Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Policy & Regulation·

May 16, 2024

China busts underground bank conducting illegal currency exchanges via crypto

China's authorities have dismantled an underground bank that illicitly utilized cryptocurrency for currency exchange operations between the Chinese yuan and the South Korean won, involving approximately 2.14 billion yuan ($295.8 million). China has a history of imposing strict capital control policies, prompting some individuals and entities to resort to cryptocurrency as a means of bypassing these regulations. According to a report published by local police in Northeast China’s Jilin province, six suspects were apprehended for their alleged involvement in facilitating the illegal operations spanning China and South Korea.Photo by Hyory Liu on UnsplashExploiting cryptocurrency featuresThe suspects purportedly took advantage of cryptocurrency features like transaction anonymity and decentralization to execute foreign currency exchange activities unlawfully. Investigations revealed that the criminal group utilized domestic accounts for fund receipt and transfer, alongside over-the-counter cryptocurrency transactions. Supporting illicit transactionsThe arrested individuals allegedly aided various entities, including South Korean purchasing agents, cross-border e-commerce platforms and import-export trade firms, in circumventing currency exchange regulations between the Chinese yuan and the South Korean won. 

news
Web3 & Enterprise·

Jul 25, 2024

HKX latest exchange to drop out of Hong Kong market

HKX management has advised Hong Kong resident users of the platform to withdraw assets following the company’s decision to halt operations in Hong Kong.  The company publicized its decision on July 18, making the following statement on its website: “We would like to inform you that our management team has, after careful consideration, decided to withdraw our application for the Type 1 and Type 7 licenses under the Securities and Futures Ordinance (Cap. 571) and the virtual asset service provider license under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615).”Photo by Zhe ZHANG on UnsplashCompliance strugglesHKX’s exit from Hong Kong is the latest in a series of crypto exchange withdrawals from the Chinese autonomous territory. Other exchanges such as OKX, KuCoin, Gate.io and Binance had all bowed out back in May.  HKX initially applied for a Hong Kong license in February. However, like many others, the exchange failed to comply with Hong Kong’s regulatory requirements. While Hong Kong has been making a concerted effort to establish a regulatory framework and licensing system in order to create the conditions for it to become a crypto hub, it has also been grappling with making regulations strict enough to stamp out fraud in the wake of the JPEX exchange scandal. With that, it appears that many exchanges are finding the regulatory requirements difficult to live with. Originally, 24 exchanges had applied for a virtual asset trading platform (VATP) license. As it stands today, 12 of those original applicants have dropped out, with one more having its application returned with no clarity emerging as to the reason why. HKX has suspended new user registrations. The company’s management has not suggested that they will reapply for a license and reboot the service at a later stage. The company had flagged its intentions back in May, suspending trading and deposit services on May 29. OKX announced on May 24 that it was withdrawing from the Hong Kong market, citing a review of its business strategy. Around the same timeframe, Gate.io withdrew from the market in Hong Kong having failed to achieve compliance in accordance with the new licensing requirements.  Notwithstanding that outcome, the firm suggested that it planned to revamp its platform in line with the Chinese autonomous territory’s licensing requirements, and return to the market once that had been achieved. In a notice posted to its website on May 22, it stated: “Gate.HK is actively working on the aforementioned overhaul. We plan to resume our business in Hong Kong in the future and contribute to the virtual asset ecosystem after obtaining the relevant licenses.” That overhaul has yet to be completed as right now, the platform only allows the withdrawal of funds by its previous Hong Kong-based customers. Back in May 2023, Eddie Yue, the CEO of the Hong Kong Monetary Authority, suggested that there would be no light touch regulation in Hong Kong. HashKey Exchange, alongside OSL, was the first business to secure licensing under the new framework. In April, HasKey CEO Livio Weng told the Financial Times that these regulations block access to overseas investors while the local market in Hong Kong isn’t very big. It emerged in recent weeks that Hong Kong regulators are reviewing whether crypto regulation is “excessively stringent.” 

news
Policy & Regulation·

Dec 19, 2023

Kazakhstan sets sights on 2024 expansion amid CBDC pilot success

Kazakhstan sets sights on 2024 expansion amid CBDC pilot successKazakhstan’s central bank digital currency (CBDC), the digital tenge, has completed a one-month pilot project, paving the way for significant advancements in business, regulation and technology in 2024.Photo by Nessi Gileva on UnsplashReal-world use through Onay cardThe National Bank of Kazakhstan (NBK) established the National Payment Corporation (NPK) in September. NPK is a dedicated entity that’s responsible for spearheading the launch and development of the digital tenge.At that time, the CBDC pilot phase had advanced to controlled environment use. Global exchange Binance has been actively involved with the project. It supported the pilot by way of its BNB Chain.During the pilot phase, the digital tenge played a pivotal role in providing free school lunches to children in Almaty, Kazakhstan’s largest city. The initiative utilized the local Onay card, initially designed for the transit system and transactions were facilitated by Kazpost, the Kazakh postal system operator.Local banking partnersNPC Chairman Binur Zhalenov became the first person to transact using the digital tenge in November. At the time, it was revealed that Eurasian Bank was one of the local banking participants on the project.Eurasian collaborated with Visa and Mastercard, alongside three other local banks, distributing plastic cards to focus group members. These cards empowered users to make both in-person and online purchases, with the added functionality of cash withdrawals from ATMs.Participating merchants were given the flexibility to accept digital tenge directly or convert them into “non-cash” tenge. The converted funds seamlessly integrated into existing point-of-sale (POS) and QR systems, demonstrating interoperability within and outside Kazakhstan.The success extended beyond local transactions, with further experiments involving cross-border payments via SWIFT, issuance of CBDC-backed stablecoins on platforms like Binance and the Kazakhstan Stock Exchange, tokenization of gold, value-added tax collection through smart contracts and the trial of a “move-to-earn” app.New objectivesWith an eye on the upcoming year, the National Bank of Kazakhstan and the National Payment Corporation (NPC) have set ambitious objectives. Plans include expanding the network of intermediary banks and advancing decentralized finance applications. A primary focus is on enabling offline transactions on a large scale to enhance financial inclusion in regions with limited internet connectivity.Anticipated developments also include increased participation in cross-border payment projects, such as Project mBridge, an experimental multi-CBDC platform being coordinated and developed by the central bank of central banks, the Bank for International Settlements. Regulatory and legislative goals are on the agenda, alongside efforts to enhance the security and processing speed of the digital tenge.While addressing privacy concerns, Zhalenov emphasized in interviews that the digital tenge will not be utilized for user surveillance. Previously, Zhalenov has also alluded to the versatility of the digital tenge due to its programmable nature, citing smart contracts in particular as having great potential.The successful pilot project and the ambitious plans for 2024 position Kazakhstan’s digital tenge as a promising development in the realm of CBDCs, showcasing the central Asian nation’s positive approach to innovation and financial inclusivity.

news
Loading