Top

Mixin Network Suspends Services Amid $200 Million Hack

Policy & Regulation·September 25, 2023, 11:56 PM

On Monday, Mixin Network, a decentralized peer-to-peer network whose project team is based in Hong Kong, officially confirmed a substantial security breach that resulted in the loss of approximately $200 million in crypto assets from its mainnet.

Photo by GuerrillaBuzz on Unsplash

 

September 23 hack

This incident, disclosed via an X (formerly Twitter) post, prompted the immediate suspension of all deposit and withdrawal services on Mixin Network until further notice.

The project team outlined that the hack occurred on September 23, exposing vulnerabilities that allowed malicious actors to compromise the database of a third-party cloud service provider. Mixin Network has taken action to address the situation, enlisting the expertise of Singapore-headquartered blockchain security investigator SlowMist and the support of Google to conduct a thorough investigation and formulate a recovery plan.

At the time of the breach, Mixin Network’s holdings included $94.48 million in Ether, $23.55 million in Dai, and $23.3 million in Bitcoin, as reported in an independent investigation by PeckShield. The total value of assets affected amounted to $141.32 million.

Cyvers, an Israeli Web3 security firm, has also been looking into the matter on Monday. In a social media post, the firm stated:

”Our internal investigation has uncovered suspicious funding transactions involving @MixinKernel hacker addresses. Two of hacker addresses received 51 $ETH from 0x1795F0eBDa5A836aE63F28CE546E72de069A8bd2 who was interacted with @HuobiGlobal and @binance.”

The firm goes on to call on Binance and its CEO Changpeng Zhao (CZ) and Huobi to help identify the wallet address in question.

 

Halting withdrawals

In response to the security breach, Mixin Network has temporarily halted all deposits and withdrawals on its platform. These services will only resume once the vulnerabilities have been identified and fully resolved. On X, the project stated:

”Deposit and withdrawal services on Mixin Network have been temporarily suspended. After discussion and consensus among all nodes, these services will be reopened once the vulnerabilities are confirmed and fixed. During this period, transfers are not affected.”

Details regarding the plans to recover the lost assets for affected users have yet to be announced.

Despite initial promises that Mixin Network’s Founder, Feng Xiaodong, would address the incident in a public Mandarin live stream on September 25, links to the live stream were not provided on the official social media channels or the website mixin.network.

The incident has garnered criticism on the basis of a lack of decentralization. One commentator stated:

”Some of those blockchain protocols are so decentralized that when their cloud database is hacked, coins are also gone.”

 

Ongoing hacks

This security breach on Mixin Network is the latest in a series of high-profile crypto-related incidents. Ethereum Co-Founder Vitalik Buterin recently fell victim to a SIM swap attack, which resulted in the compromise of his X (formerly Twitter) account.

In a statement, Buterin revealed that the hackers had successfully executed a SIM swap, a type of attack that targets the victim’s mobile phone number to gain unauthorized access to various online accounts, including social media, banking, and cryptocurrency platforms.

The repercussions of the Mixin Network hack underscore the ongoing challenges faced by the crypto industry in ensuring the security and protection of digital assets. As investigations continue, affected users await further developments and the eventual resumption of deposit and withdrawal services.

More to Read
View All
Web3 & Enterprise·

Jun 26, 2023

Wemade Unveils Blockchain-Powered Platform for Various Communities

Wemade Unveils Blockchain-Powered Platform for Various CommunitiesSouth Korean gaming company Wemade today unveiled their latest creation, Wepublic, a blockchain-powered platform for various communities. The objective of Wepublic is to establish a transparent and trustworthy digital society on the WEMIX3.0 Mainnet.Photo by Pixabay on PexelsFrom political parties to NGOsInitially built as a fundraising platform, Wepublic caters to entities of any scale or domain, be it political parties, religious groups, or non-profit organizations. Wepublic is committed to transforming itself into a platform for everyone.By leveraging blockchain, Wepublic ensures that all information and records stored on the platform are transparent, making them immune to counterfeiting and diversion. Furthermore, Wepublic is dedicated to fostering inclusivity and democratic decision-making. Every member within a group on Wepublic has the ability to engage in organizational activities and contribute to fair decision-making processes.Four proof protocolsIn the near future, Wepublic will introduce the “Wepublic Wallet,” enabling users to create or participate in decentralized autonomous organizations (DAOs). To ensure transparency and reliability of DAO operations, Wepublic relies on four proof protocols. These protocols serve to verify user identities, credentials, account balances, and the outcomes of governance processes.The first protocol utilizes decentralized identifiers (DIDs) to safeguard personal information, prioritizing user privacy and security. The second protocol employs soulbound tokens (SBTs) to effectively manage groups within the platform. The third protocol provides visibility into account balances and transaction records, adding an additional layer of transparency. Lastly, the fourth protocol ensures the transparent recording of all governance processes on the blockchain, promoting accountability and trust.

news
Web3 & Enterprise·

Apr 12, 2023

South Korea’s GDAC Suffers $13M hack

South Korea’s GDAC Suffers $13M hackSouth Korean cryptocurrency exchange, GDAC, has suffered a significant hacking incident that has resulted in the loss of approximately 23% of its custodial digital assets.©Pexels/PixabayThe hack occurred on Sunday when some of the exchange’s hot wallets were breached, and the stolen assets were transferred to an unidentified wallet. GDAC reported the incident on Monday and disclosed that the exchange lost over $13.1 million in Bitcoin, Ether, Wemix, and USDT, with more than $10 million in Wemix.According to blockchain analytics firm Arkham Intelligence, the hacker has since swapped the USDT for ETH, sending 461 ETH to cryptocurrency tumbler, Tornado Cash. The hacker used three separate wallets to take funds from two of the exchange’s hot wallets. Arkham has labeled the wallets as follows:GDAC Hacker 1: 0x244615D99684175d31369332039b2D84ce925EC5GDAC Hacker 2: 0x62B5eb2cb925Ce2898f9327B235b3228e7Cac1C2GDAC Hacker 3: 0x87597bDB421482190e223aCa0A4DEAd75AB0a98DGDAC deposits/withdrawals suspendedGDAC has suspended its withdrawal and deposit services and reported the incident to the Korea Internet and Security Agency and the Financial Intelligence Unit. The exchange has also requested other cryptocurrency exchanges to block incoming transactions from suspicious addresses.In a notice posted on its website, GDAC CEO Seunghwan Han apologized for the suspension of deposits/withdrawals and concern relative to the hack, adding that the firm will be working towards investor protection and safe withdrawal of funds in due course. GDAC also posted the breakdown of the digital asset quantities lost in the hack, with the hacker stealing 60.80 BTC, 350.5 ETH, 10,000 WEMIX and 220,000 USDT.Crypto hacks increasingThis hacking incident comes at a time when cryptocurrency hacks have been on the rise. According to blockchain analytics firm Chainalysis, illicit actors stole $3.8 billion worth of assets last year, the largest one-year loss in crypto’s history. In addition, other crypto platforms have also suffered notable hacks and exploits in the past 15 to 18 months. Axie Infinity’s Ronin bridge, for example, suffered a $625 million hack last year, and decentralized-finance protocol Sushi was exploited for $3.3 million on Sunday.GDAC is not the only South Korean cryptocurrency exchange to suffer a significant hacking incident. In 2018, Coinrail was hacked, resulting in the loss of approximately $40 million worth of assets, and in 2021, Upbit suffered a $50 million hack.In response to these incidents, South Korea has taken steps to tighten regulations around cryptocurrency exchanges. In March 2021, the country’s Financial Services Commission issued a revised regulation that requires cryptocurrency exchanges to maintain stricter anti-money laundering measures and report suspicious transactions.The GDAC hack is a stark reminder of the risks associated with cryptocurrency investing and the importance of implementing robust security measures. Investors and cryptocurrency exchanges should take note of this incident and ensure that they have adequate security measures in place to protect against potential hacks and exploits.

news
Web3 & Enterprise·

Sep 14, 2023

Bitget Launches $100M Crypto Ecosystem Fund

Bitget Launches $100M Crypto Ecosystem FundSeychelles-based crypto exchange Bitget has launched its EmpowerX Fund, a $100 million initiative unveiled during Bitget’s fifth-anniversary summit in Singapore on Tuesday.Photo by micheile henderson on UnsplashStrategic investmentThe firm expanded on the finer details of the fund at the summit event and also by way of a press release published to PR Newswire. The primary goal of the initiative is to enrich the platform’s ecosystem by strategically investing in various sectors, including regional exchanges, data analytics firms, and media organizations.Bitget’s approach via this new fund is grounded in diversification to meet the ever-evolving needs of its 20 million global customers. The exchange envisions creating a comprehensive trading ecosystem that encompasses trading, investment, research, DeFi, and media.Gracy Chen, the Managing Director of Bitget, emphasized that the cryptocurrency exchange sector is in a constant state of evolution and with that, the firm has a forward-looking vision that extends beyond the present. Chen stated:“The CEX landscape is continually evolving amid influences of tightened regulations, rapid growth of Layer 2 and DeFi technologies, and we are expecting that more investment, meager [sic] and acquisition will happen in the following months. Our vision goes beyond the present.”She added: “With the launch of the Bitget EmpowerX Fund, we take another major step in our mission to develop Bitget into a truly comprehensive platform for all needs. Through strategic, targeted investments that foster long-term growth, we aim to continually expand our ecosystem of services to better serve the evolving needs of users. We also want to empower other people in our industry, because a rising tide lifts all boats.”Broader investment trendBitget’s EmpowerX Fund is part of a broader trend of strategic investments and expansion. In April, the exchange introduced the $100 million Web3 Fund, which focuses on supporting projects based in Asia and partnering with global venture capital firms, including Foresight Ventures, SevenX Ventures, and Gitcoin Fund.As part of that initiative, the firm invested $20 million in Sei Labs, the developers of the layer one Sei blockchain. The strategic direction being taken by Bitget extends beyond digital assets, as Bitget allocated $30 million to invest in the BitKeep multi-chain wallet, which subsequently underwent a rebranding as Bitget Wallet. This investment marked a significant milestone in Bitget’s journey toward embracing decentralized strategies.Diversifying service offeringTo better cater to the evolving needs of its users, Bitget has diversified its service offerings. In addition to traditional trading, the platform has ventured into the realm of crypto loans, a bold move given the difficulties experienced in 2022 by crypto lending firms like Celsius, BlockFi, Hodlnaut, Vauld, and Voyager Digital, who all ended up in bankruptcy.The company has taken a further step towards diversification on Tuesday, announcing the launch of its Bitget Wealth Management product. The firm claims that the product is targeted to meet the needs of high-net-worth individuals and institutions, offering to assist them in optimizing their financial portfolios.Bitget has also adapted to a changing regulatory landscape recently, stepping up its compliance in terms of Know Your Customer (KYC) measures.

news
Loading