Fun

OKX investigates multimillion account thefts after SIM swap attacks

News Feed - 2024-06-12 09:06:47

Zoltan Vardai11 hours agoOKX investigates multimillion account thefts after SIM swap attacksAccording to SlowMist, despite the two similar phishing incidents, OKX’s two-factor authentication mechanism was not the main vulnerability point.4530 Total views19 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksThe OKX cryptocurrency exchange and security partner SlowMist are investigating a multi-million dollar exploit that resulted in two stolen user accounts.


The investigation pertains to the theft of two OKX exchange accounts on June 9 through an SMS attack, also known as a SIM swap. This information was reported by Yu Xian, founder of SlowMist, in a post on X.“The SMS risk notification came from Hong Kong and a new API Key was created (with withdrawal and trading permissions, which is why we suspected a cross-trading intention before, but it seems that it can be ruled out now).”


While the amount stolen through the attack is unclear, Xian wrote that “millions of dollars of assets were stolen.”


Related:Crypto hacks soar to $19B in 13 years: Crystal Intelligence2FA was not the main issue behind the attack: SlowMist


While onchain security firm SlowMist is still investigating the hacker wallet and the underlying incidents, the exchange’s two-factor authentication (2FA) mechanisms may not be the main point of vulnerability.


In a June 9 X post, SlowMist founder Xian wrote:“I haven’t turned on a 2FA authenticator like Google Authenticator, but I’m not sure if this is the key point.”


Cointelegraph has approached OKX and SlowMist for comment.


OKX’s 2FA mechanism allowed the attackers to switch to a low-security verification method, which allowed them to whitelist withdrawal addresses via SMS verification, according to an analysis by Web3 security group Dilation Effect.


However, more sophisticated hackers have recently been bypassing 2FA verification methods. At the beginning of June, a Chinese trader lost $1 million to a scam that used a promotional Google Chrome plugin called Aggr. The plugin steals user cookies, which are used by hackers to bypass passwords and 2FA authentication.$3 billion stolen in hacks — Why are crypto crimes surging? Source:Cointelegraph


Related:Crypto hacks increase in 2024, but smart contracts are not to blamePhishing attacks are on the rise


Phishing attacks were on the rise in June after CoinGecko confirmed a data breach suffered by its third-party email management platform, GetResponse. The breach led to the attacker sending 23,723 phishing emails to victims.


Phishing attacks involve hackers aiming to steal sensitive information like crypto wallet private keys. Other phishing attacks, known as address poisoning scams, aim to trick investors into willingly sending funds to a fraudulent address similar to addresses they previously interacted with.


Private key and personal data leaks have become the biggest reason behind crypto-related hacks, as exploiters are targeting the lowest-hanging fruit.Crypto total losses by vulnerabilities. Source: Merkle Science


Over 55% of hacked digital assets were lost to private key leaks during 2023, according to Merkle Science’s 2024 HackHub report.


Magazine:Roaring Kitty’s GME shares hit $1B, BTC open interest soars, and other news: Hodler’s Digest, June 2–8# Cryptocurrencies# Altcoin# Phishing# Hackers# Hacks# DeFi# OKXAdd reaction

News Feed

William Suberg13 hours agoBitcoin price can go ‘full bull’ next month if 200-week trendline staysBitcoin and crypto are in line for a classic breakout should multiple time-tested patterns continue, says analyst Cole
Bitcoin.com Exchange to List Aspire and Aspire Gas as Newest Digital Asset Creation Platform Comes to Market 
Bitcoin.com Exchange to List Aspire and Aspire Gas as Newest Digital Asset Creation Platform Comes to Market Aspire (ASP) is the first digital asset creation platform to resist bot
Brian Quarmby3 hours agoX ‘everything app’ push continues as Elon Musk tests video game streamingDuring his stream, Elon Musk said that X has plans to integrate streaming services with Xbox and PS5 but has no plans o
Acclaimed NFT Artist’s Blockchain-Backed Digital Art Auction Raises $3.5 Million
Acclaimed NFT Artist"s Blockchain-Backed Digital Art Auction Raises $3.5 Million Blockchain-backed digital art is continuing to make waves and this week an artis
T-Rex files for ‘ghost pepper’ 2X leveraged MicroStrategy ETF
Tom Mitchelhill3 hours agoT-Rex files for ‘ghost pepper’ 2X leveraged MicroStrategy ETFFinancial services firm T-Rex Group has applied for what could be the “most volatile ETF” ever seen in the United States.465
Amaka Nwaokocha11 hours agoReddit engineer shares strategy behind NFT onboarding at EthCCSpasova emphasized that the primary motivation behind running Collectible Avatars on-chain is to empower users with freedom of use.
Avalanche integrates with Stripe for fiat-to-crypto onboarding
Christopher Roark7 hours agoAvalanche integrates with Stripe for fiat-to-crypto onboardingAvalanche C-Chain users can now buy AVAX directly within Web3 apps by using a widget supplied by Stripe.3792 Total views3 Total sh
Dacxi Announces Global Tokenized Crowdfunding Solution – the Dacxi Chain
Dacxi Announces Global Tokenized Crowdfunding Solution - the Dacxi Chain press release PRESS RELEASE. Dacxi has announced theDacxi Chain – the world’s first tokenized
Solana releases mainnet beta update v1.17.31 to resolve congestion issues
Prashant Jha20 minutes agoSolana releases mainnet beta update v1.17.31 to resolve congestion issuesThe Solana Foundation claimed ongoing network congestion could be attributed to the high demand for Solana block space an
Bitcoin Loophole: Wanna Make $13K in 24 Hours? This Crypto Trading App Is a Scam
Bitcoin Loophole: Wanna Make $13K in 24 Hours? This Crypto Trading App Is a ScamA bitcoin investment scheme claiming to help people make over $13,000 within 24 hours has recently ga
EigenLayer on the brink of potential yield crisis
Zoltan Vardai14 hours agoEigenLayer on the brink of potential yield crisisLiquid staking tokens on EigenLayer will require more utility in the decentralized finance space to avoid a potential yield crisis in the future.1
Founder of World’s Largest Hedge Fund Ray Dalio Sees Bitcoin as Gold Alternative in Portfolios
Founder of World"s Largest Hedge Fund Ray Dalio Sees Bitcoin as Gold Alternative in Portfolios Billionaire hedge fund manager Ray Dalio, a long-time bitcoin skep