Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Mar 27, 2024

Coinone updates its mobile app to provide better UX for crypto investors

Coinone, one of the five fiat-to-crypto trading platforms in South Korea, unveiled an upgraded version of its mobile app charts for a better user experience. According to local news source Bizwatch, the update introduces an array of indicators at the bottom of the charts to facilitate more comprehensive analysis. Additionally, the app now includes three new chart features: a display of best orders, the capability to see price alert lines and access to a 90-day transaction history. Since last year, Coinone has rolled out 20 updates aimed at enhancing the trading experience and bolstering security for its users. This year also saw several new features. Among these are the integration of TradingView charts and the addition of share buttons for announcements. Additionally, Coinone recently started providing the functionality to print statements for crypto accounts.Photo by Kanchanara on UnsplashHiring more developersThese enhancements are part of Coinone's continuous efforts to elevate customer satisfaction and refine its services. Despite the downturn that the cryptocurrency industry faced last year, Coinone took a noteworthy step by bringing on board 20 new developers this year. This move underscores Coinone's proactive stance in improving its platform and offerings amidst challenging market conditions. Coinone's focus on meeting customer demands has led to a notable reduction in inquiries. Last year, the exchange reported that its efforts to enhance customer service resulted in a decrease of more than 45% in the number of customer inquiries. Compliance amid changing regulatory environmentMarking its 10th anniversary last month, Coinone has set its sights on emphasizing investor protection and regulatory compliance in anticipation of the upcoming implementation of the Virtual Asset User Protection Act, which is slated to take effect in July.  Cha Myung-hun, the CEO of Coinone, commented on the recent updates, noting that the surge in public interest towards virtual asset investment has prompted the decade-old exchange to enhance its chart functionalities, specifically catering to novice investors. 

news
Policy & Regulation·

Oct 24, 2023

Seoul and Baobab Partners Face Controversy Over Unpaid Prize Winnings for SWF2023 Hackathon

Seoul and Baobab Partners Face Controversy Over Unpaid Prize Winnings for SWF2023 HackathonThe city of Seoul has come under public scrutiny for failing to pay the winners of the Seoul Web3 Festival (SWF2023) Hackathon a cash prize worth KRW 150 million (approximately $112,000). The Seoul Metropolitan Government has argued that since it was simply a naming rights sponsor, the responsibility for paying the prizes lies with Baobab Partners, who co-hosted the event. However, critics argue that the city did not properly vet Baobab Partners more rigorously before hosting the event.Photo by okaybuild on PixabayUnpaid prizes lingerThe SWF2023 Hackathon took place from July 31 to August 2 at Dongdaemun Design Plaza (DDP) and was co-hosted by the city of Seoul, the Seoul Design Foundation, and Baobab Partners. It offered a total prize pool of KRW 150 million attracting 417 participants who made up 115 teams.However, although over two months have passed since then, the winners are yet to be paid their prize money. “Baobab Partners initially proposed the SWF2023 event, and they were responsible for gathering the necessary sponsorship funds to run the event,” said a city representative.According to industry sources on Monday, the company’s CEO, Choi Jin-beom, issued a handwritten apology last Friday regarding the incident. “We promised to pay the winners by today, but we were unable to deliver on that promise. We explored multiple avenues, including investors, new contractors, and other assets, but were ultimately unable to secure the funds to do so,” he said. “The narrative that the funds were diverted elsewhere or invested in cryptocurrencies or stocks is untrue,” he added, clarifying that related information was transparently disclosed to the city of Seoul.Baobab Partners’ swift rise raises industry eyebrowsBaobab Partners had previously participated as an event planner at last year’s Blockchain Week in Busan, which turned out to be a success. “We also spoke with the Busan city government, who gave a positive opinion of the company,” the representative added. It was under this context that Seoul entered into a naming rights agreement with Baobab Partners. The agreement stipulated that the company would be in charge of attracting and managing sponsorships, and the prize money and operational costs would be covered by corporate sponsorship funds.Nevertheless, questions have arisen within the industry about Baobab Partners’ short track record and its successive collaborations with public organizations. Baobab Partners is a startup that was founded in May 2021. In November of the same year, the firm signed memoranda of understanding with three blockchain companies during NFT Busan 2021, a large-scale NFT fair held in the southern port city to share the latest blockchain trends. As a result of its efforts, it was listed alongside prominent companies such as Coinone and Onther despite only six months passing since its establishment. Subsequently, Baobab Partners relocated from Seoul to Busan, and the following year, it participated as an event planner at Blockchain Week in Busan.Accumulating allegationsSpeculation suggests that this success was not solely due to Baobab Partners’s capabilities. The company’s CEO is believed to have political connections, according to an anonymous industry insider. Choi denied such claims and stressed that its technical expertise should not be downplayed, citing the fact that Baobab Partners was the first entity in Korea to develop virtual reality (VR) banking technology and had received a KRW 15 billion investment from Finger, a KOSDAQ-listed company.Baobab Partners has also been mired in controversy over supposedly unpaid wages. In response to a claim made by an industry source that many former employees of Baobab Partners have still not received their due wages, a Seoul representative stated that there is no such dispute according to conversations with company representatives, seeking to dispel the dispute. Choi further explained, “We didn’t have wage disputes until last year. The difficulty in paying wages began in January this year due to the failure to execute promised investment funds.”The city said that it is currently conducting legal examinations and looking into necessary measures for two matters involving Baobab Partners, including the handling of hackathon winnings.

news
Markets·

May 15, 2025

Japanese firms expand Bitcoin holdings amid growing institutional interest

Several Japanese companies, including Remixpoint and Metaplanet, have been increasing their Bitcoin (BTC) holdings, underscoring the growing institutional interest in cryptocurrencies in the region.Photo by Kanchanara on UnsplashRemixpoint, an energy consulting firm listed on the Tokyo Stock Exchange, recently announced an additional purchase of 32.83 BTC valued at 500 million yen ($3.4 million), according to local news outlet CoinPost. This acquisition took place on May 13 at an average price of 15.23 million yen ($104,270) per BTC, bringing the company's total BTC holdings to 648.82 BTC. Remixpoint's crypto portfolio, including BTC, is now valued at 11.1 billion yen ($76 million) and also comprises Ethereum (ETH), Solana (SOL), XRP and Dogecoin (DOGE). The firm began actively accumulating BTC late last year, motivated by multiple factors, including the positive price trend following the latest Bitcoin halving event, increased market activity after the latest U.S. presidential election and the growth in institutional participation, particularly after the approval of spot crypto ETFs in the U.S. Metaplanet becomes a major BTC holderAnother notable player, Metaplanet, a publicly traded Japanese company specializing in Bitcoin investment, has positioned itself as one of the largest BTC holders globally. As of May 12, Metaplanet’s Bitcoin yield reached 170%, with total holdings of 6,796 BTC. This places it as the 11th largest Bitcoin holder worldwide and the largest in Asia, surpassing El Salvador, which currently holds 6,177 BTC, according to data from Arkham. Metaplanet's ongoing Bitcoin accumulation aligns with CEO Simon Gerovich's advocacy for Bitcoin. In a March podcast, Gerovich said he encourages his friends to allocate "100% of their net worth into Bitcoin." The company’s strategic goal is to amass 10,000 BTC by the end of 2025 and 21,000 BTC by 2026. Reinforcing its influence, Metaplanet appointed Eric Trump, the second son of pro-crypto U.S. President Donald Trump, to its newly formed Strategic Board of Advisors in January. Evolving crypto policies, including national reservesBefore Trump's second term, Gerovich expressed his expectation that other countries would follow the U.S. once it established a national Bitcoin strategic reserve—a move formalized by President Trump through an executive order in March. In a related development, Ukraine is reportedly drafting a bill to create a similar reserve in collaboration with Binance. Meanwhile, in Taiwan, lawmaker Ko Ju-Chun has been advocating for adding Bitcoin to the country's national reserves. In a similar trend, another Japanese firm, Value Creation, disclosed plans last month to acquire 100 million yen ($660,000) worth of Bitcoin, further reflecting the growing interest among Japanese companies in crypto investments. Complementing this corporate adoption trend, Japan's Financial Services Agency (FSA) has been shaping its regulatory framework for cryptocurrencies. The agency aims to redefine digital assets as financial products under the Financial Instruments and Exchange Act, a move viewed as an attempt to balance innovation with investor protection. Building on this approach, an FSA discussion paper released on April 10, which remained open for public feedback until May 10, proposed classifying crypto assets into two categories: those used for fundraising and business activities, and those that are not—such as BTC and ETH. This regulatory evolution, alongside increasing corporate investment in BTC, reflects Japan's efforts to adapt to the evolving global crypto landscape.

news
Loading