Top

HTX Hacker Returns Funds

Policy & Regulation·October 10, 2023, 12:46 AM

The hacker responsible for the nearly 5,000 ETH exploit on the Seychelles-headquartered cryptocurrency exchange HTX (formerly known as Huobi) last month has decided to return the stolen funds.

Towards the end of last month, the exchange fell victim to a hack, resulting in a loss estimated at around $8 million. According to on-chain data, the hacker has repatriated the pilfered cryptocurrency, marking a significant development in the aftermath of the cyberattack.

Photo by Shubham Dhage on Unsplash

 

Hacker rewarded

The returned funds were sent back in two separate transactions, one consisting of approximately 4,000 ETH and the other totaling around 1,000 ETH. HTX advisor and Tron Founder, Justin Sun, took to X (formerly Twitter) to officially confirm the recovery. In his statement, Sun revealed that HTX had not only received all the stolen funds as promised by the hacker but had also extended a gesture of goodwill. HTX rewarded the responsible party with a “white hat bonus” amounting to 250 ETH, equivalent to a substantial $400,000.

Sun expressed his satisfaction with the hacker’s decision, stating:

“We have confirmed that the hacker has fully returned all funds, as promised, and we have also paid the hacker a white hat bonus of 250 ETH. The hacker made the right choice. We would like to express our gratitude to everyone in the industry for their help.”

 

Hacker advisory message

During the return of the funds, the hacker conveyed a message on-chain, shedding light on the reason behind this act of restitution. The message read:

“Received your message. White hat bonus to

0x1Fc8674A51D6b97C968BE384337519CE7003152B. Your system hot wallet private key leak, you should change system hot wallet address and reduce the system hot wallet rate.”

HTX, in response to the hacker’s decision to return the funds and in accordance with its commitment, promptly sent the white hat bonus to the specified address. The exchange also requested the hacker to provide a detailed security vulnerability analysis report to the email address htxsafe@htx-inc.com.

This request aims to prevent similar incidents in the future, with assurances that the hacker’s privacy will be safeguarded.

Justin Sun had confirmed the original hack in September, at the time reassuring the community that HTX had covered all losses arising from the attack and resolved associated issues satisfactorily.

While acknowledging the severity of the hack, Sun pointed out that the stolen amount represented a relatively small fraction of the $3 billion in assets held by HTX’s users. To incentivize the return of the funds, HTX had even offered a reward of 5%, which equated to $400,000.

However, Sun also emphasized that if the funds had not been returned within a seven-day window, the company would have been compelled to involve law enforcement authorities.

Thankfully, it did not come to that, and the cryptocurrency exchange can now move forward with the confidence that its users’ assets are secure. This incident highlights the importance of cooperation and ethical choices within the crypto community, as well as the potential for resolution even in the face of cyberattacks.

More to Read
View All
Policy & Regulation·

Nov 22, 2023

Crypto Travel Rule solutions provider CODE obtains ISO 37301 certification

Crypto Travel Rule solutions provider CODE obtains ISO 37301 certificationCODE, a Travel Rule solutions provider and joint venture co-founded by Korean cryptocurrency exchanges Bithumb, Coinone and Korbit, announced on Wednesday (local time) that it has obtained the ISO 37301 certification for compliance management systems (CMS) from the Korea Compliance Initiative (KCI).Photo by Héctor J. Rivas on UnsplashBoosting complianceISO 37301 is an international standard that outlines the requirements and guidelines for an organization in establishing, developing, implementing, evaluating, maintaining and improving a CMS. It provides a framework for organizations to ensure that they are following all relevant and applicable laws, regulations, codes of conduct and more to exercise good governance, transparency and accountability.CODE has taken the initiative to bolster its CMS to provide more secure and reliable Travel Rule solutions by analyzing and managing compliance risks. The firm’s CEO Lee Sung-mi is responsible for overseeing these efforts as the recently appointed head of compliance. Through these measures, the company explained that it has been capable of building a system to comply with strict international standards.The Travel Rule under the Financial Action Task Force’s (FATF) Recommendation #16 outlines that virtual asset service providers (VASPs) must share certain personal information about customers — including names and account numbers — when facilitating crypto transactions that exceed a certain amount.CODE is also running mandatory training sessions and various programs for all employees to ensure adherence to compliance requirements. In particular, the firm operates a system to monitor Travel Rule compliance risks that may arise during cryptocurrency deposits and withdrawals.“Beyond establishing a robust compliance management culture as a Travel Rule solution provider, we will continue to work with our corporate members to ensure that this culture can be more widely adopted across the crypto industry,” said Lee Sung-mi.Contributing to anti-money launderingCODE has also recently teamed up with global blockchain analytics and crypto compliance solutions provider Elliptic to help Korean VASPs adapt to the evolving international regulatory landscape for anti-money laundering (AML) and the crypto Travel Rule.

news
Policy & Regulation·

Jul 21, 2023

Korea’s FSC Embarks on Developing Regulatory Framework for VASPs

Korea’s FSC Embarks on Developing Regulatory Framework for VASPsThe South Korean Financial Services Commission (FSC) has taken a step towards the development of a virtual asset regulation system by seeking external parties to undertake a research project in this area, according to local news agency News1.Photo by Joshua Miranda on PexelsSecond phaseEarlier this month, the National Assembly passed the Virtual Asset User Protection Bill, aimed at protecting investors and preventing unfair trading practices. This legislative accomplishment, scheduled to go effective in July next year, is referred to as the “first phase” of virtual asset regulations. Building upon this foundation, the FSC has now shifted its focus to the “second phase,” which involves the regulation of virtual asset service providers (VASPs).Regulating VASP operationsOne primary concern regarding VASPs is the potential for conflicts of interest arising from their involvement in the issuance and distribution of virtual assets. In response, the FSC is determined to design a regulatory framework that covers a wide range of virtual assets, including stablecoins, security tokens, and utility tokens.In addition to this, the FSC intends to establish a system that governs advisory and disclosure businesses, which will play a crucial role in disseminating information about asset prices and disclosures.Moreover, the regulatory system will include guidelines for holding parties accountable in case of incidents and for overseeing the operations of VASPs to maintain a safe and fair market environment.The FSC acknowledges the significance of aligning policies with international standards. To achieve this, the commission will conduct an examination of virtual asset regulatory approaches taken by different countries and international organizations. Through this study, the FSC aims to integrate global best practices and approaches into Korea’s own regulatory framework for virtual assets.Once the study is complete, the FSC has to report the result to the National Policy Committee of the National Assembly by July 2024 before the Virtual Asset User Protection Bill goes into effect.

news
Web3 & Enterprise·

Oct 04, 2024

HashPalette acquisition sees Aptos Labs enter Japanese market

Aptos Labs, the developers behind the Aptos layer-1 blockchain, has entered the Japanese market through the acquisition of HashPalette, a blockchain network concerned with the issuance, management and distribution of non-fungible tokens (NFTs). HashPalette informed stakeholders of the development on Oct. through an X post, alongside a press release published on its behalf by Japanese public relations company PR Times. Photo by Tianshu Liu on UnsplashExpanding Asian presenceUp until now, HashPalette has been a wholly owned subsidiary of HashPort, a blockchain-related consulting and infrastructure provider based in Tokyo. This acquisition sees the project transfer to being a wholly owned subsidiary of Aptos Labs. Accordingly, this will mean that applications developed by HashPalette will be migrated onto the Aptos Network. Similarly, the Palette Chain blockchain will migrate over to Aptos. From Aptos Labs’ perspective, the acquisition enables it to expand its blockchain ecosystem in Japan and within Asia more broadly. Aptos Labs Co-Founder Mo Shaikh described the acquisition as an investment in “the talented builders and creators of the region.”  Deal pending approvals, closing conditionsWhile the parties have announced the acquisition, the deal is still subject to required approvals being granted, together with various closing conditions related to the sale being met. Addressing the need to close out the deal, HashPalette tweeted:“HashPort and Aptos Labs will work closely together in the transition and will take great care to ensure that all stakeholders, including PLT and ELF holders, are not disadvantaged by the migration.” The PLT token is HashPalette’s native token. According to the project’s whitepaper, it has utility when it comes to the payment of NFT issuance fees and node management fees relative to the Palette Chain. Additionally, it can be used to pay for NFTs issued on the Palette Chain and for subscription payments related to applications developed on top of the network. The ELF token is a crypto asset utilized within THE LAND ELF Crossing, an NFT farming game which was developed by HashPalette and issued on the Palette Chain. The game is being marketed in Japan with the assistance of Animoca Brands following a partnership earlier this year. The companies have agreed to gradually migrate NFTs which had been issued on Palette Chain, relative to the EXPO2025 digital wallet developed by HashPort, to the Aptos Network. Once that migration has been achieved, it’s envisaged that the Aptos Network will become the only blockchain associated with the EXPO2025 digital wallet. Unresolved Palette Chain issuesFrom the point of view of the development team behind HashPalette, it was outlined in the press release that the move goes beyond a simple financial transaction. It acknowledged that “Palette Chain still has many issues.”  Against that background, the team believes that in order to further accelerate the social implementation of Web3, it has “considered how to make services built on Palette Chain more scalable and usable, and to enable smoother access to the global Web3 market.” That consideration has brought the project team to the conclusion that migrating to the Aptos Network offers the best path forward. At the time of writing, Aptos’ APT token was trading at $8.93, up 12.44% over the course of 24 hours, according to CoinMarketCap data.

news
Loading