Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Nov 28, 2023

Crypto Travel Rule solutions provider CODE obtains ISO/IEC 27001 certification

Crypto Travel Rule solutions provider CODE obtains ISO/IEC 27001 certificationCODE, a Travel Rule solutions provider and joint venture co-founded by Korean cryptocurrency exchanges Bithumb, Coinone and Korbit, announced on Tuesday (local time) that it has obtained ISO/IEC 27001 certification for information security management systems (ISMS).Photo by Scott Graham on UnsplashEnhanced cybersecurity and operational resilienceThe ISO/IEC 27001 is a standard by which companies can develop, implement, maintain and improve their ISMS to carry out robust risk management, cybersecurity and operational excellence as required by institutions like the European Union’s General Data Protection Regulation (EU GDPR).“CODE will provide a service environment that encourages confidence in our corporate members and the overall market starting with the acquisition of this information security management system certification,” said Lee Sung-mi, CEO of CODE.Consecutive effortsAs a Travel Rule solutions provider, CODE has been ramping up efforts to strengthen its compliance and information security capabilities. The company’s ISO/IEC 27001 certification comes shortly after it obtained ISO 37301 certification from the Korea Compliance Initiative (KCI). ISO 37301 is a standard for compliance management systems (CMS) that assesses organizations based on their compliance with laws, regulations, codes of conduct and more to exercise good governance, transparency and accountability.

news
Policy & Regulation·

Nov 23, 2023

Mammoth Foundation signs deal with the Philippines’ AFAB for blockchain business collaboration

Mammoth Foundation signs deal with the Philippines’ AFAB for blockchain business collaborationThe Mammoth Foundation, a blockchain research and development company, announced on Thursday that it has signed a memorandum of understanding (MOU) with the Authority of the Freeport Area of Bataan (AFAB) of the Philippines to establish business partnerships in the blockchain field. Under this agreement, the Mammoth Foundation intends to bring its blockchain technology to the Philippines as a part of efforts to expand its global business.Photo by Sean Yoro on UnsplashFostering innovation in the PhilippinesAFAB is a free economic zone in the Philippines dedicated to pushing development, economic growth and sustainability through creating jobs and establishing technologically-relevant infrastructure systems. In particular, it is focusing on the adoption of cutting-edge technologies such as blockchain, artificial intelligence (AI) and fintech. As one of the oldest free economic zones in Asia, companies residing in the zone are granted preferential measures such as tax exemptions and special visas. Firms that operate innovative businesses can also receive licenses to support the development of the global IT industry — the Mammoth Foundation being one of these.Global expansion and daily engagementHeadquartered in Singapore with offices in the United Kingdom and several Asian countries, the Mammoth Foundation offers dApps in a range of fields such as healthcare, e-commerce, entertainment and gaming through its mainnet Giant Mammoth Chain (GMMT). GMMT is built on the BNB Chain Application Sidechain and is fully compatible with the Ethereum virtual machine (EVM).Participants in GMMT can acquire token rewards through Play-to-Earn (P2E) and Life-to-Earn (L2E) mechanisms by participating in everyday activities and hobbies like walking, shopping, gaming and reading comics. These tokens can then be used within the Mammoth ecosystem.“The Philippines’ market for advanced technologies such as AI and blockchain is expected to grow in the future,” said John Baek, Chairman of the Mammoth Foundation. “We will strive to expand GMMT globally.”

news
Web3 & Enterprise·

Nov 06, 2023

X-TICKET teams up with Catalyze Research for XRPL expansion

X-TICKET teams up with Catalyze Research for XRPL expansionSouth Korean Web3 performing arts platform X-TICKET has signed a memorandum of understanding (MOU) with Catalyze Research, a Web3 research firm and an official partner of Ripple, to jointly expand the XRP Ledger (XRPL) ecosystem and support the integration of Web3 into Korea’s performing arts landscape.Photo by Kanchanara on Unsplash“We are delighted to work alongside Catalyze Research. The XRPL ecosystem, together with XRP, is poised to play a significant role in bringing the Korean performing arts industry onto the global stage. We hope to create synergies through collaborations with Korean cultural performances,” said X-TICKET CEO Shin Yong-un.Leading a new era of event ticketingX-TICKET harnesses blockchain technology to provide digital collectible tickets for performing arts shows, including live musicals like “Cats” and “The Phantom of the Opera.” This service is expected to revolutionize the industry by preventing various problems that tend to occur with ticketing, such as duplication, loss and scalping, thus fostering a secure, transparent and efficient performing arts ecosystem. The platform recently launched its beta version and held a sales event for NFT tickets to “The Phantom of the Opera” shows.Pioneering Web3 solutionsCatalyze Research, on the other hand, specializes in Web3 and blockchain research and consultations. The firm teamed up with Ripple in July to expand the presence of XRPL in the Korean market — a decentralized, public blockchain for businesses and developers — and encourage participation in the XRPL developer community.“Catalyze Research is actively engaged in numerous collaborations to expand the XRPL ecosystem. We plan to implement blockchain technology into X-TICKET and the Korean performing arts sector to extend the ecosystem’s reach,” the firm stated.The partnership between the two enterprises represents a significant step forward in the intersection of technology and the arts in Korea.

news
Loading