Three ways to prevent exchange hacks—how 3FA can foil cryptocurrency exchange robberies

2019-5-16 17:22

The recent hack of the world’s biggest cryptocurrency exchange, Binance, highlights the need for heightened security in the crypto space.

In what Wired reported as “a ‘large-scale security breach,’ hackers stole not only 7,000 bitcoin—equivalent to over $40 million ($56 million at the time of this writing, just one week later)—but also some user two-factor authentication codes and API tokens.”

This is just one of the many cryptocurrency heists totaling 100s of millions of dollars that CipherTrace has reported on in the last year.

Why are sophisticated hackers targeting the crypto space? Because, obviously, that’s where the money is. The huge hot wallet stash looted from Binance represented only about 2 percent of the exchange’s reserves. And, if this is the rumored ‘Crypto Spring’ to the recent winter, then as valuations begin to rise dramatically expect things to get worse.

The good thing for the industry is that Binance did the right thing—they were transparent and didn’t delay in reporting the theft, announcing it the same day it was discovered. “The hackers used a variety of techniques, including phishing, viruses and other attacks,” according to Binance CEO Changpeng Zhao in a May 7 blog post.

“The hackers had the patience to wait, and execute well-orchestrated actions through multiple seemingly independent accounts at the most opportune time. The transaction is structured in a way that passed our existing security checks.”

Moreover, Zhao announced that no customer funds would be used to cover losses, as Binance had set up a self-insurance fund in 2018 that accrues 10 percent of all trading fees in a separate cold wallet.

How did the theft occur? We are currently researching the attack, but from what we know Binance had the current state of the cybersecurity art in place. The attacker(s) probably used a password stolen in a phishing attack, or they exploited a combination of vulnerabilities.

As Chairman of the Anti-Phishing Working Group, an organization that has been fighting eCrime and phishing for more than 16 years, I can tell you it’s highly likely that phishing was an attack vector.

Spear phishing (targeted attacks on high-value individuals) and business email compromise (BEC) are getting a lot worse. And phishers are casting their nets—and spears—at crypto companies in particular. The Binance hack could have been an employee being duped into giving a password by a clever email ruse. It could have been phishing plus fileless malware or an APT. It could have stemmed from any number of vulnerabilities typically present in the attack surface of such a large, global IT network.

Time to triple-down on security

Two-factor authentication (2FA) is no longer strong enough, and SMS is a weak second factor. As was detailed in the CipherTrace Q4 2018 Crypto AML report, attackers often “port” phone numbers in order to receive SMS text messages that are used in a number of 2FA systems. Which obviously means this approach is not secure. But, by having an authentication app on the phone, instead of relying on SMS text message codes, companies are protected even if an employee’s phone is hijacked or SIM-swapped.

So what can and should exchanges do to prevent thefts? In our opinion, given the ever-increasing sophistication and persistence of the bad guys, there’s only one viable solution at the moment. Well, there’s three, actually.

The answer is three-factor authentication (3FA)—two things they have, and one thing they know. To access the network, exchange employees should be required to use an authentication app on their phone, a certificate on their computer to access the corporate VPN, and a password. That way, if criminals phish an exchange worker’s password or break it with brute force they’re still not getting in. Plus, unlike passwords, certificates can be revoked.

The attacker can gain the password and even compromise one of the user’s devices but that won’t get all three factors. And without compromising all three factors, they’re not getting in. Three-factor is the new strong auth. It may sound like this proposal puts an onerous burden on employees, but having a certificate on the computer takes no day-to-day effort.

The post Three ways to prevent exchange hacks—how 3FA can foil cryptocurrency exchange robberies appeared first on CryptoSlate.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Safe Exchange Coin (SAFEX) íà Currencies.ru

$ 0.0054306 (-0.25%)
Îáúåì 24H $1.742k
Èçìåíåèÿ 24h: 1.41 %, 7d: -8.63 %
Cåãîäíÿ L: $0.0053635 - H: $0.0055227
Êàïèòàëèçàöèÿ $6.099m Rank 99999
Öåíà â ÷àñ íîâîñòè $ 0.0064451 (-15.74%)

exchange cryptocurrency robberies security million foil hacks

exchange cryptocurrency → Ðåçóëüòàòîâ: 126


CoinSwitch Review 2022 – A Look At Features, Fees, Security

CoinSwitch platform is the first cryptocurrency and altcoin exchange aggregator. It has integrated many leading exchanges across the globe to provide best exchange rates to its users. CoinSwitch is a cryptocurrency exchange providing the best way to invest in cryptocurrencies by aggregating all leading exchanges and comparing cryptocurrency prices in real time.

2022-3-9 23:20


trueDigital to acquire CFTC registrations from trueEX to launch crypto derivatives exchange

CryptoNinjas - Bitcoin, Cryptocurrency & Blockchain Asset SourcetrueDigital, a provider of financial technologies and products for traditional and digital asset markets, today announce dit has reached an agreement in principle to acquire, subject to CFTC approval, the Designated Contract Market (DCM) and Swaps Execution Facility (SEF) registrations held by trueEX.

2019-7-13 20:40


Japanese Crypto Exchange Bitpoint Loses $32 Million In Hack; BTC, BCH, ETH, LTC, and XRP Stolen

The hacking attempts at cryptocurrency exchanges are becoming more and more prevalent as yet another exchange lost over $32 million USD worth of cryptocurrency funds. The hack on Japan’s BitPoint led to the indefinite closure of withdrawal, deposit and trading services on the platform leading to several questions on the security of the exchange. This […]

2019-7-12 16:38


CODEX crypto exchange implements US requirement to block IP addresses

CryptoNinjas - Bitcoin, Cryptocurrency & Blockchain Asset SourceCODEX, a cryptocurrency exchange licensed in Estonia, announced that in order to stay compliant with the law, moving forward, users originating from the United States won’t be able to use the exchange platform, and all underlying functionality including trading, deposits, withdrawals, registrations, etc.

2019-7-11 18:34


Ôîòî:

Bitfinex Exchange Launch LEO Token Buy Back Program

Bitfinex, a controversial cryptocurrency exchange that claims to be the largest and most advanced bitcoin trading venue, has announced the commencement of its LEO token buyback program. The exchange says it has successfully used 27 percent of the revenue generated from the sale of Ampleforth tokens on Tokinex, its initial exchange offering (IEO) platform toRead MoreRead More.

2019-7-10 20:00


New Anti-Bitcoin Move From SEC As It Suspends Trading on the First Publicly Traded Cryptocurrency Exchange Bitcoin Generation

Just as the cryptocurrency market is turning bullish, the US Securities and Exchange Commission (SEC) takes another step back… The post New Anti-Bitcoin Move From SEC As It Suspends Trading on the First Publicly Traded Cryptocurrency Exchange Bitcoin Generation appeared first on Invest In Blockchain.

2019-4-30 17:54


Ôîòî:

Australia: Regulators Slap AUD 33k Fine on Byte Power Cryptocurrency Exchange for Irregularities

Australian Securities and Investments Commission (ASIC), the region’s securities regulator, has issued an infringement notice to Byte Power Group Limited, an Australia-based digital assets exchange, alleging that the crypto trading venue failed to comply with its continuous disclosure duties and the regulated exchange has now paid a penalty of AUD 33,000 reports ZDNet on FebruaryRead MoreRead More.

2019-2-16 22:00


Beaxy Exchange Hits Over 4.2 Million Soft Cap, Announces Its First 25 Cryptocurrencies

A Saint Kitts and Nevis-based cryptocurrency exchange platform is set to be the latest entrant in the crypto industry. Beaxy, whose aim is to rank among the best and indeed create an ultimate all-in-one cryptocurrency exchange, will possibly go live by the end of the first quarter of 2019. Currently undergoing Beta testing, the exchange […]

2019-1-27 18:57


Bitcoin Gold (BTG) Gets Delisted By Bittrex Crypto Exchange Due To $18 Million Hack

Bittrex Exchange Removes Bitcoin Gold From Their Exchange Among cryptocurrency startup companies, the risk of theft, extortion, or major attack is very significant. The cryptocurrency community has always been especially susceptible to crime, because of the prevalence of technology-minded hackers in the markets, as well as the anonymous nature of cryptocurrencies in general. For these […]

2018-9-4 13:37


Ôîòî:

How Exactly Should You Choose A Cryptocurrency Exchange?

Choosing a cryptocurrency exchange can be a difficult task. It’s not a fast process, it’s hard work. Even signing up to a cryptocurrency exchange can be time consuming, and requires you to rifle through a number of intrusive questions before uploading pictures of your personal documents, overall, it’s not a nice experience and therefore you don’t want to have to keep doing it.

2018-8-17 23:00