{"id":212967,"date":"2017-08-22T23:35:53","date_gmt":"2017-08-23T03:35:53","guid":{"rendered":"http:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/a-very-dumb-mistake-costs-cryptocurrency-investors-big-time-wired\/"},"modified":"2017-08-22T23:35:53","modified_gmt":"2017-08-23T03:35:53","slug":"a-very-dumb-mistake-costs-cryptocurrency-investors-big-time-wired","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/cryptocurrency-2\/a-very-dumb-mistake-costs-cryptocurrency-investors-big-time-wired\/","title":{"rendered":"A Very Dumb Mistake Costs Cryptocurrency Investors Big Time &#8211; WIRED"},"content":{"rendered":"<p><p>        The digital financial     services    developer Enigma prides itself on ultra-secure    products . The    company's Catalyst platform protects financial info with a    cutting-edge combination of blockchain-inspired privacy    technology and cryptography. So it comes as no small surprise    that on Monday, scammers took over the company's website,    mailing lists, and Slack accounts by exploiting some extremely    basic security mistakes Enigma had made. The blunders also    facilitated a scam that ultimately cost Enigma supporters    almost $500,000.   <\/p>\n<p>    Enigma has planned an Initial Coin    Offering for September 11an unregulated cryptocurrency    fund-raising campaign that startups use when they want to raise    capital for their company without going through the process of    working with an established financial institution or venture    capital fund. (The SEC has promised to    clamp down on these ICOs     , but so far is in the exploratory    phase.)   <\/p>\n<p>            Tom Simonite          <\/p>\n<p>            Regulators Warn Cryptocurrency Startup Fundraisers to            Play By the Rules          <\/p>\n<p>            Gabriel Nicholas          <\/p>\n<p>            Ethereum Is Coding's New Wild West          <\/p>\n<p>            Brian Barrett          <\/p>\n<p>            Security News This Week: Two Huge Cryptocurrency Heists            Cost Investors Millions          <\/p>\n<p>    With the ICO in mind, scammers    compromised official Enigma channels to create a sense of    legitimacy and urgency. The plot proved easy to pull off. At    least one of the passwords protecting the Enigma accounts,    which included a Slack account with administrative privileges,    had previously leaked, and     reports indicate     that the    accounts weren't protected by two-factor authentication.       <\/p>\n<p>    The hackers began defacing the    company's main site and Slack accounts, and pushed a special    \"pre-sale\" ahead of the ICO, directing money toward their own    cryptocurrency wallet. They also went rogue on the company's    mailing lists. Many users realized that the push was a scam,    but the hustle did tempt some interested backers into sending    1,492 coins in the cryptocurrency Ethereum, which converts to    almost $495,000.  <\/p>\n<p>    Enigma said in a statement on Monday    that its community fund-raiser, also called a crowd sale, was    always set definitively for September 11, and emphasized that    its secure servers had not been hacked. But a spokesperson    confirmed that the scammers compromised account passwords using    various methods. And in response to the incident, the company    says it is adding strong, random passwords and two-factor    authentication for each account, plus implementing robust    password changing and better system compartmentalization.    \"Weve moved up a number of critical security steps and taken    additional measures to protect the community going forward,\"    says Tor Bair, Enigma's head of marketing and growth. \"Were    now very well aware of the potential threats and are taking no    chances.\"   <\/p>\n<p>    Though honest mistakes can happen at    any growing organization, the Enigma community grappled with    the implications of the incident on Monday, wondering how a    specialized cryptography company could only now be realizing    the need for stringent account hygiene. \"This will go down in    crypto history as one of the stupidest moments ever. We need a    meme,\" one Reddit user wrote. Some Redditors even claimed that    they used the breached credential repository     Have    I Been Pwned to    determine that the Enigma accounts scammers accessed reused a    previously exposed account password from CEO Guy Zyskind. But    Zyskind told WIRED that none of the breached Enigma accounts    relied on reused passwords.  <\/p>\n<p>    While the Enigma team worked to restore    secure Slack service, the community's discussion moved to    secure messaging app Telegram. \"No word on honoring those who    were scammed b\/c of y'all negligence and poor security? Speaks    volumes,\" a user called Jay wrote in the open chatroom. Many    users indicated support for Enigma, though, and seemed    satisfied with the company's remediation efforts.      <\/p>\n<p>    \"Hacking accounts that do not have    dual-factor authentication enabled and other best in class    security measures is a trivial hack for most dedicated    attackers,\" says Chris Pierson, the general counsel and chief    security officer of the payment platform Viewpost. \"To the    public it looks as if the company has been hacked, and provides    a significant amount of negative press about the companys    security and privacy responsibilities.\"  <\/p>\n<p>    Enigma said on Monday evening that it    is working to mitigate the damage. We're actively    investigating the scam attempt and the parties involved with    multiple partners, including vigilant members of our community,    other companies in our space, and exchanges, Bair says.       <\/p>\n<p>    Since they are unregulated by the    governmentfor now, anywayICOs have perks that make them    appealing to cryptocurrency companies, but by their nature they    are also less predictable than standard fund-raising avenues.    In mid July, scammers stole roughly $7 million from supporters    during the ICO of the cryptocurrency management platform    CoinDash. A few days later, hackers stole $32 million in    Ethereum (though much of it was later recovered) by exploiting    a vulnerability in a crypto product called Parity Wallet.       <\/p>\n<p>    \"The news of the attack is certainly    not surprising,\" says Eric Klonowski, a senior advanced threat    research analyst at the internet security firm Webroot.    \"Investors were ready to part with their money at a moments    notice, and the attacker was prepared to capitalize.... That    said, recent core cryptocurrency heists are all a result of    third-party vulnerabilities and their handling of investments,    and not in the cryptography or implementation itself.\"       <\/p>\n<p>    With the September 11 ICO still rapidly    approaching, at least Enigma has some time to get its    first-line security right.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>View post:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/enigma-ico-ethereum-heist\/\" title=\"A Very Dumb Mistake Costs Cryptocurrency Investors Big Time - WIRED\">A Very Dumb Mistake Costs Cryptocurrency Investors Big Time - WIRED<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The digital financial services developer Enigma prides itself on ultra-secure products . The company's Catalyst platform protects financial info with a cutting-edge combination of blockchain-inspired privacy technology and cryptography.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/cryptocurrency-2\/a-very-dumb-mistake-costs-cryptocurrency-investors-big-time-wired\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94874],"tags":[],"class_list":["post-212967","post","type-post","status-publish","format-standard","hentry","category-cryptocurrency-2"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/212967"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=212967"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/212967\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=212967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=212967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=212967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}