Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Jun 05, 2023

Korean Firms Join Forces to Expand the Security Token Market

Korean Firms Join Forces to Expand the Security Token MarketSouth Korean tech firm AIITONE announced today that it signed a memorandum of understanding (MOU) with real estate developer Korea Asset Development to expand security token businesses, according to a report by news agency Newsis.Photo by Shubham Dhage on UnsplashVentures into fintechAIITONE is renowned for its expertise in applying extended reality (XR) technology to smart defense and metaverse projects. In their latest strategic move, they have hired a blockchain tech group to venture into fintech sectors, with a specific focus on security tokens.Real estate expertiseKorea Asset Development, a real estate developer engaged in multiple projects nationwide, is currently involved in the development of upscale housing in Seoul and Busan, high-end residences in Songdo, as well as luxury resorts in Chungcheong and Gangwon Provinces.Through their collaborative endeavors, AIITONE and Korea Asset Development seek to capitalize on their respective technological expertise and knowledge. They plan to share their know-how and establish a comprehensive cooperation framework, specifically targeting content development associated with security tokens. Furthermore, both parties have committed to consistently exploring new areas of cooperation.Security token opportunitiesIn particular, the two companies have identified real estate due to its relatively easier valuation compared to other assets. The market for real estate security tokens in Korea is projected to reach 34 trillion KRW ($26 billion) by 2024. It is estimated that financial services, including real estate, account for approximately 70% of the total security token market size.AIITONE CEO Lee Jin-yup underlined the importance of cooperation with a range of players that bring diverse resources, considering that the security token market involves high-value tangible assets such as real estate, music, and artworks. He said the partnership with Korea Asset Development will help the company secure a competitive edge in the burgeoning real estate security token market.Development in JapanNot just South Korea, but other East Asian nations too are experiencing significant strides in the security token market. Japan serves as a case in point, with companies like Mitsui & Co. Digital Asset Management (Mitsui & Co. DAM) exploring the potential of this emerging market.Mitsui & Co. DAM last month introduced a platform that allows retail investors to access security tokens backed by real-world assets. This initiative opens up previously inaccessible investment opportunities to a broader range of participants.Moreover, the Tokyo Metropolitan Government has taken an active role in supporting security token businesses within its jurisdiction. From May 31, 2023, to February 29, 2024, the government runs a subsidy program for security token projects based in the capital city. Under this program, eligible businesses can receive subsidies of up to 5 million yen ($36,000) per project.

news
Web3 & Enterprise·

Feb 15, 2024

Game company behind XPLA blockchain witnesses growth in revenue last year

Com2uS Holdings, the South Korean game publishing company behind Layer 1 blockchain XPLA, disclosed today that its revenue last year saw a 22.5% increase from 2022, reaching KRW 142.3 billion ($106.7 million). On the back of the revenue growth, the company's consolidated operating loss narrowed to KRW 14 billion, improving from 2022’s KRW 26.4 billion. Additionally, the net loss decreased to KRW 16.5 billion, down from the previous year’s KRW 70.6 billion. The operating loss for the fourth quarter stood at KRW 16.5 billion, showing an improvement from 2022 Q4's KRW 20.9 billion. During the same period, revenue reached KRW 21.4 billion, and the net loss was recorded at KRW 8 billion.Photo by Andrey Metelev on UnsplashGame sales and marketing expensesCom2uS Holdings attributed the increase in profits to game sales growth, which was encouraged by the release of more games. However, the company also noted a decrease in income from investments in associates and an increase in marketing expenses, which were driven by the launch of new games. Last year's operating expenses totaled KRW 156.4 billion. Labor costs, which constitute the largest portion of operating expenses, experienced a year-on-year decrease of 6.2%, amounting to KRW 46.7 billion. In contrast, there was an increase in spending across three areas: commissions rose by 43.8% to KRW 30.7 billion, loyalty expenses increased by 26.6% to KRW 25.1 billion and marketing saw a jump of 134.9% to KRW 21.1 billion. According to a report from local news agency Yonhap, Jung Chul-ho, CEO of Com2uS Holdings, emphasized at the earnings presentation today that the company is committed to growth in game publishing, blockchain projects and platform initiatives, all directed towards enhancing the company's value.Triple-A games on XPLA blockchainAs part of the company’s blockchain endeavors, the XPLA platform is set to focus on improving user convenience and incorporating major content, including a variety of triple-A games. Looking ahead, Com2uS Holdings anticipates that its idle role-playing game, Soul Strike, will contribute to the company's revenue for the first quarter. Since its debut last month, Soul Strike has been attracting attention not only in Korea but across Asia. The game publisher also outlined its global release plans for the MMORPG, Zenonia Chronobreak. Gamers in Taiwan can expect access to the game in the second quarter, while those in Japan and others will be able to play in the fourth quarter.

news
Web3 & Enterprise·

May 25, 2023

OCBC Bank Partners With ADDX to Launch Tokenized Note

OCBC Bank Partners With ADDX to Launch Tokenized NoteSingapore’s longest established bank, OCBC Bank, has partnered with blockchain-centric private market investment platform, ADDX, to launch a tokenized equity-linked structured note.Tokenized equity-based productsThe product is significant in that it represents the first tokenized equity-linked structured note that the cornerstone bank has offered. That in itself gives an indication of how conventional finance will mesh with tokenized products as both the conventional finance system and digital assets space evolve over the coming years.An equity-linked note is a debt instrument, normally in the form of a bond. It’s distinct from a standard fixed income security as it’s a market-linked structured product. That means that it performs in sync with a particular equity stock, a basket of equity stocks or with an equity index.ADDX CEO Oi-Yee Choo elaborated on the product offering: “Structured products are designed to provide investors with unique risk and return characteristics that may not be available through traditional investments, and are an attractive option for investors weighing yield-generating options in the current economic climate.”Photo by Shubham Dhage on UnsplashLeveraging tokenizationBy leveraging tokenization, the ADDX platform realizes cost savings, cutting out counterparties from the process. Additionally, tokenization allows fractionalization of assets and financial products, making a product offering accessible to all market participants. In this particular instance, the OCDC/ADDX product is restricted solely to accredited investors.Singapore-based ADDX currently lists in excess of seventy tokenized products on its platform right now. These range from commercial paper, bonds, real estate and equities or equity-based products.On those products it has collaborated with global alternative investment product specialists Investcorp and Hamilton Lane, telecommunications giant Singtel and securities broker CGS-CIMB Securities. Additionally, it has partnered with UOB, Singapore’s third largest bank, and a number of entities owned by state-owned Singaporean investing giant, Temasek.While the conventional finance world has been skeptical of digital assets and the overarching cryptocurrency and blockchain space has had its fair share of setbacks interlaced within its progression, forward-looking TradFi players are conscious of not getting left behind. That’s reflected in the comments of OCBC Bank’s Head of Global Treasury, Kenneth Lai, in relation to the ADDX partnership:”While we already have a comprehensive stable of treasury products which includes sustainability-linked interest rate swaps, cross currency swaps, structured deposits and green bonds, it is important that we continue to innovate and find new channels for our products. We are therefore pleased to be the first Singapore bank to offer an equity-linked structured note in tokenized form on ADDX. It is the first innovation resulting from a longer-term partnership with ADDX, and we are hopeful that it will lead to more diverse product offerings that are relevant and appealing to the global accredited investor base of ADDX.”Further comments by Choo suggest that the two firms have plans to broaden the partnership to encompass a greater range of products. She referred to more structured products being in the pipeline as the duo seek to exploit their combined expertise and capabilities.As it stands today, just $0.3 trillion in global assets are currently tokenized. That number is expected to grow to $16 trillion within seven years.

news
Loading