Top

CoinEx Reveals Insights Into Recent Platform Hack

Policy & Regulation·September 20, 2023, 1:33 AM

Hong Kong crypto exchange CoinEx has issued a further update relative to the security breach that occurred on the platform last week resulting in one of the exchange’s hot wallets being compromised.

Photo by FLY:D on Unsplash

 

Immediate response

In the immediate aftermath of the $70 million hack, CoinEx took action to safeguard user assets and initiate an investigation into the incident. It suspended all deposit and withdrawal services and executed an emergency shutdown of the hot wallet server. Following this, the company securely moved the remaining assets to cold storage, commencing the process of reconstructing and deploying a new wallet architecture.

The firm also engaged in an investigation, spearheaded by its wallet and security teams, to ascertain the extent of the breach. Moreover, CoinEx claims to have proactively reached out to fellow exchanges to freeze any assets related to the attack.

Haipo Yang, the Founder and CEO of CoinEx, conveyed his apologies to affected users through his personal X (formerly Twitter) account. He emphasized the team’s commitment to restoring services promptly and reassured users that their funds will remain secure.

Following up on that commitment, CoinEx published an update on the hot wallet hack on September 15 to address these concerns individually.

 

New wallet deployment

The exchange expects to finalize wallet upgrades within the upcoming week, after which withdrawals will gradually be phased in, subject to security evaluations. The CoinEx team is currently working on developing and deploying an entirely new and robust wallet system capable of managing activities across 211 chains and 737 assets.

The firm has outlined that each of its product lines operates independently, featuring its own risk control system. Consequently, the security incident that occurred on CoinEx will not affect the integrity of its other product lines.

In its most recent update on Tuesday, the Hong Kong crypto exchange confirmed that 80% of its wallet system has now been reconstructed. It added that it has initiated preparations to enable the withdrawal system on the platform. It stated:

”Details about the resumption of withdrawals, including specific dates, times, and arrangements, will be announced on the CoinEx website. Please stay updated on our announcements for the latest information.”

 

Ongoing investigation

Regarding the identity of the attacker, CoinEx has confirmed that the matter is currently under investigation. While some security firms have made attribution claims, the company is focusing primarily on deploying the new wallet architecture, restoring affected users and functionalities, and enhancing overall security.

At the same time, the company has initiated communications with the hackers in a bid to proactively seek a mutually agreeable resolution. While the incident implicates the loss of a substantial amount of funds, the firm maintains that in the context of the overall business, the sum represents only a small percentage of total assets under its management.

Exchange security remains a major challenge in the crypto sector, with hacks happening on an ongoing basis. Last week, Seychelles-headquartered peer-to-peer crypto platform Remitano acknowledged a $2.7 million hack. At the beginning of September, crypto gambling platform Stake was reported to have suffered a $41 million hack.

More to Read
View All
Web3 & Enterprise·

Apr 24, 2023

OPNX Confirms Significant VC Backing

Newly founded bankruptcy claim trading platform OPNX has provided further details about the entities backing the fledgling startup. Taking to Twitter on Friday, Open Exchange CEO Leslie Lamb outlined a number of venture capital backers, with a mixture of international and Asia-centric firms among them. Global backersLamb’s tweet via the firm’s official Twitter account, together with a similar announcement published to the firm’s website, outlined AppWorks, a leading Taiwanese venture capital firm and startup accelerator, as an investor in the company. Other Asian backers include Hong Kong-based crypto fund, Token Bay Capital and the Hong Kong-based arm of one of China’s largest banks, China Merchant Bank International.With the firm based in Dubai, Middle-Eastern interest is represented through the involvement of Saudi digital asset fund, Tuwaiq Limited. Otherwise, the company lists a number of other international backers, including US equity options exchange MIAX Group, DeFi-focused venture and trading firm Nascent, top tier global venture capital firm Susquehanna and the investment arm of market maker and early stage investor, DRW. Questionable founding teamOnly hours after the disclosure by Open Exchange, DRW reached out to CoinDesk to confirm that it is not an investor in the bankruptcy claims exchange. Nascent and Susquehanna also denied that they are involved. The companies are still being listed by OPNX as backers of the project on its website.The launch of OPNX has been mired in controversy from the outset as its founding team includes the founders of the former crypto hedge fund Three Arrows Capital (3AC) which failed spectacularly in 2022. Su Zhu and Kyle Davies, the founders of 3AC are now the founders behind OPNX. Before their involvement, OPNX was preceded by Seychelles-based crypto yield platform CoinFLEX. That business also failed during the 2022 crypto bear market. It entered into a restructuring process with the consent of the courts in the Seychelles. Emerging from it is OPNX with the 3AC duo of Zhu and Davies having gotten involved at that point. Industry push-backMany in the crypto space have been highly critical of the development of OPNX on the basis of the involvement of both Zhu and Davies. The duo are being blamed for the collapse of the crypto hedge fund due to mismanagement and the knock on effects the firm’s demise had on other entities within crypto. Many of the series of crypto lenders who failed at a later stage in 2022 had major exposure to the wayward hedge fund.There had been some speculation as to who was backing the new project. Earlier this month, BitMEX co-founder and former CEO Arthur Hayes claimed that the 3AC duo had received substantial funding from Bahrain’s sovereign wealth fund to establish the project. In February, Hayes suggested that the crypto bull market must be starting based on news of Zhu and Davies wanting to launch the OPNX platform.Crypto-focused venture capitalist Michael Arrington also spoke out around that time, stating on Twitter, that 3AC founders successfully raising capital for their latest venture was “the saddest bulls**t I’ve heard in a long time.”Upon its launch earlier this month, industry commentators quickly declared the project a flop citing a trading volume of $13.64 on its first day of trading. Five days in, OPNX made light of the situation, declaring a win on the basis that it had progressed to $12,398 in trading volume, representing a 90,000% increase in trading.Dubai’s Virtual Assets Regulatory Authority (VARA) issued an investor and marketplace alert on April 12 stating that while OPNX may be Dubai-based, it is not regulated by VARA and instead operates on an unregulated basis. It warned investors against using any unregulated crypto entity.

news
Policy & Regulation·

Jan 17, 2024

Crypto exchange Flybit passes post-audit for ISMS-P certification

South Korean cryptocurrency exchange Flybit, which is operated by the Korean Fintech Industry Association, has passed the post-audit for its Information Security and Privacy Management System certification (ISMS-P), according to local news website News1 on Wednesday (KST).Photo by FlyD on UnsplashRigorous certification standardsThe ISMS-P is a security management system jointly operated by South Korea’s Ministry of Science and ICT and the Personal Information Protection Commission, representing the highest level of security management in the country. It combines 80 requirements for Information Security Management System (ISMS) certification and 22 requirements for Personal Information Management System (PIMS) certification, totaling 102 requirements that must be met. Once obtained, certification is valid for three years, and annual post-audits are required to maintain its validity. Flybit’s commitment to security"Cryptocurrency exchanges are businesses that manage customers' valuable assets. All Flybit members approach their work by recognizing the fact that the protection of personal information is our most important value,” the exchange said. "We will continually strive to maintain security accidents since the establishment of the exchange." Flybit first obtained the ISMS certification in December 2020 and the ISMS-P certification two years later in December 2022. The most recent ISMS-P follow-up audit was conducted last month. After a thorough examination, the results of the audit were delivered by the Korea Internet and Security Agency (KISA) on Dec. 12, which stated that the exchange could maintain its certification. In October last year, the firm also received the highest rating in the comprehensive anti-money laundering (AML) evaluation conducted annually by the Financial Intelligence Unit (FIU) under the Financial Services Commission.

news
Policy & Regulation·

May 23, 2023

Huobi Falls Foul of Malaysian Regulator

Huobi Falls Foul of Malaysian RegulatorMalaysia’s Securities Commission, the regulator responsible for investor protection and market integrity in the South East Asian country, has closed down the Malaysian operations of Seychelles-headquartered global crypto exchange Huobi.Photo by Zukiman Mohamad on PexelsThe regulator announced the shutdown via a press release published to its website on Monday. The Commission outlined that it has taken action against both the exchange, Huobi Global Limited, and its CEO Leon Li. It cites “operating illegally in Malaysia,” given that it was operating as an unregistered digital asset exchange (DAX) as the rationale for the decision.With the enforcement action has come an order to Huobi from the regulator to “cease circulating, publishing or sending any advertisements, whether in email or on social media platforms, to Malaysian investors, and to stop its operations in the country, including to disable its website and mobile application on several platforms such as Apple Store, Google Play and any other digital application platform.”Compliance concernsThe Securities Commission is putting the onus on the Huobi Global CEO to ensure that this order is complied with. The regulator said that it had concerns about the platform’s compliance with local regulatory requirements. It further outlined that it is an offense in Malaysia to operate a DAX without having completed registration with the Commission as a Recognized Market Operator (RMO) under Section 7 (1) of the Capital Markets and Services Act 2007.The Malaysian regulator also took the opportunity to warn citizens that they should only seek to trade on platforms that are registered RMOs and that for right now, those that have funds on the Huobi platform should withdraw their assets and cease trading on the platform.Expected newsHuobi doesn’t seem to have made an official statement relative to the Malaysian Security Commission’s decision via its official media channels. However, it did provide the following response to CoinTelegraph on Monday:“In response to recent reports, we would like to clarify that the situation outlined pertains to the previous Huobi entity and former shareholders. This is not associated with the current Huobi platform, which adheres to strict regulatory compliance globally.”Taking that response at face value, the company doesn’t seem to be particularly bothered about the enforcement action. It seems as if Huobi were already prepared for this eventuality, by starting a new corporate entity from scratch.In August 2022, the Malaysian regulator issued Huobi Global with a lesser enforcement action by adding the company to its investor alert list. It chastised the firm for operating without regulatory approval.Malaysia hasn’t been a hotbed of activity where crypto and digital assets have been concerned and certainly doesn’t compare with Asian centers like Hong Kong and Singapore who are actively chasing crypto business. However, in March of last year, the country’s Deputy Minister of Communications and Multimedia, Zahidi Zainul, said that the Southeast Asian country should recognize crypto assets like Bitcoin as legal tender.In 2021, Malaysia’s central bank joined a Bank of International Settlements (BIS)-led trial to explore the proof of concept of a central bank digital currency (CBDC), in order to enhance technical and policy capabilities should there ever be a need to issue one.

news
Loading