Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Jul 27, 2023

KuCoin Dismisses Notion of a Layoff Plan

KuCoin Dismisses Notion of a Layoff PlanAmidst recent rumors of significant layoffs at Seychelles-based cryptocurrency exchange KuCoin, the company’s CEO has come forward to deny any such plans.While not refuting the possibility of staff reductions, KuCoin’s CEO, Johnny Lyu, took issue with the term “layoffs,” asserting that it was a reevaluation of the organization’s structure rather than job terminations. The speculations about staff cuts were first reported by Colin Wu of Wu Blockchain on Twitter.Photo by Joao Viegas on UnsplashAlleged 30% workforce reductionAccording to his sources, KuCoin was planning to layoff around 30% of its workforce, attributing the alleged measure to a strict know-your-customer (KYC) policy that had impacted the firm’s profits.The KYC policy in question was introduced after KuCoin faced legal action from the United States. In March, the New York Attorney General accused the exchange of violating securities and commodities laws, leading to the implementation of the more stringent KYC measures.Routine bi-annual appraisalsInstead, Lyu has clarified that any adjustments to the company’s headcount were a result of routine bi-annual appraisals aimed at maintaining competitiveness in the market.Taking to Twitter on Tuesday, Lyu referred to the layoff reports as “rumors.” He emphasized that the company regularly evaluates its organizational structure based on employee performance and overall company development to ensure dynamism and competitiveness.The Kucoin CEO pointed to a recent report issued by the company as evidence of the exchange’s ongoing growth. The report revealed that the firm had added 300 new employees in the first half of the year. It also mentioned that KuCoin was in the process of upgrading its KYC authentication systems to enhance user asset security, comply with global compliance requirements, and create a safer trading environment.Despite the speculation and policy changes, KuCoin ranks 11th in terms of “trust score” among other exchanges, according to CoinGecko. Over the past day, the exchange notched up an impressive $327 million in trading volume.KYC policy changeRecently, KuCoin updated its KYC policy, requiring newly registered users to complete the KYC process to access the exchange’s products and services. Existing registered users who had not completed KYC by the deadline faced restrictions on their accounts, limiting certain activities but allowing fund withdrawals.The update to the KYC policy had a notable impact on KuCoin’s trading volume. A day after the announcement, trading volume skyrocketed to $6.8 billion from the previous day’s $500 million, according to CoinGecko data.Lyu has pledged to continue investing in the company’s core businesses while providing users with the exceptional trading experience they’ve been promised.KuCoin may have dispelled rumors of widespread layoffs and clarified that any staff adjustments were part of routine organizational development. However, there’s no doubt that the crypto exchange business is going through a difficult period.Most exchanges have suffered due to regulatory pushback, particularly those that have focused their activities in the United States. Earlier this month, global exchange Binance cut 1,000 jobs with plans to make further cuts in the future.

news
Policy & Regulation·

Jul 04, 2023

Singapore Looks to Prohibit Crypto Lending and Staking

Singapore Looks to Prohibit Crypto Lending and StakingIn a move to bolster investor protection and maintain financial stability, the Monetary Authority of Singapore (MAS) is introducing new guidelines for cryptocurrency platforms operating in the country.Details of the measures were published by MAS on Monday. According to its statement, the measures “will mitigate the risk of loss or misuse of customers’ assets, and facilitate the recovery of customers’ assets in the event of a DPT [Digital Payment Token] service provider’s insolvency.”The proposed guidelines outline several key measures. One such measure is the daily reconciliation of customer assets, which will help prevent discrepancies and safeguard against potential losses.Photo by Hu Chen on UnsplashHolding assets in trustAdditionally, the custody function, responsible for holding and safeguarding client assets, will be operationally separated from other business divisions to minimize the risk of mismanagement or unauthorized use. By the end of this year, it’s understood that crypto platforms will be required to store client assets in trust accounts, ensuring enhanced security and accountability.DisclosuresFurthermore, licensed cryptocurrency service providers will be mandated to provide explicit disclosures to customers, clearly outlining the risks associated with holding and trading digital payment tokens (DPTs). Recognizing the speculative nature of digital token trading, the MAS acknowledges that regulations alone cannot fully protect consumers from potential losses.To further protect retail investors, the MAS intends to prohibit cryptocurrency service providers from facilitating lending or staking activities. Lending and staking, where digital tokens are loaned or pledged to earn profits, are considered unsuitable for the general public due to their complex and high-risk nature.These measures come as part of Singapore’s efforts to strengthen its regulatory environment for digital assets. The consultation process began last year, following the collapse of FTX, a cryptocurrency exchange.Singaporeans suffered disproportionately with the collapse of FTX as previously, MAS had banned global crypto exchange Binance from operating within the city-state. That led to Singapore having more FTX customers than many other world regions. To compound matters, state-owned global investment firm Temasek, was an investor in the fraudulent crypto exchange.MAS had called for feedback and proposals, with a focus on enhancing investor safeguards and promoting responsible trading practices. While the regulations aim to provide a safer environment for investors, the MAS also emphasizes the importance of individuals exercising caution when engaging in digital token trading.Contrasting approachesWhile Singapore is taking steps to tighten regulations, other cities like Hong Kong are adopting a more inclusive approach to the crypto industry. Hong Kong Legislative Council member Johnny Ng has voiced support for the local crypto business and has encouraged prominent exchanges like Coinbase to establish operations in the territory, aiming to foster greater engagement and growth within the sector.As the crypto industry continues to evolve, regulatory frameworks play a crucial role in ensuring investor protection and maintaining market integrity. Singapore’s proactive approach to strengthening its regulatory environment reflects its commitment to striking a balance between fostering innovation and safeguarding the interests of investors.

news
Web3 & Enterprise·

Dec 13, 2023

Fingerlabs teams up with Metaclub to gather users for Web3 membership platform

Fingerlabs teams up with Metaclub to gather users for Web3 membership platformFingerlabs, a subsidiary of South Korean digital marketing company FSN, has decided to collaborate with reward points app Metaclub to expand user engagement for its Web3 membership platform Bling, according to an official press release on Wednesday (KST).Photo by NordWood Themes on UnsplashInnovating rewards systems and digital marketingMetaclub is a lifestyle platform that allows users to accumulate and spend reward points that can be used at various brands and websites. It currently boasts 80,000 members and hit a cumulative transaction value of KRW 30 billion (approximately $22.7 million) within a year after its launch. On the other hand, Bling is a marketing solution that allows businesses to create and manage NFTs that offer membership benefits to their customers. Users can create customizable characters on Favorlet, Fingerlabs’ NFT wallet and customer management service, using clothing or accessories called “parts.” These parts are linked to various benefits offered by Fingerlabs’ partner firms.Unique membership experienceThrough this collaboration, Bling and Metaclub are holding a promotional event where users who fill their Metaclub account with more than KRW 200,000 and collect Metaclub parts NFTs on their Bling account will be eligible to receive 3% in reward points.“By working with Metaclub, which has a high number of users in their 20s and 30s, we believe that Bling can quickly establish itself as a next-generation Web3 membership service,” said Kim Dong-hoon, CEO of Fingerlabs. “We have a clear understanding of the features and capabilities of both platforms, so we will be able to build our membership base through various collaborative projects.”

news
Loading