Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Jan 11, 2024

CoinNess soars to 2nd among news apps in Korea amid bitcoin ETF frenzy

CoinNess, the leading crypto media platform in South Korea, announced today that it has become the country’s largest online community platform for cryptocurrency enthusiasts. 100,000 daily active usersThe virtual asset media outlet revealed that during the second week of January, the average daily active user (DAU) count neared 100,000. The platform also experienced a milestone, with the average concurrent user count surpassing 15,000 for the first time, edging out Coinpan, Korea's preeminent cryptocurrency community website. High ranking in app marketsAdditionally, CoinNess achieved the second position in the Top Charts for free iPhone apps in the news category on the Apple App Store in Korea. The top spot is held by the social media platform X, previously known as Twitter. On the Android Play Store, the CoinNess app ranked 82nd in the finance category and is the fourth most popular among crypto-related apps, trailing behind Bithumb, Upbit and Bitget. The significant increase in CoinNess’ user base can be attributed to the recent surge in interest in spot bitcoin exchange-traded funds (ETFs). More and more Korean investors have turned to CoinNess, finding it crucial to stay informed about the U.S. Securities and Exchange Commission’s (SEC) approval of spot bitcoin ETFs and to begin participating in the cryptocurrency market.Korean crypto market’s prominenceThe prominence of the Korean market in the world of cryptocurrency is highlighted by the Korean won's leading role in the fiat currency trading of bitcoin. According to a Bloomberg report, in November, the Korean won made up 42.8% of all fiat currencies used in bitcoin transactions, surpassing the U.S. dollar. Regarding this development, Kim Jung-ho, CEO of CoinNess, said, “Korean investors generally commit substantially more funds to cryptocurrency investments than the average seen globally. They are keenly attuned to international news and market trends, demonstrating a propensity for analyzing the market from diverse viewpoints.” Established in 2018, CoinNess is a news platform specializing in live updates on virtual asset investment. The media expanded to include an online community in 2021, creating a more holistic experience for its users. In Korea, CoinNess prides itself on having the largest active user base in the cryptocurrency media and community sector. Furthermore, CoinNess stands out as the only business-to-business (B2B) provider of live cryptocurrency news in Korea. It delivers real-time crypto updates to prominent platforms, including Coinone and Gopax, which are among the nation's five largest fiat-to-crypto exchanges. English service in Q1Moving forward, CoinNess is gearing up to launch a new service in the first quarter, offering live, around-the-clock updates on cryptocurrency markets in English to a global audience. As a key partner with Ness LAB, the blockchain research firm responsible for the NESS token, CoinNess seeks to enhance Ness LAB’s efforts to cultivate an information economy within the cryptocurrency sector. 

news
Policy & Regulation·

Jul 02, 2025

Malaysian regulator seeks feedback on crypto framework enhancements

The Securities Commission Malaysia (SC), the statutory body tasked with regulating and developing capital markets within the Southeast Asian nation, has published a consultation paper in an effort to garner public feedback on potential enhancements to its crypto regulatory framework. In a press release published to its website on June 30, the SC claimed that its proposals seek “to enhance competitiveness of Malaysia’s regulated digital asset market, improve investor protection and strengthen the resilience and integrity of [Digital Asset Exchange] operators.”Photo by Vlad Shapochnikov on UnsplashEasing listing requirementsIn the event that the proposals are adopted, one key change would see a liberalization of the listing requirements for digital assets. Where certain key eligibility criteria have been met, the regulator would allow the listing of digital assets on digital asset exchanges without prior SC approval. The regulator stated that it wants to make this change in order to speed up the time taken to get digital assets to market as they emerge. By setting out additional criteria, there will be greater exchange operator accountability. Exchange operators would bear responsibility for listing tokens in compliance with the requirements set out by the regulator.  Assets could only be listed once those assets and the underlying protocol and network had undergone security audits which had been carried out by an independent and qualified blockchain security auditor, with the audit results made public.  For the purposes of the “Liberalised Listing Framework,” the asset must have been trading on a Financial Action Task Force (FATF)-compliant virtual asset service provider (VASP) platform for a minimum of one year. The regulator believes that easing the listing requirements will result in a broader digital asset product offering being made available in Malaysia. Last month, Thailand’s Securities and Exchange Commission (SEC) started a public consultation process aimed at revising token listing rules. Coin listing processes have also come under scrutiny from the authorities in South Korea recently. Segregating client assetsAmong the proposals is a plan to oblige exchange platforms to properly segregate client assets from operational funds and assets held by the exchange business. In recent years, many failed crypto exchange platforms, most notably FTX, got into difficulty by co-mingling customer funds with operational funds. Furthermore, the regulator doesn’t want any cross-over of assets between the local exchange operator and any overseas affiliate companies it may have.The SC stated that it is cognizant of recent global exchange failures, which has led it towards further enhancing crypto exchange operational governance and controls. It suggests that only 10% of client assets should be held by a Malaysian exchange in hot wallets, with the remaining 90% held in cold or offline wallets. The SC said that it welcomes feedback from members of the various stakeholder groups on the proposals outlined. The public consultation period runs from June 30 through Aug. 11.  Malaysia is expected to have 4.74 million crypto users by 2026. That would equate to 13% of Malaysians using crypto by then.

news
Policy & Regulation·

Jan 12, 2024

South Korea’s top asset manager halts trading for bitcoin ETFs

Mirae Asset Securities, South Korea’s largest asset management firm, has begun suspending trading for bitcoin ETFs, according to industry sources on Friday. This comes after an announcement made by the Financial Services Commission (FSC) stating that brokering spot bitcoin ETFs may be considered a violation of the government’s stance on virtual assets and the Financial Investment Services and Capital Markets Act.Photo by Dmytro Demidko on UnsplashTaking preemptive measuresThe asset manager has blocked new purchases of spot bitcoin ETFs listed in Canada and Germany starting yesterday and is considering suspending trading of bitcoin futures ETFs that have been listed in overseas markets since 2021. This includes the Proshares Bitcoin Strategy ETF, Valkyrie Bitcoin Strategy ETF, Invesco Galaxy Bitcoin Strategy ETF and VanEck Bitcoin Strategy ETF. As Korean financial authorities are putting the brakes on domestic investments in the recently approved spot bitcoin ETF by the U.S. Securities Exchange Commission (SEC), it is believed that Mirae Asset Securities is putting a preemptive halt to trading in other bitcoin ETFs. Spot vs futuresSpot bitcoin ETFs differ from futures ETFs in that they track the price of Bitcoin by actually holding the cryptocurrency, while the latter tracks its price through futures contracts. South Korean securities firms have been brokering futures ETFs listed in overseas market for a while now.

news
Loading