Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Web3 & Enterprise·

Oct 17, 2023

Hong Kong Crypto Exchange Contemplates Sale at HK$1 Billion Valuation

Hong Kong Crypto Exchange Contemplates Sale at HK$1 Billion ValuationHong Kong’s BC Technology Group is reportedly considering the sale of its crypto platform, OSL, with a suggested valuation of approximately HK$1 billion ($128 million).Photo by Samuel Chan on UnsplashDiscussions with potential buyersThat’s according to a report published by Bloomberg on Monday. OSL holds the distinction of being one of only two exchanges alongside competitor HashKey licensed under the digital asset regulations introduced by the city of Hong Kong in June. Bloomberg cited anonymous sources familiar with the matter having revealed that BC Technology has initiated discussions with potential buyers, including industry players and funds.OSL’s platform encompasses prime brokerage, exchange services, and secure custody solutions for the cryptocurrency markets. Furthermore, OSL plays a pivotal role in facilitating financial institutions’ access to virtual asset trading. Rather than a complete sale of the company, BC Technology is considering the possibility of divesting specific parts of the business, according to these sources.It’s important to note that these deliberations are ongoing, and there is no guarantee that they will culminate in a final deal, as highlighted by the insiders. In response to an inquiry from Bloomberg News, a representative from BC Technology stated:“We are a highly transparent and regulated company. We do not comment on market rumors and speculations.”Valuable trading licenseOSL's regulatory licensing is likely to add considerably to its value. Earlier this year it emerged that digital asset sector firms were shelling out a range between HK$20 million and HK$200 million in their efforts to secure crypto trading licenses in Hong Kong.In May the company obtained Type 1, 4, and 9 licensing from Hong Kong’s Securities and Futures Commission (SFC) through its OSL Asset Management (OSLAM) business. Following the acquisition of licensing, the firm moved to launch its first fund, concentrating on blockchain, artificial intelligence (AI), and Web3 technologies.Hong Kong’s crypto hub challengesHong Kong enabled retail-level crypto trading on June 1, with the aim of further establishing the city as a hub for the cryptocurrency sector. The regulatory change enabled retail investors to trade larger tokens such as Bitcoin and Ethereum on licensed exchanges. Despite these efforts, demand for cryptocurrencies remains lackluster due to the lingering effects of last year’s wave of crypto sector bankruptcies.To compound matters, Hong Kong is also grappling with the repercussions of the JPEX exchange scandal, an unlicensed Dubai-headquartered entity that further tarnished the reputation of the digital asset industry in the region.BC Technology’s market value has shown substantial growth, surging to almost HK$1.9 billion from its low point earlier in the year. However, the company’s shares remain down by 80% from their peak in June 2021, which coincided with the cryptocurrency market’s frenzy during the pandemic.In response to market developments, OSL has withdrawn its application for a digital asset license in Singapore and it is preparing a revised submission. It’s worth noting that certain clients from Singapore are being transitioned to the exchange in Hong Kong.

news
Web3 & Enterprise·

Dec 05, 2023

Crypto.com unlocks regulated expansion through UK FCA licensing award

Crypto.com unlocks regulated expansion through UK FCA licensing awardSingapore’s Crypto.com has obtained an Electronic Money Institution (EMI) license from the Financial Conduct Authority (FCA) in the United Kingdom. The approval complements the platform’s existing status as a registered crypto-asset business, a milestone achieved in August 2022.Photo by Robert Tudor on UnsplashSet to expand product offeringIn a press release published to its website on Monday, the company outlined that the EMI license represents a pivotal step for the firm, empowering the exchange to issue and manage electronic money. This expansion goes beyond its initial crypto-asset business focus, which concentrated primarily on compliance with anti-money laundering (AML) and counter-terrorist financing (CTF) regulations.The regulatory nod came after Crypto.com underwent a comprehensive examination of its business and compliance practices, ensuring alignment with the stringent AML and CTF requirements in the UK.With this authorization in hand, Crypto.com is poised to introduce a range of e-money products tailored for the UK market. This move aligns the company with other cryptocurrency firms like Coinbase and Gemini, which have previously secured similar licenses.Notwithstanding that, while some other well-known platforms have struggled with recently introduced rules related to the marketing of crypto products and services in the UK, Crypto.com’s UK subsidiary company, FORIS DAX UK LIMITED, had successfully registered with the FCA in October.Building out global expansionWhile a trend has emerged in 2023 for crypto platforms to expand within regional markets around the world beyond the United States, Crypto.com has been following a global strategy for some time already. Last month, CRO DAX Middle East, a subsidiary company of Crypto.com, secured a license from the Virtual Assets Regulatory Authority (VARA) in Dubai to offer regulated virtual asset services.Earlier this year, Patrick Yoon, General Manager of Crypto.com’s Korean business outlined plans for expansion within that market, including the aspiration to obtain the banking relationship required in order to conduct virtual asset trading business in South Korea.Dutch licensing successEarlier in July, Crypto.com received approval from the Dutch central bank, De Nederlandsche Bank (DNB), to extend its cryptocurrency services in the Netherlands.This recognition places Crypto.com among the 36 cryptocurrency-related businesses approved by the Dutch central bank, joining major industry players like Coinbase Europe, eToro and Bitstamp. Notably, this approval followed Binance’s inability to secure registration in the Netherlands, leading to its exit from the country.Expressing enthusiasm about this achievement, Kris Marszalek, CEO of Crypto.com, emphasized the importance of the UK market for their business. He stated:“The UK has and continues to be a hugely important market for our business and the greater industry. We look forward to continuing to collaborate with a global regulatory leader in the FCA in our collective pursuit of responsible innovation for crypto.”Crypto.com’s global expansion strategy includes regulatory approvals in Singapore, France, Italy, Dubai and Australia. However, in a strategic shift, the platform discontinued its institutional exchange service for professional customers in the United States in June. Citing a decline in demand, this move aligns with the broader market conditions in the U.S., influenced by ongoing legal actions against major exchanges such as Binance and Coinbase.

news
Policy & Regulation·

Jan 27, 2024

Hong Kong raises red flag on 'Floki' and 'TokenFi' staking programs

Hong Kong's financial watchdog, the Securities and Futures Commission (SFC), has issued a stern warning against two crypto investment schemes, namely the "Floki” and “TokenFi” staking programs. Offering high annual returnsThese programs, luring investors with enticing promises of annual returns ranging from 30% to over 100%, have triggered concerns within the regulatory authority due to their lack of authorization and questionable nature. In an update issued on Friday, the SFC emphasized that both Floki and TokenFi's staking offerings have not been granted approval for public offerings. Furthermore, the administrators of these programs have failed to provide convincing explanations about the feasibility of achieving such unusually high returns. The SFC cautioned that engaging in staking arrangements involving virtual assets without proper authorization may constitute unauthorized collective investment schemes.Photo by Sigmund on UnsplashUnsustainable yieldThe watchdog expressed its worry about the legitimacy of these staking programs, highlighting that neither has received the necessary authorization to provide services to the public in Hong Kong. Investors participating in these programs would not be protected under the SFC's regulations, potentially exposing them to significant financial losses. With the failure of many crypto platforms in 2022, a number of industry commentators began to question the sustainability of some public offerings. One such commentator, Allen Farrington, General Partner at bitcoin-native venture capital firm Axiom, repeatedly asked, “Where does the yield come from?” That appears to be the SFC’s concern in this instance. In its statement, it reaffirmed its commitment to upholding regulatory standards and safeguarding investors from fraudulent schemes. It warned that any breach of the law, including the promotion of unlicensed collective investment schemes, will result in appropriate legal action. Elon Musk-inspired meme coinFloki, initially conceived as a meme-coin inspired by Dogecoin, a project associated with Elon Musk, has evolved into a comprehensive Web3 project spanning decentralized finance, NFTs and the metaverse. TokenFi is a crypto and asset tokenization platform under the Floki umbrella, which aims to capitalize on the booming trillion-dollar tokenization industry. TokenFi, denoted by the ticker TOKEN, seeks to simplify the crypto and asset tokenization process with aspirations of becoming a leading platform globally. Launched last October, TokenFi operates as a multichain tokenization platform on both Ethereum and Binance Smart Chain. While both Floki and TokenFi offer distinct staking programs, they share a close integration. Stakers under the Floki scheme gain access to a significant portion of TokenFi's supply, while TokenFi stakers earn TOKEN rewards through a user-friendly interface. In the broader context of crypto staking, the practice allows users to earn rewards by contributing to a blockchain's security through the proof-of-stake mechanism. By staking cryptocurrency, users participate in a staking pool, similar to depositing money into a savings account. Staking rewards typically range from 5-20%, attracting investors seeking profitable opportunities. However, caution is advised against schemes promising unrealistic returns. The SFC, in collaboration with the Hong Kong Police Force, established a dedicated working group last year to enhance vigilance and enforcement in the evolving crypto sector. 

news
Loading