Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Markets·

Sep 29, 2023

Hong Kong’s HashKey Adds AVAX Trading

Hong Kong’s HashKey Adds AVAX TradingHashKey Hong Kong, the Chinese autonomous territory’s first licensed retail crypto exchange, has unveiled an addition to its platform with the launch of Avalanche (AVAX) trading.According to an announcement published to its website on Wednesday, HashKey has listed Avalanche on Thursday with the caveat that access to AVAX trading will be reserved for professional investors, as defined by Hong Kong’s Securities & Futures Commission (SFC).Photo by Wance Paleri on UnsplashAccessible to professional investorsTo meet the criteria as a professional investor in Hong Kong, individuals must possess an investment portfolio valued at a minimum of 8 million Hong Kong dollars, roughly equivalent to $1 million. This decision sets AVAX apart from other widely traded cryptocurrencies, such as Bitcoin and Ether, which remain accessible to retail investors in Hong Kong. While Tether (USDT) enjoys retail status, the majority of altcoins on HashKey will remain the preserve of professional investors.This move is a direct result of the SFC’s proactive stance on regulating the rapidly expanding crypto market in Hong Kong. Since the introduction of regulated retail crypto trading in the Chinese autonomous territory in August, the SFC has imposed rigorous requirements on exchanges. HashKey mandates users to deposit a minimum of 10,000 Hong Kong dollars or $1,500 into their exchange accounts as part of the Know Your Customer (KYC) verification process.Low trading volumeAmid these regulatory challenges, HashKey Hong Kong currently reports a 24-hour trading volume of approximately $5.3 million, significantly lower than its global peers. This lower trading volume suggests that stringent regulations may be affecting the exchange’s ability to attract retail investors effectively.The path to regulatory compliance in Hong Kong has been anything but smooth for crypto exchanges. Reports indicate that these platforms have collectively invested over $25 million in establishing the requisite infrastructure for obtaining a Hong Kong Virtual Asset Service Provider (VASP) license. It was reported earlier this year that crypto firms are forking out between $2.55 million and $25.5 million in order to secure a VASP trading license.Despite the challenges, HashKey is looking at various avenues in bringing its offering forward. Earlier this month the firm signed a memorandum of understanding (MOU) with insurer OneDegree. That collaboration could be significant as it should lead to the assets of HashKey users being protected and insured on the platform. That would solve a major issue for participants in the crypto space amid the backdrop of ongoing platform failures and hacks.JPEX collapseEven as regulatory efforts intensify, the crypto industry in Hong Kong has not been impervious to bad actors. The recent collapse of the JPEX crypto exchange earlier this month serves as a stark reminder of the ongoing risks associated with the industry. Described as the largest financial fraud in Hong Kong’s history, JPEX faced allegations of embezzling over $178 million of investors’ funds. Notably, JPEX was operating without SFC registration at the time of the alleged embezzlement.In response to such incidents, the SFC has taken proactive measures by publishing a warning list of crypto exchanges considered non-compliant within the Chinese autonomous territory.

news
Web3 & Enterprise·

Aug 22, 2023

Aevo Launches Novel Index Perpetual Contract

Aevo Launches Novel Index Perpetual ContractAevo, the layer-2 derivatives platform launched by Singapore’s Ribbon Finance earlier this year, has introduced a new index perpetual contract.The contract allows traders to engage in long or short positions based on the market capitalization of accounts within the social application Friend.tech.Photo by Compare Fibre on UnsplashFRIEND-PERPThe FRIEND-PERP market is now live according to The Block, and it has gained significant traction, boasting a daily trading volume of $501,824 and a current trading price of $7.14. This market operates on a unique premise — a perpetual contract, which, unlike conventional futures contracts, does not adhere to an expiration date. This feature is particularly appealing to the crypto trading community, enabling them to seize opportunities without the constraints of time-bound contracts.Surge in interestFriend.tech, the social app at the center of this Aevo product offering, has integrated with Ethereum layer-2 network Base, a blockchain incubated by Coinbase earlier this year. This network, which officially welcomed the public on August 9, has been the center of attention within the crypto sector over the past couple of weeks.The social app enables market participants to buy shares of individuals who hold accounts on X (formerly Twitter). Since its launch earlier this month, the Friend.tech app has grown rapidly. It attracted over 100,000 daily users within 24 hours of its launch.Each user stands to benefit financially from the purchase and sale of their shares, a pioneering approach that has lured prominent figures, including venture capitalist Garry Tan, NBA star Grayson Allen, and celebrated YouTuber FaZe Banks, to the platform.Boost for BaseUS crypto platform Coinbase has embraced Friend.tech as it marks the first major breakthrough use case for its Base blockchain network. This collaborative effort has propelled the Base network to new heights, positioning it among the top cryptocurrency projects by user fee revenue. With $1.4 million in fees generated over the last 24 hours alone, Friend.tech ranks among industry giants, trailing only Ethereum and Lido Finance in this metric, according to data from DeFiLlama.While the app has risen at a phenomenal pace, there are concerns relative to the degree of privacy it affords its users. The public availability of the Friend.tech API used to convert X usernames into wallet addresses has raised the alarm for potential data exposure.A Yearn Finance developer, known by the pseudonym Banteg, used this API to compile a list of Ethereum addresses linked to X accounts. While the community has reassured users that access can be revoked, the implications of this exposure for privacy and security cannot be understated.The Aevo project was first announced by Ribbon Finance in September 2022 and subsequently launched in June. The goal of the project is to convert users from centralized exchanges, bringing them over to the decentralized exchange (DEX) platform.

news
Policy & Regulation·

Dec 08, 2023

Regulatory crackdown as Hong Kong authorities act against crypto entities

Regulatory crackdown as Hong Kong authorities act against crypto entitiesIn a recent move, the Securities and Futures Commission (SFC) of Hong Kong has issued a public warning against suspected virtual asset-related frauds involving HongKongDAO and BitCuped, marking a significant crackdown on deceptive practices in the crypto space.The action taken by the SFC in conjunction with the Hong Kong Police Force was outlined in a notice published on Wednesday. The notice stated:“The SFC suspects HongKongDAO may be disseminating false and misleading information about itself and its business through online channels.”In relation to BitCuped, it stated: “The SFC notes that BitCuped claims on its website that ‘Laura Cha’ and ‘Nicolas Aguzin’ serve as its Chairman and Chief Executive Officer respectively, when in fact none of them has any affiliations with BitCuped.”Photo by Teodor Kuduschiev on UnsplashHongKongDAO’s alleged misinformationOperating under the name “Hong Kong Digital Research Institute,” HongKongDAO has faced accusations of disseminating false and misleading information. The SFC expressed concerns about the claims made by HongKongDAO, including assertions of licensing by the SFC, engagement in regulated activities since July 2020, and bids for a “Hong Kong Digital Currency Exchange Licence” related to the government’s stablecoins framework.The SFC contends that these claims are unfounded and could potentially mislead the public into believing that HongKongDAO’s services are officially sanctioned and legitimate.HongKongDAO seems to manage at least two Telegram groups, one in Chinese with over 10,000 members and the other in English with over 1,700 members. Within these groups, there appears to be a promotion of the purported “market” price and future market value of the HKD token, enticing investors to make purchases.Allegations of BitCuped false affiliationsSimultaneously, BitCuped has been accused of making fraudulent claims to enhance the credibility of its operations. The company falsely asserted affiliations with prominent figures Laura Cha and Nicolas Aguzin, claiming them as its chairman and CEO, respectively. However, the SFC has refuted these affiliations. Laura Cha is the Chairman of Hong Kong Exchanges and Clearing Limited (HKEX), while Nicolas Aguzin is the Executive Director and CEO of HKEX.Taking proactive measures, the SFC has requested the Hong Kong Police Force to block access to the websites of both HongKongDAO and BitCuped. Cease and desist letters have also been issued to the operators of these websites, demanding the cessation of the sale of HKD Tokens offered by HongKongDAO.Series of crypto scamsFollowing the JPEX fraud allegations in September, Hong Kong faced another cryptocurrency exchange scandal involving Hounax in November. With at least 145 police reports filed and a sum of over HK$148 million ($19 million) involved, affected investors expressed frustration at what they deemed a slow response from regulatory bodies.These incidents have reignited discussions about the need for more robust cryptocurrency regulations in Hong Kong. The city’s aspiration to become a global hub for crypto innovation and adoption faces challenges due to a lack of clear and consistent regulation, leaving investors vulnerable to fraud and manipulation.In light of these developments, the SFC emphasized the importance of public caution regarding investment opportunities that seem too good to be true. The regulator urged vigilance against social media and instant messaging platforms where individuals, not investment professionals, might lure unsuspecting investors.

news
Loading