Top

Hong Kong’s SFC flags suspect platforms disguised as HashKey

Policy & Regulation·February 05, 2025, 8:10 AM

The Securities and Futures Commission (SFC), an independent statutory body that regulates Hong Kong’s securities and futures markets, has alerted investors to 33 suspicious websites which appear to be masquerading as HashKey, one of the Chinese autonomous territory’s first licensed virtual asset exchanges.

https://asset.coinness.com/en/news/0a0810f4b692c037f402c1b90d1045fb.webp
Photo by Dan Freeman on Unsplash

Alert list

The regulator flagged the websites by publishing their domain names to its alert list. Hong Kong’s SFC first published its alert list relative to suspicious crypto-related entities in November 2021. In terms of both suspicious trading platforms and suspicious crypto-related web links, the regulator has found 91 instances to date. Remarks added to the listing confirm that a HashKey company, Hash Blockchain Limited, had reported the websites to the regulator as fraudulent websites.

 

The web domain links have been slightly modified when compared to official links to the HashKey website, in an effort to mislead HashKey customers. A little less than two weeks ago, HashKey published a statement to its website, making service users aware of the fraudulent links and websites. It stated:

 

“Fraudulent websites will appear under different domain names or with slight modifications or variations of the official HashKey Exchange website address www.hashkey.com by adding a combination of letters, numbers or symbols.”

 

The company added that it has no connection with these websites, that no affiliation exists with HashKey Exchange, and consequently the company doesn’t accept any liability for any matters relating to these fraudulent websites and links.

 

As well as the regulator, HashKey has also reported the matter to the Hong Kong Police Force.

 

Tackling crypto-related fraud

Both law enforcement and regulators in Hong Kong have been more proactive in tackling any signs of crypto-related fraud or potential scams following an episode of fraud involving an unlicensed Dubai-headquartered crypto exchange, JPEX, in 2023.

 

At that time, the authorities within the Chinese autonomous territory received in excess of 2,369 complaints from Hong Kong residents who had been duped by the unregulated exchange. Overall, victims were out of pocket to the tune of $166 million.

 

Some commentators had likened the JPEX scandal as being an “FTX moment” for Hong Kong, referring to the high profile collapse of Bahamas-headquartered crypto exchange FTX in November 2022. However, Hong Kong investors also suffered as a result of the FTX collapse. 

 

In fact, the Hong Kong Monetary Authority (HKMA) and the SFC were listed as FTX creditors in 2023. The statutory bodies appeared on the FTX creditor list alongside 50 Hong Kong institutions.

 

Towards the end of 2023, the agency issued a public warning regarding HongKongDAO and BitCuped, entities that were accused of misinformation.

 

In February 2024, the SFC issued a reminder to investors within the Chinese autonomous territory to ensure that they’re only engaging with licensed cryptocurrency platforms. To date, the regulator has awarded crypto trading licenses to seven virtual asset trading platforms (VATPs).

 

Earlier this month, the regulator extended use of its swift licensing process to all new applicants in an effort to fast-track the approval of more licensed platforms.

More to Read
View All
Web3 & Enterprise·

Jan 19, 2024

FactBlock sworn in as newest member of WEMIX’s 40 WONDERS

FactBlock, a Seoul-based Web3 ecosystem builder and consulting firm, has become the newest member of the WEMIX3.0 blockchain’s 40 WONDERS, or Node Council Partners (NCP), according to an official announcement on Friday (KST). Photo by Growtika on UnsplashShaping the WEMIX3.0 ecosystemThe 40 WONDERS make up a governance council that represents the interests of the WEMIX community by participating in on-chain voting processes for improving or changing WEMIX3.0’s protocol. They are also responsible for validating transactions and operating nodes on the mainnet to boost and maintain its integrity and security. In particular, each member gets to choose their own WONDER number – FactBlock has joined as WONDER 13, shortly after blockchain security audit firm Verichains joined as WONDER 12. FactBlock was able to join by tapping into its resources from secured investments and committing to expanding the ever-growing WEMIX ecosystem and promoting community activity. FactBlock’s industry-oriented missionThe firm is dedicated to ameliorating information asymmetry within the Web3 industry, serving as a gateway for overseas blockchain projects looking to enter the South Korean market and local firms preparing to go international. The firm’s upcoming projects for this year include the launch of Fablo, an educational platform for collective blockchain learning centered around community engagement.  FactBlock has also hosted Korea Blockchain Week (KBW), the largest blockchain conference in the country and in Asia, since 2018. Last year’s event was held at the Shilla Hotel in Seoul in September, hosting a number of industry experts who discussed trends and outlooks for the Web3 industry.

news
Web3 & Enterprise·

Jun 07, 2023

Atomic Wallet Hacker Uses Lazarus Crypto Mixer

Atomic Wallet Hacker Uses Lazarus Crypto MixerThe stolen cryptocurrency from the recent $35 million hack of Atomic Wallet is already being moved to a crypto mixer favored by North Korea’s notorious cyber-hacking group.Photo by Micha Brändli on UnsplashSinbad.ioAccording to UK-based crypto compliance analysis firm Elliptic, the funds have made their way to a crypto mixer used by Lazarus Group, a notorious hacker group that focuses on crypto heists which is believed to have direct ties with the North Korean government.On June 5, Elliptic’s Investigations Team revealed that it had traced the funds from the Atomic Wallet hack to the crypto mixer Sinbad.io. Lazarus had previously used the mixer to launder over $100 million in stolen crypto assets.While the exact amount sent to the mixer was not specified, Elliptic noted that the stolen funds were being exchanged for Bitcoin before undergoing obfuscation through the mixer. Additionally, Elliptic reported that Sinbad.io is likely a rebranded version of Blender.io, another mixer extensively used to launder funds by the Lazarus Group. Blender.io has been sanctioned by the US Treasury.Atomic Wallet hackThe hack of several user accounts on Atomic Wallet occurred on June 3, resulting in losses of up to $35 million. News of the issue broke with the following tweet from the project team (which has subsequently been deleted): “We have received reports of wallets being compromised. We are doing all we can to investigate and analyze the situation. As we have more information, we will share it accordingly.”In a follow-up tweet the next day, the team confirmed that it was investigating the matter with the assistance of a number of “leading security companies.”However, Atomic Wallet later downplayed the incident, stating that less than 1% of its monthly active users were affected. The project team was castigated by users for trying to present the hack as a minor incident. One user took to Twitter to call out the Atomic Wallet team for “having the nerve to come to the networks and say that only 1% of wallets were affected.”The Atomic Wallet project is based out of Tallinn, Estonia, having been founded in 2017. It claims to provide a non-custodial decentralized multi-currency crypto wallet. The product supports over fifty coins and two hundred tokens. It also offers atomic swaps between digital assets, while also supporting integrations with instant exchanges such as Changelly, ShapeShift, and others.Roland Säde, the Chief Marketing Officer of Atomic Wallet, assured users that the team is working tirelessly to recover the stolen funds. He emphasized the need to complete the investigation to develop a concrete plan.Despite the ongoing efforts, Säde urged victims to track the illicit transfers and report them to popular crypto exchanges. By doing so, it was thought that may hinder the scammers from exchanging the funds.Crypto hacking menaceLazarus Group hackers have been the bane of the crypto space in recent years. Elliptic released a report last month that identified Japan as having been the country most adversely affected by the North Korean hackers. It’s understood that the estimated $721 million in stolen crypto from Japan-based entities amounts to nearly nine times the value of North Korea’s exports based on 2021 data.While Atomic Wallet is directly reporting the incidents, Säde believes that having more individuals monitoring the hackers’ activities will make it more challenging for them to move the funds undetected. Unfortunately, Elliptic’s recent findings suggest that for many victims, it may already be too late to prevent further misuse of their stolen cryptocurrency.

news
Web3 & Enterprise·

Aug 06, 2024

Amber Group calls for crypto project transparency & accountability

At the end of last month, social derivatives trading platform ZKX, a protocol that runs on the Ethereum-centric Starknet layer-2 network, shut down blindsiding the project’s stakeholders. That event has led to Singapore-headquartered digital assets firm Amber Group speaking out, calling for cryptocurrency projects to be more accountable and transparent going forward. Not economically viableNews of the project shutdown emerged when ZKX founder Eduard Jubany Tur took to X on July 30 to outline the discontinuation of the protocol. Tur claimed that the project was “unable to find an economically viable path for the protocol.” In a long-form post, the ZKX founder outlined that user engagement had been minimal, resulting in disappointing trading volumes. By extension, Tur claimed that revenues didn’t come anywhere close to covering cloud server expenses. “The market is undervaluing the work done and infrastructure built by appchains and dApps coming from ecosystems like ours,” Tur added. Pseudonymous blockchain sleuth ZachXBT had a different take on the matter, claiming that the shutdown represented a rug pull. Amber Group chimed in on the subject on X on Aug. 3. Amber suggested that it wouldn’t break any contractual non-disclosure obligations it had with regard to ZKX but that aside, the firm took the opportunity to share its perspective more broadly in an effort to promote transparency.Photo by Markus Spiske on PexelsAmber Group criticismAmber Group criticized the ZKX team on the basis of a lack of transparency. It stated: “The last update we received was on July 30, when the project announced the cessation of operations. This decision was made without prior communication, highlighting the importance of transparency in our industry.” Staying with that theme, it claimed that clear communication and transparency are essential for fostering trust and collaboration within the crypto community, and that such principles would guide future projects. Amber Group had acted as a market maker relative to the ZKX project. It borrowed and purchased ZKX tokens in support of the launch of the token and in an effort to support token liquidity post-launch. It had secured two million ZKX tokens from the open market, with its overall holding totaling three million ZKX tokens. Project investor HashKey Capital also took to the X social media platform on the subject. Like Amber Group it too criticized the ZKX project for its lack of accountability and transparency. It described the project’s reluctance to communicate as “disappointing,” while it asserted that Tur’s handling of the situation had been “regrettable.” Ye Su, founding partner at ArkStream Capital, expressed a similar complaint, stating on X that “when ZKX shut down, as investors, we got zero heads-up.” He also singled out Tur, claiming that “Edward took the money from early supporters without any communication, showing no moral standards and losing his right to future entrepreneurship in the industry.”

news
Loading