Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Mar 12, 2024

CryptoTax joins hands with Infinite Block to provide crypto custodial and accounting services

Xxsoft, an information technology firm based in South Korea, announced today that it entered a partnership with a blockchain firm Infinite Block, local media outlet Kyunghyang Games reported. Xxsoft is the operator of CryptoTax, a tax and accounting service specializing in crypto assets. The two companies aim to provide crypto custodial and accounting services for companies and enterprises.Photo by Sarah Elizabeth on UnsplashCryptoTax specializes in handling crypto investors’ taxation using algorithms designed to process crypto tax and accounting. These algorithms were developed with participation from tax accountants and accountants with expertise in crypto assets. CryptoTax also offers a solution as a service (SaaS) called Cryptotax Enterprise, which offers corporate clients the advantage of automated tax processing with direct access to accounting documents.  Meanwhile, Infinite Block is a key management service (KMS) provider based in Korea, serving clients ranging from startups to big firms. The company provides crypto wallets catering to individual clients’ needs, from internet-enabled hot wallets to cold wallets that keep private keys offline. Infinite Block employs multi-signature technology and multi-party computation to securely protect clients’ private keys. Rising demand for institutional crypto accountingYoon Dong-hwan, CEO of Xxsoft, said the shift in crypto regulations – as seen in events like the approval of spot Bitcoin ETFs by the U.S. Securities Exchange Commission – will result in higher demand for crypto custodial services compliant with financial authorities. He stated that the partnership with Infinite Block will allow the company to provide a convenient service tailored to the needs of corporate clients.  Jeong Gu-tae, CEO of Infinite Block, highlighted the importance of companies being equipped with a fully compliant internal control system when it comes to crypto taxation and accounting, because firms are subject to stricter regulations compared to individual investors. Jeong reaffirmed the company’s commitment to building a healthy local crypto market, saying that it will continue developing effective crypto asset management systems for corporations in close cooperation with CryptoTax.  

news
Policy & Regulation·

May 27, 2023

Gulf Binance Secures Thai Digital Asset License

Gulf Binance Secures Thai Digital Asset LicenseBinance, one of the world’s leading cryptocurrency exchanges, has secured a digital asset operator license in Thailand, paving the way for the launch of a new crypto exchange and broker. The license, granted by the Ministry of Finance of Thailand and overseen by the Southeast Asian country’s Securities and Exchange Commission (SEC), ensures that the upcoming platform will operate in compliance with regulatory requirements.Photo by Markus Winkler on UnsplashLicense awardThe license was awarded to Gulf Binance, a joint venture between Binance and Gulf Innova Co., Ltd., a subsidiary of Gulf Energy Development PCL. It marks a significant milestone in Binance’s expansion efforts. The partnership was initiated through a memorandum of understanding signed in January 2022, as both parties recognized the potential of establishing a digital asset exchange in Thailand.Richard Teng, the head of Asia, Europe, and MENA at Binance commented on the development: “By harnessing Binance’s expertise together with Gulf’s established local presence and network, Gulf Binance aims to showcase the full potential of blockchain technology to meet the needs of Thai users. Local users can expect access to a trusted and regulated service that prioritizes user security alongside compliance with local regulations.”Combined expertiseGulf Innova, as a prominent player in the Thai business landscape, brings extensive expertise and experience in the digital asset trading sector to the joint venture. The conglomerate, headed by billionaire Sarath Ratanavadi, operates in various industries, including energy production, telecommunications, and digital businesses.By combining Binance’s unparalleled growth and expertise in the digital asset space with Gulf’s established presence and knowledge in Thailand, the partnership aims to create a powerful synergy that drives innovation, fosters growth, and provides exceptional value to users in the digital asset ecosystem.Q4 launchThe new crypto exchange is expected to commence operations in the fourth quarter of 2023, although further details about the platform will be disclosed closer to the launch.Often criticized for its opaque structure, Binance is showing renewed commitment to transparency and regulatory compliance. As regulatory frameworks are put in place in varying jurisdictions, global crypto businesses are having to change corporate structures in order to meet these changing requirements. That’s evidenced by Binance’s Thai joint venture, its launch of a separate corporate entity in the form of Binance Japan and a similar move by crypto exchange BitMEX in Hong Kong.Thailand has emerged as a significant cryptocurrency hub in Southeast Asia, with its capital city, Bangkok, ranked 10th globally in The Crypto Readiness Index published by Recap, a cryptocurrency tax software company. Despite the ban on cryptocurrencies as a payment method, Thailand continues to flourish as a hub for trading and investment activities in the crypto space.That ban on cryptocurrency payments, implemented by the SEC in April 2022, aimed to safeguard the stability of the financial system and mitigate potential risks to the economy. The SEC identified price volatility, cyber theft, and personal data leakage as concerns associated with cryptocurrencies. However, the regulatory measures did not impede trading or investment activities, allowing the crypto industry to thrive.Chainalysis, a leading blockchain analysis company, ranked Thailand 8th in its Global Crypto Adoption Index for 2022, surpassing countries like Russia, China, Nigeria, Turkey, Argentina, and the UK. This recognition highlights Thailand’s progressive stance toward digital assets and its growing adoption within the country.

news
Policy & Regulation·

Jun 22, 2023

New Kazakh Platform Underscores Binance’s Push Eastwards

New Kazakh Platform Underscores Binance’s Push EastwardsGlobal cryptocurrency exchange Binance is making a significant move towards the East in response to mounting regulatory challenges in Western markets. The exchange has recently launched a regulated digital asset platform in Kazakhstan, marking a milestone in its expansion strategy.The announcement was made during a press conference held on June 20, attended by distinguished guests including representatives from Kazakhstan’s banking sector and Binance Kazakhstan’s leadership. The company followed up with a blog post detailing the development, published to its website on Wednesday.This milestone achievement follows Binance’s preliminary approval for operations in Kazakhstan received last August. By October, the Astana Financial Services Authority (AIFC) granted the exchange a permanent license to establish a digital asset platform and provide custodial services at the Astana International Financial Center.Photo by Engin Akyurt on PexelsBespoke platformThe newly established Binance platform in Kazakhstan aims to cater specifically to the needs of Kazakhstani users. It offers a comprehensive suite of services encompassing cryptocurrency exchange, conversion, fiat currency deposits and withdrawals, as well as custody of crypto assets.These financial services will be facilitated through a partnership with Freedom Finance Bank, Kazakhstan’s banking partner for Binance. Users of the platform will be able to transfer fiat funds to their accounts, with deposits and withdrawals currently supported through bank transfers or bank cards via Freedom Finance Bank.Adverse Western market conditionsBinance’s expansion into Kazakhstan comes at a time when the exchange is grappling with legal challenges in the United States and several European countries. In the US, Binance is currently embroiled in a lawsuit with the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC).Last month, Binance announced its withdrawal from the Canadian market, citing regulatory changes which the company described as “untenable.” Meanwhile, in Europe, the company has faced regulatory pushback, including an investigation into alleged “aggravated money laundering” in France and its exit from the Dutch market due to the absence of a virtual asset service provider license.Binance’s withdrawal from European markets has been attributed to its efforts to comply with the European Union’s approved Markets in Crypto Assets (MiCA) regulations, although there are reports indicating collaboration between European regulators and the SEC in their investigations into Binance.Eastern expansionWhile Binance has been facing ongoing setbacks in Western markets, it continues to expand eastwards. Late last month, the firm announced plans to establish a dedicated platform in Japan. Around the same time, it secured a trading license through its Thai joint venture company.Binance is not the only major crypto firm making a strategic shift towards Asia. Other global cryptocurrency exchanges such as Gemini and Coinbase, have also expressed their intention to strengthen their presence in the Asia Pacific region. This trend highlights a broader pattern of the crypto exchange landscape gradually shifting towards the East, reflecting a reconfiguration of the global market.As Binance expands its regulated operations in Kazakhstan, it aims to navigate the complex regulatory environment and continue providing secure and compliant services to users in a key market. The move not only positions Binance strategically but also underscores the evolving dynamics that may well be playing into a regional shift in leadership where the development of digital assets is concerned.

news
Loading