Top

CoinEx Reveals Insights Into Recent Platform Hack

Policy & Regulation·September 20, 2023, 1:33 AM

Hong Kong crypto exchange CoinEx has issued a further update relative to the security breach that occurred on the platform last week resulting in one of the exchange’s hot wallets being compromised.

Photo by FLY:D on Unsplash

 

Immediate response

In the immediate aftermath of the $70 million hack, CoinEx took action to safeguard user assets and initiate an investigation into the incident. It suspended all deposit and withdrawal services and executed an emergency shutdown of the hot wallet server. Following this, the company securely moved the remaining assets to cold storage, commencing the process of reconstructing and deploying a new wallet architecture.

The firm also engaged in an investigation, spearheaded by its wallet and security teams, to ascertain the extent of the breach. Moreover, CoinEx claims to have proactively reached out to fellow exchanges to freeze any assets related to the attack.

Haipo Yang, the Founder and CEO of CoinEx, conveyed his apologies to affected users through his personal X (formerly Twitter) account. He emphasized the team’s commitment to restoring services promptly and reassured users that their funds will remain secure.

Following up on that commitment, CoinEx published an update on the hot wallet hack on September 15 to address these concerns individually.

 

New wallet deployment

The exchange expects to finalize wallet upgrades within the upcoming week, after which withdrawals will gradually be phased in, subject to security evaluations. The CoinEx team is currently working on developing and deploying an entirely new and robust wallet system capable of managing activities across 211 chains and 737 assets.

The firm has outlined that each of its product lines operates independently, featuring its own risk control system. Consequently, the security incident that occurred on CoinEx will not affect the integrity of its other product lines.

In its most recent update on Tuesday, the Hong Kong crypto exchange confirmed that 80% of its wallet system has now been reconstructed. It added that it has initiated preparations to enable the withdrawal system on the platform. It stated:

”Details about the resumption of withdrawals, including specific dates, times, and arrangements, will be announced on the CoinEx website. Please stay updated on our announcements for the latest information.”

 

Ongoing investigation

Regarding the identity of the attacker, CoinEx has confirmed that the matter is currently under investigation. While some security firms have made attribution claims, the company is focusing primarily on deploying the new wallet architecture, restoring affected users and functionalities, and enhancing overall security.

At the same time, the company has initiated communications with the hackers in a bid to proactively seek a mutually agreeable resolution. While the incident implicates the loss of a substantial amount of funds, the firm maintains that in the context of the overall business, the sum represents only a small percentage of total assets under its management.

Exchange security remains a major challenge in the crypto sector, with hacks happening on an ongoing basis. Last week, Seychelles-headquartered peer-to-peer crypto platform Remitano acknowledged a $2.7 million hack. At the beginning of September, crypto gambling platform Stake was reported to have suffered a $41 million hack.

More to Read
View All
Web3 & Enterprise·

Mar 12, 2024

Korean crypto exchange Upbit launches BTC-ETH Duo Index

Dunamu, the operator of South Korea’s leading crypto exchange Upbit, announced today that it launched a new crypto price tracking service, Bitcoin-Ethereum Duo Index (Duo Index). The news was reported by the local media outlet Etoday.  The service tracks the two most prominent tokens, Bitcoin and Ethereum, each being the top performer and the runner-up in terms of market capitalization in the crypto asset market. It is a strategy index that equally weights Bitcoin and Ethereum, with their holding ratio updated to 1:1 every month. The weightings of the two cryptocurrencies in the index are subject to an adjustment factor, which is based on their prices. The BTC-ETC Duo Index is currently available on the Upbit Cryptocurrency Index (UBCI) website. Photo by Markus Winkler on UnsplashThe Federal Reserve’s approval of spot Bitcoin ETFs in January has drawn significant attention from many investors, driving up the prices not only of Bitcoin but also Ethereum. Dunamu explained that this heightened interest surrounding Bitcoin and Ethereum is the reason behind its launch of the Duo Index. New tool to boost crypto portfolio’s performance Referencing the Duo Index can help investors estimate their own crypto assets portfolios and boost their performances based on the indicators it offers, including the winning rate of the two coins combined.   The current winning rate of the Duo Index stands at over 58%, which is three percentage points higher than that of the Upbit Market Index (UBMI), which tracks not only Bitcoin and Ethereum but also other altcoins. The high winning rate of the Duo Index demonstrates the bullish sentiment surrounding the two top coins. A Dunamu official stated that the company will continue to keep up with the crypto market trend and further release other strategy indices that would serve the emerging needs of the investors.  

news
Policy & Regulation·

May 24, 2024

Thai regulator takes action against deceptive crypto ads

In an effort to safeguard crypto investors from falling prey to misleading advertisements, the Securities and Exchange Commission (SEC) of Thailand has intensified its scrutiny of promotional campaigns within the crypto sphere. Photo by Dave Kim on UnsplashBroker agent eventsOn April 29, the Bangkok Post reported that the SEC has raised concerns regarding the potential violation of local regulations through introducing broker agent (IBA) events. These events, the SEC clarified, may breach regulations as IBAs are only permitted to promote digital token services to deter speculation on cryptocurrencies, categorized as high-risk assets. IBAs, acting as local conduits for partner digital asset exchanges, typically earn commissions by onboarding clients within a specific market. Such practices are common for exchanges or brokers that don't directly operate in certain markets. Deputy Secretary-General Anek Yooyuen conveyed the commission's unease over crypto exchanges offering preferential treatment to onboard users. Yooyuen stated: "When operators organise sales promotions by offering rewards to entice people to use the service, this could encourage use of the service without considering the investment risks. This is especially the case for cryptocurrencies.” Warning of consequencesHe cautioned that failure to adhere to these guidelines would result in “punishment according to the law.” While cryptocurrency exchanges are legal in Thailand, they must secure local approval. Notably, last month, Thailand even greenlit asset management firms to launch private funds, offering Bitcoin exchange-traded funds (ETFs) exclusively to institutional and ultra-high-net-worth investors. Nonetheless, the country recently prohibited the sale of cryptocurrency lending products and mandated that exchanges prominently display risk warning messages. International regulatory trendThis move by the Thai SEC mirrors actions taken by regulators in other major crypto markets. For instance, the United Kingdom's Financial Conduct Authority (FCA) issued 450 alerts for illegal crypto ads in 2023 alone. Similarly, Spain’s principal securities market regulator, the National Stock Market Commission, denounced fraudulent crypto asset promotions in November 2023, emphasizing companies’ obligations to adhere to local laws. Thai advertising guidelines mandate businesses and advertisers to substantiate the “facts” presented in their campaigns, failing which could lead to legal repercussions. A recent incident provides a case in point. Hackers hijacked advertisements on Etherscan, redirecting users to phishing sites aimed at draining crypto wallets. Scam Sniffer, a blockchain investigation firm, attributed the widespread phishing campaign to the inadequate oversight by advertisement aggregators. The company made the following statement on the matter: “Etherscan aggregates ads from platforms like Coinzilla and Persona, where insufficient filtering could lead to exposure to phishing attempts.” The wallet drainer scam involves enticing users to counterfeit websites and coercing them to link their crypto wallets, enabling scammers to siphon funds into their own wallets without user authentication or consent. This is not the first time that the authorities in Thailand have homed in on crypto-related advertising. In August 2023, the Southeast Asian country’s Ministry of Digital Economy and Society (MDES) outlined that it had engaged with social media firm Meta, owner of Facebook, informing it that its response to the proliferation of fraudulent platform ads relative to crypto had been inadequate. 

news
Policy & Regulation·

Aug 26, 2023

Hong Kong Regulator Explores Tokenization to Transform Bond Market

Hong Kong Regulator Explores Tokenization to Transform Bond MarketThe Hong Kong Monetary Authority (HKMA), the local regulator within the Chinese autonomous territory, unveiled the outcomes of its Project Evergreen study on Friday. Within the report, it indicated an interest in harnessing tokenization in order to improve aspects of the bond market.Photo by Jimmy Chan on PexelsBond market impact assessmentIn this comprehensive report, the regulator delved into the intricate world of bond tokenization, offering an in-depth assessment of its potential impact on the market. The 24-page report covers a range of insights, spanning use cases and benefits to the challenges encountered during the study. The overarching sentiment emerging from the study paints tokenization as a compelling avenue for enhancing the bond market’s functionality.Eddie Yue, the Chief Executive of HKMA, emphasized that the study underscored the latent potential of integrating distributed ledger technology (DLT) into real capital market transactions, all within the framework of Hong Kong’s existing legal structure. In addition, the research revealed the prospect of DLT elevating efficiency, transparency, and liquidity within bond markets.Highlighting efficienciesThe report highlighted that the digital nature of tokenized bonds has the power to render paper certificates obsolete, ushering in an era of streamlined processes and diminished errors. Moreover, the study emphasized the capacity for various stakeholders to seamlessly interact via a shared DLT platform, fostering an environment of collaboration. Real-time data synchronization would ensure heightened transparency, a crucial factor in modern financial markets.Furthermore, the report identifies that a standout feature of tokenization lies in atomic delivery versus payment (DvP) settlements for bond transfers. This innovation serves to significantly expedite the settlement process while bolstering the case for end-to-end DLT adoption.That said, the report acknowledges the nascent state of bond tokenization. Yue emphasized that a plethora of challenges must be overcome before mass adoption becomes viable. The HKMA official underscored the necessity for regulatory frameworks to evolve alongside technology adoption.These insights arrive at a time when Hong Kong is carving its niche as a haven for crypto and decentralized finance endeavors. A multitude of enterprises are believed to be queuing up for a coveted Hong Kong crypto license, underscoring the city’s rising stature in the digital finance sphere.July saw Hong Kong’s announcement of a partnership with Saudi Arabia, focusing on tokenization and payments. Additionally, the HKMA is actively exploring the establishment of a regulatory framework for the digital Hong Kong dollar and stablecoins, heralding a commitment to the distributed ledger technology (DLT) application. An imminent seminar with industry stakeholders is planned, aimed at introducing DLT technology and fostering its adoption.Arthur Chan, HKMA Assistant Chief Executive, anticipates wider DLT integration, envisioning reduced settlement times for bond issuances and instantaneous settlement through tokenized cash and smart contracts. He acknowledges the evolving nature of DLT platforms, acknowledging the need for further research and development. However, Chan envisions a future where tokenization extends beyond bonds, potentially encompassing securities, real estate, and mortgage products.

news
Loading