Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Oct 24, 2023

Hong Kong Adapts Crypto Regulations to Broaden Market Access

Hong Kong Adapts Crypto Regulations to Broaden Market AccessHong Kong’s financial regulator has taken a further regulatory step in its evolving stance on cryptocurrency trading, widening the scope of retail access to digital assets through intermediaries.Photo by Chapman Chow on UnsplashResponding to growing demandThe move follows a surge in interest in spot Bitcoin exchange-traded funds (ETFs) and recent investigations into the unlicensed operations of the JPEX exchange. In a circular published by the Securities and Futures Commission (SFC) on Friday, the regulator explained that the policy shift was prompted by changing market dynamics and growing inquiries from the industry.The new guidelines aim to extend access to a broader clientele and facilitate the direct deposit and withdrawal of virtual assets through intermediaries, all while maintaining stringent safeguards. The circular states:”The policy is updated in light of the latest market developments and enquiries from the industry seeking to further expand retail access through intermediaries and to allow investors to directly deposit and withdraw virtual assets to/from intermediaries with appropriate safeguards.”Cautionary notesDespite this welcome expansion, there are a couple of cautionary notes included within the circular. Hong Kong remains circumspect about overseas virtual asset (VA) products, deeming them “complex” and, as a result, riskier. The circular emphasizes that “VA-related products considered complex should only be offered to professional investors.” For instance, an overseas VA non-derivative ETF is likely to fall into this category.The other condition pertains to potential clients, who will be required to undergo a one-off test to assess their knowledge of investing and ensure they possess the financial wherewithal to manage the risks associated with virtual asset trading. Furthermore, intermediaries must furnish clients with comprehensive risk disclosure statements.The regulator also places an onus on the intermediary to set a limit for each retail client, to ensure that a retail client’s exposure to virtual assets is reasonable. The circular outlines that deposit and withdrawal of client funds should only happen through the use of segregated funding accounts on an SFC-licensed platform.Crypto sector aspirationsThis shift in regulation underscores Hong Kong’s ongoing aspirations to solidify its position as a hub for virtual assets. The territory embarked on a new regulatory regime in June, enabling applications for crypto trading platform licenses. By August, the first batch of licenses was granted, allowing exchanges to cater to retail customers. This marked a notable turnaround from Hong Kong’s prior 18 months of skepticism and hostility toward the cryptocurrency sector.The timing of these regulatory changes coincides with surging interest in spot Bitcoin ETFs, with JPMorgan even suggesting that approval in the US could materialize within months. This shift in regulatory perspective in Hong Kong also follows the investigation and accusations made against the JPEX exchange for conducting unlicensed operations, leading to arrests and the promise to disclose details of licensed applicants. The JPEX scandal has also dampened public confidence in crypto in Hong Kong more recently.Hong Kong is adapting its crypto regulations to be more inclusive while maintaining a cautious approach toward complex overseas virtual asset products. This regulatory shift underscores the region’s determination to foster its status as a leading hub for virtual assets, following a change of heart from its previous stance of skepticism and reluctance towards the crypto industry.

news
Policy & Regulation·

Jul 12, 2023

Dubai Regulator Suspends BitOasis’ Crypto License

Dubai Regulator Suspends BitOasis’ Crypto LicenseDubai’s pioneering cryptocurrency exchange, BitOasis, has had its operating license suspended by the city’s cryptocurrency regulator for failing to meet key conditions within the required timeframes. The Virtual Assets Regulatory Authority (VARA) took enforcement action against BitOasis and initiated a review of the Dubai-based firm.BitOasis was granted a conditional license on April 12, which allowed it to operate on the condition that it met specific requirements within 30 to 60 days. However, the exchange has failed to fulfill these conditions, leading to the suspension of its license. VARA did not disclose the exact nature of the unmet conditions, but it stated that until they are satisfied, BitOasis’ “License for Institutional and Qualified Retail Investors” will remain non-operational.Photo by iridial on UnsplashFirst MVP broker-dealer license holderBitOasis had received the first “minimum viable product operational license” from VARA, enabling it to offer broker-dealer services to qualified institutional and retail investors in Dubai. This license represents a crucial step towards obtaining a full market product (FMP) license, but as of now, no firm has been issued an FMP license by VARA.To become eligible for the FMP license, BitOasis must fulfill the conditions specified in its current license, as outlined by VARA. The regulatory authority has emphasized its commitment to monitoring the situation for compliance remediation.OPNX reprimandThis recent development follows VARA’s reprimand of Su Zhu and Kyle Davies, the co-founders of the now-defunct crypto hedge fund Three Arrows Capital, in April. The duo had operated and promoted their new OPNX crypto exchange in Dubai without the necessary license, catching VARA’s attention.BitOasis addressed the regulatory concerns in a blog post on Tuesday, affirming its collaboration with VARA to meet the remaining conditions for the Operational MVP License. The exchange clarified that the issue with its license does not impact other services provided, such as broker-dealer services for existing retail users. It also took to Twitter on Tuesday to clarify the situation. The company has suspended new user registrations until further notice, presumably as it works towards meeting VARAs licensing requirements.BitOasis stated: “You can continue to use BitOasis with the assurance that your assets are safe, secure, and held at their full value on our platform, and our team will continue to cooperate with the Virtual Asset Regulatory Authority and fulfill all post-operational license terms, as well as working towards a full market product license.”The firm referred to the “unique challenges” that are associated with licensing and suggested that it is determined to address them and to “be a leader in the virtual assets sector.”The suspension of BitOasis’ license highlights the stringent regulatory environment in Dubai’s cryptocurrency sector. VARA is demonstrating that it remains committed to enforcing compliance and ensuring that crypto exchanges meet the necessary requirements. BitOasis must rectify the issues and meet the conditions of its license to regain its operational status and proceed towards obtaining the coveted full market product license in the future.

news
Policy & Regulation·

Jun 14, 2023

Korea Securities Depository Spotlights the Significance of a Security Token Platform

Korea Securities Depository Spotlights the Significance of a Security Token PlatformDuring a press conference held today in Seoul, Chairman Lee Soon-ho of the Korea Securities Depository (KSD) highlighted the need for developing innovative financial infrastructure, including a security token platform, as reported by local tech news outlet etnews.Photo by JEONGUK -on UnsplashBlockchain-based securitiesIn recent times, there has been a surge in demand for blockchain-based securities, prompting the South Korean government to issue guidelines on security tokens in February of this year. Consequently, securities firms, fractional investment platforms, and technology companies have been collaborating to form consortia.The KSD has been actively studying the legislative and institutional aspects of security tokens to establish a foundation for their widespread acceptance. Furthermore, it has devised a mid-to-long-term roadmap for the security token platform. Since February, the KSD has been spearheading a security tokens council with an aim to develop a business model for a security token platform starting in July.KSD’s roleSpecifically, the KSD intends to provide feedback on subsequent legislative revisions pertaining to security tokens, review security token registrations, and establish methods for managing the total volume of security tokens under the Act on Electronic Registration of Stocks and Bonds.Additionally, the KSD aims to expedite the construction of a new system for the capital market infrastructure. This endeavor entails revamping the operational system to enable flexible responses to internal and external changes, as well as creating a smart workplace suited for the digital era.Since its establishment in 1974, the KSD has played a crucial role in supporting the development of the Korean capital market by providing diverse securities services, including the issuance and distribution of securities. Nonetheless, participants at the conference concurred that the agency needs a fresh vision and strategy to maintain its position in the future.Chairman Lee emphasized that the agency’s 50th anniversary will take place next year, prompting a thorough assessment of its current status and the formulation of a new vision and strategy to adapt to the ever-evolving financial landscape. As part of these efforts, he underscored the recent establishment of a task force dedicated to devising future plans.

news
Loading