Top

Telcoin makes users whole in exploit recovery

Web3 & Enterprise·January 13, 2024, 10:31 AM

Singapore-regulated Telcoin, a developer of financial applications for mobile users, has successfully restored user balances following an exploit that saw approximately $1.2 million worth of funds transferred from affected accounts.

https://asset.coinness.com/en/news/3c1766686bc03dc8348603085a3f1f51.webp
Photo by Martin Sanchez on Unsplash

Unauthorized withdrawal of assets

The incident, which occurred in late December, was attributed to an error in the interaction between Telcoin's digital wallet and a proxy contract on Polygon. In a blog post which was published on Wednesday, the company shared a full post-mortem analysis report which it commissioned Hong Kong-based blockchain security firm BlockSec to carry out, relative to the exploit.

 

The fault in the proxy contract's implementation caused a technical conflict that allowed for the unauthorized withdrawal of assets. Fortunately, no admin keys were compromised, ensuring that the broader Telcoin ecosystem remained unaffected.

 

In response to the security breach, Telcoin took action by immediately freezing the use of its application as a precautionary measure. The team initiated an investigation and committed to releasing updates promptly to address the issue and restore normalcy. The identified address associated with the exploit was 0x35d2775e5f95596509951b140d68fc5b9185ff98.

 

TEL token freefall

Despite the initial market turbulence, with the price of the Telcoin (TEL) token plummeting, the cryptocurrency has demonstrated resilience. On Dec. 25, TEL fell from a peak price of $0.00235146 to $0.00122535, representing a 48% decrease. At the time of writing, the price has slightly rebounded, trading at $0.001335. Nevertheless, it's still down 40% over the course of the past month's trading.

 

In a social media direct message to CoinDesk recently, Telcoin's founder and CEO, Paul Neuner, expressed pride in how his team responded to the issue, stating:

 

“Making the decision to preemptively restore affected user wallets from our company treasury was a no-brainer, and I’m proud of the team for making that happen in record time.”

 

Regulatory standing

Telcoin's regulatory standing played a crucial role in instilling confidence during this challenging time. Although headquartered in Tokyo, the company is regulated in Singapore as a Major Payment Institution (MPI) by the Monetary Authority of Singapore (MAS).

 

The firm is also registered and regulated in other global markets, including Canada and Australia. Telcoin maintains offices in Singapore, Tokyo, Dubai and Los Angeles. The company had been active in trying to shape regulation in the United States in 2023, with company executives having made repeated visits to Washington D.C. to meet with Financial Services Committee members and staffers on Capitol Hill.

 

In April of last year, the company extended its service offering to the European market, starting out initially in Lithuania.

It appears that the restoration of Telcoin's application services led to a significant boost in user confidence. The company reported a 400% increase in deposits compared to the previous month. Users responded favorably to Telcoin's swift resolution of the security breach, with a ratio of $3.60 being deposited for every $1 withdrawn in the first day since the service restoration.

 

Telcoin's measures, collaboration with security experts and the surge in user deposits appear to have resulted in a resilient recovery. The saga highlights the importance of prompt and transparent responses in maintaining trust in the face of crypto security issues.

 

 

More to Read
View All
Web3 & Enterprise·

Sep 28, 2023

Cartesi Launches Inaugural dApp on Ethereum Mainnet

Cartesi Launches Inaugural dApp on Ethereum MainnetSingapore-based Cartesi, the app-specific roll-up protocol with a virtual machine running Linux distributions, has introduced its inaugural dApp.The decentralized application, aptly named Honeypot, has been designed to serve as a platform for developers and ethical hackers to rigorously scrutinize the security of the Cartesi protocol’s underlying codebase, all in exchange for lucrative bounties.Photo by Michael Förtsch on UnsplashHoneypot deploymentAccording to a press release published on Tuesday, Honeypot is set to fulfill the vital role of stress-testing Cartesi’s foundational code on the Ethereum mainnet. The successful deployment of Honeypot will pave the way for Cartesi’s technology to be employed in a multitude of other dApps. Notably, a unique aspect of Honeypot is the tempting incentive it offers. The first individual to successfully hack it will be entitled to drain the sum of 1.77 million Cartesi tokens, equivalent to $220,000, after one year without any constraints.Embedded within the Honeypot dApp’s backend code is an algorithm that only permits the Cartesi Foundation’s depositor account to make fund withdrawals. Participants who dare to take on this code-breaking challenge must successfully navigate the intricacies of the algorithm to claim the reward.Developer Advocacy contributor to Cartesi, Gabriel Barros, stated: “We want to welcome all developers to test Cartesi’s Rollup infrastructure — but in a gamified challenge.”Aiding dApp developmentCartesi stands as a Layer 2 network specifically designed to streamline the development of intricate and powerful dApps. Its mission is to bridge the gap between conventional development practices and blockchain-based solutions, attempting to offer a seamless transition for developers.At its core, Cartesi introduces a mechanism that enables dApps to execute resource-intensive computations off-chain within a Linux environment. Crucially, these off-chain computations are verifiable by the blockchain, ensuring that the final results remain consistent across all nodes. This approach empowers developers to harness existing software and tools while ensuring compatibility with the blockchain.Linux insideThe choice of a Linux environment is pivotal to Cartesi’s framework. Linux enjoys widespread usage worldwide, particularly in server environments, making it a familiar and well-adopted platform. This familiarity extends to the extensive array of tools and libraries available within the Linux ecosystem, which are leveraged by developers for a myriad of traditional web applications.Gabriel Barros underlined Cartesi’s mission, stating:“Cartesi’s goal is to eliminate the limitations Web3 developers face by enabling them to import decades of familiar programming tools, libraries, and languages to the blockchain. By doing so, Cartesi unlocks a new realm of possibilities, allowing developers to surpass what was previously imaginable with earlier web3 applications.”Cartesi’s introduction of the Honeypot dApp on the Ethereum mainnet signifies a significant step towards ensuring the security and robustness of its protocol. Furthermore, it demonstrates Cartesi’s intentions in attempting to foster a vibrant and innovative ecosystem for developers in the blockchain space.

news
Policy & Regulation·

Feb 21, 2024

Regulatory clarity spurs traditional brokerages’ interest in Hong Kong

In less than a year since Hong Kong regulators gave the green light to crypto exchanges, there's been a noticeable surge of interest among traditional financial institutions and brokerages eager to secure their digital asset licenses for trading.Photo by Florian Wehde on UnsplashTiger BrokersTiger Brokers, a Beijing-headquartered one-stop trading brokerage with nine million international customers, offers one such example. The firm upgraded its Type 1 Hong Kong Securities & Futures Commission (SFC) license in January to include crypto trading for professional investors and financial institutions based in Hong Kong. The move followed an uptick in interest from mainland China-based firms in Q4, 2023.In a recent interview with Cointelegraph, John Fei Zeng, the CFO and director of Tiger Brokers, revealed that the firm currently boasts 865,500 funded accounts in Hong Kong, managing $18.9 billion in assets. Zeng stated: "Residents of Hong Kong will be able to trade virtual assets such as Bitcoin and Ethereum alongside stocks, options, futures, funds, and ETFs [Through Tiger Trade]." He explained that as part of the firm's expansion plans, additional digital assets will be evaluated. HKMA guidance on crypto custodyAs a testament to the regulatory clarity that has attracted firms like Tiger Brokers, on Tuesday Hong Kong's central bank issued guidance for authorized institutions interested in offering custody services for digital assets. The Hong Kong Monetary Authority (HKMA) outlined comprehensive risk assessment procedures and emphasized the importance of robust policies, oversight, and resource allocation to manage custodial activities effectively. Notably, the HKMA's guidance seeks to address concerns stemming from recent industry mishaps, including the collapse of FTX, Terra and Three Arrows Capital (3AC), by mandating stringent safeguards to protect clients' digital assets from theft, fraud or misappropriation. Key requirements include independent systems audits, secure storage practices and transparent record-keeping, underscoring the regulator's commitment to fostering trust and stability in the digital asset ecosystem. Victory SecuritiesIn a similar move to that of Tiger Brokers, Victory Securities, another Hong Kong brokerage, secured a license from the SFC last November to offer crypto trading services for retail investors. The company reported a significant surge in virtual asset transactions and new customer acquisitions, prompting plans to introduce trading discounts to incentivize compliant and safe virtual asset trading services. Moreover, OSL, a licensed Hong Kong crypto exchange, joined forces with Interactive Brokers in November 2023, enabling the latter to offer bitcoin and ether trading to retail investors through its platform. Further underscoring the evolving regulatory landscape, crypto exchange Bybit submitted a retail trading license application in Hong Kong, indicative of the sector's continued growth and maturity. Nevertheless, navigating the regulatory framework isn't without its challenges. Web3 firms eyeing Hong Kong may need to invest up to $25 million in corporate infrastructure and compliance to secure licensing approval, reflecting the stringent requirements imposed by regulators. As Hong Kong continues to refine its regulatory framework and enhance investor protections, the stage is set for further collaboration between traditional financial institutions and emerging crypto players within the Chinese autonomous territory.

news
Web3 & Enterprise·

May 07, 2024

Polaris Office marks 10th anniversary, POLA rises 14%

South Korea-based document management software firm Polaris Office announced the 10th anniversary of its office software (SW) cloud service launch, according to local media News1. Reaching this milestone has coincided with the rising price of its native token, POLA. At the time of writing, POLA is trading at KRW 48.89 ($0.04), up 13.99% from the previous week.  The 10th anniversary of its service launch appears to be a direct cause behind this recent rise in POLA prices, despite the recent downturn in the crypto market. The company said that it recently held an AI (artificial intelligence) talk concert to celebrate its 10-year milestone.Photo by Andrew Neel on UnsplashPOLA as rewards for sharing knowledge Launched in 2020, POLA tokens are distributed as a reward within its platform, Polaris Share Service, which the company describes as "the distributed trading system of incentive knowledge." Here, users can earn POLA by creating content and sharing knowledge on the platform. Cloud-based document management softwarePolaris Office offers a cloud-based service that allows real-time document editing on various operating systems (OS) including mobile, web office, Windows and Mac. Since the outbreak of the COVID-19 pandemic, the company has experienced significant growth in its sales, recording an all-time high annual sales last year. This growth is attributed to the increased adoption of hybrid work environments.  By consolidated standards, Polaris Office recorded KRW 107.9 billion in sales, KRW 6.2 billion in operating profit and KRW 24.4 billion in net profit, marking YoY increase of 346.1%, 277.1% and 91.2%, respectively.  Joining government-led document AI projectMeanwhile, Polaris Office has been designated as a participatory company in the "SW Computing Industry Source Technology Development Project" led by the Ministry of Science and ICT of Korea, as reported by crypto media CoinNess on April 15. In this project, Polaris Office is expected to contribute to advancing the document AI technology. 

news
Loading