Investing in crypto: how to stay away from weak players

Kostiantyn Oleshko

The main reason behind the hacks of crypto exchanges is weak key management. For example, all 4 hacks that took place in 2021 were caused by the ability of hackers to obtain access to hot wallets. 

Crypto exchanges market: (un)safe heaven for investors’ money

Crypto exchanges are playing a central role in the functioning of the crypto market. According to CoinGecko, there are a bit more than 400 active crypto exchanges as of middle May. More than 30 exchanges process greater than $1B daily trading volume. Users are interested in being confident of the security of their assets traded. 

Since 2012, crypto exchanges have lost $2.66B as a result of hacks. The total number of exchanges that have fallen victim is 46. In 2020, there were 9 recorded hacks of crypto exchanges, the biggest one was the KuCoin hack ($275M). In 2021, there were only 4 recorded hacks, the biggest one was the BitMart hack ($150M). Thus, it is reasonable to note that the state of security in the crypto exchanges industry has improved. 

The main reason behind the hacks of crypto exchanges is weak key management. For example, all 4 hacks that took place in 2021 were caused by the ability of hackers to obtain access to hot wallets. 

But crypto exchanges are just middlemen. What about the security of the final destination for your money – cryptocurrencies? According to the recently released security rating of cryptocurrencies – more than 90% of the top 1,500 cryptocurrencies by CoinGecko do not have all basic security features in place

White hat hackers fighting against cybercrime

While common users most often fall victim to simple social engineering attacks such as phishing, crypto projects have experienced advanced cyberattacks involving the use of novel attack vectors. 

For example, in the Axie Infinity breach, hackers attacked the bridge, and networks that connect blockchains. Hackers managed to compromise Ronin network, the own blockchain created by Axie Infinity. Exploiters used hacked private keys to forge fake withdrawals and compromised other key validator nodes. When speaking about bridges, the attack surface is much greater compared to normal DeFi projects. 

Also, bad actors actively utilize flash loan attacks to get voting power without collateral. Flash loans are possible via decentralized lending protocols. They often involve complex financial transactions. If smart contracts are not properly designed, they are vulnerable to flash loan attacks. 

Unfortunately, by solely relying on their internal cybersecurity efforts, projects cannot eliminate all possible security threats. Cooperation with ethical hackers constitutes a universal security solution for crypto projects. Namely, crypto projects run bug bounty programs on reputable platforms such as Yes We Hack, Immunefi, or HackenProof and reward ethical hackers for finding bugs. And bug bounty programs are becoming a must-have testing process for successful projects.

How to see whether your chosen token is a safe option?

  • Look for its audit report. Smart contract audit report shows whether the token’s code contains vulnerabilities including the critical ones. Also, try to verify whether the code deployed by a project matches the audited code. Namely, check whether the code published, for example, on Etherscan/BSCscan is the same as the code audited. If there is no match, it is likely that a project tries to manipulate its users. 
  • Look for a platform audit. For utility tokens, there is a risk that users may lose their assets due to vulnerabilities in their platforms such as DEX or farming services. 
  • Try to find the project’s bug bounty program. An active public bug bounty program run by a project on a reputable platform is a strong indicator of ensuring the security of users’ assets and data.
  • Check whether a project has insurance. Insurance guarantees that even if a project is hacked, investors will get their money back. 
  • Analyze its history. Be careful when finding a project with previous hack cases.

Conclusion

Security breaches, rug pulls, phishing and other forms of scams undermine users’ trust in crypto. Weak security and high volatility are the factors deterring the real mass adoption of crypto. By improving the security of virtual assets, we can make crypto much more attractive for investors and, thus, prevent or mitigate the negative effects of possible crypto winter. 

Kostiantyn Oleshko, product owner at CER.live.

About Kostiantyn Oleshko: Kostya is a master of science in applied cryptography with 6+ years of expertise in the blockchain industry. He used to work as a Project Manager at many crypto projects, including the entities linked to the National Bank of Ukraine that were developing E-Hryvnia, Ukrainian CBDC. He strongly believes that security is the key to crypto mass adoption.

Read this next

Retail FX

eToro valuation halved as SPAC merger deadline expires

The deadline for the completion of the SPAC merger of eToro had passed yesterday, June 30, and the Israeli broker apparently canceled the deal with Betsy Cohen-backed blank-check firm.

Institutional FX

FXSpotStream reports second best figure for monthly volumes

Trading volumes on institutional FX platforms surged in June after fears over the impact of Russia’s military invasion of Ukraine sent speculative asset classes reeling.

Retail FX

Vantage expands MT5 offering with access to new stocks

ASIC-regulated foreign exchange brokerage Vantage has expanded its service offering and trading products by incorporating new markets, namely 14 exchange-based stocks on MetaTrader 5.

Digital Assets

CFTC charges $1.7 billion Bitcoin scam, largest to date

Mirror Trading accepted at least 29,421 Bitcoin from approximately 23,000 investors from the United States and even more throughout the world.

Retail FX

Spotware Systems upgrades cTrader Desktop to version 4.3

Spotware Systems, a technology provider for the electronic trading industry, has launched an updated version of its cTrader Desktop, which adds new functionality to join a roster of advanced trading capabilities.

Digital Assets

OKX launches Block Trading for tighter pricing

With Block Trading, users can integrate spot and derivatives trades on the same platform and trade multiple currencies in a single trade. The service supports trading of perpetual swap, futures, and option contracts with popular altcoins as the underlying.

Industry News

Interactive Brokers pays $1 million to settle with CFTC

Interactive Brokers overcharged its customers a total of $710,828.14.

Metaverse Gaming NFT

DappRadar launches cross-chain token staking

The launch of the cross-chain token staking mechanism by DappRadar comes under a partnership with LayerZero protocol, which enables smart contracts to communicate across different chains.

Digital Assets

Polkadot releases one-stop marketplace for Substrate pallets

Proof-of-stake blockchain Polkadot has achieved a significant feat in its development, as it rolls out Substrate Marketplace, a one-stop shop for exploring the many Substrate pallets currently available.

<