Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Sep 27, 2023

Indian Crypto Platform Mudrex Expands Operations in Italy

Indian Crypto Platform Mudrex Expands Operations in ItalyMudrex, the Indian cryptocurrency investment platform, has achieved a new milestone by successfully registering to operate in Italy.News of Mudrex’s move into the Italian market emerged via a press release published on Tuesday, as well as through an interview given recently by CEO and Co-Founder Edul Patel to CoinDesk. The expansion into Italy marks a rare international move for Indian crypto entities, which have faced challenges due to stringent taxation policies and the global crypto market’s fluctuations.Photo by Mathew Schwartz on UnsplashGlobal expansion planPatel unveiled Mudrex’s ambitious plan for global expansion, with half of the team actively working on international initiatives. The firm’s journey into the Italian market involved gaining approval for registration with Italy’s Organismo Agenti e Mediatori (OAM), a crucial step for crypto firms operating in the country. This registration, granted on September 1, was a strategic move that the company had been carefully planning. Patel explained:“We just wanted some time to pass after the approval before we made the news public.”Coin Sets and thematic indexesDespite having only one million registered users, Mudrex stands out as one of India’s largest crypto platforms. It offers a unique investment approach, focusing on index investing through Coin Sets, an innovative alternative to speculative trading. These Coin Sets encompass various categories, including small, mid, and large-cap assets, as well as Bitcoin (BTC) and Ethereum (ETH). Additionally, Mudrex provides thematic indexes that cover layer one and layer two solutions, NFTs, metaverse projects, and Dow trackers.“While India is our home and where we initially grew, our international customers have told us that investment products in their regions lack diversity,” Patel noted. “We believe that our product is unique and offers distinct advantages.”Mudrex was established in 2018 in Bengaluru while also establishing an office in San Francisco. Alongside Patel, its other Founders included Alankar Saxena as CTO, Rohit Goyal in the role of VP of DeFi, and Prince Arora as VP of Engineering.In 2021 it raised $2.5 million in funding with a view towards launching crypto mutual funds and ETFs. It followed that up in 2022 when it raised $6.5 million in a pre-series A funding round, supported by Y-Combinator, Arkham Ventures, and Tribe Capital.The firm participated in what has become a crypto platform trend over recent months by incorporating an AI chatbot into its platform in June to assist platform users when it comes to learning about crypto.Lithuanian trading licenseMudrex’s expansion into Italy was facilitated by the company’s prior fulfillment of EU operating requirements. The company had obtained a license in Lithuania less than a year ago, enabling it to navigate the EU regulatory landscape efficiently. During the six months of pursuing registration in Italy, Mudrex’s presence in the EU grew substantially, with user numbers increasing from approximately 5,000 to 17,000.With its foothold established in Italy, Mudrex now seeks to make its investment products accessible through various registered entities, including banking partner apps. Patel confirmed ongoing discussions with potential partners, further signaling the company’s commitment to expanding its global footprint.

news
Web3 & Enterprise·

Jan 25, 2024

Eggverse and Weracle team up to bolster NFT gaming ecosystem

South Korean NFT trading platform Eggverse has signed a strategic business agreement with blockchain gaming platform operator Weracle to target the global market for NFT-linked gaming and expand the ecosystem, according to local news site ZDNet on Thursday (KST). The two firms plan to sketch a business model and implement specific strategies to provide differentiated and more convenient gaming experiences for users by making trading NFTs faster and easier.Photo by Choong Deng Xiang on UnsplashCollaborative expansion"With our years of project experience with leading partners in each field and our in-house technology, we expect to create strong synergies in expanding the global gaming ecosystem of both companies," Eggverse said. "Through this collaboration, we will promote various types of Web3 games in new marketplaces. We expect it will yield the biggest progress among the events we plan to organize in the first half of 2024." Popularizing digital assetsBased in Singapore, Weracle provides a variety of services, including swapping its own governance token, Weracle (WERAC), and Weracle Wallet, which allows users to store and manage game NFTs. Eggverse, on the other hand, is known for its Web3-compatible service that allows customers to mint and resell real-life items like hotel vouchers and artwork as NFTs – the first of its kind in South Korea. Last November, the platform signed a business deal with Asian blockchain hub SPLabs to venture into the Southeast Asian Web3 market.

news
Policy & Regulation·

Nov 04, 2023

SEC seeks summary judgment against Terraform Labs

SEC seeks summary judgment against Terraform LabsThe U.S. Securities and Exchange Commission (SEC) is making a strong push for a summary judgment in its ongoing legal battle against Singapore’s Terraform Labs and its co-founder Do Kwon. Such an outcome would spare the need for a protracted trial.According to a motion filed by the SEC on Thursday, the record shows that there is “no genuine dispute as to any material fact and that the moving party is entitled to judgment as a matter of law.”Photo by Caleb Fisher on UnsplashRelying on the Howey TestThe SEC’s filing underscores its central argument that Kwon and Terraform Labs were involved in the sale of securities. The document categorically states:“There is no dispute that purchasers made an investment of money, either through fiat currency or crypto assets, for each crypto asset — LUNA, wLUNA, MIR, and UST, thereby satisfying the first prong of Howey.” The Howey Test refers back to a U.S. Supreme Court case — SEC v. Howey — which took place in 1946. The case set a precedent and has subsequently become the cornerstone of determining what is or is not a security in the United States.This argument hinges on the idea that funds were pooled in a common enterprise with the expectation of profits primarily derived from the efforts of the promoters.Citing fraud as well as unregistered securitiesThe SEC’s assertion is two-fold, contending that not only did Terraform and Kwon engage in selling securities, but they also engaged in fraudulent activities and disseminated misleading information. The SEC reiterates these claims in its filing, emphasizing that the defendants committed fraud by duping investors about the stability of UST.They allegedly falsely attributed the algorithm for price stabilization while orchestrating clandestine third-party interventions. This purported deception made their claims regarding the algorithm’s effectiveness deceptive and involved the omission of crucial information. The fallout from Terra’s collapse in May of the previous year resulted in the destruction of substantial investor wealth, totaling billions of dollars.Similar defense team filingThe SEC’s move to seek summary judgment comes in the wake of a similar filing by Kwon’s defense team last Friday. Kwon is currently serving a sentence for document forgery in Montenegro, a situation stemming from his arrest at an airport with forged passports.Notably, Terraform’s co-founder, Daniel Shin, who is currently on trial in South Korea, has attributed the collapse of Terraform Labs to Kwon’s mismanagement. Shin has claimed his separation from the company and its activities occurred two years before its eventual collapse.In this legal battle that holds significant implications for the cryptocurrency and blockchain space, the SEC continues to emphasize its position, asserting that Kwon and Terraform Labs engaged in the sale of securities through deceptive means. The outcome of this case could have far-reaching consequences, setting precedents for future regulatory actions in the industry.

news
Loading