Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Policy & Regulation·

Jul 14, 2023

South Korean Banks Adopt Blockchain for Streamlined Civil Servant Loans

South Korean Banks Adopt Blockchain for Streamlined Civil Servant LoansSouth Korea’s state-run financial organizations and banks are embracing blockchain technology to streamline the loan process for government employees and enhance loan management for banks.Photo by Shubham Dhage on UnsplashBlockchain-aided loan servicesIn a collaboration announced today at the Korea Federation of Banks (KFB) in Seoul, the Korea Financial Telecommunications and Clearings Institute (KFTC), the Government Employees Pension Service (GEPS), and four local banks are coming together to introduce blockchain technology in providing loan services specifically tailored for civil servants. The four participating banks are NongHyup Bank, Hana Bank, DGB Daegu Bank, and Gwangju Bank.Easier applicationAt present, civil servants are required to acquire a physical loan recommendation letter from the GEPS in order to apply for a bank loan. However, with the implementation of the new loan system, the GEPS will have the capability to issue blockchain-based letters, which can be obtained by civil servants either in-person or remotely at banks. This innovative approach will significantly simplify the verification process for these letters.Easier managementFurthermore, the manual exchange of loan-related information, such as repayment history and retirement details, between banks and the GEPS will be replaced by a more efficient system. The KFTC will take on the role of mediator, ensuring that any changes to this information are immediately reflected in real time. This streamlined approach will significantly enhance loan management for lenders.The launch of this service is scheduled for November this year, bringing about improved accessibility to loans for government employees. As the project progresses, other financial institutions are expected to join in, further enhancing the convenience of public servants. Additionally, these collaborating organizations will explore joint services aimed at providing the necessary support to stabilize the livelihoods of civil servants.

news
Web3 & Enterprise·

Nov 25, 2023

BingX embarks on rebrand to further service offering

BingX embarks on rebrand to further service offeringBingX, the Singapore-headquartered cryptocurrency exchange platform, has taken the decision to rebrand the business.Improving the trading experienceThe platform, originally known for its role in guiding newcomers into the crypto space through copy trading, claims that the move is designed to elevate the trading experience for users by prioritizing simplicity, efficiency and security.This transformation includes a substantial overhaul of BingX’s visual identity, highlighted by a streamlined logo that caters to the practical needs of traders. The changes extend to the platform’s color palette and typography on digital platforms, all aimed at making the trading process more intuitive and user-friendly.Photo by Patrik Michalicka on UnsplashBroadening market appealWhile initially recognized for its focus on crypto beginners, BingX is now broadening its horizons. The platform introduces advanced features catering to a diverse range of crypto enthusiasts, from novices to seasoned traders. This expansion underscores BingX’s adaptive approach to the dynamic cryptocurrency market, addressing the evolving needs of its user base.Megan Nyvold, Head of Branding at BingX, outlined that the rebranding aligns with the company’s enduring vision of democratizing crypto trading globally, emphasizing diversity and creating professional, user-centric trading environments.From ‘Trading Made Easy‘ to ‘Empowering Traders’In tandem with the visual changes, BingX has also unveiled a new tagline, transitioning from “Trading Made Easy” to “Empowering Traders.” This shift emphasizes the company’s commitment to supporting traders at all levels, ensuring access to reliable and transparent services.In a blog post published by the company on Thursday, Nyvold stated:”Over the past five years, BingX’s vision to build a gateway for the next billion crypto users has been unwavering. As part of this evolution, we have refined our core values with a renewed emphasis on promoting diversity. As we introduce our refreshed brand identity, we reaffirm our assurance of empowering our users, focusing on a more professional and user-centric trading environment that aligns with our vision for collective success.”This latest move is one of a number of ongoing efforts BingX has made this year to further develop the business. In July, the company introduced AstraBit to the platform, an automated algorithmic trading and portfolio management tool, to enhance and automate the crypto trading experience for its platform users.The following month, it introduced a Multiple Deposit Addresses feature to enable greater flexibility and convenience for service users. September brought a collaboration with WunderTrading, adding the use of its automated trading bots to BingX platform users. Earlier this year, the company had integrated crypto portfolio tracker CoinTracking with the platform, in an effort to allow service users to generate reports for tax purposes with ease.BingX was founded in Singapore in 2018 by Josh Lu. The platform claims to have five million service users.

news
Policy & Regulation·

Apr 27, 2023

US Sanctions Chinese for Enabling Crypto Money Laundering

US Sanctions Chinese for Enabling Crypto Money LaunderingIn a press release published earlier this week, the Office of Foreign Assets Control (OFAC) within the Department of the Treasury in the United States, stated that it had sanctioned two Chinese nationals and a Hong Kong British national for allegedly having aided the North Korean government in crypto money laundering activities.©Pexels/RODNAE ProductionsThe Americans claim that the funds are the proceeds of cyber crime with the laundered money in turn being used to support the Democratic People’s Republic of Korea (DPRK) regime, including its ballistic missile and weapons programs.Illicit OTC crypto tradesThe three OFAC-sanctioned individuals are Wu Huihui (Wu), Cheng Hung Man (Cheng) and Sim Hyon Sop (Sim). Wu is an over the counter (OTC) cryptocurrency trader based within China. OFAC claims that he has facilitated the conversion of millions of dollars worth of stolen digital assets into fiat currency at the behest of a North Korean cyber-crime syndicate.In 2009 OFAC sanctioned a small North Korean bank, Korea Kwangson Banking Corp. (KKBC). At the time, the agency claimed that KKBC had extended financial services to previously designated North Korean banks including Tanchon Commercial Bank and Korea Hyoksin Trading Corporation. Fourteen years on, OFAC has now identified Sim as a facilitator of KKBC money laundering schemes. OFAC claims that Sim represented the sanctioned bank, and in the process, he was the recipient of millions of dollars worth of cryptocurrency.Overseas earningsThe agency claims that the source of this money was the earnings of North Korean IT workers who had worked overseas, including within the United States. The North Korean regime has pursued a strategy of sending workers into employment overseas in an effort to raise capital in harder currency.Like Wu, Cheng was also identified as an OTC cryptocurrency trader. It’s understood that Cheng collaborated with Wu, and employed a series of shell companies in order to convert cryptocurrency into fiat money.Blockchain data analysis firm Chainalysis has researched the topic based upon the OFAC and Department of Justice data and information. That analysis has revealed that the North Korean hackers and cyber-crime facilitators make use of cryptocurrency mixers such as Tornado Cash and Sinbad. While other illicit entities utilize these crypto mixers which attempt to obfuscate the origin of digital assets, Chainalysis’ research suggests that the North Korea-affiliated actors use mixers to a far greater extent than others.Reward offeredIt’s understood that the US authorities indicted a fourth person who remains unknown beyond his/her online moniker, “live:jammychen0150.” Properties in the United States connected with the three known individuals have been frozen. The State Department has also outlined its willingness to provide a reward of up to $5 million for any information that leads to the arrest or conviction of Sim. Furthermore, rewards of $500,000 each are being offered relative to the apprehension of two of Sim’s associates, Han Linlin and Qin Gouming.In a statement, Department of Justice Criminal Division Assistant Attorney General Kenneth Polite Jr. said that “the North Korean operatives have innovated their approach to evading sanctions by exploiting the technological features of virtual assets to facilitate payments and profits, and targeting virtual currency companies for theft.”

news
Loading