Top

HKMA Issues Warning Against Crypto Firm Misrepresentation

Policy & Regulation·September 19, 2023, 1:02 AM

The Hong Kong Monetary Authority (HKMA), the central bank for the Chinese autonomous territory, has taken a stand against cryptocurrency businesses that falsely present themselves as “banks” and market their products as “deposits,” issuing a public advisory to raise awareness about the issue.

Photo by Marcel Eberle on Unsplash

 

Banking ordinance violations

In a press release published to its website on Friday, the HKMA said that instances had arisen where crypto firms had labeled themselves as “crypto banks,” “crypto asset banks,” and “digital trading banks.” The regulatory authority underscored that such misrepresentations could be in violation of the Banking Ordinance in Hong Kong.

In addition to adopting misleading bank-related titles, these crypto firms have been advertising “savings plans” as “low risk” with “high return,” potentially misleading the public into believing that these entities are authorized banks in Hong Kong, where they can securely deposit their funds.

The HKMA stressed that only entities such as licensed banks, restricted license banks, and deposit-taking companies, collectively referred to as “authorized institutions” and holding a license granted by the HKMA, are legally permitted to engage in banking or deposit-taking activities in Hong Kong.

Furthermore, funds held on crypto exchanges are not covered by Hong Kong’s Deposit Protection Scheme. “Under the Banking Ordinance, only licensed banks, restricted license banks and deposit-taking companies, which have been granted a license by the HKMA can carry out banking or deposit-taking business in Hong Kong,” the HKMA stated.

 

Misuse of banking terms

Any entity using the term “bank” in its business name or implying that it offers banking services in Hong Kong is committing an offense, according to the central bank. The same rule applies to any entity engaging in deposit-taking activities in Hong Kong or soliciting the public to make deposits.

It’s important to note that crypto firms not officially recognized as banks in Hong Kong are not subject to the oversight of the HKMA.

The HKMA advised the public to exercise caution. In cases of uncertainty regarding an entity claiming to be a bank or soliciting deposits in Hong Kong, individuals are encouraged to consult the register of authorized institutions on the HKMA’s website, and if doubts persist, it suggests that they should contact the authority via its Public Enquiry Service hotline.

According to section 97 of the Banking Ordinance, only a bank or a central bank can use the term “bank” or its derivatives in its business name in Hong Kong without the written consent of the HKMA.

Additionally, sections 11 and 12 of the Banking Ordinance stipulate that only entities possessing a valid banking license or recognized as authorized institutions are permitted to engage in banking or deposit-taking activities in Hong Kong. As per section 92 of the Banking Ordinance, only an authorized institution is authorized to issue advertisements inviting the public to make deposits, with certain exceptions.

The HKMA’s advisory serves as a stern reminder to the crypto industry that regulatory compliance and transparency are essential, particularly when using terms associated with traditional banking, to protect the interests of the public.

More to Read
View All
Web3 & Enterprise·

Jan 12, 2024

CoinGecko security breach latest threat within crypto space

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach. Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.Photo by GuerrillaBuzz on UnsplashPhishing scamDuring this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content. In an X post, CoinGecko wrote:”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.” Employee errorThe firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker. Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities. CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented. SEC incompetenceCoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs). While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security. Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack. Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions. CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

news
Web3 & Enterprise·

Nov 07, 2023

Kloint and Korea University to develop on-chain data analysis solutions

Kloint and Korea University to develop on-chain data analysis solutionsKloint, a company specializing in the tracking of virtual asset transactions, revealed on Tuesday a partnership with the College of Informatics and the Center for Information System Security at Korea University. The collaboration is set to focus on the joint development of algorithms and platforms for on-chain data analysis.Photo by Shubham Dhage on UnsplashSharing insights on regulatory frameworksAs part of this initiative, Kloint and Korea University will cooperate to understand the domestic and international demand for on-chain data analysis. They will also exchange insights on the regulatory and policy frameworks that govern the technologies involved.Growing crypto-related criminal activitiesThe collaborative effort between Kloint and Korea University is set against a backdrop where, with the expansion of the cryptocurrency market, there has been a corresponding uptick in its use for criminal activities like money laundering, drug trafficking, and embezzlement.Traditional techniques used by government bodies, such as the public prosecutor’s office and financial regulators, have proven expensive and increasingly ineffective in tracking virtual assets as they struggle to keep pace with the sophisticated methods now used to circumvent detection.Kloint was co-founded last September by three blockchain technology firms: Fair Square Lab, S2W and Ozys. With a vision set on the horizon, Kloint is gearing up to supply government entities and virtual asset service providers (VASPs) with analytical platforms and reporting services. In the more immediate term, the company is focusing its efforts on developing solutions for data collection and analysis tailored to the Korean cryptocurrency market.

news
Web3 & Enterprise·

Dec 15, 2023

Hitachi collaborates with Concordium on biometric crypto wallet

Hitachi collaborates with Concordium on biometric crypto walletJapan’s Hitachi Solutions, a subsidiary company of the Hitachi multinational conglomerate, has joined forces with the Concordium Foundation, unveiling a collaboration that centers on a state-of-the-art biometric crypto wallet.Photo by Nuno Antunes on UnsplashAlternative approach to securing cryptoAnnounced on Tuesday by the Concordium Foundation, a Swiss-based development team behind the Concordium layer one blockchain, this “proof of technology” initiative has the potential to fundamentally change how users access and secure their cryptocurrency accounts.Breaking away from traditional methods, the proposed biometric crypto wallet leverages users’ fingerprints or facial scans to generate a set of seed words, eliminating the need for users to store or remember them. This novel approach simplifies the restoration process, allowing users to recover their accounts with a mere biometric scan.Improving UXIf crypto and Web3 are to be adopted by ordinary people en-masse, user experience has long been identified within the sector as an area that still requires development. Making users responsible for the storage of a private key is fraught with difficulty, given the likelihood of private keys being lost or compromised.Various approaches are being taken to solve this issue. Tangem Wallet is one such alternative that utilizes near-field communication (NFC) in combination with an app and a card with an inbuilt chip, negating the need for the user to memorize a private key.This biometric-centered approach from Hitachi and Concordium represents another user-friendly approach to the problem of user authentication, harnessing the power of Hitachi’s Public Biometric Infrastructure (PBI) and Concordium’s self-sovereign identity framework. The result is an account creation process based entirely on biometric data, enhancing both security and user convenience.Complementary technologyConcordium’s network, with its stringent ID process for account creation to combat malicious activities, stands to gain substantial benefits from this technology. The biometric wallet will fortify users’ access to their IDs, a critical aspect of network security. Moreover, the technology’s applicability extends beyond Concordium, offering potential integration with any blockchain network.Users of the biometric wallet will have the flexibility to unlock their accounts either by regenerating seed words through a biometric scan or by decrypting a copy of the seed words. This dual-layered approach ensures that access is granted solely through the user’s unique biometric data, enhancing security and mitigating the risk of loss or theft.Developing this cutting-edge technology poses challenges, particularly in handling the inherent “fuzziness” of biometric data, where no two scans produce identical results, even from the same individual. Hitachi’s team addressed this by employing fuzzy key generation and specialized error correction technology, effectively distinguishing between scans.Unlike traditional crypto wallets that necessitate secure storage of seed words, the biometric wallet by Hitachi and Concordium, alongside solutions like multiparty-computation wallets and magic links, aims to overcome this hurdle. The goal is to resolve the issue of lost backup, a significant barrier to wider crypto adoption.This is not Hitachi’s first foray into the crypto/blockchain space. In mid-November the company announced a collaboration with the Japan Exchange Group (JPX), banking giant Nomura and Nomura portfolio company BOOSTRY to launch a $69 million digital green bond on the blockchain. In October Hitachi joined a consortium of Japanese companies with a view towards developing decentralized identity technology.

news
Loading