Skip to main content

CoinDesk Crypto

Zcash Latest Hard Fork ‘Heartwood’ Makes Mining Private

6 years 2 months ago

Privacy coin Zcash has successfully hard forked in the planned network update “Heartwood.” With the update, miners can receive coinbase transactions right to a private address, in addition to other new features.

The hard fork occurred on July 16 at 10:58 UTC at block height 903,000, according to the Electric Coin Company (ECC), the for-profit development house behind the project. An uncontentious hard fork, Heartwood was supported by both the ECC and Zcash Foundation.

Read more: Zcash’s Funding Vote and the Woes of Decentralized Governance

Related: Fidelity International Doubles Stake in Bitcoin Mining Firm Hut 8

The update includes two Zcash Improvement Proposals (ZIPs). The first, “Shielded Coinbase” (ZIP 213) brings long-sought privacy solutions for Zcash (ZEC) mining while ZIP 221 “Flyclient” adds support for lightweight clients that verify transactions, the ECC said in a March blog.

As a hard fork, the updates are backward incompatible, meaning all nodes must sync to the new software in order to use the Zcash blockchain.

Heartwood is the privacy coin’s fourth hard fork since the network launched in late 2016. Zcash last hard forked in December 2019 with “Blossom.” 

“The Zcash Foundation is excited to support the Heartwood Zcash upgrade alongside the ECC, and thrilled that users will soon be able to connect to the Zcash network using Zebra, an alternate, consensus-compatible Zcash implementation built by the Foundation,” Zcash Foundation executive director Josh Cincinnati said in an email to CoinDesk. 

Related: Introducing the CoinDesk 20: The Assets That Matter Most in Crypto

(The Zebra client, written in Rust, was built in cooperation with Parity Technologies and released in June 2019).

Private coinbase transactions

Shielded coinbase transactions allow miners to claim coinbase transactions – the reward for processing transactions – directly to Zcash’s shielded addresses. Shielded addresses obfuscate information such as amounts, addresses and the encrypted memo field.

Implementing private coinbase transactions has been on the Zcash roadmap since the project’s early days. It was made possible by earlier technical updates found in 2018’s Sapling hard fork, according to the ECC.

“With this feature, when a mining pool or solo miner chooses to move coinbase rewards, [its] now private. For example, a mining pool can perform shielded payouts to miners in a shielded transaction,” ECC CTO Nathan Wilcox said in an email to CoinDesk.

Flyclient

Flyclient allows users to verify transactions with the smallest amount of information possible. Similar to Bitcoin Simplified Payment Verification (SPV) nodes, the spec proves the knowledge of a transaction using only the block header, rather than the full content of the block.

The ZIP has a few positive consequences for developers: It gives easier access to cross-chain interoperability, such as with the Ethereum network, and provides protection for light clients. The ECC announced plans to build interoperability projects with the second-largest blockchain by market cap, Ethereum, at DevCon 5 this past October.

Read more: Zcash Will Get a Gateway Into Ethereum’s DeFi Ecosystem

“Right now, you need a Zcash full node to get full privacy. Our ZIP helps protect light clients from malicious servers and pushes towards full privacy for every wallet,” said ZIP co-author and Summa founder James Prestwich in a private message.

Related Stories
CoinDesk

$1.4B in ‘High-Risk’ Crypto Flowed Onto Exchanges in H1 2020, Analysis Firm Says

6 years 2 months ago

Over $1.4 billion-worth of cryptocurrency tainted by illicit use moved onto global exchanges from January to June, according to blockchain analysis firm PeckShield.

The top 10 crypto exchanges to have received these “high-risk” assets include popular platforms such as Huobi, Binance, OKEx, ZB, Gate.io, BitMEX, Bithumb and Coinbase, the China-based firm said in a report released Tuesday. 

“The data highlights the current compliance challenge crypto exchanges face,” according to the report.

Related: Promoters of Crypto Ponzi Scheme OneCoin Murdered in Mexico

PeckShield said its analysis was based on over 100 million blockchain addresses it has labeled and tracked over the course of a year, including top-5 crypto assets like bitcoin, ether and tether.

Among these addresses, the firm identified many associated with Ponzi schemes, dark web transactions and hacks, as well as illegal online gambling operations that use cryptocurrencies as funding rails. 

The analysis suggests that various cryptocurrencies – equaling 147,000 bitcoin or over $1.4 billion in value at press time – have ended up in wallets on global exchanges. 

Separately, as of June 30, nearly $1.6 billion-worth of crypto assets from these high-risk addresses have entered cryptocurrency mixer services, after which they may end up at exchanges. Coin mixers obfuscate the source of transactions on-chain.

Related: Kraken Adds 3 DeFi Tokens – COMP, KAVA, KNC

In a follow-up report released Thursday, the firm revealed a chart with its data that shows Huobi, Binance and OKEx received the bulk of the tainted crypto transactions.

“The problem of the inflow of tainted cryptos has not been entirely put under regulation with strict enforcement,” the firm wrote in the report. “So anti-money laundering is considered as an important issue and then there’s no real follow-up. … But it’s a matter of time, not if, [until] the regulatory hammer will come [down].”

The findings come at a time the Financial Action Task Force, a global anti-money laundering watchdog, has been pushing for tougher enforcement of the so-called Travel Rule for crypto companies. 

The issue of crypto transactions tainted by illegal activities has recently hit over-the-counter trading desks in China, leading to the bank accounts of many being frozen by local law enforcement.

PeckShield added that, out of the 100 million blockchain addresses it has tracked, over 53 million belong to exchanges. Coinbase ranks top with 18 million bitcoin addresses, followed by Binance with 5.42 million.

Coinbase also holds the most cryptocurrency in the monitored addresses, with $11 billion-worth of assets. Huobi, Binance, Bitifnex, OKEx followed with $5.8 billion, $3.4 billion, $3 billion and $2.5 billion in crypto, respectively.

Related Stories
CoinDesk

OKCoin Joins Coinbase in Supplying Oracle Feed for DeFi Project Compound

6 years 2 months ago

OKCoin has launched a new API feed for the decentralized finance (DeFi) space that has already been picked up by lender Compound.

  • The San Francisco-based exchange said Wednesday that OKCoin Oracle would provide on-chain data for DeFi products and features.
  • As a liquid and regulated trading platform, OKCoin said its cryptographically signed price feed would be accurate, adding it would also verify and guarantee the data’s reliability.
  • San Francisco-based exchange Coinbase unveiled its own price feed plugin for the DeFi space in April.
  • Like Coinbase’s, OKCoin’s feed has been incorporated into the oracle system launched last August by Compound.
  • Known as the Open Price Feed System, Compounds oracle relies on data providers to effectively share data on-chain.
  • Rival oracle system ChainLink works broadly along the same lines, although it rewards third-party entities with LINK tokens for providing accurate data, and takes them away again when they don’t.
  • OKCoin was founded by Star Xu, who is also the founder of the separate exchange OKEx, which is based in Hong Kong.

See also: Why Crypto Exchange OKCoin Jumped Through Hoops to Get Licensed in Japan

Related Stories
CoinDesk

Man Charged With Defrauding $4.5M in Crypto to Fund Gambling Habit

6 years 2 months ago

A 27-year-old has been accused of defrauding investors into sending him millions of dollars in cryptocurrencies that he used on offshore gambling sites.

  • A criminal complaint filed July 9 at the U.S. Attorney’s Office charges Douglas Jae Woo Kim, who is based in New York, with wire fraud, alleging he conned three investors out of more than $4.5 million worth of bitcoin and ether.
  • The Department of Justice (DOJ) claims Kim told investors he was a cryptocurrency trader and asked for loans for a low-risk investment he claimed he had already invested $300,000 to $400,000 into.
  • The DOJ alleges that after receiving the funds, Kim sent either all or a substantial amount to offshore crypto gambling websites, Nitrogen Sports and Fairlay.
  • Between October 2017 and May 2020, the complaint says Kim convinced three investors to transfer a total of 123 bitcoin (~$1.1 million), 15,252 ether ($3.5 million), as well as approximately $30,000 in USD.
  • Although Kim promised loans would be repaid with high-levels of interest, the DOJ says that most of the bitcoin and all of the ETH has yet to be refunded.
  • Only one investor, so far, has been fully repaid.
  • Per an affidavit from the Federal Bureau of Investigation (FBI), none of the investors had any idea their money was being used on gambling sites.
  • The FBI also says Kim has been trying to convince new investors for loans since February 2020.
  • The DOJ has charged Kim with one count of wire fraud; he appeared before magistrates to face the charge on Wednesday.
  • If convicted, he faces up to 20 years in prison and a $250,000 penalty.

See also: Disgraced Lobbyist Jack Abramoff Pleads Guilty to Fraud in Crypto Case

Related Stories
CoinDesk

Man Charged with Defrauding $4.5M in Crypto to Fund Gambling Habit

6 years 2 months ago

A 27-year-old has been accused of defrauding investors into sending him millions of dollars in cryptocurrencies that he used on offshore gambling sites.

  • A criminal complaint filed July 9 at the U.S. Attorney’s Office charges Douglas Jae Woo Kim, who is based in New York, with wire fraud, alleging that he conned three investors out of more than $4.5 million worth of bitcoin and ether.
  • The Department of Justice (DOJ) claims Kim told investors he was a cryptocurrency trader and asked for loans for a low-risk investment that he claimed he had already invested $300,000 to $400,000 into.
  • The DOJ alleges that after receiving the funds, Kim sent either all or a substantial amount to offshore crypto gambling websites, Nitrogen Sports and Fairlay.
  • Between October 2017 and May 2020, the complaint says Kim convinced three investors to transfer a total of 123 bitcoin (~$1.1 million), 15,252 ether ($3.5 million), as well as approximately $30,000 in USD.
  • Although Kim promised loans would be repaid with high-levels of interest, the DOJ says that most of the bitcoin and all of the ETH has yet to be refunded.
  • Only one investor, so far, has been fully-repaid.
  • Per an affidavit from the Federal Burea of Investigation (FBI), none of the investors had any idea their money was being used on gambling sites.
  • The FBI also says Kim has been trying to convince new investors for loans since February 2020.
  • The DOJ has charged Kim with one count of wire fraud; he appeared before magistrates to face the charge on Wednesday.
  • If convicted, he faces up to twenty years in prison and a $250,000 penalty.

See also: Disgraced Lobbyist Jack Abramoff Pleads Guilty to Fraud in Crypto Case

Related Stories
CoinDesk

Binance CEO Criticizes Twitter Security After Coordinated Attack on Prominent Accounts

6 years 2 months ago

In a fireside chat at the World Blockchain Summit Asia on Thursday Binance’s CEO Changpeng “CZ” Zhao threw shade at Twitter’s security following coordinated attacks against prominent accounts on the platform Wednesday.

  • Starting with cryptocurrency firms like Coinbase, Gemini and Binance – and indeed CoinDesk – and moving on to big names such as Joe Biden, Barack Obama, Bill Gates and Elon Musk, the hackers were somehow able to post from the accounts offering a fake crypto giveaway.
  • Twitter has yet to provide a breakdown of how the mass attack was carried out, but says it's working on it.
  • Speaking to CoinDesk’s managing director of content products, Joon Ian Wong, Binance’s CZ said, while the bitcoin giveaway scam was rudimentary in its approach, it was a sign of how important strong security is for the industry.
  • CZ, whose account was also breached, said Twitter offers “limited security options” and the options that are available are a “little weak.”
  • He said he became aware of his own account being compromised after high profile accounts had also come under attack.
  • Twitter does provide two-factor authentication (2FA), but that seems to have been bypassed in the attack. Many of the affected accounts, including CoinDesk’s, had 2FA activated.
  • In the event of a hack where crypto funds are stolen from either individuals or exchanges, Binance seeks to blacklist the attacker’s addresses in coordination with other exchanges in order to deter future thefts, according to CZ.
  • Everyone in the community needs to work together and collaborate in order to “fight back” against bad actors in the space, he said.
  • Despite the hack of his and Binance’s accounts, CZ said Twitter is still his preferred social media platform due to its design and reach.
  • He had not yet regained control over his Twitter account at time of the interview.

See also: Binance Quashes Upbit Hackers’ Attempt to Launder Stolen Funds

Related Stories
CoinDesk

Twitter Hack Used Bitcoin to Cash In: Here’s Why

6 years 2 months ago

Someone hacked Twitter Wednesday – and they used bitcoin to capitalize on it.

But, why? 

Bitcoin is an alternative money system based on the value of censorship resistance. In other words, Bitcoin was built from the ground up to evade third-party interference (think banks, governments and law enforcement), making it a natural tool in the hands of a world-class hacker.

Related: Twitter Says ‘Coordinated Social Engineering’ Attack Caused Bitcoin Scam

Read more: Why Use Bitcoin?

Bitcoin’s value proposition can be broken into a few categories all based on the technology under the hood.

Once the hacker gets it, it’s theirs

Bitcoin is electronic. A popular meme for bitcoin is “magic internet money,” which, in a sense, it is. Bitcoin operates natively online – you can send bitcoin from your phone or computer to anyone else, just about anywhere in the world, in a few clicks, without anyone being able to stop you. And once you’ve sent it, you can’t get it back.

Read more: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

Related: Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

That feature – or in this case, a bother – is a prime reason Bitcoin exists. Bitcoin relies on what are called Peer-to-Peer (P2P) transactions in order to not be confiscatable by middlemen such as law enforcement. Once the coins are in someone else’s wallet, count them as good as gone.

Bitcoin is pseudonymous

Like many Twitter handles, bitcoin is pseudonymous. We can’t link an address to a personal identity very easily. 

Stolen USD, on the other hand, would be near impossible to get into and out of a bank account without being flagged. Traditionally, money is moved from one account to another through a third party. 

Legacy systems have the upside of being able to reverse transactions and attach identities to them. That is clearly a disadvantage to hackers. (Notably, reports surfaced of the hacker running a similar campaign on CashApp for USD). Bitcoin transactions, by comparison, are a lot harder to control.

Bitcoin is liquid

Bitcoin is also traded online in a lot of places. Holding bitcoins in your wallet wouldn’t be worth much without people to swap dollars for bitcoins. Launched in 2009, bitcoin is the most established and most highly traded digital asset. It’s also available on popular financial apps such as CashApp or PayPal.

Read more: Is Bitcoin Legal?

“It’s common sense that the attackers would choose Bitcoin. Bitcoin is the most censorship resistant and liquid asset in existence,” Blocksteam CSO Samson Mow said in a private message. 

All this to say that the Twitter hacker chose the right cryptocurrency to get U.S. dollars.

But bitcoin can be tracked and traced

Addresses can be tracked, however. And they can also be blackballed by others. By nature, the Bitcoin blockchain is 100% transparent. That means the ins-and-outs of transactions from one party to another are viewable for all to see with a little know-how.

For example, popular cryptocurrency exchange Coinbase would not allow users of its service to transfer funds to the Twitter hacker’s address. 

Blockchain analytics firm Chainalysis says the 12 or so bitcoins (worth about $110,000 at the time) the hacker netted are already on the move. But we can see where they are going. Some firms are even able to match “meatspace” identities with blockchain ones based on small details hackers overlook.

Having said that, there are tools available to people who really want to obfuscate their transactions, and whoever perpetrated this particular heist seems to be prepared to take measures to protect their loot.

At the end of the day, it’s important that people be wary of promises of free money on the internet – whether that comes in the form of dollars, pounds or bitcoin.

Related Stories
CoinDesk

Twitter Says ‘Coordinated Social Engineering’ Attack Caused Bitcoin Scam

6 years 2 months ago

Twitter claims “a coordinated social engineering attack” caused one of the world’s largest social media platforms to melt down on Wednesday after prominent celebrity profiles were used to promote a large-scale bitcoin scam.

  • A mass takeover of big-name celebrities including former Vice President Joe Biden, former U.S. President Barack Obama, Kanye West, and Elon Musk saw their accounts compromised, starting at 19:00 UTC.
  • Twitter said in a series of tweets that hackers targeted “some of” its employees who had access to internal tools, which they used “to take control of many highly-visible (including verified) accounts and Tweet on their behalf.”
  • The social media platform is looking into what else was impacted, while restoring accounts to their users.
  • Motherboard, VICE Magazine’s tech section, said it spoke to two sources who took over accounts, who claimed they paid a Twitter insider to manage the takeovers.
  • Twitter being “highly centralized” led to the hack, said Ben Sigman, CTO at blockchain startup Make Sense Labs.
  • Twitter employees have “godmode” access to create Tweets from any user, Sigman claimed.
  • It’s worth noting all addresses are bench32/Segwit addresses which helps narrow down the wallet and service being used.

See also: Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

Related Stories
CoinDesk

Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

6 years 2 months ago

The defrauded bitcoin amassed during Wednesday’s monumental Twitter hack is already “on the move,” according to cryptocurrency tracing firm Chainalysis.

  • Chainalysis told CoinDesk it is monitoring four wallets associated with the attack.
  • The most prevalent address received $120,000 in bitcoin from 375 transactions. Secondary addresses received $6,700 in bitcoin from 100 transactions. An XRP wallet netted nothing.
  • So far, a wallet whose associations are not yet known has received 5 bitcoin ($46,055) in total. “We are collaborating with our customers to find leads from this wallet,” Chainalysis spokesperson Maddie Kennedy said.
  • Part of the scam relied on hackers churning their own crypto between wallets to inflate the number of people who appeared to be chipping in, according to Chainalysis. The firm called the tactic “unsurprising.”
  • A Japanese wallet that sent scammers $40,000 in bitcoin appears to have been the single largest victim of the still-unexplained hack. International exchanges were generally the source of victims’ bitcoin, Chainalysis said.
  • No BTC has been cashed out to fiat just yet, the crypto-sleuthing firm added.

Read more: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

Related Stories
CoinDesk

Twitter Breach Reactions: Security Professionals Offer an Early Assessment

6 years 2 months ago

@jack’s been pwned. 

All of Twitter went ablaze Wednesday afternoon as major crypto accounts started tweeting they had partnered with a phony site called “Crypto For Health” on a giveaway of 5,000 BTC.

It was a scam, but one that was able to reach the biggest accounts on Twitter, including that of former President Barack Obama, the most followed account in the world. 

Related: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Read more: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

Security pros contacted by CoinDesk had a wide array of opinions on the breach, but they all agreed the fault did not lie with each hacked account’s owner. They said the breach was likely from either third-party apps plugged into people’s Twitter accounts or from within the social media giant itself. 

“Whatever the root cause will end up being, this amount of total pwnage would say to me that this is something novel and mass exploitable, not something well known and targeted,” Erik Cabetas, managing partner at Include Security, told CoinDesk in an email.

Cabetas and Frans Rosén, another security professional from a firm in Europe called Detectify, pointed CoinDesk to this tweet, which detailed the following:

Related: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

(OTP stands for “one-time password,” a security method commonly used as part of 2FA, or “two-factor identification.”) The account @6 is for Adrian Lamo, a journalist with 163,000 followers, who has now put his account on private.

Jessy Irwin, a security professional formerly of AgileBits (maker of 1Password) and Cosmos maker Tendermint, said there are a lot of ways to hack into big accounts. 

“There are endless OAuth integrations, the APIs that allow third-party services to access the platform, and some of the SMS features,” she wrote. “[Twitter has] done some work to improve authorization and authentication, but if you are a super-user or you have a team posting for you, it’s still extremely difficult to secure the service.” 

Parham Eftekhari, of the Cybersecurity Collaborative, a forum for security pros, cautioned that all security professionals could do is speculate. The scale of the attack and Twitter’s frustrated response indicated the problem could be a deep one:

Inside the birdhouse

Many security-adjacent accounts are sharing rumors that the breach is actually from inside Twitter, which would suggest all kinds of data could be compromised. 

Richard Ma, founder of smart-contract auditing firm Quantstamp, told CoinDesk his team believed the problem was at Twitter’s San Francisco HQ.

“Based on what we’ve gathered so far, this is an internal Twitter security breach. The hacker was able to breach Twitter and gain access to internal admin functionality,” he told CoinDesk.

Irwin added:

“It is a ‘silly’ hack, but it’s also important to look and why people are motivated to hack things. Some hackers like to watch the world burn – that’s just how it is. It could be a campaign to make Twitter look silly or ill-prepared for the role it has in public discourse.”

Eftekhari agreed, noting it’s important to remember we are in an election year, and that Twitter is a de facto communications institution for the United States, which could be appealing to rival nation states. 

After all, he noted, the payout ($106,200 so far) was small.

Read more: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Irwin said associates in the security community have already noticed the domains being used by the cybercriminals have been active since April. “That suggests this is a known issue or an older vulnerability that was not recently introduced,” she said.

Yonathan Klijnsma, a threat researcher at the cybersecurity company RiskIQ, said that while he can’t be sure, there is speculation a Twitter support member account was hijacked.

“While we do not know if this is the cause, it might explain how they hijacked so many accounts,” Klijnsma told CoinDesk in an email. “Twitter support is able to help users who are locked out of their account by (normally) verifying information and then helping them get back into their account. Gaining access to a support member’s account could lead to the massive and seemingly effortless hijacking we observed today.”

He said the scale of the ongoing scam through these Twitter accounts with massive followings seems to be the whole story.

“But RiskIQ has been able to track much more of the bad guy’s infrastructure used in their scam operations,” said Klijnsma. “We’ve identified around 400 domains so far that are all tied to these scams.”

Scam’s source

Rosén emphasized to CoinDesk that he could only speculate, but noted that the origin of the tweets has been “Twitter Web App” and that Twitter Support noted people might expect trouble with resets. 

This suggested to Rosén that the “service used to send out password resets was breached somehow,” and that “some specific flow when resetting password made it possible to gain access to the web app.”

Which, he cautioned, might mean that the attacker could do more than tweet, such as accessing DMs. Dan Guido, of Trail of Bits, a security firm widely relied on in crypto, pointed CoinDesk to a thread he wrote on the incident on one of his firm’s secondary accounts. In that, he noted:

“Twitter has never been great at securing their own data. After getting their backend hacked in 2009 (very similar to today!), the FTC barred Twitter from making claims about their security for 20 years.”

Quantstamp’s Ma said this event could cement a key belief of the crypto faithful. 

“Overall I think this reinforces many people’s preference for self-custody of data in the crypto community,” Ma said. “Many Twitter users are not aware of the full control they are providing when using a third party platform with special privileges over their accounts.”

Related Stories
CoinDesk

Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

6 years 2 months ago

Twitter melted down Wednesday as the accounts of former President Barack Obama, presidential candidate and former Vice President Joe Biden, Kanye West, Elon Musk, prominent crypto Twitter figures, exchanges and others with verified accounts were hacked. Here’s a growing list of the victims:

People
  • Barack Obama
  • Joe Biden
  • Elon Musk
  • Benjamin Netanyahu
  • Floyd Mayweather
  • Kanye West
  • Changpeng Zhao
  • Charlie Lee
  • Justin Sun
  • Michael Bloomberg
  • Jeff Bezos
  • Warren Buffett
  • Wiz Khalifa
  • Bill Gates
  • xxxtencion
  • Kim Kardashian West
  • MrBeast
  • Numerous other minor and unverified Twitter accounts

Follow our coverage: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

Exchanges and other crypto firms
  • Binance
  • Coinbase
  • KuCoin
  • Gemini
  • Bitfinex
  • Bitcoin
  • Ripple
  • CoinDesk
Corporates
  • Cash App
  • Apple
  • Uber

This is a developing story.

Related Stories
CoinDesk

Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

6 years 2 months ago

Twitter’s thin veil of security went into full meltdown at 19:00 UTC on Wednesday.

Within minutes, an apparently coordinated hack began: A mass takeover of the most prominent names in crypto. Within hours, even Barack Obama’s account was compromised.

The messages pumped a bitcoin giveaway scam associated with an organization called “Crypto For Health.”

Related: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

First, they came for Binance’s account. Gemini was next. Then Coinbase. CoinDesk. Justin Sun. Charlie Lee. Bitcoin.org. Kucoin. Bitfinex. The Tron Foundation. Ripple.

Millions of collective followers began seeing the same, cloying message: “I am giving back to my fans. All Bitcoin sent to my address below will be sent back doubled.”

About one hour in, the hack ditched its “Crypto For Health” tagline and went mainstream. Elon Musk’s account led the charge. Then Bill Gates. Then Elon Musk’s account came back for more. Kanye showed up an hour later. Jeff Bezos promised $50 million. Michael Bloomberg. Joe Biden. Barack Obama.

“I’m feeling generous because of Covid-19. I’ll double any BTC payment sent to my BTC address for the next hour. Good luck, and stay safe out there!” Musk’s account tweeted out. That post, like many of them, has since been deleted. (The hacker returned to Musk’s account for a second (and third) round, however.)

Related: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Read More: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account 

Apple, Uber get hit

By 21:00 UTC the hack had moved on to the tech giants. Apple’s account promised to double your bitcoin. Uber’s said it would return $10 million to users.

Hackers all linked to or directly promoted a single bitcoin wallet address. Some fell for it. By press time the wallet had received 11.5 BTC worth $106,200 and sent out 5.8 BTC worth $53,600 in 278 transactions. 

The hacked accounts collectively had at least 139.6 million followers. 

What was so perplexing about this hack was that some of these accounts had two-factor authentication. At least CoinDesk’s did.

With no easy explanation for how a single hack could target so many prominent Twitter accounts from such a broad spectrum – technology, entertainment, philanthropy, politics – Twitter users began to grasp for rumors. In the end, crypto was just once again ahead of the curve.

As news of the hack began to creep into the mainstream media, Twitter’s stock plunged 4% in after-hours trading.

This is a developing story.

Related Stories
CoinDesk

Swiss Crypto Bank SEBA to Offer Token Securitization on Corda Network

6 years 2 months ago

Switzerland’s licensed crypto-first bank SEBA and Corda-based Digital Asset Shared Ledger (DASL) announced a new partnership on Wednesday letting the bank offer asset securitization services on Corda’s public network.

  • In an emailed press release, SEBA said it is the first digital bank to offer clients the ability to issue and invest in blockchain tokens that represent real tradable assets like treasury bonds or foreign exchange contracts on the open-source blockchain platform Corda. 
  • SEBA said in its statement that it will create a custodial wallet for customers, issue digital securities and distribute them to investor networks.
  • Luzius Meisser, founder of Switzerland’s Bitcoin Association, told CoinDesk via an email that it was good to see SEBA moving forward with tokenization as it is an application to which distributed ledger technology can add value. 
  • Earlier this year, SEBA partnered with TokenSoft’s European distributor to offer asset tokenization services in what it said was an effort to bridge the gap between traditional and digital financial systems.
Related Stories
CoinDesk

Market Wrap: Bitcoin Sticks Around $9,200 as Traders Eye Other Markets for Action

6 years 2 months ago

Traders look towards altcoins and equities as volatility dips in a quiet July bitcoin market.

  • Bitcoin (BTC) trading around $9,185 as of 20:00 UTC (4 p.m. ET). Slipping 1% over the previous 24 hours.
  • Bitcoin’s 24-hour range: $9,153-$9,279
  • BTC below 10-day and 50-day moving average, a bearish signal for market technicians.

Traders seem to pine for the bitcoin volatility that was once the norm – and they expect it to return after what has been a lull. “Trading bitcoins is about as exciting as sitting in traffic,” said Jack Tan, founding partner of Taiwan-based quantitative firm Kronos Research. “I’m guessing bitcoin’s time will come in the next couple of months, but for now just enjoy the altcoin and equities rallies.”

Read More: CoinDesk Quarterly Review, Q2 2020

Related: New Metric Suggests Imminent Volatility for Bitcoin

Indeed, alternative coins to bitcoin, or altcoins, are picking up traction. Bitcoin’s dominance, a measure of the world’s oldest cryptocurrency occupies crypto market share, is down to 63%. It’s a level not seen since Feb. 18, as traders look towards non-bitcoin assets, particularly in the decentralized finance, or DeFI, space.

In addition, stock markets are up today:

Meanwhile, bitcoin continues to trade in stasis around $9,200. “Over the last three months we’ve seen lower volatility, and especially over the last 30 days it’s at a historic low for bitcoin,” said Michael Rabkin of Chicago-based crypto trading firm DV Chain. According to data from Skew, bitcoin’s implied volatility, a measure of the future expectation of volatility, has dipped as low as 46% in July. 

“This tells you what the market thinks the volatility of bitcoin is based on options pricing – dead in the water,” said Vishal Shah, an options trader and founder of derivatives exchange Alphas5.

Related: Bitcoin Has American Mindshare but Few Users

Read More: Correlation – Crypto’s Most Enigmatic Metric

It’s a holding pattern for bitcoin, said Rabkin. “I think given the equity markets being up – in my opinion based on the additional announced quantitative easing – we could see the price rise as investors look for a safe haven asset as coronavirus and trade wars continue,” he told CoinDesk.  

Uniswap offers more trading pairs

Ether (ETH), the second-largest cryptocurrency by market capitalization, was down Wednesday, trading around $237 and slipping 1.5% in 24 hours as of 20:00 UTC (4:00 p.m. ET). 

The Ethereum-powered decentralized exchange, or DEX, Uniswap is the top-ranking platform by volume at $30 million per day. One of the reasons: trading choice. Andrew Tu of algorithm trading firm Efficient Frontier says with Uniswap’s smart contract upgrade to version 2 in May, the DEX can perform swaps not just from ether-to-token, but also token-to-token on Ethereum’s network. “This creates much more flexibility in the types of pairs offered,” he said. 

Uniswap currently offers 351 coins and 794 trading pairs, according to data aggregator CoinGecko. By comparison, second-largest DEX Balancer has 69 coins with 136 pairs. Third place in volume is stablecoin DEX Curve, which offers eight coins and 19 trading pairs. “Liquidity begets more liquidity,” said Tu. “The more liquidity a venue has, the more it attracts new traders, who add to the pool and create more liquidity.”

Other markets

Digital assets on the CoinDesk 20 are mixed, mostly in the red Wednesday. Notable winners as of 20:00 UTC (4:00 p.m. ET): 

Read More: With Bitcoin Stuck in the Doldrums, Altcoins Continue to Rally

Notable losers as of 20:00 UTC (4:00 p.m. ET):

Read More: Hong Kong Citizens Turn to Stablecoins to Resist National Security Law

Commodities: 

  • Oil is up 1.1%. Price per barrel of West Texas Intermediate crude:  $40.98
  • Gold is flat Wednesday, up 0.18% at $1,812 per ounce

Read More: UK Fintech Firm Revolut Brings Bitcoin, Ether Trading to US Customers

Treasurys:

  • U.S. Treasury bonds were mixed Wednesday. Yields, which move in the opposite direction as price, were down most on the two-year bond, in the red 11%.

Read More: Russian Activists Use Bitcoin, and the Kremlin Doesn’t Like It

Related Stories
CoinDesk

Hackers Take Over Apple, Uber, Prominent Crypto Twitter Accounts in Simultaneous Attack

6 years 2 months ago

UPDATE: This is an ongoing situation. Click here for real-time updates.

Hackers pumping a crypto giveaway scam appear to have compromised the Twitter accounts of leading exchanges, individuals and at least one news organization.

  • The unknown attackers tweeted identical messages promising that they were “giving back 5000 BTC ($45,889,950) to the community” on Wednesday afternoon from the accounts of Gemini, Binance, KuCoin, Coinbase, Litecoin’s Charlie Lee, Tron’s Justin Sun, Bitcoin, Bitfinex, Ripple, Cash App, Elon Musk, Uber, Apple, Kanye West, Jeff Bezos, Michael Bloomberg, Warren Buffett, Barack Obama and CoinDesk.
  • Their messages, sent within minutes of each other, prompted readers to claim their rewards at an included link associated with “Crypto For Health.”
  • Changpeng Zhao, Binance’s CEO, attempted to warn Twitter users that the Tweet was a scam within five minutes of the hack. But the attackers appear to have hidden his response and hacked him too.
  • Kucoin was also targeted in the hack. CoinDesk’s account was as well.
  • Attempts to reach the hacked entities were not immediately successful.
  • At least some of the compromised accounts have multi-factor authentication enabled, including CoinDesk’s.
  • The address linked to the scam appears to have received more than 11.3 BTC, or roughly $103,960.
  • Shares of Twitter fell as much as 3% in after-hours trading.
Related Stories
CoinDesk

The Bahamas Edges Closer to Hurricane-Proof Digital Currency

6 years 2 months ago

The Bahamas’ central bank said it is “progressing” toward the full launch of a mobile phone-based digital currency (CBDC) it’s betting can withstand the battering of a Category 5 hurricane. 

  • Last September, the Bahamas struggled to rebound from Hurricane Dorian’s $3.4 billion devastation, in part because the storm, the largest in Bahamian history, had decimated the islands’ physical banking and payments systems.
  • Some Bahamian banks and ATMs remained offline for months, the central bank said in its Sunday report. “Mobile phone coverage, by contrast, was generally restored within a few days after Dorian,” it said.
  • The central bank believes it can fast-track future recoveries by building CBDC functionality into mobile phones. It projected this could help ease critical post-disaster recovery tools such as receiving insurance claims.
  • “The Dorian aftermath demonstrated one major benefit: rapid payments system restoration after a disaster,” the central bank said.
  • It also noted a mobile phone CBDC can eliminate some pandemic-era pain points, such as queueing at a bank and physically exchanging currency.
  • The central bank’s CBDC effort, known as Project Sand Dollar, is currently in the testing phase on the island of Abaco.


Related Stories
CoinDesk

Three Arrows, Framework Invest in DeFi Site Aave With $3M LEND Token Sale

6 years 2 months ago

Framework Ventures and Three Arrows Capital announced Wednesday a $3 million investment in Aave, the firm behind the third-largest lending platform in decentralized finance (DeFi).

  • The two funds purchased Aave’s native LEND tokens directly from the company. LEND has appreciated 1,200% on a year-to-date basis.
  • “We believe there will be a significant market shift of private borrow/lend activity moving to decentralized money market protocols,” Framework Ventures’ Michael Anderson said in a statement. “Aave stands to significantly benefit from this underlying shift.”
  • The total value locked (TVL) on Aave is currently $218.6 million, according to DeFi Pulse. The top lending protocol, Compound, has $695.4 million worth of crypto assets “locked in” to its system.
  • Aave’s TVL has spiked with the rest of the DeFi market since the general upturn began following the release of Compound's COMP token on June 15. The value of assets locked on Aave is up over 250% since mid-June.
  • Aave sits in a similar place in the market to Compound, but offers more assets for deposits and borrows. Compound currently lists nine; Aave lists 17.
  • “Our focus has always been innovation and diligent risk management,” Aave founder Stani Kulechov said in a statement.

Read more: First Mover: Twelve-Fold Gains for Aave’s LEND Token Might Be More Than DeFi Hype

Related Stories
CoinDesk

Three Arrows, Framework Invest in DeFi Site Aave With $3M LEND Token Sale

6 years 2 months ago

Framework Ventures and Three Arrows Capital announced Wednesday a $3 million investment in Aave, the firm behind the third-largest lending platform in decentralized finance (DeFi).

  • The two funds purchased Aave’s native LEND tokens directly from the company. LEND has appreciated 1,200% on a year-to-date basis.
  • “We believe there will be a significant market shift of private borrow/lend activity moving to decentralized money market protocols,” Framework Ventures’ Michael Anderson said in a statement. “Aave stands to significantly benefit from this underlying shift.”
  • The total value locked (TVL) on Aave is currently $218.6 million, according to DeFi Pulse. The top lending protocol, Compound, has $695.4 million worth of crypto assets “locked in” to its system.
  • Aave’s TVL has spiked with the rest of the DeFi market since the general upturn began following the release of Compound's COMP token on June 15. The value of assets locked on Aave is up over 250% since mid-June.
  • Aave sits in a similar place in the market to Compound, but offers more assets for deposits and borrows. Compound currently lists nine; Aave lists 17.
  • “Our focus has always been innovation and diligent risk management,” Aave founder Stani Kulechov said in a statement.

Read more: First Mover: Twelve-Fold Gains for Aave’s LEND Token Might Be More Than DeFi Hype

Related Stories
CoinDesk

Blockchain Bites: BitLicense Feedback, Digital Yuan Trial and How US Bills Could Threaten Privacy

6 years 2 months ago

China will trial its digital yuan with a mega food retailer, U.S. bills are seriously threatening online privacy and an a16z alum is launching a venture firm focused on distributed tech. Here’s the story:

Trial Plan
China wants to trial its digital yuan with online food seller Meituan-Dianping as well as another two Tencent-backed companies. The Beijing-based company has held talks with the research wing at the People’s Bank of China (PBoC) over trialling the digital yuan on its platform, according to sources speaking to Bloomberg. The exact details of the collaboration are not yet known. Listed in Hong Kong, Meituan-Dianping’s 400 million active users make it one of the largest food delivery platforms in the world.

Funding Dissent
Opposition politicians and dissidents in Russia are using bitcoin to fund their activities against President Vladimir Putin. “Our opponents understand they can’t cut us off from sources of funding because [if they try] at least a part of the donations will go into crypto,” Leonid Volkov, who manages political operations for Alexei Navalny, Putin’s most prominent opponent, said. “Last time our accounts got frozen, we saw an uptick in bitcoin donations.” The candidate has raised more than 600 bitcoin since 2016, and other non-governmental organizations and advocacy groups have followed suit. 

Related: First Mover: UK Economy Setback Renews Questions of Bitcoin’s Resilience

BitLicense Feedback?
Industry reactions made to the BitLicense have been overwhelmingly positive, said Linda Lacewell, superintendent of the New York Department of Financial Services. Lacewell, who took office last year, has created a conditional license allowing companies to partner with existing licensed entities to legally operate in New York, enabled self-certification of virtual currencies and has issued guidance on coin listings for licensed platforms.

Privacy Threatened
Multiple bills that threaten encryption are moving through the U.S. Senate and could pose a threat to technology that protects users’ privacy. The Lawful Access to Encrypted Data (LAED) Act and the Eliminating Abusive and Rampant Neglect of Interactive Technologies (“EARN IT”) Act take aim at privacy tech and cryptography by mandating “backdoors” be installed for government watchdogs. “There’s no such thing as a backdoor just for good guys,” said Daisy Soderberg-Rivkin, a fellow focusing on children and technology at the R Street Institute, a policy think tank in Washington, D.C. “This opens up users’ information to a whole mess of bad actors.”

New Fund
An Andreessen Horowitz (a16z) alum is launching a venture firm focused on building a crypto-powered “ownership economy.” Jesse Walden, who focused on blockchain investments at a16z, announced his Variant Fund in a blog post published Tuesday, which is backed by a16z’s Chris Dixon and Marc Andreessen, Union Square Ventures and Compound’s Robert Leshner. Separately, Evertas, an insurance provider focused on the cryptocurrency space, has raised $2.8 million in a seed round led by Morgan Creek.

Quick bites The narrative

A leaked FBI bulletin makes reference to OneCoin, in all but name, when detailing the money-laundering risks of private investment funds. 

Related: Blockchain Bites: Chainlink’s Interest, Ethereum’s ‘ReGenesis’ and Crypto Taxes

In the bulletin, dated May 1, the FBI argues criminals and foreign adversaries of the U.S. “likely” use hedge funds, private equity and other investment vehicles to circumvent financial institutions’ anti-money laundering (AML) procedures. 

OneCoin’s story is told, without naming the firm or its founders, as an example of a “fraudulent cryptocurrency investment scheme.” A known Ponzi scheme, the FBI details how the fraudsters maneuvered through the banking system, without ever disclosing the source of its funds, and was able to transfer stolen funds to “a series of purported private equity funds holding accounts at financial institutions, including those in the Cayman Islands and the Republic of Ireland,” according to the report. 

Incidentally, two OneCoin promoters were found dead in Mexico last month.

“While OneCoin was a scam, the veiled references to its crimes in the FBI bulletin are a salient reminder that banks, not cryptocurrencies, were used to launder the ill-gotten gains,” CoinDesk reports. 

Market intel

Alt-Season
Bitcoin is still consolidating with no clear direction in sight, but some alternative cryptocurrencies are soaring. The leading cryptocurrency has been trading the narrow range of $9,000–$10,000 for two months. Meanwhile, link, a token used on the decentralized oracle network Chainlink, is up 78% on a month-to-date basis and up 364% for 2020. And Aave’s lend token has increased by over 1200% so far this year, following the launch of mainnet in January. 

Tech pod

Bitcoin Smart Contracts
Bitcoin Core contributor Jeremy Rubin has revealed his work on a new smart-contract language for Bitcoin, which he hopes will increase the “financial self-sovereignty” of users. The new language, called Sapio, could enable the building of stateful smart contracts, a type most commonly associated with the Ethereum blockchain. Bitcoin supports several different types of smart contracts, which are generally much more complicated to create than on Ethereum.

Ethereum’s Client
Ethereum 2.0 client Prysm is “basically ready” to launch, according to Richard Ma, CEO of Quantstamp, the code’s auditor. This news comes on the heels of last week’s announced push by network developers to launch the proof-of-stake (PoS) version of Ethereum before 2020 closes out. Prysm client’s code was “well-written and documented,” Quantstamp said in a blog post. The firm identified 65 issues relating to the granularity of timestamps, pseudo-random number generation and second preimage attacks on Merkle trees. Ten engineers combed over Prysm’s ETH 2.0 codebase, programmed in the Go language, for two months, Ma said.

Opinion

American Mindshare
J.P. Koning, a CoinDesk columnist and owner of the popular Moneyness blog, looks into the Federal Reserve’s annual “Survey of Consumer Choice” and determines bitcoin has American mindshare, but few users. According to the survey, in 2019, 70.7% of participants said they were familiar with bitcoin, up from 68.7% in 2018. Though out of 3,363 surveyed, effectively 0% had used bitcoin to make payments in the previous 12 months. “Bitcoin has succeeded in grabbing an impressively large chunk of American mindshare. However, common knowledge of bitcoin tends to be of poor quality,” Koning writes. 

Who won #CryptoTwitter?

Preview(opens in a new tab)

Related Stories
CoinDesk

Gemini Crypto Exchange Integrates With Privacy-Focused Brave Browser

6 years 2 months ago

Brave users can now use the Gemini cryptocurrency exchange to buy, sell and store crypto within their browsers.

  • The Gemini Trading Widget is now live in Brave’s Nightly version, the testing and development version of Brave, and will go live in Brave’s general release in the next few weeks, the companies announced on Wednesday.
  • Brave-verified content creators can now also custody their digital assets in a Gemini Creator Wallet.
  • “This is a deep integration spanning multiple product features, and our teams have been in lockstep to ensure that Brave Rewards works seamlessly with Gemini,” Jason Mintz, principal of product management at Gemini, said in a statement. “This includes building additional functionality (like OAuth) into the Gemini platform so customers can interact with us wherever they are – like trading in TradingView, browsing the web in Brave, or using their Samsung phone.” 
  • The Brave browser delivers ads to internet users and rewards them for their attention with the basic attention token (BAT). In April, Gemini announced that BAT was available for trading on its platform. 
  • Gemini is a New York-based trust company and will be able to offer this service in all U.S. states except Hawaii. 

Read more: Compound’s ‘Yield Farmers’ Briefly Turned BAT Into DeFi’s Largest Coin

Related Stories
CoinDesk
Checked
1 minute 16 seconds ago
CoinDesk Crypto
Leader in cryptocurrency, Bitcoin, Ethereum, XRP, blockchain, DeFi, digital finance and Web 3.0 news with analysis, video and live price updates.
Subscribe to CoinDesk Crypto feed