1. Home
  2. Cybersecurity

Cybersecurity

BingX confirms the resumption of withdrawal services following hack

Monetary losses from the BingX hack were initially reported as totaling $26 million, but the figure has since swelled to $52 million.

BingX — a popular cryptocurrency exchange — has announced that withdrawal services on the platform will resume on Sept. 21, 2024, for certain digital assets.

According to the exchange's announcement, withdrawals for Tether's US dollar stablecoin (USDT), Circle's US dollar stablecoin (USDC), Bitcoin (BTC), Ethereum (ETH), Tron (TRX), and Solana (SOL) will resume first followed by withdrawal services for other tokens and digital assets over the next two weeks.

The exchange notified customers that deposit services would likewise resume in the next several weeks and told clients that withdrawal requests submitted before the disruption of withdrawal services have been canceled and must be resubmitted.

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Making crypto mainstream requires greater efforts to stop fraud

One of the greatest use-cases of blockchain technologies is the ability to improve security and counter malicious actors, but we need to get serious about it.

We find it easy to talk about the benefits of the digital economy, whether the internet or digital assets, but the costs are often overlooked. Whether the surge in human trafficking that has emerged on social media platforms or the rise of cybersecurity vulnerabilities, the expansion of the digital economy comes with new risks to manage.

The digital asset community is no different and, to scale and become sustainable, it must confront the prevalence of fraud. And, it’s not hard: already distributed ledger technologies are demonstrating their value by solving concrete use-cases. This week in Vienna, Austria, the Austrian National Bank — together with the Complexity Science Hub and other sponsors — are hosting a conference on advances in financial technology, with a wide array of presenters who have researched value-enhancing uses of blockchain technology.

Thanks to pioneering work by the Federal Trade Commission’s Consumer Sentinel, we now have basic statistics on the incidence of fraud, the perpetrators, and the countries that exhibit the greatest violations. Using these data on complaints, Michel Grosz and Devesh Raval from the FTC show that it is possible to identify countries with excess levels of fraud based on their level of exports and to whom they are exporting. We need this caliber of data and the processes to support its collection to make strides in countering fraud.

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

US prosecutors oppose Mango Market exploiter’s motion for acquittal

Following the exploit, Eisenberg claimed he negotiated a settlement with Mango Markets' insurance fund to ensure users retained their money.

Prosecutors for the United States Southern District of New York (SDNY) filed a motion on Sept. 18 opposing Mango Markets exploiter Avraham Eisenberg's request for acquittal or a new trial.

According to the documents filed by SDNY attorneys, the jury correctly convicted Eisenberg by evaluating a "mountain of evidence" beginning with the prosecution's assertion that Mango perpetual swaps are subject to the Commodities Exchange Act.

The federal prosecutors stressed that Eisenberg's defense — arguing the fraud charges do not apply in the case because the defendant did not seek to manipulate the market price of the underlying asset — were materially incorrect and noted the jury instructions on price manipulation. Attorneys for the Southern District of New York asserted:

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Ethena domain registrar hacked, Ethena Labs warns users to stay away

The Ethena website appears to have suffered a front-end attack, and users are encouraged not to interact with the platform. 

The Ethena website suffered what appears to be a front-end exploit on Sept. 18, and Ethena Labs has cautioned users not to interact with any site or application claiming to be Ethena.

According to a social media post from Ethena Labs, the website's domain registrar account was compromised, and the site is currently deactivated until the issue is resolved.

Ethena Labs also reassured clients that the Ethena protocol was not affected by the exploit and that all customer funds were safe.

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Attacker drains $1.4M from CUT token pools via mysterious unverified contract

An account used an unreadable function to remove 1.4 million BSC-USD without needing to burn the equivalent LP tokens.

An attacker drained over $1.4 million worth of Bows Coin Synthetic US Dollar (BSC-USD) from a liquidity pool holding CUT tokens on Sept. 10, according to a report from blockchain security platform CertiK.

The CUT token contract relied on a separate, unverified contract to set its “future yield” parameter, and this separate contract was used to drain the BSC-USD through an unknown method.

CertiK reported the event on X.

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

New Android malware steals private keys from screenshots and images

According to a recent FBI warning, North Korean hackers are "aggressively targeting" the crypto industry with “well-disguised” attacks.

A new Android malware called SpyAgent, discovered by software security firm McAfee, can steal private keys stored in screenshots and images on a smartphone’s internal storage.

More specifically, the malware uses a mechanism known as optical character recognition (OCR) to scan images stored on a smartphone and extract words from them. OCR is present in many technologies, including desktop computers, which can recognize, copy, and paste text from images.

McAfee Labs explained that the malware is distributed through malicious links sent through text messages. The cybersecurity company broke down the process, beginning with an unsuspecting user clicking on a link they received.

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Hypernative Secures $16 Million in Series A Funding to Enhance Web3 Security

Hypernative Secures  Million in Series A Funding to Enhance Web3 SecurityHypernative has successfully secured $16 million in a Series A funding round spearheaded by Quantstamp, with other notable investors joining the fray. This new capital will be channeled into enhancing its artificial intelligence (AI)-driven security solutions tailored for the Web3 ecosystem. Hypernative Garners $16M Funding to Fortify Web3 Security With AI Solutions In a blog […]

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Critical bug identified and remedied in Circle’s Noble-CCTP

Blockchain security firm Asymmetric Research privately disclosed the vulnerability to Circle, which has since been addressed.

On Aug. 27, Asymmetric Research revealed it identified a critical bug in Circle’s Noble-CCTP, a component of the USDC (USDC) Cross-Chain Transfer Protocol, on the Cosmos network.

According to the Web3 security firm, a malicious actor could have potentially sidestepped the cross-chain transfer protocol’s message sender verification process to mint fake USDC tokens on the Noble bridge.

More specifically, the Noble-CCTP “ReceiveMessage” handler was accepting “BurnMessages” from any sender without first checking that the bridging message was sent from a verified “TokenMessenger” address on the original chain. The security firm outlined the vulnerability in greater detail:

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

Avalanche Discord Compromised—Fake Token Scammers Strike Again

Avalanche Discord Compromised—Fake Token Scammers Strike AgainFollowing the hack of the Polygon Discord server, Avalanche’s official X account (@avax) alerted the public that their Discord channel had also been breached. “SECURITY ALERT,” Avalanche announced. “The official Avalanche Discord has been compromised. Please do not interact with any accounts or click any links until further notice.” Just like the Polygon Discord breach […]

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin

WazirX slams external forces for delaying restructuring efforts

This restructuring plan is expected to provide greater clarity on the steps WazirX will take to stabilize its operations and protect its users’ interests.

Indian crypto exchange WazirX has criticized external forces that it claims are deliberately hindering its recovery efforts.

The criticism came after the exchange announced a comprehensive restructuring plan designed to restore financial stability and enhance the security of its users’ assets. 

In the public statement on X, WazirX criticized unnamed external parties for allegedly attempting to prolong the restructuring process. The exchange claimed that the entities are motivated by a desire to maintain uncertainty and complicate the resolution WazirX has been striving to achieve since it was hacked. 

Read more

MicroStrategy completes $3 billion convertible notes offering to buy more Bitcoin