Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Aug 24, 2023

Fake Security Tokens Linked to HD Hyundai Oilbank in Circulation

Fake Security Tokens Linked to HD Hyundai Oilbank in CirculationHD Hyundai Oilbank, one of South Korea’s leading refiners, said Wednesday that a counterfeit security token dubbed “HOBT” claiming affiliation to the company has been circulating online. The token is allegedly based on old stock certificates under the company’s former name, Hyundai Oil Refinery, as the underlying assets, though the company had changed its name to HD Hyundai Oilbank back in 2002. Both the token and the underlying asset are invalid and have no relation at all to HD Hyundai Oilbank, the company emphasized, so investors must exercise caution.Fraudulent promotionEntities that are giving away or selling HBOT tokens are attracting investors by promoting a one-on-one exchange of the tokens for old Hyundai Oil Refinery stock certificates. They are also promising to grant shareholder rights through blockchain technology as well as interest payments of 4% every month for a total of 24% over six months.Fraudulent activities like these have recently been on the rise following the legalization of security tokens and the formal issuance of a select few tokens.Investigative measuresThe Incheon Metropolitan Police is currently conducting an investigation into the case. Notably, the old Hyundai Oil Refinery stock certificates that the involved entities are claiming to be underlying assets have been proven to be fake in over ten court rulings. Although owners of these old stock certificates had filed lawsuits against the company related to shareholder registration renewals since the late 2000s, all of them had lost their cases.Photo by Tingey Injury Law Firm on UnsplashPast events resurfacingThis recent circulation of the forged HOBT tokens is attributed to employees of a disposal company who pocketed the invalid stock certificates and certificate papers, rather than disposing of them as they were required to do.In January 2002, HD Hyundai Oilbank had hired a company to dispose of documents — including those related to the old stock certificates — that had lost their validity during the process of attracting and increasing foreign capital.“In May of that year, we started receiving frequent inquiries about the stock certificates. We filed a legal complaint against the employees and conspirators of the disposal company for illegally distributing the certificates (including the stock certificate papers), and they were subsequently punished for theft and fraud,” the company explained.

news
Web3 & Enterprise·

Nov 23, 2023

Wintermute Asia executes inaugural options block trade via CME

Wintermute Asia executes inaugural options block trade via CMEWintermute Asia Pte. Ltd, the digital asset derivatives trading arm of the well-known algorithmic trading firm and crypto market maker Wintermute Group, has successfully executed its first options block trade through the CME Group.The BTC/USD block trade was conducted in collaboration with U.K.-based liquidity and data solutions specialist TP ICAP. It was successfully cleared by ABN AMRO, marking a significant milestone for Wintermute Asia in the digital assets space.Photo by Kanchanara on UnsplashMeeting institutional investor needsInstitutional interest in secure and alternative avenues for exposure to digital assets continues to build momentum. It’s likely with that in mind that Wintermute Asia is strategically expanding its derivatives product offerings with this latest move. It’s also no surprise that Wintermute’s Singapore-based team was involved in this development, given a recent expansion of its Singapore base and the fact that its derivatives business is dealt with in Singapore.Presently, Wintermute Asia provides vanilla options in BTC, ETH and various altcoins, featuring expiration periods ranging from 1 day to 6 months. The platform also caters to more sophisticated needs with the inclusion of exotic options.Evgeny Gaevoy, CEO of Wintermute Group, expressed enthusiasm about Wintermute Asia’s evolving product offering, stating:“Wintermute Asia is excited to offer a range of OTC derivatives solutions to our counterparties that can accommodate all of their trading needs. Our growing suite of derivative instruments allows investors to easily hedge and manage risks, generate yield, and gain synthetic exposure to the underlying digital assets.”The move towards facilitating options block trades aligns with the increasing diversification of institutional portfolios into the digital asset sector. Giovanni Vicioso, Global Head of Cryptocurrency Products at CME Group, emphasized the significance of the partnership with Wintermute Asia. He commented:“We are pleased to provide Wintermute and its counterparties with access to our highly liquid, regulated suite of benchmark cryptocurrency futures and options on bitcoin and ether.”Involving TradFi heavyweightsCME is a cornerstone TradFi financial derivatives exchange, first established in 1898 and headquartered in Chicago in the United States. Its CEO Terry Duffy pushed back against proposals from convicted fraudster and FTX Founder Sam Bankman Fried in 2022 to alter the futures clearing model on the basis that such a move would introduce significant risk into the financial system. A year on from the failure of FTX and many other crypto platforms, a move towards involving established TradFi firms like CME, as Wintermute is doing, is far more appealing to institutional investors.Sam Newman, Digital Assets Head of Broking at TP ICAP, acknowledged Wintermute as another participant in block trading CME Group cryptocurrency products. TP ICAP, a key player in digital asset broking services since 2020, has been instrumental in price discovery and liquidity through global coverage on regulated exchanges. Newman expressed excitement about witnessing crypto-native firms like Wintermute accessing traditional products and services, indicating the market’s maturation.Earlier this year, CME Group upgraded its BrokerTec Stream from version 1.5 to 2.0. The upgrade aims to enhance performance and reduce latency for clients, introducing features such as sweepable matching and firm price improvements. Recently, CME became the second largest bitcoin futures exchange, second only to global crypto exchange Binance.

news
Policy & Regulation·

Oct 25, 2023

As Excitement for First US Spot Bitcoin ETF Intensifies, South Korea Still Faces Mountain to Climb

As Excitement for First US Spot Bitcoin ETF Intensifies, South Korea Still Faces Mountain to ClimbThe price of bitcoin has surged significantly as it recorded an 18% increase in the past week, spurred by mounting anticipation surrounding the US’ first spot bitcoin exchange-traded fund (ETF) propelled by asset management juggernauts BlackRock and Fidelity Investments — a threshold that had not been crossed in over a year. According to CoinMarketCap, bitcoin is trading in the upper $33,000 range as of 5 p.m. KST on Wednesday.Photo by André François McKenzie on UnsplashOngoing buildupThe approval of a spot bitcoin ETF — long rejected or delayed due to a plethora of reasons like the volatility of cryptocurrencies and their susceptibility to market manipulation — would in the long run open up the possibility for institutions to earmark bitcoin as a major asset that can be integrated into the sphere of traditional finance. This would make bitcoin easier to handle and increase its exposure to traditional investors. “The mere possibility of this development marks a significant shift in the market landscape,” said an unnamed executive at a Korean asset management company in a news article by South Korean news outlet Maeil Business Newspaper.BlackRock’s spot bitcoin ETF, the iShares Bitcoin Trust, was also listed on the US Depository Trust & Clearing Corporation (DTCC)’s website with the ticker symbol IBTC on Monday before it mysteriously disappeared the following day. It has since been relisted on the website. The listing is “all part of the process of bringing ETF to market”, as explained by Bloomberg’s senior ETF analyst Eric Balchunas via his X (formerly Twitter) account on Tuesday.Is a spot bitcoin ETF on the table for Korea?However, Korean experts believe that there are still numerous hurdles to overcome in order for a spot bitcoin ETF to settle in Korea. In particular, some question whether cryptocurrency platforms that offer custodial services can even be classified as exchanges. There is also the issue of bitcoin’s varying prices across different exchanges. Its current price on Upbit, the country’s largest crypto exchange, is in the KRW 45.9 million range as of 5 p.m. on Wednesday. Local financial authorities have reportedly expressed skepticism about bitcoin ETFs for these reasons, suggesting a murky future for this development becoming a reality in Korea.

news
Loading