Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Nov 03, 2023

Treehouse expands NFT data offering through Origins acquisition

Treehouse expands NFT data offering through Origins acquisitionTreehouse, a Singapore-based Web3 data firm, has bolstered its presence in the NFT analytics market with the recent acquisition of Origins Analytics, an NFT analytics platform. This strategic move is aimed at enhancing Treehouse’s NFT product offerings and expanding its capabilities in the flourishing NFT ecosystem.Photo by Andrey Metelev on UnsplashAcquisition synergyTreehouse announced the acquisition on Thursday, via a press release published by PR Newswire. Origins Analytics has distinguished itself as a leader in NFT data analysis. The enterprise had raised $4 million in funding in 2022, going on to grow a community of over 10,000 users. The enterprise-grade platform offers valuable insights and services to NFT enthusiasts and investors.Origins Analytics proficiency in both on-chain and off-chain data analysis had made it a highly sought-after name in the NFT space. With this acquisition, Treehouse is doubling down on its intention to deliver comprehensive NFT analytics services to its clientele.In reorganizing the businesses following acquisition, the founding team of Origins Analytics will be joining forces with Treehouse. Treehouse’s management believes that this synergy of expertise from both companies will ensure a seamless transition and integration of Origins’ capabilities into Treehouse’s existing suite of offerings.Broadening service offeringThe integration of Origins Analytics opens up new avenues for Treehouse’s service portfolio. As a consequence, Treehouse will now be able to offer an algorithmically tagged NFT wallet notification system. This will allow its clients to anticipate and better leverage algorithms to deliver real-time updates on NFT transactions and wallet activity.Treehouse is set to introduce NFT analytics bots designed to provide comprehensive data insights and market trends, empowering users to make informed decisions in the dynamic NFT sector. Additionally, the company will go forward to offer an NFT wallet profiling API, granting users deeper insights into NFT wallet activity and aiding in trend identification and opportunity spotting.CEO of Treehouse, Brandon Goh, conveyed his enthusiasm for the acquisition and the broader NFT analytics market, stating:“Treehouse is excited to make this move into NFT analytics. This strategic acquisition underscores our commitment to our clients, many of whom have NFT exposures. Our team is gearing up to integrate Origins’ system into our flagship product, Hyperion, confident that its technology aligns with our users’ needs and paves the way for us to serve the wider NFT community. Despite the bear market, Treehouse is expanding and is actively looking to acquire synergetic businesses.’’Expansion ambitionsTreehouse’s decision to acquire Origins Analytics comes hot on the heels of its successful seed round in 2021, which saw it raise $18 million from prominent investors, including Lightspeed, MassMutual, Binance, Mirana, LeadBlock, Jump, GSR and Wintermute. This recent acquisition stands as a testament to Treehouse’s ambition to broaden its Web3 portfolio and provide cutting-edge services to its valued clients.While the exact financial terms of the acquisition remain undisclosed, Treehouse clearly views this move as a strategic investment in the rapidly expanding NFT market. The company demonstrates confidence in its ability to harness the potential of the NFT sector, even in the face of challenging market conditions.

news
Web3 & Enterprise·

May 07, 2024

Polaris Office marks 10th anniversary, POLA rises 14%

South Korea-based document management software firm Polaris Office announced the 10th anniversary of its office software (SW) cloud service launch, according to local media News1. Reaching this milestone has coincided with the rising price of its native token, POLA. At the time of writing, POLA is trading at KRW 48.89 ($0.04), up 13.99% from the previous week.  The 10th anniversary of its service launch appears to be a direct cause behind this recent rise in POLA prices, despite the recent downturn in the crypto market. The company said that it recently held an AI (artificial intelligence) talk concert to celebrate its 10-year milestone.Photo by Andrew Neel on UnsplashPOLA as rewards for sharing knowledge Launched in 2020, POLA tokens are distributed as a reward within its platform, Polaris Share Service, which the company describes as "the distributed trading system of incentive knowledge." Here, users can earn POLA by creating content and sharing knowledge on the platform. Cloud-based document management softwarePolaris Office offers a cloud-based service that allows real-time document editing on various operating systems (OS) including mobile, web office, Windows and Mac. Since the outbreak of the COVID-19 pandemic, the company has experienced significant growth in its sales, recording an all-time high annual sales last year. This growth is attributed to the increased adoption of hybrid work environments.  By consolidated standards, Polaris Office recorded KRW 107.9 billion in sales, KRW 6.2 billion in operating profit and KRW 24.4 billion in net profit, marking YoY increase of 346.1%, 277.1% and 91.2%, respectively.  Joining government-led document AI projectMeanwhile, Polaris Office has been designated as a participatory company in the "SW Computing Industry Source Technology Development Project" led by the Ministry of Science and ICT of Korea, as reported by crypto media CoinNess on April 15. In this project, Polaris Office is expected to contribute to advancing the document AI technology. 

news
Web3 & Enterprise·

Apr 19, 2023

Lackluster Nasdaq Debut for Bitdeer

Bitcoin miner Bitdeer Technologies Group’s stock had a rough debut on the Nasdaq exchange, losing almost 30% of its value shortly after market open on Friday. The Singapore-based firm, which is one of the largest bitcoin miners in the world, had delayed its listing several times and saw a lukewarm reception from investors. Bitdeer’s merger with a special-purpose acquisition vehicle called Blue Safari Group Acquisition Corp was approved on Tuesday, paving the way for the listing. Mining across six sitesBitdeer has six mining sites across Washington state, Texas, Tennessee, and Norway, with a total energy capacity of 775 megawatts as of the end of 2022. It has a hashrate or computing power of 16.2 exahash per second (EH/s), second only to bankrupt miner Core Scientific and higher than Riot Platforms and Marathon Digital Holdings. Around one-quarter of the hashrate is used for self-mining, while the rest is given out for cloud mining, which means that customers rent the machines and reap the rewards.Despite the company’s impressive size and scale, Bitdeer’s financial performance deteriorated in 2022, which was partly due to worsening market conditions. The company reported revenue of $330.3 million and a loss of $62.4 million for the year, compared with $394.7 million in revenue and a profit of $82.6 million in the previous year. The company’s listing comes at a better time than last year, as market conditions have improved, and bitcoin has passed the $30,000 mark. Mining equities have also outperformed the digital asset in percentage growth. Differentiation of mining operatorsHowever, Bitdeer’s listing was not received as positively as expected, and the stock was halted several times for volatility shortly after the market opened. Other crypto mining stocks saw single-digit upticks in their share value at the same time. The market is beginning to shift from operators with the biggest scale to operators with the best unit economics, said investment bank Stifel Nicolaus’s analyst Bill Papanastasiou.This shift may explain why investors were not too keen on Bitdeer’s debut, as the company’s financials are not as strong as those of its competitors. Despite Bitdeer being larger than Marathon and Riot, based on its current share price and valuation, it is priced at a third of the value of its two industry peers.Bitdeer was born out of the world’s largest rig manufacturer, Bitmain, following a spat between the two co-founders. The firm is not the only cloud mining firm affiliated with Bitmain that is going public via SPAC, as BitFuFu is also in the process of going public, but has delayed its listing. Bitdeer’s stock debut may have been lackluster, but the company remains one of the largest bitcoin miners in the world.Shares in the newly quoted public company opened at $9.70, sliding to $6.30, before ending the first day’s trading at $7.03.

news
Loading