Subscribe for notification
Crypto

OKX Probes Multi-Million Account Thefts After SIM Swaps

SlowMist claims that although OKX’s two-factor authentication system was not the primary point of vulnerability, there were two identical phishing events.

SlowMist, a security partner of OKX cryptocurrency exchange, is looking into a multi-million dollar attack that led to the theft of two user accounts.

The subject of the inquiry is the June 9 theft of two OKX exchange accounts via SMS attack, commonly called SIM swapping. SlowMist’s founder, Yu Xian, revealed this knowledge in a post on X.

“The SMS risk notification came from Hong Kong and a new API Key was created (with withdrawal and trading permissions, which is why we suspected a cross-trading intention before, but it seems that it can be ruled out now).”

Although it’s unknown how much was taken in the attack, Xian said that “millions of dollars of assets were stolen.”

2FA did not primarily cause the attack: Slow-Mist

Even if the blockchain security company SlowMist is currently looking into the hacker wallet and related events, the exchange’s two-factor authentication (2FA) systems may not be the primary weak point.

Xian, the founder of SlowMist, wrote the following on June 9 X:

“I haven’t turned on a 2FA authenticator like Google Authenticator, but I’m not sure if this is the key point.”

According to an analysis by Web3 security organization Dilation Effect, OKX’s 2FA system allowed attackers to switch to a low-security verification method, enabling withdrawal addresses via SMS verification.

More experienced hackers, nevertheless, have lately begun evading 2FA authentication procedures. A Chinese trader lost $1 million to a fraud that used the Aggr Google Chrome plugin at the start of June. Hackers utilize stolen user cookies from the plugin to get around 2FA authentication and passwords.

$3 billion stolen in hacks — Why are crypto crimes surging?. Source: Cointelegraph

Attacks by phishers are increasing.

June saw increased phishing attempts following CoinGecko’s confirmation of a data breach involving GetResponse, a third-party email management platform. Because of the incident, victims received 23,723 phishing emails from the attacker.

Hackers who use phishing attacks try to obtain private keys to crypto wallets and other sensitive data. Aiming to deceive investors into voluntarily sending money to a phony address that resembles addresses they have previously interacted with, other phishing attempts are also referred to as address poisoning scams.

Because hackers are looking for the easiest targets, private key, and personal data leaks are becoming the leading causes of crypto-related hacks.

Crypto total losses by vulnerabilities. Source: Merkle Science

According to Merkle Science’s 2024 HackHub report, private critical leaks during 2023 resulted in the loss of almost 55% of the hacked digital assets.

Ruth Okarter

Ruth is a seasoned news reporter and editor who brings her sharp eye and passion for storytelling to Protechbro.com. With a background in English and literary studies, Ruth crafts compelling narratives that unpack the complexities of the ever-evolving tech landscape.

Disqus Comments Loading...

Recent Posts

Gold-Backed Coin Aims To Boost Bitcoin In Texas

A Texas congressman says the state's gold-backed digital currency could boost crypto adoption and inspire investors to explore Bitcoin. According…

2 hours ago

Ether Price Rises Despite Whale Sell-off

Ether price is breaking out above $3,700 despite significant selling pressure, driven by an emerging bull flag, analysts report. Some…

2 hours ago

Kevin Warsh- Treasury Secretary, Succeed Fed Chair Powell

Donald Trump is considering Kevin Warsh for Treasury Secretary and to succeed Jerome Powell as Fed Chair when his term…

4 hours ago

Upbit Refunds Millions After Crypto Hack

Upbit refunded 8.5 billion won to 380 voice phishing victims, as authorities expose North Korea's involvement in previous hacks. Upbit,…

6 hours ago

Charles Schwab CEO Regrets Not Investing In Crypto

Rick Wurster, set to become CEO next year, stated he has no plans to buy crypto but aims to support…

6 hours ago

Federal Task Force Busts Cartel-Linked Crypto Laundering Ring

Nine individuals were charged with laundering U.S. drug proceeds into cryptocurrency for Mexican and Colombian cartels from 2020 to 2023.…

8 hours ago