Market
The Survival Story of FixedFloat
In February, the decentralized cryptocurrency exchange FixedFloat experienced a drainer attack, resulting in the loss of over $26 million worth of Bitcoin (BTC) and Ethereum (ETH). By late March, the exchange suffered a second exploit, leading to an additional loss of $2.8 million.
A few months later, FixedFloat shared the details of these incidents and ongoing investigation with BeInCrypto.
FixedFloat has been hacked twice this year. How did this happen?
The first hack occurred on the night of February 16-17. This was an external attack caused by vulnerabilities in our security structure. A hacker exploited a vulnerability in our security and was able to gain access to some of FixedFloat’s functions. The second breach took place on March 31, where the hacker exploited a vulnerability in a third-party service we were using at the time.
Was the second hack committed by the same hacker who committed the previous hack, or was it a different attacker?
We believe the same hacker committed both hacks because the attacks originated from the same IP address. We cannot provide all the details at the moment. However, we can report that hackers possess a large number of compromised servers.
On some of these servers, they have deployed the infrastructure for attacks. They likely did not store evidence on their own devices, instead using third-party servers. The hackers utilized numerous unique IP addresses; however, some were used to launch both attacks.
Do you have information about who exactly is behind the hacks?
We have been using Time4VPS hosting for a long time. This is a fairly large web hosting provider in Europe, operating since 2012. We chose Time4VPS for our purposes, since this hosting offers fairly cheap servers with low performance. This was a convenient and profitable option for implementing some technical solutions at the initial stage of development of our project.
Over the past years, we have migrated our subservers and wallets. At the beginning of 2024, several low-power nodes with wallets and some subsystems remained on the Time4VPS server. After the first hack, the hacker discovered the IP address of one of our technical servers rented from Time4VPS.
How did the hacker use the information?
The hacker logged into all our servers, rented from Time4VPS hosting, simultaneously, despite knowing only one IP address. We immediately changed all passwords on servers and accounts, but the hacker quickly changed the passwords again. We found a solution to prevent server authorization and started transitioning from this hosting provider.
However, the hacker gained access to all hoster functions, including global access to all servers, rendering our solutions ineffective. The hacker changed the account email to an invalid one, preventing us from logging in or receiving password change notifications. They connected to the servers without authorization.
At this point, we realized the need to destroy the servers and remove them from the whitelists immediately. Our delay in doing so allowed the hacker to send requests that enabled them to steal funds.
Have you contacted Time4VPS support?
On March 31, immediately after discovering unauthorized access to our servers, we contacted Time4VPS to report the hack. We were extremely surprised by their inaction. Technical support informed us that the technicians had the day off and could not assist us. The following day, the Time4VPS team remained inactive. They merely advised us to change the passwords on our account.
We eventually convinced them to verify that certain actions could not be performed through their personal account. Only then did they confirm the hack and promise to provide a report on the incident the next day.
Have you received a hack report from Time4VPS?
More than three months have passed, and there is still no report from Time4VPS. Instead, they requested that we provide some documents through their system. We refused because Time4VPS representatives have not confirmed that they found and fixed the vulnerability. Their demands have created the risk of another information leak.
We agreed to cooperate only with the direct involvement of law enforcement or after they confirmed the vulnerability had been corrected. Additionally, our lawyer was prepared to provide the necessary documents directly at the company’s office to receive reports and assistance. However, Time4VPS management rejected this offer.
Why do you think Time4VPS was inactive at the time of the hack and did not provide assistance after it?
We do not exclude the possibility that a hoster’s employee could have facilitated the hacking. However, we are more inclined to believe that Time4VPS and the Lithuanian company behind it are simply careless. We believe the hoster’s critical vulnerabilities remain unfixed, leaving all their clients’ data unprotected from hacker attacks.
Did the hack impact your customers?
This incident caused problems not only for us but also for our users. As soon as we detected the hack, we turned off FixedFloat and suspended all ongoing exchanges.
FixedFloat is an automated, non-custodial, centralized cryptocurrency exchange service, so we don’t store our users’ funds. Additionally, FixedFloat is not a cryptocurrency mixer. We send funds to exchanges only from our addresses, and this information is public.
Due to the hack, we had obligations to clients who made exchanges at that time. We have since fulfilled all obligations to our users, and completed all orders that stopped due to the service outage. Only our service suffered from the hacking and theft of funds.
What measures did you take after the hack?
The first breach was due to a security vulnerability, which we have since fixed. Unfortunately, we did not anticipate an attack from third parties. Following the second hack, our service was under maintenance for over two months. During this period, our specialists worked extensively to enhance our infrastructure and protect against such attacks.
We have radically revised our security system. This included conducting a comprehensive audit, implementing additional security measures, and improving our threat detection and prevention systems.
Have you completed the technical work?
Yes, FixedFloat has resumed operations. Most cryptocurrencies are already available for exchange, and our specialists are working on adding new currencies. We have been providing high-quality, convenient, and fast cryptocurrency exchange services for six years, and we intend to continue our work.
From a hack survivor perspective, can you give a few recommendations to other platforms and its users on how to increase security?
As a service that has experienced two hacks for different reasons, we’d recommend the following:
- Conduct frequent audits of your security systems. Identify and address all vulnerabilities promptly.
- Plan for Provider Vulnerabilities. The second hack exploited a vulnerability in our hosting provider, Time4VPS. Platforms should anticipate such scenarios and have a robust procedure for dealing with service provider hacks.
- Always prioritize user safety. Implement strict security measures and protocols to protect user data and funds.
What steps are you taking to regain the trust of your users following these accidents?
We are actively engaging with our users through various communication channels, including social networks and forums. This allows us to inform them about the changes we have made. Currently, not all users are aware that FixedFloat has resumed operations, but we are working to spread this information.
We understand that many were concerned about the hack’s impact on our users. However, we emphasize that we are a non-custodial service and do not store user funds. Orders that were not fulfilled due to the emergency shutdown have been completed. At present, we have no financial obligations to our users.
Disclaimer
In compliance with the Trust Project guidelines, this opinion article presents the author’s perspective and may not necessarily reflect the views of BeInCrypto. BeInCrypto remains committed to transparent reporting and upholding the highest standards of journalism. Readers are advised to verify information independently and consult with a professional before making decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.
Market
Ethereum Price Can Reach $3,500 On The Back Of These Factors
Ethereum, the second-largest cryptocurrency, recently failed to breach $3,524, triggering a sharp price drop. Since then, recovery efforts have remained weak as volatility persists.
However, the current conditions suggest Ethereum may be preparing for a comeback as the market stabilizes.
Ethereum Has Room For Recovery
Ethereum’s Network Value to Transaction (NVT) Ratio is experiencing a decline, recently hitting a monthly low. A low NVT indicates that transaction activity is balanced with network value, reflecting reduced volatility. This creates an environment conducive to price recovery, something Ethereum urgently needs to regain its footing.
With the NVT ratio signaling healthy network activity, Ethereum is positioned to stabilize in the short term. Declining volatility often fosters investor confidence, making it more likely for the cryptocurrency to see renewed buying interest. As speculative activity wanes, Ethereum has an opportunity to chart a path toward meaningful recovery.
Ethereum’s realized profits recently dropped to a six-week low, pointing to a significant reduction in selling pressure from investors. This trend highlights the market’s shifting sentiment, with fewer participants looking to offload their holdings. Such conditions could provide Ethereum with the breathing room required to capitalize on broader bullish cues.
The lack of an uptick in realized profits suggests that the selling lull may persist, allowing Ethereum to focus on building upward momentum. With investors holding onto their coins, market conditions are primed for a gradual recovery, provided external factors remain favorable.
ETH Price Prediction: Breaking The Barrier
Ethereum is currently trading near $3,300, just below the critical resistance level of $3,327. Flipping this into support is essential for ETH to initiate a rally toward $3,524, representing a 6% increase from current levels. This move would mark a partial recovery from recent losses.
Breaking through the $3,524 resistance is crucial for Ethereum’s recovery. Achieving this would erase the recent downturn and also position the altcoin for further gains, potentially targeting $3,711. Such a move would underscore Ethereum’s resilience and align with the broader market’s bullish sentiment.
However, failing to establish $3,327 as a support level could stall Ethereum’s recovery. This scenario would leave the cryptocurrency vulnerable to a retracement toward $3,200, undermining recent progress and potentially delaying its path to $3,500.
Disclaimer
In line with the Trust Project guidelines, this price analysis article is for informational purposes only and should not be considered financial or investment advice. BeInCrypto is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Always conduct your own research and consult with a professional before making any financial decisions. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.
Market
Justin Sun, Vitalik Buterin Speak Amid Ethereum Reform Debate
TRON founder Justin Sun has offered a hypothetical plan for Ethereum and the Ethereum Foundation (EF) under his leadership. His remarks come amid controversy over EF’s leadership transformation.
In a series of posts on X (formerly Twitter), Ethereum co-founder Vitalik Buterin outlined the reforms’ goals and progress. He highlighted improvements in technical expertise, ecosystem engagement, and operational efficiency.
Justin Sun Outlines Blueprint for Ethereum Leadership
The TRON executive shared ambitious remarks on how he would lead the Ethereum Foundation if given the opportunity. Sun’s vision, shared on X, outlined a four-point plan to radically restructure EF operations, optimize Ethereum’s economic model, and drive the price of ETH to $10,000.
“If EF and Ethereum were under my leadership, ETH would hit $10,000,” Sun claimed.
Sun proposed an immediate halt to ETH sales for three years to stabilize supply and boost market confidence. He suggested covering EF’s operational costs through DeFi protocols like Aave, staking yields, and stablecoin borrowing, aligning with Ethereum’s deflationary goals.
A key component of his plan involves imposing significant taxes on Layer 2 (L2) solutions, aiming to generate $5 billion annually. The collected taxes would go toward exclusively repurchasing and burning ETH, further enhancing its scarcity and value.
Sun also called for a drastic downsizing of EF staff, retaining only top performers and offering them significant salary increases. This merit-based approach, he argued, would streamline operations and improve efficiency.
Finally, Sun emphasized adjusting node rewards and increasing fee burns to reinforce Ethereum’s deflationary narrative. He proposed redirecting all resources toward Ethereum’s core L1 development, focusing on scalability, security, and adoption. Justin Sun’s plan sparked a mixed response, with some applauding the bold vision.
“These are all very practical suggestions. Please pay attention to them and refer to them, Vitalik Buterin,” core developer 0xSea.eth posed.
Meanwhile, others challenged Sun to focus on TRON and explore bringing decentralized finance (DeFi) to its ecosystem.
“Maybe start with how to make DeFi great on TRON – you should ask your exec team (and yourself), “Why is DeFi nonexistent on TRON despite it being the chain with the most stable coins on it?” If you answer this, maybe TRON can beat eth one day,” ZIGChain co-founder Abdul Rafay Gadit remarked.
Vitalik Buterin Defends Leadership Amid Criticism
Sun’s proposed solution aligns with Vitalik Buterin’s recent post discussing ongoing changes over the past year, some of which have already been implemented. Buterin emphasized goals such as strengthening the EF’s technical leadership and improving collaboration with ecosystem participants. He also addressed concerns, rejecting the notion that the EF might adopt centralized or politically motivated roles.
“…these things aren’t what EF does and this isn’t going to change. People seeking a different vision are welcome to start their orgs,” Buterin articulated.
Aya Miyaguchi, an EF executive, confirmed the ongoing efforts, expressing excitement about forthcoming announcements. She noted that the reforms aim to solidify Ethereum’s position as a global neutral platform while embracing decentralized and privacy-preserving technologies.
The announcement has stirred controversy within the crypto community. Critics argue that the current leadership has failed to manage Ethereum effectively.
“Respectfully, just let new blood take over. You guys can’t even make a simple Twitter account work—how can you be trusted to lead the second biggest blockchain,” Wazz posed.
Another user, Coinmamba, suggested that pressuring Miyaguchi to resign could result in Ethereum reaching new all-time high. Buterin strongly condemned these comments, defending Miyaguchi and calling out the toxicity of such social media rhetoric.
“No. This is not how this game works,” Buterin retorted. “The person deciding the new EF leadership team is me. If you ‘keep the pressure on,’ then you are creating an environment that is actively toxic to top talent. YOU ARE MAKING MY JOB HARDER,” the Ethereum co-founder lamented.
Buterin also refuted specific claims against Miyaguchi, pointing out inaccuracies in translations and misinterpretations of her statements. He reiterated the need for a “proper board” within EF to enhance governance.
Ethereum’s ETH token was trading at $3,305 as of this writing, representing a modest 0.2% surge since Wednesday’s session opened.
Disclaimer
In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.
Market
Dogecoin Holding Time and Whale Activity Spikes
Dogecoin (DOGE), a leading meme coin, is signaling a potential breakout from its narrow trading range.
If this momentum continues, it could reclaim its multi-year high of $0.48, fueled by extended holding periods and increased accumulation by large holders.
Dogecoin Investors Reduce Distribution
The on-chain assessment of DOGE’s performance has revealed a significant spike in the holding time of all its coins transacted in the past seven days. According to IntoTheBlock, this has climbed by 302% during the review period.
The holding time of an asset’s transacted coins represents the average duration tokens are kept in wallets before being sold or transferred.
Longer holding periods like this reduce selling pressure in the DOGE market. This reflects stronger investor conviction, as investors choose to keep their coins rather than sell them.
In addition to reducing selling activity, DOGE whales have increased their holdings over the past week. This is reflected by the 112% uptick in its large holders’ netflow during that period.
An asset’s large holders’ netflow metric tracks the movement of coins into and out of wallets controlled by whales or institutional investors. When this metric spikes, it suggests that these large holders are accumulating more of the asset, signaling increased confidence in its future price movement.
DOGE Price Prediction: Bullish Run Could Continue
If this bullish momentum is maintained, DOGE will extend its weekly 3% spike. As buying pressure strengthens, the meme coin could revisit its four-year high of $0.48.
However, this bullish outlook will be invalidated if accumulation stalls and selling activity recommences. In that scenario, DOGE’s price could slip to $0.29.
Disclaimer
In line with the Trust Project guidelines, this price analysis article is for informational purposes only and should not be considered financial or investment advice. BeInCrypto is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Always conduct your own research and consult with a professional before making any financial decisions. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.
-
Regulation24 hours ago
Acting SEC Chair Uyeda announces new crypto task force
-
Regulation22 hours ago
Turkey rolls out new crypto AML regulations
-
Ethereum18 hours ago
ETH breaks $3,900 as Bitcoin spikes past $103k
-
Regulation19 hours ago
Crypto custody firm Copper withdraws UK registration
-
Ethereum21 hours ago
Ethereum ETFs inflows surge as Bitcoin ETFs see major outflows
-
Market15 hours ago
Weekly Price Analysis: Bitcoin Remains Rangebound while Altcoins Fly
-
Market21 hours ago
Bitcoin price analysis: economic headwinds push price lower
-
Market18 hours ago
Top 4 altcoins to buy before the market fully recovers