Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Sep 07, 2023

Zodia Markets Achieves Crypto Broker-Dealer Approval in UAE

Zodia Markets Achieves Crypto Broker-Dealer Approval in UAEZodia Markets, the London-based digital asset marketplace backed by Standard Chartered Ventures, has achieved the milestone of receiving In-Principle Approval (IPA) to operate as a cryptocurrency broker-dealer in Abu Dhabi’s over-the-counter (OTC) market.Photo by Kamil Rogalinski on UnsplashADGM green lightThat’s according to a press release published by Zawya, a business intelligence media outlet that covers the Middle East and North Africa (MENA) region. The regulatory approval comes from the Abu Dhabi Global Market (ADGM), a renowned financial hub in the United Arab Emirates (UAE).Salem Mohammed Al Darei, CEO of the ADGM Authority, extended his congratulations to Zodia Markets on this achievement and welcomed them into the ADGM ecosystem. The In-Principle Approval marks the third step in a comprehensive five-stage application process outlined by ADGM. The subsequent stages involve securing final approval and undergoing an “operational launch” test to ensure seamless functionality, with a need to follow ADGM’s guidance meticulously.“The harmony of traditional and new-age finance in Abu Dhabi with an international leading digital asset firm such as Zodia Markets that is backed by the well-established Standard Chartered will contribute to further enhancing the attractiveness of ADGM as a preferred destination for global entities,” Al Darei stated.Expanding global footprintZodia Markets’ strategic decision to enter the UAE market aligns with the growing prominence of the UAE in the digital assets industry. This move compliments Zodia Custody’s decision to launch a crypto custodian service in the UAE emirate of Dubai back in May. While both businesses are independent of each other and fully segregated, they share the very same parent company in Standard Chartered.At the time, a memorandum of understanding (MoU) was signed by parent company Standard Chartered alongside the Dubai International Financial Center (DIFC).This latest move bolsters the geographical presence of Zodia Markets but also provides institutional investors in the Middle East and Africa with convenient access to the world of digital assets, thereby strengthening the company’s global footprint in the digital asset space.News of the firm’s intentions to enter the UAE market emerged last November. The company’s thinking at the time was that it could exploit an opportunity to expand in the MENA region due to more progressive regulation while the US and Europe were perceived to be developing at a much slower pace from a regulatory point of view, making them unattractive comparatively.ADGM has been at the forefront of shaping the regulatory landscape for companies involved in virtual assets. In April, it put forward a legal framework for decentralized tech. As part of its commitment to fostering innovation, ADGM recently granted permission for the operation of a virtual asset platform named M2 and issued a license to the cryptocurrency exchange Rain in July.Usman Ahmad, CEO of Zodia Markets, articulated the company’s mission, stating:“Our goal is to provide institutions seamless access to trade digital assets without compromising on the standards and controls that exist in traditional financial markets.”Zodia Markets is a joint venture between Standard Chartered and Hong Kong-based digital assets platform OSL, which also expressed its enthusiasm for the In-Principle Approval.

news
Policy & Regulation·

Dec 07, 2023

Japan mulls unrealized crypto gains tax exemption

Japan mulls unrealized crypto gains tax exemptionJapanese lawmakers are currently in discussions about a proposal that could exempt companies from paying taxes on unrealized cryptocurrency gains.Photo by Joshua Tan on UnsplashReforming aggressive crypto tax policyThe plan is anticipated to be incorporated into the fiscal 2024 tax reform agenda, according to a report published by Nikkei Asia on Wednesday.Up until now, Japan has had some of the most aggressive tax rates where cryptocurrencies are concerned when compared internationally. At the moment, corporations have to pay a 30% tax on crypto holdings regardless of whether they’ve sold those digital assets or not. The policy has been criticized broadly by crypto sector participants in Japan. It is seen as inequitable, considering that Japan taxes profits from stocks at a flat 20%.Corporate tax exemptionThe proposal, currently under deliberation by Japan’s ruling coalition, specifically targets Japanese companies holding digital assets for purposes other than short-term trading. If approved, these firms may be granted an exemption from corporate tax, contingent on mark-to-market valuations at the close of the fiscal year.Mark-to-market valuations involve assessing the fair values of assets with periodic fluctuations, such as cryptocurrencies. This exemption is expected to benefit various entities, including venture capital (VC) firms, non-fungible token (NFT) businesses and other blockchain companies holding cryptocurrencies for payment purposes. Additionally, crypto issuers, who are also crypto holders, would not be subjected to these taxes.Policymakers from the Liberal Democratic Party and the ruling coalition partner Komeito engaged in discussions on Tuesday regarding these potential tax exemptions.Bringing clarity to crypto taxationThis move is part of Japan’s ongoing efforts to bring clarity to crypto taxation. In June, the National Tax Agency clarified that crypto issuers in the country would not be liable to pay capital gains taxes on unrealized gains, fostering a more conducive environment for crypto-related businesses.Japan has been actively reviewing its crypto tax policies since last year, aiming to incentivize companies to stay in the country. This initiative follows the departure of several startups due to heavy tax burdens.Industry reactionWith news of this potential Japanese crypto tax reform breaking, crypto community members haven’t wasted any time in providing their thoughts. Taking to the X social media platform, Sota Watanabe, the founder of the Astar Network multichain dApp hub, wrote:”Good move. This is what I requested multiple times to the government over years. Once this issue is solved this year, all companies, especially big enterprises, can hodl crypto like ASTR much easier. Japan weighs ending tax on some corporate crypto holdings.”Former Goldman Sachs Portfolio Manager and Web3 investor, Steve Lee, said that this is “another big move in Japan that would help enterprises push their crypto business.”The Financial Services Agency (FSA), Japan’s top financial regulator, recently submitted legislation-change requests to the government, seeking alterations to the taxation of domestic crypto firms. Critics argue that the existing rule has impeded innovation in the crypto-asset and blockchain sectors, placing an undue burden on companies.On Oct. 16, major businesses in Japan, through the Japan Association of New Economy (JANE), urged the government to implement crypto tax reforms in 2024. Their appeal emphasizes the potential for reduced tax rates to stimulate growth and increase tax revenue.

news
Policy & Regulation·

Dec 09, 2023

Taiwan weighs up CBDC following feasibility study completion

Taiwan weighs up CBDC following feasibility study completionTaiwan’s central bank, the Central Bank of the Republic of China (Taiwan), recently concluded an in-depth feasibility and technology study on the potential implementation of a wholesale central bank digital currency (CBDC).Photo by Timo Volz on UnsplashGathering feedback and refining designAccording to statements made by Deputy Governor Chu Mei-lie while speaking at an annual event organized for the banking sector by the Financial Information Service Co., an entity that oversees Taiwan’s banking, payment and settlement systems, Chu disclosed that the central bank is now in the process of gathering feedback and refining the design of the CBDC platform.In her keynote speech, Chu underscored the significance of CBDCs in the evolving landscape of digital currencies. She concurred with the Bank for International Settlements’ (BIS) assertion that conventional payment tools and platforms may not always meet the demands of all-day transactions, smart contracts and automatic settlements facilitating simultaneous and irreversible transfers of assets or funds.Supporting asset tokenizationChu emphasized that a nation’s monetary system should be poised to support tokenized assets. CBDCs, she suggested, could potentially offer comprehensive payment and settlement services, integrating tokenization and a unified ledger that harmonizes CBDCs with traditional currencies.The concept of a unified ledger, as explained by Chu, doesn’t imply a single ledger but rather that tokenized ledgers of each economy could coexist and connect through an application interface.This approach aims to ensure interoperability, minimizing the risk of errors in message transmission. Interoperability is also being worked on by financial messaging service SWIFT. It recently collaborated with central banks in Hong Kong and Kazakhstan with a view towards testing a connector that would enable the integration of SWIFT with CBDCs.Additionally, a unified ledger is anticipated to expedite the clearing process, foster a secure trading environment and ensure the safe, reliable and effective execution of currency and asset transactions.International integration of e-CNYChu acknowledged that foreign central banks are actively exploring the feasibility of issuing CBDCs to establish a unified value for all forms of currency. Of the many early-stage CBDC projects that are out there, China’s e-CNY has gathered the greatest momentum.British bank Standard Chartered has been the most recent entity to join the Chinese CBDC international pilot project. Taiwan’s Fubon Bank has enabled its customers to top up e-CNY via mobile banking. The leading CBDC currency has similar collaborations in place with Hong Kong banks, HSBC and Hang Seng Bank.Fubon has also gotten involved alongside Ripple in a pilot program run by the Hong Kong Monetary Authority. Through that collaboration, it is supporting an asset tokenization trial that revolves around Hong Kong’s CBDC, the e-HKD.Chu outlined that in the case of Taiwan, the matter of a CBDC is being pursued cautiously, without a predefined timetable for reaching a conclusion. The monetary policymaker plans to engage in discussions with academic and business sectors to inform its stance on CBDCs.Meanwhile, the central bank is committed to enhancing overall planning related to the CBDC platform, focusing on transaction ease, capacity and innovative functionalities. Chu also highlighted the consideration of offline transaction scenarios in this ongoing process.

news
Loading