Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

admin
Pinned February 21, 2022

<> Embed

@  Email

Report

Uploaded by user
New US stock exchange will use the blockchain to track trading activity
<> Embed @  Email Report

New US stock exchange will use the blockchain to track trading activity

Coinbase hackers exploit multi-factor flaw to steal from 6,000 customers

The flaw allowed the bad actors to receive the victims 2FA tokens via text.

Mariella Moon
M. Moon
October 2nd, 2021
New US stock exchange will use the blockchain to track trading activity | DeviceDaily.com
dulezidar via Getty Images

Bad actors were able to infiltrate the accounts of and steal cryptocurrency from around 6,000 Coinbase customers by exploiting a multi-factor authentication flaw, according to Bleeping Computer. The cryptocurrency exchange told the publication that its security team observed a large-scale phishing campaign targeting its users between April and early May 2021. Some users may have fallen victim to the malicious emails, giving hackers access to their usernames and passwords. Worse, even those who had multi-factor authentication switched on were compromised because of a flaw in the exchange’s system.

In the notification [PDF] it sent to affected customers, Coinbase said the bad actors took advantage of a vulnerability in its SMS Account Recovery process. That allowed the hackers to receive the two-factor token that was supposed to be sent via text to the account owner’s phone number. 

Coinbase recommends using two-factor with a security key on its website, followed by an authenticator app. It lists SMS authentication as a last resort, advising users to lock their mobile accounts to protect themselves from SIM swap scams or phone port frauds. Back in August, Coinbase also notified 125,000 users that their two-factor settings had changed, but the exchange said back then that the notification was sent by mistake and wasn’t the result of a hack.

In its letter to customers, Coinbase said it patched up its SMS Account Recovery protocols as soon as it learned about the issue. It’s also reimbursing everyone who’s lost cryptocurrency from the event. Those who were affected by the hack may want to make sure all their other accounts are secure, though, since it also exposed their names, addresses and other sensitive information when their accounts were infiltrated.

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics   

(23)