Coinbase reports 6,000 crypto account hacks after SMS flaw

Lời nói đầu:Hackers used an unusual vulnerability to steal crypto from user accounts at the American crypto exchange.

Over 6,000 Coinbase users saw their drained last week as hackers exploited an authentication bug to bypass the companys SMS security feature, tech publication Bleeping Computer reported.

Coinbase said it would reimburse the stolen amounts to make up for damages and did not report further security breaches as of press time.

The hackers exploited a vulnerability to bypass the SMS authentication feature put in place by Coinbase to ensure user security. They illicitly gained access to user email addresses, passwords, and associated phone numbers, and used this information to log in.

Hackers may have conducted large-scale phishing campaigns to gain access to such sensitive information—said Coinbase—one that unsuspecting users willingly gave out.

Banking trojan viruses have, in addition, been known to hit Coinbase users in the past.

Inside the Coinbase hit

As part of its security, hackers with access to a Coinbase customers credentials and email account are normally prevented from logging into an account if a customer has multi-factor authentication enabled.

However, Coinbase said a vulnerability existed in their SMS account recovery process, allowing the hackers to gain the SMS two-factor authentication token needed to access a secured account.

“Even with the information described above, additional authentication is required in order to access your Coinbase account,” a notification read.

It added, “In this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbases SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.”

Coinbase patched the bug shortly after it was discovered. Meanwhile, the exchange said it would reimburse the stolen funds directly into the accounts of affected users.

“We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed — we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today,” a notice sent to users read.

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

AUTOMATED MARKET MAKER (AMM) LÀ GÌ?NHỮNG LƯU Ý VỀ AMM MÀ TRADER CẦN BIẾT

Bài tiếp theo

TIỀN ĐIỆN TỬ ĐƯỢC SỬ DỤNG ĐỂ RỬA TIỀN NHƯ THẾ NÀO?