Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Jul 06, 2023

FTX Opts Out of Plan to Sell off FTX Japan

FTX Opts Out of Plan to Sell off FTX JapanThe FTX Debtor that was brought in to manage the bankrupt estate of the failed FTX cryptocurrency exchange has decided to not follow through with a plan to sell off the Japanese business.That’s according to a report by Nikkei on Thursday. In November 2022 a new management team was brought in to restructure the FTX business immediately following the business having filed for Chapter 11 bankruptcy in the courts in Delaware in the United States.Photo by Jezael Melgoza on UnsplashOptimizing value for creditorsThe original plan was to look to sell off subsidiary companies within the group such as FTX Japan, FTX Turkey, and FTX Europe. Those plans have now at the very least been delayed. Nikkei cited an FTX executive who claimed that it’s not so much that plans have been delayed but rather that the FTX Debtor has identified another approach that will likely optimize value for creditors.“They hope to increase the price by selling the entire group, rather than selling subsidiaries in various regions,” Nikkei’s FTX source stated.Rebooting the exchangeThe response from creditors to this news has been largely positive. While the notion of a rebooted FTX business has proven to be controversial within the crypto space, most creditors recognize that the business can provide much greater value for them if it is restarted internationally.Global investment banking firm Perella Weinberg Partners (PWP) was brought in by the FTX Debtor in November 2022 to carry out a strategic review of the assets held by the FTX group. In a recent bankruptcy court hearing in Delaware, one of its partners stated that they are currently in the process of inviting bids from interested parties.At that time, PWP indicated that the Debtor was looking to revive the international FTX business. That would likely mean an entity headquartered outside the United States. It remains to be seen what will happen in the case of the FTX US business. Due to an unwelcoming regulatory approach in the US right now, setting up a crypto business there is seen as having additional risk factors.Asian interestA number of weeks ago, the Debtor filed a list of interested parties. The list included a number of high-profile Asian companies, although it’s not clear if their interest lies in the business in its entirety or specific FTX assets.Among them was Japanese telecoms firm Docomo. Tokyo-headquartered global financial services company Nomura also featured. Japan’s largest Ecommerce company, Rakuten, also signed a letter of intent in expressing its interest. FTX Japan had attracted 41 bidders. It’s being speculated that some of these Japanese entities will now bid on the entire business or join consortiums who will do so.FTX Japan solventCreditors of FTX Japan have fared much better than their international counterparts. In the wake of the collapse of the Mt.Gox cryptocurrency exchange in 2014, the Japanese authorities set to work on providing greater protections for customers. As a consequence, FTX Japan was required to ring-fence customer funds. For that reason, Japanese customers have already been given access to their funds.In a recent exchange on Twitter, well-known American investor Mark Cuban pointed out that Japanese regulators had been successful in protecting FTX investors in Japan. Cuban made the point to former US Securities and Exchange Commission (SEC) regulator John Reed Stark, underscoring the failure of US regulators in doing so.

news
Policy & Regulation·

Mar 26, 2024

Philippines follows through on Binance ban

The Philippines' financial regulator announced that it is implementing what amounts to a ban on Binance in the Southeast Asian nation by blocking local access to the leading global cryptocurrency exchange. This decision, publicized via a press release on March 25, comes as the Securities and Exchange Commission (SEC) raised concerns last November over Binance's operations in the country, citing a lack of necessary licenses for certain investment products. According to the press release, the SEC revealed that it sought assistance from the National Telecommunication Commission (NTC) to enforce the ban, expressing worries about the security of Filipino investors' funds on the platform. In a letter addressed to the NTC, SEC Chairman Emilio Aquino stated:"The SEC has identified the aforementioned platform and concluded that the public's continued access to these websites/apps poses a threat to the security of the funds of investing Filipinos.”Photo by Krisia on PexelsA similar move was taken last December by the Financial Intelligence Unit (FIU) in India, as it acted to block access to what it deemed to be non-compliant global crypto exchanges. Unlicensed servicesThe SEC alleges that Binance offers services like leveraged trading and crypto savings accounts without the required licenses, violating the country's Securities Regulation Code. Consequently, the ban is set to be implemented within three months, allowing investors time to exit their positions held through Binance. Furthermore, the SEC has requested Google and Meta to restrict Binance-related advertisements targeted at Filipino users on their platforms, extending the regulatory measures to online advertising as well. A similar stance was taken by authorities in Thailand last August with the Ministry of Digital Economy and Society (MDES) engaging in talks with Facebook in an effort to curb questionable crypto-related advertising on the platform. Regulatory setbackThis move by the Philippines' financial watchdog marks another regulatory setback for Binance, which has faced increasing scrutiny globally. In December 2023, a U.S. court ordered Binance to pay significant fines to the Commodity Futures Trading Commission (CFTC) for evading federal law and operating an illegal derivatives exchange. As part of the settlement, Binance's former CEO, Changpeng Zhao (CZ), agreed to step down from his position, with Zhao also facing civil and criminal charges related to anti-money laundering laws. The SEC's cautionary stance against Binance dates back to November 2023, shortly after Zhao's legal troubles in the U.S. emerged. At that time, the SEC expressed its intention to ban Binance in the Philippines, though the execution was postponed due to changes in the leadership of the regulatory body. Notably, Kenneth Stern, who headed up Binance's operations in the Philippines, exited the company in July 2023, amidst mounting regulatory pressures and legal challenges. Binance had seen many leading executives part ways with it in the lead-up to the company’s settlement with the U.S. Department of Justice (DoJ) last year. With regulatory actions tightening around Binance globally, the future of the exchange in various jurisdictions remains uncertain. The ban in the Philippines adds to the ongoing regulatory challenges faced by the company and underscores the growing importance of compliance within the cryptocurrency industry.

news
Markets·

Nov 15, 2024

Sygnum survey reveals greater crypto allocation appetite in Singapore

Sygnum Bank, a digital asset bank based in Switzerland and Singapore, has conducted a survey which has identified that investors in Singapore are more interested in increasing their allocation to crypto than their international peers. The bank’s 2024 Future Finance survey states that while a global average of institutional investors of 47% plan to increase their exposure to crypto next year, in the case of Singapore-based institutional investors, 57% of them expressed the view that they would increase their crypto holdings in 2025.Photo by Precondo CA on UnsplashThe report states:  "Singapore investors exhibit a higher risk appetite and motivation to invest on average than respondents from other countries.” The annual survey, which was published on Nov. 14, collated insights garnered from more than 400 institutional and professional investors, distributed across 27 countries, with average investor experience of in excess of 10 years. 121 of the survey’s participants were based in Singapore, with the survey having been conducted during Q3 2024. Long-term confidenceSingaporean respondents suggested that they were confident in the long-term potential and outlook where cryptocurrencies are concerned. While the main reason for investing in crypto was to gain exposure to digital assets in line with a global trend (56%), 41% of respondents from the city-state cited portfolio diversification as their reason for investing in the emerging asset class.  75% of investors expressed the belief that regulatory clarity has improved recently. Growing confidence among institutional investors generally is likely to be developing due to increasing certainty relative to digital asset regulation. While Donald Trump had not been elected in the United States at the time that survey participants responded, it was looking increasingly likely that he would win the election.  That’s likely to have had a bearing on investor outlook, not just within the United States but internationally, given the implications in terms of positive regulation and an overall positive approach to crypto. 39% of Singaporean respondents cited yield-generation opportunities as their motivation in investing in digital assets. The recent advent of spot crypto exchange-traded funds (ETFs) stood out as another motivation for investors.  Breaking down specific areas of interest within the crypto sector, 71% of Singaporean respondents were interested in investment in layer-1 blockchain networks. Meanwhile, 56% expressed an interest in Web3 infrastructure investment options, with 41% showing an interest in layer-2 blockchain networks. Interest in asset tokenizationIn relation to tokenization, 47% of those surveyed in Singapore indicated an interest in tokenizing mutual funds and corporate bonds over and above other financial assets and products. When first proposed, real estate was considered the most obvious asset primed for tokenization but mutual funds and corporate bonds now appear to be gaining more traction. Asset tokenization has been garnering considerable attention in mainstream finance but especially so in Singapore. Local regulator, the Monetary Authority of Singapore, (MAS) has been running Project Guardian, a collaboration between MAS and the financial services industry with an emphasis on asset tokenization. The project recently brought in the German central bank, the World Bank, HSBC and markets infrastructure firm Euroclear as participants. 

news
Loading