Top

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Web3 & Enterprise·January 25, 2024, 6:11 AM

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).

https://asset.coinness.com/en/news/a9bbc815696c54bad7b2a3dbe873910d.webp
Photo by Franck on Unsplash

Teamwork excellence

This Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said.

 

Securing the future

The team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms.

 

Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability.

 

"We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity."

 

CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

More to Read
View All
Policy & Regulation·

Apr 28, 2023

HK Regulators Facilitate Dialogue between Banks and Crypto Enterprises

HK Regulators Facilitate Dialogue between Banks and Crypto EnterprisesIn a recent column, Arthur Yuen, Deputy CEO at the Hong Kong Monetary Authority (HKMA), stated that the HKMA and the Securities and Futures Commission (SFC) will jointly convene a meeting on Friday to share opinions on providing banking services to virtual asset service providers (VASPs).Proportionate CDD measuresYuen said that banks should “differentiate the risk levels of customers and apply proportionate CDD [customer due diligence] measures,” and “refrain from adopting a ‘one-size-fits-all’ approach to reject account opening applications.” To address misconceptions about CDD, the HKMA issued a circular on Thursday, offering further clarification and sharing notable cases and best practices.The HKMA called on banks to enhance employee training on account opening procedures and create task forces to help companies seize new business opportunities. The HKMA plans to actively take part in developing and introducing international standards, and provide guidance and support for banks to adopt appropriate anti-money laundering measures.SFC’s guidelines in MayMeanwhile, SFC CEO Julia Leung said in a discussion with Bloomberg that the SFC will issue virtual asset guidelines in May.Reactions on TwitterIn his tweet, Justin Sun, the founder of blockchain DAO ecosystem Tron, hinted at the potential development of a Tron-based stablecoin in Hong Kong. The Hong Kong Innovation Encryption Fund (HKIEF), an investor in blockchain projects, also took to Twitter to predict the details of a regulatory framework for cryptocurrencies in the city.According to HKIEF, USDT and USDC will be classified as security tokens, while BTC and ETH won’t be deemed securities. Exchanges trading non-security tokens will need both a VASP license and a trust license. Hong Kong-based virtual asset exchanges will be required to obtain a full license by May 31, 2024.

news
Policy & Regulation·

Sep 04, 2023

Korean Financial Authority Orders Suspension and Levies $1.4M Fine on Crypto Lender Delio

Korean Financial Authority Orders Suspension and Levies $1.4M Fine on Crypto Lender DelioDelio, a cryptocurrency lending company based in South Korea, has received a directive from the financial regulatory authority to cease its operations for a duration of three months, according to local news agency Yonhap. Additionally, the company has been levied with a fine amounting to KRW 1.896 billion ($1.4 million).Photo by Riva Ferdian on UnsplashExecutive dismissal recommendedThis announcement was made on September 1 by the Financial Intelligence Unit (KoFIU) under the South Korean Financial Services Commission. In addition to the measures mentioned above, the KoFIU advised the company to remove one of its executives.As a virtual asset service provider (VASP) registered with the financial regulatory authority, Delio offered deposit services with an annual yield reaching up to 10.7%. However, in June of this year, the company abruptly halted its withdrawal services, prompting investigations conducted by both the KoFIU and public prosecutors.Involvement with unregistered VASPsThe KoFIU saw that Delio had engaged in trading activities with unregistered VASPs and had also breached the restrictions on the trading of affiliate-issued virtual assets. These actions are prohibited under the Financial Transaction Information Act.The financial authority identified a total of 171 instances in which Delio facilitated the transfer of its customers’ virtual assets to unregistered VASPs located outside the country. Additionally, the authority also uncovered the company’s engagement in storing the virtual assets of unregistered VASPs.It was also discovered that Delio had not only neglected to assess the risks of money laundering before introducing new products or services but had also failed to fulfill Know Your Customer (KYC) obligations.

news
Markets·

Mar 17, 2025

North Korea becomes major nation-state holder of Bitcoin following hack

While South Korea’s central bank has opted not to accumulate Bitcoin (BTC) at a nation-state level, North Korea has become a major holder of the leading crypto asset, albeit in a very unconventional way. The Democratic People's Republic of Korea (North Korea) is believed to currently be in possession of 13,518 BTC. That’s according to data compiled by the blockchain analytics firm Arkham Intelligence. Arkham has labeled the holding as belonging to the notorious North Korean hacking organization Lazarus Group. It’s been alleged by many observers over recent years that Lazarus is controlled by the North Korean government. Photo by Vasilis Chatzopoulos on UnsplashOn this basis, it would appear that North Korea now has a larger Bitcoin holding than the Bitcoin-friendly jurisdictions of Bhutan and El Salvador. The Kingdom of Bhutan holds 10,635 BTC through Druk Holdings and Investments (DHI), the commercial arm of the Royal Government of Bhutan.  Meanwhile, El Salvador holds 6,119 BTC. Bhutan has been accumulating Bitcoin as a consequence of Bitcoin mining activity carried out by the government in partnership with Singapore-based Bitcoin mining firm Bitdeer and others within the Asian country over recent years. El Salvador made a commitment to buy Bitcoin on an ongoing basis following its recognition of the digital asset as legal tender back in 2021. Based on Bitcoin pricing at the time of writing, Arkham’s data suggests that North Korea currently holds Bitcoin with an overall value of around $1.14 billion. It’s believed that North Korea’s overall holdings have been bumped up recently following a $1.4 billion hack of global crypto exchange Bybit last month. According to crypto data analysis firm Coin Metrics, the hack stands as one of the largest of all time.  Arkham’s data suggests that North Korea now has the third largest nation-state holding of Bitcoin, with the U.S. in first place, with 198,109 BTC, and the UK next with a holding of 61,245 BTC. Besides Bitcoin, the Lazarus Group is understood to be sitting on ETH, BNB, DAI and BUSD worth in the region of $30 million. In the immediate aftermath of the hack, the hackers moved to swap out some of the stolen Ether (ETH) for Bitcoin via the THORChain decentralized liquidity protocol. South Korea not building Bitcoin reserveWhile North Korea appears to have accumulated Bitcoin at the nation-state level through nefarious means, the Republic of Korea’s (South Korea) central bank has given an indication that it currently has no plans to accumulate Bitcoin.  According to a recent local media report, the Bank of Korea (BOK) responded in writing to a query from a Korean parliamentarian, outlining that there is no plan currently to develop a Bitcoin reserve or to stockpile Bitcoin at a national level.  The BOK is understood to have cited Bitcoin’s price volatility as a major concern. Additionally, the central bank outlined that Bitcoin doesn’t conform to the International Monetary Fund’s (IMF) guidelines relative to foreign exchange reserve management.

news
Loading