Top

Hacking Attempts on Upbit Reach 160,000 in First Half of the Year

Policy & Regulation·October 10, 2023, 2:53 AM

There have been approximately 160,000 hacking attempts on Upbit, Korea’s largest cryptocurrency exchange, in the first half of this year alone, according to a report submitted by Upbit’s operator Dunamu to lawmaker Park Sung-joong of the National Assembly’s Science, ICT, Broadcasting, and Communications Committee.

“Cryptocurrency hacking incidents are increasing both domestically and internationally, and hacking attacks on exchanges such as Upbit, which have daily trading volumes exceeding KRW 2 trillion, are a serious issue,” Park said.

Photo by Clint Patterson on Unsplash

 

An uptick in hacking attempts

The data revealed that the number of cyber breach attempts in the first half of the year totaled 159,061–2.17 times higher than the number of attempts in the first half of last year, which stood at 73,249.

Hacking attempts on Upbit have been steadily increasing in recent years, from 8,356 in the second half of 2020 to 34,687 and 63,912 in the first and second half of 2021, respectively. In the first half of last year, there were 73,249, and 87,242 in the second half. Notably, the exchange suffered losses of approximately KRW 58 billion (approximately $43 million) from a hacking attack in 2019.

 

Ramping up security

Subsequently, Dunamu has taken action to enhance security by managing over 70% of its assets in cold wallets and operating hot wallets in a distributed structure instead of a singular one. Hot wallets refer to online crypto wallets, whereas cold wallets are crypto wallets that are offline and disconnected from the internet. Hot wallets offer the advantage of direct deposits and withdrawals, but they have weaker security levels — most known exchange hacks have thus occurred through this medium. On the other hand, cold wallets store private keys on offline sources like external hard drives and portable storage devices, making real-time trading difficult but providing better security and stability.

“We have taken various preventive measures since the hacking incident in 2019, such as operating hot wallets in a distributed manner. There have not been any successful cyber breaches to date,” Upbit said.

Regarding the role of the Ministry of Science and ICT in managing and overseeing crypto hacking incidents, Park pointed out that this still remains ambiguous. “The Ministry should conduct large-scale white-hat hacking tests and security assessments for crypto exchanges that are frequently faced with hacking attempts, as well as for hospitals and subway systems that manage large amounts of personal information,” he said.

More to Read
View All
Policy & Regulation·

Oct 24, 2023

Singapore High Court Embraces NFTs for Financial Investigations

Singapore High Court Embraces NFTs for Financial InvestigationsA recent decision by the Singapore High Court has seen it embrace non-fungible tokens (NFTs) in financial investigations. Financial investigation firm Intelligent Sanctuary, also known as iSanctuary, has been granted permission to attach NFTs containing legal documents to cold wallets linked to a hacking incident.This innovative approach, similar to the one used in Italy and the United States to deliver court summonses recently, signals a new departure in the application of NFT technology in the legal and financial world.Photo by Choong Deng Xiang on UnsplashMoving towards tokenized legal ordersLondon-based iSanctuary set out details of the court decision in a blog post published to its website recently. A pivotal moment in this scenario was the court’s issuance of a global freezing order encapsulated within soulbound NFTs, securely linked to the specified wallets. Soulbound NFTs are special types of NFTs which are tied to a user’s account. They cannot be transferred or traded.Although these NFTs do not halt transactions, they serve as powerful deterrents, notifying counterparties and exchanges about the wallets’ dubious past involvement in a hacking event.Monitoring fund movementsFurthermore, iSanctuary has unveiled an ingenious strategy to actively monitor funds leaving these wallets through the NFTs. This innovative method ensures a permanent and unbreakable connection between the NFTs and the wallets.iSanctuary recounted on its website that it was employed by a businessperson who had lost $3 million in crypto assets and was able to track the stolen funds successfully. Their method, which combines both on-chain and off-chain evidence, was presented by an iSanctuary senior investigator to the Singapore High Court. This led to the issuance of a worldwide injunction.iSanctuary’s financial and crypto investigators identified a series of cold wallets holding the proceeds of the crime, and the court approved their use of NFTs for service delivery.Mintable collaborationiSanctuary accredited Singaporean NFT marketplace Mintable as the creator of the NFTs. As reported by local news media outlet The Straits Times last week, this case revolved around a stolen private key and the alleged involvement of Singapore-based crypto exchanges in laundering the stolen assets. The fraudsters, purportedly from Singapore, are alleged to have orchestrated this saga that spans countries from Singapore to Spain, Ireland, Britain, and other European territories.Taking to X (formerly Twitter) to comment on the saga, Mintable founder Zach Burks stated:”Happy to help clean up the crypto space and move the NFT ecosystem into a realm of utility and away from the speculation of jpegs!”In a subsequent post, Burks highlighted further NFT-related innovation when pointing to a central bank digital currency (CBDC) pilot program led by Mastercard that implicated the use of NFTs to stamp out fraud. Mintable supported that particular use of the technology within that project.iSanctuary’s founder, Jonathan Benton, emphasized the impact of the recent initiative, calling it a “game changer.” The approach enables swift action, allowing for the identification of illicit asset holders and expediting the issuance of civil or criminal orders, even red flags, within hours if necessary. It also demonstrates that NFTs can be put to good use, above and beyond speculative trading.

news
Policy & Regulation·

Sep 13, 2023

Compliance and Cooperation — A Necessary Formula for Combatting Crypto Crimes

Compliance and Cooperation — A Necessary Formula for Combatting Crypto CrimesFrom common scams like voice phishing to threats of violence, the involvement of cryptocurrencies in crimes against the general public is steadily on the rise both in South Korea and abroad.Photo by Bermix Studio on UnsplashAccording to blockchain data analysis firm Chainalysis, the scale of cryptocurrency-related crimes and hacking on a global scale has decreased by 45.2% and 23.5%, respectively, compared to last year. However, financial losses resulting from smaller ransomware attacks, including phishing scams, are showing an upward trend.Authorities and industry figures alike are increasingly emphasizing the need for close cooperation to combat this growing issue, as existing regulations and legal frameworks remain insufficient to do so.Chainalysis and crypto exchange Binance co-hosted a policy summit in Seoul on Tuesday called “Securing the Future of Crypto,” where experts gathered at the Courtyard Marriott hotel to discuss compliance and cooperation between the public and private sectors in fighting crypto crimes.Challenges and complexities in crypto investigations“The Korean National Police Agency receives dozens of reports of financial losses and urgent requests for account freezes every day, with 80% of them pertaining to Binance,” said Kim Min-jae, an investigator at the National Police Agency’s International Cyber Cooperation Division.Citing a recent case of a voice phishing scam targeting a woman in her 60s, Kim said that authorities were able to proceed with the investigation within 30 minutes after receiving information from the exchange. However, addressing crimes beyond large cryptocurrency exchanges like Binance, such as those involving decentralized finance (DeFi) systems or foreign exchanges, poses a more difficult challenge due to the lack of proper measures to deal with them.Lee Soo-pyeong, a cybercrime investigator at the Korean National Police Agency’s Cyber Investigation Division, also noted that although domestic cases are relatively easier to investigate, there have been many cases — such as the appalling Nth Room case that caused an uproar throughout Korea in 2020 — that involved overseas accounts and exchanges.Steps for effective crime controlWhat measures, then, should authorities and corporations take in order to deal with such issues? Lee stressed the importance of cooperation among international judicial bodies and adherence from businesses to enhance the response to increasingly sophisticated crypto crimes.Know Your Customer (KYC) standards — the guidelines used in investment and financial services to verify customers’ identities and assess their risk and financial profiles — play an important role in this regard. However, “There are no platforms yet, including major exchanges like Binance, that provide us with personal information through KYC measures when funds are laundered,” Kim explained. He expressed hopes for a system jointly established by relevant entities, including local exchanges, that will enable swift criminal investigation.Lee also highlighted the importance of compliance from foreign companies, stating, “While it’s possible to request mutual legal assistance in criminal matters from the International Criminal Police Organization (Interpol), active cooperation from foreign companies is essential.”From an international point of view, Jarek Jakubcek, Head of Intelligence and Investigations APAC at Binance, pointed out that upholding international standards and standardized processes is important, given the fact that crypto crimes transcend borders. While some countries excel in compliance and enforcing anti-money laundering (AML) policies, others fall short, leading criminals to exploit these disparities.Recently, there have been criminals who move their funds through blockchain networks. The development of bridge technology, which facilitates cross-chain asset transfers, has led to laundering techniques becoming more and more sophisticated. However, he assured that tracing funds is still possible, although doing so has become harder than before.The amalgamation of these circumstances has thereby ushered in the era of Know Your Transaction (KYT). While exchanges have traditionally been obligated to perform Know Your Customer (KYC) procedures to prevent money laundering, they must now go beyond verifying user information and analyze customer transaction data in order to understand where money is coming from and how it flows, Jakubcek said. To achieve this, he argued, they must request information from users and work with on-chain data analysis solution companies like Chainalysis to secure real transaction data. Alec Zebrick, Manager of Investigations in the Asia-Pacific region at Chainalysis, added that leveraging on-chain data allows the verification of most transactions.In the rapidly evolving crypto landscape where crimes are still a force to deal with, experts agree that reinforcing compliance and cooperation between exchanges and authorities is imperative.

news
Policy & Regulation·

May 03, 2023

Korea’s Changwon City Boosts Local Art Scene with NFTs

Korea’s Changwon City Boosts Local Art Scene with NFTsOn Monday, South Korea’s Changwon City announced its plan to support local artists by promoting their work through non-fungible tokens (NFTs). This initiative aims to help artists adapt to the rapidly changing fine art industry, driven by state-of-the-art technology, and stay current with the latest trends.NFT ART in ChangwonThis project “NFT ART in Changwon” came to life after the city partnered with MetaGalaxia, a Korean NFT marketplace, earlier this year.Jung Hyun-sub, head of the city’s culture, tourism, and sports division, has encouraged local citizens to participate in the project and emphasized the city’s commitment to fostering the NFT industry, starting with a focus on local artworks.15 artistsThe application process for the project will run from May 1 to May 30, and 15 artists will be selected. Eligible applicants must be Changwon residents who have either majored or are currently majoring in fine arts or have publicly exhibited their artwork.Artists can submit various forms of artwork that can be turned into NFTs, including paintings, photographs, and videos. Those selected will benefit from registration as NFT artists on MetaGalaxia, digitization of their original artworks into NFTs, and promotion of their artworks and profiles across various social media platforms.© Pexels/Dom J

news
Loading