Top

Remitano Struck by $2.7M Alleged Hack

Policy & Regulation·September 16, 2023, 1:21 AM

Hacks have been an unfortunate constant in the crypto and DeFi space with that reality having been compounded by news that Seychelles-based crypto exchange Remitano is believed to have been the victim of a $2.7 million heist.

Photo by Growtika on Unsplash

 

Suspicious transactions

It’s understood that the firm encountered highly suspicious transactions, with the $2.7 million having seemingly vanished from its wallet, all at the hands of a single account. The incident unfolded on Thursday and has left blockchain analysts speculating about a potential security breach.

The Remitano hot wallet initiated transfers to an address devoid of any prior transaction history. These transfers amounted to approximately $1.4 million in Tether (USDT), $208,000 in USD Coin (USDC), and 104,000 ANKR tokens (valued at $2,000 at the time). Those transfers raised concerns about the security of the platform.

Israeli blockchain analytics platform Cyvers promptly sounded the alarm, notifying the crypto community about these suspicious transactions that had drained significant sums from Remitano’s coffers. This sudden event raised concern within the crypto space and naturally among Remitano customers.

 

Tether freezes wallet address

Amid the growing apprehension, Tether, the issuer of USD stablecoin USDT, took decisive action by freezing the address associated with the alleged attacker. This swift intervention effectively halted any further movement of $1.4 million worth of drained cryptocurrency. Tether’s proactive response could potentially have prevented additional loss, preserving customers’ assets from further depletion.

Remitano had remained notably silent initially in the wake of this incident, declining to issue any formal statement regarding the breach. It has since acted, as on Friday, it published a statement relative to the issue on its website. The absence of communication from the exchange had only fueled greater speculation surrounding the incident. However, the statement outlined:

”On September 14, 2023, our Security Management team discovered a data breach from a third-party source that had compromised some of our sensitive information. As a result, a small amount of funds from the exchange’s hot wallets were transferred to suspicious wallet addresses through unauthorized withdrawal transactions.”

Remitano, recognized as a peer-to-peer cryptocurrency exchange and payment processor, primarily caters to users in emerging markets across several countries, including Pakistan, Ghana, Venezuela, Cambodia, Kenya, Malaysia, India, South Africa, Vietnam, and Nigeria.

The firm sought to reassure its customers:

”As of now, Remitano ensures that users’ assets have NOT been and will NOT be affected by this incident. We are working tirelessly to uphold our commitment to ensuring the security and protection of your crypto assets.”

Remitano was established in 2015; it is operated by Babylon Solutions Limited, which is headquartered in the Seychelles.

Unfortunately, this episode adds to the troubling trend of cryptocurrency exchange hacks witnessed in 2023. Authorities in the United States have attributed these attacks to the Lazarus Group, a notorious cyber-crime organization allegedly linked to the North Korean government which has wreaked havoc globally although disproportionately so within the Asian region.

More to Read
View All
Web3 & Enterprise·

May 16, 2023

Japanese Firm Exec Underscores User Experience and Collaboration in Web3

Japanese Firm Exec Underscores User Experience and Collaboration in Web3Hiroshi Tsuruoka, the Chief Operating Officer (COO) of UNCHAIN, a Japanese company specializing in Web3 entertainment services, recently underscored the significance of unique experiences and collaboration in the Web3 space. He shared these insights during his conversation with Webmaster Forum, a platform offered by Japanese web content provider Impress Corporation.UNCHAIN, Tsuruoka’s employer, aims to assist companies in entering the Web3 sphere and developing entertainment services that offer users a secure and enjoyable experience. The company provides comprehensive support, including planning, development, and marketing, tailored specifically for the Web3 environment.Photo by Shubham’s Web3 on UnsplashImportance of content qualityDuring the interview, Tsuruoka said that Web3 seems to have lost some of its previous popularity in Japan. Initially, the market experienced rapid growth driven by highly speculative products like NFT artworks and Play to Earn (P2E) games, which attracted participation from many Japanese companies. However, the subsequent downturn of global projects prompted the Japanese blockchain industry to reassess its strategy, recognizing the paramount importance of content quality.Meaningful experiencesAccording to Tsuruoka, the appeal of blockchain games extends beyond their profit potential, deriving more from the unique, enjoyable experiences they offer. He believes that gamers find it meaningful when they play a pivotal role in expanding the gaming market and giving rise to new gaming cultures. Moreover, the incorporation of NFTs in games allows users to retain ownership of their in-game items even if a company discontinues its service, fostering a deeper emotional connection between users and their virtual possessions.This emerging trend fosters a culture of creation, where users, operators, and creators come together in a collaborative space to generate secondary creations and new services. Users delight in actively contributing to this ecosystem and helping it grow.Tsuruoka recognizes that decentralization presents both advantages and challenges. On one hand, it offers individuals greater freedom. However, it also places the full responsibility of data management on the users themselves, in contrast to a centralized environment where the game provider handles data management.Tsuruoka advises against placing excessive emphasis on speculation and financial gain when discussing Web3. Instead, he encourages companies to prioritize delivering meaningful and valuable experiences to users. Tsuruoka believes that emotional experiences, such as owning a distinctive avatar through digital assets, hold tremendous potential in the Web3 realm.Web2 success firstHe asserts that no Web3 project can guarantee success without proving its worth in the Web2 space. Services that proved valuable in Web2 could experience significant growth when combined with Web3 elements.Strong relationshipsTsuruoka highlights the importance of establishing strong relationships between companies and users in the Web3 environment. While platforms like Discord can facilitate these relationships, it is crucial to strategically design user engagement, motivation, and enjoyment before launching a service. Effective community management in the Web3 space requires deep user engagement, which entails ongoing and intensive communication between operators and users.Tsuruoka emphasized the need to heed user feedback. Regardless of the service type, incorporating user opinions and collaborating with them can result in significant community and project growth, with corresponding increases in asset values. He added that this is not limited to the Web3 domain.

news
Policy & Regulation·

Oct 04, 2023

Hong Kong’s Development as Crypto Hub May Soften Chinese Stance on Crypto

Hong Kong’s Development as Crypto Hub May Soften Chinese Stance on CryptoHong Kong is making waves in the crypto sector that could potentially signal a shift in China’s attitude toward digital assets. That’s a theory that has been given consideration by crypto analytics firm Chainalysis in a recently released report highlighting Hong Kong’s crypto transformation and suggesting a growing tolerance for crypto within China’s corridors of power.Photo by farfar on UnsplashOTC trade showing resilienceDespite China’s stringent regulations and the ongoing crypto market downturn, Hong Kong’s over-the-counter (OTC) crypto market has demonstrated remarkable resilience, with a transaction volume of $64 billion in the past year. While this is slightly less than China’s $86.4 billion, it’s a noteworthy achievement considering Hong Kong’s smaller population and the challenges facing the crypto industry.The close relationship between China and Hong Kong has led some industry commentators to speculate that Hong Kong’s rise as a crypto hub could indicate a shift in China’s stance on digital assets.The crypto-friendly environment in Hong Kong has not gone unnoticed. Merton Lam of Crypto HK, an OTC digital asset trading center in the city, notes that cryptocurrencies have become an integral part of investment portfolios for banks, private equity firms, and high-net-worth individuals in the region. Even Chinese state-owned businesses are launching cryptocurrency-focused investment funds.Hong Kong cornering institutional tradeWhat sets Hong Kong apart in the crypto landscape is its proficiency in large institutional crypto transactions, with 46.8% of its annual crypto trades exceeding $10 million. In contrast, retail trades under $10,000 accounted for just 4% of the city’s crypto volume, slightly below the global average of 4.7%. This institutional dominance distinguishes Hong Kong from other Asian regions.For comparison, South Korea heavily relies on retail trading on centralized exchanges, while Japan maintains a transaction breakdown that aligns closely with global trends, balancing centralized exchanges with DeFi protocols.A cautionary noteHowever, Dave Chapman of OSL Digital Securities offers a note of caution, suggesting that Hong Kong’s promotion as a crypto hub might be more exploratory, aimed at gaining a better understanding of digital assets without significantly loosening mainland policies.Despite the uncertainties, Markus Thielen, Head of Research and Strategy at Singapore’s Matrixport, believes that Hong Kong is acting as a “testing ground” for broader cryptocurrency adoption in China. The city’s unique position makes it an attractive destination for the crypto asset management industry, setting it apart from other jurisdictions that often view crypto firms as service providers rather than end-users.Hong Kong’s progress is particularly noteworthy when considering the broader context of East Asia’s crypto market. Chainalysis analysis reveals that East Asia’s share of crypto transaction value dropped from around 30% in 2019 to less than 10% by the second quarter of 2022 due to China’s crypto bans. Hong Kong’s recent surge could potentially act as a “tailwind” to reignite crypto activity in the region.The evolving relationship between the mainland and the autonomous territory of Hong Kong may hold the key to understanding the future of cryptocurrency in the region.

news
Web3 & Enterprise·

Jan 12, 2024

CoinGecko security breach latest threat within crypto space

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach. Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.Photo by GuerrillaBuzz on UnsplashPhishing scamDuring this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content. In an X post, CoinGecko wrote:”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.” Employee errorThe firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker. Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities. CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented. SEC incompetenceCoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs). While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security. Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack. Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions. CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

news
Loading