Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Policy & Regulation·

Jun 01, 2023

Korean Crypto Exchange Alliance Reveals Standardized Regulation Guidelines

Korean Crypto Exchange Alliance Reveals Standardized Regulation GuidelinesThe Digital Asset eXchagne Alliance (DAXA), consisting of five leading cryptocurrency exchanges in South Korea, today revealed standardized regulation guidelines, according to a report by news media The Asia Business Daily.Photo by Nick Fewings on UnsplashStandardized guidelinesTwo important documents — the standardized internal control framework and the code of conduct and ethics — were released by DAXA today. These documents were developed based on data provided by financial investment firms and member exchanges. Reviewed by DAXA members and advisors, this documentation represents a significant milestone as it is the first of its kind to address the unique characteristics of the crypto industry. The establishment of unified rules and regulations through the collaborative efforts of the member exchanges stands as a commendable achievement.Internal control frameworkThe internal control framework consists of five parts, encompassing a total of 68 articles. These parts cover general provisions; governance of virtual asset service providers (VASPs); organization and standards for internal control; compliance officers and internal control system management; and compliance details.Code of ethicsThe code of conduct and ethics comprises five chapters with 24 articles. These chapters focus on general provisions, customer ethics, employee ethics, corporate management ethics, and societal ethics.DAXA Vice Chairman Kim Jae-jin expressed optimism that these guidelines will serve as a valuable reference for all VASPs, fostering the development of a fair, trustworthy, and globally competitive crypto market.DAXA’s websiteLast month marked the launch of DAXA’s official website, and their YouTube channel has been active since January. The alliance is made up of five member exchanges: Gopax, Bithumb, Upbit, Korbit, and Coinone. At the helm of the alliance is Chairman Lee Sirgoo, who concurrently serves as CEO of Dunamu — the company operating Upbit, the largest cryptocurrency exchange in the nation.

news
Policy & Regulation·

Jun 22, 2023

Ripple Receives In-Principle Approval From Singaporean Regulator

Ripple Receives In-Principle Approval From Singaporean RegulatorRipple, the blockchain-based payments firm, has obtained in-principle regulatory approval from the Monetary Authority of Singapore (MAS) to offer digital asset payments and token products in Singapore.Photo by Dids on PexelsODL service expansionThe approval, announced on Wednesday, will enable Ripple’s subsidiary, Ripple Markets Asia Pacific, to expand its On-Demand Liquidity (ODL) service. ODL facilitates the seamless transfer of the XRP cryptocurrency across borders without the involvement of traditional banking intermediaries.Ripple had applied for an institutional payment license under Singapore’s Payment Service Act to secure the regulatory green light. In response to the approval, Ripple CEO Brad Garlinghouse praised the MAS for its pragmatic and innovation-driven approach to cryptocurrency-related services.He expressed confidence that Singapore would serve as a prominent gateway for Ripple’s business operations in the Asia Pacific (APAC) region. On Twitter, Garlinghouse wrote: “As a major global financial center, Singapore led the way in taking a pragmatic, innovation-first approach to crypto — we’re incredibly proud @Ripple is one of a handful of firms (<20) to receive in-principle approval for a MAS MPI license for digital payment token services!”Stuart Alderoty, Ripple’s Chief Legal Officer, explained that the regulatory approval from MAS would enhance Ripple’s ability to support forward-thinking customers who are exploring the potential of blockchain and crypto technologies to create a more inclusive and borderless financial system.Growing APAC presenceRipple’s presence in Singapore has already been growing significantly. In 2022, the company doubled its number of employees at its Asia Pacific headquarters, with Singapore becoming a major hub for ODL transactions. The MAS, recognizing the potential of fintech firms in the digital money services sector, published its Purpose Bound Money (PBM) white paper on Wednesday, proposing standards for such firms operating in Singapore.While Ripple has made progress with regulatory compliance in Singapore, it has faced legal challenges in other jurisdictions. Since December 2020, Ripple’s legal team has been dealing with a lawsuit filed by the US Securities and Exchange Commission (SEC), accusing Ripple of conducting an unregistered securities offering with its XRP token.The case is expected to reach a verdict in the coming months. While the speculation is that the case has gone well for Ripple, it remains to be seen to what extent it can get the upper hand in taking on a cornerstone institution of the US establishment like the SEC.Either way, Ripple is moving to develop on a global basis. It has recently pursued further development in the Middle East via a Dubai expansion. In Hong Kong, it is collaborating with local regulators in trialing the use of its technology relative to real-world asset tokenization.The company has also established partnerships with central banks in Montenegro and Thailand, as well as numerous regional banks and financial institutions worldwide.The regulatory approval from MAS marks a significant milestone for Ripple, expanding its customer reach and positioning the company for further growth in the digital asset payment sector. Digital asset innovation is truly global and as many organizations are demonstrating, just as Ripple is in this instance, innovative curtailment in one region will simply manifest itself as greater development in another.

news
Web3 & Enterprise·

Jun 02, 2023

Wemade Introduces New DeFi Services on WEMIX3.0 Mainnet

Wemade Introduces New DeFi Services on WEMIX3.0 MainnetKorean blockchain game maker Wemade announced today that it will deploy decentralized finance (DeFi) services Kurrency and Konverter on the WEMIX3.0 Mainnet.Photo by Shubham Dhage on UnsplashTwo DeFi servicesKurrency utilizes a collateralized debt position (CDP) model, providing users with the capability to lock up a certain amount of virtual assets in order to mint, deposit, and swap the WEMIX Crypto Dollar (WCD). WCD, a cryptocurrency designed to minimize price fluctuations, complements the WEMIX Dollar, which is fully backed by the stablecoin USDC.Konverter is a new decentralized exchange (DEX) that combines the strengths of established DEXs. On June 9, Konverter will demonstrate functions that contribute to the efficiency of Kurrency. These functions involve seamless swaps between WCD and a variety of stablecoins. The full-fledged version of Konverter, set to launch in the second half of this year, will offer a broader array of swap services along with a “governance function” that doesn’t require forced lock-ups.Mainnet firstThe initial launch of Kurrency and Konverter will take place on the WEMIX3.0 Mainnet. Their goal is to magnify the ecosystem’s scope by boosting the utility of assets within the network and harnessing the synergies derived from decentralized apps (dApps).Multichain expansionLater, the two services on the WEMIX3.0 Mainnet will become more refined and reliable, paving the way for a multichain expansion. A successful implementation will improve interconnectivity between various blockchains, ultimately bolstering the value of the WEMIX ecosystem.Engaging usersStarting today, Kurrency is initiating various quests to encourage user participation. Users gaining experience from these quests will become eligible to join community events, promoting a more vibrant and engaged user base.

news
Loading