Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Dec 22, 2025

South Korea plans to revive crypto ICOs under stricter disclosure and oversight rules

South Korea is set to allow initial coin offerings (ICOs) next year, easing a ban on crypto fundraising that has been in place since 2017. A draft of the Digital Asset Basic Act, prepared by the Financial Services Commission, would allow domestic sales of digital assets if issuers meet disclosure requirements, the Maeil Business Newspaper reported. The measure is intended to address concerns about tokens that are initially listed on overseas exchanges before becoming available to South Korean investors. The legislation outlines tougher accountability standards for crypto issuers. Projects that provide false information or fail to disclose material details in their whitepapers ahead of an ICO could be held liable for investor losses. Liability would also extend to other parties substantially involved in an offering, including outsourced operators and market makers.Photo by Y K on UnsplashStablecoin issuers need Korean presenceSeparate provisions set out rules for stablecoins, barring tokens issued by entities without a physical presence in South Korea from domestic trading, a restriction that would apply to widely used stablecoins such as USDT and USDC. Issuers would be required to fully back stablecoins with reserves such as cash or government bonds held at banks or financial institutions and would be prohibited from paying interest to users. The proposal reflected the FSC’s position on the second phase of digital asset legislation focused on stablecoin issuers. The issue remains subject to inter-institutional debate, with the Bank of Korea pressing for a bank-led consortium model for stablecoin issuance. The ruling Democratic Party of Korea (DPK) is expected to review a consolidated bill combining proposals from the government and the National Assembly next month, with plans to advance the legislation during the regular parliamentary session in the first quarter of 2026. The FSC’s focus on consumer protection is also reflected in its plans to introduce a Digital Finance Security Act, detailed in a recent report to the presidential office. According to Digital Asset, the proposed legislation would establish rules for traditional financial institutions as well as electronic financial businesses and virtual asset service providers. The move came after a 44.5 billion won ($30 million) hacking incident last month at Upbit, the country’s largest crypto exchange. Existing regulations under the Virtual Asset User Protection Act do not contain provisions specifically covering such cases. Separately, the FSC is working to strengthen its response to emerging forms of financial crime, including transnational offenses and crypto-enabled money laundering. It said measures under consideration included adding state-level criminal organizations to the list of entities barred from financial transactions, improving anti-money-laundering (AML) rules to better align with international standards, and expanding the scope of the travel rule. On the supervisory side, the commission intends to make the Virtual Asset Division a permanent unit after initially establishing it as a temporary body, News1 reported. The Virtual Asset Inspection Division within the Financial Intelligence Unit is also set to become a standing unit. Price declines weigh on exchangesThe stepped-up regulatory focus has coincided with a broader downturn in the crypto market. Bitcoin is trading below $89,000, about 30% below its all-time high of $126,000 set earlier in October. CoinGecko data cited by IT Chosun showed average daily trading volume across South Korean exchanges falling to $2.95 billion in November from $4.41 billion in August, with trading fees accounting for about 98% of exchange revenue. The broader market weakness has also been accompanied by declines in altcoins. South Korean crypto investors attributed the recent drop in altcoin prices to capital flowing into major cryptocurrencies such as Bitcoin and Ethereum. A weekly survey conducted by CoinNess and Cratos showed that 41.7% of the 2,000 respondents cited capital concentration in leading tokens as the primary factor, followed by the growing number of altcoins at 31.6%, their limited practical value at 14.7%, and technical factors such as chart patterns at 12.1%. 

news
Web3 & Enterprise·

Jul 12, 2023

NEOPIN Launches South Korea’s First ETH Liquid Staking Product

NEOPIN Launches South Korea’s First ETH Liquid Staking ProductNEOPIN, the global CeDeFi platform of Neowiz Holdings, a South Korean investment holding company, has launched liquid staking products for ETH and KLAY, as reported by local media outlet News1.Photo by Kanchanara on UnsplashLiquidity provider tokensLiquid staking enables users to deposit their cryptocurrencies into a staking pool and, in return, receive liquidity provider tokens. These tokens can then be redeposited to earn additional yield. For example, NEOPIN users can stake ETH or KLAY on the platform and receive npETH or npKLAY tokens, respectively, which can be further deposited to earn rewards.NEOPIN asserts that it is the first Korean blockchain project to introduce an ETH liquid staking product. To make the platform more user-friendly, NEOPIN has improved its interface, ensuring easy navigation for its customers.In celebration of this launch, NEOPIN is hosting a promotional event. Users who utilize the ETH liquid staking product will earn the NPT token, the native token of the NEOPIN ecosystem, with an annual percentage yield (APY) of 5% until August 9. Meanwhile, participants in the KLAY liquid staking product can earn twice the reward points until September 26 through the ongoing NEOPIN membership promotion campaign.Qualitative and quantitative growthPrior to this development, it was reported that NEOPLY, the operator of NEOPIN, joined the Innovation Programme of the Abu Dhabi Investment Office (ADIO) in the United Arab Emirates (UAE). Stefan Kim, Chief Business Officer at NEOPIN, highlighted the strategic collaboration between the platform and the Abu Dhabi Global Market (ADGM) to establish a regulatory framework for decentralized finance (DeFi). Kim emphasized that while this partnership will contribute to NEOPIN’s qualitative growth, the implementation of liquid staking derivatives finance (LSD-Fi) will pave the way for its quantitative expansion.

news
Web3 & Enterprise·

Aug 30, 2023

India’s Jio Financial Services to Delve Into Blockchain

India’s Jio Financial Services to Delve Into BlockchainJio Financial Services (JFS), a subsidiary of Indian multinational conglomerate Reliance Industries (RIL), is gearing up to venture further into the realm of blockchain and central bank digital currencies (CBDCs), according to announcements made by Indian billionaire businessman and Reliance Chairman and Managing Director, Mukesh Ambani, during RIL’s 46th annual general meeting on Monday.Photo by Shubham Dhage on UnsplashBlockchain ambitionsThe Indian billionaire revealed his Web3-related plans, signaling a strategic move for JFS towards blockchain and centralized digital currencies. While addressing the AGM, Ambani emphasized his current caution regarding highly volatile crypto assets. However, he indicated that he aims to have Jio Financial delve deeper into blockchain technology and permissioned digital currencies, particularly the eRupee CBDC, which is undergoing advanced trials within India.JFS will serve as the entry point for Reliance Industries into the Web3 sector. Formerly known as Reliance Strategic Investments, JFS has been rebranded and will now facilitate management services for digital assets.Consolidating payment infrastructureAmbani’s vision for JFS encompasses the consolidation of payment infrastructure, a strategic effort to drive digital adoption throughout India. JFS hit the headlines in July when it was revealed that it was forging a major partnership with BlackRock, the world’s largest asset manager, valued at over $100 billion as of August 18.Ambani’s statement during the RIL annual general meeting highlighted JFS’s objectives: “JFS will consolidate its payment infrastructure further driving digital adoption for India. JFS products will explore pathbreaking features such as blockchain-based platforms and CBDC.”CBDC development has been ongoing through initiatives taken by central banks around the world over the past couple of years. The Reserve Bank of India (RBI) has been no slouch in this respect. It is actively engaged in developing its own CBDC, aiming to modernize online payment systems while reducing reliance on physical cash, thereby optimizing operational efficiency.In July, the RBI turned its attention to the cross-border functionality aspect of CBDCs, experimenting with various use cases relative to international payments. At a governmental level, India is also playing a key role in working towards global regulatory standards for cryptocurrencies. The RBI has contributed to the discussion, citing risks associated with stablecoins in a Financial Stability Report released in June and calling for global regulation.RIL CBDC initiativesNotably, Reliance General Insurance recently announced its acceptance of the eRupee CBDC for premium payments, and earlier this year, Reliance Retail initiated the use of India’s digital rupee CBDC across its Mumbai-based stores. The CBDC is anticipated to outperform India’s successful Unified Payments Interface (UPI) mobile payments system, according to V Subramaniam, Managing Director at Reliance Retail.Ambani’s RIL empire encompasses a diverse range of businesses, including Jio’s network services, retail stores, and fuel stations. Mukesh Ambani’s move to embrace blockchain and CBDCs will likely have broader implications beyond his own companies, given that it signals his intention to drive India’s digital transformation forward.

news
Loading