Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Apr 10, 2023

Korean Travel Rule Solution Provider Partners with ACAMS to Enhance AML Measures

Korean Travel Rule Solution Provider Partners with ACAMS to Enhance AML MeasuresConnect Digital Exchanges (Code), the Korean Travel Rule solution provider, announced today that it has forged a partnership with the Association of Certified Anti-Money Laundering Specialists (ACAMS), the largest international membership organization of its kind.©Pexels/Savvas StavrinosTravel RuleThe Travel Rule, issued by the Financial Action Task Force (FATF) to prevent money laundering and terrorist financing, requires virtual asset service providers to screen the information of the senders and recipients of crypto transactions.Code’s collaboration with ACAMSCode will collaborate with ACAMS to develop more effective anti-money laundering (AML) measures in Korea by producing anti-financial crime experts, and enhancing Travel Rule regulations. ACAMS offers internationally recognized training programs, with more than 40,000 certified AML specialists in over 175 countries and regions.More about CodeCode was jointly established by Korea’s major crypto exchanges Bithumb, Coinone, and Korbit in August 2021. Code recently published a report containing the Travel Rule operation results over the past year in Korea and its recommendations.

news
Web3 & Enterprise·

Feb 03, 2024

3AC-founded OPNX Exchange announces closure

In a recent announcement OPNX, the Seychelles-incorporated cryptocurrency bankruptcy claims platform co-founded by the creators of the now-defunct hedge fund Three Arrows Capital (3AC), has revealed its decision to cease all operations.Photo by Kelly Sikkema on UnsplashFebruary 14 shutdownIn a message to its users, subsequently shared on social media on Thursday, the OPNX team expressed its commitment to ensuring an orderly closure, urging users to settle all positions by Feb. 7 and withdraw their funds from the platform before Feb. 14, as all withdrawal functionality will be disabled thereafter. The team expressed gratitude to the OPNX community, acknowledging their dedication and trust throughout the platform's existence. Short for "Open Exchange," OPNX served as both a hybrid bankruptcy claims platform and a crypto exchange, enabling users to trade creditor claims of bankrupt crypto companies. The origin of OPNX can be linked to two defunct crypto entities — Coinflex and 3AC. Seychelles-based Coinflex was a crypto yield platform that was forced to suspend withdrawals in June 2022. It subsequently entered into a bankruptcy process. Coinflex co-founder Mark Lamb joined forces with 3AC’s Kyle Davies and Su Zhu to found OPNX. In October, Coinflex creditors sued Lamb, alleging that he had appropriated Coinflex's intellectual property, customer base, employees and technology to establish OPNX. Mired in problemsWithin its short existence, OPNX has been mired in problems. From the very outset, there was little goodwill for the new venture, given that many crypto sector participants took a dim view of Zhu and Davies due to the turmoil the collapse of 3AC caused within the industry. In April of last year, OPNX claimed to have significant venture capital backing, only for many of the VC entities mentioned to quickly deny such claims subsequently. The following month, the local regulator in Dubai, the Virtual Assets Regulatory Authority, formally reprimanded the OPNX founders for promoting an unregulated business within the Emirate of Dubai. In August, it emerged that VARA had hit OPNX and its founders with a hefty fine. Following the closure announcement, the native OX token of OPNX experienced a significant price decline. Over the course of the past 24 hours, the token unit price has fallen 13.6% to $0.007981. The failure of 3AC led to Teneo, the firm responsible for liquidating 3AC's assets, subpoenaing Zhu and Davies for concealing details of their physical whereabouts through messages on social media platform X. The closure of OPNX adds to the challenges faced by Zhu and Davies, as Teneo is actively seeking to recover $1.3 billion directly from the co-founders. The claim asserts that Zhu and Davies engaged in substantial leverage with investor funds after the insolvency of their hedge fund. In September 2023, Singapore's central bank issued nine-year prohibition orders against Davies and Zhu, citing alleged violations of the country's securities laws at Three Arrows Capital. All the while, crypto community sentiment remains negative where OPNX and its founders are concerned. Taking to social media, Ikigai Asset Management’s Travis Kling didn’t mince his words, stating:”I mean it from the bottom of my heart when I say **** these criminals.” As OPNX concludes its operations, the unfolding events surrounding its co-founders and their association with the failed hedge fund continue to draw attention to the need for the industry to raise its standards.  

news
Policy & Regulation·

Aug 08, 2023

Singapore Pledges $112M to Boost Fintech Solutions Including Web3

Singapore Pledges $112M to Boost Fintech Solutions Including Web3Acknowledging the growing significance of collaboration with industry stakeholders in propelling advancements in emergent technologies such as Web3, Singapore’s central bank, the Monetary Authority of Singapore (MAS), has unveiled plans to allocate up to 150 million Singapore dollars (approximately $112 million) towards supporting a spectrum of financial technology solutions, with a special focus on Web3.Photo by Jason Leung on UnsplashDistributed over three yearsThis financial commitment, outlined in a press release published to the MAS website on Monday, will be distributed over a three-year period as part of the revamped Financial Sector Technology and Innovation Scheme (FSTI 3.0), designed to invigorate and fortify innovation by backing projects that leverage cutting-edge technologies.The renewed innovation scheme encompasses multiple avenues, including the Enhanced Centre of Excellence track, the Environmental, Social and Governance (ESG) fintech track, and the Innovation Acceleration track — the last incorporating the realm of Web3.Emphasizing industry partnershipsMAS underlined the importance of forging partnerships with industry participants to bolster inventive fintech solutions originating from emerging technologies such as Web3.“MAS will conduct open calls for the use of innovative technologies in industry use cases. Grant funding will be provided to support actual trial and commercialization,” the central bank stated.In addition to these efforts, the initiative will maintain its commitment to encouraging adoption across domains like artificial intelligence, data analytics, and regulatory technology (RegTech). Furthermore, there will be an emphasis on fostering adoption within companies that are still digitally maturing and seeking to integrate RegTech solutions.Applicants across the various program tracks will be required to allocate resources toward nurturing talent. This strategy aims to augment Singapore’s fintech talent pool, ultimately contributing to the nation’s expertise in the sector.Ravi Menon, the Managing Director of MAS, underscored the substantial investment that the Financial Sector Development Fund (FSDF) has funneled into the FSTI program since its inception in 2015.Menon highlighted that this initiative’s overarching objective is to spur innovation and facilitate the seamless integration of novel technologies within the financial landscape. Over the years, the program has exemplified its commitment to driving transformation and pioneering the adoption of new technology across the financial sector.Nurturing Web3 innovationPotential Web3 and crypto hubs have come and gone, but Singapore has been vying to take its place as a center for Web3 innovation over a sustained period after it suffered some setbacks in 2022 related to a string of crypto business failures.While Binance had not been permitted to serve customers in the city-state, that meant that a disproportionate number of Singaporeans got caught up in the failure of the FTX crypto exchange. Alongside that regulatory failure, state investment giant Temasek had to write off a substantial investment in the company, while suffering reputational damage for not having detected the FTX fraud.The city-state has also been home to the failure of crypto lender Hodlnaut and crypto hedge fund Three Arrows Capital (3AC). Despite these setbacks, Singaporean authorities are continuing to work towards setting the proper stage to further develop Web3 innovation. In June, MAS proposed a comprehensive framework for the design of open networks relative to tokenized digital assets. This latest initiative will further Singapore’s ambition to grow its Web3 sector.

news
Loading