Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Policy & Regulation·

Mar 13, 2024

Hong Kong regulator unveils stablecoin sandbox

Following December's release of proposed fiat-referenced stablecoin regulations, the Hong Kong Monetary Authority (HKMA) has progressed further with the introduction of a stablecoin sandbox.Photo by Nextvoyage on PexelsFormulating a regulatory regimeThe regulatory sandbox, announced through a press release published to the regulator’s website on March 12, encompasses stablecoin currencies beyond the Hong Kong dollar, although the HKMA refrained from specifying particular currencies. Eddie Yue, CEO of the HKMA, emphasized the sandbox's role as a platform for constructive dialogue between the regulatory authority and the industry. Yue stated:"The sandbox arrangement serves as an effective channel for the HKMA and the industry to exchange views on the proposed regulatory regime.”Yue further noted that such engagement is pivotal for formulating regulatory requirements conducive to the sustainable and responsible growth of the stablecoin issuance business. The stablecoin sandbox finds its digital footprint within the International Financial Centre on the HKMA's website. The documentation accompanying the sandbox outlines several key requirements for potential participants. These include demonstrating genuine interest and a feasible plan for issuing fiat-referenced stablecoins in Hong Kong, as well as a concrete strategy for engagement within the sandbox. Additionally, applicants must exhibit a reasonable prospect of compliance with the proposed regulatory framework. Minimum capital requirementsOne notable regulation proposed stipulates that issuers must be Hong Kong-based entities with a minimum capital requirement of HK$25 million ($3.2 million) or 2% of the stablecoin issuance, whichever is higher. The HKMA remains vigilant regarding public announcements by sandbox participants, ensuring that such declarations do not misconstrue endorsement or accreditation from the regulatory authority. In late January, reports suggested discussions between Harvest Global Investment, RD Technologies, Venture Smart Financial Holdings and the HKMA regarding their potential entry into the sandbox. Harvest Global Investment, boasting over $200 billion in assets under management, signifies a significant player in this evolving digital assets space.RD Technologies took to the X social media platform to publicize its approval of the HKMA’s stablecoin sandbox. It also availed of the opportunity to outline that it’s in the process of launching a Hong Kong dollar (HKD)-based stablecoin, which will be known by the short-code HKDR.Hong Kong-based fintech firm AnchorX also chimed in, stating that the sandbox is “a pivotal step forward for the industry, enabling informed dialogue and collaboration between regulators and fintech innovators.” Like RD Technologies, AnchorX is also looking to get involved in the stablecoin business, having developed the AxHKD Hong Kong dollar-based stablecoin, which it is currently beta testing, in collaboration with Conflux Network. Juan Leon, crypto analyst with Bitwise Asset Management, suggested that the move is a great initiative, while calling on the U.S. Federal Reserve Chair Jerome Powell to follow Hong Kong’s example. On the tokenization front, Hong Kong made headlines in 2023 with the issuance of the world's largest native digital bond — a green bond exceeding $750 million. Late last year, it also proposed regulations relative to tokenization of real-world assets.Guidance provided to banks on tokenization, coupled with plans for forthcoming legislation, further solidifies Hong Kong's position as a trailblazer in the realm of digital finance.  

news
Web3 & Enterprise·

Aug 18, 2023

Galaxia Metaverse and ZIKTALK to Expand Blockchain and Web3 Initiatives

Galaxia Metaverse and ZIKTALK to Expand Blockchain and Web3 InitiativesSouth Korean blockchain company Galaxia Metaverse said Friday it has signed a memorandum of understanding (MOU) with the Web3 social media platform ZIKTALK. The two companies plan to collaborate for the expansion of and boosted connectivity between Galaxia’s blockchain wallet and ZIKTALK’s social media services.Photo by GuerrillaBuzz on UnsplashEncouraging engagementZIKTALK is a Web3 short-form video platform that rewards users based on their activities in the app. Video creators and viewers can receive ZIK tokens as rewards for watching or sharing videos, inviting friends, gaining followers, leaving comments, and more. Currently, the platform has around 1.4 million users primarily in Southeast Asian countries such as the Philippines, Indonesia, and Vietnam.Galaxia Metaverse’s main service, Galaxia Wallet (GXA Wallet), is a digital blockchain wallet that supports major mainnets such as Ethereum, Binance, Polygon, and Klaytn. Its utility token Galaxia (GXA), which can be stored in the Wallet, is rewarded through staking and can be used for purchasing NFTs. Wallet holders can also receive rewards when they use MetaGalaxia, a curation-based NFT marketplace, and acquire GXA when they use a coffee delivery application created by WeMakePrice O, the food delivery platform of e-commerce firm WeMakePrice.Together, Galaxia and ZIKTALK aim to expand their blockchain ecosystems to allow users to utilize their wallets and tokens in a safer and more convenient manner. This includes implementing more services such as token registration and wallet connection so that ZIKTALK users can use Galaxia Wallet more efficiently.“The majority of ZIKTALK users, which mainly consists of young people in their 20s and 30s who enjoy short-form content, represent the demographic that would benefit most from using Galaxia Wallet,” Galaxia said in a statement.Global growth and partnershipsMeanwhile, Galaxia has been actively expanding its blockchain ecosystem this year both domestically and internationally, collaborating with industry leaders such as Korean online marketplace Coupang and Singaporean blockchain-based mobility enterprise MVL Foundation.

news
Web3 & Enterprise·

May 08, 2023

ZkLink Snags $10M Funding Ahead of Mainnet Launch

ZkLink Snags $10M Funding Ahead of Mainnet LaunchZkLink, a layer 2 multi-chain blockchain network project based out of Singapore, has secured $10 million in funding in advance of its mainnet launch which is scheduled for Q3, 2023.Photo by Markus Winkler on UnsplashStrategic funding roundThe Singaporean project offers a blockchain infrastructure layer that enables the ability to trade digital assets across various disparate blockchain networks. Coinbase Ventures, the investment arm of US cryptocurrency exchange Coinbase, focuses its attention on early-stage cryptocurrency and blockchain projects.That’s precisely why it has now participated in a $10 million investment in the Singaporean start-up, given that the ZkLink network doesn’t launch on mainnet for a number of months yet. Other participants in the funding round included Ascensive Assets, SIG DTI, BigBrain Holdings, Efficient Frontier, among others.In posting news of the funding to social media, ZkLink confirmed that the fresh strategic funding round has brought total funding to date to $18.5 million. “The funds raised take zkLink a step further to envision a multi-chain future with unified liquidity and seamless multi-chain user experience while remaining fully trustless and self-custodial,” the project stated.Its previous $8.5 million funding round was completed in October 2021. Among the early investors on that occasion were Arrington Capital, DeFi Alliance, Huobi Ventures, Ascensive Assets, Morningstar Ventures, GSR, Marshland Capital, Skynet Trading, ZBS Capital, and others. New York-based blockchain financing and investment platform, Republic Crypto, was the lead investor at that time.Bridging assets securely acrossZkLink uses zero knowledge technology in order to connect various layer one and layer two networks. A zero knowledge proof is the core innovation that the approach relies upon, with the proof presenting as a cryptographic technique that ensures that no data is revealed during a transaction, save for the exchange of some known value already evident to both prover and verifier.That approach makes for efficient cross-chain bridging, guaranteeing strong security without external trust assumptions. By connecting various layer one and layer two networks, zkLink claims that it empowers the next generation of decentralized trading products.Developers can access ZkLink application programming interfaces (APIs) in order to create order book decentralized exchanges (DEXs), NFT marketplaces, among other use cases. The project is harnessing zero knowledge technology to abstract away all the complexity of multi-chain trading while keeping it ultra secure and true to the ethos of crypto.A multi-chain futureWith blockchain networks being highly fragmented, the concept of a multi-chain future is one that is being increasingly embraced within the crypto space. Various projects have been launched in an effort to effect such a scenario. However, the first generation of bridging solutions have proven to be weak from a security perspective. Zero knowledge technology is seen as a potential solution to this issue.Effecting a seamless multi-chain will also bring about greater efficiencies. As a case in point, currently USDT-Ethereum and USDT-Solana exist as separate assets on distinct blockchains representing the very same USDT stablecoin. With seamless bridging, there would be no need for the duplication.In recent days, the ZkLink project team has been busy working on safety features related to securing decentralized finance protocols. In a press release associated with that work, ZkLink Co-Founder Vince Lang stated: “It is unacceptable that billions of dollars are lost each year due to custody fraud or cross-chain bridge exploits, so we encourage other DeFi protocols to conduct the same test to prove self-custody of user’s funds.”

news
Loading