Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Aug 17, 2023

SK Telecom and Polygon Labs Team Up for Web3 Ecosystem Development

SK Telecom and Polygon Labs Team Up for Web3 Ecosystem DevelopmentSouth Korean telecommunications giant SK Telecom (SKT) and global blockchain firm Polygon Labs have joined hands to foster the growth of the Web3 ecosystem.Photo by GuerrillaBuzz on UnsplashThe two companies signed a memorandum of understanding (MOU) on Thursday at SK-T Tower located in Euljiro, Seoul. SKT’s Web3 Chief Officer, Oh Se-hyeon, and Polygon Labs’ CEO, Marc Boiron, were in attendance.Polygon Labs is the operator of the Polygon blockchain network, which is critically acclaimed for its superior blockchain performance, scalability, Ethereum compatibility, and more. The firm is also well-known for its engagement with various global enterprises and Web3 projects.“Polygon Labs has developed optimal blockchain technology for the popularization of Web3, and we expect our collaboration with SKT to serve as a key opportunity to offer Web3 experiences and services to a wider audience,” said Polygon CEO Boiron.Empowering NFT trade and connectivityAccording to the agreement, SKT’s NFT marketplace “TopPort” and the company’s upcoming Web3 wallet will operate on Polygon’s blockchain network. On the other hand, Polygon Labs will aid in integrating SKT’s Web3 services into its global ecosystem.This will enable NFT creators who use TopPort to trade their NFTs on the Polygon network. In addition, NFTs issued on TopPort will now be tradable on other NFT marketplaces within the Polygon network, enhancing global compatibility and scalability.SKT and Polygon also plan to allow SKT’s Web3 wallet to be used across various decentralized applications (dApps) within the Polygon ecosystem. Furthermore, they are exploring the possibility of facilitating NFT trading on TopPort using Polygon’s native token, MATIC.Promoting the advancement of Web3This partnership aims to drive sustained growth within the Web3 ecosystem, particularly by finding and incubating promising Web3 enterprises. To do so, Polygon Labs is considering investments in Web3 startups endorsed by SKT through its investment arm Polygon Ventures.SKT’s Web3 Chief Officer Oh expressed high hopes for the synergy between SKT’s blockchain service technology and expertise and Polygon Labs’ infrastructure technology and ecosystem, saying, “This collaboration could become a cornerstone for the future popularization of Web3.”All of these efforts are geared towards paving the way for Web3’s mainstream adoption, as these two industry giants combine their strengths to spearhead the evolution of the Web3 ecosystem.

news
Web3 & Enterprise·

Feb 27, 2025

Bgin Blockchain files for Nasdaq listing

Bgin Blockchain Limited, a crypto mining equipment manufacturer headquartered in Singapore, filed documentation last Friday with the Securities and Exchange Commission (SEC) with a view towards launching an initial public offering (IPO) in the U.S. The Feb. 21 filing, a Form F-1 registration statement, outlines that the company wishes to go forward with the IPO after the effective date of the filing has been established. Bgin identified itself as an “emerging growth company.”  The registration statement was filed on behalf of Bgin by Hunter Taubman Fischer & Li LLC, in conjunction with the underwriters represented by Robinson & Cole LLP. It proposes to offer the U.S. investing public 59.54 million Class A ordinary shares and 15.69 million Class B shares. As part of its plan, Class A shares would be listed on the Nasdaq stock exchange using “BGIN” as the ticker symbol.Photo by Leslie Lopez Holder on Unsplash$50 million raiseIn a statement published on Renaissance Capital's website, the independent investment bank outlined that Bgin is seeking to raise $50 million in capital through the IPO.  It’s understood that funds raised by way of the IPO will be utilized to ramp up research and development efforts. The bookrunners, responsible for managing the IPO, are Chardan Capital Markets and The Benchmark Company. As yet, no information has been provided with regard to how Bgin will price its share offering. Renaissance described Bgin as a digital asset technology company “with proprietary cryptocurrency mining technologies and a strategic focus on alternative cryptocurrencies.”  The company, founded in 2019, focuses on the design, manufacture and distribution of mining equipment relative to Kaspa (KAS), Alephium (ALPH) and Radiant (RXD) blockchain networks. Bgin supplies 8nm and 12nm ASIC chips dedicated to these alternative blockchain networks, which all depend on the use of a proof-of-work (PoW) consensus mechanism. Additionally, Bgin mines cryptocurrency itself while providing a hosting service for crypto mining, with facilities in the U.S. and Hong Kong. It hosts 4,020 mining rigs for customers, with 3,330 of these located within facilities in Iowa and Nebraska.  Across various subsidiaries Bgin manages 33,862 active mining rigs in the U.S. within its own mining operations. And additional 12,000 non-operational rigs are currently in storage facilities in the U.S. and Hong Kong. Over a 12-month period ending on June 30, 2024, the company recorded revenues of $392 million. In 2023, the firm recorded sales of 68,000 mining rigs. In H1 2024, the company sold over 47,000 mining machines. The filing disclosed that the company’s Hong Kong subsidiary was responsible for considerable crypto mining facilities in mainland China prior to China deeming the activity to be illegal in 2021. Providing full disclosure in the lead-up to its IPO, the firm warned that it continued to operate crypto mining facilities in China for a number of months in violation of that law. It identifies this item as a risk factor as potentially, the firm could be penalized and fined.

news
Markets·

Nov 05, 2024

Asia emerges at the forefront of crypto development

Asia has taken the lead, surpassing North America, in terms of being a crypto developer hub according to a recent report. Electric Capital, a venture capital firm based in Silicon Valley in the United States, recently compiled a report centered upon global crypto developer data. Its analysis of the data has led to some interesting findings. Photo by Shubham Dhage on UnsplashNorth America loses its leadElectric Capital General Partner Maria Shen took to the X social media platform on Oct. 30 to provide further details on some key takeaways. In the first instance, Shen points out that North America has lost its lead in terms of crypto developer share, with Asia emerging as the leading region in this respect. Shen stated that “for the first time, Asia is the #1 continent for crypto talent.” Underpinning that claim, she provided data that identifies a drop in North America’s share of crypto developers from 44% in 2015 to 24% in 2024. Within the same timeframe, Asia’s share of crypto developer talent has increased from 13% to 32%. Teasing the data out further, the United States still remains the number one country for crypto devs on a country-by-country basis. It leads this particular metric with 18.8% of the developer talent pool, followed by India with 11.8% and the United Kingdom with 4.2%. A consequence of U.S. regulatory uncertaintyRegulatory uncertainty in the United States has been identified as a contributing factor by some crypto community commentators. The Securities and Exchange Commission (SEC) in the U.S. has engaged in regulation by enforcement rather than establishing a bespoke regulatory framework for crypto.  This approach has led to SEC Commissioner Mark Uyeda calling crypto regulation in the U.S. “a disaster” earlier this month. Others, like Nic Carter, a partner at Castle Island Ventures, have gone further, describing the approach of the Biden Administration to crypto as “Operation Choke Point 2.0,” suggesting that there is an active plan being implemented to suppress the industry. This negative approach has led many U.S.-headquartered crypto firms to pursue growth opportunities overseas, particularly within centers in Asia and the Middle East such as Dubai, Abu Dhabi, Hong Kong and Singapore. All of these centers have taken the opposite approach, deliberately working towards putting purpose-made regulatory frameworks in place over the course of the past two years, in order to get crypto innovation started on the right footing. Shen underscored the issue from a U.S. perspective, by pointing out that 81% of crypto devs, who are actively playing their part in shaping the future of digital money, live outside the U.S. She highlighted the significance of this, stating: “This is a national security issue & innovation drain for the US.” In a subsequent post, she questioned whether this had come about due to a negative regulatory environment, adding that “the US needs clear crypto policy to maintain its country lead.” 

news
Loading