Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Sep 05, 2023

Bybit Leans on Innovative Tech by Launching AI-Powered Trading Assistant

Bybit Leans on Innovative Tech by Launching AI-Powered Trading AssistantDubai-headquartered cryptocurrency exchange Bybit has introduced TradeGPT, an AI-powered educational tool aimed at changing the way in which traders interact with the cryptocurrency market.A ToolsGPT follow-upThe move follows on from the firm’s launch of ToolsGPT in June, an AI-based tool that aids platform users to generate technical analysis and takes a ChatGPT-like approach in providing responses to user queries. Vivien Fang, Head of Financial Products at Bybit, explained: “Our analysts and tech team created ToolsGPT to provide the financial education and mentorship that is sorely needed in our hyper-financialized world. Essentially, we built the tool that we all wished we had when we began our careers in financial engineering and trading.”Photo by Wance Paleri on UnsplashAI mentor and guideFor Bybit users, TradeGPT offers a multitude of benefits, including real-time market analysis, multilingual support, and personalized guidance. It functions as a mentor and guide, empowering users to comprehend market trends, formulate strategies, and select the most suitable investment products to achieve their financial goals.This offering addresses the limitations of traditional AI systems and provides real-time market data. TradeGPT leverages Bybit’s extensive market data, trading analytics, and technical analysis tools, making it a resource for traders navigating the complexities of the cryptocurrency landscape.Following industry trendBybit’s TradeGPT follows in the footsteps of Singapore-based platform Crypto.com, which unveiled its AI-enabled platform, Amy, in May. Amy leverages the technology of OpenAI’s ChatGPT to deliver real-time information about specific tokens, projects, price listings, and historical events to Crypto.com platform users.At the time Kris Marszalek, CEO of Crypto.com, highlighted the platform’s significance, stating: “Amy is the latest example of our incredible momentum.” The company added that it followed a series of notable product launches, including CFTC-regulated options trading, on-chain staking solutions, and the GEN 3.0 Crypto.com Exchange.Binance, the world’s largest cryptocurrency exchange by trading volume, introduced Binance Sensei in April. The company has integrated the AI-powered learning tool into Binance Academy and offers users of all skill levels an interactive chat window for guidance.As an increasing number of cryptocurrency companies launch AI-enabled platforms, the synergy between AI and the industry becomes more apparent. AI’s data processing capabilities could address scalability issues and expedite transaction processing for cryptocurrencies.Conversely, cryptocurrencies could incentivize research and development in the field of AI. Tokenized economies may reward contributors to AI projects, fostering collaboration and innovation. Furthermore, cryptocurrency-enabled decentralized networks could provide secure and transparent platforms for exchanging AI-generated insights without the need for intermediaries.Digital assets are developing in real-time alongside other technologies. The introduction of Bybit’s TradeGPT, alongside Crypto.com’s Amy and Binance’s Sensei, offers a step forward in harnessing the power of AI to empower cryptocurrency traders. As these AI-driven tools continue to evolve and gain traction, they’re likely to reshape how individuals and institutions engage with the cryptocurrency market.

news
Policy & Regulation·

Feb 28, 2025

First stablecoins gain DFSA approval in Dubai

The Dubai Financial Services Authority (DFSA), the financial regulatory agency of the Dubai International Financial Center (DIFC), a special economic zone, has approved two stablecoins under its crypto regulatory framework. The two stablecoins, USD Coin (USDC) and EURC, are both issued by blockchain-focused financial services firm Circle. While USDC is a U.S. dollar-backed stablecoin, EURC is a euro-backed stablecoin. In a press release published on the Circle website on Feb. 24, the company announced details regarding the approval. The stablecoins are the first to be recognized and approved by the DFSA.Photo by Christoph Schulz on UnsplashStablecoin integrationThe development means that firms based in the DIFC are now free to integrate either stablecoin into digital asset applications and products focused on areas such as payments and treasury management. A number of Circle executives took to social media to comment on the development. Circle Co-founder and CEO Jeremy Allaire outlined on X that the approval means that financial institutions in Dubai “are now able to transact in markets with USDC and EURC.” In legally recognizing the two stablecoins, Allaire pointed out that the DFSA had joined regulators in the European Union (EU) and Canada.  Last Summer, Allaire announced that Circle’s stablecoins complied with the EU’s Markets in Crypto Assets (MiCA) regulation. In December, Circle became the first stablecoin issuer to meet Canadian listing regulations. Dante Disparte, Circle’s chief strategy officer and head of global policy, pointed out that a trend is emerging requiring the pre-clearing of stablecoins prior to them entering into circulation or gaining regulatory approval. “In always-on finance, reciprocity is key,” he added.  Meanwhile, the firm’s EU Strategy & Policy Director, Patrick Hansen, underscored the significance of the approval. Hansen pointed to the fact that the DIFC is home to 6,000 registered entities, including 800 authorized financial firms. An ‘edge’ over TetherEugene Cheung, Chief Institutional Business Officer at Hong Kong-based digital asset platform OSL, said that the approval was “massive for institutional adoption,” while giving Circle an “edge” over Tether within the $157 billion stablecoin market. While Circle has always taken a regulatory-compliant approach, competitor Tether has struggled with compliance. In Europe, 10 companies have been approved to issue stablecoins under MiCA regulations, but Tether is not among them. This has led to a number of exchanges delisting Tether’s USDT in Europe. The DIFC was first established in 2004. The economic free-zone caters to firms operating within the Middle East, South Asian and African regions. The number of businesses registered within the free zone has increased by 25% since 2023. In November 2022, the DIFC recognized Bitcoin (BTC), Ethereum (ETH) and Litecoin (LTC). The following year, it added Toncoin (TON) and Ripple’s XRP, together with ZETA, the native token of the ZetaChain network. In 2024, the DFSA amended its crypto regulations to allow foreign funds to invest in recognized crypto tokens, while enabling domestic qualified investor funds to invest in unrecognized tokens.Although the regulatory approach taken by the authorities in Dubai accommodates stablecoins, algorithmic stablecoins are prohibited.

news
Web3 & Enterprise·

Mar 09, 2024

Nissan delves into metaverse on a heritage and safety theme

On March 7, Nissan Motor Co. introduced an innovative metaverse experience titled the "Heritage Cars & Safe Drive Studio," blending elements of automotive history with interactive safety education.Photo by Matthijs Waanders on UnsplashMarking 90 years in businessThe studio, launched to commemorate Nissan's 90th anniversary, features three iconic models from the company's past, recreated in virtual environments to reflect their respective eras. Among the showcased vehicles is the Silvia Q’s S13, renowned globally for its role in drifting culture. Users can explore this historic car from the 1980s while learning about the influence of pedestrian clothing colors on driver visibility. In another exhibit, users engage in a mini-game designed to educate on driver field-of-view and the impact of multitasking on safety. Alongside, the Skyline 2000GTX-E, famous for its presence in popular media like the Gran Turismo video game series and Fast and Furious movies, adds a touch of nostalgia and excitement, transporting users to the 1970s era. In a 1950s and 60s American diner and drive-in theater setting, the final exhibit offers a hands-on steering wheel spin exercise. These experiences aim to merge Nissan's heritage with vital safety knowledge, such as understanding the significance of pedestrian attire and the dangers of distracted driving. Developed in collaboration with Japanese university researchers, these immersive experiences are accessible through Meta Quest headsets, marking Nissan's continued exploration of virtual and augmented reality for customer engagement and education. Previous forays into the metaverseThis initiative aligns with Nissan's ongoing efforts to enhance its presence in the metaverse. It’s not the carmaker's first rodeo where the metaverse is concerned. It introduced its first virtual test drive and a virtual unveiling of its Sakura model in 2022. That same year, the company suggested it was interested in providing more in the way of virtual events, even going as far as to suggest the development of virtual customer support offices for clients. It followed that up in December 2023 with a revamp of four existing metaverse worlds, a project that also formed part of its 90th-anniversary celebrations. Nissan's latest foray into the metaverse coincides with advancements in augmented reality (AR) and virtual reality (VR) hardware. The recent launch of Apple's inaugural mixed-reality headset in February 2024 signals intensified competition among tech giants like Meta and Microsoft, who have been gradually expanding into consumer and enterprise AR/VR markets over the past decade. Broader auto industry interestNissan isn’t alone in the auto industry in taking initial steps into the metaverse. Rival Toyota has taken a different approach, pursuing an interest in creating remote workspaces for staff so that meetings can be held in the metaverse. Hyundai experimented with entering the metaverse as early as 2021. Through a partnership with Naver Z, the company offered virtual test drives of its Sonata model. Meanwhile Renault Korea has tipped its toes in the metaverse by offering consumers the ability to custom-build virtual cars on a metaverse platform. Through these metaverse updates, Nissan aims to stay at the forefront of automotive innovation, utilizing immersive experiences to engage customers and promote safety awareness in an increasingly digital world. 

news
Loading