On November 5, 2019, Vietnam-based cryptocurrency exchange VinDAX was hacked, losing half a million U.S. dollars worth of funds spread across 23 different cryptocurrencies.[1] The VinDAX hack marks the latest in a series of cryptocurrency exchange hacks and data breaches that have taken place this year, and is part of a larger and growing trend of digital currency heists that have occurred since Bitcoin, the first cryptocurrency, was introduced in 2008.[2] In July of this year, Japan-based cryptocurrency exchange Bitpoint was also hacked, losing about $32 million in cryptocurrency,[3] and earlier this year, hackers stole $16 million worth of cryptocurrency from New Zealand-based Cryptopia.[4] Losses from cryptocurrency hacks this year alone are reported to have totaled around $1.39 billion worth of assets.[5]
Background
Cryptocurrencies are built on a technology called blockchain a distributed ledger technology in which transactions are recorded across a network of peer-to-peer computers. Since the most well-known cryptocurrency, Bitcoin, together with the underlying blockchain technology, was developed by one or more developers using the pseudonym Satoshi Nakamoto and published in a white paper in 2008,[6] blockchain has been praised for its intrinsic security, as well as qualities that allow cryptocurrency holders to remain largely anonymous. But the same features that have made blockchain an innovative financial technology also make cryptocurrencies an attractive target for theft; once stolen, the nature of blockchain technology makes it extremely difficult to trace the culprits and track down the stolen assets.
Cryptocurrencies generally are based upon a system that uses a public digital key, which is used for identification (similar to a bank account number), and a private digital key (similar to a personal identification number to access that account), which is used for encryption and authentication. The other component of the system is the wallet, which stores cryptocurrencies. Each wallet has a unique address, which is used for sending and receiving funds. A user starts with an address, which in turn generates a private key and a public key using an algorithm; the private key grants the user ownership of the funds at a specified address. When sending funds, the system software identifies the transaction with the private key (without disclosing it), which validates for the benefit of all on the relevant network the authority of the user to transfer the funds from its address (which it does by generating a unique digital signature for every transaction a user undertakes). The public key, which is the public address for the wallet (in effect the address is a representation of the public key) and is intended to be shared, is derived from the private key (that is, the private key generates the public key). At the heart of the cryptography system is the one-way aspect of these components: the public key cannot be derived from the address, and the private key cannot be derived from the public key.
Experts say that one of the safest ways to store cryptocurrency is by using what is known as a hardware wallet.[7] This is an off-line device like a thumb drive, in which a users private keys are stored. These devices often require passwords, backed by sophisticated encryption systems, and multi-factor authentication procedures in order to gain access to the private keys stored on them. (These devices do not store cryptocurrency assets themselves, but rather the private keys associated with the cryptocurrency assets in the blockchain system.) The problem with this system is that it is cumbersome. Accessing funds requires having the hardware wallet on-hand, and then engaging in a lengthy process of opening up the hardware wallet and gaining access to the private keys stored in the wallet. This can make it hard to respond quickly to the highly volatile cryptocurrency marketplace.
The solution to which many resort is keeping their funds on the exchanges they use to buy and sell cryptocurrency (examples include Coinbase, Bittrex and CEX.io). However, since the cryptocurrencies themselves are not actually on the exchanges, what this technically means is that the users are storing their private keys on the exchange. The exchanges therefore act as warehouses of private keys associated with hundreds of millions, and often billions, of dollars in cryptocurrency assets. Not surprisingly given the concentration risk, these exchanges have increasingly become a favorite target for high-value hacks.
Cryptocurrency hacks not only result in significant loss of personal holdings; they also create wild fluctuations in cryptocurrency markets. After a $37 million hack of the Korean exchange Coinrail in 2018, Bitcoin (the first, and most popular cryptocurrency) lost approximately 11% of its market value.[8] A similar drop occurred after hackers stole 120,000 Bitcoins from Hong Kong-based exchange Bitfinex in 2016.[9]
In light of the increasing number of cryptocurrency exchange hacks in recent years, companies that invest in cryptocurrency projects or have significant holdings in cryptocurrencies should keep the following in mind:
What should companies with significant holdings in cryptocurrencies be considering?
Due diligence
Companies considering investing in cryptocurrencies may want to undertake a thorough due diligence analysis of the cybersecurity measures, response protocols, and access controls for their preferred method of storing their private keys, whether that method involves using an exchange, a hardware wallet, or some other method.
Companies may also want to engage outside counsel or retain in-house expertise to advise them as to their legal obligations for how they store their private keys. For example, companies may need to determine whether applicable SEC laws and regulations require the use of a qualified custodian for holding private keys, as well as their obligations for instituting specific controls and response procedures for protecting against the loss of clients assets.
Use offline or hardware wallets
As discussed above, there are few safer ways to secure cryptocurrency assets than using a hardware wallet for maintaining private keys. While these hardware wallets are commercially available, large investors may consider instead engaging computer engineers that can build custom hardware wallets. Similarly, as discussed above, companies may want to consider engaging a reputable, insured, qualified cryptocurrency custodian service for storing private keys.
What should companies that are investing in cryptocurrency businesses be considering?
When investing in a cryptocurrency exchange project, invest heavily in cybersecurity.
Cryptocurrency users have many exchange options, and they tend to be fairly discriminating about which they choose to use based on the exchanges reputations for cybersecurity and history of cyber penetrations. A new cryptocurrency exchange will need to earn a reputation for integrity and cybersecurity in order to attract users (unless, as is sometimes the case, the exchange offers certain desirable cryptocurrencies that are not available on other available exchanges). Nothing will cripple a new cryptocurrency exchange faster than a successful cyber penetration, and the short history of cryptocurrency is rife with now-defunct exchanges that either went bankrupt and/or lost all user confidence after a cyberattack.
If your company is contemplating investing in a cryptocurrency exchange project, robust cybersecurity should be considered. This includes not only technical cybersecurity measures, but also robust cybersecurity policies, compliance and reporting mechanisms, and audit controls. Capable in-house expertise or outside firms can help you develop these procedures, and your company may want to secure this expertise well before your project launches.
When investing in a cryptocurrency blockchain project, develop cyber penetration response policies in advance.
As discussed above, most cryptocurrency hacks do not compromise the blockchain itself, but the exchanges where the transactions occur and the private keys are stored. These hacks can devastate the cryptocurrency market. But a cryptocurrency blockchain or platform can itself be compromised, and when this happens, having the right response procedures in place is critical.
An example of this was seen with Ethereuma blockchain-based smart contract[10] system that used the cryptocurrency Ether to compensate the operators of the computational engine that powers the blockchain system and as a medium for the exchange of value for the performance of smart contracts. In 2016, an organization called the DAO[11] developed a smart contract system built on the Ethereum platform designed to facilitate venture capital fund investment. Hackers exploited a flaw in that smart contract system, resulting in the theft of $50 million worth of Ether. A vote was held within the Ethereum community about how to respond to the hack, with a majority voting to do a hard fork[12] of the Ethereum blockchain. Since the blockchain represents a history of all transactions since its inception, a hard fork is effectively a way to reverse time by erasing the history of the transactions on the blockchain system since the occurrence of the compromising event (hard forks can also be planned events so the rules and protocols governing the blockchain can be updated). This hard fork was extremely controversial within the Ethereum community because it resulted in the reversal of both legitimate and illegitimate transactions, and the value of Ether and confidence in the Ethereum platform temporarily suffered as a result.
One of the reasons the DAO hack was so disruptive to the Ethereum community was because of the debate that ensued within that community over how to respond to it. Thus, companies considering whether to invest in a cryptocurrency project should consider not only how to gird their projects against technical hacks, but also how to develop and disseminate response policies that would give users assurance that the cryptocurrency project would commit to a predictable, controlled course of action in response to various compromising events.
Excerpt from:
VinDAX Is the Seventh Cryptocurrency Exchange Hacked This Year: What Should Investors Be Considering? - Lexology
- Bitcoin Center NYC To Support Wednesday's CryptoCurrency Convention By Hosting After-Party [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- CryptoCurrency.org [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Qoinpro Cryptocurrency Faucet - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Global Issues Cryptocurrency Project - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- cryptocurrency - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- PotCoin @ Cryptocurrency convention NYC, Good Audio - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 2014 - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Unobtanium Cryptocurrency Explained - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- How To Create Your Own Cryptocurrency Co.Labs code ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- CryptoCoinsNews - Cryptocurrency and Bitcoin News with ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Joe Rogan and Reddit Co-founder Alexis Ohanian talk Dogecoin, Cryptocurrency - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- How To Assess A CryptoCurrency: AltCoin Assessment Protocol. What's the next big AltCoin? - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Reggie Middleton's UltraCoin @ NYC CryptoCurrency Convention - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- The future is Nxt (cryptocurrency platform) - Video [Last Updated On: April 19th, 2014] [Originally Added On: April 19th, 2014]
- CryptoCurrency Convention 4/9/14 - Dan Larimer Bitshares - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- CryptoCurrency Convention 4/9/14 - Xavier Hawk Permacredits - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Does a cryptocurrency have the potential to revolutionize Ukraine? - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Marscoin @ CryptoCurrency Convention NYC 4/9/14 - Lennart Lopin - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Vertcoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fisher - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- UltraCoin @ CryptoCurrency Convention NYC 4/9/14 - Reggie Middleton - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- iCoin @ CryptoCurrency Convention NYC 4/9/14 - Ryan Ridgeway - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- The Future of Cryptocurrency, Investing, and Crowdfunding (Toronto #BitcoinExpo Highlights) #548 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- mTrader.org - Cryptocurrency Mining System - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Know How 74 Cryptocurrency - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- CryptoCurrency of the World Unite! - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Bitpagar Cryptocurrency - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- Violincoin - The first cryptocurrency for musician - - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency: Get Mining! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- The Cryptocurrency Store - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- Bitcoin Song - The Cryptocurrency Store - Video [Last Updated On: May 25th, 2014] [Originally Added On: May 25th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Sudbury Cryptocurrency Conference, May 26th: Ethereum - Video [Last Updated On: May 30th, 2014] [Originally Added On: May 30th, 2014]
- 2014 Cubieboard 1, 2 - Mining Peercoins (SHA-256 based) Cryptocurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- 2nd Salaries in CryptoCurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- The Best Cryptocurrency Trading Platform - Video [Last Updated On: June 3rd, 2014] [Originally Added On: June 3rd, 2014]
- Cryptocurrency business forum - Video [Last Updated On: June 4th, 2014] [Originally Added On: June 4th, 2014]
- Cryptocurrency Opportunities in Southeast Asia | John KIM - Video [Last Updated On: June 7th, 2014] [Originally Added On: June 7th, 2014]
- Facebook Approves Cryptocurrency Tipping Apps -- Bitcoin Weekend In San Francisco - Video [Last Updated On: June 8th, 2014] [Originally Added On: June 8th, 2014]
- Wolf of Wall Street & Cryptocurrency w/ Patrick "PK" McDonnell - Video [Last Updated On: June 9th, 2014] [Originally Added On: June 9th, 2014]
- BankNote CryptoCurrency Review - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- CryptoCurrency 4 Housing for Father's Day! - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- Hyper CryptoCurrency Review - Video [Last Updated On: June 14th, 2014] [Originally Added On: June 14th, 2014]
- 0NE " EPIC " (HD dubstep mix) spot - a cryptocurrency with an Engine - Video [Last Updated On: June 15th, 2014] [Originally Added On: June 15th, 2014]
- Bitcoin,Litecoin mining rig cryptocurrency 2500W system, 6x 280x ASUS Beast 2014 - Video [Last Updated On: June 17th, 2014] [Originally Added On: June 17th, 2014]
- The Rundown Live #281 Tatiana Moroz (Chemtrails,CryptoCurrency,Anti-War) - Video [Last Updated On: June 19th, 2014] [Originally Added On: June 19th, 2014]
- Neutrality Coin New Alternative Cryptocurrency - Video [Last Updated On: June 20th, 2014] [Originally Added On: June 20th, 2014]
- Cryptocurrency Update - Buy Low, Sell High! - Video [Last Updated On: June 21st, 2014] [Originally Added On: June 21st, 2014]