Cryptospace Spotlight #30 (24 Jul 2022): Blockchain security startup raised $90M. NFT platform compromised. Polygon unveiled zkEVM. Dubai announced metaverse strategy.
Blockchain security startup Halborn raised $90M, NFT platform PREMINT was compromised and lost 320 NFTs, Polygon unveiled zkEVM to reduce transaction costs and increase throughput!
Technology and Industry
Polygon unveiled - zero knowledge Ethereum Virtual Machine (zkEVM) - a technology it claims that will reduce transaction costs and greatly increase throughput on a layer-2 rollup which inherits the security of Ethereum.
A closed testnet of Polygon’s zkEVM should be available within two weeks with a public permissionless testnet to follow a few weeks later. The product is expected to reach the Ethereum mainnet by year’s end
Blockchain security startup Halborn raised $90M in a new early-stage funding round led by Summit Partners despite crypto winter. [more]
Founded in 2019, Halborn offers cybersecurity for blockchain organizations that continually assesses an organization’s vital assets. The company’s services include security advisory, advanced penetration testing, smart contract audits, DevOps and automation.
The difficulty of mining a bitcoin block dropped by 5% on Thursday as miners turned off their machines to lower power demands on energy grids dealing with a U.S. heat wave, particularly in Texas. [more]
BNP Paribas Securities selects Fireblocks, METACO for digital asset custody [more]
DBS Bank CEO Piyush Gupta pointed out that blockchain will power 'the back office of the world' in 5 to 10 years. [more]
Minecraft's developer Mojang Studios said that it would be excluding the integration of NFTs alongside blockchain technology as a whole, in its game. [more]
Tesla sold about 75% of its Bitcoin to add $936 million to balance sheet. [more]
Three Arrows founders tell Bloomberg 'the whole situation is regrettable'. [more]
Su Zhu revealed the 3AC team had close ties to Terra co-founder Do Kwon, which made them overlook several red flags with the project that eventually led to a multi-million dollar loss for the hedge fund.
Southeast Asian crypto exchange Zipmex announced on Wednesday that it is halting all withdrawals. Following which, it said on Thursday night that it will prolong its customer withdrawal freeze until Friday, “to prevent any technical issues,” while it did not specify a time. [more][more-Zipmex]
Founded in 2018 by Marcus Lim and Akalarp Yimwilai, Zipmex lists 2 million users and primarily operates in Singapore and Thailand, and offers services in Australia and Indonesia. [more]
Zipmex Thailand, the locally regulated entity, paused operations for an hour on Wednesday night, citing market volatility and liquidity problems faced by partner Zipmex Global Singapore. It was the first admission by an Asian firm of exposure to crypto lenders Celsius, and Babel Finance. [more]
CEO of Zipmex Thailand encouraged customers to join a class action lawsuit that Zipmex Thailand is preparing to file against Zipmex Global.
Thailand’s Securities and Exchange Commission (SEC) questioned the exchange on Thursday to clarify its amount of customer assets under management and details of how deposited funds were used.
Policy and Regulatory
United Kingdom - UK’s Treasury said it will seek to regulate “certain types” of stablecoins as a form of payment in a wide-ranging financial bill designed to phase out hundreds of pieces of EU-retained law. [more]
Financial Markets Infrastructure Sandboxes, included in the UK’s Financial Services bill, will also be created in a bid to allow firms to test new technologies and practices.
South Korea - Cryptocurrency exchanges in South Korea are being searched for links to the infamous Terraform Labs, the organization behind the Terra ecosystem in the wake of its stablecoin crash. [more]
Prosecutors want to examine seized materials, question witnesses and determine whether TerraUSD’s crash was intentional
United States - The US Securities and Exchange Commission (SEC) alleged that a former Coinbase product manager and people close to him traded cryptocurrencies based on confidential information. [more]
The SEC alleges that the group “perpetrated a scheme to trade ahead of multiple announcements regarding certain crypto assets that would be made available for trading on the Coinbase platform”.
Dubai - His Highness Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, crown prince of Dubai and chairman of the Dubai Executive Council, unveiled the metaverse strategy. The strategy aims to attract over 1,000 firms and is expected to support the creation of more than 40,000 virtual jobs by 2030. [more]
Taiwan - Financial Supervisory Commission (FSC) banned crypto purchases using credit cards with the issuance of issued a letter to the banking industry association asking that they not grant “merchant status” to virtual asset providers which service credit card holders. [more]
Details of the letter stated that digital assets are highly speculative and prices are often extremely volatile.
Hong Kong - Hong Kong Monetary Authority (HKMA) CEO Eddie Yue has stated that despite the shortcomings in the cryptocurrency sector, the industry is likely to play a central role in future financial systems. [more]
Financial Stability Board - The FSB said that it is working on a “robust” regulatory framework for crypto assets and will report its recommendations to the G20 finance ministers and central bank governors in October. [more]
Security and Risk
17 Jul - NFT platform PREMINT was infiltrated by attacker and lost 320 NFTs. [more] [more-Premint]
The attacker manipulated a JavaScript file on PREMINT that led to users being presented with a wallet connection that was malicious.
This was possible due to a software vulnerability in an open source tool used by PREMINT to facilitate users uploading their custom images to an Amazon S3 bucket. The vulnerability allowed the attacker to upload files to destinations outside the specified directory within the bucket, including a folder that contained a small subset of the JavaScript PREMINT uses.
The malicious code rewrote parts of the PREMINT login and project pages to replace the standard “Connect Wallet” dialog with a different, malicious dialog, which instead requested full access to the victims’ wallets.
Premint announced that it will repay these victims. It is also acquiring wallet security firm Vulcan to help prevent hacks from happening again. [more]
Yuga Lab indicated that its security team has been tracking a persistent threat group that targets the NFT community. [more]
It believed that they may soon be launching a coordinated attack targeting multiple communities via compromised social media accounts.