Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Policy & Regulation·

Feb 06, 2024

Haru Invest executives arrested for $750M crypto embezzlement

The joint virtual asset crime investigation unit of the Seoul Southern District Prosecutors' Office announced the arrest of three executives from South Korean cryptocurrency yield platform Haru Invest, according to a report by local news agency Yonhap. They are accused of embezzling cryptocurrencies valued at over 1 trillion Korean won ($750 million).Photo by niu niu on UnsplashFraud lawsuitThis development comes after approximately 100 investors filed a fraud lawsuit in June against the executives of Haru and Delio, another Korean crypto lending firm.  The three leading executives of Haru, one aged 44 and the other two aged 40, are facing fraud charges for failing to return cryptocurrencies deposited by around 16,000 customers.Misleading promotionsInvestigations uncovered that Haru Invest was offering misleading promotions for its products. Despite assurances that it utilized a risk-free, diversified investment strategy to manage user assets, Haru Invest predominantly allocated the majority of these assets towards concentrated investments from March 2020 to June 2023. Haru Invest had garnered attention from crypto investors, promising an annual return of up to 12%.  Subsequently, on June 13, Haru halted the withdrawal of digital assets without prior notice. The platform is currently in the midst of bankruptcy proceedings.  Delio, having allocated some of its assets with Haru, also came under public scrutiny that same month when it ceased withdrawals just a day following Haru's questionable action.

news
Web3 & Enterprise·

May 10, 2023

Zero Two Enters Into JV to Develop First Middle East Mining Op

Zero Two Enters Into JV to Develop First Middle East Mining OpZero Two, a digital assets development company based in Abu Dhabi in the United Arab Emirates (UAE), has partnered with leading North American crypto miner Marathon Digital in a joint venture that will result in the development and operation of the Middle East’s first large-scale crypto mining facility.Photo by Manuel Geissinger on PexelsInitial capacity of 250 MWIn a press release issued on Tuesday, Marathon Digital outlined that the venture is focused on accelerating the global digital economy while also supporting Abu Dhabi’s power grid.To progress the project, the two companies have formed the Abu Dhabi Global Markets JV Entity (AGDM Entity). Initially, two digital asset mining facilities, with a combined capacity of 250 MW, will be developed.One site, at Masdar City, Abu Dhabi, will account for 200 MW of that capacity. The remaining 50 MW capacity will be developed at a site located in the port area of Mina Zayed. The strategy of the firms is to exploit excess network energy in Abu Dhabi. The firms see this as a win/win as increasing the base load of the Abu Dhabi power grid will result in a more sustainable grid. The companies intend to supplement any use of non-sustainably produced energy with carbon offset certificates.80/20 equity splitThe two firms have agreed upon an 80%/20% equity split, with Zero Two being the lead investor. In the initial development period for the venture during 2023, both entities will contribute resources to the joint venture in proportion to the equity division, in the form of capital, equipment and infrastructure.Zero Two and Marathon had previously collaborated on a pilot project with the objective of determining the feasibility of building a large-scale facility. Air-cooled miners have not proven to be a success in hot arid climates like that of the Rub Al Khali Middle Eastern desert.The upshot of the pilot program was a determination that a custom-built immersion-cooled system would be feasible. Mining equipment for the facilities is already on order while construction at the two sites is underway. Both sites are expected to go online before the end of the year with a combined hashrate of 7 EH/s.Ahmed Al Hameli commented on the joint venture: “This alliance leverages Zero Two’s regional expertise, expansive relationships, and growing blockchain infrastructure development and operational capabilities, with Marathon’s technical prowess in developing digital asset sites and innovative mining technologies.These synergies create a powerful combination and lay the groundwork for the success of this pioneering project in the Middle East. Marathon shares our commitment to actively supporting Abu Dhabi’s power grid and developing global digital assets infrastructure. We look forward to working with them on this venture.”Jurisdictional arbitrageMarathon’s CEO Fred Thiel said that Zero Two’s regional relationships were an optimal compliment. It may be both a timely and shrewd move by Marathon to develop this project in the Middle East region. In recent weeks the Biden administration floated the idea of a 30% crypto mining tax. Crypto mining is a global endeavor.That type of additional overhead would make it very difficult for North American miners to remain viable. By opening up new working relationships in other regions, the company may be in a better position to pivot should North America and the firm’s Montana-based mining facility become unsustainable.

news
Web3 & Enterprise·

Aug 22, 2024

Tether plans launch of dirham-pegged stablecoin

Tether, the issuer of the USDT stablecoin, has teamed up with local partners in the United Arab Emirates (UAE) in order to launch a dirham (AED)-backed stablecoin. In a statement published to the firm’s website on Aug. 21, Tether outlined that the stablecoin is being launched in partnership with Dubai-based technology conglomerate Phoenix Group and Green Acorn Investments, a company that describes itself as “a socially responsible investment firm dedicated to supporting critical sectors and supporting the generation of sustainable wealth and financial literacy.”Photo by DrawKit Illustrations on UnsplashFully backed by AED reservesThe stablecoin issuer outlined that each token will be “fully backed by liquid UAE-based reserves.” Tether further maintained that the back-end management of the new token will adhere to the firm’s “transparent and robust reserve standards,” and that “every Dirham-pegged token is tied to the value of the AED, providing stability and confidence in its value.”  Tether dominates the stablecoin market where USDT accounts for $117 billion, against a backdrop of an overall stablecoin market valued at $169 billion.  Perennial skepticsThe company has perennially faced criticism for a lack of transparency relative to the backing of its USDT stablecoin, given its policy of providing attestation reports instead of fully comprehensive audits from a top-tier auditing firm. One of the firm’s critics, the pseudonymous X account @OccamiCrypto took to the social media platform to provide its reaction to this most recent development, stating: "This Tether UAE stablecoin 'launch' will likely be as real as Tether’s promised audit and real time reserve reporting." The Tether critic went on to claim that the announcement is nothing more than "Tether spin," and that Tether has never attempted to become regulated in any market and that nothing would come of it. Another Tether critic, freelance journalist Jacob Silverman, commented on the development on X, stating:”Russian businessmen in UAE must be rejoicing.” His comment is suggestive of a common assertion that Tether is being used to facilitate the circumvention of sanctions. According to the firm’s press release, it believes that the product will enable users locally to access the benefits of the AED in digital form. The company claims that it will “streamline international trade and remittances, reduce transaction fees, and provide a hedge against currency fluctuations, thus playing a crucial role in the financial ecosystem of the UAE and beyond.” Tether’s partner Phoenix Group has been active in the crypto-sphere in recent times through mining. In December of last year, the company sealed a $380 million deal with Chinese mining equipment manufacturer MicroBT. Earlier that month, the company went public on the Abu Dhabi Securities Exchange (ADX). On face value, this development appears positive. However, UAE-based crypto and blockchain lawyer Irina Heaver recently warned that tightening regulations within the UAE may shut down crypto payments within the country. Heaver specifically cited the use of USDT as being under threat, with the potential for stablecoin-based transactions to be prohibited as new rules are ushered in.  

news
Loading