Connect with us

Latest News

CoinStats suspends app after security breach compromises 1,590 wallets | MATIC News

Avatar

Published

on

CoinStats, the crypto portfolio app, has temporarily shut down its application to address a security incident. The company stated the breach was limited to 1,590 wallets or 1.3% of all CoinStats Wallets. The company reported that connected wallets and centralized exchanges (CEXes) were unaffected. CoinStats is also investigating a scam notification some iOS and Android users received.

Author’s note: As a long-time supporter of CoinStats, I personally had limited funds in a CoinStats wallet generated around 2022. These funds were moved out of the wallet, which was not connected to any external apps, around 1.5 hours before the notification scam was sent to users. Funds from both Ethereum and Polygon wallets are now with the attacker.

CoinStats stated that the list of affected wallets may be updated as the investigation progresses, but significant changes are not expected. Users with affected wallets are advised to move their funds immediately using their exported private keys if they were previously exported. CoinStats provided a link to the list of affected wallets.

Scam notification promoting 14.2 ETH prize to users

The scam notification falsely informed users of a reward and directed them to log into the CoinStats AirScout wallet. The link pointed users to a Drainer website, which was promoted via a CoinStats push notification and official in-app notification on the app’s home screen. The company is looking into the issue and has apologized for the inconvenience, assuring users that updates will be provided as soon as possible.

The notification falsely congratulated recipients on winning a 14.2 ETH reward in an event with a total pool of 200 ETH. The message also mentioned that the event was to celebrate exceeding 2 million CoinStats users and the launch of CoinStats AirScout, and it falsely stated that users’ crypto had been transferred to the CoinStats AirScout Wallet.

The company is actively investigating the extent of the compromised funds and will issue updates as more information becomes available. Efforts are underway to restore the app’s functionality as swiftly as possible, and CoinStats has expressed gratitude for users’ patience during this period.

CryptoSlate reached out to CoinStats moments after the notification was sent but has not received a response.

Potential causes of the private key breach

While CoinStats has not yet publicly disclosed insights into the cause of the attack, the incident may raise concerns about whether private keys were stored on their server and the randomness of wallets generated from within the app, especially since only CoinStats-generated wallets appear to have been specifically targeted and drained.

The attackers’ ability to access the server and send a malicious push notification suggests that they may also have gained insights into the wallet generation process. Any potential weaknesses in the random number generation used during that time could have allowed attackers to predict private keys and compromise user funds.

No wallets or API connections shared with the CoinStats portfolio application appear to have been affected at this point. However, some users have reported that other wallets that were connected to utilize DeFi features have been drained. These are unconfirmed by CoinStats at this time.

CoinStats acted swiftly and removed access to the application within hours of the incident. As of press time, the app remains down while the investigation is ongoing.

As always, stay vigilant of any surprise competitions or rewards across crypto and use hardware wallets to secure critical funds.

The post CoinStats suspends app after security breach compromises 1,590 wallets appeared first on CryptoSlate.


Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News

Crypto VC investment ‘continued rebound’ in Q2 with $3.2 billion invested – Galaxy | MATIC News

Avatar

Published

on

Venture capital investments in crypto continued to rebound in the second quarter, with a total $3.2 billion invested during the period — up 28% compared to $2.5 billion in the previous quarter, according to Galaxy Digital latest research report.

The report also identified a 94% quarterly surge in median pre-money valuation, which rose to $37 million from $19 million in the first quarter.

Galaxy noted the second quarter’s median pre-money valuation is the highest since the fourth quarter of 2021 and represents an almost all-time high. It attributed the surge to a more competitive market, giving companies greater negotiation leverage in deals.

Meanwhile, the second quarter median deal size grew to $3.2 million from $3 million, up 7% after remaining largely steady for five quarters. Deal count fell to 577 in the second quarter, down from 603 in the first quarter but up from less than 400 in the fourth quarter of 2023.

According to the report:

“Despite a lack of available investment capital compared to previous peaks, the resurgence of the crypto market… is leading to significant competition and [FOMO] among investors.”

The report highlighted a positive shift in crypto venture capital sentiment, buoyed by a nearly 50% year-to-date rise in Bitcoin and Ethereum prices. If the trend continues, 2024 will have the third-highest investment capital and deal count numbers after the bull markets of 2021 and 2022.

However, the report also noted that despite Bitcoin experiencing a significant rise since January 2023, venture capital activity has not kept pace, trading well below the levels seen when the flagship crypto last traded above $60,000 in 2021 and 2022.

The divergence is attributed to several factors, including crypto-native catalysts like Bitcoin ETFs and emerging areas such as restaking and Bitcoin Layer 2 solutions. Additionally, pressures from crypto startup bankruptcies, regulatory challenges, and macroeconomic headwinds, particularly interest rates, have collectively contributed to the breakdown.

Other data and trends

Specific project categories led fundraising — including Web3, which brought in $758 million or 24% of all capital. Infrastructure brought in over $450 million (15%), trading and exchanges brought in under $400 million (12%), and Layer 1 brought in under $400 million (12%).

Bitcoin Layer 2 networks continued to see significant investments of $94.6 million, up 174% on a quarterly basis. Galaxy said “investor excitement remains high” around the possibility of composable blockspace attracting DeFi and NFT projects to Bitcoin.

US companies dominated VC investment, attracting 53% of all capital and 40% of deals. Galaxy said US dominance exists despite regulatory change that could cause companies to leave the country and warned policymakers to be aware of their impact.

Early-stage firms received about 78% of capital, while late-stage companies received 20% of all capital. Galaxy said that larger general VC firms have left the sector or scaled down their activity, reducing the ability of later-stage startups to raise money.

Mentioned in this article
Posted In: US, Investments


Continue Reading

Latest News

Bittensor proposes burning 10% supply to stabilize TAO following $8 million exploit | MATIC News

Avatar

Published

on

OpenTensor Foundation (OTF) has proposed burning 10% of the Bitttensor (TAO) supply to stabilize the token’s price in response to a recent exploit that led to the loss of $8 million worth of the tokens.

The decentralized AI network has put forward a vote for users to decide on the burn. Active voters participating in the proposal will be rewarded with compensatory DAO rewards at a later date.

The exploit, which occurred on July 2, saw a Bittensor user lose 32,000 TAO tokens due to a leaked private key. The incident caused an immediate 15% drop in TAO’s price, hitting a six-month low of $227. The price has since rebounded slightly to $240.

Attack timeline

The attack timeline reveals that the incident began on July 2 at 7:06 P.M. UTC when funds started being transferred out of wallets.

OTF detected the abnormal transfer volume and initiated a war room by 7:25 P.M. UTC, and by 7:41 P.M. UTC, the team had neutralized the attack by placing validators behind a firewall and activating safe mode to prevent nodes from connecting to the chain.

During this period, the network was configured to only produce blocks, halting all transactions to prevent further losses and allowing time for a thorough investigation.

The root cause of the attack was traced back to a malicious package in the PyPi Package Manager version 6.12.2, which compromised user security. The package, posing as a legitimate Bittensor package, contained code designed to steal unencrypted coldkey details.

When users downloaded this package and decrypted their coldkeys, the decrypted bytecode was sent to a remote server controlled by the attacker.

The incident prompted an immediate response from the OTF team, which prioritized the security breach over regular updates and maintenance. The disruption has been a significant test for the network, highlighting both its vulnerabilities and the resilience of its infrastructure.

Aftermath

Despite the severity of the attack, some validators, such as RoundTable 21, confirmed that their delegators’ funds remained secure, emphasizing that the exploit did not impact all users uniformly.

However, the decision to halt the chain has led to a debate within the community about its implications for Bittensor’s claim of decentralization. Critics argue that the ability to pause the chain contradicts the principles of a decentralized AI network, while supporters believe it was necessary to protect users’ assets.

OTF plans to gradually resume normal operations of the Bittensor blockchain, ensuring a safe and responsible approach. Regular progress updates will be provided to the community.

As a precaution, users who suspect their wallets were compromised are advised to create new wallets and transfer their funds once the blockchain resumes normal operation. Additionally, upgrading to the latest version of Bittensor is strongly recommended.

Moving forward, Bittensor will implement enhanced package verification processes, increase the frequency of security audits, adopt best practices in public security policies, and improve monitoring and logging of package uploads and downloads.

The proposed token burn and ongoing security enhancements aim to restore confidence in the TAO ecosystem. The outcome of the vote will play a crucial role in stabilizing and securing the network, with the community eagerly awaiting further updates from the developers.

Mentioned in this article


Continue Reading

Latest News

Europe’s largest Bitcoin miner Northern Data to launch IPO in the US | MATIC News

Avatar

Published

on

Europe’s largest Bitcoin miner, Northern Data AG, has announced plans for a substantial initial public offering (IPO) in the US at a valuation between $10 billion and $16 billion.

The IPO, which will be held on the Nasdaq stock exchange, is scheduled for the first half of 2025 and may also include selling a minority stake to investors prior to the public listing.

Following the IPO announcement, Northern Data’s shares on the XETRA stock exchange surged by over 5%, reaching €25. This positive market reaction indicates strong investor confidence in the company’s future prospects. The firm first considered an IPO in 2021 but decided against it at the time.

The upcoming offering will highlight two of Northern Data’s key business units: Taiga, which handles the company’s cloud computing activities, and Ardent, which manages its data centers. Both units are crucial to Northern Data’s strategy to capitalize on the rapidly expanding AI sector.

The crypto industry continues to face regulatory challenges. Previous attempts by digital asset firms to go public, including Circle, encountered difficulties due to regulatory scrutiny. However, Northern Data’s focus on AI and cloud computing may help it navigate these challenges more effectively.

AI pivot

Originally founded as Northern Bitcoin AG, Northern Data has grown into a significant player in the Bitcoin mining industry. In recent years, the company has diversified its operations to include artificial intelligence (AI) and cloud computing, responding to the decreasing profitability of Bitcoin mining and the growing opportunities in these fields.

In November 2023, Northern Data secured $610 million in debt financing from Tether. The investment is intended to strengthen Northern Data’s AI and cloud computing operations.

The financing followed a strategic partnership between the two companies announced in September 2023. The partnership aimed to focus on AI, peer-to-peer communications, and data storage solutions.

Northern Data’s pivot towards AI and cloud computing reflects a broader industry trend. As the profitability of Bitcoin mining declines, many companies, including Core Scientific and Hut 8 Corp, are exploring new revenue streams.

Committed to Bitcoin mining

While diversifying its business, Northern Data remains committed to Bitcoin mining and plans to continue expanding its footprint in the industry.

Peak Mining, the company’s US-based Bitcoin mining unit, is a significant part of its operations, with nearly 700 megawatts of high-performance computing data centers. In 2023, Peak Mining mined 2,298 BTC, generating over $64 million in revenue despite an 18% year-over-year decrease in production.

Northern Data’s presence in the US has been growing steadily. In May, the company acquired its second 300-megawatt mining site, further solidifying its position in the American market. The expansion highlights Northern Data’s long-term commitment to Bitcoin mining, even as it explores new technological frontiers.

Mentioned in this article


Continue Reading

Trending