Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Dec 04, 2023

GroundX releases membership NFT for JND Studios’ character figures on Klip Drops

GroundX releases membership NFT for JND Studios’ character figures on Klip DropsGroundX, the blockchain subsidiary of South Korean conglomerate Kakao, has teamed up with JND Studios — the only hyper-realistic figure maker in South Korea — to drop a membership non-fungible token (NFT) collection on Klip Drops, its digital art curation gallery and NFT platform, according to an official announcement on Monday (local time).Photo by Choong Deng Xiang on UnsplashExclusive accessJND Studios’ figures are known for being hard to acquire, as they are often made in small batches that sell out quickly. Owners of the membership NFT will get the exclusive opportunity to be the first to purchase products from the company’s K-Star Figures lineup, which features figures of popular characters from South Korean movies and dramas. This will allow the NFT owners to secure the items before their official release without the risk of them selling out prematurely.The first character from the lineup — actor Choi Min-sik as Oh Dae-su from the critically acclaimed film “Oldboy” — will be gifted to customers who purchase the NFT. The product is valued at KRW 3 million (approximately $2,300), according to JND Studios. A figure of actress Kim Hye-soo as the iconic Madam Jung from the movie “Tazza” will also be unveiled early next year.The sales period for the NFT drop will run until Jan. 3 with a limited quantity available for purchase. Buyers can link their Klip wallet on the JND Studios website, verify the NFTs they own, and then purchase the K-Stars membership NFT to get their hands on the upcoming K-Star Figures.Spearheading NFT integrationGroundX is leveraging Klip Drops to promote the widespread adoption of NFTs by implementing them in diverse sectors, such as art, retail and culture, where they can be used as membership vouchers, tickets or even coupons.

news
Web3 & Enterprise·

Oct 23, 2024

Komainu acquires Singaporean digital asset custodian

Jersey-headquartered Komainu, a digital asset custodian backed by Japan’s Nomura Holdings, is in the process of acquiring Propine Holdings, a Singaporean competitor. Subject to approvalKomainu has signed an agreement in principle with Propine to acquire the company, according to a press release published on Oct. 22 by PR Newswire on behalf of the two firms. One of the key elements in completing the deal is attaining the approval of local regulator the Monetary Authority of Singapore (MAS). This is Komainu’s first acquisition, and according to the firm’s co-CEO Paul Frost-Smith, it will be the first of several. According to Bloomberg, Frost-Smith stated in an interview that “an absolutely key factor in building” the business is obtaining access to Propine’s Capital Market Services license, which the company was awarded in Singapore. Frost-Smith described the acquisition as "setting ourselves up for the future with a licensed platform that we can grow." The company intends to further its efforts in terms of compliance by applying for a Major Payment Institution (MPI) license in Singapore. Komainu is motivated in developing in this manner as it has identified increasing demand from established institutions in Singapore for advisory services.Photo by RDNE Stock project on PexelsStrategic hubThe Komainu co-CEO said that the Asia-Pacific (APAC) region was central to Komainu’s heritage. With that, he added that Singapore is “an important strategic hub for Komainu in Asia and Propine will enhance our capabilities in meeting the significant client demand we are experiencing, including for Komainu Connect, our collateral management service, which is already extensively utilised by our investor clients in Hong Kong, Singapore, Malaysia, Thailand and Australia.” Back in August, global crypto exchange platform Bitfinex signed a memorandum of understanding (MOU) with Komainu Connect, with a view towards enhancing trading security. In July Komainu was added by crypto infrastructure firm Fireblocks to its Global Custodian Partner Program. The Japanese market has been one that Komainu has been focusing on. Frost-Smith asserted that it will serve as a major hub for the company, given that it is home to its primary backer, Nomura.  In November 2023, the company partnered with Crypto Garage, a regulated Japanese crypto-asset financial services firm. The collaboration extended Komainu’s dealings with the firm, given that it had invested in Crypto Garage’s parent company, Digital Garage, previously. At the time, the companies claimed that the partnership would allow them both to leverage their collective expertise. Komainu has also been following a regulatory-compliant path in other markets. In the UK, where it’s stationed, it received permission from the Financial Conduct Authority (FCA) to operate as a crypto custodian in October 2023. In August of the same year, it was awarded an operating license by the Virtual Asset Regulatory Authority (VARA) in Dubai. Alongside Nomura, the company was also established with the backing of digital asset security firm Ledger and digital asset investment manager CoinShares. Earlier this year, Komainu was approved by Nasdaq to be a core custodian relative to its suite of crypto indices. 

news
Policy & Regulation·

Jun 20, 2023

Korean Travel Rule Solution Provider CODE to Start Charging Monthly Fees Next Month

Korean Travel Rule Solution Provider CODE to Start Charging Monthly Fees Next MonthSouth Korean Travel Rule solution provider CODE, established in collaboration between local cryptocurrency exchanges Bithumb, Coinone, and Korbit, has announced the implementation of service fees starting next month. Up until this point, CODE has been offering its services free of charge. The notification regarding this change was issued to CODE’s clientele, which includes various crypto exchanges, as reported by local tech news outlet Digital Daily.Photo by Kenny Eliason on UnsplashTravel RuleThe Travel Rule regulations, set by the Financial Action Task Force (FATF) and Korean legislation, require Korean trading platforms to maintain records of both the sender and recipient’s information for virtual asset transactions exceeding 1 million KRW ($780). The FATF, founded in 1989 and headquartered in Paris, is an international financial watchdog dedicated to combating global money laundering and terrorist financing.More competitive priceCODE is anticipated to offer its services at a more competitive price of 1 million KRW ($780), in contrast to its rival VerifyVASP (VV), which introduced a monthly fee of $1,800 earlier this year. VV is a product developed by Lambda 256, a subsidiary of Dunamu, the parent company of Upbit, the largest cryptocurrency exchange in Korea.CODE launched its services in March last year. Among its crypto exchange members are Gopax, Cashierest, and Coredax. In December, the Travel Rule solution provider appointed Lee Sung-mi, the former compliance officer of Bithumb, as its new CEO, and since then, it has accelerated its monetization plan. Prior to Lee’s appointment, Coinone CEO Cha Myung-hun had been at the helm of CODE.

news
Loading