Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Jun 28, 2023

Hong Kong Web3 Companies Invest Millions in VASP Licenses

Hong Kong Web3 Companies Invest Millions in VASP LicensesWeb3 firms in Hong Kong are making significant financial investments to obtain Virtual Asset Service Provider (VASP) licenses.According to a report by Foresight News on Tuesday, the cost of these licenses is ranging between 20 million and 200 million Hong Kong dollars ($2.55 million and $25.5 million).Industry sources explained to the publication that the high costs are due to the lack of existing infrastructure in traditional financial institutions, requiring significant investments in various aspects such as products and teams. Even experienced cryptocurrency institutions find the cost of obtaining a license to be substantial.Photo by Daniam Chou on UnsplashEarly licenseesAnalysts at Foresight highlighted that several Hong Kong subsidiaries of exchanges, including OKX, BitgetX, HashKey Pro, OSL, and Gate.io, have already commenced operations. OKX, in particular, has witnessed impressive growth in Hong Kong, with 8,800 registered users and a cumulative trading volume of $150 million as of June 27.To regulate the cryptocurrency exchange industry, Hong Kong introduced new VASP licensing requirements on June 1.These requirements mandate firms to disclose user statistics and company financials to the Securities and Futures Commission (SFC) of Hong Kong for regulatory approval. Exchanges that fail to comply with the requirements will be compelled to halt operations in the special administrative region (SAR) by mid-next year.Virtual asset ratingsOn the same day, the Hong Kong Virtual Asset Consortium unveiled its virtual asset index, which encompasses major cryptocurrencies such as Bitcoin, as well as altcoins and privacy tokens. The consortium aims to offer ratings services and indexes to facilitate retail crypto trading in the SAR. Notably, it has received support from prominent players in the industry, including Huobi, KuCoin, Bitget, and others.The introduction of VASP licenses and the subsequent investments made by Web3 companies demonstrate the evolving regulatory landscape in Hong Kong. With the stringent licensing requirements, the industry aims to enhance transparency and accountability, ensuring the protection of investors and fostering a more secure environment for cryptocurrency trading.The involvement of established exchanges and the formation of the Hong Kong Virtual Asset Consortium further underscore the growing interest and support for cryptocurrencies in the region. These initiatives are designed to provide retail investors with reliable information.In that way, they enable them to make informed decisions while participating in the digital assets space. The consortium’s collaboration with industry leaders reflects a collective effort to promote the growth and adoption of cryptocurrencies in Hong Kong.Last week’s news of banking stalwart HSBC offering Hong Kong-based crypto exchange-traded funds (ETFs) to its banking customers has also delivered a shot in the arm to the development of crypto in the Chinese autonomous territory.As the regulatory framework continues to evolve and mature, it is expected that Hong Kong will attract more Web3 companies seeking to operate in a regulated and compliant environment.The investment in VASP licenses signals a commitment to long-term growth in establishing a base in Hong Kong. Ongoing developments in Hong Kong over the course of the past six months point to the recognition of the potential benefits that cryptocurrencies and blockchain technology can bring to the financial landscape of Hong Kong and level of the level of intent locally to progress the technology.

news
Web3 & Enterprise·

Nov 17, 2023

Elliptic and CODE join forces to propel crypto compliance in Korea

Elliptic and CODE join forces to propel crypto compliance in KoreaElliptic, a global blockchain analytics and crypto compliance solutions provider, has partnered with CODE, a Seoul-based Travel Rule solution provider, as part of efforts to expand its operations into the Korean market. Under this agreement, the two companies aim to actively support virtual asset service providers (VASPs) in South Korea in their attempts to adapt to the evolving international regulatory landscape for anti-money laundering (AML) and the crypto Travel Rule.Photo by NordWood Themes on UnsplashCrypto Travel RuleThe Travel Rule refers to the Financial Action Task Force’s (FATF) Recommendation #16, which outlines that VASPs must share certain personal information about customers — including names and account numbers — when facilitating crypto transactions that exceed a certain amount.Empowering VASPs through risk mitigationElliptic and CODE will work together on comprehensive regulatory technology-based (RegTech) solutions to enable VASPs to identify AML and Counter Financing of Terrorism (CFT) risks among virtual asset transactions, ultimately leading the sustainable growth of the crypto asset industry. In particular, CODE will be able to leverage Elliptic’s services to ensure compliance with Travel Rule regulations. Elliptic offers solutions like wallet screening, transaction monitoring, crypto investigations and VASP screening for big names like Coinbase, Binance and BitGo, as well as law enforcement agencies.“This partnership with Elliptic allows us to expand our compliance services beyond Travel Rule-related solutions for VASPs. Elliptic’s advanced technology and expertise will help our corporate members achieve regulatory compliance more efficiently, contributing greatly to enhancing transparency and security throughout the larger virtual asset industry,” said CODE CEO Lee Sung-mi.

news
Policy & Regulation·

Nov 28, 2023

Zipmex Thailand halts crypto trading citing SEC compliance

Zipmex Thailand halts crypto trading citing SEC complianceTroubled cryptocurrency exchange Zipmex Thailand has recently announced the temporary suspension of digital asset trading until early next year.Photo by Anh Tuan To on UnsplashTrading and deposits suspendedThe decision, outlined by the firm in a Facebook post on Saturday, is attributed to the platform’s efforts in ensuring full compliance with the standards set by Thailand’s Securities and Exchange Commission (SEC).In the Facebook post, Zipmex Limited addressed its customers, stating:“Dear customers, Zipmex Limited would like to ensure the proper and compliant conduct of the company’s business operations in accordance with the criteria set by Thailand’s Securities and Exchange Commission (SEC).”The suspension of digital asset trading and deposits of all types became effective from Nov. 25.Withdrawals remain openDespite the suspension, customers will retain the ability to withdraw Thai baht and digital assets from their Trade Wallet through the website and mobile application until Jan. 31, 2024. However, for digital assets categorized as “Trade Only,” customers are instructed to contact Customer Support for withdrawal. Beyond Jan. 31, 2024, when the withdrawal feature through the website and mobile application is suspended, customers will need to seek assistance from Customer Support.Zipmex Thailand also emphasized that the withdrawal process for digital assets may take between seven to 14 days, requiring customers to provide supporting documents for identity and account ownership verification.As a cryptocurrency exchange headquartered in Singapore and operating in multiple countries, including Thailand, Australia and Indonesia, Zipmex has already fallen foul of Thailand’s SEC. Earlier this year, it was hit with penalties related to allegations of improper use of a digital asset custodian service and the redirection of customers to the Singapore-based exchange, Zipmex Pte, creating a conflict of interest.Financial difficultiesThe exchange has faced financial challenges, including difficulties in repaying creditors after losses incurred from exposure to crypto lenders Babel Finance and Genesis in 2022. A planned $100 million buyout earlier in the year fell through when the buyer, reportedly V Ventures, withdrew from the purchase.Zipmex’s troubles date back to last summer when the exchange halted withdrawals due to volatile market conditions and a liquidity crunch resulting from exposure to the troubled crypto lender Babel Finance. Despite facing financial difficulties, the exchange expressed its commitment to maintaining the integrity of its platform.In August of the same year, Bloomberg reported that Zipmex intended to meet with potential investors and Thailand’s financial regulator to discuss a recovery plan. By November, the platform was in advanced discussions with venture capital fund V Ventures for the sale of a majority stake.Earlier this year, the Thai Securities and Exchange Commission announced an investigation into whether Zipmex breached local rules in its offering of certain digital-asset products. In April, the company filed a request to extend the moratorium period to enable the firm to work towards restructuring. Later that month, it appeared that the V Ventures investment deal had fallen through. By July, the beleaguered firm had sued the investor for breach of contract.The ongoing challenges faced by Zipmex underscore the complex landscape and regulatory scrutiny surrounding cryptocurrency exchanges in various jurisdictions.

news
Loading