Top

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Web3 & Enterprise·January 25, 2024, 6:11 AM

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).

https://asset.coinness.com/en/news/a9bbc815696c54bad7b2a3dbe873910d.webp
Photo by Franck on Unsplash

Teamwork excellence

This Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said.

 

Securing the future

The team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms.

 

Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability.

 

"We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity."

 

CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

More to Read
View All
Policy & Regulation·

Dec 06, 2023

Taiwan to review crypto ETFs amid developments overseas

Taiwan to review crypto ETFs amid developments overseasThe Financial Supervisory Commission (FSC) in Taiwan has disclosed its close examination of foreign cryptocurrency futures products and exchange-traded funds (ETFs), signaling a potential shift in its regulatory approach.According to a report in Chinese-language financial newspaper, Taiwan’s Commercial Times, the FSC aims to gradually ease restrictions, aligning its stance with global market conditions.Photo by bordercollie 1712 on UnsplashResponding to crypto ETF activity internationallyThe Taiwanese regulator is carrying out this exploration against the backdrop of significant global developments. The possibility of the Federal Reserve cutting interest rates and the upcoming review by the U.S. Securities and Exchange Commission (SEC) of the spot bitcoin ETF in January next year are key factors influencing the FSC’s considerations.The anticipation surrounding the Bitcoin halving in April, combined with speculation that a spot bitcoin ETF approval is imminent in the U.S., have contributed to a 145% surge this year in Bitcoin’s unit price, adding momentum to that regulatory contemplation in Taiwan. There has been speculation that BlackRock, the world’s largest fund manager, is already preparing for the approval of its iShares Bitcoin Trust ETF.Recognizing the potential impact of a Bitcoin index stock fund, contingent on SEC approval and subsequent public investment permission, the FSC is closely monitoring global trends.Closer to home, it emerged last month that Hong Kong’s Securities and Futures Commission (SFC) is actively exploring the possibility of permitting retail participation in a spot crypto ETF. Domestic investment banks in Taiwan, attuned to these developments, have expressed longstanding interest in introducing similar crypto products.The FSC draws parallels with global counterparts, citing the proliferation of cryptocurrency futures products and ETFs in various markets.Cautious regulatory reviewAdopting a phased approach, the FSC emphasizes self-discipline and standards in relaxing regulations around crypto ETFs. This cautious strategy aligns with Taiwan’s historical prudence, previously observed in the delayed approval of cryptocurrency ETFs and blockchain ETFs due to concerns over volatility and speculative nature.As Taiwan contemplates a significant move into the cryptocurrency ETF domain, industry players remain cautiously optimistic. While some had considered private placements for overseas cryptocurrency ETFs, challenges such as tightened regulatory supervision and concerns over errors and price lags prompted a reevaluation.Earlier this month, ETF issuer ProShares launched its short Ether-linked ETF product on the New York Stock Exchange’s Arca, using the ticker symbol SETH. Spot bitcoin ETFs have been launched in Canada, Germany, Australia and Brazil. The products have also been made available via tax havens such as the Cayman Islands, Jersey, Liechtenstein and Guernsey.The regulator in Taiwan hints at a potential strategy involving “cryptocurrency concept ETFs.” These funds could invest in cryptocurrency-related software and hardware vendors, offering investors exposure to the industry without direct linkage to cryptocurrency price fluctuations.

news
Policy & Regulation·

Dec 19, 2023

Kazakhstan sets sights on 2024 expansion amid CBDC pilot success

Kazakhstan sets sights on 2024 expansion amid CBDC pilot successKazakhstan’s central bank digital currency (CBDC), the digital tenge, has completed a one-month pilot project, paving the way for significant advancements in business, regulation and technology in 2024.Photo by Nessi Gileva on UnsplashReal-world use through Onay cardThe National Bank of Kazakhstan (NBK) established the National Payment Corporation (NPK) in September. NPK is a dedicated entity that’s responsible for spearheading the launch and development of the digital tenge.At that time, the CBDC pilot phase had advanced to controlled environment use. Global exchange Binance has been actively involved with the project. It supported the pilot by way of its BNB Chain.During the pilot phase, the digital tenge played a pivotal role in providing free school lunches to children in Almaty, Kazakhstan’s largest city. The initiative utilized the local Onay card, initially designed for the transit system and transactions were facilitated by Kazpost, the Kazakh postal system operator.Local banking partnersNPC Chairman Binur Zhalenov became the first person to transact using the digital tenge in November. At the time, it was revealed that Eurasian Bank was one of the local banking participants on the project.Eurasian collaborated with Visa and Mastercard, alongside three other local banks, distributing plastic cards to focus group members. These cards empowered users to make both in-person and online purchases, with the added functionality of cash withdrawals from ATMs.Participating merchants were given the flexibility to accept digital tenge directly or convert them into “non-cash” tenge. The converted funds seamlessly integrated into existing point-of-sale (POS) and QR systems, demonstrating interoperability within and outside Kazakhstan.The success extended beyond local transactions, with further experiments involving cross-border payments via SWIFT, issuance of CBDC-backed stablecoins on platforms like Binance and the Kazakhstan Stock Exchange, tokenization of gold, value-added tax collection through smart contracts and the trial of a “move-to-earn” app.New objectivesWith an eye on the upcoming year, the National Bank of Kazakhstan and the National Payment Corporation (NPC) have set ambitious objectives. Plans include expanding the network of intermediary banks and advancing decentralized finance applications. A primary focus is on enabling offline transactions on a large scale to enhance financial inclusion in regions with limited internet connectivity.Anticipated developments also include increased participation in cross-border payment projects, such as Project mBridge, an experimental multi-CBDC platform being coordinated and developed by the central bank of central banks, the Bank for International Settlements. Regulatory and legislative goals are on the agenda, alongside efforts to enhance the security and processing speed of the digital tenge.While addressing privacy concerns, Zhalenov emphasized in interviews that the digital tenge will not be utilized for user surveillance. Previously, Zhalenov has also alluded to the versatility of the digital tenge due to its programmable nature, citing smart contracts in particular as having great potential.The successful pilot project and the ambitious plans for 2024 position Kazakhstan’s digital tenge as a promising development in the realm of CBDCs, showcasing the central Asian nation’s positive approach to innovation and financial inclusivity.

news
Policy & Regulation·

Jul 27, 2023

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRW

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRWIn a significant step towards regulating the cryptocurrency market and ensuring the safety of virtual asset users, South Korea’s Federation of Banks (KFB) has collaborated with financial authorities and virtual asset exchanges to establish the “Guidelines for the Operation of Real Name Accounts for Virtual Assets.” The KFB, as a group of banks and financial institutions, facilitates cooperation between its members and promotes the development of the financial industry.Photo by rc.xyz NFT gallery on UnsplashThe guidelines come as a response to the increasing need for stronger money laundering prevention measures and standardization in the crypto industry. The first step towards this was taken in 2018 when crypto exchanges became obliged to establish a real name account at a bank in order to provide Korean Won (KRW) deposit and withdrawal services to their customers. Currently, the exchanges that won such bank accounts are Upbit, Bithumb, Coinone, Korbit, and Gopax.However, this policy brought with it a set of challenges, including differing practices among various cryptocurrency exchanges, leading to inconveniences for users. Additionally, varying user protection measures, such as reserve requirements, caused confusion in the market.3 billion KRW in reservesTo address these issues, the new guidelines aim to clarify how banks operate cryptocurrency real-name accounts and bolster overall security. One of the key changes is the requirement for crypto exchanges to maintain a reserve of at least 3 billion KRW ($2.36 million). This reserve fund serves as a precautionary measure to address potential financial losses resulting from hacking incidents or system failures at crypto exchanges.Furthermore, the guidelines mandate banks to manage deposit and withdrawal limits by categorizing user accounts into limited and normal accounts. A limited account will not be converted to a normal account, which grants higher deposit and withdrawal limits, until the user’s transaction purpose and the source of funds are verified.Enhanced due diligenceIn addition, banks will perform annual enhanced due diligence (EDD) for individual account holders. This thorough review will encompass users’ identification, transaction purposes, and the origin of funds.User asset segregationTo safeguard users’ funds, crypto exchanges will be required to ensure that customer deposits are held separately or placed in trust. Regular due diligence at crypto exchanges will also be conducted by banks, with mandatory visits occurring at least once a month. Moreover, third-party services will be engaged to perform independent due diligence every quarter on crypto exchanges, providing an additional assessment of their operations.The official launch of these new guidelines is scheduled for January of next year. However, the requirement of depositing at least 3 billion KRW will come into effect earlier, starting in September of this year. Additionally, the implementation of guidelines for expanding deposit and withdrawal limits is anticipated in March of next year.

news
Loading