Connect with us

Market

The Survival Story of FixedFloat

Published

on


In February, the decentralized cryptocurrency exchange FixedFloat experienced a drainer attack, resulting in the loss of over $26 million worth of Bitcoin (BTC) and Ethereum (ETH). By late March, the exchange suffered a second exploit, leading to an additional loss of $2.8 million.

A few months later, FixedFloat shared the details of these incidents and ongoing investigation with BeInCrypto.

FixedFloat has been hacked twice this year. How did this happen?

The first hack occurred on the night of February 16-17. This was an external attack caused by vulnerabilities in our security structure. A hacker exploited a vulnerability in our security and was able to gain access to some of FixedFloat’s functions. The second breach took place on March 31, where the hacker exploited a vulnerability in a third-party service we were using at the time.

Was the second hack committed by the same hacker who committed the previous hack, or was it a different attacker?

We believe the same hacker committed both hacks because the attacks originated from the same IP address. We cannot provide all the details at the moment. However, we can report that hackers possess a large number of compromised servers.

On some of these servers, they have deployed the infrastructure for attacks. They likely did not store evidence on their own devices, instead using third-party servers. The hackers utilized numerous unique IP addresses; however, some were used to launch both attacks.

Do you have information about who exactly is behind the hacks?

We have been using Time4VPS hosting for a long time. This is a fairly large web hosting provider in Europe, operating since 2012. We chose Time4VPS for our purposes, since this hosting offers fairly cheap servers with low performance. This was a convenient and profitable option for implementing some technical solutions at the initial stage of development of our project.

Over the past years, we have migrated our subservers and wallets. At the beginning of 2024, several low-power nodes with wallets and some subsystems remained on the Time4VPS server. After the first hack, the hacker discovered the IP address of one of our technical servers rented from Time4VPS.

How did the hacker use the information?

The hacker logged into all our servers, rented from Time4VPS hosting, simultaneously, despite knowing only one IP address. We immediately changed all passwords on servers and accounts, but the hacker quickly changed the passwords again. We found a solution to prevent server authorization and started transitioning from this hosting provider.

However, the hacker gained access to all hoster functions, including global access to all servers, rendering our solutions ineffective. The hacker changed the account email to an invalid one, preventing us from logging in or receiving password change notifications. They connected to the servers without authorization.

At this point, we realized the need to destroy the servers and remove them from the whitelists immediately. Our delay in doing so allowed the hacker to send requests that enabled them to steal funds.

Peckshield report
Peckshield Report on First Hack. Source: Peckshield

Have you contacted Time4VPS support?

On March 31, immediately after discovering unauthorized access to our servers, we contacted Time4VPS to report the hack. We were extremely surprised by their inaction. Technical support informed us that the technicians had the day off and could not assist us. The following day, the Time4VPS team remained inactive. They merely advised us to change the passwords on our account.

We eventually convinced them to verify that certain actions could not be performed through their personal account. Only then did they confirm the hack and promise to provide a report on the incident the next day.

Have you received a hack report from Time4VPS?

More than three months have passed, and there is still no report from Time4VPS. Instead, they requested that we provide some documents through their system. We refused because Time4VPS representatives have not confirmed that they found and fixed the vulnerability. Their demands have created the risk of another information leak.

We agreed to cooperate only with the direct involvement of law enforcement or after they confirmed the vulnerability had been corrected. Additionally, our lawyer was prepared to provide the necessary documents directly at the company’s office to receive reports and assistance. However, Time4VPS management rejected this offer.

Why do you think Time4VPS was inactive at the time of the hack and did not provide assistance after it?

We do not exclude the possibility that a hoster’s employee could have facilitated the hacking. However, we are more inclined to believe that Time4VPS and the Lithuanian company behind it are simply careless. We believe the hoster’s critical vulnerabilities remain unfixed, leaving all their clients’ data unprotected from hacker attacks.

Did the hack impact your customers?

This incident caused problems not only for us but also for our users. As soon as we detected the hack, we turned off FixedFloat and suspended all ongoing exchanges.

FixedFloat is an automated, non-custodial, centralized cryptocurrency exchange service, so we don’t store our users’ funds. Additionally, FixedFloat is not a cryptocurrency mixer. We send funds to exchanges only from our addresses, and this information is public.

Due to the hack, we had obligations to clients who made exchanges at that time. We have since fulfilled all obligations to our users, and completed all orders that stopped due to the service outage. Only our service suffered from the hacking and theft of funds.

What measures did you take after the hack?

The first breach was due to a security vulnerability, which we have since fixed. Unfortunately, we did not anticipate an attack from third parties. Following the second hack, our service was under maintenance for over two months. During this period, our specialists worked extensively to enhance our infrastructure and protect against such attacks.

We have radically revised our security system. This included conducting a comprehensive audit, implementing additional security measures, and improving our threat detection and prevention systems.

Have you completed the technical work?

Yes, FixedFloat has resumed operations. Most cryptocurrencies are already available for exchange, and our specialists are working on adding new currencies. We have been providing high-quality, convenient, and fast cryptocurrency exchange services for six years, and we intend to continue our work.

From a hack survivor perspective, can you give a few recommendations to other platforms and its users on how to increase security?

As a service that has experienced two hacks for different reasons, we’d recommend the following:

  • Conduct frequent audits of your security systems. Identify and address all vulnerabilities promptly.
  • Plan for Provider Vulnerabilities. The second hack exploited a vulnerability in our hosting provider, Time4VPS. Platforms should anticipate such scenarios and have a robust procedure for dealing with service provider hacks.
  • Always prioritize user safety. Implement strict security measures and protocols to protect user data and funds.

What steps are you taking to regain the trust of your users following these accidents?

We are actively engaging with our users through various communication channels, including social networks and forums. This allows us to inform them about the changes we have made. Currently, not all users are aware that FixedFloat has resumed operations, but we are working to spread this information.

We understand that many were concerned about the hack’s impact on our users. However, we emphasize that we are a non-custodial service and do not store user funds. Orders that were not fulfilled due to the emergency shutdown have been completed. At present, we have no financial obligations to our users.

Disclaimer

In compliance with the Trust Project guidelines, this opinion article presents the author’s perspective and may not necessarily reflect the views of BeInCrypto. BeInCrypto remains committed to transparent reporting and upholding the highest standards of journalism. Readers are advised to verify information independently and consult with a professional before making decisions based on this content.  Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Market

TRON to Launch Gas-Free Stablecoin Transfers in Q4 2024

Published

on

By


TRON founder Justin Sun announced that his team is developing a stablecoin solution to increase institutional adoption of such assets.

On July 6, Sun revealed that a gas-free stablecoin solution will launch on the TRON network in the fourth quarter of this year.

Gas-Free Stablecoin Solution

Sun explained that this innovation means users will not need to pay a gas fee for stablecoin transactions. Instead, the stablecoins will cover the fees themselves. This solution will initially be available on the TRON Network before expanding to Ethereum and other Ethereum Virtual Machine (EVM)-compatible public chains.

“Our team is developing a new solution that enables gas-free stablecoin transfers. In other words, transfers can be made without paying any gas tokens, with the fees being entirely covered by the stablecoins themselves,” Sun stated.

Sun added that this development could help TRON become the first blockchain to surpass one billion addresses. TRON gained prominence by offering affordable stablecoin access, making it the second-largest network for such assets after Ethereum. TRON controls around 36% of the stablecoin market, with Tether dominating 99% of its $58 billion stablecoin supply.

Read more: A Guide to the Best Stablecoins in 2024

Tron Stablecoin
TRON Stablecoin Market Cap. Source: DeFillama

Despite facing regulatory challenges and allegations of misuse by fraudsters, Sun believes this solution will further drive institutional stablecoin adoption. Over the years, stablecoins have become one of the most successful real-world applications in the emerging industry, especially after payment giants like PayPal launched theirs.

Stablecoins, typically pegged to the US dollar, offer a stable alternative to volatile digital assets like Bitcoin. In emerging markets, crypto users use these assets to hedge against depreciating national currencies and as a payment method for goods and services.

Read more: 10 Platforms That Provide the Best Interest Rate on Stablecoins

Market experts predict that demand for these assets will continue to grow. Visa notes that this growth is helping it catch up with established settlement networks. Due to this, regulatory efforts in various countries, including the United States, aim to bring these assets into compliance due to their high adoption rate.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.



Source link

Continue Reading

Market

1 in 4 US Voters Likely to Invest in Ethereum ETFs

Published

on

By


A survey by Grayscale and The Harris Poll indicates that US Securities and Exchange Commission (SEC) approval of a spot Ethereum (ETH) exchange-traded funds (ETFs) would likely boost American investment in the digital asset.

Though the long-term performance of these ETFs is uncertain, the poll suggests their introduction will significantly advance the crypto market’s maturity and mainstream adoption.

Ethereum ETF Will Drive Adoption

The poll reveals that nearly one in four likely voters would consider investing in Ethereum if an ETF-based product were approved. This approval would increase their interest in Ethereum and other crypto assets beyond Bitcoin.

Read more: Ethereum ETF Explained: What It Is and How It Works

US Investors interest in Ethereum
US Investors Interest in Ethereum ETF. Source: Grayscale

Grayscale’s findings support analysts’ predictions about Ethereum ETFs’ potential success. Quinn Thompson, founder of Leker Capital, referencing Neil Osborne, stated that the ETH ETF is a proxy for traditional investors who lack exposure to blockchain and crypto beyond digital gold.

“By investing in Ethereum you’re getting exposure to stablecoins/payments, tokenization, DeFi, digital art/NFTs, infrastructure/staking/layer 2 scaling. All of this new technology is built on Ethereum and pays fees for its usage and activity which accrues as revenue to the ETH network and token,” Quinn explained.

This perspective leads many market experts to anticipate significant investment inflows once trading begins. Charles Yu, Vice President of Research at Galaxy Digital, estimated that ETH ETFs might attract up to $1 billion in monthly inflows during the first five months. Similarly, Bitwise CIO Matthew Hougan predicted $15 billion in inflows within the first 18 months.

Despite the potential for high success, 25% of Grayscale respondents said that ETF approval would not influence their investment interest. The survey also highlighted that a considerable portion of the population remains unfamiliar with spot Ethereum ETF. It shows that around 43% of US voters were unaware of it.

Read more: Crypto ETN vs. Crypto ETF: What Is the Difference?

Ethereum ETF Survey
Ethereum ETF Survey. Source: Grayscale

Meanwhile, the survey shows crypto has become an increasingly important subject for American voters. According to the survey, a third of American likely voters have become more open to crypto since the beginning of this year, and 47% of them believe that crypto will eventually wind up in their investment portfolios.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.



Source link

Continue Reading

Market

Where Will Bitcoin (BTC) Price Head Amidst Liquidations?

Published

on

By


Bitcoin’s (BTC) price has barely recovered from the debacle of momentum witnessed over the last few days. 

Nevertheless, the cryptocurrency appears to be under the threat of further drawdown due to not bearishness but bullishness of the investors.

Bitcoin Faces a Challenge

Bitcoin’s price fell from $62,000 to $53,300, shocking the crypto market and killing many bullish dreams. The futures market registered long liquidations amounting to $263 million in three days.

This is the second-highest liquidation in the last two weeks, with the previous high noted three months ago in April. Generally, such high liquidations tend to calm investors down and make them step back to let the market cool down.

Read more: How To Buy Bitcoin (BTC) and Everything You Need To Know

Bitcoin Long Liquidations.
Bitcoin Long Liquidations. Source: Coinglass

However, BTC holders do not seem to agree with this opinion. The drawdown is considered to be facing the impact of Federal Reserve Chair Jerome Powell’s bearish speech earlier this week. Thus, the investors expect a quick recovery and are prepared to profit from it.

Analyst Willy Woo highlighted this in his explanation of the difference between buying futures and buying spot. He denoted that the former results in a bearish environment and stated that this could cause further losses.

According to the Bitcoin Open Value Oscillator, about half a million long contracts are still open in the futures market. Should Bitcoin’s price fall further, these longs could be liquidated. This will result in an extended period of bearishness for BTC.

Bitcoin Open Value Oscillator
Bitcoin Open Value Oscillator. Source: Willy Woo

BTC Price Prediction: Validating the Pattern

Bitcoin’s price, trading at $56,961 at the time of writing, is stabilizing after nearly falling to $53,300 yesterday. The cryptocurrency has yet to fulfill the expected 17% drawdown arising from the double top formation from four months ago.

This prediction targets a drop to $50,900, which will lead to massive long liquidations, as mentioned above. Should BTC lose its support of $55,000, this would become more probable.

Read More: Bitcoin (BTC) Price Prediction 2024/2025/2030

Bitcoin Price Analysis.
Bitcoin Price Analysis. Source: TradingView

On the other hand, if Bitcoin’s price manages to bounce back from $55,000 and flip $58,800 into support again, recovery could begin. This would enable a rise to $60,000 to invalidate the bearish thesis.

Disclaimer

In line with the Trust Project guidelines, this price analysis article is for informational purposes only and should not be considered financial or investment advice. BeInCrypto is committed to accurate, unbiased reporting, but market conditions are subject to change without notice. Always conduct your own research and consult with a professional before making any financial decisions. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.



Source link

Continue Reading
Advertisement

Trending

Copyright © 2024 coin2049.io