Fun

OKX investigates multimillion account thefts after SIM swap attacks

News Feed - 2024-06-12 09:06:47

Zoltan Vardai11 hours agoOKX investigates multimillion account thefts after SIM swap attacksAccording to SlowMist, despite the two similar phishing incidents, OKX’s two-factor authentication mechanism was not the main vulnerability point.4530 Total views19 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksThe OKX cryptocurrency exchange and security partner SlowMist are investigating a multi-million dollar exploit that resulted in two stolen user accounts.


The investigation pertains to the theft of two OKX exchange accounts on June 9 through an SMS attack, also known as a SIM swap. This information was reported by Yu Xian, founder of SlowMist, in a post on X.“The SMS risk notification came from Hong Kong and a new API Key was created (with withdrawal and trading permissions, which is why we suspected a cross-trading intention before, but it seems that it can be ruled out now).”


While the amount stolen through the attack is unclear, Xian wrote that “millions of dollars of assets were stolen.”


Related:Crypto hacks soar to $19B in 13 years: Crystal Intelligence2FA was not the main issue behind the attack: SlowMist


While onchain security firm SlowMist is still investigating the hacker wallet and the underlying incidents, the exchange’s two-factor authentication (2FA) mechanisms may not be the main point of vulnerability.


In a June 9 X post, SlowMist founder Xian wrote:“I haven’t turned on a 2FA authenticator like Google Authenticator, but I’m not sure if this is the key point.”


Cointelegraph has approached OKX and SlowMist for comment.


OKX’s 2FA mechanism allowed the attackers to switch to a low-security verification method, which allowed them to whitelist withdrawal addresses via SMS verification, according to an analysis by Web3 security group Dilation Effect.


However, more sophisticated hackers have recently been bypassing 2FA verification methods. At the beginning of June, a Chinese trader lost $1 million to a scam that used a promotional Google Chrome plugin called Aggr. The plugin steals user cookies, which are used by hackers to bypass passwords and 2FA authentication.$3 billion stolen in hacks — Why are crypto crimes surging? Source:Cointelegraph


Related:Crypto hacks increase in 2024, but smart contracts are not to blamePhishing attacks are on the rise


Phishing attacks were on the rise in June after CoinGecko confirmed a data breach suffered by its third-party email management platform, GetResponse. The breach led to the attacker sending 23,723 phishing emails to victims.


Phishing attacks involve hackers aiming to steal sensitive information like crypto wallet private keys. Other phishing attacks, known as address poisoning scams, aim to trick investors into willingly sending funds to a fraudulent address similar to addresses they previously interacted with.


Private key and personal data leaks have become the biggest reason behind crypto-related hacks, as exploiters are targeting the lowest-hanging fruit.Crypto total losses by vulnerabilities. Source: Merkle Science


Over 55% of hacked digital assets were lost to private key leaks during 2023, according to Merkle Science’s 2024 HackHub report.


Magazine:Roaring Kitty’s GME shares hit $1B, BTC open interest soars, and other news: Hodler’s Digest, June 2–8# Cryptocurrencies# Altcoin# Phishing# Hackers# Hacks# DeFi# OKXAdd reaction

News Feed

BOJ ex-board member says another rate hike unlikely this year
Tom Mitchelhill7 hours agoBOJ ex-board member says another rate hike unlikely this yearThe Bank of Japan is unlikely to raise interest rates again for the rest of the year, but it’ll be a "toss up" whether th
Prashant Jha12 hours agoNima Capital goes dark after dumping 9M SYN tokens, community calls it VC rugThe VC firm had received a grant from the project in return for locking $40 million worth of liquidity in SYN.2719 Tota
Food and Cash Shortages Push Cubans Toward Permissionless Cryptocurrencies
Food and Cash Shortages Push Cubans Toward Permissionless CryptocurrenciesThe Nation of Cuba is dealing with a national food crisis, as Venezuela has stopped offering aid to the sma
NFTICALLY Announces COMEARTH, the Leading E-Commerce Metaverse Ecosystem
NFTICALLY Announces COMEARTH, the Leading E-Commerce Metaverse Ecosystem sponsored NFTICALLY, a Web3 E-Commerce SaaS platform that powers over 9,000 NFT Marketplaces & Storefronts g
Eligma Raises Additional €4 Million Equity Investment at €50 Million Valuation
Eligma Raises Additional €4 Million Equity Investment at €50 Million Valuation PRESS RELEASE. Crypto payments startup Eligma has announced it recently comple
Here’s What Happens When You Use Lightning Network for the First Time
Here’s What Happens When You Use Lightning Network for the First Time Do you remember receiving your first bitcoin? Seeing those satoshis arrive in your wallet is a magical, al
Bitcoin, Ethereum Technical Analysis: ETH, BTC Surge Over 10% as Big 2 Lead Crypto Rebound
Bitcoin, Ethereum Technical Analysis: ETH, BTC Surge Over 10% as Big 2 Lead Crypto Rebound As LUNA’s life support was all but switched off on Friday, BTC and ETH rallied, wi
Shopping․io Is Building the First Ever Metaverse Shopping Center
Shopping․io Is Building the First Ever Metaverse Shopping Center sponsored Shopping․io, the very first E-commerce platform that allows users to purchase from major hubs usi
How Many Women Users Before Crypto Is Not Sexist?
How Many Women Users Before Crypto Is Not Sexist? A recent headline on Micky — an iconoclastic media outlet that focuses on cryptocurrency — read “Crypto Twitte
Trump's RNC speech gave tech enthusiasts hope for the future
Christopher Koopman1 hour agoTrump"s RNC speech gave tech enthusiasts hope for the futureResidents of Silicon Valley have been boarding the Trump train, and Trump"s speech at the RNC illustrated some of the reasons.381 T
Free TON Community Achieves Sufficient Decentralization With the Network Becoming a Defacto Mainnet
Free TON Community Achieves Sufficient Decentralization With the Network Becoming a Defacto Mainnet The Free TON community declares achieving sufficient decentra
Binance and Paxos-Backed Stablecoin BUSD’s Market Cap Climbs 22% in 2 Months
Binance and Paxos-Backed Stablecoin BUSD"s Market Cap Climbs 22% in 2 Months In mid-August, or 68 days ago, the market capitalization of the stablecoin BUSD was approximately $17.7