Top

Kronos Research experiences significant cybersecurity breach

Web3 & Enterprise·November 21, 2023, 12:16 AM

Kronos Research, a Taipei-based crypto trading, market making and venture capital firm, has found itself in the crosshairs of a cyber attack.

Photo by FLY:D on Unsplash

 

$25.6 million loss

Hackers gained unauthorized access to the company’s API keys, resulting in losses exceeding $25.6 million spread across various cryptocurrencies, prompting a concern within the crypto community.

The breach was detailed by the company in a social media post on the X platform on Saturday. That post read:

“In the interest of transparency Around 4 hours ago, we experienced unauthorized access of some of our API keys. We paused all trading while we conduct an investigation. Potential losses are not a significant portion of our equity and we aim to resume trading as soon as possible.”

 

On-chain sleuthing

Investigations by crypto community members have followed, led by blockchain researcher ZachXBT. ZachXBT is a well-known anonymous persona in the crypto space, having earned a reputation for uncovering hacks, scams and unethical practices within the crypto sector.

In this instance, ZachXBT uncovered a trail of transactions originating from a Kronos Research account. The meticulous execution of the cyber attack was evident in six transactions involving 2,780 ETH, 2,540 ETH (repeated twice), 2,636 ETH, 4.93 ETH and 2,507.52 ETH, all directed to addresses controlled by the hacker.

Kronos Research has followed up with a tweet thread on X, acknowledging the gravity of the situation and confirming losses of approximately $25.65 million in crypto assets. Despite the alarming figures, the company sought to reassure stakeholders by emphasizing that the losses represent a relatively small fraction of its total equity. In a commendable display of accountability, Kronos Research pledged to absorb all losses internally, shielding its partners from the financial ramifications of the breach.

The Taiwanese firm posted:

“Our team has been working round the clock to minimize the impact and resume trading operations, following a hacking incident that involved unauthorized access to our API Keys.”

 

Implications for Woo X

The operational repercussions were swift and impactful, with Kronos Research opting for a temporary suspension of all trading operations. This decision rippled through to Woo X, the affiliated Taipei-based exchange and liquidity provider created by Kronos, which temporarily blocked specific asset combinations due to liquidity concerns. Importantly, Woo X assured users of the security of their funds and later announced the resumption of spot and perpetual trading.

Looking forward, Kronos Research outlined its intention to resume trading operations in the coming days, contingent on favorable conditions.

The cyber attack on Kronos Research occurred against the backdrop of heightened cybersecurity concerns within the crypto space. According to blockchain security firm Certik, approximately $173 million was lost to crypto attacks in November alone. The Kronos Research breach follows on the heels of Poloniex’s $131 million hack, highlighting the persistent challenges faced by crypto platforms in securing user assets.

More to Read
View All
Policy & Regulation·

Apr 10, 2023

Korean Lawmakers Complete First Rough Draft of Virtual Asset User Protection Bill

Korean Lawmakers Complete First Rough Draft of Virtual Asset User Protection BillKorean lawmakers have completed the first rough draft of the virtual asset user protection bill at a National Policy Committee meeting held later last month.©Pexels/Matthias ZomerAgreeing on term usage ‘virtual assets’So far, 18 bills have been proposed to regulate cryptocurrencies, and the lawmakers and the Financial Services Commission (FSC) agreed to use the term “virtual assets” to encompass similar terms such as digital assets and crypto assets.Phased enactment of billsThe bills are likely to be reviewed under the title “Virtual Asset User Protection Act.” The bipartisan group agreed to enact the bills in phases, introducing the user protection bill in the first phase and the virtual asset listing and issuance bill in the second phase.Meanwhile, there were mixed opinions on the content of the bills. In particular, there was debate over whether the bills should stipulate that the central bank digital currency (CBDC) is excluded from virtual assets, and whether the bills should include a standard for determining if a virtual asset is a security.Debate over stipulating CBDC’s statusThe stipulation of excluding CBDC from virtual assets was the most divisive topic since it would lead to defining the conditions for other assets such as non-fungible tokens. Moreover, the Act on Reporting and Using Specified Financial Transaction Information, which currently regulates virtual asset service providers (VASPs), does not contain any stipulation on CBDC. Some raised concerns that such discrepancies could later cause confusion. In the end, assembly members decided to discuss the matter again in April after consulting with the Bank of Korea and the Ministry of Government Legislation.Criteria for classifying virtual assets as securitiesRegarding whether to include criteria for classifying virtual assets as securities, the lawmakers and financial regulators took different sides.Lee Yong-woo, a member of the Democratic Party of Korea, underlined that a clear statement of the relationship between the issuer and the recipient of virtual assets in a whitepaper can determine their security status. He added that such provisions should be included in the bills.Park Min-woo, an FSC official, on the other hand, commented on a cautious note that in case virtual assets fall under the category of securities, they may not be applicable to the virtual asset act. He explained that VASPs might deal with both securities and virtual assets, and in such cases, there could be a misunderstanding that VASPs are not subject to the virtual asset act simply because they trade securities.

news
Web3 & Enterprise·

Sep 04, 2025

UAE’s RAK Properties to accept crypto payments through Hubpay partnership

RAK Properties has signed a strategic agreement with Hubpay that will allow international buyers to pay for homes in the United Arab Emirates (UAE) using digital assets, the real estate developer said in a Sept. 1 statement on its website. Under the arrangement, customers can settle property purchases with major cryptocurrencies, including USDT, Bitcoin (BTC), and Ethereum (ETH). Payments will be processed on Hubpay’s regulated platform, converted into UAE dirhams, and transferred directly to RAK Properties’ account. The company said it will not handle digital assets directly. Instead, all transactions will be processed by Hubpay and its partners, who are licensed by Dubai’s Virtual Assets Regulatory Authority (VARA), to ensure compliance and transparency. The initiative is aimed at drawing new categories of overseas investors to Ras Al Khaimah, the UAE’s sixth-most populous city, including the developer’s Mina waterfront community.Photo by Precondo CA on UnsplashUAE’s crypto market expands amid rising risksThe move comes amid growing crypto activity in the UAE. A Chainalysis report last year ranked the Middle East & North Africa as the seventh-largest crypto market and noted that the UAE’s decentralized finance adoption was above the global average, citing regulatory clarity. From July 2023 to June 2024, crypto inflows to the UAE leaned heavily toward stablecoins, which represented 51.3% of value received, compared with 44.7% worldwide. Bitcoin’s share was smaller than the global average at 16.5% versus 22.3%, while altcoins and Ethereum showed little difference at 24.4% and 7.8%, respectively. At the state level, the UAE itself has emerged as a significant player. Based on Arkham’s tracking, it is the world’s fourth-largest government Bitcoin holder, with about 6,352 BTC ($703 million). In contrast to the U.S. and U.K., whose holdings largely stem from law enforcement seizures, the UAE’s reserves come from mining through Citadel Mining. The firm is majority-owned by 2PointZero under the International Holding Company (IHC), which is chaired by Sheikh Tahnoun bin Zayed al-Nahyan, the UAE’s national security adviser and a prominent member of the ruling family in Abu Dhabi. As crypto use has grown, so too have the risks. In the first half of this year, the UAE recorded the world’s largest average per-victim losses from crypto crime, with nearly $80,000 stolen per individual, according to Chainalysis. Only the U.S. came close to that figure, while Chile, India, Lithuania, Japan, Iran, Israel, Norway, and Germany rounded out the global top ten. Harmonizing crypto rulesAmid a shifting crypto landscape, regulatory structures in the UAE are continuing to evolve. At the federal level, the Securities and Commodities Authority (SCA) supervises virtual asset services, while the Central Bank of the UAE (CBUAE) oversees payment tokens. The Dubai International Financial Centre and the Abu Dhabi Global Market operate their own frameworks. Last month, the SCA and VARA introduced a cooperation framework to harmonize oversight and allow mutual recognition of licenses, though the system stops short of automatic passporting in order to preserve national security controls. In related developments, the National Bank of Ras Al Khaimah (RAKBANK) became the first bank in the UAE to partner with Bitpanda Technology Solutions, a Vienna-based crypto exchange and digital assets infrastructure provider. The partnership, which builds on earlier work exploring the issuance of digital payment tokens, is expected to give RAKBANK customers access to a variety of crypto use cases. 

news
Web3 & Enterprise·

Mar 08, 2024

World’s oldest exchange gains in-principle approval in Singapore

Bitstamp, regarded as the longest-running cryptocurrency exchange in the business, declared on March 6 that it has obtained in-principle approval for a license to function as a Major Payment Institution (MPI) from the Monetary Authority of Singapore (MAS).Photo by Zhu Hongzhi on UnsplashFirst major Euro exchange in SingaporeThis preliminary approval, a precursor to a full-fledged license for operation in Singapore, marks a significant milestone for Bitstamp towards offering digital payment token services within the city-state. According to the exchange's press release, it's the first crypto trading platform with a substantial presence in the European Union (EU) to secure such approval from MAS. The nod from Singapore’s financial regulator arrives amidst notable regulatory strides in the crypto domain, including the European Union’s rollout of the Markets in Crypto-Assets (MiCA) framework and the green light given by the U.S. for Bitcoin ETFs. Focusing on AsiaBitstamp's strategic focus on the Asia Pacific region, with Singapore as its central hub, underscores its focus in delivering services to both institutional and retail clientele across the region. The firm’s intent in this regard became clear in August of last year when Bitstamp sought capital funding to enable it to extend the platform’s reach into various markets across Asia. Whilst the company’s origins can  be traced back to Slovenia, it has since developed further ties with Asia. In 2018, the company was acquired by NXMH, a subsidiary of South Korea’s NXC Corporation. The same holding company owns Korean crypto exchange Korbit. Compliance strategyWhile the licensing is quite the achievement, the company already boasts a robust regulatory track record, surpassing the 50-license mark across key markets such as Luxembourg, the Netherlands, Italy, Spain, France the United States (with coverage in 40 states including New York, Washington, Texas and Florida) and the United Kingdom. In its press release the company referred to its ever-growing licensing collection, outlining that “compliance and regulation [are] at the heart of all operations.” Leonard Hoh, Bitstamp's APAC General Manager, lauded Singapore's proactive stance in establishing a regulatory framework for crypto exchanges, positioning the city-state as a pivotal player in the digital assets landscape. Singapore has already granted full licenses to several crypto service providers, including Blockchain.com, Circle, Coinbase and Ripple. In late 2023, Bitstamp initiated talks with three major European banks regarding the potential introduction of cryptocurrency services in 2024. This signals a broader trend within the EU, where the crypto regulatory initiative, MiCA, is smoothing the path for traditional financial institutions to venture into the digital assets realm. Robert Zagotta, Bitstamp’s Chief Commercial Officer, highlighted the surge in interest surrounding its “Bitstamp-as-a-Service” offering, especially within European circles. This service furnishes a white-label licensing framework, coupled with requisite technology, to aid banks and fintech entities in facilitating cryptocurrency transactions for their clientele. However, the regulatory landscape isn't as welcoming in India, where the country’s Financial Intelligence Unit (FIU) urged the Ministry of Electronics and Information Technology to block the URLs of nine major global crypto exchanges, including Bitstamp, in late 2023. 

news
Loading