KuCoin September 2020 Hack: Hacken Research

2020-10-17 17:00

Last week, the hottest topic in the crypto markets was the KuCoin hack. Our team highly values the need for increasing user awareness of such threats, so beyond research into the specifics of the hack itself, we have also included recommendations on how to prevent similar situations in the future.

Background

On September 25, 2020, cryptocurrency exchange KuCoin was hacked. The estimated stolen cryptocurrency amount is more than $275 million in various cryptocurrencies.

On their official website, the KuCoin team explained that the hack was due to a leak of the KuCoin hot wallet private keys.

The following cryptocurrencies were stolen:

1,008 BTC; 14,713 BSV; 26,733 LTC; 9,588,383 XLM, Omni and EOS-based Tether (USDT) worth $14 million $153 million in Ether and ERC20s (11,542 ETH, 122 million VELO tokens (about $75.7 million), $1.2MM SNX, Silent Notary (SNTR), Covesting (COV), Orion Protocol (ORN), KardiaChain (KAI), NOIA Network (NOIA) and Opacity (OPQ)) + dozens of ERC-20 altcoins; Over 18,495,798 XRP. 

The Tether team was able to block all of the stolen USDT, which some consider is a good way to deal with cases of hacked or stolen coins. Thanks to Tether’s blocking, KuCoin has already been able to return funds equivalent to $64 million. However, Tether’s ability to block transactions has been seen by others as antithetical to the core values of cryptocurrencies, since blocking transactions exposes the centralization in the Tether protocol. Bitcoin transactions, on the other hand, cannot be blocked, 

The hacker made withdrawals from the KuCoin hot wallets to the following addresses: 

ETH: https://etherscan.io/address/0xeb31973e0febf3e3d7058234a5ebbae1ab4b8c23 BTC https://www.blockchain.com/btc/address/1TYyommJW3uhjhcnHhUSuTQFqSBAxBDPV
https://www.blockchain.com/btc/address/12FACbewf5Fy9nmeaLQtm6Ugo5WS8g2Hay LTC: https://live.blockcypher.com/ltc/address/LQtFoidy5TmLrPP77MZzgMRffqPsmRfMXE/ XRP: https://bithomp.com/explorer/r3mZvvHVLPtRWAujzBsAoXqH11jhwQZvzY BSV: https://blockchair.com/bitcoin-sv/address/15mC7zKbLyErSKzGRHpy6gyqS7GyRpWjEi XLM: https://stellarchain.io/address/GBM3PJWNB5VKNOFXCDTTNXPMUNBMYTLAAPYDIIKLHUGMKX7ZGN2FNGFU USDT: https://omniexplorer.info/address/1NRsEQRg5EjmJHbPUX7YADVPcPzCQBkyU7 TRX: https://tronscan.org/#/address/TB3j1gUXaLXXq2bstiSMfjQ9R7Yh9DdDgK

As we found out from the transactions, the hacker sold the stolen cryptocurrency from the above addresses on decentralized exchanges like Uniswap and anonymized the stolen cryptocurrencies through mixing services. A key advantage of Uniswap, a decentralized exchange, is that it enables users to retain full custody of their digital assets when exchanging them. However, hackers took advantage of the fact that there is no single point of authority that could block them from using the platform and were able to launder the stolen funds.

The fact that a hacker uses decentralized exchanges negatively affects their reputation but at the same time confirms their reliability. Uniswap is completely decentralized and is a reliable service for exchanging cryptocurrencies. Everyone can exchange cryptocurrency without fear of their transactions being blocked.

How Did the Hack Happen? Malicious actions of employees — Exchange employees could have illegally shared the hot wallets’ private keys. Attack on web infrastructure — An attacker could gain access to the exchange’s hot wallet services. However, we consider such a version unlikely. Social engineering attack — Hackers could obtain access to private keys as a result of a phishing attack by using exploits, viruses, and backdoors on employees who had access to private keys.

According to KuCoin CEO and co-founder Johnny Lyu on Twitter,  the Kucoin team has found suspects, but no more information was given beyond that law enforcement is involved.

Will KuCoin Cover the Losses?

Despite the exchange claiming to reimburse all losses to users, we can see that there are not enough funds on the identified KuCoin wallets to pay off the losses caused by the hack. In addition, the exchange did not have a secure asset fund from which to recover losses. It is possible that these funds are kept in bank accounts of the exchange or in “secret” wallets, but we do not have such information.

Other exchanges do have insurance funds to be used in such events, like the Bittrex Digital Asset Insurance or Coinbase.

Who Is at Risk?

Since the KuCoin hack was due to leaked information about hot wallets, we consider exchanges that store large amounts of funds in hot wallets to be at risk of a similar attack. The following list includes some of the exchanges that rely on hot wallets:

Poloniex: https://etherscan.io/address/0xa910f92acdaf488fa6ef02174fb86208ad7722ba; Coinoine: https://etherscan.io/address/0x167a9333bf582556f35bd4d16a7e80e191aa6476; FTX: https://etherscan.io/address/0x2faf487a4414fe77e2327f0bf4ae2a264a776ad2
https://etherscan.io/address/0xc098b2a3aa256d2140208c3de6543aaef5cd3a94. How to Avoid Hacks in the Future? Periodically reinitialize hot wallets. KuCoin’s hot wallet key pairs have not been changed for three years; their first transactions were made on September 17, 2017. Two-man rule. Use secret sharing schemes. One of the most popular ways is to use Shamir’s Secret Sharing scheme.  Do not store more than 5% of all deposits in hot wallets. The other 95% must be stored in a cold wallet.  Store crypto in several hot wallets for each cryptocurrency platform. Each wallet must have its own private key. Perform regular penetration tests, phishing simulations, and red team exercises.

Perform audits of the cryptocurrency storage system that is included in SOC2 and/or ISO27000 auditing procedures: https://gemini.com/blog/gemini-completes-soc-2-review-a-worlds-first-for-a-cryptocurrency-exchange-and-custodian

CER.live Downgrades KuCoin. 

Because of the security incident, CER.live has now downgraded KuCoin from 6th place to 24th.

About CER.live

CER provides a fundamental analysis of the cryptocurrency exchange market. Through continuous cyber-forensic investigations and in-depth ranking methodology, CER has gained crypto traders’ trust as the only unbiased platform for crypto exchange reliability checks.

CER.live is integrated into one of the largest crypto-related analytical websites, CoinGecko, and is a member of all major crypto transparency alliances, including the Data Transparency and Accountability Alliance, run by CoinMarketCap.

Conclusion

The KuCoin exchange hack showed us that some exchanges have to pay more attention to common security standards. Some respectable exchanges such as U.S.-based Gemini, Coinbase and custody service provider Bitgo have already passed SOC-2 audits. SOC 2 examination on an annual basis demonstrates that an exchange cares about the safeguarding of its clients’ data and deposits.

Regardless of the reason for the hack, we recommend that exchanges adhere to generally accepted rules for storing client funds and perform regular audits. 

With regards to cyber criminals using DEXs to launder stolen funds, while not being able to freezer funds increases user confidence in the truly decentralized nature of these types of platforms, it also means that it’s much easier for malicious hackers to move ill-gotten goods without any problems. This is something that will need to be addressed soon if DEXs are to continue being used in this space.”

The post KuCoin September 2020 Hack: Hacken Research appeared first on CoinMarketCap Blog.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

KuCoin Shares (KCS) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $9.9109
Капитализация $0 Rank 99999
Цена в час новости $ 0.884 (-100%)

hack kucoin september research hacken 2020 reading

hack kucoin → Результатов: 45


BitMEX Loses its Dominant Position; Competition Among Binance, ByBit, & Others Heating Up

Since starting the month, the price of bitcoin has weathered numerous storms. From KuCoin’s $281 million hack, US President Donald Trump testing coronavirus positive, UK’s FCA banning crypto derivatives to FATF red-flagging hardware wallets, Europol prioritizing privacy wallets, and of course, BitMEX’ indictment, BTC held through it all.

2020-10-12 16:21


Kucoin’s Hackers Identified With ‘Substantial Proof’ in $280M Theft, Law Enforcement Involved

Kucoin announced through its CEO Johnny Lyu that they have found the hackers who compromised close to $280 million of the exchange’s funds in last week’s hack. Lyu tweeted this update over the weekend as crypto markets struggled in the red zone following the Kucoin hack, BitMEX indictments, and the news of President Trump contracting […] The post Kucoin's Hackers Identified With 'Substantial Proof' in 0M Theft, Law Enforcement Involved first appeared on BitcoinExchangeGuide.

2020-10-5 16:16


Фото:

Here’s Why Bitcoin Hasn’t Nuked Lower Despite Barrage of Bearish News

Many analysts and investors have been quite surprised at how stable Bitcoin’s price has been despite a plethora of bear-favoring developments within the markets From a macro perspective, President Trump’s recent viral diagnosis has rocked the traditional markets, which has had a trickle-down effect on crypto Within the crypto market, the recent $150m KuCoin hack, as well as the government’s charges against the BitMEX founders, have both spooked investors Despite all these factors placing pressure […]

2020-10-4 00:00


Фото:

Kucoin Hack: $17M Laundered Via Decentralized Exchanges, Blockchain Analysis Firm Claims This Can Still be Traced

Elliptic says the Kucoin hacker has sold $17. 1 million worth of tokens via decentralized exchanges (dex) platforms like Uniswap, Kyber Network, Tokenlon. The shift to dex applications comes after centralized projects came to the aid of the beleaguered exchange by blocking any cashing out of the hack related funds.

2020-10-2 10:30


Chainalysis расширит присутствие в Восточной Азии

Аналитическая компания Chainalysis объявила об открытии двух новых офисов в Токио и Сингапуре с целью расширения бизнеса в Азиатско-Тихоокеанском регионе. #KuCoin hack is yet another ex that crypto exchanges, law enforcement & financial institutions all over the world need investigations & compliance tools.

2020-9-29 15:12


Фото:

Похищенные с KuCoin токены LINK пришли в движение

Хакер, взломавший горячие кошельки KuCoin, перевел 50 тысяч токенов LINK (почти $530 000) на неизвестный адрес. На это обратил внимание аналитический ресурс Whale Alert. ⚠ 50,000 #LINK (529,962 USD) of stolen funds transferred from Kucoin Hack 2020 to unknown wallet Tx: https://t.

2020-9-29 13:35


KuCoin Hack: Exchange’s Insurance Fund to Cover User Loss “Completely,” Tether Freezes 33M USDT

The Singapore-based cryptocurrency exchange KuCoin released a statement regarding detecting large withdrawals on September 26, 2020, at 03:05:37 (UTC+8). The exchange has reportedly lost $150 million worth of funds, although KuCoin hasn’t declared it yet but released “suspicious addresses,” which are constantly updated.

2020-9-27 15:48


Фото:

POST COVID HACK 2020

Post Covid Hack 2020 is an online & global hackathon proudly organised by Indorse & Coinsilium and supported by blockchain & government partners IOVLabs, B4H, RSK, the Government of Gibraltar through their initiative #ThinkGibraltar, KuCoin & KuChain, Mishcon de Reya, Tribe Accelerator, UCL Centre for Blockchain Technologies, and many more! Post Covid Hack 2020 aims […]

2020-8-29 18:19