Top

Axie Infinity co-founder suffers $9.5M loss in wallet hack

Web3 & Enterprise·February 24, 2024, 7:54 AM

Jeff “Jihoz” Zirlin, one of the co-founders of Sky Mavis, the Singapore-headquartered development firm behind both Axie Infinity and the Ronin Network, has faced a significant setback as some of his personal crypto wallets have fallen victim to a hack.

https://asset.coinness.com/en/news/6c4d02fadf8c8ffe6c606825b3e5bd7e.webp
Photo by GuerrillaBuzz on Unsplash

Funds drained through Tornado Cash

The hack has resulted in the loss of approximately $9.7 million worth of ether (ETH). The breach, which occurred on Feb. 23, saw two crypto wallet addresses associated with Zirlin compromised. The perpetrator managed to abscond with 3,248 ETH, funneling the stolen funds through Tornado Cash, a privacy-focused Ethereum mixer.

 

The alarm was raised by PeckShield, a blockchain investigation firm, which identified the compromise of a "whale wallet" through the Ronin Bridge. PeckShield attributed the breach to a "wallet compromise," which facilitated unauthorized outbound transfers of funds.

 

PeckShield's investigation revealed that the pilfered 3,248 ETH was initially dispersed across three different wallets before being funneled into Tornado Cash. This service, notorious for its use by hackers seeking to obfuscate the origin and traceability of illicit funds, served as a conduit for the stolen assets.

 

Confirming the attack and remarking on having had a “tough morning,” Zirkin outlined on social media that “the attack is limited to my personal accounts, and has nothing to do with validation or operations of the Ronin chain.”

 

He emphasized the implementation of stringent security protocols across all chain-related activities, seeking to reassure stakeholders of the company’s commitment to safeguarding user assets. Although specific details regarding the breach remain undisclosed, Zirlin's statement suggests a leakage of the private keys associated with his personal wallets, granting unauthorized access to the hacker.

 

Ronin Network secure

PeckShield’s revelation prompted Aleksander Larsen, co-founder of Ronin Network, to swiftly respond, affirming the robust security measures of the Ronin Bridge. The social media post that Larsen had responded to, which he claimed to have an “extremely misleading title,” was later deleted.

 

Larsen suspected that the breach stemmed from a wallet hack rather than a flaw within the bridge itself. Notably, Ronin had been targeted in a high-profile attack in March 2022, orchestrated by the North Korea-backed Lazarus Group, resulting in a $625 million loss.

In response to this previous breach Sky Mavis initiated a comprehensive overhaul of Ronin's core systems to bolster decentralization and mitigate future vulnerabilities.

 

$112M Ripple co-founder hack

In a separate incident, Binance intercepted $4.2 million worth of stolen XRP, part of the $112 million hack targeting Ripple co-founder Chris Larsen's personal wallet on Jan. 31. Unlike the Axie Infinity breach, the perpetrator behind Larsen's hack refrained from leveraging crypto mixer services or decentralized exchanges, enabling Binance to track and immobilize a portion of the illicitly obtained funds.

 

Axie Infinity, heralded as a pioneering "play-to-earn" Web3 game, has emerged as a lucrative platform, enabling players to earn cryptocurrency and trade in-game assets via blockchain technology. Since its inception in 2018, the game has amassed $1.3 billion in revenue, underscoring its prominence within the burgeoning blockchain gaming ecosystem.

 

More to Read
View All
Web3 & Enterprise·

Oct 16, 2023

SK Planet Teams Up with T1 for LoL NFT Event: ‘The Hero’s Journey’

SK Planet Teams Up with T1 for LoL NFT Event: ‘The Hero’s Journey’SK Planet, the data and tech subsidiary of South Korean conglomerate SK Group, announced last week that it is conducting a non-fungible token (NFT) event called “The Hero’s Journey.” This event is a collaborative effort with T1 Entertainment and Sports, the company behind League of Legends (LoL) team T1. T1 Entertainment and Sports is a global esports joint venture established by American company Comcast Spectacor and SK Telecom, the telecommunications subsidiary of SK Group.This event coincides with the 2023 League of Legends World Championship (Worlds 2023), taking place in Korea from October 10 to November 19 (local time).Photo by RDNE Stock project on PexelsMission-based adventureThe NFT promotion, running until December 3, promises a unique and rewarding experience for users. LoL and NFT enthusiasts are encouraged to complete five missions and earn NFTs at various physical locations related to T1, a participant in Worlds 2023.These locations include T1’s headquarters, Base Camp, Café & Arena, and HiKR Ground. To complete their missions, visitors can collect stamps from each site, sign up for a T1 membership, and either attend a Worlds 2023 game at the stadium or join the viewing party.Anyone who has downloaded UPTN Station, the digital wallet launched in June by SK Planet, can join this promotional event, with the chance to receive rewards for each completed mission. Rewards include NFTs of LoL players like Lee “Faker” Sang-hyeok and Choi “Zeus” Woo-je, discounts on T1 memberships, vouchers for the T1 HQ SHOP, and free drink coupons.Upon completing all five missions, participants will automatically be entered for a chance to win various prizes. These include AVAX tokens, player-signed jerseys, tickets to T1 CON — a fan meet-up with T1 players — and a T1 Bap invitation, which gives fans the opportunity to tour the T1 headquarters and enjoy a meal on-site.SK Planet’s NFT commitmentLately, SK Planet has been actively undertaking NFT endeavors. In June, it introduced an NFT membership program named “Road to Rich,” capitalizing on OK Cashbag, which is the popular customer rewards program of SK Planet. This was followed by the debut of a blockchain-centric ticketing service, developed in partnership with layer 1 blockchain protocol Avalanche. Looking ahead, SK Planet aims to provide an even broader range of practical utility NFTs.Commenting on their latest project, Kim Kyo-soo, who leads the customer experience division at SK Planet, shared his excitement about collaborating with T1, one of the world’s most popular esports teams. He sees the use of NFTs in this event as a meaningful way to connect with fans in person. Kim anticipates a strong response and active participation from the esports community.

news
Web3 & Enterprise·

Nov 01, 2023

Rotonda holds blockchain hackathon at GBIC 2023

Rotonda holds blockchain hackathon at GBIC 2023Rotonda, the operator of the digital asset wallet platform Bithumb Buritto Wallet, hosted a hackathon on Monday (local time) at this year’s Global Blockchain Incheon Conference (GBIC), centered around the theme of addressing a variety of local issues, such as carbon reduction, industrial and urban issues and public services using Web3 technology. Contestants from across the country gathered to create blockchain-based prototypes aimed at addressing such issues.Photo by Marvin Meyer on UnsplashOther blockchain and Web3 companies like Roa Core, Ret Games and ReFi Korea also participated as sponsors for the competition, which was held at Songdo Convensia, an international conference complex located in Songdo International Business District.Innovative solutions recognizedThe ten teams that made it to the finals presented a range of ideas related to the theme, which were judged based on how applicable, feasible and influential they are, as well as their potential for development and social contribution.“Through this year’s hackathon, we were introduced to innovative ideas and high-quality technologies to address various local problems. Discovering and supporting passionate entrepreneurs is in line with the values that we uphold within our ecosystem at Bithumb Buritto Wallet,” said Lee Sang-ho, Vice President at Bithumb Burrito Wallet.The grand prize of KRW 5 million (approximately $3,600) was awarded to DIY, a team that developed a project to promote cultural resources, tourism experiences and sports industries in Incheon using dynamic non-fungible tokens (dNFTs). dNFTs can be adapted or changed based on external events and data. The hackathon judges praised the team for adding gamification elements to increase citizen participation and streamlining administrative procedures through smart contracts. The team also won additional benefits like office space in Incheon’s Jemulpo Smart Town.“We are delighted to be recognized for the in-depth discussions we had amongst our members to develop a highly usable and differentiated platform,” the team said in a statement. “We will strive to leverage blockchain technology to create various success stories.”Additional winnersTwo runner-up prizes went to the Caffeine Addiction team, which developed a platform for motivating coffee drinkers to dispose of used coffee grounds, and the Datayo team, which developed dBus, a smart mobility platform with token-based crowdfunding processes. They received KRW 3 million and KRW 2 million, respectively, in prize winnings.

news
Policy & Regulation·

Dec 13, 2023

NFTs not subject to South Korea’s Virtual Asset User Protection Act

NFTs not subject to South Korea’s Virtual Asset User Protection ActIn anticipation of the Virtual Asset User Protection Act coming into effect in July of next year, the South Korean Financial Services Commission (FSC) has issued an advance notice regarding its subordinate statutes.Photo by Ethan Brooke on UnsplashSeven specific provisionsThe subsidiary regulations under the Act detail seven specific provisions aligned with the Act’s objectives. Firstly, assets categorized as electronic securities, mobile vouchers, deposit tokens backed by the Bank of Korea’s central bank digital currencies (CBDCs) and non-fungible tokens (NFTs) will not be classified as virtual assets and hence, not regulated by this Act. However, in instances where NFTs are used as a means of payment for specific goods or services, they will be regarded as virtual assets.Secondly, banks will take responsibility for managing the deposits of users on cryptocurrency exchanges. This aligns with the Act’s requirement for virtual asset service providers (VASPs) to keep users’ funds separate from their own, either by depositing them in, or entrusting them to, reputable institutions. Under these regulations, banks are required to manage users’ assets in a manner consistent with how investors’ deposits are handled under the Capital Markets Act. This means that banks are allowed to invest VASP users’ assets only in secure instruments, such as state and local government bonds, and are also obligated to pay fees to deposit owners, taking into account the yields of these investments.80% of user assets in cold walletsThe third key aspect of the regulations is that VASPs are required to store a minimum of 80% of user assets in cold wallets, which are not connected to the internet. This is higher than the current requirement of 70%, enhancing the security measures for users of virtual assets. To calculate the total value of a virtual asset at any given time, its total supply is multiplied by its average daily price over the past year. VASPs are obligated to assess the value of virtual assets every month.The fourth regulation mandates that VASPs must enroll in an insurance plan, contribute to a rainy day fund or accumulate reserves. This is to ensure they can fulfill their compensation responsibilities in the event of incidents like security breaches or technical failures. The required preparation amount is set at a minimum of 5% of the user assets stored in hot wallets, as these are more susceptible to risks. VASPs are required to update their compensation thresholds or reserves monthly and must take any necessary actions to comply with these requirements by the next working day following the update.Information disclosure guidelinesAnother regulation addresses the issue of insider trading in the context of the virtual asset market. Under the current Capital Markets Act, information is considered disclosed when it’s made available through disclosure systems of the FSC or the Korea Exchange (KRX). However, since the cryptocurrency market lacks a similar system, the new statute provides criteria for determining when information is deemed disclosed.For instance, if a VASP, including exchanges, releases crucial information about a virtual asset on an exchange and six hours pass, that information is regarded as disclosed. This acknowledges the non-stop nature of the crypto market. Moreover, information disclosed post 6 p.m. is treated as officially disclosed after 9 a.m. the next day.Additionally, if a virtual asset issuer publishes significant information about its token on a website hosting its white paper, the information is deemed public after one day. This is conditional upon the website being publicly accessible and having consistently provided important token information for the preceding six months.These rules aim to provide clarity and fairness in information disclosure in the crypto market, adapting the principles of traditional financial markets to the unique dynamics of virtual assets.No arbitrary suspension of transactionsThe sixth regulation restricts VASPs from arbitrarily halting deposits and withdrawals of virtual assets unless there are justifiable reasons for such actions. Acceptable circumstances for suspending these transactions include situations where the VASP experiences a technical disruption in its system, where regulatory authorities instruct a VASP to cease deposits and withdrawals or where cyberattacks or similar incidents have occurred or are clearly imminent.Lastly, virtual asset exchanges are required to monitor for abnormal transactions continuously. These are transactions that show substantial shifts in the prices or trading volumes of virtual assets, particularly in response to news or rumors that could influence cryptocurrency prices. If VASPs suspect unfair trading practices, they must report to the FSC or the Financial Supervisory Service (FSS). When there is ample evidence of such activities, crypto exchanges are obligated to notify the police or the prosecutors’ office. In addition, the financial regulator has the authority to levy fines based on the prosecution’s decisions or after completing consultations with the prosecution if a year has passed since the day of the report.During the period of advance notice, which spans from Nov. 11 to Jan. 22, the FSC will seek comments from relevant organizations, experts and businesses. This process is aimed at refining the rules and regulations subordinate to the Virtual Asset User Protection Act. Moving forward, the financial authorities plan to publish a set of guidelines and Q&A materials and conduct explanatory sessions, with the goal of ensuring a smooth implementation of the Act.

news
Loading