Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Web3 & Enterprise·

Mar 05, 2025

Silver lining for Bybit with UAE trading license approval

After being targeted in a $1.4 billion hack, the global crypto exchange platform Bybit was awarded in-principle approval to establish itself as a Virtual Asset Platform Operator (VAPO) within the United Arab Emirates (UAE). While Bybit announced the milestone via a press release published on Feb. 27, the approval had been awarded on Feb. 18, three days before the platform was hacked.Photo by Saj Shafique on UnsplashRegulatory challengesIn addition to the recent exploit, the crypto exchange platform had been having difficulties on the regulatory front in recent months, and from that perspective, this licensing award is a welcome development. Last December, the Malaysian Securities Commission reprimanded the platform and its CEO, Ben Zhou, for carrying out digital asset trading activities in Malaysia without having obtained the necessary licensing. Consequently, the firm left the Malaysian market, promising to return once it had obtained the required licenses. For similar reasons, Bybit left the Indian market in January, citing a need to “operate in full compliance” with local regulations. The company said that it was working with the regulator to finalize its registration as a Virtual Asset Service Provider (VASP) in India. The platform also experienced difficulties in complying with the recently introduced Markets in Crypto Assets (MiCA) regulation in Europe. However, it has been working with regulators in Austria in an effort to acquire MiCA licensing. Consequently, the French regulator, Autorité des Marchés Financiers, removed the firm from its blacklist. Earlier this month, Japan’s Financial Services Agency (FSA) ordered Apple and Google to remove the apps of a number of unregistered crypto platforms, including Bybit, from the Japanese versions of their app stores.  Commenting on this recent achievement in the UAE, Ben Zhou stated: “This approval marks a crucial step in our journey to providing secure and transparent crypto trading solutions. Bybit remains dedicated to working hand-in-hand with regulators to foster a compliant and innovative digital asset ecosystem to both retail and institutional investors in the UAE.” Hack falloutIt’s unclear to what extent the recent hack, which is understood to be one of the largest thefts of any kind, may be diverting resources and focus away from the efforts the company was making to address regulatory issues globally. However, it’s reasonable to assume that recent events make for a challenging time for the company. On Feb. 26, the Federal Bureau of Investigation (FBI) in the United States said that North Korea was responsible for the hack. The agency warned exchanges to freeze transactions linked to the stolen funds. The FBI outlined that “TraderTraitor” actors have been converting the funds to Bitcoin and other digital assets in an effort to launder the funds and eventually extract the funds in fiat currency. North Korea’s Lazarus hacking group has gained notoriety for its successes in hacking crypto platforms and the sophisticated nature of the attacks mounted in the process. The group is suspected of having hacked the Indian crypto platform WazirX last year, which resulted in the theft of $235 million in digital assets.

news
Web3 & Enterprise·

Jun 21, 2023

Academia, Industry Collaborate on Crypto Accounting Research in Korea

Academia, Industry Collaborate on Crypto Accounting Research in KoreaThe Korean Accounting Association (KAA) and Samil PwC, the South Korean member firm of global accounting company PwC, have joined forces to conduct collaborative research on accounting for cryptocurrency assets, according to a report by local news outlet Maeil Business Newspaper.Photo by Pixabay on PexelsCollaborative effortsUnder this newly formed partnership, the KAA’s crypto asset committee will work closely with Samil PwC to explore a wide range of crypto assets, facilitate the development of financial statements pertaining to these assets for businesses, and implement accounting policies that align with the characteristics of cryptocurrencies.Leading the crypto asset committee is Roh Hee-chun from Soongsil University, while Partner Lee Jae-hyeok from Samil PwC will participate in the study. Until 2028, this collaboration is poised to yield insights and findings on crypto asset accounting.First seminarThe committee is set to hold its first seminar on June 27, serving as a platform for knowledge exchange and fostering deeper understanding among industry professionals. Furthermore, the accountants involved anticipate publishing a paper in an academic journal next year.PwC’s Assurance Leader Oh Kee-won emphasized the accounting firm’s commitment to leveraging its extensive resources in order to produce outcomes that positively impact society.Meanwhile, KAA President-elect Kim Gap-soon highlighted the relative novelty of crypto asset accounting, acknowledging that there is much ground to be covered. The association aims to establish a solid foundation that offers optimal guidance in the field of crypto asset accounting.

news
Policy & Regulation·

Aug 24, 2023

Celebrating a Decade of Crypto in South Korea: Experts Convene to Chart the Future

Celebrating a Decade of Crypto in South Korea: Experts Convene to Chart the FutureThe MK Virtual Asset Conference, an event held in Seoul yesterday to celebrate the 10th anniversary of South Korea’s cryptocurrency industry, convened experts, politicians, and stakeholders to discuss the future of blockchain and digital assets.The conference was hosted by Maeil Business Newspaper and its blockchain subsidiary Mblock, and sponsored by cryptocurrency exchange Korbit, the Korean Securities Association, and the Korea Derivatives Association. It served as a valuable opportunity to evaluate the current state of the crypto market and explore solutions for pressing challenges.Photo by Ciaran O’Brien on UnsplashInevitable rise of blockchainOne of the distinguished speakers at the event highlighted the inevitable rise of blockchain technology. Kim Yong-beom, CEO of Hashed Open Research, the research arm of Seoul-based crypto venture capital firm Hashed, said, “Blockchain is the antithesis of the modern financial and capital system. While traditional finance possesses its own merits, it also carries substantial transaction fees and is confined within national boundaries. It is only natural that such a counterforce has emerged to address these issues.”He continued, “Given that traditional finance properly responds to blockchain technology’s rise and overcomes its limits, blockchain may lose its competitive edge. However, if traditional finance fails to do so, blockchain will not be easily dismissed.”CEO Kim also highlighted the third section named “Blueprint for the Future Monetary System” of the Bank of International Settlements’ 2023 Annual Economic Report, which was published in June. The report states, “The BIS Innovation Hub, in partnership with central banks around the world, stands at the forefront of experimentation with CBDCs and tokenization.” According to Kim, the traditionally conservative financial institution, which had previously been skeptical about blockchain-based distributed ledger technology, has now shifted its position to be more accepting of blockchain.Importance of institutional investorsDuring the conference, an academic underscored the importance of allowing institutional investors to enter the virtual asset space. Kang Hyoung-goo, an assistant professor in the Department of Finance at Hanyang University Business School, pointed out that the crypto market, when primarily driven by retail investors, tends to favor volatile assets over stable ones. Due to this inclination, more individual investors are attracted to exchanges where speculative trading is a frequent occurrence. This dynamic creates a vicious cycle, he explained.Defining digital assetsOn a different note, Lee Han-jin, a lawyer at Kim and Chang, one of the largest law firms in the country, emphasized the crucial need to establish a legal definition of digital assets. In Lee’s view, digital assets exist in the form of data on the blockchain, setting them apart from traditional assets. He argued that without a legal definition outlining the nature of these assets, they could potentially devolve into entities that mislead the public, lacking both legal reliability and trustworthiness.Political voicesPoliticians also took the stage to share their thoughts. Back Hye-ryun, a Democratic Party of Korea member, expressed in her congratulatory speech her commitment to protecting virtual asset users through legislation. Kim Jong-min, another lawmaker from the same party, underscored the unstoppable nature of the blockchain trend. Yun Chang-hyun, a lawmaker of the ruling People Power Party, mentioned that while Bitcoin couldn’t establish itself as a key currency in an anarchic manner, stablecoins and central bank digital currencies (CBDCs) are now positioned to fill that role.Regulatory considerationsMeanwhile, Kim So-young, Vice Chairman of the Financial Services Commission, stressed the ongoing uncertainty surrounding the societal impact of cryptocurrencies and how governments should oversee them. He emphasized that the Korean government aims to establish a balanced framework to facilitate the responsible development of digital assets. Furthermore, he highlighted the necessity of collaborating with major economies due to the global nature of virtual assets.

news
Loading