Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jul 19, 2023

AIITONE Partners with FIDES Development for Real Estate Tokenization

AIITONE Partners with FIDES Development for Real Estate TokenizationAIITONE, a South Korean blockchain-based fintech company, has announced a partnership with FIDES Development, a real estate developer, to enhance their collaboration in the security token sector, as reported by local outlet Hankook Economy TV.FIDES Development has been undertaking various initiatives within the real estate sector, including the identification of underlying assets for security tokens, the development of virtual reality-based show houses, and the implementation of artificial intelligence-powered property technology. In order to support FIDES in these endeavors, AIITONE will provide its advanced fintech services.Photo by Jiho Choi on UnsplashReal estate tokenizationThe objective of the collaboration between the two companies is the tokenization of real estate properties. FIDES Development has developed a wide range of projects, including apartments, offices, and multi-purpose complexes. One of their current projects is a 39-floor accommodation building in Gangwon Province.Legalizing security tokensGiven the accelerating legislative process associated with legalizing security tokens in the National Assembly, construction and development companies are increasingly interested in the fractional investment industry.Both AIITONE and FIDES Development expressed their excitement about this partnership, as they believe it will enable them to identify valuable real estate assets and tokenize them, thus creating innovative and secure investment opportunities.Notably, Kim Seung-bae, CEO of FIDES Development, is also the chairperson of the Korea Developer Association (KODA), which has trained around 18,000 professionals in the field. KODA serves as a legal organization representing South Korea’s real estate development industry.Similar developments in JapanMeanwhile, similar developments have been observed in Korea’s neighboring country, Japan. In May, Mitsui & Co. Digital Asset Management introduced Alterna, a security token platform with a primary focus on real estate. Alterna has democratized investment opportunities that were previously inaccessible, enabling individuals to invest with a minimum of 100,000 yen. The platform garnered substantial interest from Japanese investors, amassing over 10,000 pre-registrants ahead of its official launch.

news
Web3 & Enterprise·

Nov 14, 2023

Covenant Labs and Haechi Labs join forces to integrate Web3 services into P2E game

Covenant Labs and Haechi Labs join forces to integrate Web3 services into P2E gameCovenant Labs, a subsidiary of South Korean smart city platform CityLabs, has signed a memorandum of understanding (MOU) with Haechi Labs, a blockchain service provider, to integrate Haechi Labs’s services into its Play-to-Earn (P2E) game Covenant Child and related non-fungible token (NFT) projects, thus expanding its presence in the blockchain ecosystem.Photo by ELLA DON on UnsplashElevating Web3 accessibility and securityThese services include Face Wallet — a non-custodial digital wallet geared towards onboarding Web2 users to Web3 — and Kalos, a blockchain and smart contract security audit service for Web3 enterprises.Face Wallet has gained recognition within the industry as a widely-used wallet across global blockchain mainnets, including Polygon, Solana, BNB, NEAR Protocol, Aptos and Avalanche.Notably, it addresses issues that users usually run into with traditional digital wallets like MetaMask, such as complicated login processes. It allows users to log in using their social media accounts, such as Google, Apple, X (formerly Twitter), Discord, Facebook and Kakao, without installing a separate wallet. Users can also enhance their wallet security through two-factor authentication (2FA) by setting a simple six-digit PIN code.Meanwhile, Kalos provides detailed and personalized security audit reports put together by security experts from around the world. The service specializes in areas like Solana Smart Contract, zero-knowledge proofs and Cosmos SDK.Enhancing the gaming experienceThese two services will be integrated into Covenant Child, which offers engaging content through both gameplay and game finance (GameFi). In particular, its GameFi system allocates two types of tokens — Covenant (COVN) and Child (CHLD) through P2E activities, such as mining compatible NFTs earned during gameplay.Covenant Labs CEO Jin Hyung-il and Haechi Labs CEO Moon Geon-ki expressed their anticipation for the agreement, stating that their respective companies would aim to provide gamers with a stepping stone to easily onboard Convenant Labs’ gaming ecosystem and gain access to various user-friendly services.

news
Web3 & Enterprise·

Jan 24, 2025

Phemex halts withdraws following $37M hack

Phemex, a Singapore-headquartered crypto derivatives trading platform, has halted withdrawals following a multi-million dollar hack.Photo by GuerrillaBuzz on UnsplashHot wallet compromisedIn a message to platform users published to social media, the project stated: “To ensure security, withdrawals have been temporarily suspended while we conduct an emergency inspection and strengthen wallet services. We sincerely apologize for the inconvenience. Withdrawals will be restored soon.” In further commentary, the project apologized for the disruption, assuring service users that its mission remains to provide a trusted trading environment, while outlining that it is working on putting together a compensation plan. It added that “Our ongoing business operations are fine,” and that “trading services continue as usual.” The digital assets were removed from the platform over multiple blockchains including Polygon, Arbitrum, the Base network and BNB. Blockchain analytics firm Lookonchain itemized some of the assets that are believed to have been stolen. They include 3.48 million USDC stablecoin, 3.42 million USDT stablecoin, 841 ETH valued at $2.7 million, 110,701 LINK valued at $2.69 million, 142 billion PEPE tokens valued at $2.12 million, 1.19 million FET tokens valued at $1.45 million and 29,509 AVAX tokens valued at $1.04 million. Initial reports put the loss at $31 million. However, Web3 security firm Cyvers later claimed that $37  million covers the full extent of the loss. Following deeper analysis, it found that both Bitcoin and TRON blockchains had also been impacted, resulting in the overall loss being increased by a further $6 million. Cold wallet assets are safeThe company’s CEO Federico Variola, published a post on X advising service users that all of the assets held within the company’s cold wallets remain safe. He included a link to the Phemex proof of reserves, encouraging customers to check it. In a follow-up post, he wrote: “We are currently carefully testing our system to reprise withdrawals as soon as possible. Due to the sophistication of the threat actor we cannot rush this stage. The estimated timeline to reprise full operations is within 24h, thank you for your support.” The XNET Foundation, a non-profit entity that develops decentralized wireless networks, said that it is actively working with the Phemex team on the production of an exploit report following the incident. It added that “It has been confirmed that tokens sent to the exchange for a launchpad pool were compromised as part of this exploit.” Ongoing problemCrypto hacking remains a major concern within the digital assets sector. Blockchain security firm PackShield reported recently that $1.3 billion had been laundered from crypto hacks in 2024. That statistic demonstrates that the problem is worsening as it accounts for a $342 million or 280% increase when compared with 2023. In December a Chainalysis report found that 61% of the hacking losses suffered in 2024 implicated the involvement of North Korean hackers. It estimated crypto hacking losses of $2.2 billion for 2024, based on losses associated with 303 hacking incidents.

news
Loading