Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Sep 05, 2023

South Korea Reveals Guidelines for Public Officials’ Virtual Asset Disclosure

South Korea Reveals Guidelines for Public Officials’ Virtual Asset DisclosureSouth Korea’s high-ranking government officials will soon be obliged to divulge specific information regarding their virtual asset holdings, including types and quantities, as part of their wealth declaration process. The Ministry of Personnel Management (MPM) issued a press release yesterday, announcing revisions to the Enforcement Decree of the Public Service Ethics Act. These amendments are slated to come into effect on December 14.Photo by Chris Boland on UnsplashIn addition, officials holding positions of rank one or higher will be required to disclose the methods through which they acquired their virtual assets. They must also furnish documentation of transaction records for a period of one year.These amendments to the decree come in the wake of the revised Public Service Ethics Act, which was passed in May. The primary aim of this act is to make it obligatory for government employees to declare their virtual asset holdings. The changes to the decree can be summarized into five main points.Types and amountsFirst, officials obligated to disclose their wealth must report the types and amounts of virtual assets. The prices of virtual assets traded on Upbit, Bithumb, Coinone, and Korbit — all virtual asset service providers (VASPs) designated by the Commissioner of the National Tax Service — are required to be reported using the average daily price observed on the reporting day. As for other assets, their values should align with their most recent market prices. In cases where determining these prices is not feasible, they should be reported at reasonable values that reflect transaction prices.Acquisition methodsSecond, high-level public officials must explain how they acquired virtual assets. Under the existing regulation, officials are obligated to reveal both the date and method of acquisition, along with the source of funds. However, following the adoption of the updated decree, they will also be required to provide analogous information for virtual assets.Year-long transaction historyThird, comprehensive guidelines will be established to outline the process of reporting virtual asset transaction history records. Officials subject to the disclosure requirement must divulge all virtual asset transactions conducted within the past year, even if they do not possess such assets on the day of reporting. They are obligated to furnish documentation prepared by VASPs.Officials and their family membersFourth, officials are required to permit VASPs and other relevant institutions to provide the Government Ethics Committee with information on virtual asset holdings owned by both themselves and their family members. This will be facilitated through the inclusion of virtual assets in the existing information provision agreement, similar to the approach applied to other types of assets such as real estate.Addressing conflict of interestLastly, the revised decree could potentially impose restrictions on certain public officials with regard to possessing virtual assets, especially when their responsibilities encompass tasks like formulating relevant policies, granting approval for virtual assets, and overseeing taxation matters related to them. The outcomes of these restrictions will be reported on an annual basis to the Government Ethics Committee.In a briefing regarding this development, MPM Vice Minister Lee In-ho underscored the significance of the amended decree as the regulatory framework for enforcing the requirement of public officials to declare their virtual assets. He highlighted the Korean government’s commitment to ensuring that public servants adhere to accurate reporting practices concerning virtual assets, thereby preventing unlawful accumulation of wealth.

news
Web3 & Enterprise·

Jan 23, 2024

Ondo Finance announces APAC expansion

U.S.-based crypto startup Ondo Finance, a financial infrastructure firm that concerns itself with the tokenization of real-world assets (RWAs), has officially revealed its intention to expand into the Asia Pacific (APAC) area, with the inauguration of its first office in the region. In a press release published by the company on Sunday, Ondo clarified that the expansion is a direct response to the escalating interest in digital assets throughout Asia. That interest the company attributes to factors such as a flourishing crypto community, shifting regulatory environments and a growing appetite for exposure to U.S. assets.Photo by Florian Wehde on Unsplash40% market shareAt present, Ondo Finance holds a 40% share of the global market where tokenized RWAs are concerned. That market share has been driven by its three main tokenized product offerings: OUSG, designed for exposure to U.S. Treasuries; OMMF, facilitating exposure to U.S. money market funds; and USDY, positioned as a yield-bearing alternative to traditional stablecoins. These products serve as a conduit for global investors to access U.S.-based asset classes in tokenized form, aligning with the rising trend of digital asset adoption. To spearhead its APAC expansion initiative, Ondo Finance has appointed Ashwin Khosa as the vice president of business development in the region. Khosa brings nearly a decade of experience in Hong Kong-based institutional business development, having worked with multinational financial services company Citi, alongside key crypto firms such as Tether and its sister company, Bitfinex. His expertise encompasses both on-chain finance and a profound understanding of the APAC market. Khosa stated: “The team is top-notch and the mission of bringing real world assets onchain is extremely important. I look forward to working closely with partners in the region to help investors gain access to this next generation of high-quality assets.” Founded in 2021 with roots tied to the Goldman Sachs Digital Assets team and supported by leading venture capitalists including Founders Fund, Pantera Capital and Coinbase Ventures, Ondo Finance is looking to solidify its position as a dominant force in this newly emerging market on the back of nearly 40% of the global market share in tokenized securities. Nathan Allman, the founder and CEO of Ondo, expressed his excitement about the expansion, stating:“We’re very excited about our expansion into APAC. There is an active and rapidly growing crypto community and an appreciation for the type of high-quality exposure to US assets that our tokens provide.” Suspected token dumpIn a related development on Monday, on-chain sleuths have presented data that may indicate a sell-off of $11 million worth of ONDO tokens, the project’s native token. 20 million tokens were sold, with the suggestion that the token unit price fell in tandem with that market activity. Earlier on Monday, the token traded at $0.3062. At the time of writing, it's trading at $0.25. This expansion into the APAC region follows a string of pivotal developments for Ondo, including the revelation of its strategic roadmap and partnerships within the Ondo ecosystem. Additionally, the Ondo Foundation has introduced a points program and a proposed unlocking of its ONDO token, marking an integral part of the company's ongoing growth and development.   

news
Policy & Regulation·

May 24, 2024

Gate.HK ceases operations and withdraws license application in Hong Kong

Gate.HK, cryptocurrency exchange Gate.io’s Hong Kong entity, is discontinuing its operations and has retracted its application for a crypto trading platform license with the local regulator. The company announced on Wednesday a planned "major overhaul" of its platform and has ceased new user registrations and deposits immediately. In compliance with local regulations, Gate.HK will delist all tokens—including major ones like Bitcoin, Ether and USDT—on May 28, urging users to withdraw their assets by August 28. The trading platform, which launched officially in May 2023, aims to re-enter the Hong Kong market in the future after securing the necessary approvals and contributing to the virtual asset ecosystem.Photo by Kelly Sikkema on UnsplashRegulatory environment and industry responseThe withdrawal of the license application, initially submitted in February 2023, was noted on the website of the Hong Kong Securities and Futures Commission (SFC) on May 22, without a disclosed reason for the withdrawal. The SFC mandates that crypto trading platforms without a submitted license application by Feb. 29 must shut down by May 31 or within three months upon receiving further notice. This regulation has impacted several platforms, including HKVAEX and Huobi HK, both of which have recently withdrawn their license applications and ceased operations or faced operational uncertainties in the region. Currently, the SFC is reviewing applications from 20 crypto firms, indicating significant interest among global exchanges in securing retail trading licenses in Hong Kong. 

news
Loading