Skip to main content

CoinDesk Crypto

ConsenSys Accused of Stealing Payment Startup’s Code for Rival Service

6 years 2 months ago

An Ethereum-based payments project claims in a new lawsuit that ConsenSys abused its position of trust as an investor to access trade secrets and create a rival offering.

  • BlockCrushr filed a complaint Tuesday alleging ConsenSys misappropriated its intellectual property to create a rival version of its payments system that allows recurring transactions, such as monthly payments, on the Ethereum blockchain.
  • CoinDesk reached out to ConsenSys for comment but hadn’t received a response at press time.
  • Per the filing, ConsenSys Ventures invested $100,000 into BlockCrushr and invited the firm to participate in that year’s Tachyon Accelerator program.
  • As part of the agreement, BlockCrushr said it shared its intellectual property, including 120,000 lines of source code, to help ConsenSys guide and support it.
  • Between October 2018 and February 2019, BlockCrushr said, ConsenSys had requested over 20 meetings to talk in depth about the payments system.
  • BlockCrushr, which is based in Canada, shared information because it was promised further investment, the filing states.
  • The startup said Vincente Hernandez, a developer with Token Foundry, another ConsenSys project, was present at many meetings.
  • The complaint alleges Hernandez put some of BlockCrushr’s publicly available code in his own GitHub.
  • He is said to have became a founding member of Daisy Payments (now CodeFi), another recurring payment system, a few weeks later.
  • In February 2019, ConsenSys allegedly ceased communications with BlockCrushr and didn’t return its calls.
  • As ConsenSys was still an investor, BlockCrushr says it informed the company privately that its payments system would launch on Aug. 23, 2019.
  • On Aug. 22, ConsenSys launched Daisy Payments, which BlockCrushr claims is a near-identical offering to its own.
  • BlockCrushr claims it was forced to cancel its own launch as a result.
  • CodeFi is now used as the foundation for ConsenSys’ new staking service.
  • According to the filing, ConsenSys employees, including CEO Joe Lubin, said there was a firewall issue and that some of BlockCrushr’s proprietary information may have been used by other teams.
  • However, BlockCrushr said no action was taken and communications stopped soon after.
  • The startup is now formally accusing ConsenSys of two counts of misappropriating trade secrets and one count of a breach of contract, and is suing for damages.

See also: ConsenSys Muscles Into Compliance With New Regulatory Product for DeFi

Read the full filing below:

Related Stories
CoinDesk

Blockchain Enabled Fantasy Soccer Firm Sorare Raises $4M in Seed Fund Round

6 years 2 months ago

Blockchain enabled fantasy soccer platform Sorare announced Thursday it has raised $4 million in a seed funding round led by e.ventures. 

In an announcement emailed to CoinDesk, the firm said besides venture capital investors including e.ventures and Fabric Ventures, a former member of German national soccer team, Andre Schurrle, has also invested in the firm. 

Using the Ethereum blockchain, Sorare generates unique digital trading cards representing professional soccer players that can be traded by users. A user plays as the team manager and can use their five cards to compete in the weekly league competitions. 

Related: US Soccer Players Can Be Collected, Traded in Tokenized Fantasy Game

Recently, Sorare announced licensing partnerships with the U.S. soccer league, MLS, and the South Korean K-League, bringing both leagues onto its platform. According to the firm’s CEO, Nicolas Julia, the two agreements helped the firm add about 3500 new users to its platform. 

“We’ve had major traction, essentially targeting the ‘crypto-enthusiast’ potential users,” said Julia, noting that over the next few months the firm would focus on building a better free-to-play experience and also improve the platform for fiat users. “It’s important for us that they can play without needing to install metamask and buying ether,” he added. 

Users on Sorare’s platform can also buy tokens representing other soccer players to improve their team and – depending on how the players perform in real life – they might receive rewards in ether or more trading cards.

“When COVID sort of hit, we thought that it would be the end of something like Sorare,” said Max Mersch, Co-founder of Fabric Ventures, pointing out how the platform largely depends on live soccer games which were suspended as different countries went into lockdown. Fabric Ventures has also previously invested in Ethereum-enabled virtual reality game Decentraland. 

Related: South Korean Soccer League Tokenizes Players for Fantasy Football Game

Introduced to the platform first as a player himself, Mersch said the firm’s replay model, allowing players to reenact matches from past seasons, helped players keep gaming. He added that it was also quite impressive to see the amount of money people were willing to spend to get these digital cards. According to Sorare, sales on its platform touched $350,000 in June of this year. 

“I was immediately impressed with the vision for the future of football collectibles: digital cards of football players,” said Schurrle in the emailed statement. Part of Germany’s World Cup winning team in 2014, Schurrle was removed from the German soccer club Dortmund’s squad recently, according to a report by The Sun. 

According to Sorare, the scarcity of its tokens is what makes the tokens valuable, and they are likely to appreciate in value if a player performs well. Counting on the growing traction blockchain-enabled games have been receiving recently, Julia said the firm would use the money raised to expand its team and get closer to its ambition of getting “the top 20 leagues with all their clubs licensed” onto its platform. 

Related Stories
CoinDesk

First Mover: ‘Boring’ Bitcoin Shrugs Off Twitter Hack as Stablecoins Co-Opt Satoshi’s Dream

6 years 2 months ago

In a paradoxical twist, bitcoin’s price, which is denominated in dollars, has become unusually stable in recent weeks, prompting some Twitter users to joke that it’s trading like a stablecoin.

“It’s surprising to see bitcoin be so boring given everything happening both within and outside the crypto industry,” the digital-asset analysis firm Messari wrote in its daily email to subscribers. 

You’re reading First Mover, CoinDesk’s daily markets newsletter. Assembled by the CoinDesk Markets Team, First Mover starts your day with the most up-to-date sentiment around crypto markets, which of course never close, putting in context every wild swing in bitcoin and more. We follow the money so you don’t have to. You can subscribe here.

Related: After the Twitter Hack, We Need a User-Owned Internet More Than Ever

On Wednesday, the cryptocurrency slid 0.5% to about $9,200, even as reports emerged that a bitcoin “giveaway” scam was at the heart of a coordinated hack targeting accounts of prominent Twitter users, including former U.S. President Barack Obama and Microsoft founder Bill Gates.

“Even if there is a small percentage of bitcoin that is used for illicit activity, investors now understand this is no different than cash, except that digital currencies are much more traceable,” Joe DiPasquale, CEO of BitBull Capital, told First Mover in an email. 

Bitcoin was designed by Satoshi Nakamoto as a peer-to-peer payment method, a version of electronic cash that would “allow online payments to be sent directly from one party to another,” according to the white paper. 

But a new report suggests bitcoin’s original core payments function might be increasingly fulfilled by a competing faction of digital tokens – so-called stablecoins like tether and USD coin, which have values linked to the price of the U.S. dollar.

Related: Bitcoin Option Traders Now Betting on Short-Term Price Drop

Stablecoins, invented five years ago, have expanded rapidly this year, doubling in the past four months to an outstanding supply of about $12 billion.

Cryptocurrency traders use them as the de facto form of liquidity in digital-asset markets, to move money between exchanges and park cash on the sidelines. Investors can lend out the dollar-linked tokens for yields up to 13%, more than 20 times the level on 10-year U.S. Treasury notes. Some holders might simply want U.S. dollars as a safe haven as the coronavirus roils the global economy. 

Recently, though, more people might be using stablecoins to send each other payments, according to a report this week published jointly by cryptocurrency exchange Bitstamp and research firm Coin Metrics. 

The analysts noted that the daily transfer value of stablecoins recently surged past $2 billion, while bitcoin’s slid to just below $2 billion. Global remittances and cross-border payments are a “natural use case for stablecoins given their ease of international transfer,” they wrote. 

“It feels like a little bit of a paradigm shift, especially now that stablecoins are exploding,” Nate Maddrey, a senior research analyst at Coin Metrics, said in a phone interview. 

The sudden popularity of stablecoins could raise knotty questions over the utility of bitcoin, which is the oldest cryptocurrency, at 11 years, and the biggest by far, at a market capitalization of $170 billion. 

Maddrey believes bitcoin’s value proposition has changed over the years: Many investors are buying it because they see the cryptocurrency as a store of value, similar to gold, and as the linchpin of the world’s most secure blockchain network. Because of its capped supply, bitcoin is often posited as a hedge against inflation and central-bank money printing. 

“I don’t really see a path where bitcoin becomes a true medium of exchange,” Maddrey said. 

The rise of stablecoins marks a new chapter in fast-moving and ever-evolving cryptocurrency markets. A thousand flowers are blooming as entrepreneurs unveil semi-autonomous “decentralized finance” projects, financial firms prepare to tokenize traditional assets like U.S. Treasury bonds and foreign-exchange contracts, and Facebook pushes forward with its own digital token, Libra. PayPal, the payments company, has told the European Commission it’s developing cryptocurrency capabilities. 

Countries around the world are developing their own tokens, known as central bank digital currencies, or CDBCs, which could eventually provide another option for peer-to-peer payments. Just this week, reports have emerged that both Japan and the U.K.are considering digital versions of their currencies. 

While the Federal Reserve has yet to unveil its own version, some countries with exchange rates pegged or closely linked to the dollar might be able to create CBDCs that work like proxies for the U.S. tender. 

That might curb the appetite for stablecoins, many of them issued by upstart companies with scant corporate transparency and untested creditworthiness.     

“Would you rather I sent you a stablecoin or a CBDC backed by a sovereign nation whose currency is pegged to the dollar?” Matt Blom, head of sales and trading for the digital-asset firm Diginex, said in a video interview. “I’d rather receive a sovereign-backed CBDC.” 

Blockforce Capital, a cryptocurrency investment firm based in San Diego, wrote Wednesday in a monthly investor update that, at least for now, there’s good money to be made from lending out or depositing stablecoins. 

“Stablecoins are proving their utility in the digital-asset ecosystem,” according to the email. “Our traditional finance friends are often shocked to hear that as interest rates sink lower and even negative in some cases, we manage to earn close to 8% as we lend out stablecoins to high-quality counterparties.”

On the other hand, holding stablecoins is essentially the reverse of betting on assets that are denominated in dollars, from stocks to bonds to oil and bitcoin. The Federal Reserve this year has pumped nearly $3 trillion of freshly created dollars into financial markets, propping up asset prices. 

“Holding dollars is no fun when assets are mooning,” Mati Greenspan, founder of the analysis firm Quantum Economics, wrote in an email. 

But, hey, maybe some people might just want to send stablecoins to a pal.  

Tweet of the day Bitcoin watch

BTC: Price: $9,085 (BPI) | 24-Hr High: $9,253 | 24-Hr Low: $9,048

Trend: Bitcoin is edging lower on Thursday, with the four-hour chart indicating a failed breakout and fresh bearish lower-highs setup. 

The number one cryptocurrency by market value is currently trading near $9,080, representing a 1.3% decline on the day. 

A falling channel represented by trendlines connecting June 1 and 22 highs and June 2 and 15 lows was breached to the higher side on July 8. As such, the cryptocurrency was expected to chart a minor rally toward resistance at $9,800 (June 22 high). 

Instead, the cryptocurrency has ended up charting fresh bearish lower highs, as represented by the trendline connecting July 8 and 13 highs (yellow line). In addition, prices fell back inside the bearish channel early on Thursday – a sign of failed breakout. Chart analysts consider failed breakouts as strong bearish signals. 

Indicators, too, are beginning to realign in favor of the bears. The MACD histogram, an indicator used to identify trend strength and trend changes, is producing deeper bars below the zero line. It indicates the downward move may gather pace. Meanwhile, on the daily chart, the histogram has crossed into bearish territory below zero. 

Bitcoin may dive below $9,000 and test support at $8,830 (June 28 high). On the higher side, a high-volume move above $9,350 is needed to revive the case for a rally to $9,800.

Related Stories
CoinDesk

Bitcoin Option Traders Now Betting on Short-Term Price Drop

6 years 2 months ago

With bitcoin looking heavy this week, short-term sentiment in the options market has flipped bearish.

  • The leading cryptocurrency by market value fell to $9,070 soon before press time, reversing the 2.5% rise to $9,450 seen last week, according to CoinDesk’s Bitcoin Price Index.
  • Prices are now closing on the lower end of the multi-week-long trading range of $9,000–$10,000.
  • Reflecting the downward trend, the one-month put-call skew for bitcoin options, a metric that measures the price of (bearish) put options relative to (bullish) call options, has risen to 4.9%, according to data provided by crypto derivatives research firm Skew.
  • The positive number indicates short-term put options are drawing higher prices than calls.
  • Traders, the data suggests, are making speculative bets to the downside or are hedging against a potential bearish move (that is, buying puts against long positions in the spot market), Shaun Phoon, senior trader at QCP Capital, told CoinDesk.
  • The one-month skew was hovering at lows below -7% a week ago, indicating stronger demand for call options – a sign of bullish bias in the options market.
  • While the one-month skew is now more bearish, the six-month skew remains below zero or bullish.
  • Demand for call options expiring in December is still higher than that for puts.
  • The three-month skew is hovering in the neutral zone near 0%.

Also read: Bitcoin Option Traders Bet on Bullish Move Following Volatility Squeeze

Disclosure: The author holds no cryptocurrency assets at the time of writing.

Related Stories
CoinDesk

Microsoft Partners With Waves Enterprise to Tokenize Industrial Assets

6 years 2 months ago

Waves’ corporate arm is planning on working with Microsoft’s Russian subsidiary, in part to create an asset tokenization platform for company equipment.

  • Waves Enterprise said Wednesday it had signed a five-year memorandum with Microsoft Russia to work jointly on corporate blockchain solutions.
  • Waves Platform is a Moscow-based tokenization project; Waves Enterprise was founded in July of last year to offer services to corporate clients on private blockchains.
  • Although nothing has been confirmed, Waves said both sides wanted to use blockchain for new supply chain solutions as well as for the “tokenization of industrial assets.”
  • An industrial asset is a catch-all term that can refer to anything from heavy machinery to basic office equipment.
  • Microsoft Russia CEO Kristina Tikhonova said the partnership was a push towards the country’s business sector getting to grips with blockchain technology.
  • Future solutions could be made available in Russia and internationally, Waves said.
  • The tie-in will look at the interplay between blockchain and cloud technologies; Waves Enterprise said it will also build a data analytics solution based on Microsoft Azure, the company’s cloud computing service.
  • In April, Russia’s Ministry of Communications officially recognized Waves as a potential technology provider for future government initiatives.

See also: Microsoft Files Patent Application for Crypto Mining System Powered by Human Activity

UPDATE: (July 16, 16:00 UTC): This article has been updated to better distinguish Waves Platform from Waves Enterprise.

Related Stories
CoinDesk

Microsoft Partners With Waves to Tokenize Industrial Assets

6 years 2 months ago

Waves’ corporate arm is planning on working with Microsoft’s Russian subsidiary, in part to create an asset tokenization platform for company equipment.

  • Waves Enterprise said Wednesday it had signed a five-year memorandum with Microsoft Russia to work jointly on corporate blockchain solutions.
  • Waves is a Moscow-based tokenization platform; Waves Enterprise was founded in July of last year to offer services to corporate clients on private blockchains.
  • Although nothing has been confirmed, Waves said both sides wanted to use blockchain for new supply chain solutions as well as for the “tokenization of industrial assets.”
  • An industrial asset is a catch-all term that can refer to anything from heavy machinery to basic office equipment.
  • Microsoft Russia CEO Kristina Tikhonova said the partnership was a push towards the country’s business sector getting to grips with blockchain technology.
  • Future solutions could be made available in Russia and internationally, Waves said.
  • The tie-in will look at the interplay between blockchain and cloud technologies; Waves Enterprise said it will also build a data analytics solution based on Microsoft Azure, the company’s cloud computing service.
  • In April, Russia’s Ministry of Communications officially recognized Waves as a potential technology provider for future government initiatives.

See also: Microsoft Files Patent Application for Crypto Mining System Powered by Human Activity

Related Stories
CoinDesk

Microsoft Partners with Waves to Tokenize Industrial Assets

6 years 2 months ago

Waves’ corporate arm is planning on working with Microsoft’s Russian subsidiary in part to create an asset tokenization platform for company equipment.

  • Waves Enterprise said Wednesday they had signed a five-year memorandum with Microsoft Russia to work jointly on corporate blockchain solutions.
  • Waves is a Moscow-based tokenization platform; Waves Enterprise was founded in July last year to offer services to corporate clients on private blockchains.
  • Although nothing has been confirmed, Waves said both sides wanted to use blockchain for new supply chain solutions as well as for the “tokenization of industrial assets.”
  • An industrial asset is a catch-all term that can refer to anything from heavy machinery to basic office equipment.
  • Microsoft Russia CEO Christina Tikhonova said the partnership was a push towards the country’s business sector getting to grips with blockchain technology.
  • Future solutions could be made available in Russia and internationally, Waves said.
  • The tie-in will look at the interplay between blockchain and cloud technologies; Waves Enterprise said it will also build a data analytics solution based on Microsoft Azure – the company’s cloud computing service.
  • In April, Russia’s Ministry of Communications officially recognized Waves as a potential technology provider for future government initiatives.

See also: Microsoft Files Patent Application for Crypto Mining System Powered by Human Activity

Related Stories
CoinDesk

Zcash Latest Hard Fork ‘Heartwood’ Makes Mining Private

6 years 2 months ago

Privacy coin Zcash has successfully hard forked in the planned network update “Heartwood.” With the update, miners can receive coinbase transactions right to a private address, in addition to other new features.

The hard fork occurred on July 16 at 10:58 UTC at block height 903,000, according to the Electric Coin Company (ECC), the for-profit development house behind the project. An uncontentious hard fork, Heartwood was supported by both the ECC and Zcash Foundation.

Read more: Zcash’s Funding Vote and the Woes of Decentralized Governance

Related: Fidelity International Doubles Stake in Bitcoin Mining Firm Hut 8

The update includes two Zcash Improvement Proposals (ZIPs). The first, “Shielded Coinbase” (ZIP 213) brings long-sought privacy solutions for Zcash (ZEC) mining while ZIP 221 “Flyclient” adds support for lightweight clients that verify transactions, the ECC said in a March blog.

As a hard fork, the updates are backward incompatible, meaning all nodes must sync to the new software in order to use the Zcash blockchain.

Heartwood is the privacy coin’s fourth hard fork since the network launched in late 2016. Zcash last hard forked in December 2019 with “Blossom.” 

“The Zcash Foundation is excited to support the Heartwood Zcash upgrade alongside the ECC, and thrilled that users will soon be able to connect to the Zcash network using Zebra, an alternate, consensus-compatible Zcash implementation built by the Foundation,” Zcash Foundation executive director Josh Cincinnati said in an email to CoinDesk. 

Related: Introducing the CoinDesk 20: The Assets That Matter Most in Crypto

(The Zebra client, written in Rust, was built in cooperation with Parity Technologies and released in June 2019).

Private coinbase transactions

Shielded coinbase transactions allow miners to claim coinbase transactions – the reward for processing transactions – directly to Zcash’s shielded addresses. Shielded addresses obfuscate information such as amounts, addresses and the encrypted memo field.

Implementing private coinbase transactions has been on the Zcash roadmap since the project’s early days. It was made possible by earlier technical updates found in 2018’s Sapling hard fork, according to the ECC.

“With this feature, when a mining pool or solo miner chooses to move coinbase rewards, [its] now private. For example, a mining pool can perform shielded payouts to miners in a shielded transaction,” ECC CTO Nathan Wilcox said in an email to CoinDesk.

Flyclient

Flyclient allows users to verify transactions with the smallest amount of information possible. Similar to Bitcoin Simplified Payment Verification (SPV) nodes, the spec proves the knowledge of a transaction using only the block header, rather than the full content of the block.

The ZIP has a few positive consequences for developers: It gives easier access to cross-chain interoperability, such as with the Ethereum network, and provides protection for light clients. The ECC announced plans to build interoperability projects with the second-largest blockchain by market cap, Ethereum, at DevCon 5 this past October.

Read more: Zcash Will Get a Gateway Into Ethereum’s DeFi Ecosystem

“Right now, you need a Zcash full node to get full privacy. Our ZIP helps protect light clients from malicious servers and pushes towards full privacy for every wallet,” said ZIP co-author and Summa founder James Prestwich in a private message.

Related Stories
CoinDesk

$1.4B in ‘High-Risk’ Crypto Flowed Onto Exchanges in H1 2020, Analysis Firm Says

6 years 2 months ago

Over $1.4 billion-worth of cryptocurrency tainted by illicit use moved onto global exchanges from January to June, according to blockchain analysis firm PeckShield.

The top 10 crypto exchanges to have received these “high-risk” assets include popular platforms such as Huobi, Binance, OKEx, ZB, Gate.io, BitMEX, Bithumb and Coinbase, the China-based firm said in a report released Tuesday. 

“The data highlights the current compliance challenge crypto exchanges face,” according to the report.

Related: Promoters of Crypto Ponzi Scheme OneCoin Murdered in Mexico

PeckShield said its analysis was based on over 100 million blockchain addresses it has labeled and tracked over the course of a year, including top-5 crypto assets like bitcoin, ether and tether.

Among these addresses, the firm identified many associated with Ponzi schemes, dark web transactions and hacks, as well as illegal online gambling operations that use cryptocurrencies as funding rails. 

The analysis suggests that various cryptocurrencies – equaling 147,000 bitcoin or over $1.4 billion in value at press time – have ended up in wallets on global exchanges. 

Separately, as of June 30, nearly $1.6 billion-worth of crypto assets from these high-risk addresses have entered cryptocurrency mixer services, after which they may end up at exchanges. Coin mixers obfuscate the source of transactions on-chain.

Related: Kraken Adds 3 DeFi Tokens – COMP, KAVA, KNC

In a follow-up report released Thursday, the firm revealed a chart with its data that shows Huobi, Binance and OKEx received the bulk of the tainted crypto transactions.

“The problem of the inflow of tainted cryptos has not been entirely put under regulation with strict enforcement,” the firm wrote in the report. “So anti-money laundering is considered as an important issue and then there’s no real follow-up. … But it’s a matter of time, not if, [until] the regulatory hammer will come [down].”

The findings come at a time the Financial Action Task Force, a global anti-money laundering watchdog, has been pushing for tougher enforcement of the so-called Travel Rule for crypto companies. 

The issue of crypto transactions tainted by illegal activities has recently hit over-the-counter trading desks in China, leading to the bank accounts of many being frozen by local law enforcement.

PeckShield added that, out of the 100 million blockchain addresses it has tracked, over 53 million belong to exchanges. Coinbase ranks top with 18 million bitcoin addresses, followed by Binance with 5.42 million.

Coinbase also holds the most cryptocurrency in the monitored addresses, with $11 billion-worth of assets. Huobi, Binance, Bitifnex, OKEx followed with $5.8 billion, $3.4 billion, $3 billion and $2.5 billion in crypto, respectively.

Related Stories
CoinDesk

OKCoin Joins Coinbase in Supplying Oracle Feed for DeFi Project Compound

6 years 2 months ago

OKCoin has launched a new API feed for the decentralized finance (DeFi) space that has already been picked up by lender Compound.

  • The San Francisco-based exchange said Wednesday that OKCoin Oracle would provide on-chain data for DeFi products and features.
  • As a liquid and regulated trading platform, OKCoin said its cryptographically signed price feed would be accurate, adding it would also verify and guarantee the data’s reliability.
  • San Francisco-based exchange Coinbase unveiled its own price feed plugin for the DeFi space in April.
  • Like Coinbase’s, OKCoin’s feed has been incorporated into the oracle system launched last August by Compound.
  • Known as the Open Price Feed System, Compounds oracle relies on data providers to effectively share data on-chain.
  • Rival oracle system ChainLink works broadly along the same lines, although it rewards third-party entities with LINK tokens for providing accurate data, and takes them away again when they don’t.
  • OKCoin was founded by Star Xu, who is also the founder of the separate exchange OKEx, which is based in Hong Kong.

See also: Why Crypto Exchange OKCoin Jumped Through Hoops to Get Licensed in Japan

Related Stories
CoinDesk

Man Charged With Defrauding $4.5M in Crypto to Fund Gambling Habit

6 years 2 months ago

A 27-year-old has been accused of defrauding investors into sending him millions of dollars in cryptocurrencies that he used on offshore gambling sites.

  • A criminal complaint filed July 9 at the U.S. Attorney’s Office charges Douglas Jae Woo Kim, who is based in New York, with wire fraud, alleging he conned three investors out of more than $4.5 million worth of bitcoin and ether.
  • The Department of Justice (DOJ) claims Kim told investors he was a cryptocurrency trader and asked for loans for a low-risk investment he claimed he had already invested $300,000 to $400,000 into.
  • The DOJ alleges that after receiving the funds, Kim sent either all or a substantial amount to offshore crypto gambling websites, Nitrogen Sports and Fairlay.
  • Between October 2017 and May 2020, the complaint says Kim convinced three investors to transfer a total of 123 bitcoin (~$1.1 million), 15,252 ether ($3.5 million), as well as approximately $30,000 in USD.
  • Although Kim promised loans would be repaid with high-levels of interest, the DOJ says that most of the bitcoin and all of the ETH has yet to be refunded.
  • Only one investor, so far, has been fully repaid.
  • Per an affidavit from the Federal Bureau of Investigation (FBI), none of the investors had any idea their money was being used on gambling sites.
  • The FBI also says Kim has been trying to convince new investors for loans since February 2020.
  • The DOJ has charged Kim with one count of wire fraud; he appeared before magistrates to face the charge on Wednesday.
  • If convicted, he faces up to 20 years in prison and a $250,000 penalty.

See also: Disgraced Lobbyist Jack Abramoff Pleads Guilty to Fraud in Crypto Case

Related Stories
CoinDesk

Man Charged with Defrauding $4.5M in Crypto to Fund Gambling Habit

6 years 2 months ago

A 27-year-old has been accused of defrauding investors into sending him millions of dollars in cryptocurrencies that he used on offshore gambling sites.

  • A criminal complaint filed July 9 at the U.S. Attorney’s Office charges Douglas Jae Woo Kim, who is based in New York, with wire fraud, alleging that he conned three investors out of more than $4.5 million worth of bitcoin and ether.
  • The Department of Justice (DOJ) claims Kim told investors he was a cryptocurrency trader and asked for loans for a low-risk investment that he claimed he had already invested $300,000 to $400,000 into.
  • The DOJ alleges that after receiving the funds, Kim sent either all or a substantial amount to offshore crypto gambling websites, Nitrogen Sports and Fairlay.
  • Between October 2017 and May 2020, the complaint says Kim convinced three investors to transfer a total of 123 bitcoin (~$1.1 million), 15,252 ether ($3.5 million), as well as approximately $30,000 in USD.
  • Although Kim promised loans would be repaid with high-levels of interest, the DOJ says that most of the bitcoin and all of the ETH has yet to be refunded.
  • Only one investor, so far, has been fully-repaid.
  • Per an affidavit from the Federal Burea of Investigation (FBI), none of the investors had any idea their money was being used on gambling sites.
  • The FBI also says Kim has been trying to convince new investors for loans since February 2020.
  • The DOJ has charged Kim with one count of wire fraud; he appeared before magistrates to face the charge on Wednesday.
  • If convicted, he faces up to twenty years in prison and a $250,000 penalty.

See also: Disgraced Lobbyist Jack Abramoff Pleads Guilty to Fraud in Crypto Case

Related Stories
CoinDesk

Binance CEO Criticizes Twitter Security After Coordinated Attack on Prominent Accounts

6 years 2 months ago

In a fireside chat at the World Blockchain Summit Asia on Thursday Binance’s CEO Changpeng “CZ” Zhao threw shade at Twitter’s security following coordinated attacks against prominent accounts on the platform Wednesday.

  • Starting with cryptocurrency firms like Coinbase, Gemini and Binance – and indeed CoinDesk – and moving on to big names such as Joe Biden, Barack Obama, Bill Gates and Elon Musk, the hackers were somehow able to post from the accounts offering a fake crypto giveaway.
  • Twitter has yet to provide a breakdown of how the mass attack was carried out, but says it's working on it.
  • Speaking to CoinDesk’s managing director of content products, Joon Ian Wong, Binance’s CZ said, while the bitcoin giveaway scam was rudimentary in its approach, it was a sign of how important strong security is for the industry.
  • CZ, whose account was also breached, said Twitter offers “limited security options” and the options that are available are a “little weak.”
  • He said he became aware of his own account being compromised after high profile accounts had also come under attack.
  • Twitter does provide two-factor authentication (2FA), but that seems to have been bypassed in the attack. Many of the affected accounts, including CoinDesk’s, had 2FA activated.
  • In the event of a hack where crypto funds are stolen from either individuals or exchanges, Binance seeks to blacklist the attacker’s addresses in coordination with other exchanges in order to deter future thefts, according to CZ.
  • Everyone in the community needs to work together and collaborate in order to “fight back” against bad actors in the space, he said.
  • Despite the hack of his and Binance’s accounts, CZ said Twitter is still his preferred social media platform due to its design and reach.
  • He had not yet regained control over his Twitter account at time of the interview.

See also: Binance Quashes Upbit Hackers’ Attempt to Launder Stolen Funds

Related Stories
CoinDesk

Twitter Hack Used Bitcoin to Cash In: Here’s Why

6 years 2 months ago

Someone hacked Twitter Wednesday – and they used bitcoin to capitalize on it.

But, why? 

Bitcoin is an alternative money system based on the value of censorship resistance. In other words, Bitcoin was built from the ground up to evade third-party interference (think banks, governments and law enforcement), making it a natural tool in the hands of a world-class hacker.

Related: Twitter Says ‘Coordinated Social Engineering’ Attack Caused Bitcoin Scam

Read more: Why Use Bitcoin?

Bitcoin’s value proposition can be broken into a few categories all based on the technology under the hood.

Once the hacker gets it, it’s theirs

Bitcoin is electronic. A popular meme for bitcoin is “magic internet money,” which, in a sense, it is. Bitcoin operates natively online – you can send bitcoin from your phone or computer to anyone else, just about anywhere in the world, in a few clicks, without anyone being able to stop you. And once you’ve sent it, you can’t get it back.

Read more: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

Related: Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

That feature – or in this case, a bother – is a prime reason Bitcoin exists. Bitcoin relies on what are called Peer-to-Peer (P2P) transactions in order to not be confiscatable by middlemen such as law enforcement. Once the coins are in someone else’s wallet, count them as good as gone.

Bitcoin is pseudonymous

Like many Twitter handles, bitcoin is pseudonymous. We can’t link an address to a personal identity very easily. 

Stolen USD, on the other hand, would be near impossible to get into and out of a bank account without being flagged. Traditionally, money is moved from one account to another through a third party. 

Legacy systems have the upside of being able to reverse transactions and attach identities to them. That is clearly a disadvantage to hackers. (Notably, reports surfaced of the hacker running a similar campaign on CashApp for USD). Bitcoin transactions, by comparison, are a lot harder to control.

Bitcoin is liquid

Bitcoin is also traded online in a lot of places. Holding bitcoins in your wallet wouldn’t be worth much without people to swap dollars for bitcoins. Launched in 2009, bitcoin is the most established and most highly traded digital asset. It’s also available on popular financial apps such as CashApp or PayPal.

Read more: Is Bitcoin Legal?

“It’s common sense that the attackers would choose Bitcoin. Bitcoin is the most censorship resistant and liquid asset in existence,” Blocksteam CSO Samson Mow said in a private message. 

All this to say that the Twitter hacker chose the right cryptocurrency to get U.S. dollars.

But bitcoin can be tracked and traced

Addresses can be tracked, however. And they can also be blackballed by others. By nature, the Bitcoin blockchain is 100% transparent. That means the ins-and-outs of transactions from one party to another are viewable for all to see with a little know-how.

For example, popular cryptocurrency exchange Coinbase would not allow users of its service to transfer funds to the Twitter hacker’s address. 

Blockchain analytics firm Chainalysis says the 12 or so bitcoins (worth about $110,000 at the time) the hacker netted are already on the move. But we can see where they are going. Some firms are even able to match “meatspace” identities with blockchain ones based on small details hackers overlook.

Having said that, there are tools available to people who really want to obfuscate their transactions, and whoever perpetrated this particular heist seems to be prepared to take measures to protect their loot.

At the end of the day, it’s important that people be wary of promises of free money on the internet – whether that comes in the form of dollars, pounds or bitcoin.

Related Stories
CoinDesk

Twitter Says ‘Coordinated Social Engineering’ Attack Caused Bitcoin Scam

6 years 2 months ago

Twitter claims “a coordinated social engineering attack” caused one of the world’s largest social media platforms to melt down on Wednesday after prominent celebrity profiles were used to promote a large-scale bitcoin scam.

  • A mass takeover of big-name celebrities including former Vice President Joe Biden, former U.S. President Barack Obama, Kanye West, and Elon Musk saw their accounts compromised, starting at 19:00 UTC.
  • Twitter said in a series of tweets that hackers targeted “some of” its employees who had access to internal tools, which they used “to take control of many highly-visible (including verified) accounts and Tweet on their behalf.”
  • The social media platform is looking into what else was impacted, while restoring accounts to their users.
  • Motherboard, VICE Magazine’s tech section, said it spoke to two sources who took over accounts, who claimed they paid a Twitter insider to manage the takeovers.
  • Twitter being “highly centralized” led to the hack, said Ben Sigman, CTO at blockchain startup Make Sense Labs.
  • Twitter employees have “godmode” access to create Tweets from any user, Sigman claimed.
  • It’s worth noting all addresses are bench32/Segwit addresses which helps narrow down the wallet and service being used.

See also: Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

Related Stories
CoinDesk

Chainalysis Says Bitcoin Scammed From Twitter Users Is ‘On the Move’

6 years 2 months ago

The defrauded bitcoin amassed during Wednesday’s monumental Twitter hack is already “on the move,” according to cryptocurrency tracing firm Chainalysis.

  • Chainalysis told CoinDesk it is monitoring four wallets associated with the attack.
  • The most prevalent address received $120,000 in bitcoin from 375 transactions. Secondary addresses received $6,700 in bitcoin from 100 transactions. An XRP wallet netted nothing.
  • So far, a wallet whose associations are not yet known has received 5 bitcoin ($46,055) in total. “We are collaborating with our customers to find leads from this wallet,” Chainalysis spokesperson Maddie Kennedy said.
  • Part of the scam relied on hackers churning their own crypto between wallets to inflate the number of people who appeared to be chipping in, according to Chainalysis. The firm called the tactic “unsurprising.”
  • A Japanese wallet that sent scammers $40,000 in bitcoin appears to have been the single largest victim of the still-unexplained hack. International exchanges were generally the source of victims’ bitcoin, Chainalysis said.
  • No BTC has been cashed out to fiat just yet, the crypto-sleuthing firm added.

Read more: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

Related Stories
CoinDesk

Twitter Breach Reactions: Security Professionals Offer an Early Assessment

6 years 2 months ago

@jack’s been pwned. 

All of Twitter went ablaze Wednesday afternoon as major crypto accounts started tweeting they had partnered with a phony site called “Crypto For Health” on a giveaway of 5,000 BTC.

It was a scam, but one that was able to reach the biggest accounts on Twitter, including that of former President Barack Obama, the most followed account in the world. 

Related: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Read more: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

Security pros contacted by CoinDesk had a wide array of opinions on the breach, but they all agreed the fault did not lie with each hacked account’s owner. They said the breach was likely from either third-party apps plugged into people’s Twitter accounts or from within the social media giant itself. 

“Whatever the root cause will end up being, this amount of total pwnage would say to me that this is something novel and mass exploitable, not something well known and targeted,” Erik Cabetas, managing partner at Include Security, told CoinDesk in an email.

Cabetas and Frans Rosén, another security professional from a firm in Europe called Detectify, pointed CoinDesk to this tweet, which detailed the following:

Related: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

(OTP stands for “one-time password,” a security method commonly used as part of 2FA, or “two-factor identification.”) The account @6 is for Adrian Lamo, a journalist with 163,000 followers, who has now put his account on private.

Jessy Irwin, a security professional formerly of AgileBits (maker of 1Password) and Cosmos maker Tendermint, said there are a lot of ways to hack into big accounts. 

“There are endless OAuth integrations, the APIs that allow third-party services to access the platform, and some of the SMS features,” she wrote. “[Twitter has] done some work to improve authorization and authentication, but if you are a super-user or you have a team posting for you, it’s still extremely difficult to secure the service.” 

Parham Eftekhari, of the Cybersecurity Collaborative, a forum for security pros, cautioned that all security professionals could do is speculate. The scale of the attack and Twitter’s frustrated response indicated the problem could be a deep one:

Inside the birdhouse

Many security-adjacent accounts are sharing rumors that the breach is actually from inside Twitter, which would suggest all kinds of data could be compromised. 

Richard Ma, founder of smart-contract auditing firm Quantstamp, told CoinDesk his team believed the problem was at Twitter’s San Francisco HQ.

“Based on what we’ve gathered so far, this is an internal Twitter security breach. The hacker was able to breach Twitter and gain access to internal admin functionality,” he told CoinDesk.

Irwin added:

“It is a ‘silly’ hack, but it’s also important to look and why people are motivated to hack things. Some hackers like to watch the world burn – that’s just how it is. It could be a campaign to make Twitter look silly or ill-prepared for the role it has in public discourse.”

Eftekhari agreed, noting it’s important to remember we are in an election year, and that Twitter is a de facto communications institution for the United States, which could be appealing to rival nation states. 

After all, he noted, the payout ($106,200 so far) was small.

Read more: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Irwin said associates in the security community have already noticed the domains being used by the cybercriminals have been active since April. “That suggests this is a known issue or an older vulnerability that was not recently introduced,” she said.

Yonathan Klijnsma, a threat researcher at the cybersecurity company RiskIQ, said that while he can’t be sure, there is speculation a Twitter support member account was hijacked.

“While we do not know if this is the cause, it might explain how they hijacked so many accounts,” Klijnsma told CoinDesk in an email. “Twitter support is able to help users who are locked out of their account by (normally) verifying information and then helping them get back into their account. Gaining access to a support member’s account could lead to the massive and seemingly effortless hijacking we observed today.”

He said the scale of the ongoing scam through these Twitter accounts with massive followings seems to be the whole story.

“But RiskIQ has been able to track much more of the bad guy’s infrastructure used in their scam operations,” said Klijnsma. “We’ve identified around 400 domains so far that are all tied to these scams.”

Scam’s source

Rosén emphasized to CoinDesk that he could only speculate, but noted that the origin of the tweets has been “Twitter Web App” and that Twitter Support noted people might expect trouble with resets. 

This suggested to Rosén that the “service used to send out password resets was breached somehow,” and that “some specific flow when resetting password made it possible to gain access to the web app.”

Which, he cautioned, might mean that the attacker could do more than tweet, such as accessing DMs. Dan Guido, of Trail of Bits, a security firm widely relied on in crypto, pointed CoinDesk to a thread he wrote on the incident on one of his firm’s secondary accounts. In that, he noted:

“Twitter has never been great at securing their own data. After getting their backend hacked in 2009 (very similar to today!), the FTC barred Twitter from making claims about their security for 20 years.”

Quantstamp’s Ma said this event could cement a key belief of the crypto faithful. 

“Overall I think this reinforces many people’s preference for self-custody of data in the crypto community,” Ma said. “Many Twitter users are not aware of the full control they are providing when using a third party platform with special privileges over their accounts.”

Related Stories
CoinDesk

Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

6 years 2 months ago

Twitter melted down Wednesday as the accounts of former President Barack Obama, presidential candidate and former Vice President Joe Biden, Kanye West, Elon Musk, prominent crypto Twitter figures, exchanges and others with verified accounts were hacked. Here’s a growing list of the victims:

People
  • Barack Obama
  • Joe Biden
  • Elon Musk
  • Benjamin Netanyahu
  • Floyd Mayweather
  • Kanye West
  • Changpeng Zhao
  • Charlie Lee
  • Justin Sun
  • Michael Bloomberg
  • Jeff Bezos
  • Warren Buffett
  • Wiz Khalifa
  • Bill Gates
  • xxxtencion
  • Kim Kardashian West
  • MrBeast
  • Numerous other minor and unverified Twitter accounts

Follow our coverage: Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

Exchanges and other crypto firms
  • Binance
  • Coinbase
  • KuCoin
  • Gemini
  • Bitfinex
  • Bitcoin
  • Ripple
  • CoinDesk
Corporates
  • Cash App
  • Apple
  • Uber

This is a developing story.

Related Stories
CoinDesk

Everything We Know About the Bitcoin Scam Rocking Twitter’s Most Prominent Accounts

6 years 2 months ago

Twitter’s thin veil of security went into full meltdown at 19:00 UTC on Wednesday.

Within minutes, an apparently coordinated hack began: A mass takeover of the most prominent names in crypto. Within hours, even Barack Obama’s account was compromised.

The messages pumped a bitcoin giveaway scam associated with an organization called “Crypto For Health.”

Related: Twitter Breach Reactions: Security Professionals Offer an Early Assessment

First, they came for Binance’s account. Gemini was next. Then Coinbase. CoinDesk. Justin Sun. Charlie Lee. Bitcoin.org. Kucoin. Bitfinex. The Tron Foundation. Ripple.

Millions of collective followers began seeing the same, cloying message: “I am giving back to my fans. All Bitcoin sent to my address below will be sent back doubled.”

About one hour in, the hack ditched its “Crypto For Health” tagline and went mainstream. Elon Musk’s account led the charge. Then Bill Gates. Then Elon Musk’s account came back for more. Kanye showed up an hour later. Jeff Bezos promised $50 million. Michael Bloomberg. Joe Biden. Barack Obama.

“I’m feeling generous because of Covid-19. I’ll double any BTC payment sent to my BTC address for the next hour. Good luck, and stay safe out there!” Musk’s account tweeted out. That post, like many of them, has since been deleted. (The hacker returned to Musk’s account for a second (and third) round, however.)

Related: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account

Read More: Obama, Biden, Netanyahu, Musk: Here’s a List of Every Hacked Twitter Account 

Apple, Uber get hit

By 21:00 UTC the hack had moved on to the tech giants. Apple’s account promised to double your bitcoin. Uber’s said it would return $10 million to users.

Hackers all linked to or directly promoted a single bitcoin wallet address. Some fell for it. By press time the wallet had received 11.5 BTC worth $106,200 and sent out 5.8 BTC worth $53,600 in 278 transactions. 

The hacked accounts collectively had at least 139.6 million followers. 

What was so perplexing about this hack was that some of these accounts had two-factor authentication. At least CoinDesk’s did.

With no easy explanation for how a single hack could target so many prominent Twitter accounts from such a broad spectrum – technology, entertainment, philanthropy, politics – Twitter users began to grasp for rumors. In the end, crypto was just once again ahead of the curve.

As news of the hack began to creep into the mainstream media, Twitter’s stock plunged 4% in after-hours trading.

This is a developing story.

Related Stories
CoinDesk

Swiss Crypto Bank SEBA to Offer Token Securitization on Corda Network

6 years 2 months ago

Switzerland’s licensed crypto-first bank SEBA and Corda-based Digital Asset Shared Ledger (DASL) announced a new partnership on Wednesday letting the bank offer asset securitization services on Corda’s public network.

  • In an emailed press release, SEBA said it is the first digital bank to offer clients the ability to issue and invest in blockchain tokens that represent real tradable assets like treasury bonds or foreign exchange contracts on the open-source blockchain platform Corda. 
  • SEBA said in its statement that it will create a custodial wallet for customers, issue digital securities and distribute them to investor networks.
  • Luzius Meisser, founder of Switzerland’s Bitcoin Association, told CoinDesk via an email that it was good to see SEBA moving forward with tokenization as it is an application to which distributed ledger technology can add value. 
  • Earlier this year, SEBA partnered with TokenSoft’s European distributor to offer asset tokenization services in what it said was an effort to bridge the gap between traditional and digital financial systems.
Related Stories
CoinDesk
Checked
5 minutes 1 second ago
CoinDesk Crypto
Leader in cryptocurrency, Bitcoin, Ethereum, XRP, blockchain, DeFi, digital finance and Web 3.0 news with analysis, video and live price updates.
Subscribe to CoinDesk Crypto feed