Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Policy & Regulation·

Dec 05, 2023

28 crypto service providers register with India’s FIU

28 crypto service providers register with India’s FIUIn India, 28 entities providing services related to virtual digital assets (VDAs) have successfully registered with the Financial Intelligence Unit (FIU), the body responsible for combating money laundering in the world’s most populous country.Notable names in this list include Neblio Technologies, more commonly known as CoinDCX, Zanmai Labs, the company responsible for the WazirX crypto platform, Bitcipher Labs’ CoinSwitch, Nextgendev Solutions and Awlencan Innovations India’s Zebpay.Photo by Big G Media on UnsplashA need to register as ‘reporting entities’This information comes in response to a question posed in the Lok Sabha (India’s lower house of Parliament), where the government emphasized the significance of these entities complying with the Prevention of Money Laundering Act (PMLA). In March, the government had formally designated companies dealing in VDAs, crypto exchanges and related intermediaries as “reporting entities” under the PMLA.According to the notification, crypto exchanges and their intermediaries are obligated to conduct Know Your Customer (KYC) procedures for their clients and platform users. This includes maintaining KYC details, identity documents, account files and business correspondence records with clients.Offshore exchanges required to registerMinister of State for Finance Pankaj Chaudhary mentioned that the registration process for VDA service providers catering to the Indian market is underway. Non-compliance with these regulations may result in appropriate action under the PMLA. It has been clarified that offshore crypto exchanges operating in India are required to adhere to these guidelines. Despite that, none of the 28 entities who have registered so far appear to be offshore companies.Commenting on the development via the X social media platform, Sumit Gupta, Co-Founder of CoinDCX, wrote:”Emphasizing compliance to PMLA is vital for the safety and financial integrity of Indians, as dealing with non-registered platforms exposes citizens to nefarious actors, putting their finances at risk.” . . . “It’s encouraging to witness the Government initiating actions against non-compliant offshore entities.”While steps to provide guidelines for the industry are largely positive, the Reserve Bank of India (RBI) has been vocal in its criticism of cryptocurrencies and calls for potential bans have cast a shadow over the industry in India. The recent collapse of prominent platforms like FTX have not been helpful, only serving to exacerbate concerns relative to India’s crypto ecosystem.The negative sentiment, coupled with an ongoing funding winter, has resulted in the closure of operations for some crypto platforms, including Pillow and WeTrade, this year. Firms like CoinSwitch and Gupta’s CoinDCX have had to reduce headcount in 2023 amid challenging market conditions.Despite these challenges, there are also positive signs. A recent report by blockchain analytics firm Chainalysis found that India has been the frontrunner more recently in terms of crypto adoption in Asia.This latest development provides guidelines where anti-money laundering processes are concerned for crypto firms in India. However, the government needs to follow through with a complete regulatory framework for the industry. The Indian courts recently declined to act on such a petition on the basis that it falls within the remit of the country’s legislature and is outside the purview of the courts.

news
Policy & Regulation·

May 03, 2023

Incheon City to Host Blockchain Conference Showcasing its Vision

Incheon City to Host Blockchain Conference Showcasing its VisionIncheon City will host a blockchain conference, Incheon Metanomics 2023, to showcase its vision at the Songdo Convensia Convention Center on May 9.The event will present the city’s goal of building a blockchain ecosystem and fostering digital economy growth. About 150 blockchain experts from around the world are expected to attend, according to Block Media.Insightful talksProminent industry figures, including Leon Sing Foong, the head of Asia-Pacific operations at cryptocurrency exchange Binance; Steve Park, Asia-Pacific head of public policy at online game platform Roblox; and Justin Kim, a solutions architect at semiconductor company AMD, will speak at the event. Foong will talk about the collaboration between crypto exchanges and governments, Park will provide insights into the future of the metaverse, and Kim will address upcoming trends in decentralized storage systems.Registration for the conference is free and open until May 4 through Event Us, with a live stream of the event available on YouTube.Incheon and DubaiIncheon has been working towards establishing a special digital economy zone within the city by utilizing blockchain technology. In March, Incheon Mayor Yoo Jeong-bok met with Ahmed Bin Sulayem, the executive chairman of the UAE’s Dubai Multi Commodities Centre (DMCC), to discuss cooperation in the blockchain industry and digital economy.The DMCC, a free trade zone in Dubai, hosts over 65,000 workers from more than 21,000 companies across 180 countries. Notably, the DMCC crypto center is home to a community of over 500 crypto firms, fostering the Web3 and blockchain economy.Similarly, Incheon operates a free trade zone that connects 147 cities with populations exceeding 1 million within a three-hour flight radius. The Incheon Free Economic Zone is appealing to global blockchain companies as it offers flexible business operations for foreign entrepreneurs.© Pexels/joon young, Park

news
Web3 & Enterprise·

May 10, 2023

OmniBOLT to Support BRC-20 Tokens on Lightning

OmniBOLT to Support BRC-20 Tokens on LightningSingapore’s OmniBOLT, a project that’s developing technological solutions within bitcoin’s layer two network environment, has outlined that it will support BRC-20 tokens on Lightning Network.Before we consider precisely what OnmiBOLT's decision to support BRC-20 tokens means, let’s cover the backstory.Photo by Sander Weeteling on UnsplashBRC-20BRC-20 is an experimental token standard which was created by an anonymous developer with the handle “Domo”, and username ‘@domodata’ on Twitter. A token standard governs how and where a cryptocurrency can be used. The approach has been pioneered by developers on the Ethereum blockchain who created the ERC-20 standard a number of years ago, relative to the Ethereum network.A bitcoin evolutionIn this instance, BRC-20 is a fungible token standard designed for the bitcoin blockchain. Bitcoin development is very slow and conservative, and deliberately so, in an effort to put network security first. However, it has had two major upgrades over the course of the last few years, namely SegWit and Taproot.Many in crypto have been critical of the bitcoin project on the basis of it being a pet rock that lacked features and the flexibility to use it in other ways aside from as a store of value or means of exchange. However, those protocol upgrades have led to further development that is expanding bitcoin’s use case and versatility.SegWit and Taproot enabled the development of Bitcoin Ordinals in January 2023. Ordinals provide a means to create Bitcoin non-fungible tokens (NFTs), by attaching data to individual satoshis, the smallest denomination of Bitcoin. NFTs created this way are immutable as they’re not created on side chains but on the bitcoin blockchain itself.In a fast moving scenario, the development of Ordinals led two months later to the emergence of the BRC-20 standard. BRC-20 tokens can be stored on the bitcoin base-chain, built with the assistance of Ordinals. BRC-20 is an exciting development as it stands to enable smart contract capabilities relative to bitcoin.Solving the bitcoin fee issueMany see this development as a solution for the longer term fees issue that the bitcoin blockchain will have to overcome. Bitcoin miners are compensated in mining rewards but the level of rewards is being cut in half every four years. The concern is that in the longer term, there may not be enough revenue for miners to continue to secure the network effectively.With the development of Bitcoin Ordinals, more fees are generated, and so this is seen as a means through which the network can sustain itself over the longer term.Mempool backlogSo what’s not to like? The issue that has arisen over the past few days is that bitcoin transaction fees have hit a two year high. Over the past few days, there have been in excess of 400,000 unconfirmed bitcoin network transactions sitting in the mempool. The mempool is a mechanism within the bitcoin protocol that stores the data relative to a queue of transactions that are waiting to be confirmed.Relieving pressure on bitcoinThat brings us back to the significance of the Singaporean team of developers at OmniBOLT deciding to support BRC-20 tokens on the lightning network. That move can relieve the pressure on the bitcoin mainnet. The project is being backed by Waterdrip Capital, Danhua Capital, Redline DAO and others.Bitcoin has been a boring protocol and many have celebrated that fact as a feature and benefit for a network that serves a couple of vitally important use cases exceptionally well. However, development never stops and it’s fascinating to see another side to the protocol unfold, and all the while, it’s not entirely clear where it will end.

news
Loading