Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Web3 & Enterprise·

Feb 22, 2024

Marking its 10th anniversary, Coinone’s cumulative trading volume hits $339B

Coinone, one of the leading cryptocurrency exchanges in South Korea, unveiled an infographic on Monday that captures the company’s decade-long history, according to local newspaper Busan Ilbo. Founded on Feb. 20, 2014, the exchange platform commemorates its 10th anniversary this year. As of Feb. 20 of this year, Coinone’s cumulative trading volume stands at KRW 452 trillion ($339.4 billion) with a total of 213 employees. The business significantly grew in size compared to 2015: its aggregate trading volume has increased by 645,000 times, while its user base and workforce have expanded by 944 and 25 times, respectively. Photo by m_____me on UnsplashVision for the future: Prioritizing investor protection and blockchain innovationCoinone is dedicated to continuing its pursuit of investor protection and blockchain innovation over the next 10 years. Since its establishment, Coinone operated its service without experiencing any security-related accidents. The company has proven its security capacity by winning the top prize at “the 22nd Information Protection Award.” The company further solidified its commitment to security by enrolling in “Personal Information Protection Reimbursement Insurance” in 2017 and has been renewing it annually. From the Wild West to the leading crypto exchange The exchange began to offer an Ethereum trading service in 2016 and a virtual asset staking service in 2018, suggesting a new way of investment back in the days when the market centered around trading.  Cha Myeong-hun, CEO of Coinone, said, “The cryptocurrency market was deemed the Wild West a decade ago. It fills me with pride to see how Coinone navigated the market and witnessed all the ups and downs of the crypto industry until it positioned itself as a well-established industry in Korea. In particular, 2024 marks the inaugural year of the Virtual Asset Act’s implementation. We are committed to leading a healthy virtual asset market by focusing more on investor protection and regulatory compliance.” 

news
Web3 & Enterprise·

Sep 15, 2023

Swing Launches Blockchain-Based Service to Offer Financial Incentives for Scooter Riders

Swing Launches Blockchain-Based Service to Offer Financial Incentives for Scooter RidersSwing, a South Korean personal mobility startup, announced today the launch of “Swing by Boats,” a blockchain-based asset tracking system, in collaboration with blockchain company Block Odyssey. Developed by Block Odyssey, Boats completed a proof-of-concept (PoC) test with a commercial bank to validate the feasibility of the technology.Photo by Sergey Lapunin on UnsplashFinancial incentives for scooter investmentsSubscribers of Boats now have the option to invest in electric scooters operated by Swing. For those who choose to purchase these scooters, Swing offers a financial incentive: an average return rate of 7.5% on the purchase price, paid out over a period of 30 months. In addition, buyers will receive a complimentary one-hour ride on Swing mobility devices. Each scooter available for purchase through Boats is priced at KRW 750,000 (approximately $564). At the end of the 30-month period, Swing commits to buying back the scooter from the purchaser.Simulation program to earn pointsBoats subscribers now have access to a scooter simulation program known as Swing Miles. Within this program, subscribers can assign one of the scooters operating on the Swing platform as their own. They can then monitor various performance metrics such as mileage, routes taken, and payment rates for their designated scooter. Whenever other riders use that specific scooter, the subscriber earns 10% of the payment made by those riders, awarded as Swing Points. These points can be redeemed like cash for services or devices within the Swing app. Before launching Boats, the company conducted a two-month beta test to enhance the service’s quality and accuracy.Jung Sung-ha, an official at Swing, explained that although the newly launched program does offer an average return rate for users, it is primarily aimed at scooter riders rather than professional investors. Jung noted that riders can directly invest in scooters and enjoy the service as if it were a game. According to Jun, the company plans to use the point system as a way to boost customer engagement.

news
Policy & Regulation·

Dec 09, 2023

Kazakhstan shuts out 980 non-compliant crypto exchanges in 2023

Kazakhstan shuts out 980 non-compliant crypto exchanges in 2023Kazakhstan has implemented stringent measures in 2023 when it comes to regulating the crypto sector, resulting in the closure of 980 crypto exchanges that failed to comply with government regulations.That’s according to a press release published by the Central Asian country’s Financial Monitoring Agency (FMA), the state entity responsible for anti-money laundering (AML) policy. These measures, taken over the course of the year, were highlighted during the 39th Plenary Week of the Eurasian Group (EAG) in the resort city of Sanya, in Hainan province in China.Photo by Kuralbek Djumagaziev on UnsplashCombating money laundering threatsThe seminar served as a platform for participating countries to exchange experiences, with an emphasis on leveraging advanced technologies, including artificial intelligence, to effectively combat emerging threats related to money laundering and terrorist financing. The Kazakhstani delegation played a leading role in discussions on virtual assets.Ruslan Ostroumov, the Head of Kazakhstan’s Financial Monitoring Agency, showcased the country’s legislative regulations and robust measures to combat the illegal turnover of digital assets. Ostroumov reported the blocking of 980 illegal cryptocurrency exchange platforms in the current year. Additionally, nine investigations into illegal exchange operations, amounting to $36.7 million, have been initiated, accompanied by ongoing preventive measures.Registration process complexityWhile the seminar’s organizers commended Kazakhstan for its proactive stance against financial crimes in the virtual assets space, the country’s crypto laws have added complexity to the registration process for exchanges.In November, the Kazakhstani authorities blocked local access to the Coinbase website due to potential violations of the country’s digital asset legislation. This decision aligned with the law on digital assets, effective since February 2023, which prohibits the issuance and trading of digital currencies and cryptocurrency exchange businesses without proper licensing.While challenges remain for crypto platforms within Kazakhstan, some have been successful in their efforts. In May, crypto derivatives trading platform Bybit was successful in gaining approval to offer its services within the country. Binance followed suit in June, securing preliminary approval. Other platforms such as CaspianEx, Biteeu, ATAIX, Upbit, Xignal and MT have been granted permission to conduct trade in Kazakhstan.In December 2020, Kazakhstan formally legalized cryptocurrency mining, and on May 6, 2021, the National Bank of Kazakhstan announced plans to issue a “digital tenge,” their version of a central bank digital currency (CBDC). Various CBDC-related projects have followed. In September, the National Payment Corporation, an entity which will be responsible for CBDC development, was launched. The same month, the National Bank of Kazakhstan entered into a collaboration with financial messaging service SWIFT to work on an interoperable CBDC connector.For the most part, these comprehensive regulations and the issuance of a CBDC signify Kazakhstan’s broader acceptance and adaptation to the cryptocurrency landscape. Authorities internationally are trying to find a balance between adequate regulation and enabling innovation to take place. Kazakhstan is no exception, and with that, there are bound to be challenges as regulatory frameworks are optimized and tweaked along the way.

news
Loading