Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jan 24, 2024

OKX and HashKey plan partnership to promote industry development

HashKey Group, the Hong Kong-based regulated cryptocurrency exchange, is planning a partnership with crypto derivatives platform OKX.Photo by Ivan Lau on UnsplashAdvancing innovation and growthThe duo announced their plans via a press release which was published on Tuesday. The objective of the partnership is aimed at advancing compliant virtual asset innovation and industry growth in Hong Kong. The collaboration between HashKey Group and OKX capitalizes on the strengths and resources of both entities to elevate services and experiences. Harnessing these strengths the pair intend to contribute towards Hong Kong's emergence as a hub for the regulated virtual asset industry. The partnership will encompass various industry initiatives, including blockchain infrastructure development, product diversification and virtual asset investment education within the region. First regulated exchangeNotably, HashKey Group achieved a significant milestone last year by becoming the first Hong Kong Securities and Futures Commission (SFC)-regulated crypto exchange authorized to serve retail users. The firm secured Type 1 and Type 7 licenses from the SFC, in line with the  "compliance first” approach the company is taking. Founded in 2018 and headquartered in Hong Kong, with operations in Singapore and Tokyo, HashKey Group caters to a diverse clientele, including retail investors, institutions, family offices, funds and professional investors. The services offered by the company encompass a Hong Kong SFC-regulated virtual asset exchange, global asset management and wealth management, with a focus on blockchain and digital assets, blockchain node validation, tokenization and Web3 incubation and community operations. Its Singaporean subsidiary, digital asset fund manager HashKey Capital, secured a regulatory license from the Monetary Authority of Singapore (MAS) in December. Unicorn statusOKX Ventures, the investment division of OKX, played a crucial role in supporting HashKey's Series A financing. That Series A funding round saw HashKey achieve unicorn status with a $1.2 billion valuation earlier this month. OKX Ventures focuses on investing in projects that nurture sustainable growth within the global virtual asset ecosystem. OKX, already serving over 50 million users worldwide, has a notable presence with sponsorships that include Manchester City FC in the English Premier League (EPL) and the McLaren Formula 1 racing team. Earlier this month, the company expanded its sponsorship with McLaren. The digital asset exchange began onboarding customers in Hong Kong a month before officially launching operations there, aligning with the city's new virtual asset service providers (VASPs) regime implemented on June 1 of last year. In March 2023, OKX established a Hong Kong entity to launch virtual asset services, with plans to apply for the virtual asset service provider (VASP) license and Type 1 & 7 licenses under the Securities and Futures Ordinance. Approval is anticipated by early 2024. The collaborative effort between HashKey Group and OKX marks a significant stride in advancing compliant virtual asset innovations in Hong Kong. This partnership aims to enhance service offerings and customer experiences, further solidifying Hong Kong's position as a regulated virtual asset industry hub. By leveraging their respective strengths, these industry leaders are well placed to assist in elevating Hong Kong's standing in the global virtual asset landscape, fostering growth and compliance in this rapidly evolving sector.  

news
Web3 & Enterprise·

Nov 23, 2023

Shinhan Card to launch NFT-based art-tech service next year

Shinhan Card to launch NFT-based art-tech service next yearSouth Korean credit card company Shinhan Card is set to launch its art-tech service dubbed “Prestige Collection” next year, according to Park Young-woong of the Digital R&D team during his presentation at the seventh annual Shinhan Future’s Lab Demo Day event held in Seoul on Wednesday.Photo by Yi Liu on UnsplashDigitizing investments in artArt-tech — a portmanteau of art and money management technology — refers to an investment method that involves purchasing or owning artworks as assets and earning profits from their sales.“We are planning to launch our art-tech service next year, which will include exhibition recommendations, NFT ticketing and NFT art warranties to work in tandem with Shinhan Card’s payment services,” Park said. He also mentioned that it is currently undergoing legal evaluations.Making event access more efficientThe inception of this upcoming release started in September, when Shinhan carried out a collaborative proof of concept (PoC) mechanism with two member startups from the ninth installment of its Future’s Lab startup acceleration program, Art Map and SnapTag.Art Map is an art curation service put together by a team of database experts, software developers, artists, curators and designers that gathers metadata based on users’ preferences to recommend exhibitions and other art-related events for them to enjoy. On the other hand, SnapTag offers a variety of services based on its patented invisible watermark technology dubbed LAB Code. LAB Code is able to create an encrypted code by subtly converting image pixels of items like product packages, photos and illustrations and applying those files to printing or production processes without damaging or changing the original image.Last month, Art Map and SnapTag used their respective technologies to work with Shinhan Card to issue and verify blockchain-based NFT tickets for the Sneakers Unboxed special exhibition held at the Sejong Museum of Art. Shinhan was responsible for minting NFTs as tickets for exhibitions promoted on Art Map’s platform, which could be issued and stored on the My NFT section on Shinhan’s mobile app ShinhanpLay. Visitors would then be able to use SnapTag’s digital check-in service Keefo to enter the exhibition.This NFT ticketing system was proven to be a time-efficient and secure alternative to traditional ticketing procedures, which come with several inconveniences like long wait lines, delayed entry, illegal ticket resells and monopolization of customer data by major ticketing conglomerates. This is especially true for music performances by famous artists, where competition during ticket sales can become intense.“Our NFT ticketing service will evolve into an art-tech management service that focuses on art,” Park explained. “Prestige Collection will leverage Art Map’s art concierge platform, SnapTag’s LAB Code technology and Shinhan Card’s My NFT service.”

news
Policy & Regulation·

Jan 08, 2024

Samjong KPMG and Xangle seminar says crypto market will improve this year

According to crypto data research platform Xangle, the crypto market is on the road to recovery this year thanks to positive outlooks on developments like a spot Bitcoin ETF, regulatory changes and diversified services.Photo by CHUTTERSNAP on UnsplashBitcoin’s resilienceSpeaking at a special seminar on virtual assets co-hosted by CrossAngle and accounting firm Samjong KPMG in Seoul last Friday, Kim Jun-woo, Co-Founder and CEO of Xangle, cited Bitcoin’s positive reputation as one of the reasons for the optimism. "There are reports that Bitcoin has a low correlation with risky virtual assets," he said. Public sentiment toward Bitcoin is also expected to improve this year as the global economy is expected to emerge from recession and manage a soft landing. Another major item on the agenda is a possible approval by the U.S. Securities and Exchange Commission (SEC) of a spot Bitcoin ETF this quarter. Web3 revolutionIn terms of innovative services, Kim stated that Web3 is expected to be actively implemented in local corporations after going through conceptual and technical testing stages. "In South Korea’s crypto market, (resources like) app stores and mobile phones exist, but there are no actual apps," Kim said. "I expect that figures from traditional finance and existing Web2 companies will enter the Web3 industry this year."  "Web2 companies will discover new business opportunities in Web3 and play a role in bringing existing content and users to Web3," said Lee Hyun-woo, Co-CEO of Xangle, in his presentation on the importance of Web3 system integration and virtual asset disclosure. "Their participation is important for the stable maturation of the Web3 ecosystem," he added. Regulation and governanceIn regards to policies and regulations, expectations point to a resolution of various uncertainties as cryptocurrencies are slowly becoming more integrated into the sphere of traditional finance. In South Korea, the imposition of basic legal regulations on virtual assets is accelerating, such as the Virtual Asset User Protection Act. The Financial Services Commission (FSC) also released guidelines for accounting and disclosure of virtual assets last month, which was examined in detail at the seminar. "The financial authorities' guidelines are more detailed than before. We expect additional guidelines from them in the future to further resolve shortcomings," Choi Yeon-taek, Managing Director of Samjong KPMG, commented.

news
Loading