Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Oct 13, 2023

Japan’s Aozora Bank Plans Digital Currency Launch

Japan’s Aozora Bank Plans Digital Currency LaunchGMO Aozora Net Bank, a Japanese commercial bank and a member of a Japanese corporate consortium comprising over 100 members, has unveiled plans to introduce a blockchain-based digital currency known as DCJPY.Photo by David Edelstein on UnsplashDCJPYAccording to Reuters, the blockchain-based digital currency is scheduled for launch in July of the upcoming year. DCJPY will be a Japanese yen-based stablecoin, underpinned by deposits and harnessing blockchain technology to enable instantaneous and seamless transactions. Unlike conventional transfer methods that rely on a bank’s data system, DCJPY circumvents this process via a blockchain network, leading to a reduction in associated costs.Efficient inter-company paymentsThe primary objective of Aozora Bank’s venture is to streamline payments between businesses. The incorporation of blockchain technology offers a secure, transparent, and efficient transaction framework. By adopting this digital currency, companies can experience the advantages of swift settlements while concurrently mitigating the financial outlays tied to traditional banking systems.This consortium recognizes the vast potential of blockchain technology and is seeking to harness its inherent benefits to enhance diverse business operations. With the upcoming launch of DCJPY, the consortium will effectively be promoting the use of blockchain-based digital currencies within Japan and catalyzing innovation within the financial sector. The project has the potential to bring about heightened efficiency, cost reductions, and an overall enhancement in the realm of financial transactions.Banking heavyweightsThis move by Aozora aligns with the global surge in interest and adoption of blockchain technology. The bank operates as a prominent member of a broader consortium, which encompasses a multitude of Japanese corporations. The consortium includes major players in Japanese banking, including Mitsubishi UFJ Financial Group (MUFG), Mizuho Financial Group, and Sumitomo Mitsui Financial Group. It has been meeting frequently to assess ways in which it can build a common settlement infrastructure for digital payments.MUFG is already deeply involved in blockchain-based innovation. The banking group has established its very own Progmat blockchain tokenization platform, which includes the Progmat Coin stablecoin platform.Last month, the bank announced a partnership with Binance which will endeavor to investigate the issuance of public blockchain stablecoins based on the Japanese yen. MUFG’s Progmat includes Mizuho as one of its clients on the blockchain platform.Stablecoin regulationThese recent announcements and Aozora Bank’s stablecoin plans follow the passage of a bill by Japan’s parliament earlier this year that restricts stablecoin issuance by non-banking institutions. The bill stipulates that only licensed banks, trust companies, and registered money transfer agents are permitted to issue stablecoins. Furthermore, it establishes a registration system for financial institutions planning to launch such digital assets, accompanied by anti-money laundering measures.A report published by Nikkei Asia earlier this year suggested that three Japanese banks, namely Shikoku Bank, Tokyo Kiraboshi, and Minna Bank, had all expressed the intention to issue stablecoins. In June, Japanese global information technology solutions company Fujitsu announced that it intended to launch a blockchain-based platform in conjunction with the Asian Development Bank.

news
Web3 & Enterprise·

Oct 27, 2023

Fair Square Lab to Develop Blockchain-Based Shareholder Meeting Platform

Fair Square Lab to Develop Blockchain-Based Shareholder Meeting PlatformSouth Korean Web3 technology company Fair Square Lab announced on Friday that it is in the process of developing a blockchain-based platform for holding electronic shareholder general meetings. The firm said that it has applied for two patents for technologies related to blockchain-based electronic shareholder meetings. One is related to their operation methods and systems, and the other is associated with the utilization of voting rights tokens.Photo by Benjamin Child on UnsplashEmpowering shareholdersIn shareholder general meetings, many minority shareholders are often unable to attend in person, thereby finding it difficult to effectively exercise their opinions or rights during the decision-making process of a company. Fair Square Lab’s pending patents aim to address this issue by enabling more shareholders to easily participate in shareholder meetings through an electronic medium. Utilizing blockchain technology would also ensure the integrity and security of voting processes.Fair Square Lab’s growing portfolioWith this latest development, Fair Square Lab is now poised to possess a total of eight blockchain-related patents. Its other patents encompass areas like managing wallets in the blockchain network, generating wallet addresses for security token platforms, and preventing erroneous transfers of security tokens on a blockchain network. The company said that it is continuously working to secure intellectual property rights for its blockchain business, including design patents and its own trademark.“We have been consistently striving to secure intellectual property rights by linking research and development with the core blockchain technologies that we have accumulated over the years. We plan to obtain a total of 12 core technology patents by the end of this year,” said Jake Kim, CEO of Fair Square Lab.

news
Web3 & Enterprise·

Jul 19, 2023

Strategic Partnership Sees BitKeep Add Mantle Network Support

Strategic Partnership Sees BitKeep Add Mantle Network SupportBitKeep, a Singapore-centric multi-chain wallet project, has recently formed a strategic partnership with Mantle Network, an Ethereum Layer 2 modular network developed by BitDAO.According to a tweet posted by BitKeep on Monday, the collaboration brings with it the opportunity for BitKeep users to now manage and transact their assets on Mantle Network directly through their wallets.The latest version update of the BitKeep wallet incorporates support to enable users to store, transfer, and trade on-chain assets seamlessly within the wallet. This integration streamlines the user experience and provides easy access to the functionalities offered by Mantle Network.Photo by Shubham Dhage on Unsplash10,000 USDT prize poolTo celebrate this partnership and promote the growth of the Mantle ecosystem, BitKeep has announced a campaign open to all Web3 users. The campaign features a prize pool of 10,000 USDT, adding an element of excitement for participants. Additionally, BitKeep plans to further expand the ecosystem by integrating more DApps based on Mantle Network, ensuring diverse offerings and attracting users from various angles.Although at a corporate level, BitKeep is headquartered in the Cayman Islands, leading members of its project team including Founder Kevin Como are based in Singapore.Mainnet alpha releaseMeanwhile, Mantle Network has reached a major milestone by unveiling its highly anticipated mainnet alpha. The announcement took place at the Ethereum Community Conference (EthCC) in Paris, following an extensive six-month testnet phase. Mantle Network, as the first Ethereum layer-2 chain incubated and governed by a decentralized autonomous organization (DAO), has already gained attention for its innovative approach.With its modular design, Mantle Network separates key components such as execution, data availability, consensus, and settlement into distinct layers. By employing optimistic roll-up technology and leveraging Ethereum’s network for security, Mantle Network achieves efficient transaction processing at a lower cost and higher throughput compared to Ethereum itself.This unique architecture has been validated during the testnet phase, handling over 14 million on-chain transactions and facilitating the deployment of more than 140,000 smart contracts.$200 million EcoFundThe mainnet launch also marks the activation of a $200 million EcoFund, which aims to fuel the growth and development of the Mantle ecosystem. This substantial fund will support the ecosystem’s progress, ensuring resources are available to drive innovation and attract developers.Moreover, the merger between Mantle Network and BitDAO has created the Mantle Ecosystem, a unified Web3 ecosystem led by a DAO. Under the Mantle.xyz brand, this collaboration harnesses the strengths and resources of both entities. The merger bolsters the tokenized governance system, empowering token holders to govern the use and allocation of the significant treasury inherited from BitDAO.As BitKeep integrates Mantle Network into its wallet, users can expect an enhanced experience and increased accessibility to the Mantle ecosystem. Meanwhile, Mantle Network’s mainnet launch and the activation of the EcoFund signify significant milestones that lay the foundation for continued growth and development in the DeFi space.

news
Loading