Top

Korbit Passes Post-Audit for ISMS-P and ISO Certifications

Web3 & Enterprise·September 06, 2023, 8:11 AM

South Korean crypto exchange Korbit announced on Wednesday that it has successfully passed a post-audit to maintain its Personal Information and Information Security Management System (ISMS-P) certification and four different International Organization for Standardization (ISO) certifications — ISO 27001, ISO 27017, ISO 27018, and ISO27701.

“By maintaining our ISMS-P and ISO certifications this year, we were able to reaffirm the stability and trustworthiness of Korbit’s personal information protection capabilities and security management system,” said Oh Se-jin, CEO of Korbit.

Photo by FLY:D on Unsplash

 

Rigorous criteria

The ISMS-P is a security management system jointly operated by the Ministry of Science and ICT and the Personal Information Protection Commission, representing the highest level of security management in Korea. It combines 80 requirements for Information Security Management System (ISMS) certification and 22 requirements for Personal Information Management System (PIMS) certification, totaling 102 requirements that must be met. Once obtained, certification is valid for three years, and annual post-audits are required to maintain its validity.

Korbit first obtained ISMS-P certification in September of 2021 and has once again passed this year’s post-audit that was conducted last Wednesday.

 

Meeting international standards

In addition, the exchange had previously passed post-audits for four ISO certifications related to information protection and personal information management systems earlier in June. This includes ISO 27001 for information security management systems, ISO 27017 for information security controls on cloud services, ISO 27018 for protection of personally identifiable information (PII) in public clouds, and ISO 27701 for privacy information management systems.

This achievement demonstrates Korbit’s commitment to reliability and security when operating and managing exchange services.

“As a crypto exchange, we will continually focus on strict security management to ensure the protection of customer information and assets,” said CEO Oh.

More to Read
View All
Web3 & Enterprise·

Jul 11, 2023

Crypto Exchange Loss Deters Temasek from Investing in Crypto Firms

Crypto Exchange Loss Deters Temasek from Investing in Crypto FirmsSingapore’s state-owned investor Temasek has ruled out investing in crypto companies for now, following a $275 million loss in the bankrupt US crypto exchange FTX.Photo by Plato Terentev on PexelsRegulatory uncertainty concernsTemasek’s Chief Investment Officer Rohit Sipahimalani said in a CNBC interview on Tuesday that the regulatory uncertainty in the crypto sector made it very difficult for the fund to make another investment in an exchange.“There’s a lot of regulatory uncertainty in this environment. And I do think that it will be very difficult for us to make another investment and exchange in the middle of all this regulatory uncertainty,” Sipahimalani said.He added that Temasek was not interested in investing in cryptocurrencies, but rather in exchanges that could generate fee-based revenue without taking balance sheet or trading risks. In May, it was reported that Temasek had invested in algorithmic currency system, Array. However, the global investment company was quick to deny those reports.“We’ve never been looking to invest in cryptocurrencies. Even the investment in FTX, we’ll be talking about investing in an exchange, which allowed us to get fee-based revenue without thinking [of] balance sheet risk or any trading risks,” he said. However, he said that Temasek would not be comfortable investing in exchanges given the way things are right now, and that it would depend on the right regulatory framework and investment opportunity.“If you have the right regulatory framework, and we are comfortable with it, and you have the right investment opportunity, there’s no reason for us to not to look at it,” he said. Temasek’s FTX investment was part of its early-stage investment strategy, where it invests in new disruptive technologies and tries to find the next winners, Sipahimalani said.But the strategy backfired when FTX filed for bankruptcy in November, with more than 1.4 million creditors and billions of dollars in liabilities, according to bankruptcy filings.Reputational damageTemasek wrote down its $275 million investment in FTX to zero soon after the collapse of the exchange. However, the bigger concern for the company is the posting of its worst returns since 2016 amid macroeconomic and geopolitical challenges. In the financial year ending in March 2023, the investing behemoth posted a $7.3 billion loss.The FTX loss sparked criticism from Singapore’s Deputy Prime Minister and Finance Minister Lawrence Wong, who called it “disappointing” and damaging for Singapore’s reputation. And that is the greater issue for Temasek relative to FTX.The amount of that particular loss is not that significant, given the size of the company and the scale of losses incurred elsewhere. The issue has been the reputational damage that the company has experienced as a direct consequence. Temasek maintains that it carried out competent due diligence, as have all of the venture capital investors who have all had their FTX investments wiped out.Further details on that due diligence are likely to emerge as Temasek, alongside many other leading investors in FTX, is being sued by creditors on the basis that they gave credence to what transpired to be a fraud. Temasek announced in May that it would cut the salaries of the staff responsible for the FTX investment, after conducting an internal review of the deal.

news
Policy & Regulation·

Oct 11, 2024

Taiwanese regulator set to launch crypto custody pilot

Taiwan’s Financial Supervisory Commission (FSC), the independent government agency that regulates activity within Taiwan’s securities, virtual assets, banking and insurance sectors, is planning to invite applications from financial institutions to participate in a crypto custody services pilot program, scheduled to commence in Q1 2025. The Central News Agency (CNA), the national news agency of the Republic of China, published a report on Oct. 8, outlining the FSC’s intentions with regard to this crypto custody pilot program. The media outlet confirmed that three Taiwanese banks had expressed an interest in participating in the program.  The Director of the FSC’s Comprehensive Planning Division, Hu Zehua, outlined at a press conference that the regulator is planning to provide further information relative to the pilot program 15 days in advance of inviting applications from prospective participants. Photo by 張 峻嘉 on UnsplashPublic consultationAdditionally, the FSC executive outlined that the regulator intends to collect feedback from the public relative to the proposed pilot program, and fine-tune the process based upon that feedback. Hu stated that he recognizes that based on crypto custody activity carried out overseas, operational security is of paramount importance. Therefore, the FSC is interested in placing emphasis on this aspect of the activity as part of the pilot program.  Illicit funds and money laundering is another area of concern. With that the FSC executive outlined that financial institutions must proactively block virtual assets that are found to originate from illicit sources. In August a Taiwanese couple was indicted for laundering around $50 million in illegal funds through cryptocurrencies. Earlier this month, the FSC revised Taiwan’s regulatory framework relative to anti-money laundering (AML). The update now requires digital assets firms to register with the Taiwanese government by no later than September 2025. Failure to do so may result in these crypto companies being fined up to $156,000 or company executives facing up to two years in prison. Bitcoin, Ethereum and Dogecoin mentionedPilot program applicants will be expected to specify the type of digital assets they intend to custody. Explanatory information released by the FSC gave Bitcoin, Ethereum and Dogecoin as examples. Additionally, applicants are required to outline the type of client they will cater towards in providing a crypto custody service. Among the examples mentioned were virtual asset platforms, professional investors and general investors. The FSC announced at the end of last month that professional investors are now permitted to access foreign virtual asset exchange-traded funds (ETFs) and invest in them through a re-entrustment method. Taiwan has been making progress recently in bringing about regulatory clarity and establishing conditions within which Web3 companies can develop. The FSC had been working towards the production of draft crypto regulations over recent months. This followed a move by Taiwanese legislators in October 2024 to introduce the Virtual Asset Management Bill to parliament, with the objective of strengthening customer protections and establishing industry supervision. In September, the regulator released guidelines, including a measure which bans overseas crypto platforms from operating within the country. 

news
Policy & Regulation·

Sep 25, 2023

Upbit Accidentally Accepts Counterfeit APT Tokens, Initiates Retrieval Efforts

Upbit Accidentally Accepts Counterfeit APT Tokens, Initiates Retrieval EffortsUpbit, South Korea’s largest cryptocurrency exchange, is reported to have accepted deposits of counterfeit Aptos (APT) tokens, mistaking them for their legitimate counterparts. The exchange has been reaching out to the sellers of these tokens by phone, requesting their recovery. This news has been circulating in several online crypto communities since the afternoon of September 24 (Korea Standard Time).Photo by Kenny Eliason on UnsplashUpbit’s responsesOn September 24 at 15:47 KST, Upbit announced a temporary suspension of deposit and withdrawal services for APT due to maintenance on the APT wallet. Following this, at 22:32 KST on the same day, Upbit explained that system maintenance was undertaken after identifying an unusual attempt linked to APT deposits. The crypto exchange went on to announce that the deposit and withdrawal services for APT would resume at 23:00 KST on the same day.DeFi degenerates’ insightsIn relation to this incident, Definalist, a group of DeFi degenerates based in Korea, shared insights on X (formerly Twitter). The group stated: “It seems that during the process of reflecting $APT coin deposits, there was a failure to check the type arguments, and all same functions transfers were recognized as the same APT native token. … If all APT ecosystem tokens were sent to Upbit’s wallet, they would have been mistakenly treated as APT native coins.”Decimal place differenceDefinalist also remarked on the fortunate nature of the counterfeit APT token having six decimal places, in contrast to the authentic APT token’s eight. They noted that if the deceptive token had mirrored the genuine token’s decimal places, the market disruption could have amplified a hundredfold. Meanwhile, the value of the counterfeit APT tokens deposited into Upbit is estimated to be about KRW 20 million (approximately $15,000).

news
Loading