Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Feb 10, 2024

Thailand’s SEC takes legal action against former Zipmex CEO

The Securities and Exchange Commission (SEC) of Thailand has initiated legal proceedings against Akarlap Yimwilai, the former director and CEO of Zipmex Thailand. Failure to disclose vital informationThe Commission set out its allegations against Yimwilai in a statement published to its website on Thursday. The allegations revolve around Yimwilai's purported failure to disclose vital information during his tenure, resulting in financial losses for Zipmex customers. According to the SEC's investigation, Yimwilai allegedly transferred cryptocurrency from Zipmex Thailand's wallets to overseas digital wallets without prior disclosure to customers.Photo by Olivier Darny on Pexels Unauthorized digital asset movementsThe SEC's findings indicate that customer assets held in Zipmex Thailand's Z Wallet were moved into overseas digital wallets before any official announcement regarding changes in terms and conditions. This conduct, the regulator asserts, contradicts the information provided by Zipmex Thailand, constituting fraudulent misrepresentation. Yimwilai served as CEO of Zipmex Thailand from August 2018 to November 2023, as per his LinkedIn profile. This deceptive action misled users regarding the security of their assets, the SEC claims, prompting the Commission to charge him with violating Section 82 of the Digital Asset Business Operation Act B.E. 2561. The SEC's accusations extend to Zipmex Thailand's submission of inaccurate reports on customer assets and violations of regulatory requirements. The regulator contends that the reports submitted by Zipmex Thailand were inconsistent with independently verified information. Inviting further legal actionIn response to these allegations, the SEC has forwarded charges against Yimwilai to the Office of the Public Prosecutor (OPP) for further legal proceedings. The SEC has also filed a formal complaint against Yimwilai with the Office of the Provincial Crime Suppression Division, indicating a pursuit of additional legal action. The determination or otherwise of legal liability will be a pivotal step in this process, emphasized by the SEC. Zipmex Thailand, a subsidiary of Singapore-based Zipmex under the leadership of Marcus Lim, obtained approval to operate from the Ministry of Finance and SEC in 2020. The company reportedly came under scrutiny from financial regulators over its acquisition by V Ventures in 2023.  V Ventures backed out of the $100 million buyout of the company last year, which would have included the return of customer deposits. It claimed that Zipmex had not lived up to the terms of the buyout contract.On Feb. 2, the Thai SEC directed Zipmex to temporarily suspend its digital asset trading and brokerage services, granting the firm a 15-day period to adhere to regulatory guidelines. Earlier reports had highlighted Zipmex's application for court protection amidst a wave of bankruptcies among crypto lenders. In November 2023, Zipmex proposed a restructuring plan to reimburse creditors at $0.30 on the dollar, encountering resistance from key stakeholders. The initial offer stood at three cents on the dollar, with the potential to increase to 30 cents in the event of optimized capital recovery.

news
Policy & Regulation·

Jan 27, 2026

South Korea set to lift 2017 ban on initial coin offerings

South Korea is expected to lift its prohibition on initial coin offerings (ICOs), permitting companies to raise funds through digital token sales for the first time since 2017. The move would mark a reversal of the country’s strict regulatory stance, which was originally implemented to curb speculation and protect investors. Regulators had imposed the blanket ban citing a proliferation of projects with unclear fundamentals, fraud, and a lack of safeguards. Authorities at the time noted that unlike initial public offerings (IPOs)—which price shares based on corporate earnings and growth potential—ICOs lacked established standards for valuing the tokens themselves, making them difficult to assess.Photo by micheile henderson on UnsplashICO limited to qualified issuersAccording to a report by Newsis, the government is preparing to allow token issuance but will restrict eligibility to corporations that meet specific thresholds. Issuers would be required to submit documentation, including white papers, to financial authorities in advance and ensure these materials are available to investors. These requirements are expected to be codified in the Digital Asset Basic Act, a second-phase crypto bill currently under preparation. The report noted that the legislation aims to protect users and mitigate market risks by clearly defining accountability for potential failures. An official from the financial regulator stated that detailed criteria, such as minimum capital requirements, would be outlined in enforcement decrees after the bill is passed. Under the proposed rules, companies would be required to file a disclosure document with financial regulators. The requirement would mirror securities filings, but with a focus on public disclosure rather than regulatory approval. The Financial Services Commission would receive the filings, while the Financial Supervisory Service would examine them. Officials are also discussing measures to hold issuing companies fully liable should problems arise after issuance, reflecting the practical challenges involved in verifying the technical aspects of token projects in advance. The regulatory shift would allow South Korean companies to issue tokens at home instead of routing offerings through jurisdictions such as Singapore or Hong Kong. Until now, Korea-based issuers have typically set up overseas entities to conduct ICOs before seeking listings on domestic exchanges. The change is expected to encourage projects that previously went offshore to return to Korea. An industry official said the return of domestic token issuance would help tech companies raise early-stage funding at home and support the launch of new businesses. The move would also intensify competition among exchanges to attract promising projects, the official said, potentially broadening product offerings and lifting trading volumes. Japan plans ETFs, industry seeks faster rolloutAs South Korea moves to allow token issuance, Japan is also easing digital asset rules, though the industry has flagged the slow pace of change. According to local media reports, Japan’s Financial Services Agency plans to revise rules governing investment trusts to allow the inclusion of digital assets. This change would pave the way for exchange-traded funds (ETFs) tracking spot crypto prices as early as 2028. Asset managers are already preparing for the shift. A Nikkei survey showed that as of last November, major firms, including Nomura Asset Management, SBI Global Asset Management, Daiwa, Asset Management One, Amova, and Mitsubishi UFJ, were considering the development of crypto-related investment trusts. However, the timeline has faced pushback. Tomoya Asakura, chief executive of SBI Global Asset Management, said on X that allowing crypto ETFs only from 2028 would be too slow for a country aiming to position itself as a global asset-management hub. He called for a faster rollout, arguing that such products could help channel household savings into investment. 

news
Web3 & Enterprise·

Jul 18, 2023

Survey Reveals Over Half of Korean Financial Firms Eyeing Both Issuance and Distribution of…

Survey Reveals Over Half of Korean Financial Firms Eyeing Both Issuance and Distribution of Security TokensIn a recent survey conducted by fintech solution provider Koscom, it was found that more than half of South Korean financial companies interested in security token businesses are planning to undertake both the issuance and distribution of security tokens. This result reflects the belief of the financial firms that if they engage only in the secondary market, they will experience reduced profitability due to the necessity of lowering transaction fees amidst fierce competition, as per local business newspaper Hankyung.Photo by Shubham Dhage on Unsplash62% of financial firmsAt a seminar held today, Koscom revealed the result of this survey it conducted among a total of 95 entities interested in security tokens, consisting of 30 securities firms, three banks, one asset management company, and 61 token issuers. Among the financial firms that belong to the first three categories, 62% answered that they will conduct both the issuance and distribution of security tokens. 31% expressed a preference for conducting only issuance, while 7% were inclined towards distribution alone.The survey also highlighted that 38% of financial companies hold a positive outlook on the security token market, although they acknowledge insufficient understanding. Additionally, 34% of respondents anticipate that the security token market will rival the exchange-traded fund (ETF) market in terms of size, while only 10% believe it will eventually replace the initial public offering (IPO) market.Cultural contentWhen it comes to the underlying real-world assets (RWAs) for security tokens, cultural content emerged as the most preferred option, with 71% of respondents selecting it. Real estate followed closely at 66%, with energy (55%), artworks (41%), and agriculture and fisheries (21%) also garnering interest. Respondents were allowed to choose multiple options for this section.Similarly, cultural content remained the top choice among token issuers, favored by 21% of respondents. It was followed by real estate (16%), artworks (14%), intellectual property (14%), and agriculture and fisheries (9%).A Koscom official attributed the preference for cultural content and real estate as underlying assets to their accessibility and profitability.This seminar, organized by Koscom, aimed to create a supportive environment for issuers and distributors struggling to promote security token businesses. Hong Woo-sun, CEO of Koscom, said the company will leverage its expertise in the capital market and blockchain technology to collaborate with authorities and relevant organizations in lowering barriers to entry for market participants who need technical infrastructure.

news
Loading