Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Sep 15, 2023

Hong Kong and Kazakhstan Pilot SWIFT’s CBDC Solution

Hong Kong and Kazakhstan Pilot SWIFT’s CBDC SolutionCentral bank digital currency (CBDC) development globally is unrelenting, with the latest iteration of that involving global financial messaging network SWIFT.The global member-owned cooperative recently disclosed that three central banks are currently participating in beta-testing of this revolutionary solution, including the Hong Kong Monetary Authority (HKMA) and the National Bank of Kazakhstan.Photo by NASA on UnsplashBuilding upon initial successThe company provided details on the initiative via a press release published to its website on Wednesday. Simultaneously, an extended consortium of over 30 financial institutions is embarking on sandbox experiments to explore a multitude of potential use cases.The impetus behind SWIFT’s commitment to CBDC interoperability grew stronger after a successful round of sandbox testing. Participants in the initial phase quickly recognized the potential and intrinsic value of SWIFT’s solution.Building on this success, the beta version of SWIFT’s CBDC connector solution is now being integrated into the infrastructure of three central banks and monetary authorities.Second phase testingIn tandem with the beta testing, SWIFT has inaugurated a second phase of sandbox experiments, drawing in a consortium of commercial banks, central banks, and financial market infrastructure providers. This phase is dedicated to exploring an array of use cases, ranging from trigger-based payments for digital trade platforms to foreign exchange models, delivery vs. payment mechanisms, and liquidity-saving techniques.Eighteen central and commercial banks had taken part in the first phase of those sandbox experiments. Equally, the second phase has attracted a long list of entities, including the Reserve Bank of Australia, Deutsche Bundesbank, HKMA, Bank of Thailand, CLS, and others. With thirty leading global financial institutions participating in this latest testing round, that makes for a 66% increase in participation by comparison with the first phase. Their collective input and collaboration will contribute towards shaping the future landscape where CBDCs are concerned.Tom Zschach, Chief Innovation Officer at SWIFT, commented on the use of the technology in bridging from existing systems, stating:“The financial community has already recognized the strong potential of our CBDC innovations for preventing digital islands while securely bridging the payment systems of today and the future.”Global hotbed of innovationThe American think tank, the Atlantic Council, has been tracking CDBC projects on a global basis. Its endeavors in that respect demonstrate the expansive efforts that are being made to develop this technology.19 of the G20 countries are in advanced stages of CBDC development, with nine already in pilot phases. While this proliferation signifies the growing importance of CBDCs on the global stage, it also raises concerns about potential fragmentation as countries predominantly focus on domestic usage.SWIFT has taken a proactive stance in addressing the potential challenges of a fragmented CBDC landscape. The company embarked on its CBDC journey over 18 months ago, with the initial sandbox phase simulating nearly 5,000 transactions between different blockchain networks and existing fiat-based payment systems.

news
Policy & Regulation·

May 31, 2023

Korean Financial Authority Installs Report Center to Counter Crypto Scams

Korean Financial Authority Installs Report Center to Counter Crypto ScamsThe Korean Financial Supervisory Service (FSS) announced today that it has installed a dedicated report center aimed at combating investment fraud related to virtual assets. From June 1 through to the end of this year, the report center will run a reporting campaign.Photo by Katrin Hauf on UnsplashSurge in crypto fraud casesWhile the National Assembly is working on the legislation of the Virtual Asset User Protection Bill, there has been a surge in fraudulent activities exploiting regulatory loopholes. According to the FSS, the number of reported cases of crypto fraudulent activities in Korea surged by 67.2% last year, reaching 199, compared to the previous year’s 119.In a proactive response to this rising concern, the FSS has set up a report center, designed to staunch the escalating tide of fraud.Coordinated efforts against financial fraudUnder the guidance of the Anti-Financial Fraud Office, the report center will operate collaboratively with other relevant departments, such as the Consumer Finance Department and the Asset Management Examination Department. Reports can be filed either via landline or through the FSS website.Swift actions on detected fraudAs part of its policy, the FSS will swiftly inform investigative agencies, like the prosecutors’ office, if an issue raised via the report center is deemed severe or contains specific facts that necessitate further scrutiny.The financial watchdog emphasized its commitment to issuing financial consumer warnings whenever potential fraud is detected and poses a risk to investors. This strategy is designed to safeguard investors and impede the spread of damages.

news
Policy & Regulation·

Jun 27, 2025

Hong Kong releases ‘LEAP’ framework for digital assets

The Financial Services and the Treasury Bureau (FSTB), a policy bureau attached to the government of the special administrative region of Hong Kong, has released a new digital assets policy statement, incorporating its “LEAP” framework for the digital assets industry within the city. The document, outlining the government’s objectives and guiding principles relative to the digital assets sector, builds on its first policy statement for the industry which it published in October 2022.Photo by Harry Shum on PexelsA ‘LEAP’ towards an integrated digital assets ecosystemThe FSTB suggests that this new policy statement builds upon foundational initiatives pioneered through the initial policy statement, asserting that “Hong Kong is poised to 'LEAP' towards a trusted, sustainable, and deeply integrated [Digital Assets] ecosystem embedded within the real economy.” The government agency also suggested that this “Policy Statement 2.0” also builds on the “ASPIRe” digital asset regulatory roadmap introduced by the Securities and Futures Commission (SFC) in February, outlining the next phase of digital asset sector development in Hong Kong. Strengthening global hub statusThe government has set out to home in on strategic measures to bring about greater liquidity in digital asset markets and diversify digital asset product offerings, while strengthening the Chinese autonomous territory’s position as a global hub for the digital asset sector. “LEAP” is an acronym for the proposed initiatives that underpin the new framework, including: - Legal and regulatory streamlining- Expanding the suite of tokenized products- Advancing use cases and cross-sectoral collaboration- People and partnership development The framework focuses heavily on the tokenization of real-world assets (RWA), with particular emphasis on bond tokenization. In February 2023, Hong Kong pioneered the issuance of the world’s first-ever tokenized government green bond. Building on that, it now seeks to bring about the regularization of the issuance of tokenized government bonds. The Hong Kong government would also like to see tokenization efforts expanding into “a broader range of assets and financial instruments.” It cited sectors such as precious metals, non-ferrous metals and renewable energy as candidates for tokenization. Promoting tokenized ETFsThe authorities are also encouraging tokenized exchange-traded funds (ETFs), with plans to introduce a stamp duty waiver for these products as an incentive. Additionally, the Hong Kong government is interested in nurturing the development of secondary market trading of such tokenized ETF products, whether that’s through digital asset trading platforms or other channels. The framework considers the further development of stablecoins. The city’s new licensing regimen for stablecoin issuers commences on Aug. 1. The FSTB maintains that stablecoins have the potential “to transform payments, supply chain management, and capital market activities by offering a cost-effective and efficient alternative to traditional systems.” In order to capitalize on this potential, the Hong Kong government, together with the city’s regulators, intends to enable licensed stablecoin issuers in the city “to explore and implement different stablecoin use cases.” Cyberport, a Hong Kong business park and digital technology incubator that hosts in excess of 1,650 startups, will also extend its support through its incubation ecosystem to further the objectives set out in the Hong Kong government’s new digital assets policy statement.

news
Loading