Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Nov 16, 2023

Web3 chatting app Beoble acquires $2 million in pre-seed funding round

Web3 chatting app Beoble acquires $2 million in pre-seed funding roundWeb3 social messaging app Beoble announced on Wednesday that it has secured a total of $2 million in pre-seed funding, gaining recognition for its innovative communication service technology and potential for future growth.Photo by Yura Fresh on UnsplashEmpowering individuals in the Web3 eraTargeted at the Hong Kong and Singaporean markets, Beoble is a Web3-based social messenger platform that employs a decentralized encryption network called the Communication Delivery Graph, which allows users to engage in end-to-end encrypted chatting between their digital wallets. It also offers a communication toolkit for integrating decentralized applications (dApps). The service emphasizes giving ownership to individuals rather than corporations, distributing “cat points” to users based on their participation and contribution to the ecosystem, which are then used to determine their eligibility for rewards like token airdrops. It currently supports all EVM-compatible blockchains like Ethereum and Polygon and plans to include others like Solana, Aptos and Sui.“Beoble’s new solution for facilitating communication among Web3 wallets will address the vulnerabilities in control and security that are characteristic of existing Web2 messaging platforms, making it a leader in the Web3 messaging market,” said Beoble CEO Cho Sung-min.Attracting industry giantsIn this pre-seed round, major investors include firms focusing on crypto and blockchain projects such as Digital Currency Group (DCG), HashKey Capital and GBV Capital. Notably, Samsung Electronics’ venture capital arm, Samsung Next, also participated as an investor.Furthermore, Beoble has received acclaim from experts for providing a direct communication channel among Web3 wallet owners and allowing them to conduct non-fungible token (NFT) and peer-to-peer (P2P) transactions. The company was also selected for the Web3 incubation program conducted by internet juggernaut Kakao’s public open-source blockchain, Klaytn, in April of last year.Beoble is currently accepting pre-registration applications for beta testing until Nov. 30 and will launch the beta version on Dec. 2.

news
Policy & Regulation·

Jun 13, 2023

China Launches Digital Yuan ATMs in Hainan Resort City of Sanya

China Launches Digital Yuan ATMs in Hainan Resort City of SanyaThe latest in a long list of initiatives to bring about further use of China’s digital yuan has seen the introduction of e-CNY ATM machines within the resort city of Sanya on Hainan Island. That’s according to a recent report published by the South China Morning Post (SCMP).Photo by Monstera on PexelsInternational currency exchangeThe introduction of e-CNY foreign exchange machines aims to provide visitors with easy access to digital payments and enhance their experience in the local mobile payments ecosystem. Resembling traditional ATMs, these machines allow tourists to deposit 20 different currencies, including US dollars and euros, and receive a physical card loaded with e-CNY in return.The card can be used for seamless payments at participating merchants with a simple tap. Travelers can also use the machines to top up their e-CNY balance, check transaction records, and manage their funds.This initiative addresses the needs of tourists who often face challenges setting up Chinese mobile wallets, which have become essential for retail, dining, transportation, and shopping. These mobile wallets typically require real-name verification and a local bank account, posing difficulties for foreign visitors.While limited prepaid options have been available in recent years, the e-CNY card now offers a convenient digital payment solution without the need to download a separate app. The machines are currently available in two cities, with the Bank of China (BOC), one of 11 authorized banks for e-CNY, leading the development of these innovative devices.Earlier this year, BOC launched a similar foreign exchange machine at Yiwu International Trade City in Zhejiang province, emphasizing China’s efforts to promote digital currency and facilitate financial accessibility. Both Zhejiang and Hainan have been striving to become attractive destinations for foreign tourists and merchants. In May, administrators within the local government in Jiangsu Province confirmed that they would be launching an initiative to promote use of the digital currency within the local education system.The introduction of these machines aligns with Beijing’s mission to develop and promote its sovereign digital currency, known as the Digital Currency Electronic Payment (DCEP). The project, which began trials in 2019, aimed to enhance financial inclusion and digital finance accessibility for unbanked individuals.Digital yuan internationalizationChina has been actively pursuing the internationalization of the digital yuan, seeking to facilitate yuan-denominated trade and investment, while reducing reliance on the existing global financial system. In May, the BOC entered into a partnership with French financial services firm BNP Paribas that will see the company promote e-CNY to its corporate clients.China’s efforts to promote cross-border use of e-CNY extend to regions like Hong Kong, a key offshore yuan center. A trial of the e-CNY for cross-border payments took place last year, facilitating more than 150 million yuan ($22 million) of cross-border e-CNY transfers in 160 payments, involving 20 commercial banks in Hong Kong, Thailand, and the United Arab Emirates (UAE).As China continues to make inroads where adoption and use of the e-CNY are concerned, these developments signal a significant shift in the way we can expect sovereign currencies to be made available globally.

news
Policy & Regulation·

Dec 08, 2023

Bitzlato co-founder to pleads guilty in US to illicit funds processing

Bitzlato co-founder to pleads guilty in US to illicit funds processingAnatoly Legkodymov, the co-founder and majority owner of Hong Kong-registered virtual currency exchange Bitzlato, entered a guilty plea in a U.S. court on Wednesday in relation to illicit funds transfer activity.Photo by Max Sandelin on UnsplashNew York court appearanceAccording to a Department of Justice press release, Legkodymov, a Russian national, appeared before U.S. District Judge Eric Vitaliano for a “criminal cause for pleading,” signaling a guilty plea.Legkodymov, 41, was arrested in Miami on Jan. 17 and has been held at the Metropolitan Detention Center (MDC) in Brooklyn since then. U.S. authorities accused him of processing approximately $700 million in illicit funds through Bitzlato, a platform headquartered in Hong Kong.The charges related to operating the platform as an unlicensed money exchange business. Allegedly, he engaged in significant cryptocurrency swaps with Hydra Market, described as a marketplace involved in drugs, stolen financial information and money laundering services.United States Attorney for the Eastern District of New York, Breon Peace stated:“Legkodymov’s guilty plea today confirms that he was well aware that Bitzlato, his cryptocurrency exchange, was being used like an open turnstile by criminals eager to take advantage of his lax controls over illicit money transactions.”The Department of Justice maintained that Bitzlato becoming “a haven for criminal proceeds and funds intended for use in criminal activity” was as a result of its “deficient know-your-customer (KYC) procedures.”Website taken downBitzlato’s website has been replaced by a notice stating that the service was seized by French authorities as part of an international law enforcement action coordinated with U.S. and German law enforcement shutting down Hydra Market in April 2022.This guilty plea is the latest development in U.S. law enforcement’s broader efforts to crack down on fraud and illicit financial activities within the cryptocurrency markets. In recent cases, FTX founder Sam Bankman-Fried was convicted for stealing billions from customers, while Binance agreed to a $4.3 billion settlement, with CEO Changpeng Zhao (CZ) pleading guilty to violating U.S. anti-money laundering laws. Binance was identified as one of Bitzlato’s top counterparties by U.S. authorities.Russia calls for Legkodymov’s releaseDespite calls from Russia’s embassy in Washington for Legkodymov’s release and an embassy visit to him in jail, the U.S. State Department confirmed that Russia rejected a proposal for the release of two Americans, including Wall Street Journal reporter Evan Gershkovich. This follows Russia’s denial of a U.S. embassy request to visit Gershkovich. The diplomatic exchanges underscore the international dimension of the case and the geopolitical tensions surrounding the detention of individuals in both countries.As U.S. law enforcement continues its efforts to combat cryptocurrency-related crimes, the anticipated guilty plea of Bitzlato’s co-founder highlights the regulatory scrutiny and consequences faced by those involved in illicit financial activities within the crypto industry.

news
Loading