The digital financial services developer Enigma prides itself on ultra-secure products . The company's Catalyst platform protects financial info with a cutting-edge combination of blockchain-inspired privacy technology and cryptography. So it comes as no small surprise that on Monday, scammers took over the company's website, mailing lists, and Slack accounts by exploiting some extremely basic security mistakes Enigma had made. The blunders also facilitated a scam that ultimately cost Enigma supporters almost $500,000.
Enigma has planned an Initial Coin Offering for September 11an unregulated cryptocurrency fund-raising campaign that startups use when they want to raise capital for their company without going through the process of working with an established financial institution or venture capital fund. (The SEC has promised to clamp down on these ICOs , but so far is in the exploratory phase.)
Tom Simonite
Regulators Warn Cryptocurrency Startup Fundraisers to Play By the Rules
Gabriel Nicholas
Ethereum Is Coding's New Wild West
Brian Barrett
Security News This Week: Two Huge Cryptocurrency Heists Cost Investors Millions
With the ICO in mind, scammers compromised official Enigma channels to create a sense of legitimacy and urgency. The plot proved easy to pull off. At least one of the passwords protecting the Enigma accounts, which included a Slack account with administrative privileges, had previously leaked, and reports indicate that the accounts weren't protected by two-factor authentication.
The hackers began defacing the company's main site and Slack accounts, and pushed a special "pre-sale" ahead of the ICO, directing money toward their own cryptocurrency wallet. They also went rogue on the company's mailing lists. Many users realized that the push was a scam, but the hustle did tempt some interested backers into sending 1,492 coins in the cryptocurrency Ethereum, which converts to almost $495,000.
Enigma said in a statement on Monday that its community fund-raiser, also called a crowd sale, was always set definitively for September 11, and emphasized that its secure servers had not been hacked. But a spokesperson confirmed that the scammers compromised account passwords using various methods. And in response to the incident, the company says it is adding strong, random passwords and two-factor authentication for each account, plus implementing robust password changing and better system compartmentalization. "Weve moved up a number of critical security steps and taken additional measures to protect the community going forward," says Tor Bair, Enigma's head of marketing and growth. "Were now very well aware of the potential threats and are taking no chances."
Though honest mistakes can happen at any growing organization, the Enigma community grappled with the implications of the incident on Monday, wondering how a specialized cryptography company could only now be realizing the need for stringent account hygiene. "This will go down in crypto history as one of the stupidest moments ever. We need a meme," one Reddit user wrote. Some Redditors even claimed that they used the breached credential repository Have I Been Pwned to determine that the Enigma accounts scammers accessed reused a previously exposed account password from CEO Guy Zyskind. But Zyskind told WIRED that none of the breached Enigma accounts relied on reused passwords.
While the Enigma team worked to restore secure Slack service, the community's discussion moved to secure messaging app Telegram. "No word on honoring those who were scammed b/c of y'all negligence and poor security? Speaks volumes," a user called Jay wrote in the open chatroom. Many users indicated support for Enigma, though, and seemed satisfied with the company's remediation efforts.
"Hacking accounts that do not have dual-factor authentication enabled and other best in class security measures is a trivial hack for most dedicated attackers," says Chris Pierson, the general counsel and chief security officer of the payment platform Viewpost. "To the public it looks as if the company has been hacked, and provides a significant amount of negative press about the companys security and privacy responsibilities."
Enigma said on Monday evening that it is working to mitigate the damage. We're actively investigating the scam attempt and the parties involved with multiple partners, including vigilant members of our community, other companies in our space, and exchanges, Bair says.
Since they are unregulated by the governmentfor now, anywayICOs have perks that make them appealing to cryptocurrency companies, but by their nature they are also less predictable than standard fund-raising avenues. In mid July, scammers stole roughly $7 million from supporters during the ICO of the cryptocurrency management platform CoinDash. A few days later, hackers stole $32 million in Ethereum (though much of it was later recovered) by exploiting a vulnerability in a crypto product called Parity Wallet.
"The news of the attack is certainly not surprising," says Eric Klonowski, a senior advanced threat research analyst at the internet security firm Webroot. "Investors were ready to part with their money at a moments notice, and the attacker was prepared to capitalize.... That said, recent core cryptocurrency heists are all a result of third-party vulnerabilities and their handling of investments, and not in the cryptography or implementation itself."
With the September 11 ICO still rapidly approaching, at least Enigma has some time to get its first-line security right.
See the rest here:
A Very Dumb Mistake Costs Cryptocurrency Investors Big Time - WIRED
- Crypto()Currency - CryptoCurrency.org - April 26th, 2014 [April 26th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia - April 26th, 2014 [April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video - April 26th, 2014 [April 26th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video - April 26th, 2014 [April 26th, 2014]
- Bitcoin / Cryptocurrency - An Extensive FAQ - Video - April 26th, 2014 [April 26th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video - April 26th, 2014 [April 26th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video - April 26th, 2014 [April 26th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video - April 26th, 2014 [April 26th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video - April 26th, 2014 [April 26th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video - April 26th, 2014 [April 26th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video - April 26th, 2014 [April 26th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video - April 26th, 2014 [April 26th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video - April 26th, 2014 [April 26th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video - April 26th, 2014 [April 26th, 2014]
- Dogecoin Founder Speaks on the Future of Cryptocurrency - April 27th, 2014 [April 27th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... - April 27th, 2014 [April 27th, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video - April 27th, 2014 [April 27th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video - April 27th, 2014 [April 27th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video - April 27th, 2014 [April 27th, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video - April 27th, 2014 [April 27th, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video - April 27th, 2014 [April 27th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video - April 27th, 2014 [April 27th, 2014]
- Australian dogecoin founder speaks on the future of cryptocurrency - April 28th, 2014 [April 28th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video - April 29th, 2014 [April 29th, 2014]
- Cryptocurrency News Round-Up: MtGox Hearing Begins as Bitcoin gets Bloomberg Endorsement - May 1st, 2014 [May 1st, 2014]
- mTrader.org - Cryptocurrency Mining System - Video - May 1st, 2014 [May 1st, 2014]
- CryptoCurrency - cryptobars commodity Launch! - Video - May 1st, 2014 [May 1st, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video - May 2nd, 2014 [May 2nd, 2014]
- Coin Pursuit Launches SliceFeeds Interactive Cryptocurrency Network - May 3rd, 2014 [May 3rd, 2014]
- Cryptocurrency | Ground Zero with Clyde Lewis - May 3rd, 2014 [May 3rd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video - May 3rd, 2014 [May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video - May 3rd, 2014 [May 3rd, 2014]
- Know How 74 Cryptocurrency - Video - May 4th, 2014 [May 4th, 2014]
- MIT undergrads will each receive $100 in bitcoin - May 5th, 2014 [May 5th, 2014]
- cryptocurrency - Fortune Finance: Hedge Funds, Markets ... - May 8th, 2014 [May 8th, 2014]
- Bitcoin wins US election panel's approval for political donations - May 9th, 2014 [May 9th, 2014]
- CryptoCurrency of the World Unite! - Video - May 9th, 2014 [May 9th, 2014]
- Major Dogecoin Wallet Hacked, Shut Down - May 13th, 2014 [May 13th, 2014]
- Such hack, much sad: Doge Vault reportedly loses $56,000 in heist - May 13th, 2014 [May 13th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video - May 13th, 2014 [May 13th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video - May 13th, 2014 [May 13th, 2014]
- AMD cuts Radeon R9 280 price as inflation woes die down - May 15th, 2014 [May 15th, 2014]
- The Cryptocurrency Certification Consortium - Video - May 15th, 2014 [May 15th, 2014]
- Bitpagar Cryptocurrency - Video - May 16th, 2014 [May 16th, 2014]
- TagPro - Cryptocurrency Juke Session w/ LTB & Counterpary - Video - May 16th, 2014 [May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video - May 16th, 2014 [May 16th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video - May 16th, 2014 [May 16th, 2014]
- Jan Irvin on Learning, Statism, Culture, Cryptocurrency and Voluntarism -- Potent News Podcast #1 - Video - May 16th, 2014 [May 16th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video - May 18th, 2014 [May 18th, 2014]
- Cryptocurrency Round-Up: Darkcoin Rise Continues; Dogecoin Saved My Life & Bitcoin Explainer Videos - May 19th, 2014 [May 19th, 2014]
- Givecoin.info Announces Partnership with Do A Bit of Good: World's First Charitable Mining Screensaver - May 21st, 2014 [May 21st, 2014]
- Cryptocurrency: Get Mining! - Video - May 22nd, 2014 [May 22nd, 2014]
- Violincoin - The first cryptocurrency for musician - - Video - May 22nd, 2014 [May 22nd, 2014]
- Trollcoin - The Fun Cryptocurrency! - Video - May 22nd, 2014 [May 22nd, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video - May 23rd, 2014 [May 23rd, 2014]
- The Cryptocurrency Store - Video - May 23rd, 2014 [May 23rd, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video - May 23rd, 2014 [May 23rd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video - May 23rd, 2014 [May 23rd, 2014]
- UT students to launch cryptocurrency exchange - May 24th, 2014 [May 24th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video - May 27th, 2014 [May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video - May 27th, 2014 [May 27th, 2014]
- Cryptocurrency Round-Up: Bitcoin Pioneer Dies and Digital Currency's Status in Australia - August 31st, 2014 [August 31st, 2014]
- Bitcoin enthusiasts discuss the cryptocurrency - Video - August 31st, 2014 [August 31st, 2014]
- Make Fast 1.0 up to 10.00 BTC or Any Cryptocurrency REAL CASH - Video - August 31st, 2014 [August 31st, 2014]
- Halcyon cryptocurrency - Video - August 31st, 2014 [August 31st, 2014]
- Selling products / services / fiat money for cryptocurrency - Coinkite PoS Terminal - Video - August 31st, 2014 [August 31st, 2014]
- Selling cryptocurrency to customers - Coinkite PoS Terminal - Video - August 31st, 2014 [August 31st, 2014]
- Cryptocurrency Made Simple - A Plain English Guide to Bitcoins - September 8th, 2014 [September 8th, 2014]
- PotatoCoin - The cryptocurrency for the third world - Video - September 8th, 2014 [September 8th, 2014]
- How To Trade One Kind Of Cryptocurrency For A Different Kind Of Cryptocurrency - Video - September 8th, 2014 [September 8th, 2014]
- How To Fund Your Bleutrade Cryptocurrency Trading Account - Video - September 8th, 2014 [September 8th, 2014]
- How To Open An Account At Bleutrade.com Cryptocurrency Exchange - Video - September 8th, 2014 [September 8th, 2014]
- Cryptocurrency Round-Up: Apple Pay Boosts Bitcoin, Nakamoto Negotiates With Hacker - September 11th, 2014 [September 11th, 2014]
- Qoinpro Cryptocurrency Faucet ok - Video - September 12th, 2014 [September 12th, 2014]
- Weekly Roundup - CEX.IO - Multi-Functional cryptocurrency exchange - Video - September 12th, 2014 [September 12th, 2014]
- TCR #27: Cryptocurrency growth, 9/11 Anniversary, CDC Scandal, Face Your Fears - Video - September 12th, 2014 [September 12th, 2014]
- VanosEnigmA 011 Bitcoin-Comedy BitcoinDog CryptoCurrency-Cat Naughty - Video - September 15th, 2014 [September 15th, 2014]
- WikiLeaks Avoided Bitcoin to Prevent Government 'Destroying' Cryptocurrency - September 16th, 2014 [September 16th, 2014]
- LXC Coin crowdfunds in challenge to Bitcoin - September 16th, 2014 [September 16th, 2014]
- Why Bitcoin Is Poised To Win Big In Las Vegas - September 19th, 2014 [September 19th, 2014]