Top

CoinEx Reveals Insights Into Recent Platform Hack

Policy & Regulation·September 20, 2023, 1:33 AM

Hong Kong crypto exchange CoinEx has issued a further update relative to the security breach that occurred on the platform last week resulting in one of the exchange’s hot wallets being compromised.

Photo by FLY:D on Unsplash

 

Immediate response

In the immediate aftermath of the $70 million hack, CoinEx took action to safeguard user assets and initiate an investigation into the incident. It suspended all deposit and withdrawal services and executed an emergency shutdown of the hot wallet server. Following this, the company securely moved the remaining assets to cold storage, commencing the process of reconstructing and deploying a new wallet architecture.

The firm also engaged in an investigation, spearheaded by its wallet and security teams, to ascertain the extent of the breach. Moreover, CoinEx claims to have proactively reached out to fellow exchanges to freeze any assets related to the attack.

Haipo Yang, the Founder and CEO of CoinEx, conveyed his apologies to affected users through his personal X (formerly Twitter) account. He emphasized the team’s commitment to restoring services promptly and reassured users that their funds will remain secure.

Following up on that commitment, CoinEx published an update on the hot wallet hack on September 15 to address these concerns individually.

 

New wallet deployment

The exchange expects to finalize wallet upgrades within the upcoming week, after which withdrawals will gradually be phased in, subject to security evaluations. The CoinEx team is currently working on developing and deploying an entirely new and robust wallet system capable of managing activities across 211 chains and 737 assets.

The firm has outlined that each of its product lines operates independently, featuring its own risk control system. Consequently, the security incident that occurred on CoinEx will not affect the integrity of its other product lines.

In its most recent update on Tuesday, the Hong Kong crypto exchange confirmed that 80% of its wallet system has now been reconstructed. It added that it has initiated preparations to enable the withdrawal system on the platform. It stated:

”Details about the resumption of withdrawals, including specific dates, times, and arrangements, will be announced on the CoinEx website. Please stay updated on our announcements for the latest information.”

 

Ongoing investigation

Regarding the identity of the attacker, CoinEx has confirmed that the matter is currently under investigation. While some security firms have made attribution claims, the company is focusing primarily on deploying the new wallet architecture, restoring affected users and functionalities, and enhancing overall security.

At the same time, the company has initiated communications with the hackers in a bid to proactively seek a mutually agreeable resolution. While the incident implicates the loss of a substantial amount of funds, the firm maintains that in the context of the overall business, the sum represents only a small percentage of total assets under its management.

Exchange security remains a major challenge in the crypto sector, with hacks happening on an ongoing basis. Last week, Seychelles-headquartered peer-to-peer crypto platform Remitano acknowledged a $2.7 million hack. At the beginning of September, crypto gambling platform Stake was reported to have suffered a $41 million hack.

More to Read
View All
Web3 & Enterprise·

Dec 19, 2023

Coinone adds new security features

Coinone adds new security featuresSouth Korean cryptocurrency exchange Coinone has recently added two new features — “Change Phone Number” and “Lock Account” — on its website and mobile app to bolster user security and convenience, according to local news site Greenpost Korea on Tuesday (KST). This comes after the platform recently rolled out plans to terminate its existing authentication services — identity verification via the Coinone PASS app was suspended on Dec. 4, and the service on the Kakao Pay platform will also be suspended on Dec. 28.Photo by FLY:D on UnsplashRobust protection measures“As the number of malicious smishing and phishing attempts to access customer accounts is increasing, it is essential to strengthen customer security. We will continue to implement security features that allow customers to use our services conveniently and safely,” said Myung-hoon Cha, CEO of Coinone.Enhanced user controlAccording to the exchange, users can change their phone number after completing the identity verification process in the “Change Information” option on the “My Page” tab. Notably, if a user’s account information is unintentionally disclosed, they can utilize the Account Lock feature to protect their account. These two features have been added to Coinone’s mobile app in its latest version upgrade.After announcing plans to suspend authentication via Kakao Pay, Coinone instead introduced authentication services via the KakaoTalk app on Dec. 14, which is generally more commonly used by Koreans. By registering a KakaoTalk mobile certificate on the “Additional Channel Authentication” tab, users can undergo identity verification without the hassle of logging in separately. This latest authentication channel was added as yet another option along with Naver, which was added earlier in August.

news
Web3 & Enterprise·

Sep 01, 2023

CJ ONE to Sell 3,000 NFTs for New Membership Service

CJ ONE to Sell 3,000 NFTs for New Membership ServiceCJ ONE, a lifestyle membership service operated by digital service company CJ OliveNetworks of South Korean conglomerate CJ Group, announced on Tuesday that it will sell 3,000 digital membership NFTs for its new lifestyle service, PRISM ONE. This comes as part of efforts to enhance brand value and boost customer benefits.Photo by Choong Deng Xiang on Unsplash“The PRISM ONE Membership NFT is an important milestone that reflects changes within CJ ONE. As a lifestyle membership, our brand will strive to provide unique experiences in all aspects of our members’ lives,” said Ha Jae-young, Head of Data Marketing at CJ OliveNetworks.Tier benefitsThe NFTs are categorized into four tiers — Basic, Special, Premium, and Prestige — with higher tiers offering more benefits. Depending on the tier, which will be decided randomly, customers can receive up to 10,000 CJ ONE membership points per month and eight times the number of points that they accumulated the previous month over a period of half a year.CJ ONE points can be used like cash at various CJ Group subsidiaries that offer services in culture, dining, shopping, and entertainment, as well as over 30 brand partners such as cafe Mega MGC Coffee, convenience store CU, and refinery company Hyundai Oilbank.10 customers with the Prestige NFT will also be chosen to receive benefits worth KRW 1 million, including welcome packages from CJ The Market, CJ Group’s online grocery shopping mall, and accommodation vouchers to use at Starville, a luxury “glamping” — a portmanteau of “glam” and “camping” — site.Limited sales and resell opportunitiesMinted with a new brand identity design, the NFTs will be sold for KRW 45,000 each on the NFT trading platform Pala starting from 7 PM (Korea Standard Time) on September 13. Customers who participate in an event until September 3 can win a chance to purchase them at a discounted price of KRW 42,000 prior to the public sale. Payments can be made with Polygon tokens (MATIC) or Korean won, and digital wallets Klip and MetaMask are also supported, the company said. In particular, the NFTs can be resold on trading platforms like Pala.

news
Web3 & Enterprise·

Jan 30, 2024

OKX Ventures broadens portfolio to include Orbiter Finance

OKX Ventures, the investment arm of the well-known crypto exchange and Web3 technology company OKX, has recently disclosed a strategic investment in Singapore’s Orbiter Finance. Developing ZK-proof technologyThe investment marks a significant step forward in advancing the evolution of blockchain infrastructure, given that Orbiter Finance has achieved recognition for its innovation in the process of developing its zero-knowledge (ZK) technology-based omni-chain rollup on the Ethereum network. This initiative goes beyond Orbiter Finance's initial role as an asset cross-rollup bridge. Over the last two years, Orbiter has processed over 12 million transactions with a total transaction volume surpassing $7.8 billion. The protocol has amassed a user base of over three million and cultivated a community exceeding 700,000 users and enthusiasts.Photo by Shubham Dhage on UnsplashOrbiter Rollup announcementAccording to a series of posts on the X social media platform over the course of the weekend, the project is gearing up to launch a ZK-tech-based instant omni-chain rollup on Ethereum. A standout feature of the protocol is the integration of ZK Simplified Payment Verification (SPV) to authenticate Layer 2 transactions on the mainnet and combat fraudulent re-layers via the Ethereum Virtual Machine (EVM).  This development introduces a secure, efficient, low-cost and rapid communication mechanism for Ethereum, with the added security benefits of ZK-SPV enabling Orbiter Finance to grant complete access to the "Maker" role. This marks a significant milestone in achieving decentralization within blockchain infrastructure. Dora Yue, founder of OKX Ventures, expressed enthusiasm about spearheading the strategic investment in Orbiter Finance. She highlighted the protocol's ability to overcome traditional bridge limitations, specifically in terms of speed, and its crucial role in enhancing the efficiency of cross-chaining between various Layer 2s and the Ethereum mainnet. Other investors in the project include Redpoint China, Hash Global and Skyland Ventures. Supporting 19 networksCurrently supporting over 19 Layer 2 rollups and a multitude of native Ethereum assets, Orbiter Finance is positioning itself as a vital infrastructure component for the Layer 2 ecosystem. Yue commended the team's ongoing commitment to product upgrades and their dedication to ensuring a more decentralized and trustless foundation for the Layer 2 ecosystem's growth in 2024. With an initial capital commitment of $100 million, OKX Ventures is focused on exploring and supporting the best global blockchain projects, fostering cutting-edge technology innovation, and investing in projects that provide long-term structural value. The venture aims to nurture innovative companies by offering global resources and leveraging historical experience in the blockchain industry. Orbiter Finance also maintains an openness to incorporating additional networks. It has established strategic partnerships with key players such as Arbitrum, Optimism, Polygon, Linea, zkSync, Base, Starknet, Scroll, Manta Network and others. In this manner, it has solidified its position in the ecosystem. Notably, the protocol announced a collaborative strategic partnership with Ingonyama earlier this month, taking a step forward in advancing ZKP acceleration. Ingonyama is a next-generation semiconductor company specializing in ZK-proof technology. With that, it is actively exploring the integration of ICICLE, a GPU library for zero-knowledge acceleration, into Orbiter's ZKP system through multiple meetings and code-sharing initiatives.  

news
Loading