Top

CoinGecko security breach latest threat within crypto space

Web3 & Enterprise·January 12, 2024, 1:51 AM

The crypto space continues to suffer a disproportionate share of hacks and scams that were further exacerbated on Wednesday, with Malaysian crypto data aggregator the latest to succumb to a security breach.

 

Serving as yet another stark reminder of the persistent threats plaguing the sector, a phishing scam targeted CoinGecko's X account, leading to a brief compromise that raised concerns about the safety of user information.

https://asset.coinness.com/en/news/665e08d0b2b6f1b715f8ec42a31003c6.webp
Photo by GuerrillaBuzz on Unsplash

Phishing scam

During this incident, hackers posted a phishing link on CoinGecko's X account, falsely advertising a token airdrop for a cryptocurrency named GCKO. The deceptive post claimed that GCKO could be used for API services, including the cryptocurrency ANKR. Swift action by CoinGecko involved the removal of the fraudulent post and a public warning urging users to avoid interacting with any suspicious links or content.

 

In an X post, CoinGecko wrote:

”Our Twitter accounts @CoinGecko and @GeckoTerminal have been compromised. We're taking immediate steps to investigate the situation and secure our accounts. Please DO NOT click on any links or engage with suspicious content. Your security is our top priority.”

 

Employee error

The firm followed up with an update on Thursday, attributing the breach to a team member inadvertently clicking on a fraudulent Calendly link, granting unauthorized access to the hacker.

 

Despite having two-factor authentication (2FA) enabled and employing robust security measures, CoinGecko emphasized that the inadvertent click allowed unauthorized access. The compromised accounts were then exploited to disseminate misleading information and potentially engage in malicious activities.

 

CoinGecko expressed sincere apologies for any confusion or inconvenience caused by the incident. The company reiterated its commitment to platform security and continuous improvement of internal controls, assuring users that corrective measures were promptly implemented.

 

SEC incompetence

CoinGecko's security incident occurred within 24 hours of a similar occurrence involving the U.S. Securities and Exchange Commission (SEC). The SEC's X account was compromised, with scammers posting a false message from Chair Gary Gensler about the approval of spot bitcoin exchange-traded funds (ETFs).

 

While CoinGecko identified a vulnerability in its security regimen, the SEC later confirmed that the breach in its case was far more basic. It was not due to infrastructure attacks but rather the lack of 2-factor authentication (2FA) tied to the SEC's account, the most basic form of operations security.

 

Gensler and the SEC have come in for major criticism from the crypto community in the U.S. due to a policy of regulation by enforcement that has been pursued. With that, the Commission came in for swift and harsh criticism in the immediate aftermath of its X account hack.

 

Many pointed out the irony of Gensler advising consumers to secure their accounts back in October when the SEC itself had failed to do so. Others queried who would be responsible for what some interpreted as an episode of market manipulation, something that the SEC has perennially associated the crypto markets with. During the time that the account was compromised, millions of dollars of value were liquidated in short and long trading positions.

 

CoinGecko's quick response serves as a valuable lesson in the importance of vigilance and proactive security measures amid the growing threats facing the cryptocurrency community.

More to Read
View All
Web3 & Enterprise·

Jun 15, 2023

More Players Join NH Bank-Led Security Token Consortium in South Korea

More Players Join NH Bank-Led Security Token Consortium in South KoreaMultiple South Korean banks and fractional investment firms are now joining the security token consortium led by NongHyup Bank (NH Bank), according to a report from local news outlet Etoday today.Expanding consortiumNH Bank announced today that the Industrial Bank of Korea, Shinhan Bank, and Woori Bank, along with fractional investment companies, will be participating in the banking sector’s security token consortium. This consortium was established in April and initially comprised NH Bank, Suhyup Bank, Jeonbuk Bank, and six fractional investment companies.The objective of the banking sector’s involvement in the consortium is to contribute to the security token industry by developing distributed ledger technology infrastructure, conducting research to promote security tokens, and strengthening investor protection.The consortium participants will engage in further discussions on how banks can participate in the security token market while adhering to evolving legislation related to security tokens. Additionally, they will explore methods to establish the necessary platforms required by fractional investment companies to issue security tokens.Photo by Mathieu Stern on UnsplashSecurity tokens as corporate bondsIn the long term, the group plans to issue security tokens as corporate bonds, taking inspiration from German tech company Siemens’ strategy, or create a secondary market for security tokens to promote the overall security token ecosystem. Earlier this year, Siemens issued a blockchain-based one-year bond worth 60 million euros ($64.9 million).The consortium’s new fractional investment firms include fractional real estate investment platform Funble, artificial intelligence entertainment firm Blade Ent, blockchain tech firm Trackchain, online bookstore Yes24’s fractional artwork ownership platform ARTiPIO, and electric vehicle (EV) charging sharing platform Charzin.

news
Web3 & Enterprise·

Oct 17, 2024

Hybrid exchange Cube lists Access Protocol (ACS)

CUBE, a hybrid crypto exchange that settles trades on-chain using secure multi-party computation, announced on its official X account that it has listed ACS, the native token of Solana-based monetization platform Access Protocol.  The hybrid exchange utilizes its custom rewards platform, Blocks, to engage users through unique packages for listing traders and token holders. Participants in the listing will be eligible for campaign rewards.  Bartosz Lipinski, CEO and co-founder at CUBE, recently revealed plans around Isometric (ISO), an intent-based transaction network, enabling cross-chain trading to eliminate the need for asset bridging.  “When we started building Cube, we wanted everything to be an intent… Everyone will be able to submit intents to the network and verify settlements on multiple chains using the decentralised MPC that we’ve built,” Lipinski said during his presentation at the Solana Breakpoint conference. “Through the decentralised MPC integration layer, you will be able to actually use the value on different layer ones without cannibalising it,” he went on to share.  ISO will be the platform token powering governance, staking, and decentralized custody, according to Cube's announcement. Both Token and Mainnet launch are expected to happen some time in Q2 2025.  In a related development on Monday, Cube announced its partnership with the Argentinian government. The company plans to explore leveraging the Isometric network as a catalyst for the South American nation’s financial system. 

news
Web3 & Enterprise·

Sep 06, 2023

Korbit Passes Post-Audit for ISMS-P and ISO Certifications

Korbit Passes Post-Audit for ISMS-P and ISO CertificationsSouth Korean crypto exchange Korbit announced on Wednesday that it has successfully passed a post-audit to maintain its Personal Information and Information Security Management System (ISMS-P) certification and four different International Organization for Standardization (ISO) certifications — ISO 27001, ISO 27017, ISO 27018, and ISO27701.“By maintaining our ISMS-P and ISO certifications this year, we were able to reaffirm the stability and trustworthiness of Korbit’s personal information protection capabilities and security management system,” said Oh Se-jin, CEO of Korbit.Photo by FLY:D on UnsplashRigorous criteriaThe ISMS-P is a security management system jointly operated by the Ministry of Science and ICT and the Personal Information Protection Commission, representing the highest level of security management in Korea. It combines 80 requirements for Information Security Management System (ISMS) certification and 22 requirements for Personal Information Management System (PIMS) certification, totaling 102 requirements that must be met. Once obtained, certification is valid for three years, and annual post-audits are required to maintain its validity.Korbit first obtained ISMS-P certification in September of 2021 and has once again passed this year’s post-audit that was conducted last Wednesday.Meeting international standardsIn addition, the exchange had previously passed post-audits for four ISO certifications related to information protection and personal information management systems earlier in June. This includes ISO 27001 for information security management systems, ISO 27017 for information security controls on cloud services, ISO 27018 for protection of personally identifiable information (PII) in public clouds, and ISO 27701 for privacy information management systems.This achievement demonstrates Korbit’s commitment to reliability and security when operating and managing exchange services.“As a crypto exchange, we will continually focus on strict security management to ensure the protection of customer information and assets,” said CEO Oh.

news
Loading