Cybercriminals hunt for vulnerabilities to hack crypto exchanges.
Cross-Site Scripting (XSS) attacks may insert malicious code into web pages in most online trading terminals. This code frequently sends traders to third-party websites or infects their devices. This malware may steal wallet passwords or change the clipboard sender's address.
Web terminals may lack HTTP headers that prevent some hacker attacks. XSS is prevented via the Content-Security-Policy response header. The X-Frame-Options header prevents clickjacking, whereas Strict-Transport-Security enforces HTTPS.
About 0.3 mistakes per 1000 lines of code. These flaws might undermine platform security. Even if exchange developers build error-free code, third-party applications may be vulnerable. Security flaws in the payment gateway, operating system, or messaging platform may be used to phish or install malware on exchange workers' devices.
Hackers may steal money from wallets by exploiting smart contract code weaknesses. A targeted wallet attack or a mass assault on wallets with the same vulnerability may occur.
False exchange representatives may use spear phishing to access workers' PCs. Finding private keys might take months of diligent work. Hacking a personal account is easier with bogus mobile applications.
If attackers know a person trades or manages a cryptocurrency exchange, they may intercept their SMS texts and exploit them during authentication or access recovery. Possible hacking methods:Wiretapping, SIM card cloning, false base station, carrier web platform hack,SS7 attack, contact center phishing
Hacked Crypto Exchanges
Mt.Gox
Tokyo-based crypto exchange Mt. Gox established in 2010. As the world's biggest cryptocurrency exchange, it handled over 70% of bitcoin transactions. Hackers stole $8.75m in bitcoin from the exchange in 2011.
After promising to increase security, the exchange was attacked again in 2014. Larger scale was used this time. Nearly 850,000 bitcoins ($615m) were stolen. They did this by flooding the exchange with bogus bitcoins. This bitcoin security leak was one of the earliest.
The corporation was sued by consumers, suppliers, and partners over the breach. Mark Karpeles, the exchange's CEO, was involved in several of them because he didn't employ version control software for the site's source code.
Any developer might mistakenly overwrite the site's code, exposing the system. These lawsuits haven't assisted exchange users yet. The Tokyo District Court is reviewing the exchange's civil rehabilitation plan to reimburse consumers.
KuCoin
KuCoin is a Singaporean crypto exchange. The 2013-founded company trades Bitcoin, Ethereum, Litecoin, and Ardor. It was robbed of $281m in coins and tokens in September 2020.
Hackers stole keys to several of the exchange's most popular wallets. KuCoin promptly banned all website transactions, but the harm was done. This is one of the biggest crypto asset breaches.
After that, KuCoin management investigated thoroughly. Over $204m was recovered in weeks thanks to this quick action. The conversation identified prospective culprits, a major breakthrough.
A North Korean cyber gang is suspected of the attack. This scenario emphasizes the need for speed and real-time transaction tracking. The exchange also plans to compensate any customer losses.
Binance
Binance is a major player. The Cayman Islands-based exchange is the world's biggest cryptocurrency exchange by volume. It operates in over 1200 marketplaces and offers 360 coins.
Additionally, Binance claims to have created an ecosystem of crypto transactions, research, training, and philanthropy. In May 2019, the exchange suffered a severe security breach.
Hackers took almost 7000 bitcoins from its hot wallet. About $40m was lost in the assault. Attackers breached the exchange's security and stole two-factor codes, APIs, and other data.
Surprisingly, one cryptocurrency wallet had all the lost bitcoins. The exchange claims its safe asset fund for users (SAFU) covers any losses.
These are several cryptocurrency exchanges where hackers stole bitcoins. Visit the links below to see the hacking events chronologically.
1-https://chainsec.io/exchange-hacks/
2-https://selfkey.org/list-of-cryptocurrency-exchange-hacks/
Important Notice:Searching for stuff takes hours, and I attempt to tell people strictly. Due to this year's halving. Everyone should be affluent throughout the halving time. So please help me with the reference link I'll provide.
Crypto.com: https://crypto.com/app/gyhxw9j7h3 to sign up for Crypto.com and we both get $25 USD :)