Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

May 10, 2023

OmniBOLT to Support BRC-20 Tokens on Lightning

OmniBOLT to Support BRC-20 Tokens on LightningSingapore’s OmniBOLT, a project that’s developing technological solutions within bitcoin’s layer two network environment, has outlined that it will support BRC-20 tokens on Lightning Network.Before we consider precisely what OnmiBOLT's decision to support BRC-20 tokens means, let’s cover the backstory.Photo by Sander Weeteling on UnsplashBRC-20BRC-20 is an experimental token standard which was created by an anonymous developer with the handle “Domo”, and username ‘@domodata’ on Twitter. A token standard governs how and where a cryptocurrency can be used. The approach has been pioneered by developers on the Ethereum blockchain who created the ERC-20 standard a number of years ago, relative to the Ethereum network.A bitcoin evolutionIn this instance, BRC-20 is a fungible token standard designed for the bitcoin blockchain. Bitcoin development is very slow and conservative, and deliberately so, in an effort to put network security first. However, it has had two major upgrades over the course of the last few years, namely SegWit and Taproot.Many in crypto have been critical of the bitcoin project on the basis of it being a pet rock that lacked features and the flexibility to use it in other ways aside from as a store of value or means of exchange. However, those protocol upgrades have led to further development that is expanding bitcoin’s use case and versatility.SegWit and Taproot enabled the development of Bitcoin Ordinals in January 2023. Ordinals provide a means to create Bitcoin non-fungible tokens (NFTs), by attaching data to individual satoshis, the smallest denomination of Bitcoin. NFTs created this way are immutable as they’re not created on side chains but on the bitcoin blockchain itself.In a fast moving scenario, the development of Ordinals led two months later to the emergence of the BRC-20 standard. BRC-20 tokens can be stored on the bitcoin base-chain, built with the assistance of Ordinals. BRC-20 is an exciting development as it stands to enable smart contract capabilities relative to bitcoin.Solving the bitcoin fee issueMany see this development as a solution for the longer term fees issue that the bitcoin blockchain will have to overcome. Bitcoin miners are compensated in mining rewards but the level of rewards is being cut in half every four years. The concern is that in the longer term, there may not be enough revenue for miners to continue to secure the network effectively.With the development of Bitcoin Ordinals, more fees are generated, and so this is seen as a means through which the network can sustain itself over the longer term.Mempool backlogSo what’s not to like? The issue that has arisen over the past few days is that bitcoin transaction fees have hit a two year high. Over the past few days, there have been in excess of 400,000 unconfirmed bitcoin network transactions sitting in the mempool. The mempool is a mechanism within the bitcoin protocol that stores the data relative to a queue of transactions that are waiting to be confirmed.Relieving pressure on bitcoinThat brings us back to the significance of the Singaporean team of developers at OmniBOLT deciding to support BRC-20 tokens on the lightning network. That move can relieve the pressure on the bitcoin mainnet. The project is being backed by Waterdrip Capital, Danhua Capital, Redline DAO and others.Bitcoin has been a boring protocol and many have celebrated that fact as a feature and benefit for a network that serves a couple of vitally important use cases exceptionally well. However, development never stops and it’s fascinating to see another side to the protocol unfold, and all the while, it’s not entirely clear where it will end.

news
Policy & Regulation·

May 11, 2023

OSL Prepares for Fund Launch Following License Approval

OSL Prepares for Fund Launch Following License ApprovalIn a press release published on Tuesday, Hong Kong-based digital asset platform OSL announced that its asset management business, OSL Asset Management (OSLAM), has been granted a license to trade by the autonomous territory’s securities regulator.Photo by Eliobed Suarez on UnsplashType 1,4 & 9 approvalHong Kong’s Securities and Futures Commission (SFC) has issued the firm with a license which permits it to carry out trading activities encompassing Type 1 (dealing in securities), Type 4 (advising on securities) and Type 9 activities. The latter category enables OSLAM to carry on a business involved in asset management.Upcoming fund launchWith licensing secured, OSLAM is now building up to its first fund launch which it envisages will happen within the next few months. According to the statement the company released, “OSLASM’s inaugural product offering will concentrate on unlocking new opportunities in the rapidly growing sectors of blockchain solutions, artificial intelligence (AI), and Web 3.0 technologies.”The firm claims that it has access to unique deal flow, together with the experience to operate in the asset management arena relative to the digital asset sector. OSL thinks that it is well placed in this regard as it is one of only two companies in Hong Kong who are currently licensed to facilitate security token offerings, trading and dealing.”OSL is an offshoot of the BC Technology Group, a company that provides staffing services to clients in the telecommunications sector. Ken Lo, the Deputy Chairman of BC Technology Group said that this milestone would empower the company “to explore new frontiers in blockchain and AI, creating value for our clients and shaping the future of the industry.” He added that the firm “can unlock unprecedented opportunities for growth, collaboration, and value creation” relative to these sectors.Licensing going live in JuneHong Kong has been pulling out all the stops to enable crypto business in recent months. It recently called on the banks to make an additional effort in catering to the needs of crypto businesses. It has been working on a regulatory framework culminating in this licensing regime. Licensing goes live on June 1.Speaking at the Bloomberg Wealth Asia Summit on Tuesday, Eddie Yue, the CEO of Hong Kong’s other regulatory body, the Hong Kong Monetary Authority (HKMA), said that the autonomous territory had very high guardrails over the past number of years that impeded the development of digital asset-related business. Yue believes that Hong Kong now has the right level of regulation and investor protection in place to enable the development of the sector.According to Yue, Hong Kong sees a greater opportunity in the overarching digital assets space as it develops. “Virtual assets or crypto is actually a very broad term. It’s not really about crypto, you’re talking about stablecoins or tokenized assets in the future.,” he stated.Many commentators have suggested that all illiquid real world assets will ultimately be tokenized in the future. As it stands today, a mere $0.3 trillion of illiquid real world assets have been tokenized. Some researchers anticipate that this level of real world asset tokenization will climb to $16 trillion by 2030.

news
Policy & Regulation·

Aug 03, 2023

Binance Thriving in China Despite Crypto Ban

Binance Thriving in China Despite Crypto BanWhen China cracked down on cryptocurrency trading in 2021, it seemed like Binance, the world’s largest crypto exchange, would have to leave the country behind. However, nearly two years later, an investigative report carried out by the Wall Street Journal finds that business is thriving for Binance in China.Photo by Hanson Lu on Unsplash$90 billion in monthly tradingThe report, which was published on Wednesday, reveals that users managed to trade a staggering $90 billion worth of cryptocurrency-related assets in China within just one month.Internal data, shared with The Wall Street Journal and corroborated by current and former employees, unveils this underground activity. Remarkably, these transactions propelled China to become Binance’s largest market, accounting for a massive 20% of global trading volume, excluding trades by a subset of major traders.Almost one million active Chinese usersDespite the supposed ban, Binance’s internal discussions highlight the pivotal role China still plays for the exchange. Current and former employees indicate that Binance’s investigations team collaborates closely with Chinese law enforcement. This partnership aims to identify potential criminal activities among the 900,000+ active users in China, underscoring Binance’s efforts to maintain oversight.However, Binance now faces regulatory challenges tied to its secretive global operations. In June, the US Securities and Exchange Commission (SEC) filed a lawsuit against Binance and its Founder, Changpeng Zhao (CZ), alleging illegal operations and misuse of customer funds.Meanwhile, the Justice Department is conducting its own investigation. A report by Semafor on Wednesday suggests that authorities are considering fraud charges but they’re concerned that such an eventuality may lead to a run on the exchange. This regulatory onslaught has seen Binance’s market share among US users plummet, leading to a reduction of over 1,000 jobs out of its 8,000-strong workforce.Circumventing regulationThe clandestine existence of Binance’s footprint in China offers insights into the exchange’s ability to function surreptitiously in unwelcoming environments. To circumvent restrictions, Binance directed Chinese users to visit local websites with domain names before rerouting them to the global exchange. This tactic allowed Binance to keep a foothold in China, even after the government blocked direct access to its website in 2017.China’s central bank, responsible for imposing the crypto ban, remained silent when questioned about these developments. Binance’s official stance is that its website is blocked in China and inaccessible to users there.Holding on to its China-based users is crucial for Binance as it navigates a treacherous regulatory landscape that threatens its future. The company’s history with China is intricate. CZ established the firm in Shanghai in 2017, only for the government to initiate a series of regulatory attacks on crypto exchanges soon after. This led to concerns about money being illicitly moved out of the country, and Zhao eventually relocated Binance’s operations to Japan.Despite this move, Binance retained a significant workforce in China, a decision that raised concerns among its US arm regarding data control. Binance’s Chinese heritage also attracted attention, with Zhao addressing the company’s challenge of being labeled both a “criminal entity” in China and a “Chinese company” in the West.Binance’s relationship with China remains complex. As the exchange navigates these murky waters, its ability to operate under the radar and maintain its foothold in markets like China will undoubtedly play a significant role in determining its future trajectory.

news
Loading