Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Oct 12, 2023

Crypto.com Complies with UK FCA’s New Digital Asset Rules

Crypto.com Complies with UK FCA’s New Digital Asset RulesWhile some Asian crypto platforms are struggling to comply with the United Kingdom’s Financial Conduct Authority (FCA) regarding new marketing-related rules that took effect on October 8, Singapore’s Crypto.com has confirmed its successful compliance. The firm is registered as FORIS DAX UK LIMITED on the FCA website.Photo by Paul Fiedler on UnsplashContinuing support for UK customersAs a result, UK customers can continue to access Crypto.com’s products and services without disruption. The company emphasized its commitment to strengthening its platform and presence in the UK market. Crypto.com stated that it fully supports measures aimed at enhancing consumer safety and security in the cryptocurrency industry. The company also expressed its ongoing cooperation with UK and international regulators to foster consumer confidence in the crypto sector.Effective from October 8, the FCA’s updated guidelines mandate that all crypto firms marketing their services to UK consumers must register with the FCA and adhere to relevant standards concerning risk disclosures and marketing practices.Regulatory compliance challengesWhile Crypto.com has managed to remain compliant, that’s not the case for all large and well-known crypto platforms. The FCA recently expanded its scrutiny of digital currency exchanges by adding Huobi and KuCoin to its list of unapproved and unregistered firms.The FCA alerted clients to the fact that these service providers were offering various crypto services in the UK without obtaining regulatory approval. This development follows a recent warning from the FCA, which highlighted several other crypto-focused companies.Binance’s compliance difficulties2023 has seen global crypto platform Binance struggle with regulatory compliance in various markets worldwide. In some jurisdictions where it has either decided to withdraw from the market or been asked to leave, the firm has taken the approach of still maintaining exposure to that market by establishing a partnership with a locally registered firm.In the UK, Binance has partnered with Rebuildingsociety.com, a peer-to-peer lending platform. However, its local partner has fallen foul of the UK's FCA. On Tuesday, the UK regulator issued a notice clarifying that Rebuildingsociety.com was not authorized to “approve the content of any financial promotion for a Qualifying Cryptoasset for communication by an unauthorized person.”Dubai-headquartered crypto exchange Bybit is another crypto business that has struggled with the FCA's new regulatory requirements. Last month the exchange denied reports that it was preparing to leave the UK market due to the new strict marketing rules. The following week the exchange confirmed that it would be leaving the UK market, ahead of the introduction of the new crypto marketing regulations.Crypto.com had received registration approval from the FCA in August 2022. At the time, CEO Kris Marsazalek stated:“We are committed to the UK market and we look forward to developing our platform and presence in the UK further by expanding our offering to customers, while continuing to work with regulators.”In June, the firm acquired a Major Payment Institution (MPI) license in its home market of Singapore from the Monetary Authority of Singapore (MAS). Around the same timeframe, the firm received a minimum viable product (MVP) license from the Virtual Assets Regulatory Authority (VARA) in Dubai.

news
Policy & Regulation·

May 21, 2024

Chinese police bust 1.9 billion USDT banking operation

In a major crackdown, the Chengdu Public Security Bureau announced on May 15 the dismantling of an extensive underground banking network, resulting in the arrest of 193 suspects across China in an operation that unveiled illegal businesses using the U.S. dollar stablecoin, Tether (USDT).Photo by DrawKit Illustrations on UnsplashUnauthorized foreign exchange settlements These activities involved illicit transactions amounting to approximately 13.8 billion yuan ($1.9 billion). The investigation began in November 2022 when authorities detected suspicious activities involving underground banks in Chengdu’s Longquanyi district. In response, a specialized task force was formed, integrating experts from various police departments, including economic investigation, cyber security and legal affairs. This team uncovered unauthorized foreign exchange settlements that bypassed national regulations. On June 1 of last year, acting on instructions received from the Ministry of Public Security, the task force conducted coordinated raids in several major cities, such as Shanghai and Shenzhen. These efforts led to the capture of key figures in the criminal syndicate, involving the arrest of 25 suspects. Law enforcement seized numerous bank cards, payment instructions and other digital payment instruments tied to the illegal operations during these raids. A broader investigation across 26 provinces has resulted in 193 suspects being arrested. Using USDT to evade regulationFurther investigations revealed that since January 2021, the syndicate exploited its import and export business to facilitate illegal activities. By using USDT as a medium, they bypassed official foreign exchange channels to service clients needing to transfer funds internationally. Moreover, these operations were intricately linked to other illicit activities, including financial fraud and smuggling. In a related development, on May 13, BeInCrypto reported that the Chinese government arrested six individuals responsible for illicit crypto transactions worth $295 million. These arrests highlight the challenges and risks associated with cryptocurrency in unregulated environments. Additionally, the Hong Kong police recently apprehended three men at a currency exchange shop following a deceptive transaction involving Tether’s USDT. The suspects allegedly showed a customer ceremonial "hell money" before deceitfully persuading him to transfer about $128,073 worth of USDT, only to refuse the agreed-upon cash exchange afterward.  According to the South China Morning Post (SCMP), hell banknotes are a form of ceremonial paper money burned as an offering to ancestors or deities in traditional Chinese culture. Late last year, USDT was used by a gang of gold smugglers in Nepal, who received $16 million in the Tether stablecoin in exchange for the precious metal. A joint investigation carried out by the authorities in Nepal and China led to the arrest of two Chinese and 13 Nepalese nationals in connection with the illicit activity. Over the course of the weekend, it emerged that two Chinese nationals had been charged by the authorities in the United States with money laundering through Bahamas-based Deltec Bank. Deltec acts as the primary banker for Tether, prompting longstanding Tether critics to suggest illicit activity relative to the stablecoin issuer’s dealings with the bank. This series of arrests and discoveries underscores the ongoing efforts of Chinese authorities to clamp down on illegal cryptocurrency activities. The activity also poses problems for Tether in its efforts to maintain compliance and stamp out illicit use in the face of ever-increasing regulatory scrutiny worldwide.

news
Web3 & Enterprise·

Jun 02, 2023

Gemini Targets UAE Crypto License

Gemini Targets UAE Crypto LicenseGemini, the US-headquartered cryptocurrency exchange owned by the Winklevoss twins, has announced its intention to obtain a cryptocurrency service license in the United Arab Emirates (UAE). The move comes as the exchange seeks to navigate the perceived “hostility and lack of clarity” surrounding cryptocurrency regulations in the United States.In a blog post published on Wednesday, Gemini highlighted the growing interest in cryptocurrencies among UAE citizens and referred to positive interactions with UAE regulators as driving factors behind its pursuit of the license. The co-CEOs of Gemini, Cameron and Tyler Winklevoss, explained in an interview with The National that their decision was influenced by the challenges they faced with crypto regulation in the US. Gemini CEO Tyler Winklevoss expressed optimism about the regulatory environment in the UAE, stating:“We’ve been super encouraged with our conversations here with the regulators. There’s an effort to make the UAE a home and a hub for crypto and, most importantly, to enact thoughtful regulation that connects, that protects both consumers, but also a company’s ability to innovate.”Photo by Nextvoyage on PexelsAbu Dhabi or Dubai — or bothAs of now, the Winklevoss twins have not yet determined the specific location for Gemini’s operations in the UAE. They hinted that the exchange’s headquarters could be established in both Abu Dhabi and Dubai, reflecting the potential for growth and development in both cities.Gemini’s decision to pursue a crypto license in the UAE underscores the country’s growing importance in the cryptocurrency industry. With its efforts to create a favorable regulatory environment and attract crypto-related businesses, the UAE aims to position itself as a crypto hub while safeguarding the interests of both consumers and innovators.Discouraging US outlookAccording to Gemini’s Global State of Crypto Report, which provides insights into cryptocurrency adoption and usage, more than 35% of respondents surveyed in the UAE reported purchasing crypto. In contrast, only 20% of respondents in the United States said they had bought cryptocurrencies.The report also revealed that nearly 32% of non-crypto owners in the UAE expressed their intention to enter the market within the next year. Furthermore, 33% of UAE crypto holders indicated that they plan to use their digital assets for in-person purchases at physical retailers, a significantly higher percentage compared to the global average of 19%.Although still a US-headquartered business, Gemini has been turned off the US market more recently. The Winklevii twins have taken a similar stance to Coinbase’s Brian Armstrong and Ripple’s Brad Garlinghouse. Coinbase has expanded in Singapore, acquired digital asset licensing in Bermuda, and has the intention of establishing a presence in Abu Dhabi.Garlinghouse has matched Armstrong’s outspokenness in criticizing the regulatory approach to digital assets in the United States. Likewise, he has acted to place Ripple on an international footing, establishing a presence in Dubai. In April, Gemini announced the opening of an engineering center in India, together with plans to expand its base in Singapore.As Gemini proceeds with its application for the UAE crypto license, industry observers will be closely monitoring the development, anticipating the potential impact of this expansion on the exchange’s operations and the broader cryptocurrency landscape in the region.

news
Loading