Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Aug 14, 2025

Fonte Capital launches Central Asia’s first spot Bitcoin ETF

Fonte Capital, an Astana-based investment management company that allocates capital across a broad range of asset classes, including digital assets, launched a spot Bitcoin exchange-traded fund (ETF) in Kazakhstan’s capital city on Aug. 13. The firm is based within the Astana International Financial Centre (AIFC), with the launch prompting AIFC Governor Renat Bekturov to take to X to outline that the product offering is the first spot Bitcoin ETF to be listed within the Central Asian region.Photo by Kanchanara on UnsplashReflecting Bitcoin price dynamicsThe product has been listed on the Astana International Exchange (AIX) and has been assigned the ticker “BETF.” In announcing the offering, Fonte claimed that the ETF “aims to accurately reflect the price dynamics of bitcoin, striving to achieve this performance before fees and fund obligations.”Shares in the ETF are listed in U.S. dollars, with the fund having a “non-exempt” classification, meaning that it can be offered to a broad range of investors, including non-qualified retail investors. Each ETF share will be fully backed by Bitcoin, with Fonte having partnered with BitGo for digital asset custody.  Delivering institutional-grade accessTaking to social media, BitGo described the product offering as a “new era for digital assets” in Kazakhstan. The company asserted that through what it termed “U.S.-regulated cold storage,” the new fund is delivering institutional-grade access to Bitcoin within the region for the first time. Fonte pointed out that the fund “provides investors with a regulated and secure way to include Bitcoin in their investment portfolios without the complexities associated with holding and transferring the underlying asset.” This isn’t the first Bitcoin-related product that the AIX has listed. Back in 2021, it listed iX Bitcoin Exchange Traded Notes, with special purpose company iX Bitcoin SPC Limited acting as the note issuer.  The product differs from the Fonte ETF in that it is backed by shares of ProShares Bitcoin Strategy ETF, a future-based ETF first listed on the New York Stock Exchange (NYSE) in 2021. In comparison, Fonte’s product has the advantage of being directly backed by Bitcoin. The ETF’s backers have pointed out that there are further implications for the ETF’s shareholders. As the product is regulated by the AIFC, Fonte asserts that within that jurisdiction, holders of the product’s shares are protected from the potential reach of international sanctions. In this regard, the product offers further protection as it is not dependent upon overseas issuers.  Overall, the AIFC has played a key role in the development of crypto within Kazakhstan over the course of the last few years. In 2023, it awarded crypto exchanges Bybit and Binance approval to trade within the Central Asian nation.  Binance subsequently launched a local crypto exchange platform in Kazakhstan, achieving full licensing in October 2024. In June of this year, the authority granted its first license for the issuance of a fiat-backed stablecoin.  It emerged recently that Kazakhstan is working towards the establishment of a national crypto reserve, with the administrators of the country’s sovereign wealth fund expressing the desire to commence investment in crypto assets.

news
Policy & Regulation·

Dec 22, 2023

Putin approves inclusion of digital ruble within Russian tax code

Putin approves inclusion of digital ruble within Russian tax codeRussian President Vladimir Putin has given his approval to a new law that incorporates the digital ruble into Russia’s tax code, marking a significant step in the country’s push towards digital currency adoption.Photo by Egor Filin on UnsplashAuthority to recover fundsThe development was reported by Russian news outlet Telesputnik on Tuesday. The legislation introduces terms such as “digital ruble” and “digital ruble wallet” into the tax code. It outlines the legal framework for these digital assets. Notably, the law grants bailiffs and court-appointed individuals the authority to recover central bank digital currency (CBDC) funds from wallets in cases where taxpayers lack sufficient fiat in their bank accounts.Moreover, the law empowers tax authorities to suspend transactions on digital ruble wallets and request documentation from platform operators to confirm fund withdrawals from a taxpayer’s account. In a move aimed at streamlining the process, confiscated digital coins can be transferred directly to the Russian Treasury.This legislation, the second major CBDC-related law passed in 2023, signals Russia’s interest in fast-tracking the implementation of its digital ruble. Despite conflicting statements, the Ministry of Finance anticipates that all Russians will have the opportunity to use digital ruble wallets for payments by 2024. However, the Central Bank has indicated a potentially delayed national roll-out, stating it may not occur before 2025.Key provisions outlined in the new law include defining the Central Bank’s role as the “operator of the digital ruble platform” and establishing liability procedures if the bank fails to fulfill these obligations. Additionally, the law addresses the taxation of transactions involving digital rubles, with exemptions for Value Added Tax (VAT) on account opening and holding.Working around sanctionsAs Russia edges closer to the digital ruble roll-out, the nation faces economic challenges due to ongoing U.S. and EU sanctions. Moscow views the CBDC as a strategic tool in international trade, aiming to leverage it to navigate economic restrictions. Government officials believe the digital ruble will play a crucial role in reducing costs and risks for domestic firms engaged in foreign trade.The Eurasian Economic Union (EAEU), a five-member economic bloc including Russia, Belarus, Kazakhstan, Armenia and Kyrgyzstan, is exploring the potential for cross-border CBDC functions. Belarus and Kazakhstan are also expediting their CBDC projects, with a focus on cross-border trading capabilities.Earlier this month, a Russian politician could begin to use their respective CBDCs for bilateral trade deals as early as next year. Even before sanctions hit, both Russia and China had been working towards de-dollarization for some time.Ongoing pilot programThe Central Bank is actively piloting the digital ruble in 11 Russian cities alongside 13 partner commercial banks. Earlier this month, the bank stated that “the pilot will continue at least until the end of 2024 and, if necessary, will be extended.” The Central Bank added that “only after the completion of the pilot will the digital ruble be introduced into mass circulation.”A group of 16 banks is set to join the trial in the coming year. The finance ministry aims to utilize the digital ruble for government subsidies and welfare payments, with plans for implementation in 2024.

news
Web3 & Enterprise·

Apr 19, 2023

Singapore Bank Opens Branch in the Metaverse

Singapore Bank Opens Branch in the MetaverseSingapore’s OCBC Bank has made its debut in the Metaverse with the opening of OCBCx65Chulia in Decentraland, a virtual platform that uses blockchain technology. The bank occupies nine plots of virtual land and visitors can access its website to open a bank account, apply for a credit card, and learn about its historical milestones and latest banking products and services.©Pexels/Andrea PiacquadioThe virtual branch got its name from its headquarters located at 65 Chulia St, OCBC Centre, Singapore. It is designed after OCBC Bank’s red logo, “a nod to the bank’s rich heritage,” the bank said in a statement.Reaching a larger and younger audienceOCBCx65Chulia represents a new way to connect with the younger generation, the bank added. “With the Bank’s arrival in the Metaverse, customers gain an additional access point that also represents a new way to engage with the younger crowd,” it said.The bank aims to tap into this emerging technology to reach a larger audience, said Peter Koh, Head of Group Technology Architecture at OCBC Bank.“Many have doubted the purpose of the Metaverse. Though a nascent and evolving space that we are still working to understand, the Metaverse remains one of the newer ways to make a connection. We are ready to tap on these, as they emerge, to reach a larger audience. At the same time, through experimentation and collaborating with an industry player, our younger colleagues can learn and develop themselves,” he said.GamificationIn the third quarter of 2023, OCBCx65Chulia will involve gamification, the bank said. This enhancement will come from the winning ideas of a group of Nanyang Polytechnic (NYP) Diploma in Interaction Design students who won the associated hackathon held in February 2023. The bank also collaborated with Web3 firm Memotics, an expert in emotive and social spaces through digital architectural design.Broader banking interestOCBC Bank, which opened its doors in 1932, is the second-largest in Southeast Asia by assets, according to Forbes. It is not the first bank in Singapore to venture into the Metaverse. Last year, DBS partnered with decentralized gaming virtual world The Sandbox to create an interactive Metaverse experience called DBS BetterWorld, which also forms part of its sustainability agenda.In February of last year JPMorgan became the first bank to enter the metaverse. At the time, it launched its virtual Onyx Lounge within Decentraland’s Metajuku Mall. The lounge featured a portrait of JPMorgan CEO Jamie Dimon, a spiral staircase and a dynamic roaming tiger.It also took the opportunity to release its “Opportunities in the Metaverse” report, in which it estimated a trillion dollar metaverse opportunity over the next few years. The metaverse has seen a plethora of well known corporations enter the space in recent times, including Gap, Adidas, PwC, Verizon and Nike.OCBC Bank’s move to the Metaverse represents a new era of banking where technology is used to reach a larger audience, especially the younger generation. With the Metaverse still being a nascent and evolving space, it is a new way to connect, engage, and experiment with the digital world.The gamification element in OCBCx65Chulia also shows how banks are exploring ways to make banking more interactive and fun. It will be interesting to see how other banks and financial institutions will follow suit and use the Metaverse to engage with customers and provide innovative services in the future.

news
Loading