Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

May 08, 2023

BitMEX Chalks Up Two New Perp Contract Listings

BitMEX Chalks Up Two New Perp Contract ListingsSeychelles-based cryptocurrency exchange and derivative trading platform BitMEX announced recently that it has added perpetual contracts relative to two additional digital assets.A perpetual contract is a crypto futures contract without an expiry date. Just like with a more conventional futures contract, a perpetual contract is a derivative product, deriving its value from the underlying crypto asset.$SUI tokenTaking to Twitter, the company outlined that it has added perpetual contracts for the $SUI token. The contracts will be available in $SUI/USD and SUI/USDT pairings. Leverage relative to the contracts is being made available up to a maximum of 50x.$SUI is the native token of the Sui blockchain platform. Sui is a layer one blockchain which launched earlier this week. It’s a smart contract platform maintained via a network of permissionless validators. The blockchain network claims to offer a scalable network with ultra low latency. Such low latency can enable diverse use cases such as retail point of sale payment systems and gaming.The contract allows users to post bitcoin as collateral, earning or losing in bitcoin as the SUI/USD rate changes. Maximum risk limit is set at 50 bitcoin. Meanwhile maker and taker fees have been set for the product at 0.02% and 0.075% respectively. A base initial margin of 2% applies while base maintenance margin of 1% applies.$PEPE tokenOn Wednesday, BitMEX also launched perpetual contract products relative to the $PEPE token at 04:00 UTC. There are two listings, PEPE/USD and PEPE/USDT. Pepe coin is a meme token project, inspired by the Pepe the Frog meme. The origins of the cartoon character stem from the Boy’s Club comic in 2005. It later became an internet meme, and later still it was adopted as a meme within the crypto space.The token itself was launched in April, sky rocketing to a $502 million market capitalization since then, representing a 2,100% rise in the token’s unit price since its launch.As in the case of the $SUI token, $PEPE is also available to trade on BitMEX with leverage as high as 50x. In an interview with one crypto news publication, a representative of BitMEX commented on the launch as follows:“PEPE needs a Perp! Perpetual Contracts are the most traded product in crypto and offer all investors taking a long or short position on tokens with better liquidity and fewer network risks. At BitMEX, we offer Tether-margined and Bitcoin-margined perpetual contracts. We are proud to be the inventor of the Perpetual Swap and have long been a leading trading venue for crypto derivatives, offering uncompromised security, a reliable platform, and deep liquidity — as professional traders deserve.”Many commentators in the crypto space have repeatedly pointed to the high risks involved with leverage. In this instance 50x leverage is incredibly high risk, making the product suitable only for those traders that fully and thoroughly understand the risk that comes with such leveraged trading.Photo by Shubham Dhage on Unsplash

news
Policy & Regulation·

Oct 04, 2023

Research Center Highlights Overvaluation in Overseas Crypto Holdings Reported to Korean Tax Agency

Research Center Highlights Overvaluation in Overseas Crypto Holdings Reported to Korean Tax AgencyThe Korbit Research Center, affiliated with one of South Korea’s leading cryptocurrency exchanges, Korbit, has raised questions about the size of overseas cryptocurrency holdings reported by Korean individuals and businesses to the National Tax Service.Photo by REDioACTIVE on PixabayThe issue of market-making activitiesThe center noted that following the 2017 initial coin offering (ICO) boom, many enterprises that issued cryptocurrencies through offshore entities might still be holding onto their native tokens. This would have resulted from their inability to distribute these tokens to the market after the speculative bubble burst. The center believes these reported values could have been influenced by the issuers’ market-making activities, possibly inflating their worth.According to the National Tax Service, Korean individuals and corporations hold a total of KRW 130.8 trillion (around $98 billion) in overseas crypto accounts. Notably, 73% (KRW 120 trillion) of this sum is held by 73 corporate entities.Highlighting a critical aspect of cryptocurrency valuation, the Korbit Research Center pointed out that when tokens are priced based on market-making activities, they may be overvalued. They further underscored that even if the true value of overseas holdings by these entities is only a tenth of the reported sum, a figure like KRW 12 trillion is still substantial.Retail investors seeking overseas optionsFurthermore, the center touched on retail investors, noting that the KRW 10 trillion in their offshore accounts indicates a gap in services offered by Korean crypto enterprises. It suggests that individual investors might be exploring foreign markets due to domestic limitations like the absence of derivatives and lending options.Given the borderless nature of the crypto industry, Korean individuals readily turn to overseas services that cater to their needs. The Korbit Research Center estimates a KRW 10 trillion unmet demand in the domestic crypto sector, suggesting that stringent local regulations might be driving capital outflows.

news
Policy & Regulation·

Jan 16, 2024

Positive signals in Vietnam suggesting XRP payments adoption

Recent statements by figures well placed in the crypto space and within the Vietnamese government point to increased potential for greater adoption of XRP, the payments solution token first developed by Ripple Labs.Photo by Silver Ringvee on Unsplash‘XRP will be big in Vietnam’Yasin Mobarak is a prominent figure within the XRP community. He’s also the founder and managing member of Dizer Capital, a venture capital and private equity firm that specializes in blockchain, internet of things (IoT) and clean energy projects. On Saturday, Mobarak tweeted out: "$XRP will be big in Vietnam." While Mobarak didn’t comment further, he did include a link to an X social media post published by XRP community member Kenny Nguyen, relaying the news that Vietnamese Finance Minister Ho Duc Phoc had announced that the government is currently working with the Vietnamese Central Bank with a view towards studying and possibly implementing the use of XRP for cross border payments. Central Bank's consideration of XRPVietnam's Central Bank is actively exploring the integration of XRP for cross-border payments, both domestically and internationally. This move aligns with the region's swift adoption of XRP, driven by its promise of faster, cost-effective and secure cross-border payment services. Ripple's recent collaboration with TPB Bank, a major player in Vietnam's banking sector, is set to fortify the entire XRP ecosystem. In September 2023, SBI Remit, a financial service provider and subsidiary company of Japanese financial services conglomerate SBI Group, initiated an XRP-based remittance service covering Southeast Asian countries like the Philippines, Vietnam and Indonesia. SBI has a long-standing partnership in place with Ripple aimed at launching international payment services. As part of that announcement, SBI confirmed the participation of Malaysia-based cross-border payments hub Tranglo in the project. Crypto adoption and growthDespite legal constraints, Vietnam emerged as a leader in crypto adoption in Asia in 2023 by claiming the third position in Chainalysis’ 2023 Global Crypto Adoption rankings. The region, still adapting to the global rise of cryptocurrencies, is undergoing a transformation. While centralized exchanges dominate in various countries, regional preferences vary. In the Philippines, a noteworthy 20% of the population engages with crypto sites for gaming and gambling. In contrast, Vietnam and Pakistan distinguish themselves with citizens favoring peer-to-peer exchanges. This approach allows direct trading between individuals, bypassing large corporations. A report produced by Kyros Ventures and Coin68 in conjunction with Hong Kong’s Animoca Brands last year found that 76% of Vietnamese crypto holders determine their investment choices based upon recommendations from friends and people within their peer group. The collaboration between regulatory bodies, financial institutions, government and crypto projects illustrates the growing integration of digital assets into traditional financial systems. This latest example pertaining to Vietnam and XRP certainly offers the potential of a much greater level of adoption in the region. While activity within Vietnam may be a key consideration for XRP investors and stakeholders in 2024, the potential for a Ripple initial public offering (IPO) is also something they’re likely to be watching out for. Over the course of the past six months, a Ripple IPO has been the subject of speculation. That speculative interest has likely increased following Circle, the issuer of U.S. dollar stablecoin USDC, filing for an IPO last week.  

news
Loading