Top

Telcoin makes users whole in exploit recovery

Web3 & Enterprise·January 13, 2024, 10:31 AM

Singapore-regulated Telcoin, a developer of financial applications for mobile users, has successfully restored user balances following an exploit that saw approximately $1.2 million worth of funds transferred from affected accounts.

https://asset.coinness.com/en/news/3c1766686bc03dc8348603085a3f1f51.webp
Photo by Martin Sanchez on Unsplash

Unauthorized withdrawal of assets

The incident, which occurred in late December, was attributed to an error in the interaction between Telcoin's digital wallet and a proxy contract on Polygon. In a blog post which was published on Wednesday, the company shared a full post-mortem analysis report which it commissioned Hong Kong-based blockchain security firm BlockSec to carry out, relative to the exploit.

 

The fault in the proxy contract's implementation caused a technical conflict that allowed for the unauthorized withdrawal of assets. Fortunately, no admin keys were compromised, ensuring that the broader Telcoin ecosystem remained unaffected.

 

In response to the security breach, Telcoin took action by immediately freezing the use of its application as a precautionary measure. The team initiated an investigation and committed to releasing updates promptly to address the issue and restore normalcy. The identified address associated with the exploit was 0x35d2775e5f95596509951b140d68fc5b9185ff98.

 

TEL token freefall

Despite the initial market turbulence, with the price of the Telcoin (TEL) token plummeting, the cryptocurrency has demonstrated resilience. On Dec. 25, TEL fell from a peak price of $0.00235146 to $0.00122535, representing a 48% decrease. At the time of writing, the price has slightly rebounded, trading at $0.001335. Nevertheless, it's still down 40% over the course of the past month's trading.

 

In a social media direct message to CoinDesk recently, Telcoin's founder and CEO, Paul Neuner, expressed pride in how his team responded to the issue, stating:

 

“Making the decision to preemptively restore affected user wallets from our company treasury was a no-brainer, and I’m proud of the team for making that happen in record time.”

 

Regulatory standing

Telcoin's regulatory standing played a crucial role in instilling confidence during this challenging time. Although headquartered in Tokyo, the company is regulated in Singapore as a Major Payment Institution (MPI) by the Monetary Authority of Singapore (MAS).

 

The firm is also registered and regulated in other global markets, including Canada and Australia. Telcoin maintains offices in Singapore, Tokyo, Dubai and Los Angeles. The company had been active in trying to shape regulation in the United States in 2023, with company executives having made repeated visits to Washington D.C. to meet with Financial Services Committee members and staffers on Capitol Hill.

 

In April of last year, the company extended its service offering to the European market, starting out initially in Lithuania.

It appears that the restoration of Telcoin's application services led to a significant boost in user confidence. The company reported a 400% increase in deposits compared to the previous month. Users responded favorably to Telcoin's swift resolution of the security breach, with a ratio of $3.60 being deposited for every $1 withdrawn in the first day since the service restoration.

 

Telcoin's measures, collaboration with security experts and the surge in user deposits appear to have resulted in a resilient recovery. The saga highlights the importance of prompt and transparent responses in maintaining trust in the face of crypto security issues.

 

 

More to Read
View All
Policy & Regulation·

Jun 22, 2023

Ripple Receives In-Principle Approval From Singaporean Regulator

Ripple Receives In-Principle Approval From Singaporean RegulatorRipple, the blockchain-based payments firm, has obtained in-principle regulatory approval from the Monetary Authority of Singapore (MAS) to offer digital asset payments and token products in Singapore.Photo by Dids on PexelsODL service expansionThe approval, announced on Wednesday, will enable Ripple’s subsidiary, Ripple Markets Asia Pacific, to expand its On-Demand Liquidity (ODL) service. ODL facilitates the seamless transfer of the XRP cryptocurrency across borders without the involvement of traditional banking intermediaries.Ripple had applied for an institutional payment license under Singapore’s Payment Service Act to secure the regulatory green light. In response to the approval, Ripple CEO Brad Garlinghouse praised the MAS for its pragmatic and innovation-driven approach to cryptocurrency-related services.He expressed confidence that Singapore would serve as a prominent gateway for Ripple’s business operations in the Asia Pacific (APAC) region. On Twitter, Garlinghouse wrote: “As a major global financial center, Singapore led the way in taking a pragmatic, innovation-first approach to crypto — we’re incredibly proud @Ripple is one of a handful of firms (<20) to receive in-principle approval for a MAS MPI license for digital payment token services!”Stuart Alderoty, Ripple’s Chief Legal Officer, explained that the regulatory approval from MAS would enhance Ripple’s ability to support forward-thinking customers who are exploring the potential of blockchain and crypto technologies to create a more inclusive and borderless financial system.Growing APAC presenceRipple’s presence in Singapore has already been growing significantly. In 2022, the company doubled its number of employees at its Asia Pacific headquarters, with Singapore becoming a major hub for ODL transactions. The MAS, recognizing the potential of fintech firms in the digital money services sector, published its Purpose Bound Money (PBM) white paper on Wednesday, proposing standards for such firms operating in Singapore.While Ripple has made progress with regulatory compliance in Singapore, it has faced legal challenges in other jurisdictions. Since December 2020, Ripple’s legal team has been dealing with a lawsuit filed by the US Securities and Exchange Commission (SEC), accusing Ripple of conducting an unregistered securities offering with its XRP token.The case is expected to reach a verdict in the coming months. While the speculation is that the case has gone well for Ripple, it remains to be seen to what extent it can get the upper hand in taking on a cornerstone institution of the US establishment like the SEC.Either way, Ripple is moving to develop on a global basis. It has recently pursued further development in the Middle East via a Dubai expansion. In Hong Kong, it is collaborating with local regulators in trialing the use of its technology relative to real-world asset tokenization.The company has also established partnerships with central banks in Montenegro and Thailand, as well as numerous regional banks and financial institutions worldwide.The regulatory approval from MAS marks a significant milestone for Ripple, expanding its customer reach and positioning the company for further growth in the digital asset payment sector. Digital asset innovation is truly global and as many organizations are demonstrating, just as Ripple is in this instance, innovative curtailment in one region will simply manifest itself as greater development in another.

news
Web3 & Enterprise·

Aug 11, 2023

BitKeep Changes Name to Bitget Wallet Following Acquisition

BitKeep Changes Name to Bitget Wallet Following AcquisitionContinuing the trend set by industry giants like Binance, KuCoin, and OKX, cross-chain wallet provider BitKeep has undergone a transformation, rebranding itself as Bitget Wallet. This strategic shift comes on the heels of the wallet’s acquisition by the prominent Seychelles-headquartered crypto exchange, which acquired a controlling stake for $30 million in March.Photo by Jon Tyson on UnsplashBitget Swap unveiledThe rebranding announcement, made on August 10, coincides with the unveiling of Bitget Swap, a novel cross-chain swap mechanism integrated into the wallet. This innovative feature draws liquidity from a network of approximately 100 decentralized exchanges spanning across 20 chains. The move positions Bitget Wallet as a versatile platform catering to traders seeking fluidity and efficiency across diverse cryptocurrencies.Bitget Wallet users are set to benefit from an enticing proposition as the exchange merges its offerings. A collective Bitget User Protection Fund, boasting a substantial $360 million pool, has been established.The fund is anchored by 6,500 Bitcoin, ensuring robust safeguards against security incidents. This initiative finds its origins in the wake of the FTX exchange collapse last November, with the fund’s value boosted by a subsequent $60 million capital appreciation due to the rally in Bitcoin prices.The synergy between the two businesses has already borne fruit for Bitget. Last month, it clarified that it had surpassed 20 million users, with the wallet integration believed to be responsible for a large part of that user growth.Growing painsBitKeep’s past wasn’t without its challenges. A security breach occurred in December when the wallet’s Android Package Kit (APK) was compromised by malware, causing losses of around $8 million among users who had installed the compromised package. In a commendable move, the company fully compensated the affected users on March 29, signaling its commitment to rectifying such setbacks.Moka Han, Chief Operating Officer of Bitget Wallet, underscored the wallet’s security-focused approach. Han revealed that cross-chain bridges are subject to stringent third-party security audits by notable entities like SlowMist and CertiK before deployment. Rigorous post-deployment monitoring further guarantees a resilient security environment.Payment channel integrationIn its recent evolution, Bitget Wallet has integrated five stable payment channels, including Banxa, Simplex, Alchemy Pay, MoonPay, and FaTPay. These integrations empower users to conveniently purchase cryptocurrencies within the wallet using methods such as credit cards, Google Pay, and Apple Pay. Additionally, the wallet has introduced a peer-to-peer marketplace, characterized by comprehensive security measures that protect both buyers and sellers.Bitget Wallet’s appeal extends far and wide across the Asia Pacific (APAC) region, boasting an impressive user base exceeding 10 million individuals. This figure constitutes nearly half of MetaMask’s user count, signifying the wallet’s considerable popularity.The company didn’t allow the rebrand milestone to pass without taking the opportunity to further promote its offering. On Thursday, it commenced a “Mystery Box Airdrop” event, offering new Bitget Wallet users the opportunity to claim individual rewards of up to 1,000 USDT.Biget’s wallet integration is in line with the changing landscape of crypto exchanges generally, with other prominent players such as OKX, KuCoin, and Binance having also ventured into the realm of self-custody wallets, enhancing their service offerings beyond traditional exchange operations.

news
Policy & Regulation·

Sep 20, 2023

CoinEx Reveals Insights Into Recent Platform Hack

CoinEx Reveals Insights Into Recent Platform HackHong Kong crypto exchange CoinEx has issued a further update relative to the security breach that occurred on the platform last week resulting in one of the exchange’s hot wallets being compromised.Photo by FLY:D on UnsplashImmediate responseIn the immediate aftermath of the $70 million hack, CoinEx took action to safeguard user assets and initiate an investigation into the incident. It suspended all deposit and withdrawal services and executed an emergency shutdown of the hot wallet server. Following this, the company securely moved the remaining assets to cold storage, commencing the process of reconstructing and deploying a new wallet architecture.The firm also engaged in an investigation, spearheaded by its wallet and security teams, to ascertain the extent of the breach. Moreover, CoinEx claims to have proactively reached out to fellow exchanges to freeze any assets related to the attack.Haipo Yang, the Founder and CEO of CoinEx, conveyed his apologies to affected users through his personal X (formerly Twitter) account. He emphasized the team’s commitment to restoring services promptly and reassured users that their funds will remain secure.Following up on that commitment, CoinEx published an update on the hot wallet hack on September 15 to address these concerns individually.New wallet deploymentThe exchange expects to finalize wallet upgrades within the upcoming week, after which withdrawals will gradually be phased in, subject to security evaluations. The CoinEx team is currently working on developing and deploying an entirely new and robust wallet system capable of managing activities across 211 chains and 737 assets.The firm has outlined that each of its product lines operates independently, featuring its own risk control system. Consequently, the security incident that occurred on CoinEx will not affect the integrity of its other product lines.In its most recent update on Tuesday, the Hong Kong crypto exchange confirmed that 80% of its wallet system has now been reconstructed. It added that it has initiated preparations to enable the withdrawal system on the platform. It stated:”Details about the resumption of withdrawals, including specific dates, times, and arrangements, will be announced on the CoinEx website. Please stay updated on our announcements for the latest information.”Ongoing investigationRegarding the identity of the attacker, CoinEx has confirmed that the matter is currently under investigation. While some security firms have made attribution claims, the company is focusing primarily on deploying the new wallet architecture, restoring affected users and functionalities, and enhancing overall security.At the same time, the company has initiated communications with the hackers in a bid to proactively seek a mutually agreeable resolution. While the incident implicates the loss of a substantial amount of funds, the firm maintains that in the context of the overall business, the sum represents only a small percentage of total assets under its management.Exchange security remains a major challenge in the crypto sector, with hacks happening on an ongoing basis. Last week, Seychelles-headquartered peer-to-peer crypto platform Remitano acknowledged a $2.7 million hack. At the beginning of September, crypto gambling platform Stake was reported to have suffered a $41 million hack.

news
Loading