Telegram (AI) YouTube Facebook X
Ру
Security Flaws Uncovered in OKX Settings

Security Flaws Uncovered in OKX Settings

A swift examination of OKX users’ security settings has revealed vulnerabilities that could lead to financial losses in the event of a potential attack. This research was conducted by a group of Web3 security enthusiasts.

The analysts conducted their review on June 10, 2024, spending half an hour on the task. During this time, they discovered that the system allows users to bypass Google Authenticator and switch to less secure verification methods (SMS, whitelisting addresses, etc.).

User actions such as disabling phone verification, Google Authenticator, and changing passwords do not trigger a 24-hour withdrawal freeze. The restriction only activates when logging in from a new device, according to the report.

When withdrawing assets from whitelisted addresses, dynamic checks based on the amount are not employed. Researchers cite other exchanges that set limits requiring re-verification for large withdrawals.

“These issues were identified through a quick analysis. It is evident that OKX’s security settings lack basic design. Perhaps, to enhance user experience, [the exchange] has made numerous compromises in security,” the report’s authors speculated.

Previously, journalist Colin Wu reported on an OKX client who lost over $2 million through AI manipulation.

Earlier in June, CISO of SlowMist, known as 23pds, presented a ranking of reasons why individual and institutional investors lose their digital assets.

The thread followed a detailed analysis of an incident where a trader lost $1 million in cryptocurrency on Binance due to a malicious Chrome browser extension, although the user blamed the exchange.

Binance co-founder Yi He denied the platform’s responsibility for the incident. She noted that the hacker manipulated the trader’s device through a plugin, and the exchange team could not influence the situation.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK