Top

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Web3 & Enterprise·January 25, 2024, 6:11 AM

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).

https://asset.coinness.com/en/news/a9bbc815696c54bad7b2a3dbe873910d.webp
Photo by Franck on Unsplash

Teamwork excellence

This Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said.

 

Securing the future

The team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms.

 

Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability.

 

"We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity."

 

CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

More to Read
View All
Web3 & Enterprise·

Sep 03, 2025

Japanese auto-parts maker Ikuyo invests in crypto firm for stablecoin settlements

Japanese auto-parts manufacturer Ikuyo announced last week its board has approved a 300 million yen ($2 million) investment in Galactic Holdings, the parent company of the TruBit cryptocurrency exchange. The investment expands a capital and business alliance first established on June 26.Photo by CHUTTERSNAP on UnsplashStablecoin for B2B cross-border paymentsIn a press release, the Kanagawa-based company stated the funding will be executed through a third-party allotment of new shares. The capital will support Galactic’s stablecoin infrastructure for B2B cross-border payments and help Ikuyo build expertise in digital financial services, diversify its assets, and enhance its long-term corporate value. The initiative arrives as Japan’s auto-parts sector, which counts more than 600,000 workers at roughly 20,000 firms, seeks new efficiencies amid global economic pressures. Autos represented 28.3% of Japan’s exports to the U.S. in 2024, making U.S. trade policy a key influence. This year, the sector navigated a 25% U.S. tariff on automobiles and parts imposed in April, which was then lowered to 15% on July 22 after a deal with the Trump administration. Shifts in the global trade landscape provide an incentive for companies to streamline operational costs. As a proof of concept, Ikuyo plans to pilot stablecoin settlements in transactions between its China-based subsidiary, Kunshan Veritas Automotive Systems, and Veritas in Mexico. Currently, these trades are settled in Mexican pesos and converted to U.S. dollars. The company expects the use of stablecoins to reduce remittance costs and accelerate settlement times.  While the launch timing, performance metrics, and monetization strategy are still being finalized, the pilot’s results will guide future business development. In the long term, Ikuyo aims to become an early adopter of stablecoin settlement in the auto-parts sector, applying the technology to improve efficiency and transparency in international trade, initially between Japan and Latin America and between Japan and Southeast Asia. Japan embraces Web3 in push for growthThis corporate move aligns with a broader trend of growing government support for decentralized technologies in Japan. Speaking at the WebX2025 event on Aug. 25, Prime Minister Shigeru Ishiba announced stronger state support for Web3 initiatives, describing the sector as a driver of innovation that could help Japan tackle demographic decline and foster economic transformation.  He noted that Web3 is already being implemented at the Osaka Expo and highlighted local pilot programs where communities use tokens as governance rewards. Ishiba also stressed that the government’s five-year startup growth plan would be strengthened through investment and regulatory reforms, with Web3 and related digital industries expected to take center stage. On the financial policy front, Finance Minister Katsunobu Kato recently addressed the rapid increase in crypto adoption across Japan. He explained that his role is to balance necessary oversight with providing the industry enough freedom to innovate. While acknowledging that digital assets remain highly volatile, Kato argued that creating a secure trading environment would protect investors while also helping to diversify and enrich their portfolios. Ikuyo’s initiative underscores the private sector’s quickening embrace of crypto. Last month, SBI Group, one of the nation’s largest financial conglomerates, revealed a strategic alliance with the decentralized oracle provider Chainlink. Their collaboration aims to expand the institutional adoption of digital assets and blockchain globally. The partnership will utilize Chainlink’s Proof of Reserve, SmartData, and Cross-Chain Interoperability Protocol (CCIP) to facilitate the tokenization of real-world assets (RWAs) across multiple blockchains.

news
Policy & Regulation·

Dec 11, 2023

South Korean FSC updates definition of virtual assets and VASP regulations for Virtual Asset User…

South Korean FSC updates definition of virtual assets and VASP regulations for Virtual Asset User Protection ActThe South Korean Financial Services Commission (FSC) on Monday (local time) published a new enforcement decree and supervisory regulations for the Virtual Asset User Protection Act, under which non-fungible tokens (NFTs) and deposit tokens are excluded from the definition of virtual assets. The act serves to protect customer assets, prevent unfair trading practices, and enforce penalties.“The enforcement decree and supervisory regulations provide detailed standards and methods to safeguard users’ assets and establish stability in the market,” the FSC said.Photo by Tingey Injury Law Firm on UnsplashDefining virtual assetsThe agency explained that it decided to exclude NFTs because they are mainly bought and sold for collection purposes, posing low risks to holders and the financial system. However, NFTs that can be used as a means of payment for purchasing certain goods and services are considered virtual assets. On the other hand, deposit tokens — which will be managed by the Bank of Korea’s central bank digital currency network — are regarded as a legitimate form of monetary deposit and are subject to relevant regulations instead of the User Protection Act. Other “electronic certificates of economic value,” such as mobile vouchers and electronic bonds, are also excluded from the definition of virtual assets.Enhancing security and transparencyFollowing the clarified definition of virtual assets, the updated regulations underline conduct measures that virtual asset service providers (VASPs) must comply with. For example, VASPs must calculate the total value of their customers’ crypto assets every month and store at least 80% in a cold wallet to prevent infringements like hacks — a boost from the current 70 percent. Cold wallets are deemed more secure than hot wallets because they keep crypto keys offline instead of staying connected to the internet.VASPs are also not allowed to arbitrarily block deposits and withdrawals of user assets without prior notice and a justifiable reason like internal system failure or hacks as well as requests from courts, investigative bodies, the National Tax Service and financial authorities. User deposits must be stored in banks, which can invest them only in safe assets such as government bonds.The act is set to take effect on July 19 next year after a legislative review scheduled for next month.

news
Web3 & Enterprise·

Oct 13, 2023

Korean Blockchain Firm Ozys Achieves ISMS Certification for Data Security

Korean Blockchain Firm Ozys Achieves ISMS Certification for Data SecuritySouth Korean blockchain technology firm Ozys has recently demonstrated its advanced security capabilities by securing a data security certificate from a quasi-governmental agency responsible for overseeing the nation’s internet services.Photo by Shubham Dhage on UnsplashCertificate from Korea Internet and Security AgencyOzys made an announcement on Friday (local time) that it has earned a certificate of Information Security Management System (ISMS) from the Korea Internet and Security Agency (KISA). The ISMS certification requires companies to meet 80 distinct criteria. Through these criteria, companies must demonstrate their approach to setting up and maintaining data security systems, as well as their plans for handling possible security incidents.Specializing in Web3 services, the blockchain developer offers a wide range of solutions related to decentralized finance (DeFi), cross-chain projects, and blockchain explorers.Smart contract developmentOzys has secured an ISMS certification specifically for blockchain-based smart contract development and service operations. Ozys is the first company in the country to attain this distinction in the realm of smart contract development.On this achievement, Choi Jin-han, CEO of Ozys, said that undergoing the ISMS certification process allowed the company to reassess its overarching security policies, bolstering its protective measures and response strategies for information assets. Choi further emphasized Ozys’ dedication to creating not just functional and user-friendly services, but also to pursuing various research initiatives focused on safeguarding customers.

news
Loading