Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jun 25, 2024

HashKey to list platform token later this year

Hong Kong-based digital asset financial services firm HashKey Group has announced its intention to list its platform token, HSK, in Q3 2024. HSK tokenomicsThe company set out details of the HSK listing via a series of posts on the X social media platform. The HSK token is based on the Ethereum ERC-20 token standard. Total token supply will be capped at one billion, 65% of which will be allocated towards ecosystem growth. The team will be incentivized by the allocation of 30% of the supply while 5% will be held back in a reserve fund.  Regarding the token’s burning mechanism, HashKey revealed it retains the discretion to repurchase up to 20% of net profits from specified businesses and subsequently burn the acquired tokens from the total supply.Photo by Zoltan Tasi on UnsplashAirdrop imminentIn a statement shared with The Block, HashKey Group detailed that HSK will be integrated across its various products and applications. The community airdrop, launching in late June, aims to encourage user participation. The company stated:“HSK is scheduled to launch a community airdrop through HashKey's core businesses in late June, encouraging users to contribute to community building.” The company believes that HSK will incentivize ecosystem contributors when it comes to development of its layer-2 ecosystem chain, the HashKey Chain. That incentive structure, the company maintains, will result in contributors “providing robust support,” while acting as a “driving force for on-chain users and assets.”  Integration with external ecosystemsThe firm outlined that the HSK token is designed to integrate with external crypto ecosystems so as to best facilitate synergy between internal and external collaborations. HashKey Group boasts a comprehensive Web3 ecosystem, inclusive of infrastructure, middleware, AI, DeFi, GameFi and the Metaverse. HashKey Group’s core businesses include HashKey Capital, HashKey Tokenisation and HashKey NFT. It also operates HashKey Exchange, a licensed cryptocurrency exchange in Hong Kong, with the exchange business having reached a $500 million assets-under-management (AUM) milestone earlier this month.  HashKey Cloud, a Web3 infrastructure provider, formed a strategic partnership with the Aptos Foundation last month with a view towards progressing projects relative to decentralized identity (DID) and security token offerings (STOs). HashKey Global, a global exchange launched in April, has risen to ninth spot in terms of overall crypto exchange trading volume. In January, HashKey Group announced that it raised nearly $100 million in its Series A financing round, achieving a pre-money valuation above $1.2 billion. In September, the investment arm of the company, HashKey Capital, launched a $100 million fund focused on altcoins.

news
Web3 & Enterprise·

Dec 08, 2023

Digital wallet D’CENT and Astar Network team up to bring scalable wallet services to users

Digital wallet D’CENT and Astar Network team up to bring scalable wallet services to usersSouth Korean digital hardware wallet service D’CENT has partnered with Japan’s leading blockchain project, Astar Network, to offer users enhanced wallet scalability and seamless asset management, according to an official Medium post on Friday (local time). D’CENT will be integrated into Astar’s blockchain network.Photo by Shubham’s Web3 on UnsplashDriving blockchain innovationAstar Network is a layer 1 blockchain that supports Ethereum virtual machine (EVM) and WebAssembly (Wasm) smart contracts. Tailored to function as a centralized smart contract hub within the Polkadot blockchain ecosystem, it serves as a comprehensive platform for developers to create and deploy decentralized applications (dApps).Astar is revolutionizing blockchain for millions of users worldwide and is actively working with major South Korean companies to achieve this goal. Its newest partner, D’CENT Wallet, which currently provides cold wallet services for hundreds of users across the world, offers an easy-to-use, secure solution for managing digital assets. In particular, it boasts a convenient user experience (UX) that employs fingerprint authentication. Through the new partnership, D’CENT will become the first wallet to support Astar-zkEVM, Astar’s layer 2 scaling solution.Enhancing accessibility and interoperabilityThe two companies plan to work together to bring D’CENT’s unique services to Astar’s Japanese and global user base. Through its integration into Astar Network, the wallet now supports over 60 blockchain networks, 29 of which are EVM-compatible. Users can also store, manage and trade their ASTR tokens — Astar’s native token. This effectively removes the complicated process of managing assets across multiple blockchains.Beyond its role in asset management, the D’CENT wallet also serves as a gateway to the Polkadot ecosystem, where wallet holders can gain access to a plethora of dApps.Both D’CENT and Astar expect that their collaboration will contribute to shaping the future of blockchain transactions and fostering a more integrated blockchain ecosystem.

news
Web3 & Enterprise·

Jul 19, 2024

UK startups move to expand into Asia

It has emerged in recent days that two London-headquartered crypto startups have taken steps towards expanding into the Asian market.  Funding to fuel Asian expansion Haruko, an investment platform that focuses on digital assets based in London, announced that it has raised $6 million in a Series A funding round, with the intention of using the funds to propel the company’s expansion into Southeast Asia. The round was led by White Star Capital and MMC Ventures. Combined with an initial seed round which was completed in March 2022, Haruko has raised a total of $16 million. The firm provided details of its latest funding earlier this week through a press release published via AccessWire.  Having been founded in 2021, the startup has established its operations in Europe and North America, adding in excess of 50 institutions to its client list. Those clients include hedge funds, family offices, market makers, over-the-counter (OTC) trading desks, digital asset custodians and prime brokerages. Haruko co-founder and CEO Shamyl Malik spoke to the firm’s global expansion plans, stating: "We're looking forward to continuing our global expansion, investing in exceptionally talented team members to support us in our goal of building out an industry-leading, end-to-end solution for digital assets and the future of the finance industry. We will continue to invest singularly in this mission, ensuring the quality of our products and services is at the forefront of all our activity." The company has already established a base in Singapore through which it can expand further into the Asian market. Asia is clearly becoming an attractive destination for crypto startups as alongside Haruko, a recent announcement from crypto custodian Copper outlined that it has acquired a trading license in Hong Kong.Photo by CHUTTERSNAP on UnsplashTCSP license in Hong Kong The London-headquartered digital assets custodian outlined on X that it has secured a Trust or Company Service Provider (TCSP) license in Hong Kong from the autonomous Chinese territory’s Companies Registry. Copper CEO Dmitry Tokarev commented on the milestone, stating: "Combining trust and efficiency is fundamental to our institution-first approach. This license approval in a key global hub only strengthens that unique offer, highlighting Copper’s compliance with Hong Kong’s regulatory frameworks and standards." The license enables the company in extending the offering of its digital asset custody services to clients in Hong Kong. Tokarev added that the license approval “is a key development in Copper’s expansion in the Asia Pacific market.” Back in 2020, the firm raised $8 million in funding in a Series A round that, as with Haruko, featured MMC Ventures, with a view towards expanding into Asia and North America. Towards the end of last year, the firm launched a settlement network for institutional crypto traders. Its ClearLoop network enables clients to manage collateral and settle trades across a number of exchanges while increasing capital efficiency and mitigating counterparty risk. Over the course of the month of June, the company claimed to have processed 13.1 million trades via ClearLoop, accounting for a notional traded volume of $109.9 billion. 17,500 individual risk clearing settlements were finalized, with 3,600 inter-exchange movements. The company had a number of significant announcements last month, including a collaboration with the Sui layer-1 blockchain and the integration of the ClearLoop system by global crypto exchange, Kraken.

news
Loading