OKX Becomes Latest Victim Crypto Theft As SMS Notification Security Fails

Bhushan Akolkar
June 10, 2024
Why Trust CoinGape
CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Pink Drainer Shuts Down After $75M Crypto Theft, Attacking 20K Victims

Highlights

  • Users of the OKX exchange reported significant thefts by breaching the platform's SMS notification security.
  • OKX is actively investigating the reported thefts and has contacted the affected users.
  • The exchange has committed to taking full responsibility if found at fault.

The total number of crypto theft incidents has been rising once again with hackers adopting innovative methods to siphon off user funds. In the latest development, users of the crypto exchange OKX reported major theft while breaching through the SMS notification security of the platform.

OKX Exchange Accounts Compromised

On Sunday morning, SlowMist reported that two different victims had their OKX exchange accounts stolen using surprisingly similar methods and features. According to SlowMist, both incidents involved SMS risk notifications originating from “Hong Kong” and the creation of new API keys with withdrawal and trading permissions. Initially suspected to be cross-trading attempts, this theory has since been ruled out. Last week, a Binance user faced similar theft losing over $1 million in crypto due to a cross-trading plugin.

The attacks were carried out by a premeditated gang in a concentrated manner. SlowMist’s tracking team, MistTrack, is actively monitoring the hacker wallet addresses involved in both incidents and will continue to provide updates. However, specific details of the incidents will not be disclosed without the victims’ consent.

Notably, 2FA authentication tools like Google Authenticator were not enabled by the victims, though it remains uncertain if this is the key factor in the breaches. SlowMist advises against panic, suggesting that a larger impact would likely result in more exaggerated related events.

Crypto Exchange Takes Responsibility

OKX, a leading cryptocurrency exchange, has responded to reports of stolen user assets circulating online today. The exchange has initiated contact with the affected users and is actively investigating the incidents.

In a statement, OKX emphasized its commitment to resolving the issue, assuring that if the platform is found responsible, it will take full responsibility for the losses. The exchange has promised to announce the investigation results as soon as they are available and urged users to remain patient and refrain from unnecessary speculation.

During the Binance attack, the crypto hacker employed a sophisticated method to manipulate his account and evade detection. By holding his web cookies hostage, the hacker executed large trades in the USDT trading pair, which has high liquidity. Additionally, the hacker placed limit sell orders at inflated prices in pairs with scarce liquidity. This strategy enabled the hacker to profit significantly without triggering any security alerts from Binance.

Advertisement
coingape google news coingape google news
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Why Trust CoinGape

CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights Read more…to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

About Author
About Author
Bhushan is a seasoned crypto writer with over eight years of experience spanning more than 10,000 contributions across multiple platforms like CoinGape, CoinSpeaker, Bitcoinist, Crypto News Flash, and others. Being a Fintech enthusiast, he loves reporting across Crypto, Blockchain, DeFi, Global Macros with a keen understanding in financial markets. 

He is committed to continuous learning and stays motivated by sharing the knowledge he acquires. In his free time, Bhushan enjoys reading thriller fiction novels and occasionally explores his culinary skills. Bhushan has a bachelors degree in electronics engineering, however, his interest in finance and economics drives him to crypto and blockchain.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.