Top

Mixin Network Suspends Services Amid $200 Million Hack

Policy & Regulation·September 25, 2023, 11:56 PM

On Monday, Mixin Network, a decentralized peer-to-peer network whose project team is based in Hong Kong, officially confirmed a substantial security breach that resulted in the loss of approximately $200 million in crypto assets from its mainnet.

Photo by GuerrillaBuzz on Unsplash

 

September 23 hack

This incident, disclosed via an X (formerly Twitter) post, prompted the immediate suspension of all deposit and withdrawal services on Mixin Network until further notice.

The project team outlined that the hack occurred on September 23, exposing vulnerabilities that allowed malicious actors to compromise the database of a third-party cloud service provider. Mixin Network has taken action to address the situation, enlisting the expertise of Singapore-headquartered blockchain security investigator SlowMist and the support of Google to conduct a thorough investigation and formulate a recovery plan.

At the time of the breach, Mixin Network’s holdings included $94.48 million in Ether, $23.55 million in Dai, and $23.3 million in Bitcoin, as reported in an independent investigation by PeckShield. The total value of assets affected amounted to $141.32 million.

Cyvers, an Israeli Web3 security firm, has also been looking into the matter on Monday. In a social media post, the firm stated:

”Our internal investigation has uncovered suspicious funding transactions involving @MixinKernel hacker addresses. Two of hacker addresses received 51 $ETH from 0x1795F0eBDa5A836aE63F28CE546E72de069A8bd2 who was interacted with @HuobiGlobal and @binance.”

The firm goes on to call on Binance and its CEO Changpeng Zhao (CZ) and Huobi to help identify the wallet address in question.

 

Halting withdrawals

In response to the security breach, Mixin Network has temporarily halted all deposits and withdrawals on its platform. These services will only resume once the vulnerabilities have been identified and fully resolved. On X, the project stated:

”Deposit and withdrawal services on Mixin Network have been temporarily suspended. After discussion and consensus among all nodes, these services will be reopened once the vulnerabilities are confirmed and fixed. During this period, transfers are not affected.”

Details regarding the plans to recover the lost assets for affected users have yet to be announced.

Despite initial promises that Mixin Network’s Founder, Feng Xiaodong, would address the incident in a public Mandarin live stream on September 25, links to the live stream were not provided on the official social media channels or the website mixin.network.

The incident has garnered criticism on the basis of a lack of decentralization. One commentator stated:

”Some of those blockchain protocols are so decentralized that when their cloud database is hacked, coins are also gone.”

 

Ongoing hacks

This security breach on Mixin Network is the latest in a series of high-profile crypto-related incidents. Ethereum Co-Founder Vitalik Buterin recently fell victim to a SIM swap attack, which resulted in the compromise of his X (formerly Twitter) account.

In a statement, Buterin revealed that the hackers had successfully executed a SIM swap, a type of attack that targets the victim’s mobile phone number to gain unauthorized access to various online accounts, including social media, banking, and cryptocurrency platforms.

The repercussions of the Mixin Network hack underscore the ongoing challenges faced by the crypto industry in ensuring the security and protection of digital assets. As investigations continue, affected users await further developments and the eventual resumption of deposit and withdrawal services.

More to Read
View All
Policy & Regulation·

Aug 03, 2023

Korean Financial Watchdog Warns Investors Against Crypto Scams

Korean Financial Watchdog Warns Investors Against Crypto ScamsThe South Korean Financial Supervisory Service (FSS) issued a press release today to warn investors against fraudulent cryptocurrency investment schemes.406 reported scams in two monthsBetween June 1 and July 30, the FSS received a total of 406 reports of crypto scams that lured individuals with false promises of high returns. Some of these perpetrators went to the extent of misrepresenting themselves as employees at crypto exchanges or project foundations. The FSS installed a virtual asset scam report center two months ago, which will run until this year’s end, as an interim measure before the implementation of the Virtual Asset User Protection Act in July of next year.Photo by Growtika on UnsplashSix scam typesTo strengthen its efforts, the FSS has shared six reported case types with the public and has issued investment warnings accordingly. Investors are advised to exercise caution when dealing with unlisted cryptocurrencies at low prices, as accurately determining their value can be challenging. Similarly, the FSS cautions against investing in cryptocurrencies sold at low prices with trading restrictions, as this could lead to difficulties in liquidating tokens if the price drops.The FSS also emphasizes the importance of being wary of cryptocurrencies with low trading volumes, as they can experience drastic price fluctuations due to limited activity. To prevent falling victim to impersonation scams, investors are urged to be cautious of individuals claiming to be employees of domestic virtual asset service providers or presenting official documents to solicit investments.Furthermore, the financial watchdog stresses the risks associated with suspicious requests associated with electronic wallets, particularly connecting to them via unsolicited emails, as they pose a high risk of being hacked.Lastly, the watchdog warns against falling for promises of high returns linked to cryptocurrencies endorsed by celebrities or well-known companies, as these may be illegal deposit-taking activities performed by unlicensed entities. The FSS advises investors to remain vigilant, conduct thorough research, and approach investment opportunities with skepticism to protect themselves from potential crypto scams.

news
Web3 & Enterprise·

Sep 06, 2024

WazirX hack: Hacker launders $10M through Tornado Cash amid legal disputes and partial withdrawals

In the aftermath of the massive $235 million hack of the WazirX cryptocurrency exchange on July 18, users and stakeholders are grappling with its devastating consequences. The breach, which compromised a significant portion of the exchange’s reserves, has led to a series of legal, financial and security-related challenges, leaving millions of users uncertain about the future of their funds. The hack and its aftermathWazirX, once a leading Indian cryptocurrency exchange, lost approximately $235 million due to a breach in one of its multi-signature wallets. This included significant amounts of Shiba Inu (SHIB), Ethereum (ETH) and other assets. The hack crippled the exchange, forcing it to temporarily shut down operations and seek a restructuring process under Singapore's insolvency laws. The WazirX hacker has since begun laundering the stolen assets through Tornado Cash, a crypto mixer known for obscuring transaction details. According to blockchain security firm Cyvers, the hacker transferred over 5,000 ETH (approximately $12 million) to a new wallet and laundered $10 million in Ethereum through Tornado Cash. This mirrors the tactics of the North Korea-backed Lazarus Group, which has used similar methods in past high-profile crypto thefts. Photo by GuerrillaBuzz on UnsplashUsers seeking redress and government interventionAs the victims of the hack face uncertainty, over 4 million active WazirX users are expected to suffer a loss of at least 43% of their funds due to the restructuring process. Frustrated by the lack of action from Indian authorities, many users have sought help from Indian Prime Minister Narendra Modi, who was visiting Singapore at the time. Users took to social media to air their grievances and demand justice, urging the government to intervene. WazirX co-founder Nischal Shetty, who is based in Dubai, added to the confusion by stating that he does not know who is responsible for safeguarding user crypto funds on the platform. His statement has fueled outrage among users, who feel abandoned by the exchange’s management. Legal and ownership disputesAmid the chaos, WazirX is also battling a legal dispute over its ownership with Binance, the world’s largest cryptocurrency exchange. Shetty has repeatedly claimed that Binance acquired WazirX, granting it significant control over the platform's operations. However, Binance founder Changpeng Zhao (CZ) refuted these claims in 2022, stating that the acquisition deal was never completed. The uncertainty surrounding the ownership of WazirX has further aggravated users, many of whom are demanding a clear statement from Binance. So far, Binance has remained silent, neither confirming nor denying its involvement. This ambiguity has intensified calls for clarification, with users fearing that a lack of transparency may worsen their chances of recovering their funds. Partial withdrawals and restructuring effortsIn response to the crisis, WazirX has initiated phased withdrawals for users, allowing them to access 66% of their Indian Rupee (INR) token balances. Initially set for September 9, the withdrawal window was moved forward, offering some relief to users. However, many are dissatisfied with the partial access to their funds and are questioning when full crypto withdrawals will resume. WazirX’s legal team has indicated that users may recover only 55% to 57% of their crypto holdings, sparking further discontent. Meanwhile, the exchange has filed a moratorium application in the Singapore High Court, seeking a six-month reprieve from legal actions as it works on a restructuring plan. Looking aheadAs the WazirX saga unfolds, the future of the exchange and its users remains uncertain. The legal battles, ownership disputes and the ongoing laundering of stolen assets pose significant challenges to the platform's recovery. For now, users can only hope that the restructuring process will bring them closer to recovering their lost funds and that authorities will step in to provide clarity and resolution. 

news
Web3 & Enterprise·

Oct 26, 2023

SC Ventures and Deutsche Bank Execute Stablecoin Payments via UDPN

SC Ventures and Deutsche Bank Execute Stablecoin Payments via UDPNSC Ventures, the Singaporean disruptive technology investment subsidiary of UK banking conglomerate Standard Chartered, has partnered with Deutsche Bank in completing the first successful proof of concept (PoC) for the Universal Digital Payments Network (UDPN).Photo by Conny Schneider on UnsplashConnecting blockchain networks with CBDCsThe UDPN is a brainchild of Hong Kong’s Red Date Technology, which in turn is a co-founder of the Chinese Blockchain-Based Service Network (BSN). The PoC was aimed at facilitating seamless connections between central bank digital currencies (CBDCs) and various blockchain networks through message-based transactions.News of the successful PoC emerged via a report by India’s English-language business newspaper Financial Express earlier this week. In conventional finance and international payments, the Society for Worldwide Interbank Financial Telecommunication (SWIFT) is the foremost, dominant financial messaging service. Notably, UDPN distinguishes itself from SWIFT as it operates on a permissioned blockchain, ensuring heightened security and regulatory compliance.As part of the PoC, several real-time transfers and swaps of synthetic USDC and EURS (Stasis Euro stablecoin) were executed between the two banks. While SC Ventures utilized code that leveraged UDPN software development kits (SDKs) and APIs, Deutsche Bank employed a graphical user interface. Rafael Otero, CTO and CPO of Deutsche Bank’s Corporate Bank division, emphasized the significance of this trial, stating that it provides an opportunity to explore how clients can actively engage in the decentralized global economy. Otero sees this as the logical next step in the evolution of financial transactions.Overcoming digital currency adoption challengesUDPN has been under development in collaboration with consultancy firm GFT Technologies and DLA Piper’s Hong Kong-based digital asset creation platform, TOKO, with further governance provided by the UDPN Alliance.The primary goal of UDPN is to overcome the hurdles that hinder the broader adoption of digital currencies, especially in the face of the surging number of CBDCs, stablecoins, and deposit tokens. The lack of interoperability among these digital assets necessitates innovative solutions.Currently, interoperability among stablecoins primarily relies on centralized cryptocurrency exchanges. However, due to the absence of proper oversight and regulatory framework in these exchanges, this method is not a sustainable solution for achieving interoperability between CBDCs and deposit tokens.UDPN takes a unique approach by providing a decentralized identity infrastructure. The actual currency transactions occur on their respective native blockchains or infrastructures. This means that UDPN enables users to seamlessly swap a USDC stablecoin on one network for a Euro stablecoin on another or even a bank deposit token.Improving upon financial messaging systemsAs UDPN incorporates an element of financial messaging for digital currencies, this hybrid approach streamlines transactions, eliminates the need for reconciliations, and enables atomic settlement. Therefore, UDPN ensures that either both sides of a transaction succeed or both fail. In contrast, purely messaging-based systems can result in one side of the transaction failing.SWIFT recently experimented with a messaging solution to connect CBDCs, and other conventional integration methods are being explored, involving APIs and routing networks, such as finP2P. It has collaborated with the central banks of Hong Kong and Kazakhstan recently in testing CBDC connectors.A report by Nikkei Asia last week suggested that Standard Chartered is venturing further into the world of digital currencies, particularly so in Asia, via SC Ventures.

news
Loading