Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Policy & Regulation·

Apr 29, 2024

Investigation launched into prominent Chinese blockchain figure Yao Qian

Authorities in China have disclosed that Yao Qian, a prominent figure in the country's blockchain industry and former head of China's central bank digital currency institute, is under investigation by the nation's anti-graft watchdog. The announcement was made on Friday, revealing that Yao is "suspected of serious violations of discipline and law." However, specific details regarding the nature of the investigation were not provided.Photo by Max van den Oetelaar on UnsplashCareer and recent roleYao Qian currently holds the position of head of the technology regulation department at the China Securities Regulatory Commission. Earlier in the month, he authored an opinion piece titled “Warnings Mount Over Novel Bitcoin ETFs That Have Taken the U.S. by Storm” on Caixin, a prominent Chinese financial news platform. Born in 1970, Yao initially served as the inaugural head of China's central bank digital currency research institute in 2017 before transitioning to the securities regulator in 2018. Contributions to blockchain discourseThroughout his career, Yao Qian has been actively involved in discussions surrounding blockchain technology. In 2022, he published a book covering various topics within the blockchain space, including DAOs, DeFi, NFTs and X-to-earn models. In the foreword of his book, Yao emphasized the growing significance of Web3 innovation, noting it as a development direction of high importance and value for nations. Lack of specifics surrounding investigationThe announcement of Yao Qian's investigation has left many observers in the blockchain industry with questions, as authorities did not provide clear reasons for the probe. Despite his past contributions and current role in technology regulation, the investigation raises uncertainties about Yao's future involvement in the blockchain sector and his standing within Chinese regulatory circles. As developments unfold, stakeholders within the blockchain community will continue to monitor the situation surrounding Yao Qian's investigation and its potential implications for China's blockchain policies and initiatives. 

news
Policy & Regulation·

Apr 10, 2023

Four Pillars for Success in Korean Security Token Market

Four Pillars for Success in Korean Security Token MarketOn Wednesday, blockchain experts in various fields gathered at the 2023 Blockchain Meetup Conference held in Seoul to discuss issues with security tokens and their outlook.©Pexels/Alesia KozikWhat attracted security token businesses’ attention at the meeting was a presentation by Jung Eui-heon from Lambda256, a subsidiary of Korean crypto exchange Upbit’s operator Dunamu. He shared four pillars for success in the Korean security token market.Security tokens gaining traction in KoreaSecurity tokens have been a trending topic in the Korean blockchain industry since the Korean Financial Services Commission (FSC) allowed the issuance and trading of security tokens last February. Furthermore, a 2022 report jointly published by Boston Consulting Group and Singaporean investment platform ADDX predicted that the total size of illiquid tokenized assets worldwide would reach $16 trillion by 2030.Against this backdrop, here are the four keys to successful security token projects that Jung outlined.Technology adaptationFirst, he emphasized the importance of adopting rapidly changing technology. To tackle the issue, he suggested teaming up with advanced tech companies for long-term collaboration. When choosing tech partners, companies should ensure they are sustainable, possess technological prowess, hold credibility on high volume transactions, and maintain the security level of financial institutions, Jung advised.Forging partnershipsThe second point he mentioned was the need to forge partnerships. The FSC’s February guideline requires the issuance and distribution of security tokens to be managed separately. This means that security token projects require collaboration between issuers, distributors, account managers, asset holders, and tech companies.New securities productsJung also noted that discovering new securities products is crucial. Partnering with existing fractional investing companies may help accelerate the security token project initially, but in the long run, enterprises will eventually have to create products in various fields such as gaming, movies, and entertainment.Token liquidityLastly, Jung underlined the token liquidity, which plays a crucial role in determining its prices. Issuers will need to find various distributors and vice versa. Securing liquidity requires the establishment of a technical standard that improves interoperability and compatibility, he highlighted.

news
Web3 & Enterprise·

Jan 05, 2024

Com2uS Platform receives ISMS-P certification for personal information security

Com2uS Holdings subsidiary Com2uS Platform has acquired a certificate of Personal Information and Information Security Management System (ISMS-P), an official certificate distributed by the Korea Internet and Security Agency (KISA), for its blockchain-based game development platform Hive.Photo by Towfiqu barbhuiya on UnsplashStreamlining game developmentHive allows developers to focus on content development by providing functions for game launch and operation in a single software development kit (SDK). It covers all systems needed to run a game, including billing, gameplay across multiple platforms, global login and verification, compliance, support, analytics, promotions, push notifications, community management and blockchain middleware. It is utilized in over 150 games and 41 corporate clients with some 100 million annual users. Robust security measuresTo receive the ISMS-P certification, companies are evaluated based on 101 different criteria, including organizational structure, management of employees and facilities, security of information processing systems and more areas related to handling personal information. "Com2uS Platform and Hive have established and promoted world-class security policies," said Choi Seok-won, CEO of Com2uS Platform. "We will continue to do our best to create an environment where users and customers worldwide can safely enjoy our content." Com2uS Platform also revealed that it runs an office dedicated to information protection, which manages data from Com2uS games and external clients. The company also strives to improve its technological capabilities for enhancing security and conducts annual company-wide training for all employees to raise security awareness. Since 2017, Com2uS Platform has retained its ISMS certification – similar to the ISMS-P but without personal information security standards – to safeguard the information of its users and customers.  

news
Loading