into a partnership with the Philippines Bureau of Customs (BOC) and Cargo Data Exchange Center Inc. (CDEC), also in 2023. The collaboration involved the use of Zetrix’s ZTrade product, a Web3 platform that enables digitized trade document verification. Zetrix launched its ZETRIX token in October 2023 through an initial exchange offering (IEO) facilitated by the Coinstore exchange.

news
Loading