Top

Telcoin makes users whole in exploit recovery

Web3 & Enterprise·January 13, 2024, 10:31 AM

Singapore-regulated Telcoin, a developer of financial applications for mobile users, has successfully restored user balances following an exploit that saw approximately $1.2 million worth of funds transferred from affected accounts.

https://asset.coinness.com/en/news/3c1766686bc03dc8348603085a3f1f51.webp
Photo by Martin Sanchez on Unsplash

Unauthorized withdrawal of assets

The incident, which occurred in late December, was attributed to an error in the interaction between Telcoin's digital wallet and a proxy contract on Polygon. In a blog post which was published on Wednesday, the company shared a full post-mortem analysis report which it commissioned Hong Kong-based blockchain security firm BlockSec to carry out, relative to the exploit.

 

The fault in the proxy contract's implementation caused a technical conflict that allowed for the unauthorized withdrawal of assets. Fortunately, no admin keys were compromised, ensuring that the broader Telcoin ecosystem remained unaffected.

 

In response to the security breach, Telcoin took action by immediately freezing the use of its application as a precautionary measure. The team initiated an investigation and committed to releasing updates promptly to address the issue and restore normalcy. The identified address associated with the exploit was 0x35d2775e5f95596509951b140d68fc5b9185ff98.

 

TEL token freefall

Despite the initial market turbulence, with the price of the Telcoin (TEL) token plummeting, the cryptocurrency has demonstrated resilience. On Dec. 25, TEL fell from a peak price of $0.00235146 to $0.00122535, representing a 48% decrease. At the time of writing, the price has slightly rebounded, trading at $0.001335. Nevertheless, it's still down 40% over the course of the past month's trading.

 

In a social media direct message to CoinDesk recently, Telcoin's founder and CEO, Paul Neuner, expressed pride in how his team responded to the issue, stating:

 

“Making the decision to preemptively restore affected user wallets from our company treasury was a no-brainer, and I’m proud of the team for making that happen in record time.”

 

Regulatory standing

Telcoin's regulatory standing played a crucial role in instilling confidence during this challenging time. Although headquartered in Tokyo, the company is regulated in Singapore as a Major Payment Institution (MPI) by the Monetary Authority of Singapore (MAS).

 

The firm is also registered and regulated in other global markets, including Canada and Australia. Telcoin maintains offices in Singapore, Tokyo, Dubai and Los Angeles. The company had been active in trying to shape regulation in the United States in 2023, with company executives having made repeated visits to Washington D.C. to meet with Financial Services Committee members and staffers on Capitol Hill.

 

In April of last year, the company extended its service offering to the European market, starting out initially in Lithuania.

It appears that the restoration of Telcoin's application services led to a significant boost in user confidence. The company reported a 400% increase in deposits compared to the previous month. Users responded favorably to Telcoin's swift resolution of the security breach, with a ratio of $3.60 being deposited for every $1 withdrawn in the first day since the service restoration.

 

Telcoin's measures, collaboration with security experts and the surge in user deposits appear to have resulted in a resilient recovery. The saga highlights the importance of prompt and transparent responses in maintaining trust in the face of crypto security issues.

 

 

More to Read
View All
Policy & Regulation·

Nov 20, 2025

Seoul launches global expansion program for fintech firms on XRP Ledger

The Seoul Metropolitan Government has launched a new initiative designed to help South Korean fintech firms expand into global markets. According to a Nov. 18 press release, the city and its blockchain partner, Catalyze Research, will utilize the XRP Ledger (XRPL), Ripple Labs’ public blockchain, to provide technology-focused mentorship and facilitate networking with overseas partners.Photo by Kanchanara on UnsplashFunding for global growthParticipating startups are eligible to receive up to $200,000 each, with the total funding pool capped at $1.8 million. The Seoul government anticipates that this initiative will assist early-stage ventures in establishing a meaningful presence in the global marketplace. Selected participants will receive mentorship from Catalyze Research on entering the blockchain ecosystem via the XRP Ledger, refining business models, and developing multichain strategies. The program is open to applicants working in a variety of specific sectors, including blockchain payments, asset tokenization, cross-border transfers, decentralized identifiers (DIDs), decentralized finance (DeFi), and regulatory technology. Beyond the core business training, Seoul is offering technical workshops that allow participants to explore complex topics such as XRPL-based issuance, liquidity configuration, fee optimization, and security architecture in greater depth. Follow-up support programs will continue to assist participating ventures after the initial phase, offering help with investor relations and jurisdiction-specific regulatory consulting. Pilot projects with overseas partners are also planned to further support company growth. The capital’s move to back crypto ventures follows its recognition in the Global Financial Centres Index (GFCI), produced annually by the London-based think tank Z/Yen and the China Development Institute (CDI). In the latest report released in September, Seoul ranked eighth in fintech among 135 cities. Price swings amid XRP ETF debutsWhile the city pushes to grow the country’s blockchain sector, XRP, the native asset of the XRP Ledger, has faced market headwinds. According to CoinMarketCap data, the token’s price dropped more than 15% over the past week amid a broader market downturn. This decline came even after the Nov. 14 launch of XRPC, a Canary Capital–managed ETF that is the first in the U.S. to track the spot price of XRP. Subsequently, the Bitwise XRP ETF is also set to debut on the New York Stock Exchange on Nov. 20. Amid the recent price weakness, XRP’s retail positioning offers a more nuanced backdrop. Glassnode’s Nov. 19 update estimates the average retail cost basis for the token at roughly $2.17, putting the typical holder about 61% in profit. The firm’s analysis a day earlier showed, at the network-wide level, 58.5% of the total supply in profit and 41.5% held at a loss—a structure that the firm said reflected a market dominated by recent buyers and prone to volatility.

news
Policy & Regulation·

Jun 29, 2023

India’s RBI Cites Stablecoin Risks With Call for Global Regulation

India’s RBI Cites Stablecoin Risks With Call for Global RegulationIn its latest Financial Stability Report released on Wednesday, the Reserve Bank of India (RBI) expressed concerns about the potential harm stablecoins could inflict on emerging markets and developing economies (EMDE).Photo by rupixen.com on UnsplashPerennial criticThe RBI has been a consistent critic of cryptocurrencies, but particularly so in the case of stablecoins, from an EMDE perspective. However, the lack of authenticated data and inherent data gaps in the crypto ecosystem hindered a comprehensive assessment of financial stability risks.According to the report, one of the ways stablecoins could pose a threat to an EMDE is through currency substitution. Since the underlying assets of stablecoins are generally denominated in freely convertible foreign currencies, the widespread adoption of stablecoins could lead to currency mismatches on the balance sheets of banks, firms, and households, resulting in an increased risk to the economy.Monetary policy headacheFurthermore, the presence of stablecoins in the economy could create challenges for an EMDE’s central bank in setting domestic interest rates and managing liquidity conditions. The decentralized, borderless, and pseudonymous characteristics of crypto-assets make them potentially attractive instruments for circumventing capital flow management measures.Another concern highlighted by the RBI is that stablecoins could undermine credit risk assessment and interfere with banks’ ability to mobilize money and create credit by offering an alternative to the domestic financial system. Additionally, the report emphasized the difficulty in tracking peer-to-peer transactions, on the basis that they increase the potential for illicit activities.In light of these risks, the RBI reiterated its call for global coordination and regulation. It emphasized the need for a globally coordinated approach to analyze the risks posed to EMDEs compared to advanced economies (AEs). As India holds the G20 presidency, one of its priorities is to establish a framework for the global regulation of unbacked crypto-assets, stablecoins, and decentralized finance (DeFi).Establishing a CBDCWhile the RBI has been cautious about cryptocurrencies, it has shown more enthusiasm for central bank digital currencies (CBDCs). In November, the RBI launched a wholesale digital rupee pilot project. It followed that up in February with a retail digital rupee pilot project. In March, it signed an agreement with the Central Bank of the United Arab Emirates to study a CBDC bridge aimed at facilitating trade and remittances.By calling for global regulation and highlighting the risks associated with stablecoins, the RBI aims to foster a safer and more secure environment for financial transactions while exploring the potential benefits of CBDCs in facilitating trade and remittances.As the discussions around stablecoins and CBDCs continue, we’re likely to see ever greater collaboration between regulators, policymakers, and international organizations with a view towards establishing a comprehensive regulatory framework that addresses the challenges and harnesses the potential of digital assets on a global basis.

news
Policy & Regulation·

Nov 09, 2023

UAE strengthens regulatory oversight of virtual asset service providers

UAE strengthens regulatory oversight of virtual asset service providersThe Central Bank of the United Arab Emirates (CBUAE) and other relevant authorities in the Middle Eastern country have issued new joint guidance for virtual asset service providers (VASPs) operating within the UAE.Photo by Thomas Drouault on UnsplashPushing back against unlicensed VASPsThese guidelines aim to prevent VASPs from operating without proper licenses in the jurisdiction, demonstrative of the country’s efforts in fighting financial crimes and maintaining the integrity of its financial system.The document outlines the penalties for VASPs operating in the UAE without a valid license. They will face civil and criminal sanctions, including financial penalties against the entity, its owners and senior managers. Moreover, the guidance cautions that licensed financial institutions (LFIs), designated non-financial businesses and professions (DNFBPs) and licensed VASPs that engage with unlicensed VASPs will be subject to law enforcement actions.The National Anti-Money Laundering and Combating Financing of Terrorism and Financing of Illegal Organizations Committee (NAMLCFTC) is the specific entity responsible for having issued the guidance in conjunction with the central bank.VASP ‘red flags’As part of those guidelines, a list of “red flags” for VASPs has been included. Through reliance on these indicators, it’s hoped that bad acting VASPs can be identified by consumers and other industry stakeholders. The document refers to red flags such as the lack of regulatory licensing, no physical presence in the UAE, pressure being applied by a platform to invest quickly and a lack of regulatory disclosure as items to look out for.Otherwise, the guidance encourages stakeholders to be suspicious of unsolicited contact being employed as a means of operation by a platform, the lack of a record of compliance, poor website and communications and the offer of unrealistic promises.Lastly, the document suggests that people should be observant of any illicit use of virtual currency, the use of fake wallets, engagement in terrorist financing and a lack of consumer protection as red flag items.The new guidance instructs all LFIs, DNFBPs and licensed VASPs to report transactions involving suspicious parties. The guidance also emphasizes that information related to unlicensed virtual asset activities can be reported through whistleblowing mechanisms.Exiting FATF ‘grey list’The release of these guidelines is part of an effort by the UAE to be removed from the Financial Action Task Force’s (FATF) “grey list.” The grey list indicates deficiencies in a country’s anti-money laundering (AML) and counter-terrorist financing (CTF) regimes.Improving control mechanisms relative to crypto has been a theme for several countries who are similarly looking to exit the FATF grey list. Last week, it emerged that Turkey is crafting new regulations governing crypto in an effort towards “grey list” removal. Earlier this year, Pakistan announced a renewed ban on cryptocurrency, as part of its efforts to remain off the grey list it had been listed on over an extended period.The UAE was placed on the FATF’s grey list in March 2022 due to AML and CTF deficiencies. However, the country made a commitment to work with the global watchdog to improve its regulatory frameworks in these areas.

news
Loading