Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Policy & Regulation·

Sep 22, 2023

Busan’s Digital Asset Exchange to Transform the City into a Global Financial Hub

Busan’s Digital Asset Exchange to Transform the City into a Global Financial HubBusan, the southern port city in South Korea, has unveiled an extensive plan for the creation of the Busan Digital Asset Exchange. The primary aim of this initiative is to establish a blockchain-based exchange that facilitates the trading of a wide range of valuable assets, including raw materials, precious metals, intellectual property rights, and carbon emission rights, all through tokenization.Photo by Joseph Pradipta on UnsplashDecentralized governance modelThis planned exchange will operate under a decentralized governance model, where separate entities will handle depository and settlement, listing assessment, and market monitoring. Such a governance framework is designed to ensure checks and balances and enhance investor protection. Busan is committed to providing both administrative and financial support for the establishment of these entities.The roadmap for this plan was presented yesterday at Busan City Hall by Mayor Park Heong-joon and the Busan Digital Asset Exchange Establishment Promotion Committee.The committee was introduced by the city in December of last year, and since then, it has been crafting specific plans. This committee is led by former lawmaker Kim Sang-min, who is recognized as an expert in blockchain policy.Operator selection processThe legal operator for the exchange is slated to be launched within this year. Starting from the middle of the upcoming month, the city of Busan will initiate an application-based process to find an exchange operator and intends to finalize the selection by November.The operator will be entirely funded through private contributions. Companies possessing blockchain technology and the capability to construct an exchange system will form a consortium to partake in the project and operate the exchange. The city of Busan will support the founding and operation of the exchange in accordance with the ordinance.Diverse asset tokenizationShould everything proceed as planned, the exchange is set to commence operations next year. It will tokenize and support the trading of items that pass through the Port of Busan, including gold, silver, copper, crude oil, and ammonia. Additionally, a marketplace will be developed to trade intellectual property (IP) rights, such as films, and carbon emission rights. Particularly, there are plans to broaden the spectrum of tradable items to include virtual assets and security tokens.In contrast to traditional stock exchanges that utilize home trading systems (HTS), the upcoming digital asset exchange will run on blockchain, which is immune to hacking and forgery. Users can trade their assets directly without intermediaries and benefit from reduced transaction costs.Highlighting blockchain as a pivotal technology in the era of the Fourth Industrial Revolution, Kim Sang-min, the chair of the committee, expressed that Busan will develop its digital asset exchange to set a global standard in the field.Mayor Park resonated with this perspective, emphasizing that in this age of digital transformation, Busan will leverage this opportunity to position itself as a global financial hub.

news
Web3 & Enterprise·

Jul 13, 2023

3D Avatar Platform GoodGang Labs Joins Finschia as Joint Mainnet Operator

3D Avatar Platform GoodGang Labs Joins Finschia as Joint Mainnet OperatorGoodGang Labs, a Singapore-based metaverse platform developer, is set to become a joint operator of the public blockchain mainnet Finschia, as reported by South Korean news agency Yonhap.The Finschia mainnet was launched by Line Tech Plus, a blockchain business subsidiary of Tokyo-based messaging app developer Line Corporation. It has been operated by the Finschia Foundations, a non-profit organization established in March in Abu Dhabi, United Arab Emirates.Photo by GuerrillaBuzz on UnsplashAdvancing Finschia’s governanceGoodGang Labs’ participation as a joint operator of the mainnet came as part of the Finschia Foundation’s establishment of a new consortium to advance its governance structure. Along with GoodGang Labs, many esteemed companies have joined as governance members to collaborate on operating the mainnet. These companies include Japanese telecom giant SoftBank, NFT platform operator LINE NEXT, blockchain infra-service provider A41, crypto firm AhnLab Blockchain Company, CeDeFi protocol Neopin, quantitative trading firm Presto Labs, and GameFi-oriented platform MARBLEX.GoodGang Labs specializes in developing technology that utilizes artificial intelligence (AI) to translate users’ facial expressions and behaviors into real-time 3D avatars. Leveraging this technology, the company is currently piloting Kiki Town, a 3D avatar communication platform.Finschia-based NFT projectsWith its involvement in Finschia, GoodGang Labs will allow various Finschia-based NFT projects to have access to the company’s services including the Kiki Town platform. FNSA, the base coin of the Finschia ecosystem, is currently listed on cryptocurrency exchanges Bithumb, Bittrex, Huobi, and Gate.io, according to crypto data tracking website CoinMarketCap.Ahn Doo-kyung, Co-Founder and CEO of GoodGang Labs, said that this partnership demonstrates the company’s capabilities during times of limited investment opportunities. He stated that GoodGang Labs will showcase a profit-generating platform that enables users to express their emotions through avatars and share their knowledge and experiences.The members of GoodGang Labs have acquired their tech expertise from notable entities such as SNOW, a subsidiary of South Korean tech behemoth Naver, and Meta, the parent company of Facebook. The company has received investments from Naver D2 Startup Factory, a startup accelerator; Naver Z, the operator of metaverse platform Zepeto; and Kakao Investment, the venture capital subsidiary of another Korean tech giant, Kakao.

news
Web3 & Enterprise·

Dec 14, 2023

NiceHash targets Asian market through EasyMining platform launch

NiceHash targets Asian market through EasyMining platform launchNiceHash, a Slovenian bitcoin mining and hashpower marketplace, has launched its crypto mining platform in Asia, known as EasyMining.Cloud-based crypto miningEstablished in 2014 by two Slovenian university students, NiceHash stands as the largest cloud-based crypto-mining hashpower marketplace globally. Boasting over 250,000 daily active miners and a user base spanning 190 countries, the platform serves as a link between hashing power suppliers and consumers, operating within the framework of the sharing economy.NiceHash published a press release from Singapore on Tuesday to announce the Asian product launch. The company has already established collaborations in the region, with Singaporean mining equipment designer iPollo appearing as a featured partner on the firm’s website.Photo by Traxer on UnsplashProduct offeringAt the core of NiceHash’s offerings is the facilitation of crypto trading and global hashpower. It claims to provide an innovative and seamless connection between miners and hashpower providers. Whether it’s mining with CPU, GPU or ASIC equipment, platform users can engage in the process to earn cryptocurrencies or sell surplus computing power, presenting an opportunity for profit without the need for an extensive data center.NiceHash employs various security measures to ensure the validity and safety of transactions. These include SSL encryption, 2-factor authentication and email notifications, enhancing the security of accounts and payments. The cost of NiceHash mining is set at 0.001 BTC, offering a range of 34 mining algorithms and supporting various coins to cater to the interests of a broad user base.The firm offers a QuickMiner service, an automatic mining program that simplifies the mining process for subscribers. Through the use of this application, miners and hashpower renters can kick-start their operations immediately.Miners and providers have the ability to trade hashpower on the platform, with dynamic pricing adjusting every 10 seconds based on cryptocurrency values, hashpower availability and miner demand.For hashpower sellers, NiceHash offers the Profitability Calculator, a tool that enables users to calculate daily mining earnings by inputting their mining rig specifications and power costs. The platform supports CPU, GPU and ASIC mining, allowing miners to focus on the most profitable algorithm and token pairings.EasyMining, the latest addition to NiceHash’s repertoire and the product it is now offering in the Asian region, represents a significant step forward for the firm in simplifying cryptocurrency mining. The company claims that users can select their preferred cryptocurrency, letting the platform handle the mining process securely and effortlessly.Changing market conditionsCrypto platforms have had to be agile in 2023, as the underlying environment for crypto-centric offerings has been subject to rapid change in many jurisdictions. While NiceHash is making a concerted effort to etch out a market share within the Asian market through this product launch, it’s also had to withdraw its services from another market in recent months.On Sept. 27, the company informed its customers that it was withdrawing from the UK market. In a letter to users, it stated:”Due to the recent regulation changes in the United Kingdom we are no longer able to provide services to those residing in the United Kingdom.” . . . “We are working hard to be able to resume our services to UK residents as soon as possible.”The company withdrew all services from the UK market, including the exchange, mining, hashpower marketplace and wallets.

news
Loading