Huobi fixes data breach involving sensitive information for 4,960 users

TL;DR Breakdown

  • Crypto exchange Huobi has fixed its data breach after a massive data leak that allegedly put users’ funds at risk since June 2021
  • The exchange risked exposure of its sensitive information, such as VIP user data and technical infrastructure of the exchange
  • However, it took months for the exchange to respond to the white hat hacker

Description

Crypto exchange Huobi has fixed its data breach after a massive data leak that allegedly put users’ funds at risk since June 2021. The data leak had information on almost all the over-the-counter (OTC) transaction information from 2017 to 2021, with some of the data being VIP user data and information on the technical infrastructure … Read more

Crypto exchange Huobi has fixed its data breach after a massive data leak that allegedly put users’ funds at risk since June 2021. The data leak had information on almost all the over-the-counter (OTC) transaction information from 2017 to 2021, with some of the data being VIP user data and information on the technical infrastructure of the exchange.

Huobi risked exposure of its sensitive information 

White hat hacker and citizen journalist Aaron Phillips disclosed the Huobi data breach. The white hacker explained that an attacker exploiting Huobi’s vulnerability would have had the opportunity to achieve the largest crypto theft in history. Anyone accessing the exchange’s credentials could have changed their domains, including hbfile.net and huobi.com. In addition, their internal documents and user data could be exposed.

According to previous reports, the company handles over a billion dollars daily in trading volume. Hence, users’ accounts and crypto assets would have been stolen if they hadn’t taken action to fix the leak. Phillips emphasized the potential for malicious scripts to be injected into Huobi’s content delivery networks (CDNs) and websites. According to him, the CDNs might have compromised all Huobi login pages, possibly harming anyone who used a Huobi website or app over the previous two years.

The exchange risks exposure to sensitive information, including the contact information and account balances of cryptocurrency users, and it puts customers at risk of losing their accounts and crypto assets. According to Phillips, this includes Huobi’s over-the-counter (OTC) trade data as well as a database of cryptocurrency whales. He confirmed, however, that no breach was carried out using the data leak.

Huobi fixes data breach

According to the exchange, which confirmed the occurrence, it was caused by the appropriate staff members’ irregular conduct in the S3 barrel of the Japanese station’s test environment. On October 8, 2022, all pertinent user data was isolated. 

The exchange asserted that the leakage was small-scale, involving 4,960 individuals. It added that the leaked information did not have sensitive information and never affected user accounts and the security of their assets. 

Huobi further stated that the Huobi Japanese and Huobi Global sites are separate entities. On June 21, 2023, the Huobi Security Team immediately took action after being alerted by a white hat team, instantly closing the associated file access permissions. According to the exchange, the issue has been resolved, and all associated user data has been removed. Huobi has since deleted the affected account, and no users are at risk anymore.

Despite the issue being resolved now, Phillips mentioned that it took months for the exchange to respond, and the leaked data remained online even after he gave Huobi the first notice in June 2022.

Crypto exchanges are prone to data breaches since they have access to a lot of customer data that can be used to steal funds by hackers. Coinsquare, a Canadian crypto exchange, suffered a data breach in November 2022. Its users’ information was exposed, such as phone numbers, names of investors, birth dates, public wallet addresses, and transaction history. However, the exchange affirmed that there were no passwords accessed, and the information is yet to be detected by bad actors.

Gemini Exchange also experienced a data breach that saw 5.7 million users stolen and leaked on hacking forums. Posts advertising the data from the breach first surfaced in September last year, with the data offered for 30 BTC, about $520,000. The same data was posted in November, offering the data and additional data from other exchanges. In another forum, later on, the data was offered for free. Gemini has since asked its clients to implement two-factor authentication and use hardware security keys to prevent hacking and accessing their funds.

The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Huobi fixes data breach involving sensitive information for 4,960 users

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月5日 12:00
Next 2023年7月5日 13:23

Related articles

  • WATCH: US Congressman disses Satoshi Nakamoto, and it is so good

    TL;DR Breakdown U.S. Congressman Brad Sherman criticized Bitcoin creator Satoshi Nakamoto during a recent Financial Services Committee crypto hearing. Sherman argued that traditional money production benefits the U.S. economy and citizens, and crypto developers aim to monopolize this. The congressman’s comments added a new level of skepticism to the ongoing crypto debate. Description A volley of hilarious critique and skepticism launched by U.S. Congressman Brad Sherman reverberated through the cavernous halls of a recent crypto hearing. Emanating from the Financial Services Committee, his acerbic remarks were squarely aimed at Satoshi Nakamoto, the enigmatic creator of Bitcoin. What’s his deal? Brad Sherman, the longstanding representative for California’s 32nd Congressional … Read more A volley of hilarious critique and skepticism launched by U.S. Congressman Brad Sherman reverberated through the cavernous halls of a recent crypto hearing. Emanating from the Financial Services Committee, his acerbic remarks were squarely aimed at Satoshi Nakamoto, the enigmatic creator of Bitcoin. What’s his deal? Brad Sherman, the longstanding representative for California’s 32nd Congressional District, ignited controversy with his biting critique of the crypto industry and, more specifically,…

    Article 2023年7月27日
  • Dogecoin price goes on a wild ride after Elon Musk’s cryptic tweet

    TL;DR Breakdown Dogecoin (DOGE) experienced a sudden and dramatic price surge of 3% within a span of just one minute.  Remarkably, a mere three hours after Musk’s tweet, the price of Dogecoin plummeted by over 5% at one point, completely erasing the earlier gains and leaving the token a few percentage points lower than before. Description In a surprising turn of events, Dogecoin (DOGE) experienced a sudden and dramatic price surge of 3% within a span of just one minute. The catalyst behind this rapid rise was none other than Elon Musk, the charismatic billionaire and prominent figure behind companies like Tesla, SpaceX, and Twitter. Known for his playful interactions with … Read more In a surprising turn of events, Dogecoin (DOGE) experienced a sudden and dramatic price surge of 3% within a span of just one minute. The catalyst behind this rapid rise was none other than Elon Musk, the charismatic billionaire and prominent figure behind companies like Tesla, SpaceX, and Twitter. Known for his playful interactions with the crypto community, Musk responded to a question on Twitter about…

    Article 2023年7月18日
  • CFTC warns clearing organizations of risks associated with digital assets

    TL;DR Breakdown The CFTC has issued a staff advisory letter to derivatives clearing organizations (DCOs) regarding the risks of expanding activities, specifically focusing on digital assets. The advisory emphasizes the importance of proactive risk management and highlights concerns related to system safeguards, conflicts of interest, and physical deliveries. Commissioner Kristin Johnson calls for the CFTC to initiate a formal rule-making process to establish stricter regulations for crypto-commodity derivatives clearing models. The United States Commodity Futures Trading Commission (CFTC) has issued a staff advisory letter to registered derivatives clearing organizations (DCOs) and DCO applicants, cautioning them about the risks involved in expanding the scope of their activities. In particular, the letter highlighted the risks associated with digital assets, signaling the CFTC’s increased focus on the emerging crypto market. Increased interest in digital assets prompts CFTC advisory The advisory letter, released by the CFTC Division of Clearing and Risk (DCR), emphasized the importance of proactive risk management. The DCR urged DCOs and applicants to actively identify and mitigate new, evolving, or unique risks from their involvement with digital assets. This move comes…

    Article 2023年6月3日
  • EthCC 2023 recap: A new era of interchain cooperation and decentralized development

    TL;DR Breakdown EthCC 2023 showcased a range of innovative projects and features, with a significant focus on Lens Protocol’s V2 update. Jesse Pollak, Coinbase’s director of Base, shared insights on the decentralized future of layer-2 blockchains. The EthCC 2023 event highlighted the imminent paradigm shift in decentralized social networking and blockchain technology. Description The Ethereum community’s recent EthCC 2023 event witnessed various innovative projects and exciting new features. Polygon’s decentralized social networking platform, Lens Protocol, introduced its highly-anticipated V2 update, promising many cutting-edge enhancements. One of the standout features in Lens Protocol’s V2 update is “Open Actions.” This groundbreaking addition enables third-party smart contracts to engage in real-time … Read more The Ethereum community’s recent EthCC 2023 event witnessed various innovative projects and exciting new features. Polygon’s decentralized social networking platform, Lens Protocol, introduced its highly-anticipated V2 update, promising many cutting-edge enhancements. One of the standout features in Lens Protocol’s V2 update is “Open Actions.” This groundbreaking addition enables third-party smart contracts to engage in real-time interactions with Lens postings. This means that users on OpenSea can now include content…

    Article 2023年7月25日
  • PancakeSwap expands to zkSync era, enhancing DeFi scalability

    TL;DR Breakdown PancakeSwap has launched on zkSync Era, improving scalability and efficiency. The launch is part of a trend of DeFi platforms using Layer 2 solutions for mass adoption. zkSync Era offers reduced gas costs and faster transactions, recently surpassing Ethereum’s daily transactions. Description In a significant development for the DeFi sector, PancakeSwap, the leading decentralized exchange (DEX) on the Binance Chain, has announced its launch on zkSync Era, an Ethereum Layer 2 network. This move is set to enhance the scalability and efficiency of the DEX, offering users reduced gas costs and faster transaction times. PancakeSwap v3 currently … Read more In a significant development for the DeFi sector, PancakeSwap, the leading decentralized exchange (DEX) on the Binance Chain, has announced its launch on zkSync Era, an Ethereum Layer 2 network. This move is set to enhance the scalability and efficiency of the DEX, offering users reduced gas costs and faster transaction times. PancakeSwap v3 currently supports swaps and liquidity providing (LP), with yield farming and LP token staking set to come online in the coming weeks. The exchange…

    Article 2023年7月29日
TOP