Top

Kronos Research experiences significant cybersecurity breach

Web3 & Enterprise·November 21, 2023, 12:16 AM

Kronos Research, a Taipei-based crypto trading, market making and venture capital firm, has found itself in the crosshairs of a cyber attack.

Photo by FLY:D on Unsplash

 

$25.6 million loss

Hackers gained unauthorized access to the company’s API keys, resulting in losses exceeding $25.6 million spread across various cryptocurrencies, prompting a concern within the crypto community.

The breach was detailed by the company in a social media post on the X platform on Saturday. That post read:

“In the interest of transparency Around 4 hours ago, we experienced unauthorized access of some of our API keys. We paused all trading while we conduct an investigation. Potential losses are not a significant portion of our equity and we aim to resume trading as soon as possible.”

 

On-chain sleuthing

Investigations by crypto community members have followed, led by blockchain researcher ZachXBT. ZachXBT is a well-known anonymous persona in the crypto space, having earned a reputation for uncovering hacks, scams and unethical practices within the crypto sector.

In this instance, ZachXBT uncovered a trail of transactions originating from a Kronos Research account. The meticulous execution of the cyber attack was evident in six transactions involving 2,780 ETH, 2,540 ETH (repeated twice), 2,636 ETH, 4.93 ETH and 2,507.52 ETH, all directed to addresses controlled by the hacker.

Kronos Research has followed up with a tweet thread on X, acknowledging the gravity of the situation and confirming losses of approximately $25.65 million in crypto assets. Despite the alarming figures, the company sought to reassure stakeholders by emphasizing that the losses represent a relatively small fraction of its total equity. In a commendable display of accountability, Kronos Research pledged to absorb all losses internally, shielding its partners from the financial ramifications of the breach.

The Taiwanese firm posted:

“Our team has been working round the clock to minimize the impact and resume trading operations, following a hacking incident that involved unauthorized access to our API Keys.”

 

Implications for Woo X

The operational repercussions were swift and impactful, with Kronos Research opting for a temporary suspension of all trading operations. This decision rippled through to Woo X, the affiliated Taipei-based exchange and liquidity provider created by Kronos, which temporarily blocked specific asset combinations due to liquidity concerns. Importantly, Woo X assured users of the security of their funds and later announced the resumption of spot and perpetual trading.

Looking forward, Kronos Research outlined its intention to resume trading operations in the coming days, contingent on favorable conditions.

The cyber attack on Kronos Research occurred against the backdrop of heightened cybersecurity concerns within the crypto space. According to blockchain security firm Certik, approximately $173 million was lost to crypto attacks in November alone. The Kronos Research breach follows on the heels of Poloniex’s $131 million hack, highlighting the persistent challenges faced by crypto platforms in securing user assets.

More to Read
View All
Web3 & Enterprise·

Nov 02, 2023

Hong Kong’s HaskKey launches app following regulatory approval

Hong Kong’s HaskKey launches app following regulatory approvalHong Kong-based cryptocurrency firm HashKey has unveiled the HashKey Exchange app, which has received the approval of the Securities and Futures Commission (SFC).News of the app launch emerged following insights shared by HashKey’s Chief Operating Officer, Livio Weng, in an interview with The Block recently.Photo by Manson Yim on UnsplashAppealing to retail tradersThe HashKey Exchange app went live on Wednesday, having received regulatory clearance from Hong Kong’s securities regulator the previous Friday. This achievement allows the app to offer full mobile trading capabilities. Prior to this milestone, HashKey had been primarily catering to professional investors under a voluntary licensing scheme.With the new app, Hongkongers can now conveniently purchase bitcoin and ether, utilizing either Hong Kong dollars or US dollars, directly from their local bank accounts. The app launch is significant as HashKey has become one of Hong Kong’s first fully compliant retail-facing crypto trading platforms. “We’ve recorded large trading volume since we began to serve retail users,” Weng stated. The move aligns with the Hong Kong government’s efforts to bolster the virtual asset sector, which was set in motion one year ago with various policy shifts.These shifts included the introduction of a mandatory licensing scheme for cryptocurrency platforms, enabling them to offer tokens with large market capitalizations to retail traders. The new licensing regulations officially took effect in June, with a one-year grace period, though no new exchanges have been approved to date. HashKey and its rival, OSL, had their previous licenses upgraded in August.Developmental challengesHong Kong has faced several challenges on this journey. While the new regulations are largely in line with international norms, the process has been notably expensive, particularly against the backdrop of a bearish crypto market.The lingering fallout from the JPEX scandal, a cryptocurrency exchange allegedly involved in fraudulent activities, continues to impact Hong Kong’s virtual asset landscape. The SFC first raised concerns about JPEX in mid-September, and since then, it has moved to tighten regulation in response, having received thousands of complaints in relation to JPEX.Despite these challenges, HashKey Group has reported significant activity on its retail platform since its launch in August, with a total trading volume exceeding US$600 million. On October 30, the 24-hour trading volume exceeded US$100 million.Planned token launchIn a move designed to incentivize new users, HashKey Exchange has introduced its platform token, HSK, which is slated to be officially listed on the exchange next year. With a total supply of 1 billion HSK, the company has specified that these tokens will not be initially sold to retail investors, emphasizing its long-term vision for the project.Established in Hong Kong in 2018, HashKey Group operates a digital asset brokerage and a venture capital arm. HashKey Exchange earned the distinction of becoming Hong Kong’s second licensed exchange in November of the previous year, following in the footsteps of OSL. Notably, five companies have applied for the new licensing scheme, according to the SFC, while several other exchanges have expressed their intent to pursue similar approval.

news
Web3 & Enterprise·

Jun 27, 2023

3AC Liquidators Pursue $1.3 Billion from Founders

3AC Liquidators Pursue $1.3 Billion from FoundersLiquidators appointed for Three Arrows Capital (3AC), the failed Singaporean cryptocurrency hedge fund, are seeking to recover $1.3 billion from the fund’s co-founders.That’s according to an unidentified source cited by Bloomberg in a report published on Tuesday. The requested amount represents losses incurred by the founders during the months leading up to the firm’s collapse, according to a source familiar with the liquidators’ claims.Photo by Giorgio Trovato on UnsplashLiability allegationsDuring a meeting with the hedge fund’s creditors on Tuesday, the liquidators discussed the allegations against Three Arrows co-founders Su Zhu and Kyle Davies. The co-founders are accused of causing the hedge fund to accumulate significant leverage between May and June 2022, despite already suffering substantial losses from ill-fated Luna tokens and other investments.The liquidators argue that the firm was insolvent at that time. Consequently, they have taken legal action against Zhu and Davies in a British Virgin Islands court to recover the losses on behalf of the fund’s creditors.Lawyers representing Zhu and Davies have not yet responded to requests for comment. However, in a Twitter post last June, Zhu mentioned that their attempts to cooperate with the liquidators were met with resistance.Crypto failure catalystThe failure of Three Arrows Capital coincided with a downturn in the digital currency market, impacting platforms that had exposure to the hedge fund, including crypto lenders BlockFi and Voyager Digital. These platforms subsequently filed for bankruptcy in the weeks following the liquidation of the hedge fund.The liquidators’ allegations against the co-founders represent an escalation of actions taken against Zhu and Davies, whom they have accused of non-cooperation during the investigation. The liquidators, who are partners at the consulting and advisory firm Teneo, were appointed by a British Virgin Islands court last year to recover funds for Three Arrows Capital’s creditors, who are collectively owed approximately $3.3 billion.Earlier this month, the liquidators urged a New York bankruptcy judge to impose a daily fine of $10,000 on Davies. They argue that this substantial fine is warranted because he has failed to respond to a subpoena requesting business records and other relevant information.While the liquidators do not currently know the whereabouts of Davies or Zhu, court documents from earlier this month referenced a New York Times article reporting that Davies had traveled to Bali after the collapse of Three Arrows Capital.Restraining orderIn May Zhu had secured a restraining order against BitMEX Co-Founder Arthur Hayes in a Singaporean court. Hayes believes that he is owed $6 million by the 3AC co-founders. Despite significant adverse publicity within the crypto space, the 3AC co-founders have proceeded to do business within the industry.They’ve established a crypto claims trading platform, OPNX, and alongside that Dubai-based business, they’ve also established a new venture capital fund, 3AC Ventures.The Dubai regulator, the Virtual Assets Regulatory Authority (VARA), has reprimanded OPNX and the business's founders for operating an unregistered digital assets business within the territory.

news
Web3 & Enterprise·

Dec 27, 2023

Kyber Network implements workforce reduction following exploit

In the aftermath of a substantial security breach in November that resulted in a confirmed loss of over $48 million, Kyber Network, the multi-chain decentralized exchange (DEX) aggregator, has taken decisive steps to restructure its operations.Photo by kate.sade on UnsplashWorking towards recoveryCEO and co-founder Victor Tran posted a lengthy message on the X social media platform on Christmas Eve to announce a 50% reduction in the firm’s workforce. The move marks a pivotal moment in the company’s efforts to recover and rebuild. As part of its strategy to ensure sustainability, Kyber temporarily suspended its liquidity protocol initiatives and KyberAI. Despite these challenging measures, the core aggregator and limit order functions remain fully operational. Tran emphasized the company’s commitment to persist and evolve, highlighting its determination to navigate through recent adversities. Despite these challenging measures, the core aggregator and limit order functions remain fully operational. Tran emphasized the company’s commitment to persist and evolve, highlighting its determination to navigate through recent adversities. Zap API additionIn an effort to enhance its services, Kyber Network disclosed plans to introduce the Zap API. This new offering aims to provide decentralized applications, crypto wallets and other DeFi projects with a seamless means to connect their users to liquidity protocols. Tran also revealed that in an effort to support its workforce during the transition, the firm has established a “voluntary database” to assist departing employees in finding new career opportunities. This initiative seeks to connect these individuals with peer projects in the industry. Exploit fall-outKyber Network took to social media on Nov. 22 to advise its KyberSwap Elastic user base of a security incident. With that notification, it advised users to withdraw their funds immediately. Over the next few days, it became clear that $48 million had been exploited on the platform by a hacker. In the immediate aftermath of the incident, the hacker posted a message on the blockchain, stating: “Negotiations will start in a few hours when I am fully rested.” He/she progressed to issuing unusual demands, including gaining complete operational control of the company and temporary ownership of the KyberDAO governance mechanism. The nature of these demands sets this particular exploit apart from others. The Kyber team, however, chose to reject these demands. It chose to respond with a blockchain message of its own, outlining that it was cooperating with law enforcement in an effort to track the hacker. The company, which operates from offices in Hanoi, Ho Chi Minh City and Singapore, also offered the hacker a carrot of a 10% bounty if the hacker agreed to return 90% of users’ funds. Instead, the firm pledged to compensate affected users through the KyberSwap Elastic Exploit Treasury Grant Program. On Dec. 20, the firm provided further details on that grant program, outlining how affected users would be refunded. Furthermore, Kyber Network is actively collaborating with authorities to identify the hacker and recover the stolen funds.Earlier this month, blockchain security firm CertiK issued an alert on social media, outlining that the hacker had moved BNB tokens to the value of $338,000 into decentralized crypto tumbler Tornado Cash.

news
Loading