Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Nov 21, 2023

Foblgate adds Bithumb Burrito Wallet as newest registrable external wallet

Foblgate adds Bithumb Burrito Wallet as newest registrable external walletSouth Korean cryptocurrency exchange Foblgate announced on Tuesday (local time) that it now allows users to register Bithumb Burrito Wallet — a Web3 digital wallet operated by Bithumb subsidiary Rotonda — as one of the external wallets that can be used for managing and trading crypto assets on their Foblgate account.Photo by Shubham’s Web3 on UnsplashRegulatory requirementsIn accordance with the Travel Rule under the Act on Reporting and Using Specified Financial Transaction Information, any given user who wants to transfer cryptocurrencies worth more than KRW 1 million (approximately $775) via a personal wallet must register that wallet beforehand. The Travel Rule refers to the Financial Action Task Force’s (FATF) Recommendation #16, which outlines that VASPs must share certain personal information about customers — including names and account numbers — when facilitating crypto transactions that exceed a certain amount. This is aimed at preventing money laundering and other illicit activities.Broadening external wallet supportFoblgate currently supports a number of other external wallets including MetaMask, Blockchain.com, MyEtherWallet and Klip. With the addition of Burrito Wallet, users now have a wider range of options for storing and trading their assets.“We will continue to support external wallets to enhance user convenience,” said Foblgate CEO Ahn Hyun-joon. “We vow to continue our efforts to meet the various needs of our users and provide a safe and convenient environment for carrying out transactions.”The exchange has published a guide for how to register and authenticate external wallets — including Burrito Wallet — on its official website.

news
Policy & Regulation·

Jul 04, 2023

Thai SEC Implements Measures to Protect Crypto Investors

Thai SEC Implements Measures to Protect Crypto InvestorsIn response to the crypto lending crisis that unfolded in 2022, prompting companies like BlockFi and Celsius to declare bankruptcy, Thailand’s Securities and Exchange Commission (SEC) has introduced new regulations aimed at safeguarding investors in the digital assets space.Photo by Jakob Owens on UnsplashDisclosing risk warningsThe guidelines, issued on Monday, require digital asset service providers to provide comprehensive warnings that emphasize the risks associated with cryptocurrency trading. All platforms must prominently display a message stating: “Cryptocurrencies are high risk. Please study and understand the risks of cryptocurrencies thoroughly, because you may lose the entire investment amount.” Prior to utilizing the service, users must consent to and acknowledge the risks.Crypto lending prohibitionIn addition to the risk disclaimer, the new guidelines explicitly forbid service providers from using customer funds for lending or investment purposes. This ban on crypto lending services prevents platforms from offering any returns on deposited crypto to customers. By implementing these measures, the Thai SEC aims to enhance investor protection and shield investors from the risks posed by lending services. The regulations are scheduled to take effect at the end of the month.Today’s guidelines are the product of months of deliberation. Discussions surrounding investor protection regulations commenced on September 1, 2022, when the SEC acknowledged the necessity for security warnings by cryptocurrency businesses to disclose the risks associated with trading digital assets. The prohibition on digital asset operators offering deposit-taking and lending services was deliberated during meetings held on December 1, 2022, and May 11, 2023.Response to crypto platform failuresThe introduction of these investor protection rules follows a significant crisis in the crypto lending sector that unfolded during the bear market of 2022. Several crypto lending firms, which had collected billions of dollars in customer deposits by promising substantial returns, collapsed during this period. Prominent lending companies such as Celsius and BlockFi filed for bankruptcy, resulting in investors’ funds being trapped in lengthy bankruptcy proceedings.The Thai SEC’s proactive approach in implementing these regulations reflects the growing concern for investor welfare within the cryptocurrency industry. By requiring clearer risk disclosures and prohibiting the use of customer assets for lending and investment, the SEC aims to instill greater confidence and transparency in the digital asset service sector.Crypto academyThailand’s SEC has run other initiatives in efforts to better protect investors. In January the Commission launched the SEC Crypto Academy, an e-learning course. The objective of that initiative was to provide investors with a basic understanding of the digital assets space prior to investing. At the time of the launch of the course, the SEC said that “the more you know your investments, the less risk you will have.”These latest regulations not only serve as a protective measure for Thai investors but also set an example for other jurisdictions to evaluate and enhance their own regulatory frameworks. As the crypto industry continues to evolve, prioritizing investor protection becomes crucial in fostering a more sustainable and responsible ecosystem.

news
Web3 & Enterprise·

Nov 09, 2023

Hana Securities chooses Itcen and INF Consulting as security token platform developers

Hana Securities chooses Itcen and INF Consulting as security token platform developersSouth Korea’s major securities company, Hana Securities, has recently chosen Itcen and INF Consulting to spearhead the development of its security token offering (STO) platform. After initial discussions in July about the project, the decision to bring these main partners on board is set to accelerate the launch of Hana Securities’ STO operations.Photo by Dave Weatherall on UnsplashComprehensive STO platformItcen and INF Consulting offer a spectrum of services from conceptualizing to building platforms. Hana Securities, in collaboration with these key partners, aims to create a comprehensive platform that manages the entire lifecycle of security tokens, encompassing everything from their issuance to circulation, by the latter half of next year. Following this development, the securities company intends to create an environment that allows various asset holders to issue security tokens. Hana Securities is also poised to orchestrate the development of the broader security token ecosystem.Choi Won-young, Head of Digital Division at Hana Securities, has expressed the firm’s commitment to the seamless development of an STO market. He mentioned that Hana Securities will engage in a range of activities, including platform development, to establish itself as a frontrunner in the STO space. The company plans to engage in dialogue with various businesses to explore collaborative opportunities that promise mutual growth.Expanding collaborative networkIn its pursuit to shape the STO market, Hana Securities has expanded its collaborative network by partnering with several entities, including Oasis Business, a prop fintech startup; Print Bakery, an art-centric platform; and Danal Entertainment, a distributor of digital content. These collaborations are centered around fractional investments and the creation of security tokens backed by diverse assets, including real estate, art pieces, precious metals like gold and silver as well as mobile content. Additionally, Hana Securities is a participant in the Next Finance Initiative (NFI) consortium alongside Mirae Asset Securities and SK Telecom via the Hana Financial Group. This alliance aims to solidify the STO market’s foundation and advance STO-related ventures.In line with this development, Hana Securities also forged a partnership with Finakle, a prop-tech enterprise that runs Rebit, a platform enabling fractional investments in commercial properties. Through this partnership, Hana Securities will manage accounts for transactions and aims to further this cooperation to refine business models going forward. Finakle, on its part, will concentrate its efforts on creating products and platforms for the issuance of security tokens tied to commercial real estate.Speaking on the joint initiative, Hana Securities’ Choi highlighted the company’s plans to widen their cooperative ventures with Finakle. This strategy is aimed at developing an array of business models and enriching the pool of commercial real estate investment options available to clients.

news
Loading