Top

Kronos Research experiences significant cybersecurity breach

Web3 & Enterprise·November 21, 2023, 12:16 AM

Kronos Research, a Taipei-based crypto trading, market making and venture capital firm, has found itself in the crosshairs of a cyber attack.

Photo by FLY:D on Unsplash

 

$25.6 million loss

Hackers gained unauthorized access to the company’s API keys, resulting in losses exceeding $25.6 million spread across various cryptocurrencies, prompting a concern within the crypto community.

The breach was detailed by the company in a social media post on the X platform on Saturday. That post read:

“In the interest of transparency Around 4 hours ago, we experienced unauthorized access of some of our API keys. We paused all trading while we conduct an investigation. Potential losses are not a significant portion of our equity and we aim to resume trading as soon as possible.”

 

On-chain sleuthing

Investigations by crypto community members have followed, led by blockchain researcher ZachXBT. ZachXBT is a well-known anonymous persona in the crypto space, having earned a reputation for uncovering hacks, scams and unethical practices within the crypto sector.

In this instance, ZachXBT uncovered a trail of transactions originating from a Kronos Research account. The meticulous execution of the cyber attack was evident in six transactions involving 2,780 ETH, 2,540 ETH (repeated twice), 2,636 ETH, 4.93 ETH and 2,507.52 ETH, all directed to addresses controlled by the hacker.

Kronos Research has followed up with a tweet thread on X, acknowledging the gravity of the situation and confirming losses of approximately $25.65 million in crypto assets. Despite the alarming figures, the company sought to reassure stakeholders by emphasizing that the losses represent a relatively small fraction of its total equity. In a commendable display of accountability, Kronos Research pledged to absorb all losses internally, shielding its partners from the financial ramifications of the breach.

The Taiwanese firm posted:

“Our team has been working round the clock to minimize the impact and resume trading operations, following a hacking incident that involved unauthorized access to our API Keys.”

 

Implications for Woo X

The operational repercussions were swift and impactful, with Kronos Research opting for a temporary suspension of all trading operations. This decision rippled through to Woo X, the affiliated Taipei-based exchange and liquidity provider created by Kronos, which temporarily blocked specific asset combinations due to liquidity concerns. Importantly, Woo X assured users of the security of their funds and later announced the resumption of spot and perpetual trading.

Looking forward, Kronos Research outlined its intention to resume trading operations in the coming days, contingent on favorable conditions.

The cyber attack on Kronos Research occurred against the backdrop of heightened cybersecurity concerns within the crypto space. According to blockchain security firm Certik, approximately $173 million was lost to crypto attacks in November alone. The Kronos Research breach follows on the heels of Poloniex’s $131 million hack, highlighting the persistent challenges faced by crypto platforms in securing user assets.

More to Read
View All
Policy & Regulation·

Feb 02, 2024

Hong Kong’s PCPD investigates Worldcoin over privacy concerns

On Wednesday, the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong launched investigations at six premises controlled by Worldcoin, the biometric cryptocurrency project established by Sam Altman, the CEO of OpenAI. Potential personal data privacy risksIn a statement, the Privacy Commissioner expressed serious concerns about potential risks to personal data privacy. The PCPD executed warrants as part of the inquiry into Worldcoin's identity verification project, particularly focusing on the use of iris-scanning orbs for identity verification. The PCPD urged Hong Kong residents to consider the implications of Worldcoin's biometric data collection and emphasized the importance of evaluating the legitimacy of such data collection. The Commission also advised individuals to inquire about the purpose of data collection, the intended use of the data, the classes of entities with access to the data, the retention period of biometric data and the safety measures implemented to protect sensitive information. "The PCPD is concerned that the operation of Worldcoin in Hong Kong involves serious risks to personal data privacy, and believes that the collection and processing of sensitive personal data by the relevant organization may be in contravention of the requirements of the Personal Data (Privacy) Ordinance," stated the privacy watchdog. The Commission highlighted that any personal data controlled by Worldcoin must be collected for a lawful purpose related to the project's function or activity, with the information collected from users' irises deemed sensitive according to regulatory guidelines.Photo by Harpreet Singh on UnsplashGlobal scrutinyWorldcoin, which commenced operations in 2021 and officially launched in July 2023, has faced regulatory scrutiny in various countries due to privacy concerns. As of December 2023, Worldcoin reported that over 5 million people had created accounts using their identities. However, the project's approach to identity verification through iris scanning has triggered investigations and actions by regulators. Notably, the project suspended services in Kenya and halted iris scans in India in response to regulatory challenges.  The company’s activities in the French and Brazilian markets have been suspended. Last year the UK’s Information Commissioner’s Office said that it would make further enquiries into the company’s activities. Meanwhile, the German data watchdog has been investigating Worldcoin since 2022. In an effort to clarify the efforts the company is making to achieve compliance across international jurisdictions where data privacy is concerned, Worldcoin recently published a blog post on the subject. Within it, the company states that it “is designed to be fully compliant with all laws and regulations governing data collection and data transfer." Despite its ongoing regulatory challenges, Worldcoin CEO Alex Blania remains steadfast in advancing the project's mission, stating recently:"We race toward billions of users as fast as we possibly can."  The project closed out 2023 by expanding into Singapore. The privacy concerns surrounding Worldcoin underscore the growing importance of balancing technological innovation with robust data privacy regulations to ensure the protection of individuals' sensitive information.

news
Policy & Regulation·

Nov 08, 2024

Japan to fine-tune crypto regulations to protect investors

Japan's Financial Services Agency (FSA) is proposing new legislation in an effort to prevent the assets of Japanese investors held on crypto exchanges from being transferred overseas. According to local news outlet Jiji Press, the Japanese regulator recently put forward the idea of drafting such a bill. It’s thought that the move suggests that the Japanese regulators have learned from the collapses of cryptocurrency exchanges Mt. Gox and FTX. Photo by Jaison Lin on UnsplashLearning from past failuresWhile Japan already had a higher standard of regulation in place prior to the FTX collapse, likely as a consequence of the authorities having experienced the downfall of Mt. Gox in February 2014, there is still room for improvement.  While funds had been ring-fenced for FTX Japan users, those who accessed services advertised in Japan through the FTX app were deemed to have been accessing a service which fell under an international jurisdiction, denying them the same protections otherwise offered to FTX Japan platform users as a consequence of the regulations that had been put in place. Incorporating a holding orderJapanese media outlet Nikkei described this latest move by the Japanese FSA as follows: “The Financial Services Agency is moving towards creating a new ‘holding order’ in the Payment Services Act, which regulates cryptocurrency exchanges, that will order them not to take domestic assets entrusted to them by customers overseas.” Consequently, the regulator is looking to add this as the latest proposed amendment to the Payment Services Act. Back in September it emerged that amendments to that existing legislation were being looked at with a view towards making it easier for businesses to incorporate digital assets into their service offerings. The regulator has also been mulling over the reclassification of crypto as a financial instrument by amending the Payment Services Act accordingly. Additionally, a more generous tax policy is being proposed. Currently, the Japanese authorities impose a tax rate of up to 55% on cryptocurrency-related revenues. Corporate holders of digital assets have to apply a 30% tax rate, irrespective of income or profits. With that, a 20% tax rate is being considered. The matter became a political issue prior to the East Asian nation’s recent elections, with the leader of the Democratic Party for the People (DPP) backing the application of a 20% crypto tax rate. The application of a holding order has applied previously to companies that have been registered under the Financial Instruments and Exchange Act. This proposed amendment would see it applied to virtual asset trading platforms as part of the Payment Services Act. Guarding against bankruptcy lossesIf applied, the amendment would prevent loss of Japanese investor funds in circumstances where a crypto exchange platform goes into bankruptcy. Legal precedent set in the FTX bankruptcy in the United States means that if a user’s funds go into a non-individually segregated hot wallet belonging to an exchange, any property rights, even if explicitly outlined in the terms of service, are lost.  A company can make a case to go into bankruptcy in any international jurisdiction, which means that this precedent has potential implications for all market participants. The proposed amendment from the Japanese FSA would serve to protect investors from such an eventuality.

news
Markets·

Apr 13, 2023

Shapella Upgrade to Have limited Impact on ETH’s Selling Pressure

Shapella Upgrade to Have limited Impact on ETH’s Selling PressureThe Shapella upgrade on the Ethereum network scheduled to take place on Wednesday will only have a limited impact on the selling pressure on ETH, according to a report by the research center at Korean cryptocurrency exchange Korbit.©Pexels/JievaniShapella upgradeOne of the key features of the Shapella upgrade is to allow withdrawal of staked ETH. This upgrade follows September’s Merge upgrade that switched the Ethereum network’s consensus algorithm from Proof of Work to Proof of Stake, significantly reducing electricity consumption.Impact on selling pressureTo predict the impact of the Shapella upgrade on the selling pressure on ETH, the analysts at Korbit Research calculated the amount of time it takes for all the ETH staked as of March 22 to be withdrawn. They believe this calculation is relevant because withdrawals of staked ETH could trigger bulk sales, potentially imposing a greater selling pressure on ETH.According to the findings, the daily sell volume for the first three days is expected to be 300,700 ETH, 0.254% of the circulating supply. This volume will gradually decrease to 43,000 ETH for the next six months and to 29,000 ETH for the following six months, each corresponding to 0.035% and 0.024% of the circulating supply, respectively.All in all, bulk selling of ETH is not likely, considering it will take about a year and five months for all the staked ETH to be withdrawn and that the amount of withdrawable ETH will stay relatively low for each period. Furthermore, since this analysis assumes an extreme case, the market will be able to effectively handle the volume over the six month to 18 month period.4 other reasonsIn addition, Korbit Research outlined four other aspects that limit the selling pressure on ETH.Firstly, there is some concern that the selling volume of ETH may increase due to unstaking resulting from the cessation of staking services at American crypto exchange Kraken. However, a decrease in the number of validators on the Ethereum network will raise the base reward. This may prompt those who unstaked ETH to stake them on other platforms, rather than selling them.Second, ETH locked up at liquidity staking protocols such as Lido Finance and Rocket Pool provide liquidity for representations of staked ETH. These platforms allow users to stake fewer than 32 ETH for rewards. According to a February Binance Research report, 57.7% of ETH stakers enjoy liquidity and rewards. Therefore, there may be a limited impetus to divest of staked ETH.Third, since only 41.1% of ETH stakers are seeing profits as of the time of writing the report, the remaining stakers would have to risk losses when withdrawing ETH. This suggests that those not yet seeing profits are more likely to keep ETH staked. Furthermore, Dune Analytics data shows that most of the ETH stakers with gains staked ETH when its price was relatively low, which indicates that they participated in staking in early days. Shivam Sharma, the author of the aforementioned Binance report, states that these ETH stakers are likely “some of the strongest Ethereum believers.”Lastly, despite the Shapella upgrade, ETH withdrawals at different staking pools may not be initiated immediately. This could limit the circulation of withdrawable ETH, which in turn would hinder the selling pressure on ETH.Macroeconomic factorsThe Korbit researchers concluded their paper with a note that the selling pressure on ETH will be more influenced by macroeconomic factors than technical factors. They added that a possible downturn in the overall economy and corrections in risky asset markets might lead investors to sell ETH.

news
Loading