Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

// // //
6/12/2018
08:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now

Bitcoin & Other Cryptocurrency Prices in Flux Following Hack

A hack of a South Korean cryptocurrency exchange over the weekend sent the price of Bitcoin and other cryptocurrencies into flux on Monday, upsetting an already volatile market.

The weekend hack of a cryptocurrency exchange in South Korea made itself felt across the globe on Monday, with a ripple effect that included a significant fluctuation in the price of Bitcoin and other virtual currencies.

The exchange, Coinrail, announced on its website Sunday that it had been attacked, although it's not clear what exactly happened or who might have been behind the incident. This particular exchange isn't as large as some of the other ones on the market, and the total loss of value is estimated at $40 million, according to Yahoo News and other published reports.

The exchange has since moved its other virtual currency to a so-called cold wallet -- a platform not connected to the wider Internet.

However, the attack made itself felt around the globe as cryptocurrency fluctuated throughout the day.

(Source: Pixabay)
(Source: Pixabay)

Bitcoin, the most popular of the various cryptocurrencies, saw its price drop from an opening high of $6,816 to a low of $6,652 at one point during the day on June 11. The price did recover somewhat later in the trading day, according to Coindesk. Another cryptocurrency, Ethereum, also saw a significant drop.

Overall, Bloomberg estimated that worldwide cryptocurrency lost about $42 billion in market value over the last three days, although there are more factors at play than a cyberattack at a small South Korean exchange, including possible regulations in China.

Still, this latest incident shows how volatile cryptocurrency has become, especially as attackers have turned more of their attention to installing crypto mining malware or engaging in crypto jacking.

In their recent Global Threat Index, Check Point security researchers found that crypto mining and crypto jacking have overtaken ransomware as the most lucrative schemes for cybercriminals. It's a trend that shows no sign of slowing down. (See Cryptomining Malware, Cryptojacking Remain Top Security Threats.)

"Cryptocurrency exchanges are largely in their infancy, and therefore do not have the historical checks, balances, processes, infrastructure and skills that an established financial institution will have," Peter Alexander, the CMO of Check Point, wrote in an email to Security Now. "Big money can flow unchecked in microseconds, and the alarm bells won't start ringing until It's too late. And of course, cryptocurrency can be traded anonymously on a global basis."


Now entering its fifth year, the 2020 Vision Executive Summit is an exclusive meeting of global CSP executives focused on navigating the disruptive forces at work in telecom today. Join us in Lisbon on December 4-6 to meet with fellow experts as we define the future of next-gen communications and how to make it profitable.

The incident in South Korea is one of several attacks that have targeted these exchanges, which security experts believe is a combination of cybercriminals, as well as some nation states looking to disrupt other countries. (See Cryptocurrency Crime: The Internet's New Wild West.)

Brajesh Goyal, the vice president of engineering at cybersecurity firm Cavirin, noted in an email to Security Now that these types of hacks should have these exchanges re-examining their entire cybersecurity plans, especially in such a volatile market.

"Once again, the need for security in depth to protect one's cyber posture," Goyal wrote. "You can't only protect the perimeter. Assume the hackers are already inside and deploy tools that offer continuous assessment and immediate alerting if security posture drift is detected. The tools exist. In this case, the regulators must mandate that exchanges including Conrail implement best practices."

At the same time, the speculation around Bitcoin and other cryptocurrencies, along with various cybercriminal schemes, have had a significant effect on this market. At the end of December, Bitcoin traded at over $19,000 and had plunged to below $7,000 since then.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Everything You Need to Know About DNS Attacks
It's important to understand DNS, potential attacks against it, and the tools and techniques required to defend DNS infrastructure. This report answers all the questions you were afraid to ask. Domain Name Service (DNS) is a critical part of any organization's digital infrastructure, but it's also one of the least understood. DNS is designed to be invisible to business professionals, IT stakeholders, and many security professionals, but DNS's threat surface is large and widely targeted. Attackers are causing a great deal of damage with an array of attacks such as denial of service, DNS cache poisoning, DNS hijackin, DNS tunneling, and DNS dangling. They are using DNS infrastructure to take control of inbound and outbound communications and preventing users from accessing the applications they are looking for. To stop attacks on DNS, security teams need to shore up the organization's security hygiene around DNS infrastructure, implement controls such as DNSSEC, and monitor DNS traffic
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-33196
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33185
PUBLISHED: 2023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests ar...
CVE-2023-33187
PUBLISHED: 2023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `ty...
CVE-2023-33194
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was...
CVE-2023-2879
PUBLISHED: 2023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file