Top

CoinEx Reveals Insights Into Recent Platform Hack

Policy & Regulation·September 20, 2023, 1:33 AM

Hong Kong crypto exchange CoinEx has issued a further update relative to the security breach that occurred on the platform last week resulting in one of the exchange’s hot wallets being compromised.

Photo by FLY:D on Unsplash

 

Immediate response

In the immediate aftermath of the $70 million hack, CoinEx took action to safeguard user assets and initiate an investigation into the incident. It suspended all deposit and withdrawal services and executed an emergency shutdown of the hot wallet server. Following this, the company securely moved the remaining assets to cold storage, commencing the process of reconstructing and deploying a new wallet architecture.

The firm also engaged in an investigation, spearheaded by its wallet and security teams, to ascertain the extent of the breach. Moreover, CoinEx claims to have proactively reached out to fellow exchanges to freeze any assets related to the attack.

Haipo Yang, the Founder and CEO of CoinEx, conveyed his apologies to affected users through his personal X (formerly Twitter) account. He emphasized the team’s commitment to restoring services promptly and reassured users that their funds will remain secure.

Following up on that commitment, CoinEx published an update on the hot wallet hack on September 15 to address these concerns individually.

 

New wallet deployment

The exchange expects to finalize wallet upgrades within the upcoming week, after which withdrawals will gradually be phased in, subject to security evaluations. The CoinEx team is currently working on developing and deploying an entirely new and robust wallet system capable of managing activities across 211 chains and 737 assets.

The firm has outlined that each of its product lines operates independently, featuring its own risk control system. Consequently, the security incident that occurred on CoinEx will not affect the integrity of its other product lines.

In its most recent update on Tuesday, the Hong Kong crypto exchange confirmed that 80% of its wallet system has now been reconstructed. It added that it has initiated preparations to enable the withdrawal system on the platform. It stated:

”Details about the resumption of withdrawals, including specific dates, times, and arrangements, will be announced on the CoinEx website. Please stay updated on our announcements for the latest information.”

 

Ongoing investigation

Regarding the identity of the attacker, CoinEx has confirmed that the matter is currently under investigation. While some security firms have made attribution claims, the company is focusing primarily on deploying the new wallet architecture, restoring affected users and functionalities, and enhancing overall security.

At the same time, the company has initiated communications with the hackers in a bid to proactively seek a mutually agreeable resolution. While the incident implicates the loss of a substantial amount of funds, the firm maintains that in the context of the overall business, the sum represents only a small percentage of total assets under its management.

Exchange security remains a major challenge in the crypto sector, with hacks happening on an ongoing basis. Last week, Seychelles-headquartered peer-to-peer crypto platform Remitano acknowledged a $2.7 million hack. At the beginning of September, crypto gambling platform Stake was reported to have suffered a $41 million hack.

More to Read
View All
Markets·

Jan 25, 2024

OKX to compensate service users following flash crash

OKX is set to compensate users after its native exchange token, OKB, experienced a rapid 48% flash crash on Tuesday. OKB price fluctuationThe crash occurred within a brief three-minute window, triggered by a series of liquidations resulting from an abnormal price fluctuation. During the event, OKB's diluted market capitalization plummeted by $6.5 billion. At around 9 a.m. GMT on Tuesday, the price of OKB dropped from $46.80 to $25.10, representing a 48% decrease within 15 minutes. However, the token has since recovered, currently trading at $47.63 at the time of writing. The crash led to the triggering of liquidations for large leverage positions, causing a cascading effect on pledged loans, leverage transactions and cross-currency transactions.Photo by Nicholas Cappello on UnsplashCompensation planOKX responded promptly, pledging to fully compensate users for any additional losses incurred due to abnormal liquidation. The exchange aims to launch a specific compensation plan within the next three days, taking into account users who engaged in on-chain trades. In a statement on Tuesday, the platform suggested that it is committed to enhancing "margin position tier rules, risk management controls and liquidation mechanism" to prevent similar issues in the future. The flash crash coincided with a day of notable price swings across cryptocurrency markets, partly driven by the Grayscale Bitcoin Trust's (GBTC) sale of bitcoin to meet investor redemption demands on its exchange-traded fund (ETF). Additionally, the bankrupt crypto exchange FTX has been selling nearly $1 billion worth of GBTC ETF shares recently, further contributing to market volatility. Focusing on complianceOKX has been actively focusing on regulatory compliance in recent times. On Dec. 29, the exchange announced the delisting of several privacy coins, including Monero (XMR), Zcash (ZEC), Dash (DASH) and Horizen (ZEN). Subsequently, on Jan. 2, the platform introduced additional requirements for United Kingdom users to comply with the new Financial Conduct Authority (FCA) regulations, including the mandatory completion of risk assessment questionnaires before engaging in trading activities. Flash crashes are a common occurrence in cryptocurrency markets, often attributed to thin liquidity distributed across multiple venues. The 2% market depth for OKB indicates that a sell order exceeding $224,000 could potentially trigger another price cascade. Notwithstanding that, oftentimes it can be difficult to pinpoint the precise reason for a flash crash. In 2021 global crypto exchange Kraken experienced a flash crash that saw token prices drop by in excess of 50% over the course of one hour before recovery was achieved. While some suggested it was caused by a technical glitch, Kraken founder Jesse Powell dismissed that notion, pointing instead to the possibility of a large-scale sell-off by a service user. Despite this recent challenge, OKB remains a significant player in the cryptocurrency space, boasting a market cap of $2.8 billion, making it the fourth-largest exchange token in circulation, according to CoinGecko. 

news
Policy & Regulation·

Aug 02, 2023

Bankruptcy Judge Permits Terraform Labs to Subpoena FTX

Bankruptcy Judge Permits Terraform Labs to Subpoena FTXIn a significant development in the bankruptcy case of defunct crypto exchange FTX, a judge has granted Singapore-based Terraform Labs the authority to subpoena information related to its ongoing case brought by the United States Securities and Exchange Commission (SEC).Photo by Bermix Studio on UnsplashHack allegationsTerraform Labs, the blockchain company that developed the Terra blockchain and failed US dollar stablecoin UST, claims that the failures of its algorithmic stablecoin and governance token were the result of an attack from short-sellers, possibly involving Alameda Research (FTX’s sister company).The order, issued by Judge John Dorsey on Monday, allows Terraform Labs to serve subpoenas to FTX Trading and FTX US, aimed at collecting evidence to support its defense against the SEC’s allegations of fraud. According to court filings, lawyers representing the FTX Debtor have not formally objected to the court order.Terraform Labs’ request for subpoena power stems from its belief that short-sellers connected to FTX entities played a role in the failure of the algorithmic stablecoin and governance token, leading to the collapse of the crypto firm. The ability to obtain information from FTX through the subpoenas could be crucial in bolstering Terraform Labs’ defense against the SEC’s fraud charges.UST collapse falloutThe collapse of the UST stablecoin in 2022 contributed to a major market crash, resulting in a significant drop in the prices of many tokens. As a result, the company filed for bankruptcy in November 2022. The Co-Founder of Terra, Do Kwon, is currently serving a four-month sentence in a Montenegrin prison for using false travel documents. He may also face extradition to the United States or South Korea on fraud charges related to Terraform Labs.Motion to dismiss deniedIn a separate high-stakes ruling, US District Judge Jed Rakoff denied Terraform Labs’ motion to dismiss the securities fraud lawsuit filed by the SEC. The judge’s decision allows the SEC’s case against Terraform Labs and Do Kwon to proceed, rejecting defense arguments that the agency lacked jurisdiction and that Terraform’s TerraUSD stablecoin did not qualify as an unregistered security.Judge Rakoff’s ruling is a significant victory for the SEC as it intensifies its enforcement actions against crypto companies involved in allegedly unlawful token sales. He found the collapse of TerraUSD, which lost its dollar peg and incurred a $40 billion loss last year, plausible as a reason to consider the token as a security that should have been registered.Moreover, Rakoff dismissed Terraform’s claim that the SEC lacked the authority to regulate stablecoins without explicit Congressional authorization, asserting that the crypto industry was significant enough to warrant application of the “Major Questions Doctrine.” This doctrine limits agency overreach into major political issues but does not apply to the crypto asset markets.The judge also rebuffed Terraform Labs’ attempts to draw parallels between the Ripple case and its own. In the Ripple case, a different judge ruled that Ripple’s XRP token sales to retail investors did not violate securities laws due to the manner of purchase on secondary markets. Rakoff firmly stated that such distinctions did not apply under the legal Howey test governing whether crypto assets qualify as securities.

news
Policy & Regulation·

Dec 14, 2023

U.S. authorities seize crypto tied to Asian ‘pig butchering’ scam

U.S. authorities seize crypto tied to Asian ‘pig butchering’ scamThe United States government has taken control of digital currency valued at approximately half a million dollars from an account linked to a Chinese individual implicated in a Reuters investigation into a crypto-investment fraud originating from Southeast Asia.Photo by Growtika on Unsplash‘Pig butchering’According to Reuters, U.S. officials have disclosed that the seized assets are connected to a crypto-investment scam known as “pig butchering,” where fraudsters manipulate unsuspecting individuals they encounter online, convincing them to invest in fraudulent crypto schemes.The unsuspecting scam victim (the pig) is conned by scammers into handing over money with the promise of an outsized return. Once funds have been handed over, the vast majority of victims are unable to recover their money.According to a document filed by U.S. authorities in federal court in Massachusetts, the U.S. Secret Service confiscated the crypto in June from an account registered to Wang Yicheng. At the time of the seizure, the digital currency was valued at around $500,000. The funds were traced back to a victim in Massachusetts who had initially fallen prey to the scam.In a recent Reuters article, Wang was identified as a businessman who cultivated relationships with members of Thailand’s law enforcement and political elite while serving as the vice president of a Chinese trade group based in Bangkok. The report outlined that a crypto account in Wang’s name had received over $90 million in recent years, with at least $9.1 million linked to a crypto wallet associated with pig-butchering scams, as reported by U.S. blockchain analysis firm TRM Labs.Multi-million dollar scamsOne case highlighted in the report involved a California man who was scammed out of approximately $2.7 million, funds that were channeled into the account in Wang’s name. Another example cited in the U.S. court filing detailed a resident of Cambridge, Massachusetts, who was allegedly defrauded of about $478,000 worth of crypto, which ended up in two crypto accounts, one of which belonged to Wang.The U.S. court filing, part of a civil forfeiture action, seeks court approval to take possession of assets linked to the alleged crime. While no criminal charges have been filed, Acting U.S. Attorney Joshua Levy emphasized the use of civil forfeitures to recover funds stolen through crypto fraud schemes, highlighting law enforcement’s adaptability in the face of cryptocurrency transactions’ seemingly elusive nature.Crypto scammers sanctionedIn a related development, authorities in the United Kingdom reported on Friday that individuals operating pig butchering crypto scams in Myanmar, Cambodia and Laos had been sanctioned, in a move coordinated with their counterparts in the U.S. and Canada, alongside the United Nations Human Rights Organization.Many of these cases are understood to involve human trafficking, where individuals are illegally detained and forced to work on pig butchering crypto scams.

news
Loading