Top

HTX and Heco Chain exploited with $115 million loss

Policy & Regulation·November 24, 2023, 2:14 AM

Seychelles-incorporated cryptocurrency exchange HTX, linked to digital-asset entrepreneur Justin Sun, has fallen victim to a significant hack, only a few months after having suffered another hack in September.

Photo by Markus Spiske on Unsplash

 

Second HTX hack in recent months

The last hack, involving a loss of digital assets to the value of $8 million, was resolved when the hacker agreed to return funds in October in return for a goodwill payment of around $400,000.

This latest unfortunate incident follows another hack on Poloniex, also associated with Sun, just weeks ago. Sun acknowledged the HTX hack in a tweet, announcing the temporary suspension of deposits and withdrawals without specifying the exact amount pilfered.

 

Separate Heco Chain hack

It is understood that approximately $30 million worth of cryptocurrencies was siphoned from the exchange wallet. The platform is actively investigating the breach, aiming to uncover the specifics surrounding the attack. Simultaneously, the HECO Bridge, which was established by HTX for cost-effective fund transfers across different blockchains, experienced a separate hack.

This breach resulted in losses exceeding $85 million, including ETH, US dollar stablecoin Tether (USDT) and various other tokens. Although initially launched by HTX, HECO operates independently from the HTX exchange.

 

Crypto community concern

These security breaches cast a shadow over Sun’s crypto ventures, especially considering the recent hack on Poloniex, which saw losses surpassing $100 million in various cryptocurrencies. A spokesperson for crypto security firm Hacken told Cointelegraph that these hacks could be the work of an insider.

“We can see that all these attacks have the same target: Justin Sun’s projects,” the spokesperson stated. These related incidents are the cause of significant speculation within the crypto space, with some concern expressed about the financial health of HTX, given that the firm is currently offering unsustainable interest rates of up to 100% APY on a selection of digital assets.

In response to the HTX hack, Justin Sun assured the community in a post on X (formerly Twitter) that HTX would fully compensate for the losses incurred in its hot wallet. The exchange has temporarily halted deposits and withdrawals as the investigation unfolds. Sun emphasized the commitment to resume services once the investigation concludes and the cause of the breach is identified.

These incidents raise questions about the security infrastructure of platforms associated with Justin Sun. The crypto community awaits further details on the investigation’s outcomes and preventive measures that will be implemented to fortify these exchanges against future attacks.

Such recent security breaches have not just affected Justin Sun-related enterprises. Earlier this month, decentralized exchange (DEX) KyberSwap was exploited to the tune of $46.5 million. Earlier this week, Kronos Research — a Taipei-based crypto trading, market making and venture capital platform — experienced a $25.6 million loss. The past twenty days have seen five major hacks resulting in an aggregate loss of a staggering $290 million.

As the crypto industry grapples with increasing security challenges, the importance of robust protective measures cannot be overstated. These developments underscore the need for a cautious and diligent approach in safeguarding digital assets within the rapidly evolving cryptocurrency landscape.

More to Read
View All
Web3 & Enterprise·

Aug 22, 2023

Wiziin Earmarks $500K Pre-Seed Funding for Blockchain Investment

Wiziin Earmarks $500K Pre-Seed Funding for Blockchain InvestmentWiziin, a Vietnamese startup specializing in venture investment management, has secured $500,000 in pre-seed funding, which it plans to use to accelerate its efforts in blockchain technology investment.Photo by Peter Nguyen on UnsplashBroad networkAt the heart of Wiziin’s primary objective — to bridge the divide between investors and founders — lies the firm’s blockchain-based platform. The Wiziin platform is specifically tailored to venture investors with a focus on digital assets.Wiziin is headed up by venture capitalist Tien Nguyen and serial entrepreneur Thong Dang. The firm was established in 2020, with a view towards playing a part in what it foresees as a revolution in investment dynamics, particularly within the Asia Pacific (APAC) region. The company’s network encompasses more than 200 investors and an array of over 5,000 raised-fund companies. The company believes that this positions it to become a transformative force in the investment landscape within the region.“The established norms of venture capital funding have long followed conventional methodologies,” commented Thong Dang, Wiziin Co-Founder. “This infusion of funding serves as a catalyst for our ongoing endeavors in emerging blockchain technology, with the ultimate aim of disrupting and revolutionizing the industry. Tokenization of assets and the integration of smart contracts will form the bedrock of our innovative approach to venture capital,” he added.Homerun.clubCentral to Wiziin’s trajectory is the development of an investment platform named “Homerun.club.” This platform is engineered to foster co-investment experiences within blockchain ecosystems for individual investors.Through the elimination of intermediaries, Wiziin is striving to democratize funding access, unleashing global empowerment for entrepreneurs and inviting a more diverse spectrum of investors.The universality of blockchain technology shatters geographical limitations, enabling start-ups like Wiziin to bring investors and entrepreneurs together from every corner of the globe. This holds profound potential for startups and investors situated in expanding markets, and markets that have historically been underserved by conventional approaches to venture capital funding and investment.“While our platform operates within a decentralized framework, the importance of user verification cannot be understated, serving as both a regulatory compliance measure and a safeguard for investor interests,” elaborated Thong Dang.Dang added: “In tandem, we’re actively seeking institutional funding in the upcoming months to further fortify the platform. This strategic step will usher in a collaborative fundraising endeavor between our project and its vibrant community, fostering mutual growth and resounding success.”DAOs and start-up fundingWiziin’s approach is just one element in the ongoing shift towards blockchain-based start-up finance innovation. Many in the crypto space have also put forward DAOs or decentralized autonomous organizations, as an agent for further disruption in this area.DAOs also leverage blockchain technology, and their use can be helpful in cutting conventional venture capital firms out of the enterprise funding process. Furthermore, they can be used to cut through unwieldy regulation relative to start-up funding.With the conventional approach to start-up finance, only accredited investors gain access to early-stage opportunities. Individual investors, regardless of their net worth, can participate in a DAO-based approach to financing. The approach facilitates broader inclusion while having the effect of increasing liquidity as well.

news
Web3 & Enterprise·

Sep 06, 2024

WazirX hack: Hacker launders $10M through Tornado Cash amid legal disputes and partial withdrawals

In the aftermath of the massive $235 million hack of the WazirX cryptocurrency exchange on July 18, users and stakeholders are grappling with its devastating consequences. The breach, which compromised a significant portion of the exchange’s reserves, has led to a series of legal, financial and security-related challenges, leaving millions of users uncertain about the future of their funds. The hack and its aftermathWazirX, once a leading Indian cryptocurrency exchange, lost approximately $235 million due to a breach in one of its multi-signature wallets. This included significant amounts of Shiba Inu (SHIB), Ethereum (ETH) and other assets. The hack crippled the exchange, forcing it to temporarily shut down operations and seek a restructuring process under Singapore's insolvency laws. The WazirX hacker has since begun laundering the stolen assets through Tornado Cash, a crypto mixer known for obscuring transaction details. According to blockchain security firm Cyvers, the hacker transferred over 5,000 ETH (approximately $12 million) to a new wallet and laundered $10 million in Ethereum through Tornado Cash. This mirrors the tactics of the North Korea-backed Lazarus Group, which has used similar methods in past high-profile crypto thefts. Photo by GuerrillaBuzz on UnsplashUsers seeking redress and government interventionAs the victims of the hack face uncertainty, over 4 million active WazirX users are expected to suffer a loss of at least 43% of their funds due to the restructuring process. Frustrated by the lack of action from Indian authorities, many users have sought help from Indian Prime Minister Narendra Modi, who was visiting Singapore at the time. Users took to social media to air their grievances and demand justice, urging the government to intervene. WazirX co-founder Nischal Shetty, who is based in Dubai, added to the confusion by stating that he does not know who is responsible for safeguarding user crypto funds on the platform. His statement has fueled outrage among users, who feel abandoned by the exchange’s management. Legal and ownership disputesAmid the chaos, WazirX is also battling a legal dispute over its ownership with Binance, the world’s largest cryptocurrency exchange. Shetty has repeatedly claimed that Binance acquired WazirX, granting it significant control over the platform's operations. However, Binance founder Changpeng Zhao (CZ) refuted these claims in 2022, stating that the acquisition deal was never completed. The uncertainty surrounding the ownership of WazirX has further aggravated users, many of whom are demanding a clear statement from Binance. So far, Binance has remained silent, neither confirming nor denying its involvement. This ambiguity has intensified calls for clarification, with users fearing that a lack of transparency may worsen their chances of recovering their funds. Partial withdrawals and restructuring effortsIn response to the crisis, WazirX has initiated phased withdrawals for users, allowing them to access 66% of their Indian Rupee (INR) token balances. Initially set for September 9, the withdrawal window was moved forward, offering some relief to users. However, many are dissatisfied with the partial access to their funds and are questioning when full crypto withdrawals will resume. WazirX’s legal team has indicated that users may recover only 55% to 57% of their crypto holdings, sparking further discontent. Meanwhile, the exchange has filed a moratorium application in the Singapore High Court, seeking a six-month reprieve from legal actions as it works on a restructuring plan. Looking aheadAs the WazirX saga unfolds, the future of the exchange and its users remains uncertain. The legal battles, ownership disputes and the ongoing laundering of stolen assets pose significant challenges to the platform's recovery. For now, users can only hope that the restructuring process will bring them closer to recovering their lost funds and that authorities will step in to provide clarity and resolution. 

news
Policy & Regulation·

Sep 25, 2023

Upbit Accidentally Accepts Counterfeit APT Tokens, Initiates Retrieval Efforts

Upbit Accidentally Accepts Counterfeit APT Tokens, Initiates Retrieval EffortsUpbit, South Korea’s largest cryptocurrency exchange, is reported to have accepted deposits of counterfeit Aptos (APT) tokens, mistaking them for their legitimate counterparts. The exchange has been reaching out to the sellers of these tokens by phone, requesting their recovery. This news has been circulating in several online crypto communities since the afternoon of September 24 (Korea Standard Time).Photo by Kenny Eliason on UnsplashUpbit’s responsesOn September 24 at 15:47 KST, Upbit announced a temporary suspension of deposit and withdrawal services for APT due to maintenance on the APT wallet. Following this, at 22:32 KST on the same day, Upbit explained that system maintenance was undertaken after identifying an unusual attempt linked to APT deposits. The crypto exchange went on to announce that the deposit and withdrawal services for APT would resume at 23:00 KST on the same day.DeFi degenerates’ insightsIn relation to this incident, Definalist, a group of DeFi degenerates based in Korea, shared insights on X (formerly Twitter). The group stated: “It seems that during the process of reflecting $APT coin deposits, there was a failure to check the type arguments, and all same functions transfers were recognized as the same APT native token. … If all APT ecosystem tokens were sent to Upbit’s wallet, they would have been mistakenly treated as APT native coins.”Decimal place differenceDefinalist also remarked on the fortunate nature of the counterfeit APT token having six decimal places, in contrast to the authentic APT token’s eight. They noted that if the deceptive token had mirrored the genuine token’s decimal places, the market disruption could have amplified a hundredfold. Meanwhile, the value of the counterfeit APT tokens deposited into Upbit is estimated to be about KRW 20 million (approximately $15,000).

news
Loading