[Editor’s note] ‘In an era when banks are also hacked, will virtual assets (coins) I entrust be safe?’
Recently, there have been a series of hacking attacks in the banking sector that are believed to have used artificial intelligence (AI). Large-scale hacking accidents have also occurred on overseas virtual asset exchanges. The domestic virtual asset exchange examines whether it can prevent such attacks and whether users can be compensated if damage occurs.
With a series of hacking attacks that appear to have used artificial intelligence (AI) by commercial banks and other financial companies, attention is also being paid to how financial authorities will supervise the security of domestic virtual asset exchanges.
The won exchange is a place where domestic investors’ virtual asset transactions and storage are concentrated, which can lead to major property damage in the event of a hack. Critics point out that as actual infringement occurred in the banking sector recently, it is necessary to check not only whether the won exchange complies with security regulations, but also whether it can prevent similar attacks.
According to the financial sector and the virtual asset industry on the 8th, the Financial Supervisory Service asked local won exchanges to complete their own security checks by today and inform them of the results in connection with the recent hacking of the financial sector.
The FSS delivered a list of Internet addresses (IPs) and a checklist of 12 items that appeared to be used in the hacking attack to Korean won exchanges. Based on this, we are checking whether the IP is blocked, whether there was any hacking attempt or damage, and whether the system that monitors security in real-time works well.
In addition to the weaknesses of the computer system exposed to the outside, it also checks whether identity verification and access rights are properly managed when accessing from the outside.
However, this inspection is not a separate list specialized for virtual asset exchanges, but a measure commonly required for all financial sectors. When the recent attack method shown in the banking sector was applied to the coin exchange system, it was not confirmed whether or not it was verified.
Large-scale hacking incidents have already occurred overseas. As 500 billion won worth of virtual assets was transferred to the attacker’s wallet without permission from Bitget, a global virtual asset exchange, last month, there is also a growing need to check the hacking response capabilities of local won exchanges.
Domestic exchanges store more than 80% of the economic value of users’ virtual assets in a safe storage box (cold wallet) separate from the Internet and operate security systems such as hacking detection and access control. The Digital Asset Exchange Joint Consultative Group (DAXA), which includes five major Korean won exchanges such as Upbit, Bithumb, Coinone, Cobbit, and Gopox, also operates best practices for hacking, malicious code, and DDoS as guidelines.
The problem is that it is difficult to conclude that the fact that such a security device is equipped alone can completely prevent actual hacking attacks.
Hwang Seok-jin, a professor at Dongguk University Graduate School of International Information Protection, said, “In recent years, not only direct attacks on the computer network itself, but also attacks that act like real users by stealing API authentication information or account rights are increasing.”
In fact, fraud attempts are being made to take over API authentication information in Korea. Upbit operator Dunamoo warned users that it was caught recruiting to pay for lending an account or API key to the social network service (SNS).
The API key is a password (authentication information) used when an external program enters a virtual asset exchange account. According to Dunamu, some recruiters explain that they only use it for simple market price inquiries, but general market price information can be checked without separate authentication. If the API key is passed on to another person, it may be abused for account information inquiry or transaction depending on the authorization granted.
Professor Hwang emphasized, “Cold Wallet and several levels of payment are still important safety devices, but this alone should not judge the overall security level of the exchange.” As the attack paths, such as account, API authentication information, managerial authority, and external connection systems, are diversified, it is necessary to check whether various security devices work properly together.
In response, each exchange responded by supplementing the automatic attack detection policy in preparation for new security threats and limiting excessive access requests in a short period of time. Some Korean won exchanges are also considering introducing a separate defense system to cope with attacks using artificial intelligence (AI).
It has also become important how far financial authorities check actual hacking defense capabilities. Although DAXA operates self-regulation related to security, it has no legal enforcement power, and complying with the regulations and preventing actual hacking attacks are separate.
Critics point out that regulators should go beyond blocking hackers’ Internet addresses (IPs) or checking whether they have been hacked as before and thoroughly check whether new hacking methods such as access information leakage can be actually prevented.
Professor Hwang said, “Daksa’s best practice is the minimum common safety standard that applies to all exchanges,” adding, “How quickly the exchange applies the ever-changing hacking method to security and whether it can prevent users’ assets from being taken away even if they are actually attacked is a more important criterion.”
Click Here For The Original Source.
