Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Jan 31, 2024

Japan works towards clearing legislative path for CBDC

Japan appears to be gearing up for the potential launch of its central bank digital currency (CBDC), the digital yen, as the government and the Bank of Japan (BoJ) collaboratively lay the legislative foundation for its rollout. While neither the BoJ nor the government has officially committed to the CBDC launch, recent developments indicate an accelerated push for its development. The BoJ's heightened focus on digital yen comes amidst concerns about falling behind China's and Europe's rapid progress in the CBDC space.Photo by Wenhao Ji on UnsplashOvercoming legal issuesAccording to a report by Japanese media outlet NHK, in a recent meeting, the Japanese government and the BoJ discussed future tasks and legal issues related to its CBDC implementation. To ensure a smooth and legally unobstructed launch, Tokyo aims to establish the necessary legal framework well in advance. Local news media Coinpost reported that the proposed legislation is set to "assume the introduction of the digital yen" and may involve amendments to key laws such as the Bank of Japan Act, the Criminal Code and the Civil Code. The goal is to finalize the list of required legal amendments by spring of the current year. In a meeting between Japan's central bank and the Finance Ministry, executives from relevant ministries and central bank directors explored various aspects of the CBDC. Discussions included the collaboration between a potential central bank digital currency and private cashless businesses, with a focus on convenience and personal data protection. Finance Ministry keen on launch ASAPLast month, the central bank received a report from a Ministry of Finance expert panel which recommended the launch of the digital yen without delay. The Ministry of Finance's December meeting addressed the division of roles between the Bank of Japan and intermediary banks, proposing a "two-tiered model" where domestic commercial banks play a pivotal role in digital yen issuance. Acting as intermediary institutions, these banks will bridge the gap between the central bank and digital yen users. The government and the BoJ are also contemplating ways to involve private businesses in the CBDC project while ensuring fair competition. Security and data privacy considerationsKey considerations in the discussions involve interoperability with other payment methods, ensuring security and handling user information safely. There is also an exploration of potential cross-border payment options. The government and the BoJ are committed to a comprehensive approach that considers various aspects of the CBDC project. Japan's unique context in the CBDC landscape is highlighted, with its continued reliance on cash and the presence of multiple private-sector tokenized money initiatives. Notably, the country boasts over 100 institutions and enterprises exploring digital currency through a digital currency forum since 2020. Separate initiatives, such as the MUFG-backed Progmat DLT platform, contribute to Japan's diverse digital currency landscape. Providing another example of progression in the digital assets arena, it emerged in September that the country is looking to permit startups to raise capital from venture capital firms using digital tokens rather than traditional equity. 

news
Web3 & Enterprise·

Sep 18, 2025

Credit Saison launches $50M blockchain fund, deepening push into emerging markets

Credit Saison, one of the largest credit card issuers in Japan, is accelerating its global venture strategy with the creation of Onigiri Capital, a new fund targeting early-stage startups building on blockchain technology. Set up in Singapore last month through Credit Saison’s corporate venture arm, Saison Capital, the vehicle is aiming for up to $50 million in commitments and will run for 10 years, with an optional two-year extension. The fund has already secured $35 million toward its target.Photo by Markus Winkler on UnsplashBuilding on a fintech track recordThe initiative is part of Credit Saison’s broader plan to expand in emerging markets and spur innovation in financial services, drawing on Saison Capital’s track record. Established in 2019, the venture arm has backed fintech startups across Asia and, since 2021, has increasingly focused on blockchain-based finance, investing in more than 40 companies. The firm said those investments laid the groundwork for Onigiri Capital, which will also enable other financial institutions to invest alongside Credit Saison in promising blockchain ventures. Onigiri Capital will concentrate on five areas: stablecoins, payments, asset tokenization, decentralized finance (DeFi), and financial infrastructure. The fund will invest primarily at the seed and early stages, with an emphasis on long-term growth. Managing the fund are Qin En Looi, a partner at Saison Capital involved in over 40 blockchain investments, and Hans de Back, a venture investor with more than two decades of experience. Cross-border stablecoin pilotThe launch comes as Japan steps up efforts in digital assets beyond investment alone. According to Electronic Times, the first phase of “Project Pax,” a cross-border stablecoin remittance pilot involving financial institutions in Japan and South Korea, concluded successfully last week. Participants were Progmat—a tokenization platform backed by a consortium of major institutions, including MUFG—along with Datachain and Shoko Chukin Bank from Japan, and Shinhan Bank, NH Nonghyup Bank, and Kbank from South Korea. Fair Square Lab and Korea Digital Asset Custody helped develop an application programming interface (API) for the trial. The pilot demonstrated the feasibility of a network that converts fiat currency into stablecoins for on-chain transfers and then back into local currency at the destination, an approach expected to reduce the time and cost of cross-border payments. The results add momentum to Japan’s bid to modernize financial infrastructure, a backdrop that Onigiri Capital aims to capitalize on as it deploys capital into the sector. 

news
Markets·

Jun 25, 2024

Nomura survey indicates shift towards crypto investment in Japan

Nomura Holdings, Japan's largest brokerage and investment banking company, along with its digital asset arm, Laser Digital, has unveiled a survey indicating a significant shift towards cryptocurrency investment among Japanese investment managers.  54% of investment managers favor cryptoThe survey, conducted in April with over 500 respondents, reveals that 54% of investment managers plan to invest in crypto assets within the next three years, aiming to stabilize their portfolios and mitigate risks through diversification and hedging against inflation. According to the survey, approximately 25% of respondents hold a positive impression of cryptocurrencies, particularly Bitcoin and Ether. Meanwhile, 62% view crypto assets as a viable diversification opportunity. Around half of those that responded indicated an interest in crypto exchange-traded funds (ETFs) while 31% are considering direct investment. This trend follows the Japanese cabinet's February approval of a proposal to include crypto in the list of assets that local investment limited partnerships can acquire or hold. Nomura anticipates a revision to the Limited Partnerships Act later this year to accommodate this change.Photo by Jezael Melgoza on UnsplashNew product development to drive demandThe survey also highlights the primary drivers for future investments in crypto assets. These include the development of a variety of financial products such as exchange-traded funds, investment trusts, staking, lending and other innovative offerings. These developments align with Japanese Prime Minister Fumio Kishida's "new capitalism" economic policy. Within that policy, Kishida outlined that fostering Web3 innovation is a key priority in a keynote address at the WebX conference in Tokyo in 2023. Metaplanet bond issuanceIn a related move, Tokyo-based investment and consulting firm Metaplanet plans to issue 1 billion yen ($6.26 million) worth of bonds to finance its Bitcoin acquisitions. The firm announced on June 24 that its board had approved the bond issuance, with the Bitcoin intended for long-term holding. A separate notice detailed that the bonds would offer an annual rate of 0.5%. Metaplanet appears to be following a business strategy first pioneered by MicroStrategy in the United States. The American business intelligence firm, now focused on Bitcoin development, holds the record for a public company with the most Bitcoin, possessing 226,331 BTC worth $15 billion. It provides an alternative means through which corporations can gain exposure to Bitcoin investment. Metaplanet is likely to fulfill a similar role within the Japanese market, meeting that developing investment need identified among Japanese investment managers in Nomura’s survey. While the Nomura survey findings are largely positive, there were a number of concerns expressed by investment managers also in relation to crypto. Among them were concerns about counterparty risk, regulatory requirements and high asset volatility. However, the report suggests that there is a path through which these concerns can be minimized. The report states: “These hurdles could soon be lowered, as Japan’s digital asset laws and regulations are rapidly being developed, enabling increased engagement from institutional investors in the future.” In December, the Japanese government approved a tax regime revision to exempt corporations from paying tax on unrealized crypto gains if they hold the assets long-term.

news
Loading