Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Aug 23, 2023

Coinone Boosts Crypto Account Security with Naver Two-Factor Authentication

Coinone Boosts Crypto Account Security with Naver Two-Factor AuthenticationCoinone, one of South Korea’s leading crypto exchanges, announced on Wednesday that it has added Naver as another channel for two-factor authentication (2FA) when signing up for an account. This move aims to enhance security and convenience for users by introducing another option for the second step of authentication in addition to KakaoTalk and one-time password (OTP) authentication.Photo by Franck on UnsplashCombatting social engineering attacks“As the popularity of investing in virtual assets is on the rise, attempts to gain unauthorized access to accounts through smishing and phishing have also increased. We hope that users can use Coinone services in a safer, more convenient manner by using Naver as an easy authentication channel,” said Cha Myunghun, CEO of Coinone.All users are required to go through 2FA when signing up for a Coinone account in order to simultaneously protect their credentials and conduct deposits, withdrawals, and transactions. Users must verify themselves with their phone number first, then once more through an additional channel like KakaoTalk, Naver, or OTP authentication.Using KakaoTalk or Naver is easy and convenient since most Koreans already have both of these apps on their phones, and it takes a relatively short amount of time to complete.Extra benefitsUsers can register for Naver authentication on both the Coinone website and the app. Once they do, they can verify themselves through the Naver app without a separate login. These users can be granted more benefits such as increased withdrawal limits, the exchange said. Those who have verified their bank accounts for storing Korean won can have a withdrawal limit of up to 500 million won (approximately $373,000).

news
Policy & Regulation·

Jul 02, 2025

Malaysian regulator seeks feedback on crypto framework enhancements

The Securities Commission Malaysia (SC), the statutory body tasked with regulating and developing capital markets within the Southeast Asian nation, has published a consultation paper in an effort to garner public feedback on potential enhancements to its crypto regulatory framework. In a press release published to its website on June 30, the SC claimed that its proposals seek “to enhance competitiveness of Malaysia’s regulated digital asset market, improve investor protection and strengthen the resilience and integrity of [Digital Asset Exchange] operators.”Photo by Vlad Shapochnikov on UnsplashEasing listing requirementsIn the event that the proposals are adopted, one key change would see a liberalization of the listing requirements for digital assets. Where certain key eligibility criteria have been met, the regulator would allow the listing of digital assets on digital asset exchanges without prior SC approval. The regulator stated that it wants to make this change in order to speed up the time taken to get digital assets to market as they emerge. By setting out additional criteria, there will be greater exchange operator accountability. Exchange operators would bear responsibility for listing tokens in compliance with the requirements set out by the regulator.  Assets could only be listed once those assets and the underlying protocol and network had undergone security audits which had been carried out by an independent and qualified blockchain security auditor, with the audit results made public.  For the purposes of the “Liberalised Listing Framework,” the asset must have been trading on a Financial Action Task Force (FATF)-compliant virtual asset service provider (VASP) platform for a minimum of one year. The regulator believes that easing the listing requirements will result in a broader digital asset product offering being made available in Malaysia. Last month, Thailand’s Securities and Exchange Commission (SEC) started a public consultation process aimed at revising token listing rules. Coin listing processes have also come under scrutiny from the authorities in South Korea recently. Segregating client assetsAmong the proposals is a plan to oblige exchange platforms to properly segregate client assets from operational funds and assets held by the exchange business. In recent years, many failed crypto exchange platforms, most notably FTX, got into difficulty by co-mingling customer funds with operational funds. Furthermore, the regulator doesn’t want any cross-over of assets between the local exchange operator and any overseas affiliate companies it may have.The SC stated that it is cognizant of recent global exchange failures, which has led it towards further enhancing crypto exchange operational governance and controls. It suggests that only 10% of client assets should be held by a Malaysian exchange in hot wallets, with the remaining 90% held in cold or offline wallets. The SC said that it welcomes feedback from members of the various stakeholder groups on the proposals outlined. The public consultation period runs from June 30 through Aug. 11.  Malaysia is expected to have 4.74 million crypto users by 2026. That would equate to 13% of Malaysians using crypto by then.

news
Policy & Regulation·

Dec 02, 2023

Binance’s U.S. legal woes may have repercussions for its expansion in Thailand

Binance’s U.S. legal woes may have repercussions for its expansion in ThailandWhile Binance, the world’s largest cryptocurrency exchange, is gearing up for a new trading venture in Thailand, the recent guilty plea by the firm in the United States and the hefty $4.3 billion penalties for anti-money laundering and sanctions violations have raised concerns about the feasibility of its Thai market venture.That’s a consideration that has been raised by a recent report by Bloomberg. Earlier this month, it emerged that Binance had entered the beta testing phase of its Binance.th platform in Thailand. The venture is a collaboration with the local company, Gulf Energy Development Pcl, led by billionaire Sarath Ratanavadi.Photo by Peter Borter on UnsplashCasting a shadow over expansion plansFollowing Founder Changpeng Zhao’s (CZ) departure from the CEO role in the wake of the US criminal probe resolution, Singaporean Richard Teng, a regulator-turned-crypto executive, has taken the helm at Binance. In its report, Bloomberg suggests that these recent issues in the U.S. have “cast a shadow over the planned domestic digital-asset platform” in Thailand.The new Binance CEO has emphasized Binance’s commitment to compliance overhaul and increased corporate transparency. In an interview Ratanavadi expressed confidence in Binance, noting that the company was not accused of crimes such as fraud or misuse of customer funds in the U.S. settlement. He stated:“Binance grew extremely fast and so probably crossed paths with some regulations.”Despite the regulatory storm, Ratanavadi chose Binance due to its market-leading position. The stringent scrutiny by Thailand’s Securities and Exchange Commission and the approval process, including inquiries about Binance, reflect the regulator’s cautious approach. The Gulf Binance Co. platform is set to launch fully in January, with Gulf Energy holding a 51% stake and Binance the remaining share.Challenges in other Asian marketsThe company may also face additional challenges in other Asian markets as a consequence of its regulatory troubles in the United States. While it remains to be seen if this was an unrelated development, it emerged earlier this week that regulators in the Philippines were moving to block access to the Binance platform and curtail the exchange’s ability to target Filipinos through advertising.In South Korea, Binance’s activities in the country have come under renewed scrutiny within the crypto community in the wake of the regulatory penalties Binance has experienced in the U.S. Binance is active in that market through its acquisition of fiat-to-crypto exchange GOPAX. While GOPAX management are unfazed by these events, others have suggested that there may be consequences in terms of the ability of GOPAX to achieve full regulatory approval.Demand reductionAnother challenge for the Thai venture includes a reduction in demand for crypto trading services in the Southeast Asian country. Official data reveals a significant drop in monthly trading volume at licensed digital-asset operators in Thailand, falling from over 250 billion baht in November 2021 to 17 billion baht ($490 million) in September 2023. The number of active trading accounts has plummeted by 87% from the peak in 2021.Ratanavadi, whose net worth is estimated at $11 billion, believes that tighter regulatory oversight will restore investor confidence. Gulf Binance’s technology partner, Advanced Info Service Pcl, with its retail outlets, is expected to contribute to the joint venture’s marketing efforts.

news
Loading