Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Policy & Regulation·

Apr 28, 2025

Russian exchange raided against backdrop of cash-to-crypto ban proposal

Mosca, a cash-to-crypto exchange headquartered at the Moscow International Business Center, was subject to a raid carried out by the Russian authorities on April 23. The raid occurred in the immediate aftermath of a call from a member of the commission of the Public Chamber (OP) of the Russian Federation to ban crypto exchanges from facilitating the purchase of cryptocurrencies using cash.Photo by Egor Filin on UnsplashInvestigating fraudWhile attending the Blockchain Life 2025 event in Moscow, Mosca’s Head of Development, Dmitry Titarenko, confirmed to Cointelegraph that the rationale provided for the raid was that it was in connection with fraud perpetrated by one of its platform users. Titarenko added: “Law enforcement agencies have carried out a standard procedure of checking our customer data.” The raid occurred during the company’s attendance at the Blockchain Life conference. Mosca was a key conference participant, having established two stands at the event and winning an award for the best crypto exchange service. Reporting on the raid, local media outlet Baza said that it had been carried out in relation to fraud perpetrated against the former head of the Samara Region Development Corporation, Olga Serova. It explained that Serova had been conned into handing over 350 million rubles ($4.24 million) and $800,000 to the scammers.  Seven arrestsShe withdrew these funds from her bank at the end of last year, despite bank officials having tried to persuade her against the withdrawal for this purpose. The news outlet added that to date, seven people have been arrested in connection with the alleged fraud. The Mosca exchange service may be proving to be attractive to scammers as the platform allows users to buy up to 100,000 USDT per day using cash. Titarenko couldn’t confirm that the raid was carried out in connection with the Serova fraud case. He said that “maybe it was [in relation to] another client.”The exchange executive also confirmed that the company had been in the process of putting in place more resources to carry out anti-money laundering (AML) and know-your-customer (KYC) checks, together with a blacklisting system related to suspicious platform users. Cash-to-crypto ban proposalThe raid occurred within 24 hours of Yevgeny Masharov, a member of the commission of the Public Chamber (OP) of the Russian Federation, putting forward a proposal to ban crypto exchanges from receiving cash, making services like Mosca’s cash-to-crypto exchange illegal. According to state-owned Russian news agency TASS, Masharov said that such a move would “cause a large-scale blow to scammers, because it’s no secret that telephone scammers use crypto exchangers to withdraw cash.”Sergey Mendeleev, a well-known figure within crypto circles in Russia, told attendees at the Blockchain Life conference that such a cash-to-crypto ban would be an unwelcome development for the sector. If such a ban were to materialize, Mendeleev suggested that it would be an indication that the Russian authorities were turning away from the greater development of cryptocurrency in Russia. Last week, it emerged that Russia’s Ministry of Finance, in collaboration with the country’s central bank, plans to launch a crypto exchange for qualified investors. The central bank also confirmed plans to launch a digital ruble payment network in 2026.

news
Web3 & Enterprise·

Aug 30, 2023

India’s Jio Financial Services to Delve Into Blockchain

India’s Jio Financial Services to Delve Into BlockchainJio Financial Services (JFS), a subsidiary of Indian multinational conglomerate Reliance Industries (RIL), is gearing up to venture further into the realm of blockchain and central bank digital currencies (CBDCs), according to announcements made by Indian billionaire businessman and Reliance Chairman and Managing Director, Mukesh Ambani, during RIL’s 46th annual general meeting on Monday.Photo by Shubham Dhage on UnsplashBlockchain ambitionsThe Indian billionaire revealed his Web3-related plans, signaling a strategic move for JFS towards blockchain and centralized digital currencies. While addressing the AGM, Ambani emphasized his current caution regarding highly volatile crypto assets. However, he indicated that he aims to have Jio Financial delve deeper into blockchain technology and permissioned digital currencies, particularly the eRupee CBDC, which is undergoing advanced trials within India.JFS will serve as the entry point for Reliance Industries into the Web3 sector. Formerly known as Reliance Strategic Investments, JFS has been rebranded and will now facilitate management services for digital assets.Consolidating payment infrastructureAmbani’s vision for JFS encompasses the consolidation of payment infrastructure, a strategic effort to drive digital adoption throughout India. JFS hit the headlines in July when it was revealed that it was forging a major partnership with BlackRock, the world’s largest asset manager, valued at over $100 billion as of August 18.Ambani’s statement during the RIL annual general meeting highlighted JFS’s objectives: “JFS will consolidate its payment infrastructure further driving digital adoption for India. JFS products will explore pathbreaking features such as blockchain-based platforms and CBDC.”CBDC development has been ongoing through initiatives taken by central banks around the world over the past couple of years. The Reserve Bank of India (RBI) has been no slouch in this respect. It is actively engaged in developing its own CBDC, aiming to modernize online payment systems while reducing reliance on physical cash, thereby optimizing operational efficiency.In July, the RBI turned its attention to the cross-border functionality aspect of CBDCs, experimenting with various use cases relative to international payments. At a governmental level, India is also playing a key role in working towards global regulatory standards for cryptocurrencies. The RBI has contributed to the discussion, citing risks associated with stablecoins in a Financial Stability Report released in June and calling for global regulation.RIL CBDC initiativesNotably, Reliance General Insurance recently announced its acceptance of the eRupee CBDC for premium payments, and earlier this year, Reliance Retail initiated the use of India’s digital rupee CBDC across its Mumbai-based stores. The CBDC is anticipated to outperform India’s successful Unified Payments Interface (UPI) mobile payments system, according to V Subramaniam, Managing Director at Reliance Retail.Ambani’s RIL empire encompasses a diverse range of businesses, including Jio’s network services, retail stores, and fuel stations. Mukesh Ambani’s move to embrace blockchain and CBDCs will likely have broader implications beyond his own companies, given that it signals his intention to drive India’s digital transformation forward.

news
Web3 & Enterprise·

Aug 10, 2023

Gravity Reports Strong Q2 Revenues, Outlining Blockchain Game Roadmap

Gravity Reports Strong Q2 Revenues, Outlining Blockchain Game RoadmapSouth Korean game developer Gravity has disclosed its consolidated financial statements to share its second-quarter performance. During this period, Gravity reported total revenues of $181 million. This represents a 147.5% increase when compared to the same quarter last year. The company also demonstrated a surge in its operating profit, reaching $40 million, which reflects a noteworthy year-on-year increase of 138.3%.Photo by Max DeRoin on PexelsRagnarok Origin driving up revenueThis upswing in revenue can be primarily attributed to the successful launch of Ragnarok Origin, an MMORPG mobile and PC game that debuted in Southeast Asia on April 6, 2023. Another contributor was the introduction of Ragnarok Origin in Taiwan, Hong Kong, and Macau, alongside Ragnarok X: Next Generation’s performance in Korea.Gravity’s reputation as a prominent player in the gaming industry has been solidified through its creation of the popular massively multiplayer online role-playing game (MMORPG) Ragnarok Online. This flagship game draws its inspiration from a series of comics bearing the same name, which weave together elements from Norse mythology.Upcoming release plansLooking ahead, the game publisher has plans to bring a variety of IP-based games to players worldwide. First, Ragnarok V: Returns is gearing up to enter its closed beta test (CBT) phase in South Korea on August 17. Meanwhile, Japanese gamers can anticipate the launch of White Chord, a character-collecting RPG mobile game, set to debut on August 29. This creation comes from the collaborative efforts of Yulong Games, a Chinese mobile game developer, and Gravity Games Alliance (GGA), Gravity’s Japanese subsidiary.Drawing on its remarkable achievement in Southeast Asia, Ragnarok Origin is now gearing up for a forthcoming launch in Central and South America, scheduled for the fourth quarter of this year. Additionally, fans in Vietnam can look forward to the release of Ragnarok M: Eternal Love, an MMORPG mobile game, slated to arrive in 2024.Blockchain initiativesGravity’s ventures into the realm of blockchain technology also deserve attention. In this regard, Ragnarok Landverse, an MMORPG blockchain PC game, is poised to undertake its second round of CBT during the third quarter of this year. The game sets its sights on a broader launch in the latter half of 2023, encompassing regions like Southeast Asia (excluding Thailand and Indonesia), the Middle East, India, Africa, and Oceania.Furthermore, the anticipation mounts for the global launch of Ragnarok Poring Merge NFT, a time-effective RPG blockchain mobile game, projected to make its debut in the fourth quarter of this year. Another captivating prospect is Ragnarok Monster World, a Web3-based RPG blockchain game for both mobile and PC platforms. Developed by Singaporean company Zero X And, known for its expertise in blockchain game and solution development, the game utilizes NFT technology and is earmarked for release in 2024.

news
Loading