Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Nov 14, 2023

India’s judiciary turns down plea to formulate a crypto regulatory framework

India’s judiciary turns down plea to formulate a crypto regulatory frameworkThe Indian courts have declined a consideration targeting the establishment of a regulatory framework for cryptocurrency trading, following a plea which had been brought to court by a petitioner.Photo by Naveed Ahmed on UnsplashBeyond the court’s purviewIndia’s Supreme Court, led by Chief Justice Chandrachud, recently confronted a petition urging the establishment of a regulatory framework for cryptocurrency trading. According to a local media report, the bench, which included Justices JD Pardiwala and Manoj Misra, dismissed the plea, emphasizing that the demands presented were legislative and thus beyond the court’s direct action purview. This decision points to the judiciary’s recognition of its constraints in crafting laws, particularly in intricate domains like cryptocurrency.The petitioner, Manu Prashant Wig, a former director at Blue Fox Motion Picture Limited currently in custody due to allegations of cryptocurrency fraud, sought relief through a public interest litigation (PIL) for crypto trading regulations in India.The Economic Offence Wing (EOW) of the Delhi Police accused Wig in 2020 of deceiving investors with promises of high returns from crypto investments, involving 133 reported victims of the scheme. Despite this, during the hearing, the Supreme Court advised Wig to pursue legal remedies through appropriate channels, specifically for bail, underlining its inability to issue directives under Article 32 of the Constitution for legislative matters.Judiciary criticize governmentWhile the judiciary has found that it cannot act itself in putting in place a crypto regulatory framework, the Supreme Court has been critical of the government’s inaction on the matter. In July, India’s highest court criticized the Indian government for its failure to establish clear cryptocurrency regulations.Interestingly, while the government hasn’t acted locally, it has been making efforts to drive regulation at an international level instead. The status of cryptocurrency trading in India remains uncertain, with the country developing a regulatory framework influenced by recommendations from the International Monetary Fund (IMF) and the Financial Stability Board (FSB), potentially leading to legal legislation within the next several months.Prime Minister Modi called on authorities internationally to establish a worldwide regulatory framework. At the recent G20 summit, it appears that member states did reach agreement on such a framework.The Supreme Court’s dismissal of the PIL marks a clear distinction between judicial and legislative responsibilities. As India moves closer to formulating a comprehensive crypto regulatory framework, this decision reinforces the imperative for legislative action to address mounting concerns and interests in the crypto market.Awaiting legislative actionThe outcome of these developments is keenly awaited by investors, legal experts and the crypto community, poised to shape the future landscape of cryptocurrency trading in India. The decision signifies the judiciary’s acknowledgment of its limitations and highlights the necessity for a legislative approach to effectively navigate the intricate landscape of cryptocurrency regulation.In this evolving scenario, the verdict amplifies the importance of a well-defined regulatory framework. As the world’s most populous country grapples with the delicate task of balancing innovation and investor protection, the Supreme Court’s decision places the ball firmly in the legislative court.

news
Policy & Regulation·

Dec 08, 2023

Korea invites distinguished financial officials to discuss digital money

Korea invites distinguished financial officials to discuss digital moneyThe Bank of Korea (BOK), South Korea’s central bank, announced on Friday (local time) its participation in an international conference focused on the economic impact and future prospects of digital currencies. This event, co-hosted by the BOK, the Ministry of Economy and Finance (MOEF), the Financial Services Commission (FSC), and the International Monetary Fund (IMF), is scheduled to take place in Seoul on Dec. 14 and 15.The conference, titled “Digital Money: Navigating a Changing Financial Landscape,” is set to welcome high-ranking officials such as Kristalina Georgieva, the Managing Director of the IMF; Choo Kyung-ho, the Minister of the Ministry of Economy and Finance (MOEF); Rhee Chang-yong, the Governor of the Bank of Korea (BOK); and Kim So-young, the Vice Chairman of the Financial Services Commission (FSC). This event is particularly significant as it marks the first visit of IMF head Kristalina Georgieva to South Korea.Photo by pan zhen on UnsplashCrypto, stablecoins, CBDCsDuring the conference, MOEF Minister Choo and FSC Vice Chairman Kim will kick off the event with welcome remarks, followed by a keynote speech from IMF’s Managing Director, Kristalina Georgieva. Spanning over two days, the conference will include seven sessions, covering a diverse range of topics. These sessions will delve into various aspects of digital money, such as practical use cases of digital currencies, regulatory approaches to cryptocurrencies, and discussions on stablecoins and central bank digital currencies (CBDCs).The conference will feature prominent financial officials in both its opening and closing sessions. On the first day, Thursday, a distinguished panel, including IMF Chief Georgieva; Stefan Ingves, the former Governor of Sveriges Riksbank; FSC Vice Chairman Kim; David E. Rutter, the Founder of R3; and Shin Hyun-song, the Economic Adviser at the Bank of International Settlements (BIS), will discuss the opportunities and challenges facing digital money.The final session on Friday will see another group of high-level financial authorities sharing their expertise and insights. This session will include BOK Governor Rhee; Eddie Yue, the Chief Executive of the Hong Kong Monetary Authority; Serey Chea, the Governor of the National Bank of Cambodia; and Veerathai Santiprabhob, the former Governor of the Bank of Thailand. Their discussion will focus on regulatory policies surrounding digital currencies.Live-streaming scheduledThe two sessions of this conference will be accessible to a global audience as they will be live-streamed on the BOK’s official YouTube channel. This provides an opportunity for interested individuals from around the world to tune in and gain insights into the evolving landscape of digital money and its regulatory environment.

news
Web3 & Enterprise·

Apr 01, 2024

Metaverse game project 'Carrieverse' attracts over 100K DAUs

Carrieverse, a South Korean blockchain gaming project based in the Metaverse, launched its global version on March 28. Since then, the game has reportedly seen over 100,000 daily active users (DAU) every day, hitting 150,000 DAUs on its first day of release. The DAU index and related infographics were released by Carrieverse on April 1, according to the local media outlet Kyunghyang Games.  A joint venture between Carriesoft and Mantisco, this blockchain-enabled metaverse platform provides users with various content centered around the life of the game's main character, "Carrie," and her friends. At the heart of the project lies the “Play, earn, and own” model. Aside from the content backed by the "Carrie and Friends" intellectual property (IP), the project has expanded its footprint by launching the Cling Wallet, the NFT project "Kola from the Space" and the crypto game "Superkola Tactics."Photo by GuerrillaBuzz on UnsplashUsers from Southeast Asia and Latin AmericaAccording to data provided by Carrieverse, a significant portion of its users come from Southeast Asian and Latin American countries. Notably, in Indonesia and Vietnam, Carrieverse ranked second and third respectively in the newly released game section of their Google Play Store. The game generated the 15th-largest revenues of all games played in the Philippines and the 16th-largest revenues in Thailand. Carrieverse is reportedly on the top 100 casual games on Google Play Store across 86 countries.  The game also topped the trending chart on the global blockchain ranking site "PlayToEarn" on the day of its global launch, securing second place as of the following Sunday.  Building a robust IP-based metaverse platform The CEO of Carrieverse, David Yoon, said that Carrieverse strives to lead the Korean blockchain gaming industry and contribute to Korea's reputation as a Web3 powerhouse. Yoon said, "A sound ecosystem is being created due to the increase in on-chain data such as wallet generation and conversion of the governance token $CVTX, as well as the increased incineration of Celeb, which can be exchanged for $CVTX. The value of the game and $CVTX will continue to rise further." Carrieverse has also announced plans for various large-scale IP collaborations with other companies, intending to become an IP-based metaverse platform with high DAUs.  

news
Loading