Top

OKX shores up App security following bug discovery

Web3 & Enterprise·December 21, 2023, 12:42 AM

Cryptocurrency exchange OKX has swiftly responded to a recently uncovered security flaw by releasing an updated version (v6.45.0) of its iOS app.

 

User data and asset vulnerability

The flaw was identified by Web3 and blockchain security specialist CertiK. It posed a Remote Code Execution (RCE) vulnerability that had the potential to compromise sensitive user data and crypto assets. Notwithstanding that, no user assets were lost or security compromised.

Taking to the X social media platform on Tuesday, CertiK wrote:

”Attention! We urge users of OKX wallets to update their iOS app to the latest version immediately. Earlier this month, we identified and reported a critical Remote Code Execution (RCE) vulnerability in the OKX iOS App, leading to potential compromise of sensitive data and crypto assets.”

Photo by FLY:D on Unsplash

 

Prompt response

Recognizing the risk, OKX has acted promptly to rectify the issue and commit to protecting user assets. It too followed up on social media with its own announcement:

”Thanks @Certik for the note. We’ve completed the relevant upgrade & this is no longer an issue. We have verified that this did not impact any customer assets. The fix has been deployed to iOS version 6.45.0 & we recommend you update the app asap.”

 

Ongoing exploits

This security incident has played out amid a backdrop that has seen a worrying number of hacks, exploits and vulnerabilities in the crypto space. In recent weeks, hacks at HTX (formerly Huobi), cross-chain bridge Heco and Poloniex have accounted for millions of dollars in losses.

As recently as last week, users of the Ledger hardware wallet were told by the company not to connect to decentralized applications as it had discovered that a malicious version of its Ledger Connect software had been distributed.

 

Industry collaboration

The collaboration between OKX and CertiK in addressing this security concern is demonstrative of how industry actors are having to cooperate in order to deal effectively with these vulnerabilities and threats.

Transparent communication and a swift response in this instance are likely to have played a role in minimizing any potential loss. In a noteworthy development, OKX, in collaboration with Tether, has collaborated with the United States Department of Justice (DOJ) to freeze $225 million in USDT tokens.

This unprecedented action primarily targeted a human trafficking syndicate in Southeast Asia, illustrating the increasing cooperation between crypto entities and law enforcement in addressing illegal activities involving digital currencies.

The immediate resolution of the iOS app vulnerability in this instance resulted in no loss occurring. That outcome underscores the importance of the prioritization of user safety and data security.

With the updated app version (v6.45.0) now available, users can proceed with their crypto transactions with renewed confidence in the platform’s security measures. As the cryptocurrency landscape evolves, crypto platforms and platform users will need to remain vigilant in order to safeguard and protect funds.

More to Read
View All
Web3 & Enterprise·

Oct 02, 2024

Ripple scores DFSA license approval in Dubai

Blockchain-based digital payment network enterprise Ripple has announced that it has acquired in-principle approval of a financial services license from the Dubai Financial Services Authority (DFSA) in the United Arab Emirates (UAE). In a press release published on the firm’s website on Oct. 1, Ripple claimed that the approval “unlocks Ripple’s end-to-end payment services in the UAE, boosting Middle East operations.” The in-principle approval is a first step on the company’s path towards full approval. That eventuality will enable Ripple to offer cross-border payment services relative to fiat and digital assets, within the Dubai International Financial Center (DIFC) special economic zone.Photo by Moose Photos on PexelsExpanding Middle Eastern presenceThe company claims that pursuing the license is part of a broader strategy to expand its Middle Eastern presence. It follows on from the firm’s move in 2020 to establish its Middle Eastern headquarters in Dubai. Ripple claims that the licensing “significantly strengthens Ripple’s global footprint as a regulated entity and enables the introduction of seamless cross-border payment services, including Ripple Payments Direct (RPD), in the United Arab Emirates (UAE).” In moving from in-principle approval to full approval, Ripple will have further obligations to accomplish, such as securing office space within the DIFC special economic zone. The company had previously indicated its intention of establishing an office within the DIFC. Back in August, it emerged that Ripple had partnered with the DIFC Innovation Hub with a view towards promoting blockchain and digital asset innovation within the UAE. Regulatory clarity in the UAERipple is striving to become the first blockchain-enabled payment services provider licensed by the DFSA. Once licensed, the company plans to roll out its enterprise-grade digital asset infrastructure. Ripple’s XRP has been one of five digital assets approved by the DFSA such that investment funds are allowed to invest in it, although the regulator did indicate in June that it is moving towards expanding the list of recognized tokens. Mired in legal difficulties with local regulator the Securities and Exchange Commission (SEC) in its home market of the United States in recent years, the company signaled a change of strategy in 2023, indicating its interest in focusing more on international expansion. While speaking at an event in Dubai at the time, Ripple CEO Brad Garlinghouse said that Ripple was expanding in Dubai. Taking to X in relation to this latest milestone, Garlinghouse wrote that “regulatory clarity is what businesses want, and what consumers need,” adding that “the UAE understands that.” In the company’s press release, Garlinghouse referred to the “forward-thinking regulatory approach” being pursued in the UAE, which he believes is positioning the country “as a global leader in this new era of financial technology.” The UAE isn’t the only focus for the company’s international expansion. Ripple has established an office in Singapore which handles over 50% of the firm’s payment flows. On Oct. 1, U.S. investment bank Houlihan Lokey published a report in which it highlighted Ripple as an emerging competitor to the SWIFT cross-border payments system.  Although the company has had some success in navigating its way through litigation with the SEC in the U.S., it’s thought that the dispute may be prolonged further as some commentators have suggested that the SEC plans to appeal a recent court decision. 

news
Policy & Regulation·

Dec 01, 2023

Paxos scores licensing approval in Abu Dhabi

Paxos scores licensing approval in Abu DhabiPaxos, a New York-based blockchain and tokenization infrastructure platform, has achieved in-principle licensing approvals from the Abu Dhabi Global Market’s (ADGM) Financial Services Regulatory Authority (FSRA).Photo by Kent Tupas on UnsplashEnabling stablecoin issuanceIn a press release published on Wednesday, Paxos outlined that these approvals mark a significant step for the company, enabling it to issue USD and other currency-backed stablecoins while also providing crypto-brokerage and custody services through two regulated ADGM entities.This licensing acquisition comes hot on the heels of a similar outcome in Singapore. Earlier this month, Paxos subsidiary Paxos Digital Singapore Pte. Ltd., received in-principle approval from the Monetary Authority of Singapore (MAS). That approval enables it to offer digital payment token services and issue USD-backed stablecoins within the Southeast Asian city-state.The company, while making efforts to focus on transparency and accountability, aims to extend the global reach of its regulated USD-backed stablecoins upon receiving full approval in Abu Dhabi. Walter Hessert, Paxos’ Head of Strategy, emphasized the importance of regulatory compliance and engagement with authorities to shape digital asset rules, maintaining Anti-Money Laundering (AML) and Know Your Customer (KYC) standards.Hessert stated:”Our IPAs [in-principle approvals] from the FSRA [Financial Services Regulatory Authority], on the heels of our IPA from the Monetary Authority of Singapore, solidify our commitment to pursuing international growth through regulated frameworks. Paxos is unique in the industry for this approach and we will continue expanding our regulatory licensing to serve global enterprises as a trusted, innovative partner.”U.S. regulatory difficultiesIn addition to Singapore and now Abu Dhabi, Paxos already holds approvals from the New York State Department of Financial Services (NYDFS), the local state regulator in New York in the United States. The company’s experience in its home market has been problematic more recently, however.In February, the Securities and Exchange Commission (SEC) issued Paxos with a Wells Notice, a letter that informs the receiver that infractions have been uncovered following investigation. The New York regulator, the NYDFS, also took action against Paxos, claiming that the company didn’t administer BUSD in a safe and sound manner.These actions led to Paxos ceasing to mint any further BUSD stablecoin, and existing BUSD tokens will remain redeemable until at least February next year.Focus on Asia and Middle EastIt’s likely that these regulatory difficulties have led to the company concentrating its effort in 2023 on expanding in overseas markets. Licensing accomplishments in Singapore and Abu Dhabi speak to that.Paxos expressed contentment with MAS as its regulator in Singapore, anticipating that the oversight will accelerate global consumer adoption of digital assets. As the first blockchain service provider to obtain licenses in both New York and Singapore, the company is strengthening its regulatory portfolio globally.This is further evidenced by a recent collaboration the company had formed in the Philippines earlier this month. Paxos has forged an alliance with Coins.ph, a leading cryptocurrency exchange in the Southeast Asian country. The goal of the collaboration is to propel the adoption in the Philippines of PayPal USD (PYUSD), a U.S. dollar stablecoin issued by Paxos.

news
Web3 & Enterprise·

Dec 07, 2023

HashKey on-boards market makers to boost liquidity

HashKey on-boards market makers to boost liquidityHashKey, a licensed crypto exchange in Hong Kong, has unveiled plans to onboard individual and enterprise market makers to enhance liquidity on its platform.Photo by engin akyurt on UnsplashMarket maker programIn an announcement on Tuesday, the exchange disclosed that interested parties, whether individuals or entities, can apply to become market makers on HashKey. To qualify, applicants need to engage in cryptocurrency trading worth a minimum of $5 million per month on the exchange.The exchange outlined that the program aimed to “recognize and incentivize users actively contributing to the liquidity” of the platform.Upon submitting their business plans for review, successful applicants will be invited to enter into a contractual agreement with the exchange’s due diligence team, commencing trading activities from Dec. 28 onwards when the program goes live.Commission free tradingThe exchange aims to encourage liquidity providers by offering a commission ranging between 0.005% and 0.015% of the transaction value, determined by monthly rankings or trading volumes, falling within a tiered structure set out within the program. Market makers demonstrating a trading volume of at least $100 million per month stand to enjoy the highest tier of commission revenue. Notably, all market makers will be exempt from commission fees on their trades.Market makers who participate via the program will be on trial for an initial two-month period. Those who are participating in market maker programs on other platforms currently will be able to avail of equivalent trial fee rates through the HashKey exchange.Service expansion trendThe move by HashKey follows a broader trend in Hong Kong, where regulated exchanges have been expanding their services and forming strategic partnerships since the issuance of the first licenses in August. In a recent development, OSL, another Hong Kong licensed exchange, collaborated with Interactive Brokers on November 28, enabling Hong Kong clients to buy Bitcoin through Interactive Brokers’ investment accounts.Additionally, on November 30, OSL welcomed Victory Securities for crypto trading services on its platform. That move came about following Victory’s acquisition of a retail crypto trading license some days beforehand. Notably, OSL received a $90 million investment from blockchain entity BGX in November.While HashKey has been extending its altcoin offerings, exclusively available to accredited investors meeting a $1 million portfolio requirement, the exchange has been proactive in enhancing user security. On Nov. 16, the platform introduced comprehensive insurance coverage for users’ and enterprise assets stored within its digital wallets in collaboration with fintech firm OneDegree.Earlier this week, it emerged that the platform had experienced an unprecedented surge in daily trading volumes. The surge had been attributed to a token rewards program that the exchange is currently running, that offers the distribution of HSK tokens or EcoPoints.As HashKey opens its doors to market makers, the move is poised to contribute to increased liquidity on the exchange, aligning with the broader trend of Hong Kong’s regulated crypto exchanges expanding their offerings and forming strategic partnerships.

news
Loading