Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Oct 10, 2023

HTX Hacker Returns Funds

HTX Hacker Returns FundsThe hacker responsible for the nearly 5,000 ETH exploit on the Seychelles-headquartered cryptocurrency exchange HTX (formerly known as Huobi) last month has decided to return the stolen funds.Towards the end of last month, the exchange fell victim to a hack, resulting in a loss estimated at around $8 million. According to on-chain data, the hacker has repatriated the pilfered cryptocurrency, marking a significant development in the aftermath of the cyberattack.Photo by Shubham Dhage on UnsplashHacker rewardedThe returned funds were sent back in two separate transactions, one consisting of approximately 4,000 ETH and the other totaling around 1,000 ETH. HTX advisor and Tron Founder, Justin Sun, took to X (formerly Twitter) to officially confirm the recovery. In his statement, Sun revealed that HTX had not only received all the stolen funds as promised by the hacker but had also extended a gesture of goodwill. HTX rewarded the responsible party with a “white hat bonus” amounting to 250 ETH, equivalent to a substantial $400,000.Sun expressed his satisfaction with the hacker’s decision, stating:“We have confirmed that the hacker has fully returned all funds, as promised, and we have also paid the hacker a white hat bonus of 250 ETH. The hacker made the right choice. We would like to express our gratitude to everyone in the industry for their help.”Hacker advisory messageDuring the return of the funds, the hacker conveyed a message on-chain, shedding light on the reason behind this act of restitution. The message read:“Received your message. White hat bonus to0x1Fc8674A51D6b97C968BE384337519CE7003152B. Your system hot wallet private key leak, you should change system hot wallet address and reduce the system hot wallet rate.”HTX, in response to the hacker’s decision to return the funds and in accordance with its commitment, promptly sent the white hat bonus to the specified address. The exchange also requested the hacker to provide a detailed security vulnerability analysis report to the email address htxsafe@htx-inc.com.This request aims to prevent similar incidents in the future, with assurances that the hacker’s privacy will be safeguarded.Justin Sun had confirmed the original hack in September, at the time reassuring the community that HTX had covered all losses arising from the attack and resolved associated issues satisfactorily.While acknowledging the severity of the hack, Sun pointed out that the stolen amount represented a relatively small fraction of the $3 billion in assets held by HTX’s users. To incentivize the return of the funds, HTX had even offered a reward of 5%, which equated to $400,000.However, Sun also emphasized that if the funds had not been returned within a seven-day window, the company would have been compelled to involve law enforcement authorities.Thankfully, it did not come to that, and the cryptocurrency exchange can now move forward with the confidence that its users’ assets are secure. This incident highlights the importance of cooperation and ethical choices within the crypto community, as well as the potential for resolution even in the face of cyberattacks.

news
Markets·

Dec 01, 2023

Coinone’s recent addition of USDT/KRW trading pair expected to reduce Kimchi premium

Coinone’s recent addition of USDT/KRW trading pair expected to reduce Kimchi premiumCoinone, a major South Korean cryptocurrency exchange, listed USDT, a stablecoin pegged to the US dollar on the platform’s Korean won-denominated market on Thursday (local time). Its listing price was KRW 1,289.Tether Limited, the company behind USDT, asserts that their stablecoin is “backed 100% by Tether’s reserves.” These reserves comprise a variety of real-world assets such as U.S. Treasuries, overnight reverse repurchase agreements, corporate bonds and precious metals. According to CoinMarketCap, USDT’s market capitalization stands at $89 billion, ranking it third in the cryptocurrency market, just behind Bitcoin and Ethereum.Photo by DrawKit Illustrations on UnsplashFirst to list USDT/KRW trading pairDespite the significance of USDT in the cryptocurrency market, Korean exchange users have faced the limitation of not being able to purchase the stablecoin using Korean won, although these exchanges did offer markets denominated in USDT. This limitation has prompted Koreans to turn to foreign cryptocurrency services for acquiring USDT. With Coinone’s latest move, the platform has become the first to facilitate USDT/KRW trading among the nation’s five fiat-to-crypto Korean exchanges — Upbit, Bithumb, Coinone, Korbit and Gopax.Regarding this development, Kwon O-hoon, Managing Partner at the law firm Cha and Kwon, told local news outlet Decenter that there seem to be no particular legal concerns with the crypto exchange’s engagement in USDT transactions. This perspective stems from the absence of stablecoin regulations in the country.Reducing the Kimchi premiumAccording to Decenter, crypto experts anticipate that the introduction of USDT/KRW trading will help in reducing the Kimchi premium, a term referring to the discrepancy in cryptocurrency prices on South Korean exchanges compared to those in foreign exchanges.For instance, according to data from CoinNess, the average price of BTC on Korean exchanges is around KRW 51,177,250. This is about 2.34% higher than its average price on foreign exchanges, which stands at KRW 50,005,909. This difference means that users on Korean exchanges need to pay an additional KRW 1,171,340 to buy one BTC, compared to what they would pay on international platforms.However, the newly added trading pair will streamline transactions between exchanges, making it simpler for investors to engage in arbitrage. This ease of transfer is expected to lead to more balanced pricing across different markets, reducing the Kimchi premium.In light of this development, Jo Dong-hyeon, CEO of blockchain company Undefined Labs, said various institutions and blockchain projects will likely find USDT increasingly useful as a store of value, given USDT facilitates easy transfers between different exchanges.

news
Web3 & Enterprise·

Oct 05, 2023

Bithumb Eliminates Trading Fees to Attract Investors and Gain Greater Market Share

Bithumb Eliminates Trading Fees to Attract Investors and Gain Greater Market ShareSouth Korean cryptocurrency exchange Bithumb has waived trading fees for all cryptocurrencies available on its platform. Before this change, users were charged trading fees ranging from 0.04% to 0.25%.Photo by Nicholas Cappello on UnsplashKorean won and BTC marketsThe platform’s Korean won market offers trade for 241 cryptocurrencies, whereas its BTC market caters to 24. The no-fee policy will remain in effect until a further announcement is made.Many suggest this move by Bithumb aims to expand its domestic market share. According to local media outlet ZDNet Korea, Upbit dominates with 86% of the Korean crypto market, leaving Bithumb trailing with 11%.Revenue impact and long-term strategyWith its 10th anniversary approaching in January, Bithumb has made this decision, potentially to attract more investors. An official from the exchange highlighted the importance of attracting investors to secure liquidity. While the absence of trading fees, Bithumb’s main revenue channel, may result in a revenue dip, the official believes that a larger user base secured by this move will be beneficial in the long run.

news
Loading