Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Policy & Regulation·

May 17, 2024

Korean FSS Governor meets U.S. SEC Chair Gensler to cooperate on crypto regulations

The governor of South Korea's Financial Supervisory Service (FSS) met with the United States Securities and Exchange Commission (SEC) Chair Gary Gensler, according to Korean media outlet Newsis. The meeting took place during FSS Governor Lee Bok-hyun's business trip to the U.S. The meeting with the SEC chair was pre-arranged earlier this year, as previously reported by crypto media CoinNess.  Governor Lee reportedly had high-ranking meetings with officials from the SEC and Commodity Futures Trading Commission (CFTC) between May 14 and May 16. Photo by Daniel Bernard on UnsplashDuring his meeting with the SEC chair, Governor Lee discussed various financial and cryptocurrency regulatory issues including the recent approval of spot Bitcoin ETFs, and reaffirmed the need for close cooperation between two countries in such oversight efforts. In particular, the two regulators came to an agreement to reinforce cooperation in investigation into unfair trading practices associated with securities and virtual assets. He also met with CFTC Chairman Rostin Behnam to share the recent trends regarding virtual asset legislation in the U.S. and agreed to strengthen information sharing between the two countries. The details of the meeting agendas remain confidential, as mutually agreed upon by the two supervisory organizations.   International financial regulatory cooperation Governor Lee’s latest meetings with U.S. financial regulators followed his attendance at the meeting for the Group of Central Bank Governors and Heads of Supervision (GHOS) held in Basel, Switzerland, on May 13. The GHOS is the oversight body of the Basel Committee on Banking Supervision (BCBS).  During the GHOS meeting, participants reached a consensus on the urgency of swiftly implementing Basel III, a set of bank regulation standards. Two-thirds of member countries are set to partially or completely adopt Basel III by the end of this year.  Furthermore, the member countries agreed to postpone the implementation of the Prudential Treatment of Banks' Exposures to Cryptoassets to Jan.1, 2026, considering the regulatory framework is currently under amendment.  

news
Web3 & Enterprise·

Nov 22, 2023

AndUs to implement ZK rollups on Its public permissionless blockchain

AndUs to implement ZK rollups on Its public permissionless blockchainAndUs, the South Korean developer of public permissionless blockchain Anduschain, announced on Wednesday (local time) that it is preparing to implement zero-knowledge (ZK) rollup technology into its blockchain to enhance scalability and security. ZK rollups are layer-2 scaling solutions that move transactions off-chain to increase throughput on the Ethereum mainnet.Photo by Shubham Dhage on UnsplashPerspective on ZK rollupsMany Korean projects are focused on developing various layer-2 solutions. Against this backdrop, Park Sung-jun, CEO of AndUs and a Ph.D. in cryptography, believes ZK rollups will eventually surpass the currently popular optimistic rollups as the mainstream technology. Although both ZK and optimistic rollups improve scalability by processing transactions off-chain, they differ in their approaches: ZK rollups rely on validity proofs, while optimistic rollups utilize fraud proofs.Introduction next yearHolding this belief, AndUs has formulated a ZK rollup implementation plan and has begun its development, aiming to introduce it by next year. Park commented that this upgrade will significantly improve the blockchain’s speed and expressed plans to offer the world’s lowest gas fees.AndUs claims that their DEB consensus algorithm focuses on fairness, enabling nodes to engage in mining without preconditions. Furthermore, Anduschain’s ZK rollups will be fully compatible with Ethereum virtual machines (EVMs), facilitating a seamless transition of decentralized applications (dApps). The cryptocurrency used on Anduschain is named DEB, and it is currently listed on cryptocurrency exchanges ProBit Global and MEXC, according to CoinMarketCap.AndUs has been participating in the Tech Incubator Program for Startups (TIPS) program, which is led by private investments under the guidance of the Korean Ministry of SMEs and Startups.

news
Policy & Regulation·

Oct 10, 2023

Komainu Secures FCA Approval in Boost For Crypto Custody in the UK

Komainu Secures FCA Approval in Boost For Crypto Custody in the UKKomainu, a digital asset storage firm backed by Tokyo-based global financial services group Nomura, has received approval from the UK’s Financial Conduct Authority (FCA) to operate as a crypto custodian wallet provider.Photo by Robert Tudor on UnsplashPaving the way for broader service offeringThe Jersey-headquartered Nomura portfolio company outlined details of its regulatory success in a blog post published on Friday. This regulatory milestone marks a pivotal moment for Komainu’s expansion within the UK market, allowing the firm to amplify its crypto service offering in the UK.The approval paves the way for the firm to offer collateral management services through its platform, Komainu Connect. Sebastian Widmann, Head of Strategy at Komainu, expressed the company’s intention to furnish institutional custody services, a fundamental aspect of the swiftly advancing cryptocurrency market. He also underscored Komainu Connect’s role as a premier collateral management solution within the UK.Komainu’s CEO, Nicolas Bertrand, spoke to the United Kingdom’s pivotal role in the global financial technology sector. He accentuated the UK’s position as a critical hub for fintech, bridging the realms of traditional finance and decentralized finance. The FCA’s endorsement underscores Komainu’s efforts in attempting to deliver secure and compliant cryptocurrency custody services.“This is a key regulatory milestone as the UK remains one of the most important hubs for financial technology and innovation that will spur the convergence of traditional and decentralized finance,” stated Bertrand.This recent approval is not an isolated achievement for Komainu. The firm has been building up recognition for its adherence to regulatory compliance. In August, it secured a full operating license from Dubai’s Virtual Asset Regulatory Authority, reinforcing its dedication to adhering to global regulatory standards.Additionally, being headquartered in Jersey, Komainu falls under the jurisdiction of the Jersey Financial Services Commission, ensuring that the firm also adheres to those local financial regulations.The company previously unveiled an agreement with local authorities, focusing on secure digital asset storage during investigations. This partnership is demonstrative of efforts made by the firm in fostering transparency and security within the cryptocurrency ecosystem, aligning with the broader regulatory objectives of the UK government.Further ambitionsHowever, Komainu’s presence is expected to reach beyond the shores of the UK and Dubai. Coinshares, one of Komainu’s parent companies, recently introduced its hedge fund division, Coinshares Hedge Fund Solutions, signaling its intent to venture into the US market. This strategic maneuver will provide eligible American investors with access to Coinshares’ array of private investment products, further cementing its global presence in the cryptocurrency sector.In June the firm partnered with Seychelles-based global crypto platform OKX. As part of that deal, the digital assets custodian will store and custody digital assets on behalf of OKX's institutional clients.With a positive track record thus far where regulatory compliance is concerned, Komainu is positioning itself for further growth and innovation relative to a fast-developing crypto sector.

news
Loading