Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Policy & Regulation·

Sep 06, 2023

Japan’s FSA Proposes Tax Exemption for Unrealized Crypto Gains

Japan’s FSA Proposes Tax Exemption for Unrealized Crypto GainsThe Financial Services Agency (FSA) of Japan has taken the step of putting forward amendments that provide a notable tax exemption for unrealized gains on cryptocurrency holdings.Photo by Erik Eastman on UnsplashFSA proposalThe move is significant in that it spares domestic companies from the standard 30% corporate tax rate typically imposed on digital assets up until now. According to reports in local media, that proposal was detailed in a comprehensive 16-page document outlining various regulatory modifications.The most pivotal change within this document is the exemption of domestic companies from the annual “unrealized gains” tax on cryptocurrencies. Unlike some countries that only tax crypto assets when they are converted into fiat currency, Japan currently enforces an annual tax on these digital assets.2023 tax reform agendaThe proposed amendment has garnered support from the Ministry of Economy, Trade and Industry, indicating its potential passage. These discussions are part of Japan’s broader tax reform agenda for 2023, suggestive of the Asian nation’s interest in fostering a favorable environment for the blockchain and cryptocurrency industries.It is important to note that this tax exemption applies exclusively to companies that issue their own tokens and does not extend to entities solely involved in investing in other digital currencies. Additionally, individual crypto investors will still be subject to a maximum income tax rate of 55% on earnings exceeding JPY 200,000 ($1,355) related to cryptocurrency, categorized as “miscellaneous income.”The exemption is structured in a way that excludes these digital coins when assessing a company’s asset market value, provided specific conditions are met. Presently, Japanese law mandates that companies holding crypto assets must pay taxes on unrealized gains at the end of each tax period.To qualify for the tax exemption, a company must meet specific criteria outlined by the tax authority. Firstly, the company must be the issuer of the cryptocurrency in question. Additionally, it must retain continuous ownership of the crypto asset after issuance, while the asset itself remains subject to transfer restrictions.Blockchain ambitionsThis development aligns with Japan’s broader ambition to nurture and expand its blockchain and cryptocurrency sectors. Prime Minister Fumio Kishida recently articulated a vision for a “new form of capitalism,” emphasizing the importance of fostering innovation and growth in emerging industries, inclusive of the Web3 sector. As Japan moves forward with these changes, it signals its interest in creating a conducive environment for blockchain and crypto ventures to thrive.Over time Japan has been iteratively building a framework in respect of digital assets. In 2017 the country recognized Bitcoin as a legitimate property in accordance with the Payment Services Act (PSA). That same year, the Tax Agency classified crypto earnings as miscellaneous income. In 2020, crypto assets were included in Japan’s fund settlement law. Around the same time frame, the FSA brought in the requirement for crypto exchanges to register and obtain a license.These amendments also form part of a series of changes that the Japan Blockchain Association (JBA), an industry advocacy group, has been canvassing for. The proposed changes reflect a pragmatic approach to taxation, doing away with a paper profits taxation treatment in favor of a more progressive approach.

news
Web3 & Enterprise·

Jan 25, 2024

CertiK Skyfall research team inducted into Samsung Mobile Security Rewards Program Hall of Fame

Global blockchain security ranking platform CertiK announced that its Skyfall research team has been inducted into the Samsung Mobile Security Rewards Program’s 2023 Hall of Fame, according to an article by South Korean news outlet Greenpost Korea on Thursday (KST).Photo by Franck on UnsplashTeamwork excellenceThis Hall of Fame recognizes outstanding security researchers who have made significant contributions each year to the security of Samsung products. CertiK Skyfall’s spot in the ranking highlights the importance of collaborative efforts in solving complex cybersecurity challenges, the company said. Securing the futureThe team was responsible for actively identifying a total of seven vulnerabilities in the Samsung Blockchain Keystore – a software development kit (SDK) developed by Samsung to manage private keys – four of which were critical and three of which were high risk. The vulnerabilities left the SDK susceptible to local attacks, including arbitrary code execution and unauthorized access to sensitive data. In response, Samsung was able to quickly deploy security patches that added appropriate boundary checks and protection mechanisms. Skyfall has formerly been acknowledged twice in Apple's release notes for discovering multiple vulnerabilities in new iOS and iPadOS software releases, the most recent being iOS 17 Security Update. Last June, the team was also awarded the Sui network’s highest bug bounty for discovering and fixing a critical vulnerability. "We are extremely proud of the outstanding performance of the CertiK Skyfall team," said Kang Li, Chief Security Officer at CertiK. "It is a testament to the team's professionalism, integrity and deep impact at the forefront of cybersecurity." CertiK is comprised of a team of seasoned experts from reputable universities including Yale and Columbia University and globally renowned companies like Google and Microsoft. The firm also operates from several offices around the world, including Seoul.

news
Policy & Regulation·

Apr 11, 2023

North Korea Using DeFi for Money Laundering

North Korea Using DeFi for Money LaunderingThe United States Treasury issued a warning on Thursday where it identifies North Korea as a user of DeFi services for money laundering. According to the Treasury, both North Korea and criminal organizations have been using DeFi platforms to launder dirty money.©Pexels/PixabayWhile DeFi has been praised for its potential to democratize finance and provide greater financial freedom to users, it has also been criticized for its lack of regulatory oversight. According to the Treasury, this lack of oversight has made DeFi platforms an attractive target for money launderers and other criminal organizations.In its warning, the Treasury noted that North Korea has been using DeFi platforms to launder money and evade international sanctions. The country is believed to have developed a sophisticated system for laundering money through cryptocurrency exchanges, and it is now turning its attention to DeFi platforms.Illicit money movementCriminal organizations are also using DeFi services for money laundering, according to the Treasury. These groups are said to be using DeFi platforms to move money around the world, in order to avoid detection and to launder the proceeds of their illicit activities.The use of DeFi for money laundering poses a significant challenge for law enforcement agencies, as these platforms operate outside of the traditional banking system and are often difficult to track. The Treasury has urged DeFi platforms to implement strong anti-money laundering (AML) and know-your-customer (KYC) policies, in order to prevent their services from being used for criminal activities.The warning from the Treasury comes at a time when DeFi is becoming increasingly popular among investors and users. According to data from DeFi Pulse, the total value locked in DeFi protocols recently surpassed $100 billion, indicating a significant level of interest and investment in the sector.Calls for greater regulationHowever, the lack of regulatory oversight and the potential for DeFi to be used for money laundering and other criminal activities have raised concerns among regulators and policymakers. Some have called for greater regulation of the sector, in order to prevent its abuse by criminal organizations.Despite these concerns, many proponents of DeFi argue that the sector has the potential to transform the financial industry and provide greater financial freedom to users. They point to the benefits of decentralized systems, such as greater transparency, lower fees, and faster transaction times.The use of DeFi for money laundering is a complex issue that requires a multifaceted approach. While regulators and policymakers must work to implement strong AML and KYC policies, users and investors must also take responsibility for ensuring that they are using DeFi platforms in a responsible and legal manner.Ultimately, the future of DeFi will depend on how the sector is able to balance innovation and regulation. While DeFi has the potential to transform the financial industry, it must also be subject to appropriate oversight and accountability in order to prevent its abuse by criminal organizations.By working together, regulators, policymakers, and industry stakeholders can help to ensure that DeFi is used for its intended purpose — to provide greater financial freedom and empowerment to users around the world.

news
Loading