Fun

OKX investigates multimillion account thefts after SIM swap attacks

News Feed - 2024-06-12 09:06:47

Zoltan Vardai11 hours agoOKX investigates multimillion account thefts after SIM swap attacksAccording to SlowMist, despite the two similar phishing incidents, OKX’s two-factor authentication mechanism was not the main vulnerability point.4530 Total views19 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksThe OKX cryptocurrency exchange and security partner SlowMist are investigating a multi-million dollar exploit that resulted in two stolen user accounts.


The investigation pertains to the theft of two OKX exchange accounts on June 9 through an SMS attack, also known as a SIM swap. This information was reported by Yu Xian, founder of SlowMist, in a post on X.“The SMS risk notification came from Hong Kong and a new API Key was created (with withdrawal and trading permissions, which is why we suspected a cross-trading intention before, but it seems that it can be ruled out now).”


While the amount stolen through the attack is unclear, Xian wrote that “millions of dollars of assets were stolen.”


Related:Crypto hacks soar to $19B in 13 years: Crystal Intelligence2FA was not the main issue behind the attack: SlowMist


While onchain security firm SlowMist is still investigating the hacker wallet and the underlying incidents, the exchange’s two-factor authentication (2FA) mechanisms may not be the main point of vulnerability.


In a June 9 X post, SlowMist founder Xian wrote:“I haven’t turned on a 2FA authenticator like Google Authenticator, but I’m not sure if this is the key point.”


Cointelegraph has approached OKX and SlowMist for comment.


OKX’s 2FA mechanism allowed the attackers to switch to a low-security verification method, which allowed them to whitelist withdrawal addresses via SMS verification, according to an analysis by Web3 security group Dilation Effect.


However, more sophisticated hackers have recently been bypassing 2FA verification methods. At the beginning of June, a Chinese trader lost $1 million to a scam that used a promotional Google Chrome plugin called Aggr. The plugin steals user cookies, which are used by hackers to bypass passwords and 2FA authentication.$3 billion stolen in hacks — Why are crypto crimes surging? Source:Cointelegraph


Related:Crypto hacks increase in 2024, but smart contracts are not to blamePhishing attacks are on the rise


Phishing attacks were on the rise in June after CoinGecko confirmed a data breach suffered by its third-party email management platform, GetResponse. The breach led to the attacker sending 23,723 phishing emails to victims.


Phishing attacks involve hackers aiming to steal sensitive information like crypto wallet private keys. Other phishing attacks, known as address poisoning scams, aim to trick investors into willingly sending funds to a fraudulent address similar to addresses they previously interacted with.


Private key and personal data leaks have become the biggest reason behind crypto-related hacks, as exploiters are targeting the lowest-hanging fruit.Crypto total losses by vulnerabilities. Source: Merkle Science


Over 55% of hacked digital assets were lost to private key leaks during 2023, according to Merkle Science’s 2024 HackHub report.


Magazine:Roaring Kitty’s GME shares hit $1B, BTC open interest soars, and other news: Hodler’s Digest, June 2–8# Cryptocurrencies# Altcoin# Phishing# Hackers# Hacks# DeFi# OKXAdd reaction

News Feed

Arijit Sarkar1 hour agoBinance scouts art for Pierre Gasly’s F1 helmet at Abu Dhabi GPBinance announced a helmet design competition to shortlist the winning art, which will be used as the helmet artwork of Gasly, who w
State of Wisconsin reports $164M investments in spot Bitcoin ETFs
Turner Wright5 hours agoState of Wisconsin reports $164M investments in spot Bitcoin ETFsThe entity responsible for managing assets in the state’s pension system reported it held millions of shares of the BlackRock iSh
Tom Mitchelhill2 hours agoUS defense bill may be problematic for USDC and stablecoins: AnalystsA proposed U.S. national defense bill could subject stablecoins issuers to KYC and AML requirements they would be unable to c
Crypto Biz: SEC targets Robinhood, Grayscale’s Ethereum ETFs, and more
Ana Paula Pereira2 hours agoCrypto Biz: SEC targets Robinhood, Grayscale’s Ethereum ETFs, and moreThis week’s Crypto Biz features Robinhood’s Wells notice, Grayscale’s Ether ETF application, Coincheck’s merger
Stablecoin Savings: Circle Launches High Yield USDC Accounts for Businesses
Stablecoin Savings: Circle Launches High Yield USDC Accounts for Businesses Two years ago the cryptocurrency firm Circle announced the launch of USDC, a stableco
Zebedee Inks Deal With Mobile Game Studio Viker to Add BTC Rewards to Solitaire, Sudoku, Missing Letters
Zebedee Inks Deal With Mobile Game Studio Viker to Add BTC Rewards to Solitaire, Sudoku, Missing Letters Seven days after the financial technology and bitcoin payments firm Zebedee
Price analysis 4/19: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIB
Rakesh Upadhyay6 hours agoPrice analysis 4/19: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIBBitcoin remains stuck inside a range after traders aggressively purchased the dip, indicating solid demand at lower levels
Samsung to Aid Bank of Korea in Central Bank Digital Currency Pilot Program
Samsung to Aid Bank of Korea in Central Bank Digital Currency Pilot Program Samsung, the Korean tech giant, has decided to participate in a central bank digital
Alleged Hydra Administrator Refuses to Provide Access to His Crypto Wallet, Report Claims
Alleged Hydra Administrator Refuses to Provide Access to His Crypto Wallet, Report Claims A Moscow court has ordered the seizure of the crypto wallet of one of the alleged administ
ZachXBT claims 21 North Korea crypto devs are making $500K a month
Stephen Katte7 hours agoZachXBT claims 21 North Korea crypto devs are making $500K a monthOnchain sleuth ZachXBT claims to have found a network of North Korean developers who have been working on dozens of crypto project
Bitcoin Price Poised for ‘Imminent’ Breakout As Network Hashrate Hits Record Highs
Bitcoin Price Poised for "Imminent" Breakout As Network Hashrate Hits Record HighsThe price of bitcoin could see an ‘imminent’ breakout, according to the latest Glassnod
Elon Musk: Recession Will Be Greatly Amplified if the Fed Raises Rates Next Week
Elon Musk: Recession Will Be Greatly Amplified if the Fed Raises Rates Next Week Billionaire Elon Musk, the CEO of Tesla and Spacex, has warned that the recession will be “gr