Top

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Web3 & Enterprise·January 25, 2024, 6:11 AM

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).

https://asset.coinness.com/en/news/a9bbc815696c54bad7b2a3dbe873910d.webp
Photo by Franck on Unsplash

Teamwork excellence

This Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said.

 

Securing the future

The team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms.

 

Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability.

 

"We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity."

 

CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

More to Read
View All
Policy & Regulation·

Dec 01, 2023

Paxos scores licensing approval in Abu Dhabi

Paxos scores licensing approval in Abu DhabiPaxos, a New York-based blockchain and tokenization infrastructure platform, has achieved in-principle licensing approvals from the Abu Dhabi Global Market’s (ADGM) Financial Services Regulatory Authority (FSRA).Photo by Kent Tupas on UnsplashEnabling stablecoin issuanceIn a press release published on Wednesday, Paxos outlined that these approvals mark a significant step for the company, enabling it to issue USD and other currency-backed stablecoins while also providing crypto-brokerage and custody services through two regulated ADGM entities.This licensing acquisition comes hot on the heels of a similar outcome in Singapore. Earlier this month, Paxos subsidiary Paxos Digital Singapore Pte. Ltd., received in-principle approval from the Monetary Authority of Singapore (MAS). That approval enables it to offer digital payment token services and issue USD-backed stablecoins within the Southeast Asian city-state.The company, while making efforts to focus on transparency and accountability, aims to extend the global reach of its regulated USD-backed stablecoins upon receiving full approval in Abu Dhabi. Walter Hessert, Paxos’ Head of Strategy, emphasized the importance of regulatory compliance and engagement with authorities to shape digital asset rules, maintaining Anti-Money Laundering (AML) and Know Your Customer (KYC) standards.Hessert stated:”Our IPAs [in-principle approvals] from the FSRA [Financial Services Regulatory Authority], on the heels of our IPA from the Monetary Authority of Singapore, solidify our commitment to pursuing international growth through regulated frameworks. Paxos is unique in the industry for this approach and we will continue expanding our regulatory licensing to serve global enterprises as a trusted, innovative partner.”U.S. regulatory difficultiesIn addition to Singapore and now Abu Dhabi, Paxos already holds approvals from the New York State Department of Financial Services (NYDFS), the local state regulator in New York in the United States. The company’s experience in its home market has been problematic more recently, however.In February, the Securities and Exchange Commission (SEC) issued Paxos with a Wells Notice, a letter that informs the receiver that infractions have been uncovered following investigation. The New York regulator, the NYDFS, also took action against Paxos, claiming that the company didn’t administer BUSD in a safe and sound manner.These actions led to Paxos ceasing to mint any further BUSD stablecoin, and existing BUSD tokens will remain redeemable until at least February next year.Focus on Asia and Middle EastIt’s likely that these regulatory difficulties have led to the company concentrating its effort in 2023 on expanding in overseas markets. Licensing accomplishments in Singapore and Abu Dhabi speak to that.Paxos expressed contentment with MAS as its regulator in Singapore, anticipating that the oversight will accelerate global consumer adoption of digital assets. As the first blockchain service provider to obtain licenses in both New York and Singapore, the company is strengthening its regulatory portfolio globally.This is further evidenced by a recent collaboration the company had formed in the Philippines earlier this month. Paxos has forged an alliance with Coins.ph, a leading cryptocurrency exchange in the Southeast Asian country. The goal of the collaboration is to propel the adoption in the Philippines of PayPal USD (PYUSD), a U.S. dollar stablecoin issued by Paxos.

news
Policy & Regulation·

Nov 24, 2023

Korea unveils detailed plan for retail CBDC transaction pilot with 100K participants

Korea unveils detailed plan for retail CBDC transaction pilot with 100K participantsThe Bank of Korea (BOK), Financial Services Commission (FSC) and Financial Supervisory Service (FSS) jointly announced on Thursday (local time) their comprehensive plan to pilot a central bank digital currency (CBDC). This pilot program will concentrate on two key areas: retail transactions and technical experiments within simulated environments.For the retail transaction aspect, the test aims to give citizens direct experience in using the new digital currency, helping them understand its advantages. This practical approach will promote public familiarity with the CBDC.In terms of technical experiments, these will be conducted in partnership with various banks. The goal is to explore and develop methods for constructing a financial market infrastructure suitable for the future, leveraging the capabilities of the digital currency.Photo by Terrence Low on UnsplashRetail CBDC test to commence in Q4 2024The initiative to examine retail transactions using a CBDC is scheduled to begin in the fourth quarter of 2024. This test will focus on improving how vouchers work. Currently, the use of vouchers faces several challenges, such as high fees, complex and slow settlement procedures and the risk of fraudulent transactions. CBDC-based deposit tokens programmed with the digital voucher functionality could help solve these problems. The exploration of digital vouchers within the realm of CBDCs is not just a concern in Korea but also a topic of global interest.Banks that will participate in the CBDC retail transaction test are to be selected by the end of the third quarter of next year, following necessary procedures such as the financial regulatory sandbox policy. These selected banks will receive the green light to issue deposit tokens within this regulatory sandbox framework. They’ll be in charge of recruiting and managing test participants, which includes both individuals and merchants. Additionally, these banks will be responsible for developing digital wallets for users and handling payment transactions. On the other hand, any bank interested in joining technical experiments in simulated environments may apply to do so until mid-December this year.Citizens who want to take part in the retail transaction test for the CBDC can apply through the banks involved in the test. However, it’s important to note that since this CBDC utilization test is a limited trial, the number of participants will be limited to a maximum of 100,000.The retail transaction test for the CBDC will involve three stages: issuance, distribution and payment. Initially, banks will issue deposit tokens with digital voucher functions upon request. Users will then use these tokens to buy goods from merchants, with the transactions being settled accordingly. Before starting, the BOK, FSC and FSS will propose pilot tasks to the banks, following consultations with relevant agencies and the review of pertinent laws. Banks will also propose tasks related to the voucher function. During the test, these tokens will be used solely for digital voucher transactions, and peer-to-peer transfers won’t be allowed.Simulated environment experiments: three use casesFor technical experiments within simulated environments, the financial authorities have selected three use cases focused on examining the technical feasibility of new types of financial instruments.The first objective is to collaborate with Korea Exchange, the only securities exchange operator in the country, to connect the CBDC system with a carbon credit trading simulation platform. This platform will be based on an external distributed ledger. The key objective here is to assess if the “delivery versus payment” (DvP) mechanism between carbon credits and special payment tokens can function smoothly. DvP is a settlement method that ensures the transfer of securities occurs only after the corresponding payment is made.The second objective will see collaboration with the Korea Financial Telecommunications and Clearings Institute (KFTC). In this scenario, a hypothetical issuer will release tokenized assets to the public through a public offering. To manage this, deposit tokens that match the subscription amount by investors will be temporarily frozen, preventing them from being liquidated. After the final allocation of these tokenized assets is determined, the system, using smart contracts, will automatically transfer funds equivalent only to the allocated tokenized assets.The last objective revolves around advancing the concept of a unified ledger introduced by the Bank for International Settlements (BIS). In this endeavor, the BOK aims to issue digital demo securities within the CBDC system. Following this, an experiment will be conducted where financial institutions will have the opportunity to trade these digital securities using the institutional CBDC. This trading will be executed using the DvP method.

news
Web3 & Enterprise·

Oct 02, 2023

Coinbase Acquires License to Enhance Crypto Operations in Singapore

Coinbase Acquires License to Enhance Crypto Operations in SingaporeUS crypto exchange business Coinbase has reached a significant milestone in its Singapore operations by obtaining a Major Payment Institution (MPI) license from the Monetary Authority of Singapore (MAS).The achievement, announced by the firm via a blog post published on Sunday, represents a pivotal moment for Coinbase as it expands its digital payment token services in Singapore to serve both individuals and institutions. The issuance of the full MPI license comes approximately one year after Coinbase initially received in-principle approval from MAS.Photo by Duy Nguyen on UnsplashEnabling broader service offeringThe importance of this development lies in Coinbase’s ability to provide advanced services, not only to individual traders but also to institutional investors. Hassan Ahmed, the country director of Coinbase Singapore, stressed the significance of this full license, stating that it will play a crucial role in strengthening relationships with stakeholders, especially regulated entities like banks. The regulatory milestone is anticipated to further cement Coinbase’s presence in the institutional finance sector in the region.Coinbase’s commitment to the Singaporean market has been evident in its continuous expansion initiatives. The company established a technology hub in Singapore last year, actively recruiting and training product managers and engineers specializing in Web3 technologies.In May the firm extended its product offering to Singaporean customers, introducing fee-less purchases of the USDC stablecoin and introducing digital asset staking. Meanwhile Coinbase Ventures, the firm’s investment arm, has also demonstrated confidence in the region by investing in more than 15 Web3 startups within Singapore over the past three years.Singapore earmarked for growthSingapore has emerged as the focal point for Coinbase’s Asia-Pacific institutional business, owing to its progressive stance on cryptocurrencies and a robust Web3 ecosystem boasting over 700 Web3 companies. According to Coinbase’s surveys, 25% of Singaporeans perceive cryptocurrencies as the future of finance, and 32% have had some form of crypto asset ownership. These statistics underscore Singapore’s growing importance in the global cryptocurrency landscape.Coinbase’s interest in meeting the demands of the local market is evident with the introduction of funding options like PayNow and the banks’ Fast And Secure Transfers (FAST) service, in addition to the integration of the Singpass onboarding system earlier this year.Despite facing regulatory challenges, including a lawsuit from the US Securities and Exchange Commission (SEC) accusing Coinbase of operating illegally, the exchange continues to explore avenues to grow and expand the business further. In August, Coinbase reported a significant improvement in its financials, with a narrower net loss and higher-than-expected revenue. This performance is reflected in its appreciating stock prices, which have more than doubled in 2023.This move places Coinbase among a select group of just over a dozen firms licensed to offer digital payment token services in Singapore. Last month, institutional investor-focused AsiaNext was officially designated as a Recognized Market Operator (RMO) by MAS. The firm was building on previous success in Singapore, having acquired a Capital Markets Services (CMS) license from MAS in June.That same month USDC stablecoin issuer Circle was awarded a full trading license. Other crypto firms to achieve licensing success in the city-state include Crypto.com and Blockchain.com.

news
Loading