Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Jun 26, 2023

GS Group Supports Blockchain Startups in Korean Retail Industry

GS Group Supports Blockchain Startups in Korean Retail IndustryThe GS Challenge, an innovative startup accelerator established through a partnership between South Korean conglomerate GS Group and early-stage venture capital fund Bluepoint Partners, has launched a program dedicated to providing support to innovative startups, including blockchain ventures, in the retail industry.Photo by Alexandru Tugui on UnsplashBlockchain & other retail solutionsThe application window for this program opened on June 16 and will remain accessible until July 13. To be eligible, applicants have to be startups that possess retail technology and have a team consisting of two or more members. Retail technology encompasses a wide range of solutions aimed at improving businesses’ understanding of their customers, streamlining inventory management, and optimizing promotional events. These solutions leverage cutting-edge technologies such as artificial intelligence, big data, cloud computing, blockchain, and the Internet of Things (IoT).Three-month programThe screening process for applicants will involve thorough document reviews and meetings conducted by both entities. Successful applicants will have the opportunity to participate in a comprehensive three-month acceleration program scheduled from August to October. This program will offer valuable guidance on various aspects of running a startup, including consultations on legal, human resources, and financial matters.Extensive retail networkAdditionally, the selected startups will gain access to the GS Retail infrastructure to test their technologies and products. GS Retail boasts an extensive network consisting of 16,000 convenience stores, 400 supermarkets, as well as infomercial and e-commerce channels. This opportunity will enable the startups to test their technology and products in a real-world retail environment, facilitating practical application and market integration.Expressing the insights gained from a decade of startup investments, Lee Sung-hwa, the VP of Corporate Development at GS Retail, emphasized the value derived from collaborating with startups. Recognizing the mutual benefits, Lee highlighted that this collaboration would prove advantageous for both GS Retail and the participating startups. GS Retail can foster innovation in the industry, while the startups can accelerate their growth by leveraging the extensive GS Retail network.

news
Policy & Regulation·

May 09, 2024

Binance collaborates with Indian authorities to dismantle scam app

The Enforcement Directorate (ED) — an Indian law enforcement agency — seized 90 crores ($10.5 million) from an online scam app called E-Nuggets with the help of global crypto exchange Binance.  ED is the governmental law enforcement agency responsible for enforcing economic laws and with that, tackling economic crime. According to a report published by Indian English language daily newspaper The Hindu, the online gaming app E-Nugget had cryptocurrencies worth $10 million stored in 70 different crypto wallet accounts spread across the three crypto exchanges.  Local Indian exchanges ZebPay and WazirX also aided the ED in its investigations and subsequent actions. The ED contacted these exchanges to block the wallet addresses and transfer the crypto assets to the agency’s wallet. Photo by Naveed Ahmed on UnsplashCrypto assets seizedThe ED, tasked with upholding such financial crimes, spearheaded the operation against E-Nuggets, an online gaming platform masquerading as a legitimate investment opportunity. Taking to the X social media platform on April 30, the Indian law enforcement agency stated: “ED, Kolkata led a successful operation against a major “online gaming app scam” known as “E-Nugget”. The E-Nugget app, masqueraded as a gaming platform, promised users high returns on their investments. Crypto assets which were taken into possession of ED are transferred into Crypto Wallet of ED.” 70 wallets implicatedWith cryptocurrencies valued at $10 million spread across 70 different wallet accounts on three crypto exchanges, the agency swiftly took action. E-Nuggets enticed unsuspecting investors with promises of substantial returns through its purported gaming interface. However, once investments were made, the platform vanished into thin air, leaving users unable to recoup their funds. The ED's investigation revealed a complex web of deceit, with the agency seizing properties totaling over 163 crores ($19.5 million), comprising cash, cryptocurrency holdings, account balances and office spaces. The scam involved the funneling of funds into digital assets through 2,500 dummy bank accounts, resulting in the discovery of 19 crores ($2.2 million) in cash. A first information report (FIR) filed at the Park Street Police Station in Kolkata, became the catalyst that triggered the ED case that was subsequently registered under the provisions of India’s Prevention of Money Laundering Act (PMLA). Masterminded by Aamir Khan, who was apprehended alongside accomplice Romen Agarwal, the scheme operated under the guise of digital transactions, which, ironically, facilitated its unraveling. Law enforcement agencies adeptly traced, froze and seized the illicit funds as they moved through the digital realm. Public ledger upends scammersCritics often point to the potential for cryptocurrency to facilitate money laundering. However, the inherent transparency of blockchain technology presents significant obstacles to such illicit activities. Notably, in the infamous 2016 Bitfinex hack, where hackers absconded with 119,756 Bitcoin, the culprits were eventually apprehended in 2022 while attempting to launder the stolen funds. The collaborative efforts between Binance, the ED, and local exchanges points to a developing commitment towards combating financial fraud within the cryptocurrency space. This wasn’t the first occasion in which Binance had cooperated with law enforcement on such matters. In October of last year, the company got with the Thai authorities to assist them in crushing a crypto-related scam. By leveraging blockchain's transparency and international cooperation, authorities can effectively dismantle illicit schemes, safeguarding investors and upholding the integrity of the digital asset ecosystem.

news
Web3 & Enterprise·

Jun 28, 2023

Bithumb Introduces Crypto Data Service Amid Fight for Profitability

Bithumb Introduces Crypto Data Service Amid Fight for ProfitabilityBithumb, one of the major cryptocurrency exchanges in South Korea, has announced the launch of a new service called Insight, aimed at providing real-time data and analytics about crypto trading. This strategic step is seen as part of Bithumb’s response to address its recent profitability challenges.Market patterns and trendsThe service, as reported by local news agency Yonhap News, leverages customers’ data to deliver market patterns in real time. By utilizing Insight, users can gain access to information such as the top three most-searched cryptos, rankings of price growth over specific periods, and price trends of major cryptos.In addition to these features, Bithumb offers insights into the trading behavior of the largest investors on the platform by showcasing the types and proportions of cryptocurrencies they purchased on the previous day. This functionality enables ordinary investors to gain a glimpse into the strategies employed by these influential players.Bithumb provides indicators that identify cryptos experiencing upward momentum or reaching their lowest points. Users can also access other data, including Bitcoin dominance, which indicates Bitcoin’s market capitalization relative to the overall crypto market cap. Additionally, the service presents information regarding the volatility of recently listed cryptos and those that have been flagged by the exchange as potentially concerning.Photo by Алекс Арцибашев on UnsplashDesktop and Android firstThe service is accessible today starting from 11:00 AM (Korea Standard Time) on desktop and Android. The iOS version is set to be released at a later time.Recent strugglesThe Korean crypto exchange’s move comes after Bithumb Korea, the exchange’s operator, has embarked on streamlining its businesses. Due to difficulties in generating profits, Bithumb Korea shut down its tech solution subsidiary Bithumb Systems, which was responsible for developing blockchain and exchange technology.Prior to that, the Bithumb exchange had closed its research center due to a decline in trading volume, even though the facility had significant value in aiding investors to make more knowledgeable choices.

news
Loading