기본 콘텐츠로 건너뛰기

Why bitcoin exchanges keep getting hacked — and how to protect yourself


The price of bitcoin took a tumble early Wednesday after a major South Korea-based cryptocurrency exchange, Bithumb, admitted hackers made off with more than $31 million worth of virtual currency. The incident is the latest in a long string of thefts at the online portals where investors trade cash for digital coins such as bitcoin and ether. Bithumb has not said how the attack occurred.
What makes exchanges vulnerable to these sorts of attacks in the first place?
For starters, cryptocurrency experts blame lax security at the hacked exchanges, as well as the booming popularity of digital currencies more generally.
"Bitcoin and other cryptocurrencies have risen dramatically in popularity and value over the past few years," said John Sedunov, an assistant professor of finance at Villanova University. "This fast run-up may have caught some exchanges off-guard, and they may not have had the capital on hand, time, or even the technical ability to ramp up security features fast enough to ward off potential attackers."

In other words, hackers love going after exchanges because they are a rewarding and often easy targets. In this respect, exchanges are little different from health-care providers with lucrative medical data, or credit reporting bureaus that hold Social Security numbers.
Unlike those types of institutions, cryptocurrency exchanges are purpose-built to move actual assets from one person to another. And that can raise additional risks. Here is how and what you can do to shield yourself.
Begin by considering your personal financial situation. If you are like many people, you have both a checking account to cover daily transactions and a savings account or safe-deposit box where you keep money you know you will not be spending anytime soon.
A lot of cryptocurrency exchanges work the same way. They run what is called a "hot" wallet that is connected to the Internet, where they store the virtual currency they know they will use to quickly fulfill their customers' trades. Meanwhile, they might keep some — or even the bulk — of their customers' funds in a "cold" wallet. This cold storage is disconnected from the Internet and inaccessible to customers, partly to ensure it is off limits to remote hackers.
While many exchanges have adopted techniques to protect their hot wallets, such as obtaining insurance on the funds inside or requiring multiple secret keys for access, it is impossible to eliminate the risk of a hack completely. Just as online criminals are constantly developing new forms of malware that exploit bugs in software its developers have not caught, hot wallets are vulnerable to the same kinds of risk.
That does not mean hot wallets are inherently bad. Imagine if every time you paid a bill at a restaurant or bar, you had to visit your savings account to physically pull out the money. It would be a massive inconvenience, and settling your tab would take ages. Hot wallets speed things up, at the cost of some built-in security risks.
For these reasons, many cryptocurrency investors recommend storing your coins not in a wallet that is controlled by an exchange, but rather in a cold wallet you control. This wallet could be a hard drive you have unplugged from a computer, a USB drive you store in a drawer in your house or even codes written on a piece of paper. When you want to sell the coins in the wallet, just reconnect the wallet to the Internet.
This approach is not without headaches, too, but it is still a better option. On Reddit, stories abound of investors who have misplaced their cold wallets or the access codes needed to open them. In these sorts of cases, your money may as well have been lost to hackers. Other investors on Reddit still say trusting yourself is preferable to trusting exchanges.

"It's frustrating to see people lose money to this consistent mistake," wrote user PM_ME_YOUR_NANO on a recent thread. "No one should be losing even 10% of their available coins because an exchange is bad. Cryptocurrency is about being trustless. Exchanges are trusted systems without great regulation."

댓글

이 블로그의 인기 게시물

BLACK LABEL Secured Automobile Smart Key Solution

Developed by MERCEDES BENZ for the first time 20 years ago, the SmartKey has been very convenient for motorists. However, since this technology has been applied so far, the smart key security has not been upgraded so that even if a simple wireless hacking device is purchased on the market, the password which is exchanged between the car and the smart key is wirelessly captured, the car door is opened, Things are happening in a random way. The biggest problem in smart key security so far is that the identification code exchanged between the smart key and the key is a fixed value and the security is difficult to hack the fixed single code value. However, if a mutual verification system, which is a security solution of BLACK LABEL, is applied to a smart key and a vehicle, it is impossible to access the vehicle even if the identification code value is fixed in a single code, Can be made. This is because the code that has been changed once and then discarded is discarded. ...

Avoiding Cryptocurrency Scams

The Money Makers Club now has 6 of 15 available seats. Learn more here! Everyone is always focused on the potential upside of buying cryptocurrency, but they forget there are always going to be hidden downsides as well. The downside risk of investing in cryptocurrencies is huge. Not only do you need to worry about the high volatility of these assets, but you also need to bear in mind that theft is always a possibility, and the assets are poorly regulated.  Lack of Regulation Creates Opportunity for Thieves In the equity and debt markets, there are stringent controls on the way capital is invested and the rules that govern investors. The goal is to protect investors from any fraud or wrongdoing, and even though there are times where it takes regulators longer than normal to catch on (see: Bernie Madoff), the general effect is a safer investment marketplace.  Fraud can occur in a variety of ways. It can be the result of false claims by the company regarding the s...

Cold Wallet Vs. Hot Wallet: What’s The Difference?

You may have heard about cold and hot digital wallets but do you know how they are different from each other? The simplest way to describe the difference between a cold wallet and a hot one is this: hot wallets are connected to the internet while cold wallets are not. Most people who hold digital assets have both cold and hot wallets because they are designed for different purposes. Hot wallets are like checking accounts while cold wallets are similar to savings accounts. People who have digital assets keep a small amount of money in their hot wallets for purchasing stuff. They keep the vast majority of their digital coins in their cold wallet. If you like Medium articles in video form, you’re in luck: SECURITY Q: Why do people keep most of their digital coins in a cold wallet? A: Hackers cannot steal digital assets that are not connected to the internet. Q: So then, how safe are hot wallets? A: The security of hot wallets is dependent upon the security ha...