Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Policy & Regulation·

Aug 08, 2023

LH Leverages Blockchain to Certify Legally Important Documents

LH Leverages Blockchain to Certify Legally Important DocumentsThe Korea Land and Housing Corporation (LH) is set to build a certification platform to replace paper documents as the sole form of legal certification. The initiative aims to bring the credibility of traditional methods like contents-certified mail to electronic documents by leveraging blockchain technology.Photo by Liam Truong on UnsplashContents-certified mail — transitioning from postal to digitalContents-certified mail refers to a specific type of mail service provided by the post office, which offers special guarantees regarding the delivery and content of a document. When a document is sent using contents-certified mail, the post office provides certain assurances that can be beneficial in legal and official contexts.Amidst the rise in demand for digital administrative services due to increased remote technologies in the post-COVID-19 era, the ongoing expansion of Web3, and enhanced customized administration, there has also been a growing need for the digitization of documents related to compensation for land and buildings.According to industry sources, LH plans to automate document transmission and management functions through the platform, establishing a digital environment for generating, sending, receiving, viewing, and storing electronic documents.Factoring in blockchain techA key feature of the proof platform is its integrated blockchain technology. “Utilizing blockchain allows accurate documentation of LH as the sender, as well as the timestamps of delivery and reception. This will subsequently enhance transparency and security,” LH said.Going paperlessBy establishing the digital platform, LH will be able to introduce a more convenient method of sending legally significant documents, essentially replacing the manual method of sending them through postal services. This could include sending them via platforms used nationwide like Naver or KakaoTalk or through text messages sent by the country’s major telecommunication companies.This innovation can contribute to the proliferation of paperless methods, addressing the expected increase in postal delivery failures tied to the rise of single-person households.“By constructing this platform, we can better protect user rights and provide administrative services that transcend the temporal and spatial constraints of registered mail,” LH said. “We will broaden our legal, institutional, and technical discussions to innovate processes for verifying the validity of electronic documents.”The project is currently in operation in certain areas related to compensation. According to LH, the plan is to expand the project’s scope to encompass all areas of compensation by next year and then to other areas such as the management and sale of rental apartments.The corporation said that it posted a bidding notice last Wednesday to hire a company that can build the blockchain-powered platform that certifies legally important documents. LH is currently undergoing a selection process.Employing smart contractsLH also mentioned that it is preparing a smart contract system. The system programs the terms agreed upon by involved parties in advance, embeds them in an electronic contract, and enables automatic execution of the terms of the contract when all conditions are met.

news
Web3 & Enterprise·

Jan 16, 2024

Blockchain research startup Four Pillars snags $527k investment

South Korean blockchain research firm Four Pillars has secured KRW 700 million (approximately $527,000) in investment funds from Kakao Ventures, Hashed and Bass Investment, according to South Korean news site Coin Readers on Tuesday.Photo by Precondo CA on UnsplashEmpowering blockchain venturesLed by a team of industry experts, Four Pillars is dedicated to supporting companies that aim to develop blockchain projects and successfully bring their business to the market. It conducts research based on its technological expertise and experience in blockchain collaborations, providing customized solutions based on each client’s circumstances. It aims to save time and money for companies looking to enter the blockchain market by providing comprehensive and relevant insights on cryptocurrency basics, the blockchain industry, regulations and market analyses, rather than simply listing information. Rapid growth and strategic partnershipsSince its establishment last year, the research platform has attracted more than 30,000 visitors per month on average in just two months. The company has also signed an agreement with Japanese publishing agency Gentosha to publish a Japanese version of its content. Other partners include the layer 1 blockchain Sei Network, Web3 gaming platform Iskra, tech juggernaut LINE’s blockchain Finschia, and Korean telecommunications provider SKT's digital T Wallet.  Before securing the recent investment, the Four Pillars team was recognized for collaborating with various developers on global blockchain projects and receiving a research sponsorship from the dYdX Foundation, a decentralized protocol operator known for being highly selective when offering sponsorships. "The core members of Four Pillars, including CEO Kim Nam-woong, are among the few people in the Korean crypto scene who can bring unique insights to research," said Brian Jang, Director at Kakao Ventures. "Based on their unrivaled research capabilities, we expect them to grow rapidly while connecting domestic and international protocols and corporate needs to business outcomes." Bridging markets, breaking barriersAs trends in the global blockchain market change at a rapid pace, the importance of high-quality, relevant research is amplified, even more so than in the era of Web2. However, information tends to be scattered across platforms, making it overwhelmingly difficult for companies to utilize it in their business endeavors. This is also one of the key reasons why overseas companies have a hard time navigating their entry into the Korean market with their limited knowledge of market trends or conditions. The same can be said for Korean companies who want to launch their businesses overseas. By bridging Korean and overseas companies and projects, Four Pillars aims to resolve this widespread information asymmetry in the ever-growing blockchain industry and establish its foothold as a global research firm. This is reminiscent of Delphi Digital, a U.S.-based crypto research firm founded in 2018 that quickly expanded and established a global Web3 accelerator service called Delphi Labs.  The Four Pillars team also aims to dedicate the investment funds towards accelerating its efforts in talent acquisition, product development and continued research. In the future, the company plans to boost diverse blockchain projects and contribute to the participation of various stakeholders in the blockchain ecosystem.  "Our priority and goal is to create a developer-friendly environment by leveraging the high-quality research and products that we provide at Four Pillars," the firm’s CEO said. "We will lower the barriers to entry for blockchain and grow the entire Web3 market by making it more suitable for both users and developers."

news
Policy & Regulation·

Jun 10, 2023

US DOJ Charges Two Russians With Mt. Gox Hack

US DOJ Charges Two Russians With Mt. Gox HackTwo Russian nationals have been charged by the US Department of Justice (DOJ) for their involvement in hacking of the Japanese cryptocurrency exchange Mt. Gox, and in causing the collapse of the infamous exchange.Photo by Tingey Injury Law Firm on UnsplashCulpable for collapseThe indictment, which has been unsealed, was originally filed on June 7, and identifies the individuals as Alexey Bilyuchenko, 43, and Aleksandr Verner, 29. They are accused of not only hacking the exchange but also conspiring to launder approximately 647,000 bitcoins, which is valued at around $17.1 billion based on Bitcoin’s unit price on Friday.Additionally, Bilyuchenko has been charged with collaborating with Alexander Vinnik to operate the illicit exchange known as BTC-e between 2011 and 2017. BTC-e was shut down by U.S. law enforcement in 2017, and Vinnik was later extradited from Greece to the U.S. in 2022 on charges of running BTC-e and engaging in money laundering.Mt. Gox, which experienced a major theft, declared bankruptcy and closed its operations in 2014. Bilyuchenko and Verner played a significant role in the theft, leading to the exchange’s insolvency, according to Assistant Attorney General Kenneth A. Polite, Jr. of the Justice Department’s Criminal Division. The indictment states that “in or about September 2011, [the defendants] and their co-conspirators gained and caused others to gain unauthorized access to the Mt. Gox server in Japan.”BTC-e exchange money launderingFurthermore, it is alleged that Bilyuchenko utilized his ill-gotten gains from the Mt. Gox theft to establish the BTC-e exchange, which facilitated global money laundering activities for criminals. US Attorney Ismail J. Ramsey for the Northern District of California stated that Bilyuchenko and his co-conspirators operated a digital currency exchange that enabled criminal entities, including hackers, ransomware actors, narcotics rings, and corrupt officials, to launder billions of dollars.In March, there were reports from CoinDesk about movements of BTC-e funds on the blockchain. An exchange wallet linked to BTC-e made its first transaction since 2017, transferring approximately 3,299 bitcoins to a crypto wallet in November 2022. Additionally, six years ago, the exchange wallet sent around 10,000 bitcoins to two unidentified recipients. However, the recent DOJ filing does not specify whether these recipients were Bilyuchenko and Verner.Slow processMeanwhile, the long-suffering creditors of the hacked exchange are only beginning to reach the final stages of the bankruptcy process. Japan’s bankruptcy process is incredibly slow and it’s taken the best part of ten years for it to reach the distribution phase. It became apparent in April that the bankruptcy estate was moving to distribute $4.5 billion in cash and digital assets to creditors. It’s understood that the process will be completed in October.While creditors are taking a haircut in bitcoin terms, on a US dollar basis, they are not fairing out badly given that the leading cryptocurrency has seen massive dollar price appreciation in the intervening years.

news
Loading