How did hackers and thieves steal 400 million worth of digital currency from the exchange in half a year?
Recently, one after another theft of digital currency trading platforms has forced the headlines of various media. Among them, Binance, the world's top ten digital currency trading platform, was stolen by hackers with 7,000 BTC (the market price was 40 million U.S. dollars at the time). The accident instantly attracted the attention of the technology media, bringing the long-lost security issue of the digital currency trading platform back to the public eye.What vulnerabilities led to the theft of these trading platforms? Who can guarantee the safety of users' assets?
1. Recovery of trading platform theft incidents
Since 2019, a total of 8 digital currency trading platforms have officially announced that they have been stolen, only 3 have made official compensation to users, and 1 is the platform's own assets. Among them, Cryptopia, which has prominent security problems, was stolen twice within a month and is currently under maintenance.

The reasons for the theft of the platform include the invasion of the official wallet of the trading platform, hard_fail, verification code hijacking, theft of the private key, and the combination of various attack methods. In the final analysis, the reasons for the stolen trading platform are mainly divided into two categories.One is the defect of the platform’s own technical risk control and defense system. Hackers use security holes to invade the platform and steal digital currency; the other is the lack of internal system of the platform, which leads to the theft of users’ personal information. In particularly bad cases, even leaked transactions personal information phenomenon.
2. Flaws in the platform’s risk control and defense system
The technical risk control system defects of the digital currency trading platform are mainly due to the lack of security attack and defense tests and the failure to deploy a security defense system. For digital currency trading platforms that have not conducted security testing, such as Mercatox, hackers use hard_fail transfer transactions to gain the "trust" of the platform server. It is not difficult to see that the platform's insufficient technical audit and testing capabilities lead to such low-level security incidents. If the platform seeks a third-party organization to do a security inspection before the contract goes online, thousands of EOS will not be stolen. Of course, there are only a very small number of trading platforms with flaws in security testing, but this link needs to be strengthened.

Most trading platforms mainly have deficiencies in the deployment of risk control and defense systems, such as BiKi and Binance.BiKi’s official announcement after the incident pointed out that hackers hijacked users’ third-party service provider verification code text messages to attack some users who did not bind Google’s verification code. This exposes the problems of its own risk control system. First, it ignores the hijacking of a single verification user. Second, it does not restrict withdrawals and transactions for a certain period of time for accounts that change login and transaction passwords. Third, it does not establish user security awareness. .Fortunately, BiKi did not approve these withdrawals at that time, otherwise the losses would be further expanded.
Compared with Internet financial companies, digital currency trading platforms have deficiencies in their risk control and defense systems. Taking Binance as an example, although Binance used the SAFU fund to bear all the losses of this accident to avoid the loss of users, this kind of compensation is not perfect and cannot cope with compensation for a wider range of security incidents. The main reason for this accident is There are deficiencies in the risk control and defense system. First of all, Binance lacks defense capabilities to deal with large-scale systematic attacks. How did hackers obtain a large number of user API keys and Google verification codes? A large number of user keys are obtained in a day. If the hacker obtained user account numbers, passwords and other information through website phishing, why did Binance not find the URL address and page content of the counterfeit Binance website earlier, or did they not find that the hacker used the currency What about the loopholes in the official website server program that insert dangerous HTML codes into some web pages of the site? In addition, the composite attack defense technology means of superimposing other attack methods such as viruses is insufficient.

Secondly, Binance’s risk control has major problems. Although the stolen 7,000 BTC only accounted for 2% of the total BTC holdings officially announced by Binance, this cannot conceal the risk control problem of the Binance platform in terms of cash withdrawal approval and transfer.
3. Lack of internal system
Previously, in the article "Great Changes Before and After IPO, Why Exchanges Seek "Compliance"", it was pointed out that digital currency trading platforms have multiple identities.The theft of the Bithumb platform also reflects the lack of functions in the internal system under multiple identities. Bithumb platform officials stated that the abnormal withdrawal incident was not due to external attacks, and it was initially determined that internal employees stole the "private key" of the digital currency. This situation reflects that there is too much power concentrated in the internal functional positions of the Bithumb platform, and there is no necessary internal functional decomposition and the establishment of the necessary regulatory checks and balances system, which will lead to internal employees using the complete "private key" to transfer digital currency assets, and self-stealing occurs. behavior behavior.

This is not an isolated case of excessive concentration of power on digital currency trading platforms. QuadrigaCX, a Canadian digital currency trading platform, owed customers $190 million due to the death of founder Gerald Cotton. Most of the funds were no longer accessible and eventually went bankrupt. These are all the harms caused by the over-concentration of functional positions on the digital currency trading platform to the platform and users.

On the other hand, it can also be seen that Bithumb's internal responsibility system is lacking, and it has not prevented irresponsible employees or former employees from using the information they need to obtain to endanger the platform. Internal personnel should obtain and use internal data to apply for review authorization and register for backup. Whoever abuses internal data to endanger the platform will be responsible for the consequences of this behavior.
4. How should individuals prevent account passwords from being stolen?
In addition to the need to improve the risk control and defense system and improve the internal system of the digital currency trading platform, how should individual investors prevent account passwords from being stolen, and even lead to the loss of digital assets? Regarding this issue, RatingToken security technicians pointed out that individual investors need to pay close attention to the following 6 points:
1. When logging in to websites such as banks, exchanges, wallets, etc., always use a secure link beginning with https;
2. Mobile phones, computers, hardware wallets and other Internet-connected devices do not use third-party unknown Wi-Fi at will;
3. If the prerequisite permits, you must install anti-virus software and refuse to "streaking";
4. When abnormal situations occur on the webpage and APP, timely confirm and terminate major operations;
5. Do not open plug-ins, emails, or links from unknown sources;
6. Try to transfer large amounts of digital currency assets to well-known and reliable cold wallets.
Technology Partner:
Official website: ratingtoken.io
RatingToken rates digital currencies and ICOs based on blockchain project data, and provides the latest and most complete rankings of digital currencies and ICOs, as well as virtual currency research reports and cryptocurrency news.
The RatingToken security team has more than 50 people, of which big data, artificial intelligence and blockchain R&D personnel account for more than 90%. Most of the team members come from the famous anti-virus software Kingsoft Antivirus team.
RatingToken continues the technical strength of Kingsoft Security, is committed to the field of blockchain security, and provides security services such as smart contract auditing.


