Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Oct 31, 2023

Korean Crypto Exchange Giants Lead Market Expansion With Increased Listings

Korean Crypto Exchange Giants Lead Market Expansion With Increased ListingsSouth Korea’s top three cryptocurrency exchanges Upbit, Bithumb and Coinone have all increased the number of cryptocurrencies they listed for trading this year compared to last year, making them responsible for leading the market’s activity and expansion.Photo by Maxim Hopman on UnsplashDynamic shifts in listing and delisting trendsA recent analysis by local news outlet News1 on the number of cryptocurrencies listed and delisted this year on the country’s major fiat-to-crypto exchanges Upbit, Bithumb, Coinone, Korbit and Gopax — listed in order of market share size — revealed that Upbit and Coinone have increased their number of listings and delistings compared to last year.The remaining three exchanges, on the other hand, showed differing results. Bithumb increased its number of listings by 47 compared to the number listed last year, while delistings decreased by three, and Gopax listed eight fewer tokens and delisted one more token. Meanwhile, Korbit’s listings decreased by 37 tokens, while delistings decreased by only one.Among the five exchanges, Bithumb listed the highest number of new cryptocurrencies this year, with 80 new currencies in total added as of Monday (local time). This represents a more than double increase compared to the 33 currencies added last year. It is also 18 more than Coinone’s 62 new currencies and 50 more than Upbit’s 30.Differing approaches based on situational factorsGopax and Korbit have taken a more conservative approach compared to Upbit, Bithumb, and Coinone, which have been more aggressive in their listing strategies. In particular, as of Oct. 4, Bithumb has also been offering free transaction fees in an effort to regain its market share. This aggressive approach can be interpreted as an effort to weather the recent crypto winter, although it hasn’t been very successful.Conversely, the exchange that delisted the most cryptocurrencies this year was Coinone, with 38 taken down as of Monday, marking a significant increase compared to last year when it delisted 26. This can be accredited to the platform’s efforts to improve its reputation and operating system following an incident earlier this year where two former employees were booked for taking bribes in exchange for listing certain cryptocurrencies. Coinone CEO Cha Myung-hun subsequently issued an apology and pledged to take proper measures to prevent such an event from recurring. Since then, the exchange has been actively looking into carrying out delistings tied to issues like the amount of currency in circulation or market price manipulation.Bithumb and Upbit came in second and third for most delistings this year, with 22 and 18, respectively.However, Korbit showed the least fluctuation in the number of listings and delistings this year — nine and three, respectively — among the five exchanges. This is a sharp contrast owing to its conservative listing policy. Speculation suggests that the platform might adopt a more aggressive stance if market conditions improve in the second half of the year.On the other hand, Gopax listed 10 tokens and delisted eight tokens. The exchange has notoriously been dealing with operational difficulties due to regulatory roadblocks despite optimistic outlooks after its acquisition by Binance, one of the world’s most prominent exchanges. Along with the recent appointment of Cho Young-joong as the new CEO of CityLabs, the company that acquired an 8.55% stake in Gopax, the exchange has been working on resolving regulatory issues and improving the state of operations.

news
Web3 & Enterprise·

Sep 26, 2023

Milk Partners Achieves Integration with OK Cashbag, Elevating Reward Point Utility

Milk Partners Achieves Integration with OK Cashbag, Elevating Reward Point UtilityMilk Partners, the operator behind a South Korean blockchain-powered platform delivering an integrated service for reward points, announced yesterday that its app, MiL.k, has achieved compatibility with OK Cashbag. This integration is notable as OK Cashbag enjoys a substantial presence in the nation, with a user base exceeding 20 million.Photo by Josh Sorenson on PexelsEnhanced utilization of reward pointsThrough this collaborative initiative, MiL.k aims to facilitate enhanced utilization of reward points for customers of both entities.MiL.k allows point collectors to swap their points across diverse domains like travel, leisure, and shopping, introducing a new approach to utilizing reward points. The company has been forging collaborations with notable companies, including conglomerate Lotte, convenience store chain CU, theater franchise Megabox, travel platform Yanolja, Malaysian budget airline AirAsia, and Indonesian loyalty platform GetPlus.Expanding Web3 servicesThe point exchange service is part of a strategic partnership agreement signed by Milk Partners and SK Planet, the operator of OK Cashbag, in June. Beyond loyalty programs, the two companies plan to maintain collaboration efforts to expand Web3 services. In particular, they will cooperate to enhance the ecosystem of the UPTN blockchain, jointly developed by SK Planet and Ava Labs, utilizing Avalanche Subnet technology.Cho Jung-min, CEO of Milk Partners, said that the utility of MiL.k has increased thanks to its partnership with OK Cashbag, whose points are accepted at numerous retailers both online and in-store. He added that the company will explore more partnerships to provide a wider range of tangible benefits to both corporate partners within the MiL.k alliance and app users.

news
Policy & Regulation·

Apr 26, 2023

Web3 Offers Potential for Japan to Rediscover its Mojo

Web3 Offers Potential for Japan to Rediscover its MojoEveryone recognizes that Japan has been at the forefront of innovation and the development of technology in the past but can it rediscover that cutting edge through Web3 and blockchain? In a recent interview with Forkast News, Yudai Suzuki, Co-Founder of a Tokyo-based Web3 incubator, suggested that it has that potential.©Pexels/邱 韬Re-establishing a competitive edgeSuzuki, who heads up Fracton Ventures, believes that such a pivot is possible for Japan in making Web3 the means through which it can rediscover the innovative edge it has been lacking in more recent years.Despite an historical strength and depth in technology and innovation, Japan has struggled when it comes to adopting and implementing new technology on a global scale more recently.Legacy techEarlier this year, it emerged that leading Japanese technology companies were collaborating with a view to creating a new open metaverse infrastructure called “Ryugukoku.” That project implicates the creation of a Japan Metaverse Economic Zone. Suzuki cites this project as demonstrative of a key issue relative to the overall development of Web3 in Japan.The project involves Japan’s legacy tech companies such as Fujitsu and Mitsubishi. He goes on to clarify that the majority of Web3 projects in Japan are being led by the existing technology behemoths despite the fact that Japan is seeing the emergence of a Web3-native generation.Suzuki identifies that one of the fundamental aspects of Web3 is that every decentralized autonomous organization (DAO) that’s created is immediately global in nature. Allied with that, most of that 18–25 year old Web3 native generation in Japan want to break through language barriers and communicate on a global basis.That outward looking characteristic is positive but it’s not how venture investment has traditionally worked in Japan. He explains that the conventional approach to investing in start-ups in Japan has been to first look to dominate the Japanese market before going global. The Fracton Ventures founder believes that this is a flawed approach in today’s world and that by the time they’ve gotten to number one in Japan, it’s already too late in trying to achieve that on a global basis.Government responsibilitySuzuki places much of the responsibility in affecting a more appropriate approach on the Japanese Government. “If they focus only on these huge Japanese companies, they will not succeed,” he says. He is also critical of the regulatory approach. Suzuki believes that “the government wants to change the laws and set new regulations at an early date,” and with that, such over-regulation has resulted in crypto entrepreneurs leaving the field. Regulation needs to be set on a more flexible basis so that it can be easily updated and upgraded as the technology develops.Global MindsetHe highlights the importance of having a global mindset and being open to different ideas and perspectives in order to succeed in the Web3 space. The entrepreneur points to that Web3-native demographic in Japan, explaining that their mindset has changed to a more global one as a consequence of dabbling in Web3. The same he believes is necessary on the part of the government if Japan is to become a leader in the tech industry once again.

news
Loading