Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Jun 12, 2023

SBINFT and JPNFT Collaborate to Establish A Secure NFT Market in Japan

SBINFT and JPNFT Collaborate to Establish A Secure NFT Market in JapanSBINFT, a Japanese company specializing in NFT consulting and marketplace services, has joined forces with JPNFT, a Japanese platform dedicated to establishing a secure NFT market by combating unauthorized NFTs, according to a press release. Together, these entities are working towards the development of a marketplace that ensures users have access to secure and authorized NFTs, with the overarching aim of promoting the distribution of legitimate digital assets.Photo by Choong Deng Xiang on UnsplashRise of NFTsThe advent of blockchain technology has revolutionized the way digital assets are valued and their ownership is determined. This transformative technology has enabled the creation of non-fungible tokens (NFTs), which now serve as digital representations of various creations and are actively traded on dedicated marketplaces.Unauthorized NFTsSince 2021, numerous new players have entered the global NFT landscape. As of March 2023, OpenSea, the world’s largest NFT marketplace, boasts a monthly trading volume of $430 million. While this growth signals promising market development, it also brings forth challenges stemming from the proliferation of pirated and unauthorized NFTs. Considering Japan’s esteemed international reputation in the realms of art and content, the country possesses the potential to emerge as a significant player in the NFT market. However, to realize this potential, appropriate measures must be swiftly implemented to guarantee security and authenticity within the industry.License check & certification markIn order to tackle this challenge, SBINFT and JPNFT have joined forces to establish a safe and sound NFT market that ensures the availability of genuine NFTs for users. As part of this collaboration, content NFTs registered on the NFT disclosure information platform called “jpnft” will undergo a verification process for authenticity when traded on the “SBINFT Market.” This verification process will involve an official license check as well as the inclusion of a JPNFT certification mark.The launch of jpnft content on the SBINFT Market is planned for the summer of 2023. The jpnft platform plays a crucial role in distinguishing between licensed NFTs and unauthorized ones by publishing official information related to NFTs based on Japanese intellectual properties. Licensed NFTs will be either issued directly by rights holders or authorized by them. It’s worth noting that the jpnft platform was developed as a project supported by the subsidy for “Japan content localization and distribution (J-LOD)” in the 2021 Supplementary Budget of the Japanese Ministry of Economy, Trade and Industry.Previously known as nanakusa, the SBINFT Market is built on two public chains (Ethereum and Polygon) and is committed to becoming a global open marketplace and. With a focus on providing a secure trading environment, the SBINFT Market meticulously reviews NFTs to safeguard users from potential risks such as fraud and hacking.Both SBINFT and JPNFT share a common philosophy that emphasizes the security of NFTs and the healthy development of the industry. With this shared vision, the SBINFT Market aims to enhance its content offerings and position itself as an authorized NFT marketplace that handles NFTs on jpnft.Government initiativeLast month, the Working Group for Digital Society Promotion under Japan’s ruling Liberal Democratic Party (LDP) presented a proposal to Prime Minister Kishida Fumio regarding the Web3 industry. This proposal recommended the implementation of measures to safeguard Japanese content and data from unauthorized monetization by foreign entities. This initiative highlights the government’s endeavor to protect and promote the integrity of Japan’s digital assets.

news
Web3 & Enterprise·

Jun 30, 2025

Litigation set to fuel Bitcoin accumulation at Genius Group

Artificial intelligence-driven education technology firm, Genius Group, has announced a plan to buy Bitcoin from the proceeds of damages that the company is pursuing through the courts. In a press release published to the Singapore-headquartered company’s website on June 26, it outlined that the firm’s Board of Directors has approved a distribution plan that would see any potential damages received from litigation that Genius Group is currently embroiled in, divided equally for distribution to shareholders and for the purchase of Bitcoin for the company’s Bitcoin treasury.Photo by Kanchanara on UnsplashUp to $1 billion in potential damagesGenius Group CEO, Roger Hamilton, commented on the matter, stating:“We are seeking combined damages of over $1 billion. As both lawsuits are being pursued by the Company to recover damages caused by third parties directly to our shareholders, the Board believes that 100% of any proceeds from the successful outcome of these cases should be directly distributed or reinvested for the benefit of shareholders.” On X, Hamilton outlined that there’s no guarantee with regard to how much the company recovers through litigation. However, he added that if justice prevails and the company is awarded $1 billion in damages, that would equal a $7 dividend per share for shareholders and the addition of 5,000 BTC to the firm’s Bitcoin treasury. Last month, the company provided an update on a lawsuit it has taken under the Racketeer Influenced and Corrupt Organizations (RICO) Act. Initially, $450 million in damages had been pursued but Genius Group amended the lawsuit, raising its claim to $750 million.  The lawsuit is being taken against Peter Ritz and Michael Moe as the controlling officers and directors of LZGI International, and against Michael Carter and John Clayton, in the United States District Court, Southern District of Florida. The company alleges that the defendants attempted to defraud Genius Group.  ‘Bitcoin First’Genius Group announced its “Bitcoin First” approach, and the launch of a Bitcoin treasury in November 2024, getting started with an initial purchase of 110 BTC valued at $10 million at that time. In April 2025, a New York court prohibited the company from selling stocks in order to fund the purchase of Bitcoin. Those court-imposed funding restrictions led to the firm selling off a small proportion of the overall Bitcoin that it was holding.  Prior to that prohibition on the purchase of Bitcoin being imposed, Genius Group had expressed the aspiration to build up its Bitcoin reserve to a value equivalent to $100 million. Wading further into the Bitcoin space, the firm acquired blockchain learning platform, XD Academy, in December 2024. On May 22, Genius Group announced that the U.S. Court of Appeals had overturned the ban imposed on the company. With that, it increased its Bitcoin holdings by 40%. As of June 17, the company held 100 BTC, valued at around $10 million. The firm plans to bring forward another lawsuit “alleging naked short selling and evidence of spoofing against certain parties,” with damages being pursued in the region of $250 million. Commenting on the coming of age of Bitcoin and the pursuit of a Bitcoin treasury strategy back in November 2024, Hamilton stated that “we're living in a unique moment in history - one most public companies will miss.” 

news
Web3 & Enterprise·

Aug 14, 2023

RaonSecure to Develop Digital Identity Strategy for the Indonesian Government

RaonSecure to Develop Digital Identity Strategy for the Indonesian GovernmentRaonSecure, a South Korea-based decentralized identity (DID) service provider utilizing blockchain technology, has secured a contract with the Korea-Indonesia e-Government Cooperation Center. The contract involves providing consultation services aimed at devising a strategy for the implementation of a digital identity system in Indonesia. The selection of RaonSecure as the contract winner was orchestrated by Korea’s National Information Society Agency (NIA), and this strategic venture is being executed through the bilateral center.Photo by Ben Sweet on UnsplashBilateral center fostering tech exchangeEstablished in Jakarta in 2016, the bilateral center aims to facilitate the exchange of technological expertise between the Korean government and its Indonesian counterpart. This organization also serves to accelerate the entry of Korean enterprises into the Southeast Asian market.Indonesia’s national service portalAs the Indonesian government looks forward to establishing a national service portal, the need for a robust national digital identity system has been growing. This system is envisaged to support functionalities such as user authentication, e-signatures, and privacy protection.Blockchain-based DID implementationIn light of these needs, RaonSecure has emerged as a suitable company for the project, showcasing its technological prowess and stability. The Korean tech firm’s expertise has been evident in the successful deployment of its blockchain-powered DID platform, OmniOne, across diverse organizational settings. Noteworthy deployments include providing OmniOne for the issuance of identification cards to government employees, licensed drivers, and military veterans. Furthermore, RaonSecure has recently partnered with the Korea Federation of Savings Banks (KFSB) to develop a solution that verifies bank customers’ identities using mobile ID cards.The Indonesian venture is encouraging development for RaonSecure as it will serve as a gateway to not only fostering its presence within Southeast Asia but also propelling its reach far beyond, and the company’s blockchain DID technology will play a key role in spearheading this expansion into new horizons.

news
Loading