|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Cryptocurrency News Articles
Loopring Collaborates with Experts and Authorities After Hackers Exploit 2FA Vulnerability to Drain Millions of Dollars
Jun 10, 2024 at 06:00 pm
On Sunday, Loopring, the Ethereum-based ZK-rollup protocol, experienced a major security breach. This incident resulted in losses reaching millions of dollars.

Loopring, an Ethereum-based ZK-rollup protocol, encountered a significant security breach on Sunday, leading to losses in the millions of dollars.
The attack exploited a vulnerability in Loopring's Guardian wallet recovery service, specifically targeting the two-factor authentication (2FA) process.
After the Hack, Loopring Cooperates with Experts and Authorities
Loopring's Guardian service enables users to designate trusted wallets for various security tasks, such as locking a compromised wallet or restoring one if the seed phrase is lost. However, the attacker managed to bypass this service, performing unauthorized wallet recoveries with a single guardian.
The vulnerability in Loopring's 2FA service allowed the attacker to impersonate the wallet owner, gaining approval for the recovery process, resetting ownership, and withdrawing assets from the affected wallets. Notably, the exploit primarily affected wallets that did not have multiple or third-party guardians.
The team has identified two wallet addresses involved in the breach. On-chain data reveals that one wallet drained approximately $5 million from the compromised wallets, which have now been fully swapped to Ethereum (ETH).
Loopring stated that they are working with Mist security experts to uncover the method used by the attacker to compromise their 2FA service. To safeguard users, Guardian-related and 2FA-related operations have been temporarily suspended, which ultimately halted the compromise.
“Loopring is working with law enforcement and professional security teams to track down the perpetrator. We will continue to provide updates as soon as the investigation progresses,” the team added.
This incident follows a recent data breach at crypto market data aggregator CoinGecko, which was accessed through its third-party email service provider, GetResponse.
On June 5, the attacker compromised the account of a GetResponse employee and exported nearly 2 million contacts from CoinGecko's account.
Subsequently, the attacker sent 23,723 phishing emails using the account of another GetResponse client. However, it's important to note that the malicious actors did not use CoinGecko's domain to send harmful emails.
CoinGecko also reassured its users that the breach did not compromise their accounts and passwords. Nevertheless, the leaked data included users' names, email addresses, IP addresses, and the locations where emails were opened.
In response to the breach, CoinGecko advised users to remain vigilant, particularly regarding emails offering airdrops. The platform also highlighted the importance of avoiding links or email attachments from unfamiliar senders and adhering to recommended security measures.
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.
-
- AVAX Price Surges as Avalanche Chain Embraces Tokenized Funds and Institutional Growth
- Sep 18, 2026 at 04:05 pm
- Avalanche's recent rebound and strategic moves into tokenized funds and institutional liquidity signal a potential turning point for AVAX, as the network positions itself for long-term growth and broader adoption.
-
- Bank of Japan's Rate Hike: Yen, Bitcoin, and the Unwinding of Carry Trades
- Sep 18, 2026 at 12:05 pm
- The Bank of Japan's recent interest rate hike sends ripples through global markets, making yen-funded trades pricier and impacting Bitcoin's standing against the Japanese currency, while sparking debates on capital flows and risk asset volatility.
-
-
- CFTC Offers Broker Registration Relief for Passive Crypto Trading Software, Signals Broader Regulatory Shift
- Sep 18, 2026 at 11:55 am
- The CFTC is providing significant relief for passive crypto trading software, easing broker registration burdens and signaling a proactive approach to crypto regulation amid legislative delays.
-
- U.S. Tightens Grip: New Sanctions Target Iranian Crypto Exchange BitBank Amid Maritime Payment Probe
- Sep 18, 2026 at 11:55 am
- The U.S. Treasury has sanctioned BitBank, an Iranian cryptocurrency exchange, for allegedly facilitating Bitcoin payments linked to maritime traffic through the Strait of Hormuz.
-
- US Treasury Sanctions Iranian Exchange BitBank Over $1 Billion in Crypto Flows: A New York Take
- Sep 18, 2026 at 11:55 am
- The US Treasury has sanctioned Iran-based BitBank, alleging it processed $1 billion in Bitcoin for Iran's Revolutionary Guard through the 'Hormuz Safe' scheme, signaling Washington's intensified crackdown on crypto-based sanctions evasion.
-
- North Korea Malware & Asia Express: CoinEx's Exit Amidst a Shifting Digital Landscape
- Sep 18, 2026 at 08:05 am
- Amidst rising North Korean cyber threats and a dynamic Asian crypto scene, CoinEx, a Hong Kong-founded exchange, shutters after nine years, signaling a pivotal moment for regional digital asset markets and regulatory landscapes.
-
-
- Vitalik Buterin Challenges AI Cybersecurity Doom Narrative, Advocates for Formal Verification
- Sep 18, 2026 at 12:05 am
- Vitalik Buterin, Ethereum co-founder, refutes the 'AI doom narrative' in cybersecurity, asserting AI's potential to bolster defenses through formal verification, a stance underpinned by Ethereum's ongoing security research.

































