Cointime

Download App
iOS & Android

Crypto thieves steal $363M in Nov, the most ‘damaging’ month so far

The cryptocurrency industry has now seen its most “damaging” month for crypto thievery, scams and exploits, with crypto criminals walking away with $363 million in November, according to a blockchain security firm.

Around $316.4 million came from exploits alone, flash loans inflicted $45.5 million in damage, and $1.1 million was lost to various exit scams, CertiK stated in a Nov. 30 X (formerly Twitter) post.

The largest exploits in November occurred on Poloniex and HTX/Heco Bridge, with losses of $131.4 million and $113.3 million, respectively.

The third largest exploit was inflicted on a single victim who lost $27 million from a phishing attack.

Meanwhile, the $45 million KyberSwap attack accounted for nearly all damage done for flash loan attacks in the month.

The latest monthly figure has surpassed an earlier record of $329 million, set in September, caused mainly by the $200 million Mixin Network attack.

As of the end of November, about $1.7 billion has now been lost to exploits, exit scams and flash loan attacks in 2023. This makes up only 54% of the crypto drained in the full year 2022, when $3.7 billion was drained to crypto incidents, while 2021 saw losses of $1.7 billion, according to CertiK.

In recent comments to Cointelegraph, Ronghui Gu, one of CertiK’s founders, argued that getting a standard smart contract audit isn’t enough these days.

He stressed that thieves continue to find new and creative ways to exploit protocols and victims, with SIM-swapping and multisignature vulnerabilities among the most recent security pitfalls being capitalized on.

Exploits of this nature are hindering adoption, believes Christian Seifert, a researcher at security firm Forta Network, who also spoke with Cointelegraph:

“Imagine you losing all your savings because the branch of your bank got broken into overnight. You wouldn’t bank there.”

These incidents “scare away” people who were previously open to exploring the Web3 space, said Jerry Peng, a research analyst at Web3 analytics firm 0xScope, in a recent note to Cointelegraph.

Comments

All Comments

Recommended for you

  • WOOFi attacker address has transferred 100 ETH to Tornado cash

    PeckShield monitoring shows that the address marked by the WOOFi attacker has transferred 100 ETH to Tornado cash. The WOOFi attacker has already transferred 2200 ETH (worth about $6.5 million) to Tornado cash.

  • Trump will hold a private dinner on the day of the court recess, inviting NFT trading card buyers to attend

    On May 10th, according to sources, former US President Donald Trump will host a dinner at his Mar-a-Lago estate on a day off, inviting NFT trading card buyers to attend. This event is part of Trump's series of non-campaign activities, aimed at balancing his White House campaign and legal disputes. After Stormy Daniels testified in Trump's trial on Tuesday, Trump expressed his desire for campaigning rather than being tied up in court. Despite no public campaign activities on Wednesday, Trump's schedule includes private political meetings.

  • Tether: Deutsche Bank’s analysis lacks clarity and substantive evidence

    According to a report on stablecoins released on May 7, Deutsche Bank analyzed 334 currencies linked to stablecoins and found that 49% of stablecoins had failed during their median lifespan of about eight to ten years. The analysts concluded that most anchored assets in the cryptocurrency field will experience significant "turbulence" caused by speculative sentiment and ultimately suffer some form of decoupling event. Deutsche Bank analysts also pointed out that Tether's reserve transparency was lacking and described the company's solvency as "doubtful".

  • Yesterday, Solana’s on-chain DEX transaction volume surpassed Ethereum, reaching $1.314 billion

    On May 10th, according to DeFiLlama data, the trading volume of Solana's DEX reached 1.314 billion US dollars yesterday, surpassing the trading volume of 1.297 billion US dollars on Ethereum's DEX.

  • US court orders seizure of 279 virtual currency accounts containing criminal proceeds from North Korean hacking

    A US court has ordered the confiscation of 279 virtual currency accounts containing proceeds from North Korean hacker crimes. US District Court Judge Timothy Kelly in Washington, DC approved the federal prosecutor's request for a summary judgment on these accounts and ordered their confiscation on May 8. This ruling means that these accounts are now under the control of the US Department of Treasury.

  • South Korea’s National Tax Service announced that it would collect 40 billion won in taxes from Bithumb users

    Bithumb has issued a preliminary notice of comprehensive income tax to some users who participated in activities held between 2018 and 2021, and announced full support for the related tax amount. The position of the National Tax Service is that rewards paid to users through various activities (including virtual assets) constitute taxable income. Bithumb does not agree with the National Tax Service's opinion, but explains that taxation is mandatory.

  • The Base ecosystem Bloom project said it has recovered 90% of the funds stolen in the attack

    On May 10th, Bloom, a decentralized derivatives exchange on the X platform, announced that they have recovered $486,000 (minus 10% for bug bounties) out of the total funds utilized ($540,000). All of these funds will be redistributed to limited partners. 10% of the bug bounty has been agreed upon in exchange for not pressing charges against those who exploited the bug. A compensation plan for limited partners affected by the bug will be completed within the next 24-48 hours. Funds are safe and there is currently no need to revoke contract access.

  • US House of Representatives passes SAB 121 crypto rule overturning SEC

    The US House of Representatives has passed H.J. Res. 109, a resolution aimed at overturning the Securities and Exchange Commission's SAB 121 regulation on digital assets. The resolution aims to reduce regulatory burden and promote regulated banks to safely hold digital assets. However, the White House supports the SEC and has threatened to veto the resolution, emphasizing that if the President receives H.J. Res. 109, he will veto it.

  • Marathon reports record net revenue of $337.2 million in first quarter of 2024

    Bitcoin mining company Marathon Digital Holdings reported a record net profit of $337.2 million in the first quarter of 2024. The quarterly net profit announced by the company in its earnings report on May 9th increased by 184% compared to the first quarter of 2023, which was $118.7 million. The diluted earnings per share for this quarter were $1.26. The company announced that its first quarter revenue for 2024 reached a record $165.2 million, an increase of 223% from the same period last year, which was $51.1 million.

  • Canada's anti-money laundering regulator fines Binance $4.4 million

    Binance Holdings Ltd, a cryptocurrency exchange, has been fined CAD 6 million (approximately USD 4.4 million) by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for violating anti-money laundering regulations. The report states that Binance was penalized for failing to register as a foreign money services business and for not reporting virtual currency transactions exceeding CAD 10,000. The fine was issued on Tuesday of this week, and the Canadian regulatory agency announced the news to the public on Thursday.