Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

6/12/2018
08:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Bitcoin & Other Cryptocurrency Prices in Flux Following Hack

A hack of a South Korean cryptocurrency exchange over the weekend sent the price of Bitcoin and other cryptocurrencies into flux on Monday, upsetting an already volatile market.

The weekend hack of a cryptocurrency exchange in South Korea made itself felt across the globe on Monday, with a ripple effect that included a significant fluctuation in the price of Bitcoin and other virtual currencies.

The exchange, Coinrail, announced on its website Sunday that it had been attacked, although it's not clear what exactly happened or who might have been behind the incident. This particular exchange isn't as large as some of the other ones on the market, and the total loss of value is estimated at $40 million, according to Yahoo News and other published reports.

The exchange has since moved its other virtual currency to a so-called cold wallet -- a platform not connected to the wider Internet.

However, the attack made itself felt around the globe as cryptocurrency fluctuated throughout the day.

(Source: Pixabay)
(Source: Pixabay)

Bitcoin, the most popular of the various cryptocurrencies, saw its price drop from an opening high of $6,816 to a low of $6,652 at one point during the day on June 11. The price did recover somewhat later in the trading day, according to Coindesk. Another cryptocurrency, Ethereum, also saw a significant drop.

Overall, Bloomberg estimated that worldwide cryptocurrency lost about $42 billion in market value over the last three days, although there are more factors at play than a cyberattack at a small South Korean exchange, including possible regulations in China.

Still, this latest incident shows how volatile cryptocurrency has become, especially as attackers have turned more of their attention to installing crypto mining malware or engaging in crypto jacking.

In their recent Global Threat Index, Check Point security researchers found that crypto mining and crypto jacking have overtaken ransomware as the most lucrative schemes for cybercriminals. It's a trend that shows no sign of slowing down. (See Cryptomining Malware, Cryptojacking Remain Top Security Threats.)

"Cryptocurrency exchanges are largely in their infancy, and therefore do not have the historical checks, balances, processes, infrastructure and skills that an established financial institution will have," Peter Alexander, the CMO of Check Point, wrote in an email to Security Now. "Big money can flow unchecked in microseconds, and the alarm bells won't start ringing until It's too late. And of course, cryptocurrency can be traded anonymously on a global basis."


Now entering its fifth year, the 2020 Vision Executive Summit is an exclusive meeting of global CSP executives focused on navigating the disruptive forces at work in telecom today. Join us in Lisbon on December 4-6 to meet with fellow experts as we define the future of next-gen communications and how to make it profitable.

The incident in South Korea is one of several attacks that have targeted these exchanges, which security experts believe is a combination of cybercriminals, as well as some nation states looking to disrupt other countries. (See Cryptocurrency Crime: The Internet's New Wild West.)

Brajesh Goyal, the vice president of engineering at cybersecurity firm Cavirin, noted in an email to Security Now that these types of hacks should have these exchanges re-examining their entire cybersecurity plans, especially in such a volatile market.

"Once again, the need for security in depth to protect one's cyber posture," Goyal wrote. "You can't only protect the perimeter. Assume the hackers are already inside and deploy tools that offer continuous assessment and immediate alerting if security posture drift is detected. The tools exist. In this case, the regulators must mandate that exchanges including Conrail implement best practices."

At the same time, the speculation around Bitcoin and other cryptocurrencies, along with various cybercriminal schemes, have had a significant effect on this market. At the end of December, Bitcoin traded at over $19,000 and had plunged to below $7,000 since then.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Data Breaches Affect the Enterprise
Data breaches continue to cause negative outcomes for companies worldwide. However, many organizations report that major impacts have declined significantly compared with a year ago, suggesting that many have gotten better at containing breach fallout. Download Dark Reading's Report "How Data Breaches Affect the Enterprise" to delve more into this timely topic.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-42122
PUBLISHED: 2021-11-30
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s attributes with numeric...
CVE-2021-42123
PUBLISHED: 2021-11-30
Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to ...
CVE-2021-42544
PUBLISHED: 2021-11-30
Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, wh...
CVE-2021-42545
PUBLISHED: 2021-11-30
An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
CVE-2021-43771
PUBLISHED: 2021-11-30
Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first o...