Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Nov 03, 2023

Korean crypto exchange Upbit adds one-second interval charts

Korean crypto exchange Upbit adds one-second interval chartsSouth Korea’s largest cryptocurrency exchange, Upbit, now offers one-second interval charts for its users.Dunamu, the blockchain and fintech company behind Upbit, announced on Friday (local time) that it has introduced a one-second interval feature to Upbit’s “original” charts. This makes Upbit the first Korean cryptocurrency exchange to offer this functionality.Photo by m. on UnsplashResponding to user demandUpbit has rolled out this one-second interval feature in response to user demand. This addition facilitates a broader range of investment strategies, allowing Upbit users to fine-tune their decisions based on their investment preferences. Now, the time frames available on Upbit are 1 second, 1 minute, 3 minutes, 5 minutes, 10 minutes, 15 minutes, 30 minutes, 1 hour, 4 hours, 1 day, 1 week and 1 month.A representative from Upbit said that they have incorporated the one-second interval feature into their original charts to provide users with quick and easy access to virtual asset price information for their investments. The official added that the company will remain committed to fostering a user-friendly and comfortable trading environment.Available on both web and mobileUsers can access the one-second interval feature on both the web and app versions of Upbit. To utilize this feature, they can select the “1s” time frame on the original charts found under the “Exchange” tab of Upbit.

news
Policy & Regulation·

Feb 21, 2024

Regulatory clarity spurs traditional brokerages’ interest in Hong Kong

In less than a year since Hong Kong regulators gave the green light to crypto exchanges, there's been a noticeable surge of interest among traditional financial institutions and brokerages eager to secure their digital asset licenses for trading.Photo by Florian Wehde on UnsplashTiger BrokersTiger Brokers, a Beijing-headquartered one-stop trading brokerage with nine million international customers, offers one such example. The firm upgraded its Type 1 Hong Kong Securities & Futures Commission (SFC) license in January to include crypto trading for professional investors and financial institutions based in Hong Kong. The move followed an uptick in interest from mainland China-based firms in Q4, 2023.In a recent interview with Cointelegraph, John Fei Zeng, the CFO and director of Tiger Brokers, revealed that the firm currently boasts 865,500 funded accounts in Hong Kong, managing $18.9 billion in assets. Zeng stated: "Residents of Hong Kong will be able to trade virtual assets such as Bitcoin and Ethereum alongside stocks, options, futures, funds, and ETFs [Through Tiger Trade]." He explained that as part of the firm's expansion plans, additional digital assets will be evaluated. HKMA guidance on crypto custodyAs a testament to the regulatory clarity that has attracted firms like Tiger Brokers, on Tuesday Hong Kong's central bank issued guidance for authorized institutions interested in offering custody services for digital assets. The Hong Kong Monetary Authority (HKMA) outlined comprehensive risk assessment procedures and emphasized the importance of robust policies, oversight, and resource allocation to manage custodial activities effectively. Notably, the HKMA's guidance seeks to address concerns stemming from recent industry mishaps, including the collapse of FTX, Terra and Three Arrows Capital (3AC), by mandating stringent safeguards to protect clients' digital assets from theft, fraud or misappropriation. Key requirements include independent systems audits, secure storage practices and transparent record-keeping, underscoring the regulator's commitment to fostering trust and stability in the digital asset ecosystem. Victory SecuritiesIn a similar move to that of Tiger Brokers, Victory Securities, another Hong Kong brokerage, secured a license from the SFC last November to offer crypto trading services for retail investors. The company reported a significant surge in virtual asset transactions and new customer acquisitions, prompting plans to introduce trading discounts to incentivize compliant and safe virtual asset trading services. Moreover, OSL, a licensed Hong Kong crypto exchange, joined forces with Interactive Brokers in November 2023, enabling the latter to offer bitcoin and ether trading to retail investors through its platform. Further underscoring the evolving regulatory landscape, crypto exchange Bybit submitted a retail trading license application in Hong Kong, indicative of the sector's continued growth and maturity. Nevertheless, navigating the regulatory framework isn't without its challenges. Web3 firms eyeing Hong Kong may need to invest up to $25 million in corporate infrastructure and compliance to secure licensing approval, reflecting the stringent requirements imposed by regulators. As Hong Kong continues to refine its regulatory framework and enhance investor protections, the stage is set for further collaboration between traditional financial institutions and emerging crypto players within the Chinese autonomous territory.

news
Web3 & Enterprise·

Apr 19, 2023

HashKey Launches Wealth Management Service Amid High Demand

HashKey Launches Wealth Management Service Amid High DemandHong Kong-based HashKey Group, a leading financial technology company in Asia, has launched Hashkey Wealth, a wealth management service in response to significant demand from investors looking for exposure to the digital assets market.©Pexels/Tima MiroshnichenkoPortfolio diversificationWith the increasing adoption of cryptocurrencies and digital assets, many investors are seeking ways to diversify their portfolios and gain exposure to this emerging asset class. HashKey’s wealth management service provides investors with access to a wide range of digital assets, including Bitcoin, Ethereum, and other cryptocurrencies, as well as alternative investments such as non-fungible tokens (NFTs) and decentralized finance (DeFi) projects.The wealth management program is designed to meet the needs of both institutional and individual investors. It offers a variety of investment strategies, ranging from passive to actively managed portfolios, with different risk profiles to suit investors’ preferences. The program also provides a range of services, including custody, trading, and portfolio rebalancing, to ensure that investors can manage their investments with ease.Established track recordHashKey has a strong track record in the digital asset market, having launched its own cryptocurrency exchange in 2018 and a blockchain accelerator program in 2019. The company has also established partnerships with leading players in the industry, such as Huobi, to expand its reach and provide investors with access to a wider range of investment opportunities.In a statement, HashKey Group CEO, Deng Chao, said, “We are excited to launch our wealth management service and provide investors with access to the emerging digital asset market. Our goal is to provide investors with a range of investment options and strategies to meet their needs, while also providing them with the tools and services they need to manage their investments effectively.”Growing interest in digital assetsThe launch of HashKey’s wealth management service comes at a time of increasing interest in digital assets from both institutional and individual investors. With the market for cryptocurrencies and other digital assets expected to continue to grow in the coming years, it is likely that demand for wealth management services in this space will also continue to increase.Additional servicesThe company also gained approval from Hong Kong’s Securities and Futures Commission (SFC) for a Type 9 asset management license which allows it to manage portfolios that are entirely invested in digital assets.Hashkey PRO, its regulated virtual asset exchange, is due to launch in Q2, 2023. In order to facilitate this, the firm has gained SFC approval for both a Type 1 license which covers dealing in securities and a Type 7 license which enables the provision of automated trading services.Overall, the launch of HashKey’s wealth management service and its virtual assets exchange is a positive development for the digital asset market, as it provides investors with a range of investment options and strategies to suit their needs. With the company’s strong track record in the industry and its commitment to providing investors with high-quality services and solutions, it is well-positioned to capitalize on the growing demand for digital asset investments.

news
Loading