Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jan 10, 2024

Partnerships enable AsiaNext to launch crypto derivative trading

AsiaNext, a Singapore-based institutional digital asset trading venue, has officially rolled out its cryptocurrency derivatives trading platform.Photo by Kirill Petropavlov on UnsplashWintermute and B2C2 collaborationsThe launch involves notable trading members such as Wintermute and London-headquartered liquidity provider B2C2. B2C2 is a subsidiary company of Japanese financial services conglomerate SBI Holdings. SBI acquired the company in August of last year with B2C2 expressing the view that the acquisition would represent an opportunity for the company to broaden its client base. SBI partnered with Swiss financial infrastructure firm Six Group in a joint venture to establish AsiaNext back in 2020 with a view towards driving institutional digital asset liquidity. Meanwhile, Wintermute’s involvement with AsiaNext in this instance follows its move in 2023 to expand its Singapore base, where it conducts its derivatives business. In November, Wintermute Asia conducted its first-ever options block trade through the CME Group, one of the world’s leading derivatives marketplaces. Wintermute's Founder & CEO, Evgeny Gaevoy, highlighted the significance of the partnership with AsiaNext in the context of traditional financial institutions seeking alternative exposure to digital assets. Gaevoy stated: "Partnering with AsiaNext enables us to elevate our derivatives offering, positioning Wintermute in the foreground of the expanding digital asset ecosystem." The AsiaNext platform asserts that it provides enhanced risk management with reduced counterparty and settlement risk. Additionally, AsiaNext offers capital efficiencies through intraday margining and settlement processes, supporting high-frequency trading and ensuring availability 24/7 for crypto derivatives trading. Chong Kok Kee, CEO of AsiaNext, emphasized the platform's commitment to providing a secure environment for institutional investors to explore digital assets in the region. By prioritizing regulation and rigorous governance, AsiaNext aims to establish itself as a trusted venue for exposure to digital assets. B2C2 CEO Thomas Restout commented on the positive nature of the collaboration. He stated:”We’ve witnessed [AsiaNext’s] unwavering commitment to governance and risk management, alongside their focus on aligning closely with our needs. This instills a high level of confidence in our partnership. Being at the forefront of digital asset adoption, we are pleased to provide liquidity on the venue through our collaboration.” Licensing approvalsIt's worth noting that AsiaNext obtained a Recognized Market Operator (RMO) license from the Monetary Authority of Singapore (MAS) in September. However, this license specifically pertains to tokenized securities, and as such, the crypto derivatives trading operates through a separate subsidiary. In June the company had acquired in-principle approval for a Capital Markets Services (CMS) license. On the digital securities front, SIX Digital Exchange (SDX) and Osaka Digital Exchange (ODX), operated by SIX and SBI respectively, play key roles in secondary markets, showcasing the partners' commitment to advancing regulated digital securities markets. Launched in late 2021, SDX was the world's first regulated digital securities market. SBI followed suit with the recent launch of ODX on Christmas Day. The anticipated approval of the first U.S. spot bitcoin ETFs adds a timely dimension to the launch, potentially driving increased demand for hedging strategies in the market. 

news
Policy & Regulation·

Nov 03, 2023

Abu Dhabi’s ADGM unveils DLT foundations regulations

Abu Dhabi’s ADGM unveils DLT foundations regulationsThe Registration Authority (RA) of Abu Dhabi Global Market (ADGM) has officially unveiled the Distributed Ledger Technology (DLT) Foundations Regulations 2023, marking yet another milestone in the evolution of digital assets regulatory frameworks both regionally and internationally.Photo by Kamil Rogalinski on UnsplashFramework for DAOs and foundationsThe new regulations were published to the ADGM website on Wednesday, with enactment occurring on Thursday. This legislative framework has been crafted to offer a comprehensive structure for DLT foundations and decentralized autonomous organizations (DAOs), addressing their unique operational needs within the blockchain sector. ADGM’s strategic vision to promote initiatives in the broader blockchain and digital asset sphere has culminated in the creation of this regulatory regime.As a global first of its kind, the DLT foundations regulation sets a precedent for blockchain foundations, Web3 entities, DAOs and traditional foundations seeking to enhance their operations through DLT. This forward-thinking framework is poised to provide a unified solution for digital asset-related activities and the broader foundations landscape, fostering transparency and efficiency.Establishing governance structuresThe ADGM DLT foundations regulation represents an effective means to establish governance structures while acknowledging the imperative decentralization characteristic of the industry. This regulatory development followed a robust public consultation process, actively involving stakeholders and industry participants to gather feedback and refine the regulations.In the realm of digital assets, ADGM continues to push towards taking leadership in regulatory standards, providing an attractive environment for Web3 startups. Ahmed Jasim Al Zaabi, Chairman of ADGM, emphasized the pivotal role that the DLT Foundations Regime plays in shaping the future of digital asset development. According to a press release on PR Newswire, Al Zaabi stated:“Abu Dhabi is rapidly emerging as the destination of choice for global players at the forefront of digital asset development. The introduction of the DLT Foundations Regime marks a revolutionary step forward, reinforcing ADGM’s commitment to a proactive approach rooted in extensive cross-industry dialogue and collaboration with various stakeholders. The new regime serves as a driving force for positive change in the digital assets sector. By transforming the blockchain and Web3 landscape, we are moving towards a future characterised by setting global benchmarks with enhanced transparency and efficiency.”Nurturing Web3 innovationOver the course of the past 12 months, the authorities in Abu Dhabi, alongside the United Arab Emirates (UAE) itself and other emirates such as Dubai, have been allocating resources towards developing the right conditions for the Web3 sector to flourish. In April of this year, a legislative framework was proposed by the ADGM.Recent months have seen a plethora of digital asset sector firms gain trading approval within the emirate. These included virtual asset firm M2, Standard Chartered digital asset subsidiary firm Zodia Markets and Laser Digital, the digital assets subsidiary of Japanese financial services conglomerate Nomura.By way of its DLT foundations regulations, the ADGM is attempting to go beyond simply creating a set of rules. The aspiration is to strive towards a future where the blockchain and digital asset industry operates within a transparent, efficient and globally respected framework. As blockchain technology continues to gain traction, Abu Dhabi’s ADGM is positioning itself to play a role in driving these advancements.

news
Web3 & Enterprise·

Oct 18, 2023

Wemade’s NILE Launches Ticket NFT Sales for Blockchain-Assisted Golf Tournament

Wemade’s NILE Launches Ticket NFT Sales for Blockchain-Assisted Golf TournamentNFT Is Life Evolution, better known as NILE, commenced the sale of ticket NFTs for the WEMIX Championship 2023, a women’s golf tournament in South Korea, on the NILE Marketplace at noon (local time) on October 18. NILE is a decentralized autonomous organization (DAO) and NFT platform, which operates on the WEMIX3.0 mainnet of South Korean blockchain game developer Wemade.Photo by Robert Ruggiero on UnsplashWEMIX Championship 2023The WEMIX Championship 2023, touted as the world’s first blockchain-assisted golf tournament, will take place from November 18 to 19 at Haeundae Beach Golf and Resort in Busan. The sports event will see participation from 24 players who are members of the Korea Ladies Professional Golf Association (KLPGA), including the top 20 athletes with the most WEMIX points, as they vie for victory in the season-ending competition.Ticket NFTs for perksThe competition is leveraging blockchain technology across all its operations. Specifically, NILE is introducing Real World Event NFTs, which consist of two main types: “ticket NFTs,” which serve as admission tickets and vouchers, and “prize NFTs,” which are awarded to the competition’s winners.Ticket NFTs are dynamic NFTs that provide a range of benefits depending on the selected tier. These benefits encompass souvenirs, food vouchers, and access to VIP-reserved facilities. There are two tiers to choose from: GROUND and NILE Suite. Golf enthusiasts can purchase these NFTs using WEMIX dollars (WEMIX$) through either the WEMIX Wallet or the una Wallet.In addition, ticket NFT holders can verify their NFTs on the decentralized communication platform, PAPYRUS, to join a special channel dedicated to the WEMIX Championship 2023, where spectators can stay informed about the latest competition news and engage in real-time interactions with one another.Looking ahead, Wemade plans to introduce additional sports events that utilize blockchain technology, aiming to provide fresh and engaging experiences while fostering a culture where both athletes and fans can fully enjoy sports competitions.

news
Loading