Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jan 05, 2024

BingX signs sponsorship deal with English Premier League club

Singapore-based cryptocurrency trading platform BingX has secured a sponsorship deal as the new sleeve sponsor for Premier League football club Chelsea.Photo by Chaos Soccer Gear on UnsplashJanuary 9 debutThe arrangement, spanning the next six months, is expected to debut during Chelsea’s Carabao Cup semi-final first-leg match against Middlesbrough on Jan. 9. As part of this sponsorship, BingX will prominently feature on the front of Chelsea’s training kits for the upcoming 2024/25 season. Meanwhile, the current shirt sponsor, Infinite Athlete, will transition to a training sleeve sponsorship starting next season. While details about the fate of Chelsea’s training kit deal with Trivago, an online hotel booking site, remain uncertain, the club is navigating sponsorship changes in the wake of owner Roman Abramovich’s prior ownership and UK government sanctions. Corporate rebrandEstablished in 2018, BingX operates as a cryptocurrency exchange headquartered in Singapore, catering to a user base of over 10 million in Southeast Asia and North America. In November, the company announced that it was rebranding the business. Part of that process was understood to involve an overhaul of BingX’s visual identity, with the introduction of a streamlined logo. Sponsorship within the English Premier League is a high profile marketing move that will undoubtedly bring more visibility to that brand. Crypto marketing spend reboundThe marketing spend of crypto firms relative to high profile sponsorship deals has recovered significantly in recent months. Such sponsorship deals peaked at the top of the crypto market in 2021. That period saw profligate spending by many of the large crypto platforms. A standout example was provided by the $135 million sponsorship deal signed by fraudulently run crypto exchange FTX for the Miami Heat stadium naming rights in the United States. While that opulent sponsorship spending subsided during the bear market, it appears that there has been a modest resurgence as market conditions have improved. Seychelles-based crypto platform OKX has ongoing marketing relationships with the McLaren Formula One racing team and Manchester City Football Club. In March, U.S.-based crypto exchange Kraken announced a marketing partnership with the Williams Formula One racing team. Earlier this week it emerged that crypto gambling platform Stake.com had signed a sponsorship deal with the Sauber Formula One team. 18 of the 20 English Premier League clubs are now understood to have agreed sponsorship deals at one time or another with crypto companies. This demonstrates the growing trend of cryptocurrency platforms associating with high-profile sports partnerships, enhancing their visibility and influence in the market. Chelsea is actively seeking a front-of-shirt sponsorship deal, considering potential collaborations, including discussions with Saudi national carrier Riyadh Air. It’s understood that the BingX deal has been agreed for in excess of £10 million ($12.7 million) per season.

news
Web3 & Enterprise·

Sep 14, 2023

Sony Network Communications and Startale Labs to Launch Joint Blockchain Venture

Sony Network Communications and Startale Labs to Launch Joint Blockchain VentureProminent Japanese internet service provider Sony Network Communications and Singapore-based Web3 company Startale Labs are undertaking a new joint venture to develop a blockchain network for facilitating the worldwide adoption of Web3.Photo by CHUTTERSNAP on UnsplashCultivating an innovative Web3 ecosystemThis comes after Sony Network Communications’ initial $3.5 million investment in Startale Labs back in June. Both companies expressed their commitment to paving the way for revolutionary Web3 applications through the development of a solid blockchain infrastructure. To do so, they said that they would leverage Sony Group’s knowledge and expertise in various sectors, such as gaming, music, entertainment, and financial services, to apply a multifaceted approach to the joint venture.“By combining Sony Network Communications’ experience in communication, the Internet of Things (IoT), artificial intelligence (AI), and solution services with Startale Labs’ insights and technical prowess in Web3, we aspire to create a global infrastructure that underpins the Web3 era, driving innovation across existing industries,” said Jun Watanabe, President and Representative Director of Sony Network Communications.The new business will be established this month under the name Sony Network Communications Labs.“This joint venture is founded on the synergy created by our respective assets and knowledge, and it is aimed at collectively developing a leading blockchain ecosystem. We are determined to discern Web3 trends and drive them globally,” said Sota Watanabe, CEO of Startale Labs.Governmental supportSony Group, Sony Network Communications’ parent company, has consistently been making strides in the Web3 realm. Sony Bank, another affiliate of the group, joined hands with Mitsui & Co. Digital Asset Management (MDM) a few months ago to establish MDM’s security token service Alterna.These efforts have been encouraged by a backdrop of active support for Web3 and crypto businesses from the Japanese government. The Japanese National Tax Agency recently announced the revised corporate taxation rules for crypto assets, which renders companies exempt from taxes on unrealized gains from cryptocurrencies if the virtual assets were issued by the company and have been continuously held since issuance, or if they have remained subject to certain transfer restrictions since issuance.Startale Labs’ popular smart contract platform Astar Network also recently launched an Ethereum layer 2 scaling solution dubbed Astar zkEVM: Supernova with Polygon Labs in a strategic move to expand Web3 adoption in Japan and onboard more enterprise partners.

news
Web3 & Enterprise·

Sep 13, 2023

Bitget Exec Speaks to Utility of Enhanced KYC

Bitget Exec Speaks to Utility of Enhanced KYCCrypto continues to undergo significant transformation as regulatory authorities across Asia tighten their grip on the industry. In response to these regulatory changes, Seychelles-headquartered Bitget has joined KuCoin and OKX, which have recently bolstered their Know Your Customer (KYC) measures to ensure compliance and safeguard their operations.In a recent interview with Cointelegraph, Bitget Managing Director Gracy Chen spoke to the utility of KYC measures, stating that KYC is useful in filtering out illegitimate users, particularly those engaged in activities such as money laundering.Photo by Pixabay on PexelsMeeting Asian regulatory requirementsThe Seychelles-based exchange with ties to China and Singapore recently announced updates to its KYC protocols. These changes come in the wake of the Monetary Authority of Singapore’s (MAS) directives, which advise financial institutions, including cryptocurrency exchanges, to implement robust risk management procedures. The MAS has taken a stringent stance, shutting down certain digital payment token service providers to prevent them from facilitating lending and staking activities by retail customers.Starting from October 1, Bitget will require users who have not completed level 1 KYC verification to be restricted from creating new trading orders. This move aims to ensure that users comply with the newly updated guidelines and maintain the integrity of the exchange’s operations.Following industry peersKuCoin and OKX, two other prominent exchanges which, like Bitget, have their corporate headquarters in Seychelles and a strong presence in Asia, have also revamped their KYC policies. While KuCoin initially introduced KYC in 2018, the exchange has strengthened its identity verification procedures, requiring users to upload documents and complete face checks.Furthermore, in July, it announced a mandatory KYC requirement, in line with anti-money laundering (AML) regulations. While the mandatory KYC requirement is already in force, the other changes are set to take effect at the end of the month.OKX, on the other hand, has implemented stringent requirements, including the submission of a government-issued ID selfie for users to access all its services. The exchange recently set a deadline for service users to complete KYC.Bitget’s Chen highlighted that its decision to embrace KYC measures was driven by a commitment to serving the market responsibly. She acknowledged that while some users may have reservations about KYC, it is a necessary step to maintain the integrity of the exchange and prevent illicit activities. Speaking at the fringes of the firm’s EmpowerX Summit in Singapore, Chen said:“I’m pretty sure if the user is a financially healthy user, such as, like, if they’re not doing something illegitimate, such as money laundering, they should be pretty comfortable with the KYC process.”Tightening regulationThe tightening of regulations in Asia is not limited to Singapore alone. Japan has also taken steps to enhance anti-money laundering measures related to cryptocurrency transactions, responding to international calls for stricter oversight. Additionally, South Korea’s Financial Services Commission (FSC) has announced plans to require companies to disclose details about their cryptocurrency holdings, expected values, and related business models in their financial statements, aligning crypto accounting with conventional financial reporting.These regulatory developments signify a broader trend in the region, with cryptocurrency service providers proactively adapting to the changing landscape. As governments and regulatory authorities take steps to address the potential risks associated with cryptocurrencies, exchanges are prioritizing compliance to ensure their longevity and continued growth.

news
Loading