Top

Hackers utilize social engineering, move funds through Cambodian platform

Policy & Regulation·July 16, 2024, 11:28 PM

A couple of recent reports have revealed how North Korean hackers have been moving funds to a Cambodian crypto payments platform while further insight has come to light with regard to how these hackers are compromising crypto companies.

 

Huoine Pay

On July 15, Reuters reported that Cambodian currency exchange and payments firm Huione Pay had received in excess of $150,000 in digital currency from a wallet associated with notorious North Korean hacking group Lazarus. Analysis of blockchain data demonstrated that the funds had been received by the Phnom Penh-headquartered payments firm in June 2023 and February 2024. 

https://asset.coinness.com/en/news/5dcc9ca840696cba8765b6b77f39bbf6.webp
Photo by allPhoto Bangkok on Unsplash

‘Pig butchering’

It’s understood that Lazarus stole those digital assets from three crypto firms during the months of June and July of 2023. While Huione has suggested that it was oblivious to the origin of the funds, a blog article by blockchain analytics company Elliptic, published to its website on July 10, suggested that “Huione Guarantee is an online marketplace that has become widely used by scam operators in South East Asia.” 

 

Elliptic went on to assert that some of these scammers employ “pig butchering” techniques, where fraudsters manipulate the victim into investing into fraudulent crypto schemes. It added that “merchants on the platform offer technology, data and money laundering services, and have engaged in transactions totaling at least $11 billion.”

 

The National Bank of Cambodia explained to Reuters that the company is not permitted to trade crypto and that it "would not hesitate to impose any corrective measures" against Huione. The platform is believed to have strong ties to Cambodia’s ruling family. One of the firm’s three directors is understood to be a cousin of the Cambodian Prime Minister, Hun Manet.

 

The Lazarus hacking group is believed to have masterminded a $305 million hack of Japanese cryptocurrency DMM Bitcoin in May of this year. Pseudonymous on-chain investigator ZachXBT claimed on X that $35 million of the proceeds had been laundered through the Huione platform.

 

Compromising crypto businesses

In a related development, a report by DL News published on July 15 has found that North Korean hackers are employing a new tactic in order to compromise crypto businesses. The hackers are scanning the internet for job postings advertised by the companies they’re targeting and submitting bogus applications.

 

A report by the United Nations Security Council has revealed that in excess of 4,000 North Koreans have taken up employment with international technology firms. Part of the social engineering-based tactics employed by the hackers includes contriving to get employees within targeted companies to install malware. 

 

Oftentimes, the resumes and LinkedIn profiles of real people are used in order to find a way in via the recruitment process. A report by DeFiLlama suggests that $664 million has been lost via instances of crypto hacking within the first half of 2024. 

More to Read
View All
Policy & Regulation·

Jul 27, 2023

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRW

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRWIn a significant step towards regulating the cryptocurrency market and ensuring the safety of virtual asset users, South Korea’s Federation of Banks (KFB) has collaborated with financial authorities and virtual asset exchanges to establish the “Guidelines for the Operation of Real Name Accounts for Virtual Assets.” The KFB, as a group of banks and financial institutions, facilitates cooperation between its members and promotes the development of the financial industry.Photo by rc.xyz NFT gallery on UnsplashThe guidelines come as a response to the increasing need for stronger money laundering prevention measures and standardization in the crypto industry. The first step towards this was taken in 2018 when crypto exchanges became obliged to establish a real name account at a bank in order to provide Korean Won (KRW) deposit and withdrawal services to their customers. Currently, the exchanges that won such bank accounts are Upbit, Bithumb, Coinone, Korbit, and Gopax.However, this policy brought with it a set of challenges, including differing practices among various cryptocurrency exchanges, leading to inconveniences for users. Additionally, varying user protection measures, such as reserve requirements, caused confusion in the market.3 billion KRW in reservesTo address these issues, the new guidelines aim to clarify how banks operate cryptocurrency real-name accounts and bolster overall security. One of the key changes is the requirement for crypto exchanges to maintain a reserve of at least 3 billion KRW ($2.36 million). This reserve fund serves as a precautionary measure to address potential financial losses resulting from hacking incidents or system failures at crypto exchanges.Furthermore, the guidelines mandate banks to manage deposit and withdrawal limits by categorizing user accounts into limited and normal accounts. A limited account will not be converted to a normal account, which grants higher deposit and withdrawal limits, until the user’s transaction purpose and the source of funds are verified.Enhanced due diligenceIn addition, banks will perform annual enhanced due diligence (EDD) for individual account holders. This thorough review will encompass users’ identification, transaction purposes, and the origin of funds.User asset segregationTo safeguard users’ funds, crypto exchanges will be required to ensure that customer deposits are held separately or placed in trust. Regular due diligence at crypto exchanges will also be conducted by banks, with mandatory visits occurring at least once a month. Moreover, third-party services will be engaged to perform independent due diligence every quarter on crypto exchanges, providing an additional assessment of their operations.The official launch of these new guidelines is scheduled for January of next year. However, the requirement of depositing at least 3 billion KRW will come into effect earlier, starting in September of this year. Additionally, the implementation of guidelines for expanding deposit and withdrawal limits is anticipated in March of next year.

news
Web3 & Enterprise·

Jan 12, 2024

Korea ST Exchange joined by various firms to bring security tokens to agriculture industry

Korea ST Exchange has committed to conducting a demonstrative experiment involving security tokens to help advance the domestic agriculture and livestock industry along with six other companies, including Korea Venture Agriculture Association, Maeil Business Agtech Innovation Center, MAM TECH, XR Touch, Jangbogo Asset and Crowdy. Representatives from all seven firms participated in an agreement signing ceremony held at the Maekyung Media Center on Thursday, according to local news site Financial News.Photo by Dan Meyers on Unsplash"Smart farms are an industry in South Korea with great potential for growth that is gaining a  competitive edge in the global market," said Cho Won-dong, CEO of Korea ST Trading. "With this agreement, our council plans to strengthen the smart farm security tokens ecosystem to increase the profits of domestic agricultural producers and strengthen global competitiveness." Fostering agricultural innovationThe experiment aims to promote the innovative trading system of smart farms for the development of the agriculture and livestock industry and discover stable underlying assets that will serve as a bridge for integration with innovative finance such as digital assets and security tokens. With this agreement, the parties will cooperate on issuing and distributing tokenized real assets, commodity tokens and security tokens, building infrastructure to support and encourage the trading of security tokens, exchanging information and sharing collaborative networks to build each participating firm’s business. They also plan to issue security tokens in the form of investment contract securities that attribute profits and losses according to the results of joint business ventures by creating a device to tokenize contracts for harvesting agricultural products. Korea ST Trading’s comprehensive roleBased on the platform, Korea ST Trading will provide support for all services such as security token distribution, trading, management, dividends, liquidation and investment information to help expand the smart farm ecosystem and attract private investments.

news
Web3 & Enterprise·

Jun 08, 2024

Bitdeer sets out mining chip roadmap

Singapore-headquartered Bitcoin mining company Bitdeer has outlined a roadmap of chip development which will culminate in the introduction of its most energy efficient mining chip to date, the “SEAL04” chip. According to a press release published by the company on June 6, the company outlined that it wanted to be transparent in demonstrating its plans over the short to medium term in terms of research and development and technological advancement.Photo by Michael Förtsch on UnsplashIterative progressionThe starting point for its roadmap is the SEAL01 chip, which the company introduced in Q1 2024. That mining chip was engineered using a four-nanometer process technology. It was developed in collaboration with a semiconductor fabricator albeit that the company has not disclosed the identity of that fabricator. That chip weighed in at 18.1 Joules/Terahash (J/TH). The SEAL01 represents the company’s first release relative to its SEALMINER technology.  Bitdeer feels that providing guidelines for technology releases will better inform market participants, and that’s important given that uncertainty creates a major difficulty for those operating in the Bitcoin mining space.  With that, Bitdeer is projecting a Q3 2024 release for its SEAL02 miner, which will clock up between 15 and 16.5J/TH. SEAL03 is scheduled for Q4 2024, with an efficiency boost taking it to between 11 and 12J/TH. Finally, the SEAL04 is scheduled for release in Q2 2025. That chip is expected to have an energy efficiency range as low as 5.5-6J/TH. The two most critical factors for Bitcoin miners to stay competitive include the cost of energy and the level of energy efficiency achieved by the mining equipment that is being used. It’s believed that the roadmap will help in managing miners’ expectations relative to technological advancement.  Gearing up for a post-halving mining environmentTo develop the SEALMINER equipment series, Bitdeer outlined last March that it had “assembled an international team of professional engineers specializing in chip design, firmware, and hardware engineering.” At that time, the company suggested that the new range of mining equipment would allow it to assist the Bitcoin mining community “in seizing opportunities following the 2024 halving event.” Alongside its chip development roadmap, the company came to the industry’s attention earlier this week with stablecoin issuer Tether acquiring a 25% stake in the Singaporean mining equipment developer, according to a filing with the U.S. Securities and Exchange Commission (SEC). This acquisition makes Tether the second-largest shareholder in Bitdeer, behind Victory Courage Ltd., which is registered to Bitdeer CEO Jihan Wu. Wu, who co-founded Bitdeer and served as CEO of ASIC manufacturer Bitmain previously, was appointed as CEO of Bitdeer in January. The appointment was made so that Wu could oversee what was expected to be a period of rapid growth at the company. In the June 6 SEC filing, Tether Holdings Limited disclosed control over 23,587,360 BTDR shares. This significant increase in holdings stems from a private placement deal closed with Bitdeer last week, enabling the Bitcoin miner to secure $100 million in financing. The deal also includes a warrant allowing Tether to purchase up to 5,000,000 additional shares at $10.00 each over the course of the next year. Bitdeer plans to use the raised funds to expand its data centers, develop ASIC-based mining rigs and support other general corporate purposes.  

news
Loading