Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Web3 & Enterprise·

Nov 22, 2023

AndUs to implement ZK rollups on Its public permissionless blockchain

AndUs to implement ZK rollups on Its public permissionless blockchainAndUs, the South Korean developer of public permissionless blockchain Anduschain, announced on Wednesday (local time) that it is preparing to implement zero-knowledge (ZK) rollup technology into its blockchain to enhance scalability and security. ZK rollups are layer-2 scaling solutions that move transactions off-chain to increase throughput on the Ethereum mainnet.Photo by Shubham Dhage on UnsplashPerspective on ZK rollupsMany Korean projects are focused on developing various layer-2 solutions. Against this backdrop, Park Sung-jun, CEO of AndUs and a Ph.D. in cryptography, believes ZK rollups will eventually surpass the currently popular optimistic rollups as the mainstream technology. Although both ZK and optimistic rollups improve scalability by processing transactions off-chain, they differ in their approaches: ZK rollups rely on validity proofs, while optimistic rollups utilize fraud proofs.Introduction next yearHolding this belief, AndUs has formulated a ZK rollup implementation plan and has begun its development, aiming to introduce it by next year. Park commented that this upgrade will significantly improve the blockchain’s speed and expressed plans to offer the world’s lowest gas fees.AndUs claims that their DEB consensus algorithm focuses on fairness, enabling nodes to engage in mining without preconditions. Furthermore, Anduschain’s ZK rollups will be fully compatible with Ethereum virtual machines (EVMs), facilitating a seamless transition of decentralized applications (dApps). The cryptocurrency used on Anduschain is named DEB, and it is currently listed on cryptocurrency exchanges ProBit Global and MEXC, according to CoinMarketCap.AndUs has been participating in the Tech Incubator Program for Startups (TIPS) program, which is led by private investments under the guidance of the Korean Ministry of SMEs and Startups.

news
Web3 & Enterprise·

Jul 04, 2023

Poly Network Exploit Results in Billions of Nonexistent Tokens

Poly Network Exploit Results in Billions of Nonexistent TokensPoly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.Photo by Shubham Dhage on UnsplashNetwork suspensionThe Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.Bridge vulnerabilitiesBridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.Illiquid Metis tokensMetis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

news
Web3 & Enterprise·

Feb 24, 2024

Swoo Pay partners with Mastercard to target Southeast Asian market

Netherlands-based mobile wallet Swoo Pay has joined forces with global financial giant Mastercard to target the Southeast Asian market, offering crypto cashback on everyday purchases. Crypto loyalty tokensThe partnership was announced via a press release published on Cointelegraph earlier this week. Through Swoo's platform, users stand to gain crypto rewards, specifically Swoo Loyalty Tokens, for each contactless payment made via the app using digitized Mastercard cards. The partnership marks yet another step forward in the convergence of traditional financial systems with the burgeoning world of cryptocurrency. It reflects a broader trend among major financial institutions and retailers, who increasingly view cryptocurrency integration as a means to revitalize loyalty programs. Once users accrue “Tokenback” in the form of Swoo Loyalty Tokens, they have the flexibility to either exchange their rewards for popular cryptocurrencies like USDT or BTC within the Swoo app or convert them into fiat currency through partnering services. As Swoo continues to refine its crypto rewards platform, it will incorporate more Web3 features, further enhancing the utility and value of loyalty tokens within its ecosystem.Photo by Markus Winkler on UnsplashTargeting emerging marketsSwoo Pay is targeting emerging markets. Alongside Southeast Asia, that also brings the Middle East region and Africa within the scope of its marketing efforts for this product offering. Emerging markets have long been seen as ideal markets within which to bring about crypto adoption more generally. The significance of this announcement wasn’t lost on Nicki Sanders, chief technology officer (CTO) with tokenized real estate enterprise, Realio. Taking to social media, Sanders cited crypto adoption as one of three main reasons as to why this partnership could be a game-changer.   Sanders feels that the nature of the offering will result in crypto adoption as daily crypto use will be boosted. In turn, that will bring digital currencies into the realm of mainstream acceptability.She also feels that the product offering will be significant in terms of financial inclusion as it’s very accessible to underserved communities. Additionally, Sanders identifies the inherent innovation as being likely to result in mass adoption. “Focusing on Android and Huawei users, Swoo Pay navigates around Google service sanctions, offering a fresh pathway to digital payments,” she claims.This partnership builds upon the success of a previous trial campaign dubbed “Super Tokenback with Mastercard.” During the three-week initiative, users enjoyed 5% Tokenback (crypto cashback) on all Mastercard purchases made through Swoo Pay. The results were positive, with over 17,000 participants conducting upwards of 128,000 transactions. Not only did this drive increase card spend, but it also introduced a wave of new consumers to the concept of crypto-backed rewards. Representatives from Swoo emphasize the seamless integration of crypto into mainstream markets, ensuring compliance with local regulations and simplifying the launch and scalability of marketing campaigns to attract new users. Conversely, officials from Mastercard underscore the company's commitment to expanding the possibilities of digital payment instruments, prioritizing convenience, technological advancement and security. They highlight the role of Swoo Pay in addressing issues with tokenized payments for Android device users, thereby broadening accessibility to these innovative financial solutions.

news
Loading