Just as important as preventing hacking is protecting the user’s assets in the event of an accident… | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


[Editor’s note] ‘In an era when banks are also hacked, will virtual assets (coins) I entrust be safe?’
Recently, there have been a series of hacking attacks in the banking sector that are believed to have used artificial intelligence (AI). Large-scale hacking accidents have also occurred on overseas virtual asset exchanges. The domestic virtual asset exchange examines whether it can prevent such attacks and whether users can be compensated if damage occurs.

Just as important as preventing hacking is protecting the user’s assets in the event of an accident. As virtual assets worth 500 billion won have recently leaked from Bitget, a global additional asset exchange, the damage compensation system of domestic exchanges is also drawing attention.

According to the financial authorities and the virtual asset industry on the 8th, the Korean won exchange is equipped with protective devices such as real possession of user assets, separate storage of cold wallets, and securing insurance and reserves in case of accidents such as hacking.

[Graphic = Mae-chyeong-AX]

There are three major stages of user protection on domestic exchanges. First, the exchange actually holds the same type and quantity as the virtual assets entrusted by the customer. Of these, more than 80% of the economic value is stored in a “cold wallet” separate from the Internet, lowering the risk of hacking.

It is an AI-generated image to help understand the article. [ChatGPT]
It is an AI-generated image to help understand the article. [ChatGPT]

There are also separate financial resources for accidents. It stipulated that the won exchange should have more than 5% of the value of users’ virtual assets, excluding assets stored in Cold Wallet, as insurance and deduction compensation limits or reserves. The standard of at least 3 billion won is applied.

The amount is recalculated every month. If the standards are not met, the compensation limit must be raised or additional reserves must be accumulated.

[Graphic = Mae-chyeong-AX]
[Graphic = Mae-chyeong-AX]

According to data submitted by the Financial Supervisory Service to the National Assembly, Bithumb, including Upbit operator Dunamu, set aside 80 billion won in reserves as of August 14. Coinone costs 30 billion won and Covit 19 billion won. Gopax operator Streamy has purchased insurance with a compensation limit of 3 billion won.

These amounts are not the limit of the exchange’s liability for damages. It is a safety device that is prepared in advance to fulfill responsibilities for hacking or computer failure.

An official at a virtual asset exchange said, “The reserve is prepared to compensate customers in the event of an accident such as hacking,” adding, “If an extreme accident occurs, we may have to compensate more than the reserve.”

There is also a procedure for compensation for damage after the accident. Doc’s “Best Practices for Computer System Operation and User Protection of Virtual Asset Businesses” stipulates that in principle, the business operator should compensate if the user is damaged by a computer failure.

When a user applies for compensation, in principle, the review is completed within 15 business days to notify the result. It also guarantees at least two opportunities to raise objections.

[Graphic = Mae-chyeong-AX]
[Graphic = Mae-chyeong-AX]

In some cases overseas, after a large-scale hacking accident, the exchange decided to compensate for user damage with its own funds. Bitget, a global virtual asset exchange, said it would bear losses and maintain user account balances through user protection funds worth more than $464 million when virtual assets worth about $388 million were leaked last month. The withdrawal service, which was suspended immediately after the accident, also resumed sequentially and normalized on the 2nd.

Even in Korea, the size of insurance or reserves is not an upper limit on the protection of user assets. However, the problem becomes complicated if large-scale damage occurs like Bitget and the exchange’s ability to absorb losses itself is shaken.

In the current Virtual Asset User Protection Act, there are no special regulations that separately set the scope of the operator’s liability for damages and the burden of proof in the event of a hacking or computer accident. However, it is an important issue in terms of user protection how users’ assets can be quickly returned if the operator’s ability to pay itself is damaged due to a large-scale accident.

An official from a virtual asset exchange said, “The minimum standards are currently reflected in the policy,” adding, “There are areas where the compensation process is not clear when damage beyond this occurs.”

Recognizing these institutional shortcomings, the Financial Services Commission is discussing ways to supplement related systems in the process of preparing a two-stage legislative government plan for virtual assets called the Framework Act on Digital Assets.



Click Here For The Original Source.

——————————————————–

..........

.

.