Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Sep 12, 2025

China funds research on stablecoin risks to financial system

China’s leading science foundation has initiated a research program to examine the effects of stablecoins, reflecting concerns that such digital currencies could pose a risk to the nation’s financial system and its fiat currency. According to the South China Morning Post, the National Natural Science Foundation of China (NSFC) is now offering grants for studies focused on stablecoins and the creation of cross-border monitoring frameworks. The foundation expressed that the unmonitored circulation of private stablecoins, particularly those pegged to the U.S. dollar, could weaken capital controls and present a potential challenge to the yuan. This initiative emerges as governments around the world, from the U.S. to regional financial centers, are actively developing rules for the digital asset sector.Photo by  Christian Lue on UnsplashStrategic research and internal debateThe NSFC will fund the projects with grants valued between 200,000 and 300,000 yuan ($28,042 to $42,063). Researchers are expected to complete their work within a year and deliver policy recommendations on how China can manage the challenges posed by global stablecoins and contribute to digital finance governance. The deadline for applications is Oct. 9. This research program is set against a backdrop of internal discussion in China regarding the possible launch of a yuan-backed stablecoin. While some economists support the idea of boosting the yuan's international profile, Bloomberg noted that former central bank governor Zhou Xiaochuan has advised caution. He recently said the high efficiency of China's current payment systems and warned that financial stability could be threatened by speculation in the stablecoin market. Analysts believe any state-sanctioned yuan stablecoin would likely be confined to offshore markets and tied to the offshore CNH. Global regulatory landscapeChina’s examination of stablecoins is part of a broader global trend of increased regulatory focus on the asset class. In Hong Kong, a new ordinance took effect on Aug. 1, creating a mandatory licensing system for stablecoin issuers under the oversight of the Hong Kong Monetary Authority. Other Asian nations are also taking action. South Korea’s government is reportedly exploring a model for a won-pegged stablecoin involving a consortium of banks and non-bank entities. Separately, Cointelegraph reported that Kyrgyzstan has introduced legislation outlining a regulatory framework for such assets. Developments are also accelerating in the U.S., where the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act was signed into law, creating a federal structure for stablecoin oversight. On a commercial level, a Minnesota-based credit union, St. Cloud Financial, intends to introduce its own stablecoin later this year, a move highlighted by Cointelegraph. This token, named Cloud Dollar (CLDUSD), is designed to integrate with the credit union's banking system to facilitate faster and cheaper transactions for its members within a regulated environment.

news
Web3 & Enterprise·

Sep 23, 2024

Hashgraph ecosystem developer explores use cases in Qatar

The Hashgraph Association, a non-profit organization that focuses on building an ecosystem of startups and enterprises relative to the use of the Hedera Hashgraph public ledger, has announced that it intends to explore use cases for the technology in Qatar. Hedera Hashgraph was first created in 2015 by Leemon Baird and Mance Harmon. The network is designed such that anyone can transact using it and deploy applications on it. However, governance is separated from consensus, with a group of businesses overseeing the network protocol.Photo by Hongbin on UnsplashFive key use casesIn a LinkedIn post published on September 19, the Hashgraph Association outlined that within the next 12 months, it would explore the implementation of five key use cases relative to the Hashgraph network in Qatar, collaborating with stakeholders within the Middle Eastern country in order to do so. First on its list is the tokenization of equities. During the TOKEN2049 event in Singapore earlier this week, the HBAR Foundation, another entity which supports the creation of Web3 communities on the Hedera network, launched the Hedera Asset Tokenization Studio.  According to the HBAR Foundation, the initiative “enables the seamless issuance and management of tokenized bonds and equities on the Hedera network.” The move, when considered in the context of the Hashgraph Association’s intentions relative to the pursuit of the tokenization of equities as a use case in Qatar, demonstrates that the distributed ledger technology (DLT) network’s most prominent stakeholders are homing in on this particular use case in furthering the use of the network.  Dr. Sabrina Tachdjian, the HBAR Foundation’s head of fintech and payments, stated that the  Asset Tokenization Studio will lower technical barriers to the tokenization of bonds and equities, along with the recording of their underlying data on the ledger. Sukuk tokenizationOther use cases up for exploration in Qatar are real estate tokenization and sukuk tokenization. A sukuk is an Islamic financial certificate. It’s a bond-like financial instrument which is sharia-compliant. The world’s first tokenized sukuk, linked to a sovereign instrument, was created in Malaysia in 2023.  Fusang Exchange listed the product, as a digitized version of a sukuk issued by the International Islamic Liquidity Management Corporation (IILM), represented via an ERC-20 token. Shariah-compliant finance represents a $4 trillion opportunity. Additionally, the Hashgraph Association is looking to exploit the carbon credit sector as a use case, while also looking towards the use of the Hedera Hashgraph ledger for the purpose of consumer engagement and loyalty programs. Digital assets frameworkOn September 1, the Qatar Financial Centre (QFC) announced that the Qatar Financial Centre Authority (QFCA) and the Qatar Financial Centre Regulatory Authority (QFCRA) had launched the QFC digital assets framework. The Hashgraph Association believes that the regulations strengthen its role in “fostering innovation and trust within the digital assets ecosystem, further solidifying the region’s position as a global leader in fintech.” In May, the Hashgraph Association announced at the Qatar Economic Forum a $50 million partnership with the QFC, with the goal of creating a digital assets venture studio in Qatar to support solutions built on the Hedera network.

news
Policy & Regulation·

Aug 29, 2023

Laos Halts Crypto Miners’ Electricity Amid Drought and Debts

Laos Halts Crypto Miners’ Electricity Amid Drought and DebtsLaos, a leading producer and exporter of hydroelectricity, has made the decision to suspend electricity supply to cryptocurrency mining operations within its borders.Photo by Ioana Farcas on UnsplashTackling a perfect stormThe decision comes as a result of a perfect storm of challenges, including a struggle to meet escalating power demands due to drought conditions, impending commitments to export electricity to Thailand, and the mounting debts of cryptocurrency mining companies.In a calculated move in 2021, Laos initiated a public-private pilot program aimed at delving into cryptocurrency mining and trading. The context for this move was China’s sweeping crackdown on mining activities, compelling miners to scout for alternative jurisdictions for their operations.In response, Laos granted authorization to a handful of entities, spanning construction conglomerates and a bank, to partake in the mining and trading of Bitcoin, Ethereum, and Litecoin. This led to a commitment to regulatory collaboration between government ministries, the Bank of Laos, and Electricité du Laos (EDL).Exploiting hydropowerLaos’ abundant and affordable electricity has placed it on the short list of locations for crypto miners to settle in. With an abundance of rivers and waterfalls, hydropower stands as one of the nation’s primary energy sources, offering a renewable source of cost-effective electricity.However, events in 2023 have disrupted that narrative. A persistent drought has hit the country during the first half of the year, which triggered an unprecedented surge in the demand for electricity from sources other than hydro.The dependence on hydropower, constituting 95% of the nation’s energy generation, struggled to keep pace with the demand. As a direct consequence, EDL, a state-owned electricity distributor, announced the cessation of electricity supply to crypto mining operations.The problem has compounded as Laos finds itself committed to exporting substantial quantities of electricity to the Electricity Generating Authority of Thailand (EGET), serving as a lifeline for Thailand’s power grid during the forthcoming dry season. This external commitment has, in turn, further strained the local capacity for electricity supply.Another Asian country, Bhutan, has also gotten involved with crypto mining in an effort to exploit its hydropower resources, where 99% of electricity supply comes from hydropower within the kingdom.Unpaid billsAnother dimension to the saga is the growing debt crisis faced by cryptocurrency mining operations. A representative of EDL cited the inability of these mining businesses to settle their accumulating electricity bills as a key factor in the decision for suspension. The Bank of Laos has further escalated matters by deciding to halt loans to cryptocurrency companies in January.Laos has had bold objectives to transform itself into Southeast Asia’s premier exporter of clean electricity. The nation’s topography, featuring mountainous terrain covering 70% of the country, has immense potential for hydropower, with over 26,000 megawatts of installed capacity and ambitious plans to double this figure.Hydroelectric dams like Nam Theun 2 have become conduits for substantial volumes of low-cost electricity, primarily directed towards neighboring Thailand and Vietnam. Meanwhile, projects like the Luang Prabang dam, boasting an installed capacity of 1,460 megawatts, underscore the country’s ambitions to develop hydropower further.Revenues from power exports have become a vital component in Laos’ gross domestic product (GDP), contributing almost 15%, as per a report from October 2022.

news
Loading