Coins: 13,977
Exchanges: 1,057
Market Cap: $2.47T 4.7%
24h Vol: $136.747B
Gas: 12 GWEI
Go Ad-free
Announcements
TABLE OF CONTENTS

Cybersecurity In The Crypto Industry | CoinGecko Virtual Meetup #4

5.0 | by Shaun Paul Lee

Cryptocurrency is a fast-growing industry and has been attracting lots of attention lately. However, not all is rosy; cryptocurrency exchanges have experienced multiple hacks in the past, most of which resulted in the loss of large sums of funds. This is due to the fact that cybersecurity isn’t given the priority it deserves. 

So we invited Dyma Budorin, the CEO of Hacken Group in our Virtual Meetup #4 on Wednesday, July 22 @ 10AM EST to discuss the state of cybersecurity in crypto. 

Held monthly, CoinGecko’s Virtual Meetup is our live online community event where we explore different key topics in the crypto sphere and invite industry leaders to share their two satoshis.

In our discussion, we touched on the current state of cybersecurity in the cryptocurrency industry, the balance between good cybersecurity and convenience, types of security audit applied to decentralized exchanges, future of the Internet, and also the recent Twitter hack. 

Here is a quick quick breakdown what Dyma shared:

 

Dyma started his career 14 years ago in the audit department of Deloitte. Having to always check for mistakes in companies, it was only natural for him to apply that knowledge to the cryptocurrency space, which is why he started Hacken. The background of the Hacken team is similar to that of Dyma’s, coming from the major accounting firms. 

 

Cryptocurrency exchanges aren’t doing enough in terms of cybersecurity. That being said, many major ones have good policies where they’ve built lots of walls to prevent hacking. 

“There are always hidden windows,” said Dyma. 

From the viewpoint of Hacken, not many exchanges are hiring cybersecurity engineers, which comes as a surprise considering the amount of assets an exchange deals with.

 

Most crypto exchanges don’t have the balance between good cybersecurity and convenience. They completely remove the focus on user security and instead prioritize convenience. Certain security features such as requiring two-factor authentication (2FA) or limiting withdrawals are overlooked, as exchanges don’t want to lose clients. 

However, Dyma believes this will change, and some security practices will become the industry standard. These benchmarks will then be converted into ISO standards and will be the main security of crypto exchanges. This will ensure the quality and safety of the crypto exchanges with such standards. 

 

From what Dyma has seen, regulators in Korea and Japan always review the financial health of the exchanges. An exchange with healthy financials would have a larger fund compared to the deposits of the clients. At the moment, 80% of exchanges aren’t fulfilling this measure. Regulators may also push crypto exchanges to reveal their assets and liabilities, and the repercussions may be very harsh when this goes into effect. 

The second benchmark to achieve would be good private keys management. Only one exchange, Gemini, has done an industry-standard review of internal controls of their private keys. This review was performed by Deloitte. Information about the exchanges should be made public information such as the information on the management team, the procedure of cold wallet private keys management, and which executives have access to the funds. 

Dyma went on to say that internal controls, financial audits, licensing, and cybersecurity will be the trend of the industry. Fiat gateways of exchanges who don’t hold proper licensing will be shut down. 


5. What kind of security audit applies to decentralized exchanges?

“For decentralized exchanges, the token from a smart contract is integrated to allow for trading,” said Dyma. “There was a case involving the Balancer exchange, whereby one of the tokens was not erc-20 but was integrated as so, and this caused a bug which was exploited by an attacker. The attacker managed to double-spend a lot of funds with this bug.”

“Before this, Balancer went through three security audits but it didn’t cover whether the tokens were integrated properly,” explained Dyma. This shows that decentralized exchanges need to obtain a third-party opinion.” 

 

In mid-July 2020, Twitter was breached by a hacker who managed to get access to all Twitter accounts via super admin rights, allowing them to tweet anything. During the hack, they sent a tweet asking for victims to send them BTC, pretending that in doing so, the sender would receive double the amount. Profiles of influential individuals such as Barack Obama, Bill Gates, Kim Kardashian and many others were accessed by the said hacker. 

Dyma believes that it could have been a government experiment or an incident whereby someone found the credentials in an intentional or unintentional way. Either way, it is a very serious issue for the Twitter security team as super admin rights is a very big asset that needs to be properly protected. 

“There should not be any available doors on the computer used to access the super admin rights—no other applications, social media accounts, absolutely nothing.” chimed Dyma. “The internal controls should be in place so that such an incident doesn’t happen. A third-party auditor who reviews these super admin rights specifically should be brought in.”


7. What do you think of the future of the Internet? Will it be a safe place?

Looking at the history of the cybersecurity space, it has come a long way. It has evolved and improved a lot. But hackers are people who would always try to bypass something. The bigger the walls, the higher the temptation for hackers. They will always find a way to get behind it or jump over the wall. 

“I think what is more important is education,” suggested Dyma. “Cybersecurity has to be a must in schools or at least an online training that you must pass.”

Hacken is currently working on providing education courses on cybersecurity and believes that awareness is really important. Interestingly, the founder of Hacken shared that he was once hacked, and also broke his finger. But he would rather break his finger again than get hacked. 


 

Web traffic is indicative of a crypto exchange’s ability to attract audiences.  The understanding is that the more traffic a website has, the more popular it is and the larger its userbase.  It is one of the metrics measured by CoinGecko’s Trust Score Exchange Ranking algorithm.

Crypto exchanges also use web traffic to attract new tokens for listing.  As higher traffic indicates more potential users, the exchange can attract higher listing fees.

As such, crypto exchanges are incentivized to have a large amount of web traffic.  There are services out there which help boost this figure. 

“This means it is harder to get fair data,” said Dyma.

This issue doesn’t just apply to crypto; it’s a global problem. 

For example, there are thousands of Instagram stores, so which one does a customer go to? The one with the most followers? How do we verify whether these followers are real or not? How do we obtain information such as their location and demographic? 

To combat this global problem, Dyma suggested that, “the traffic we track should be a combination of SimilarWeb data, social media, and mentions in search engines. It is important since it can be tracked.”

 


 

Join us for our next meetup!

Sign up to our daily newsletter and we’ll keep you posted about our next meetup. You’ll also get to stay updated on the latest news and happenings in the crypto world.

CoinGecko's Content Editorial Guidelines
CoinGecko’s content aims to demystify the crypto industry. While certain posts you see may be sponsored, we strive to uphold the highest standards of editorial quality and integrity, and do not publish any content that has not been vetted by our editors.
Learn more
Tell us how much you like this article!
Vote count: 1
Shaun Paul Lee
Shaun Paul Lee

Shaun is a Research Associate at CoinGecko with a fondness for memes and farming on the blockchain. Follow the author on Twitter @ShaunPaulLee

Related Articles


Explore Polkadot's Ecosystem
Discover trending dApps, wallets, DeFi & more

What is Zeebu?
Learn more about the Web3 neobank


coingecko
Continue in app
Track prices in real-time
Open App
Select Currency
Suggested Currencies
USD
US Dollar
IDR
Indonesian Rupiah
TWD
New Taiwan Dollar
EUR
Euro
KRW
South Korean Won
JPY
Japanese Yen
RUB
Russian Ruble
CNY
Chinese Yuan
Fiat Currencies
AED
United Arab Emirates Dirham
ARS
Argentine Peso
AUD
Australian Dollar
BDT
Bangladeshi Taka
BHD
Bahraini Dinar
BMD
Bermudian Dollar
BRL
Brazil Real
CAD
Canadian Dollar
CHF
Swiss Franc
CLP
Chilean Peso
CZK
Czech Koruna
DKK
Danish Krone
GBP
British Pound Sterling
GEL
Georgian Lari
HKD
Hong Kong Dollar
HUF
Hungarian Forint
ILS
Israeli New Shekel
INR
Indian Rupee
KWD
Kuwaiti Dinar
LKR
Sri Lankan Rupee
MMK
Burmese Kyat
MXN
Mexican Peso
MYR
Malaysian Ringgit
NGN
Nigerian Naira
NOK
Norwegian Krone
NZD
New Zealand Dollar
PHP
Philippine Peso
PKR
Pakistani Rupee
PLN
Polish Zloty
SAR
Saudi Riyal
SEK
Swedish Krona
SGD
Singapore Dollar
THB
Thai Baht
TRY
Turkish Lira
UAH
Ukrainian hryvnia
VEF
Venezuelan bolívar fuerte
VND
Vietnamese đồng
ZAR
South African Rand
XDR
IMF Special Drawing Rights
Cryptocurrencies
BTC
Bitcoin
ETH
Ether
LTC
Litecoin
BCH
Bitcoin Cash
BNB
Binance Coin
EOS
EOS
XRP
XRP
XLM
Lumens
LINK
Chainlink
DOT
Polkadot
YFI
Yearn.finance
Bitcoin Units
BITS
Bits
SATS
Satoshi
Commodities
XAG
Silver - Troy Ounce
XAU
Gold - Troy Ounce
Select Language
Popular Languages
EN
English
RU
Русский
DE
Deutsch
PL
język polski
ES
Español
VI
Tiếng việt
FR
Français
PT
Português
All Languages
AR
العربية
BG
български
CS
čeština
DA
dansk
EL
Ελληνικά
FI
suomen kieli
HE
עִבְרִית
HI
हिंदी
HR
hrvatski
HU
Magyar nyelv
ID
Bahasa Indonesia
IT
Italiano
JA
日本語
KO
한국어
LT
lietuvių kalba
NL
Nederlands
NO
norsk
RO
Limba română
SK
slovenský jazyk
SL
slovenski jezik
SV
Svenska
TH
ภาษาไทย
TR
Türkçe
UK
украї́нська мо́ва
ZH
简体中文
ZH-TW
繁體中文
Login to track your favorite coin easily 🚀
By continuing, you agree to CoinGecko Terms of Service and acknowledge you’ve read our Privacy Policy
or
Forgot your password?
Didn't receive confirmation instructions?
Resend confirmation instructions
IT'S FREE! Track your favorite coin easily with CoinGecko 🚀
By continuing, you agree to CoinGecko Terms of Service and acknowledge you’ve read our Privacy Policy
or
Password must contain at least 8 characters including 1 uppercase letter, 1 lowercase letter, 1 number, and 1 special character
Didn't receive confirmation instructions?
Resend confirmation instructions
Forgot your password?
You will receive an email with instructions on how to reset your password in a few minutes.
Resend confirmation instructions
You will receive an email with instructions for how to confirm your email address in a few minutes.
Get the CoinGecko app.
Scan this QR code to download the app now App QR Code Or check it out in the app stores