Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Aug 08, 2023

Concerns Hanging Over Huobi Result in Significant Net Outflow

Concerns Hanging Over Huobi Result in Significant Net OutflowAmidst rumors swirling around its executives’ involvement in a Chinese investigation, Seychelles-headquartered cryptocurrency exchange Huobi has observed net outflows exceeding $73.3 million in the past week.Photo by Shubham Dhage on Unsplash$73 million net outflowAccording to data sourced from blockchain analytics firm Nansen, Huobi reported an outflow of tokens worth $505.9 million over the previous week, with an inflow of $432.5 million. This resulted in a net outflow of approximately $73.3 million.Notably, this net outflow seems to be gaining momentum, as the exchange witnessed an outflow of $32.9 million on Monday alone, based on Nansen data. Additionally, Huobi’s stablecoin balances experienced a significant 33% contraction, dwindling to $99.47 million within the seven-day span, as per the data.Unverified reportsHowever, the outflow of funds coincided with unverified reports. Techub News, a Hong Kong-based crypto media outlet, cited insider sources to suggest that at least three high-ranking Huobi executives had been apprehended by Chinese authorities for investigation. Huobi originated in China with Chinese founders, albeit it has based itself in Seychelles ever since the Chinese crackdown on crypto trading emerged.Huobi’s Head of Social Media, Jiayin Xie, acknowledged the rumors and likened the situation to being “invited to tea,” a colloquial Chinese expression for being summoned by authorities for questioning. Despite this, Xie expressed concern over the baseless nature of the allegations, suggesting that the path to restoration might be challenging yet necessary for the exchange’s resurgence.Justin Sun, an advisor to Huobi, responded cryptically by tweeting the number “4,” a term commonly used in the crypto community to counter FUD (fear, uncertainty, and doubt). He also retweeted Xie’s post, standing in defiance of the rumor.Alongside this specific difficulty, Huobi continues to grapple with financial challenges. Sun revealed that the exchange hadn’t posted a profit from last year’s third quarter to this year’s second quarter. Despite this, Sun remains optimistic, projecting a potential break-even in the present quarter and a return to profitability in the upcoming quarter.Crypto platform uncertaintyThe aftermath of widespread crypto platform failures in 2022 has resulted in both regulatory pushback and concern among the crypto community relative to the well-being of the platforms that remain standing. Both Huobi and Binance are front and center of this speculation and concern. The issue is that without independently verified audits carried out by reputable auditors, market participants simply have no way of telling if these platforms are solvent.Travis Kling, the Chief Investment Officer at Ikagai Asset Management didn’t mince his words in taking Houbi to task via Twitter: “You are clowns and criminals, and there’s a billion dollar hole in your balance sheet that customers will have to eat.” Kling has been equally scathing in his criticism of Binance and its founder Changpeng Zhao (CZ). Ikagai took a significant hit in the FTX collapse, and in its wake, Kling promised to speak out more and be more critical regarding emerging issues within the sector.As the net outflows coincide with reports of executive custody, the situation surrounding Huobi remains fluid. The exchange’s journey through these challenges will no doubt be closely monitored by the crypto community.

news
Policy & Regulation·

Apr 28, 2023

Hong Kong to Issue Digital Asset Licensing Guidelines in May

Hong Kong to Issue Digital Asset Licensing Guidelines in MayAccording to Hong Kong’s Securities and Futures Commission (SFC), the Commission will issue new guidelines for virtual asset exchanges within the Chinese autonomous special administrative region (SAR).© Pexels/Jimmy ChanSFC CEO Julia Leung made that announcement while speaking at an event in the city on Thursday, indicating that the guidelines are due to be released next month. Additionally the autonomous region intends to introduce a new licensing system from June 1 onwards, enabling the retail investors among Hong Kong’s populace to trade leading cryptocurrencies like Bitcoin and Ethereum.Hong Kong authorities had provided an insight into this approach back in February, when plans to provide retail access to digital assets were first set out. At the time, they outlined the need for retail customers to pass a knowledge test relative to digital assets or otherwise only being allowed to trade such assets once the customer had completed a certain level of training relative to digital assets, provided by a regulated crypto service provider.This latest announcement has arrived amid a backdrop of a series of recent indications that signify the intent of authorities in Hong Kong to make the autonomous region a major financial hub centered around digital assets.Leung articulated that the further development of this digital assets framework follows a consultation process that attracted more than 150 responses. Although virtual asset service providers (VASPs) will need to await the complete rollout of the licensing system, a handful of crypto businesses such as OSL and Hashkey, under the supervision of the Hong Kong regulator, have already started to offer their services.Crypto as propertyA Hong Kong court recently recognized cryptocurrency as property. The ruling emerged in a bankruptcy hearing pertaining to failed cryptocurrency exchange Gatecoin. In presiding over the case, Justice Linda Chan outlined that the autonomous region takes a broad view of what constitutes property. In finding crypto to meet the definition of property, she went on to clarify that it therefore has the capability of being held in trust.The finding has particular relevance in the crypto world right now given the consequences of an “in trust” custodianship of customer’s digital assets relative to numerous ongoing bankruptcy processes involving failed crypto businesses, and the pecking order of creditors in those instances, in their efforts to recover their digital assets.Positive approachWhile mainland China remains an adverse territory relative to digital assets, Hong Kong has taken to welcoming the sector and with that, enticing crypto firms to relocate to the autonomous region from the mainland. Leadership in the city has been making all the right soundings to demonstrate that it is actively trying to nurture the nascent sector.While recent months have seen the Biden administration in the United States attempt to close off banking from the crypto sector, in contrast, Hong Kong’s largest virtual bank, ZA Bank, was recently given permission to act as a settlement bank for regulated Web3 businesses located within Hong Kong.

news
Web3 & Enterprise·

Jul 29, 2023

Checkout.com Partnership Sees Alchemy Pay Extend Global Reach

Checkout.com Partnership Sees Alchemy Pay Extend Global ReachAlchemy Pay, a leading Singapore-headquartered fiat-crypto payment gateway, has announced a major collaboration with Checkout.com, a renowned payment processor serving global digital businesses.The partnership, announced by Alchemy Pay via a blog article published on Friday, allows the firm to seamlessly integrate Checkout.com’s Visa and Mastercard channels into its on and off-ramps, enabling effortless transactions between fiat currency and cryptocurrency worldwide. Furthermore, Alchemy Pay’s NFT Checkout product is also set to incorporate these channels in the near future, expanding the reach of the payment gateway even further.Photo by Jonas Leupe on UnsplashVisa and Mastercard integrationThe company claims that the integration of Visa and Mastercard payment rails via Checkout.com enables it to achieve one of the highest payment acceptance rates in the industry. This seamless integration allows users to easily buy and sell digital assets through Visa and Mastercard using the Alchemy Pay Ramp and NFT Checkout.Checkout.com is a leading global payments solution provider catering specifically to large global enterprise merchants, handling massive transaction volumes daily. In 2021 alone, the company processed hundreds of billions of dollars in payments. Its esteemed clientele includes major names such as Netflix, Farfetch, Grab, Sony, Pizza Hut, and Shein.As a premier payment processor, Checkout.com further strengthens its position by providing crucial support to prominent players in the crypto industry, including Circle and Kucoin, among others. The company’s offerings include higher global acceptance rates, enhanced conversion rates, reduced charge-backs, and comprehensive global coverage through a streamlined entry point.Bridging crypto and fiat economiesBy eliminating obstacles to widespread crypto and NFT service adoption, Checkout.com’s smooth conversion process aligns perfectly with Alchemy Pay’s mission of bridging the gap between fiat and crypto economies on a global scale.Digital assets don’t exist in a vacuum. The history of this new asset class is short, having emerged within a world where we have all engaged with a conventional finance system which continues to hold most of the wealth that exists. It’s vital therefore, that services like Alchemy’s broaden the ability to on and off ramp between crypto and fiat if we are to encourage ever greater participation in the crypto economy.Alchemy Pay has been actively pursuing collaborations with renowned global acquirers and payment processors to streamline its on and off-ramp processes. In April the company announced a collaboration that would see it enable domestic transfer payments in India via India’s Unified Payments Interface (UPI) system to effect crypto purchases. Earlier that month, it secured $10 million in funding from market maker DWF Labs, with the funding earmarked towards expanding the business within the South Korean market.Leveraging its payment channels, Alchemy Pay has successfully connected to key markets worldwide, enhancing its capabilities in global coverage and licensing, while also reducing transaction and operating costs.In addition to strategic partnerships, Alchemy Pay has an impressive track record of securing licenses in various countries and regions, including the United States, Canada, Indonesia, and Lithuania.

news
Loading