Top

Hot Wallet Exploit Results in $23M Bitrue Loss

Web3 & Enterprise·April 19, 2023, 3:34 AM

Bitrue, a Singapore-based crypto exchange, has fallen prey to a $23 million hack due to a hot wallet exploit. The exchange has been forced to suspend all withdrawals until April 18, to provide an opportunity to conduct a thorough security review.

wallet with 20 USD bills in cash
©Pexels/Karolina Grabowska

 

Hot wallet vulnerability

Hot wallets are used by exchanges to store small amounts of cryptocurrencies for easy access. These wallets are connected to the internet and are therefore more vulnerable to attacks compared to cold wallets, which are stored offline. In the case of Bitrue, hackers were able to exploit the hot wallet and steal cryptocurrencies worth $23 million.

In a series of Twitter posts, the exchange outlined that the exploit occurred at 07:18 (UTC) on Friday. “We were able to address the matter quickly and prevented the further exploit of funds”, it went on to state.

The stolen digital assets include ETH, QNT, GALA, SHIB, HOT and MATIC. Bitrue outlined that the hot wallet funds account for only 5% of overall funds and that the rest of its wallets remain secure and have not been compromised.

Blockchain security firm PeckShield outlined how the funds were swapped and drained. A wallet it has labeled as “Bitrue drainer” swapped 173,000 QNT, 22.55 billion SHIB tokens, 46.4 million GALA and 310,000 MATIC for 8,540 ETH. The ether is now being held within the following address:

0x1819EDe3B8411EbC613F3603813Bf42aE09bA5A5

 

Reimbursing users

In response to the hack, Bitrue has promised to reimburse all affected users. However, the process could take some time.

The incident underscores the importance of taking precautions when storing cryptocurrencies on exchanges. Users should only keep a minimal amount of cryptocurrencies on an exchange and should not store more than they can afford to lose. Ongoing exploits, hacks and frauds exemplify the need for users to only use reputable platforms with a proven track record of security.

 

Doubling down on security

Bitrue has promised to improve its security measures to prevent similar incidents from occurring in the future. The exchange’s response to the hack has been lauded by many in the cryptocurrency community, who have praised the company’s transparency and commitment to reimbursing affected users.

The cryptocurrency community has been vocal in its criticism of exchanges that fail to prioritize security. The Bitrue hack is just the latest in a series of incidents that have highlighted the importance of maintaining security in the world of cryptocurrency.

It’s not the first security breach that the exchange has encountered. In 2019 Bitrue suffered a $4.7 million loss, with quantities of both XRP and Cardano (ADA) having been stolen. On that occasion, the exchange released tracking details relative to the stolen funds. Thanks to collaboration with Huobi, Bittrex and ChangeNOW, the funds and associated accounts were frozen.

According to data from CoinGecko, Bitrue trades an average of $1 billion in digital assets daily, with bitcoin and ether trading pairs accounting for a large proportion of that trading volume. The Bitrue hack has been a wake-up call for the cryptocurrency community and serves as a reminder of the ongoing risks associated with storing cryptocurrencies on exchanges.

More to Read
View All
Policy & Regulation·

Apr 10, 2023

The Philippines Forging Crypto Reg. Path US Could Learn From

The Philippines Forging Crypto Reg. Path US Could Learn FromThe Philippines has demonstrated best practice in operating a sensible regulatory framework relative to cryptocurrency while the United States has erred by engaging in regulation via enforcement while responding after the horse has bolted in relation to a string of crypto company collapses. That’s according to Robert De Guzman, Head of Legal Compliance at Philippines-based cryptocurrency exchange Coins.ph.©Unsplash/C BuezaIn an opinion piece published in Forkcast News on Tuesday, De Guzman lays out his view as to what’s required in terms of regulation, while drawing comparisons between the application of regulation relative to crypto in both jurisdictions.The need for “sensible” regulationDe Guzman believes that the crypto industry’s recent failures are a wake-up call for the whole sector. Losses of billions of dollars affected Celsius Network, BlockFi, Voyager Digital, Genesis, and FTX, and led to Silvergate, Silicon Valley Bank (SVB), and Signature banks’ collapse in a week. To maintain consumers’ trust, he believes that sensible regulation is necessary for the crypto exchanges dealing with digital assets.The legal compliance expert cites the FTX collapse. FTX’s Sam Bankman-Fried’s empire was among the largest collapses. FTX pretended to support regulation, but its true nature was an offshore exchange for global clients. Nonetheless, some businesses act on their regulation support by acquiring licenses and complying with central bank audits in the countries of operation.State-level and industry-level regulationThe crypto industry being open to self regulation is one element of the solution, he says. Regulators must proactively protect their consumers from scams and business failures, not just clean up the mess after millions of people have been harmed.Regulatory failuresDe Guzman points the finger at reactionary regulatory action. Regulators filed charges against crypto industry founders after their collapse. Previously, they missed the problems of the largest companies. FTX, based in the Bahamas, was mismanaged, and American regulators only responded after customer issues. Regulations by enforcement, preferred in several countries, wait for failure to happen before taking action. Over-regulation through enforcement pushes platforms offshore, where Wild West-type environments thrive, with clear consequences.Regulators in some countries focus on surface-level questions, like which tokens should be considered securities, while others, like in the Philippines, prioritize execution-level details to protect consumers. Anti-money laundering measures and custody are core issues, with the G-7’s Financial Action Task Force’s Travel Rule likely to be more strictly applied. Active regulation and audits are needed to ensure financial platforms act responsibly with customer deposits. Basic rules need to be put in place through a licensing regime, followed by regulation of market practices like commingling of assets, self-dealing, and trading against customers.The Philippines sensible approach to regulationThe Coins.ph legal guru holds out his home country as exemplary in terms of its approach to regulation. The Philippines’ regulatory regime requires a virtual asset service provider (VASP) license to operate a crypto exchange, as well as additional licenses for other services. The country’s central bank, BSP, directly regulates all crypto exchanges and expands its crypto regulations to adapt to market needs. KYC processes in the Philippines require recognition of valid ID documents from across 82 provinces.Additionally, the BSP expects the industry to cooperate in quarterly audits where they share balance sheet information and disclose digital assets in hot and cold wallets. Regulators in the Philippines are proactive and knowledgeable about the crypto space, which sets a sensible framework based on customer protection.

news
Markets·

Mar 25, 2024

South Korean crypto-only exchanges on the brink of closure

Several South Korean crypto-only exchanges have long been struggling to keep their business afloat due to their prolonged weak performances. The local news outlet Etoday reported that the persistent underperformance of these local crypto exchanges is mounting pressure on their corporate operation and management, resulting in them shutting down their businesses. The situation hinders them from meeting the requirements set by the Financial Intelligence Unit (FIU) of the Financial Services Commission (FSC).  Their inability to generate sufficient revenue, due to faltering token trading volumes, makes complying with the FIU guidelines a daunting task.Photo by Anne Nygård on UnsplashCascading closure of crypto exchanges According to crypto industry insiders, local crypto-only exchanges including Cashierest, Coinbit, Huobi Korea, Probit and Tennten have announced their service closure as early as the second half of last year. On Nov. 6, Cashierest announced it was shutting down its services, with Coinbit following suit in the same month. The cascading closure announcements from crypto exchanges raised concerns about their potential harm on investors.  In an effort to protect crypto investors, the FIU has released a statement that local crypto exchanges are obliged to meet the requirements of the FIU in compliance with the Virtual Asset User Protection Act, despite their closing of services. Furthermore, the regulator said finalizing business closure requires due assessment by the FIU.  "Virtual asset service providers (VASPs) must notify their users of the closure and explain how to reclaim their assets at least one month before the business closing date. They must also support users to withdraw their assets for at least three months before closing," the FIU stated.  Struggling to meet FIU requirements However, some point out that it would be challenging for near-bankrupt crypto exchanges to run a customer service center for more than three months. Some exchanges allow users to deposit and withdraw their assets until their closure, as they would under normal conditions, but charge additional fees afterward. "It is very demanding to operate customer services when we're seeing no actual gains," one exchange official said.  It has been found that some crypto exchanges failed to register a change in their business state with the FIU, which is mandatory in the event of business location or contact changes, under the Financial Transaction Reports Act.  When Etoday reporters visited the offices of some of these crypto exchanges, they were met with empty rooms. One person who is familiar with the matter said, "The exchange has moved its office to another location and is scheduled to resume service in March." 

news
Web3 & Enterprise·

Mar 06, 2024

Nexo gets on regulatory ladder in Dubai with initial approval

Nexo DWTC, the Dubai arm of the well-known crypto lender, has obtained initial licensing approval from Dubai’s Virtual Assets Regulatory Authority (VARA), marking a significant milestone in the company’s growth and development.Photo by Carlos Alberto Gómez Iñiguez on UnsplashLending, borrowing and broker-dealer activitiesThe approval grants Nexo the authorization to engage in virtual asset lending and borrowing, management and investment relative to digital assets, together with broker-dealer activities within the region. Commenting on the development, Nexo Managing Partner, CFO and Co-Founder Kalin Metodiev, stated:”Nexo is enthusiastic about the pursuit of new market strategies aligned with the transformative guidance of Dubai's Virtual Asset Regulatory Authority." The United Arab Emirates (UAE) has played a pivotal role in promoting the region as a nucleus for global innovation and governance. Dubai's early adoption of blockchain strategies in 2016 and the establishment of VARA in 2022 underscore its commitment to emerging as a global epicenter for digital asset innovation. This initiative mirrors the city's longstanding influence in the traditional finance sector. Seven million worldwide usersFor Nexo, which caters to over 7 million users worldwide, the Dubai market represents a substantial opportunity for regional expansion and the delivery of premium services. Nexo is cementing its position as a leading digital assets institution. However, it hasn’t always been easy for the company. Amidst the broader cryptocurrency downturn post the 2021 market peak, Nexo faced significant challenges. In 2022 prominent crypto lenders faced bankruptcy, drawing heightened scrutiny towards Nexo given its involvement in similar business activities. This prompted speculations about the platform's sustainability. Additionally, Nexo grappled with regulatory pressures, notably agreeing to a $45 million settlement with the U.S. Securities and Exchange Commission (SEC) for failure to register the offer and sale of its Earn Interest Product (EIP). It also faced money laundering charges in its home base of Bulgaria. These charges were later dropped. Subsequently, the company pursued $3 billion in damages from the Bulgarian state, refuting allegations that brought disrepute to the company following an investigation that found no evidence against it. Reflective of a more positive outlook more recently, Nexo Co-Founder Antoni Trenchev took to CNBC on March 1, offering his prediction that Bitcoin is on target for a $100,000 unit price in the not-too-distant future. VARA, established in March 2022 following the enactment of Law No.4 of 2022, assumes the responsibility of regulating, supervising and overseeing virtual assets and virtual asset activities across all zones in the Emirate of Dubai, excluding the Dubai International Financial Centre. VARA's pivotal role in crafting an advanced legal framework is geared towards safeguarding investors, setting international standards for virtual asset industry governance and bolstering the vision of a borderless economy. Nexo's attainment of initial approval from VARA signifies a major breakthrough in its expansion efforts, underscoring its commitment to compliance and innovation in the digital asset space. This achievement positions the company as one of the few crypto lenders making inroads into the influential Dubai market. 

news
Loading