0%

How Coinbase responds to industry-wide crypto security threats

Aug 24, 2021 3 min read
News Article Banner Image

That’s why it’s important to have a community mindset when we see security threats in the wild. As they say, rising tides lift all boats.

Security incidents aren’t unique to crypto but when they happen, the crypto industry has the unique advantage of being able to immediately analyze how stolen funds have moved on the relevant blockchains. This allows us to work with each other to freeze funds and return stolen assets to victims.

Earlier this month, Poly Network, a cross-chain DeFi protocol, and Liquid, a Japanese crypto exchange, reported sophisticated cyberattacks against their platforms. In both of these cases, Coinbase rapidly mobilized our teams to scope the situation, provide analysis and international cross-team collaboration to determine and mitigate the impact on the crypto industry (to be clear neither attack impacted the Coinbase threat platform.)

Coinbase works with industry partners to offer intelligence analysis on attacker tactics, techniques and procedures (TTPs), as well as blockchain analysis. For example, we regularly help connect victims of cyber intrusions (whether crypto exchanges or decentralized finance (DeFi) projects) to the appropriate communication channels with the rest of the virtual asset service provider (VASP) community to make sure swift and decisive action is taken.

Our specific responses depend on the type of attack, but in the case where funds are stolen, Coinbase will:

  • Block any addresses that are identified as a part of the attack from sending funds to Coinbase customers

  • Identify these addresses in our Coinbase Analytics tool (which propagates to internal and external customers of that tool)

  • Track the movement of funds using Coinbase Analytics and other analysis tools

  • Proactively reach out to ecosystem partners for additional information that might be useful in identifying the attacker

Coinbase has built relationships with the compliance, security, and other investigations functions at several exchanges and ecosystem organizations, which has helped create a trusted network of intelligence professionals that benefit from shared information when appropriate.

Sharing intelligence and analysis quickly is the most effective manner of disrupting unauthorized use of crypto exchanges and protecting our collective community of customers. By exchanging information about attacks, we can learn about attackers’ tactics and techniques, which ultimately help us defend Coinbase. Collaboration also improves our relationship with other exchanges for future incidents and helps make the crypto ecosystem more secure.

Although we’ve seen a steady decline in the financial impact of cryptocurrency exchange compromises over the past two years, there are advanced, persistent groups that continue pursuing new targets. By staying vigilant and working together we have successfully countered the actions of bad actors. For example, last September, KuCoin experienced an attack which led to the loss of $281,000,000 in funds. Ultimately, KuCoin was able to recover a large portion of stolen funds by working closely with exchange and asset issuer partners. Similarly, Liquid has already announced that $16,130,000 of the stolen ERC-20 assets have been frozen through collaboration with the cryptocurrency ecosystem.

When it comes to cybersecurity threats, it’s most important that we work together and self-regulate during these events. We encourage all organizations experiencing or suspecting a cyberattack to reach out to our security team at [email protected], in case we can help with blockchain analysis, incident response and investigation, and attacker attribution/identification.

was originally published in The Coinbase Blog on Medium, where people are continuing the conversation by highlighting and responding to this story.

Popular news

How to Set Up and Use Trust Wallet for Binance Smart Chain
#Bitcoin#Bitcoins#Config+2 more tags

How to Set Up and Use Trust Wallet for Binance Smart Chain

Your Essential Guide To Binance Leveraged Tokens

Your Essential Guide To Binance Leveraged Tokens

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)
#Subscriptions

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)

What is Grid Trading? (A Crypto-Futures Guide)

What is Grid Trading? (A Crypto-Futures Guide)

Start trading with Cryptohopper for free!

Free to use - no credit card required

Let's get started
Cryptohopper appCryptohopper app

Disclaimer: Cryptohopper is not a regulated entity. Cryptocurrency bot trading involves substantial risks, and past performance is not indicative of future results. The profits shown in product screenshots are for illustrative purposes and may be exaggerated. Only engage in bot trading if you possess sufficient knowledge or seek guidance from a qualified financial advisor. Under no circumstances shall Cryptohopper accept any liability to any person or entity for (a) any loss or damage, in whole or in part, caused by, arising out of, or in connection with transactions involving our software or (b) any direct, indirect, special, consequential, or incidental damages. Please note that the content available on the Cryptohopper social trading platform is generated by members of the Cryptohopper community and does not constitute advice or recommendations from Cryptohopper or on its behalf. Profits shown on the Markteplace are not indicative of future results. By using Cryptohopper's services, you acknowledge and accept the inherent risks involved in cryptocurrency trading and agree to hold Cryptohopper harmless from any liabilities or losses incurred. It is essential to review and understand our Terms of Service and Risk Disclosure Policy before using our software or engaging in any trading activities. Please consult legal and financial professionals for personalized advice based on your specific circumstances.

©2017 - 2024 Copyright by Cryptohopper™ - All rights reserved.