Research: Serious Shortcomings Exist in OKX Security Settings
Author: Dilation Effect Link: https://x.com/dilationeffect/status/1800116534133792841 Given the recent security incidents involving OKX users, we were curious about the causes of these attacks. As ordinary users, we decided to spend half an hour conducting a quick analysis of OKX’s user security settings, and the results were quite surprising. Note: The analysis was conducted on June 10, 2024, at 5 PM Singapore Time. 1. Despite users binding Google Authenticator (GA), verification allows switching to lower security methods, bypassing GA verification. Users bind GA considering its higher security level. However, OKX allows switching to lower security verification methods, such as SMS, during sensitive user operations like adding a whitelist address, withdrawals, and various verification changes, effectively bypassing GA verification. 2. Sensitive user operations, such as disabling phone verification, disabling GA verification, and changing the login password, do not trigger a 24-hour withdrawal ban. The withdrawal ban only triggers when logging in on a new device, representing a compromise in the risk control measures for password changes. 3. Whitelist address withdrawals do not employ dynamic verification based on withdrawal amounts. Once an address is added to the whitelist, withdrawals up to the limit can proceed without additional verification. Unlike other exchanges that set a limit requiring re-verification for larger amounts. This quick analysis reveals that OKX’s security settings lack baseline design. Possibly to enhance user experience, OKX has made significant compromises in security. Whether this design is good or bad, users will make their own judgments and choices. Dilation Effect would like to remind users to bind GA to their accounts. Otherwise, they may end up working for hackers, as email and SMS are easily susceptible to attacks. Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
Asia's weekly TOP10 crypto news (Jun 3 to Jun 9)
Sunday, June 9, 2024
1. Hong Kong Regulatory News This Week 1.1 Hong Kong Officials Visit Europe to Promote Web3 link On June 3, Christopher Hui, Secretary for Financial Services and the Treasury of Hong Kong, embarked on
Weekly Project Updates: EigenLayer Achieves Record TVL, Wormhole Launches Governance, StarkWare Backs Bitcoin Scal…
Saturday, June 8, 2024
1. EigenLayer TVL Surpasses $2 Billion, Continues to Achieve Historic Highs link EigenLayer's Total Value Locked (TVL) has surpassed $2 billion, marking a historical high and solidifying its
WuBlockchain Weekly: ECB Lowers Interest Rates, Bybit Unexpectedly Opens Registration for Mainland China Users, Bi…
Friday, June 7, 2024
1. Bitcoin Spot ETF Sees $887 Million Net Inflows on June 4, Sustains 17-Day Inflow Streak link On June 4, Grayscale's GBTC ETF experienced a net inflow of $28.195 million. On the same day, the
Mining News in May:Tether Mega-Investment, Riot Wants to Acquire BitFarms, Canaan's New Models, sponsored by Bitde…
Wednesday, June 5, 2024
Title sponsored by Bitdeer, a NASDAQ-listed mining company. 1. Bitdeer announces up to $150 million in private placement funding. Tether regard Bitdeer as one of the strongest vertically integrated
In-depth Analysis: Why was the Binance Account Stolen after Using the Malicious Plug-in?
Tuesday, June 4, 2024
By:@SlowMist_Team Source:https://web3caff.com/zh/archives/94779 https://foresightnews.pro/article/detail/61654 On March 1, 2024, according to Twitter user @doomxbt, there was an abnormal situation with
You Might Also Like
Bitcoin pullback could be set up for $370k bull run price target
Friday, February 28, 2025
Bitcoin's 27% slide raises prospects for rebound, aligns with historical cycle patterns. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
WuBlockchain Weekly: SEC Terminates Lawsuits Against Multiple Crypto Companies, Bitcoin Drops Below $80,000, OKX S…
Friday, February 28, 2025
On Friday, OKX market data revealed that BTC fell below $80000, reaching a low of $78258, with the current price at $80514, reflecting a 24-hour decline of 7.22%. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
FBI confirms North Korea-backed Lazarus hackers stole $1.5 billion from Bybit
Thursday, February 27, 2025
FBI tracks Ethereum laundering spree by North Korean hackers amid rising threat of cyber warfare in the crypto world. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Interview with MicroStrategy Founder Michael Saylor: The Company Holding the Most Bitcoin in the World
Thursday, February 27, 2025
In this interview, Colin from WuBlockchain had an in-depth discussion with MicroStrategy founder Michael Saylor about the company's ongoing Bitcoin acquisition strategy, the growing adoption of
Abu Dhabi Invests $436.9M In Bitcoin ETF
Thursday, February 27, 2025
February 17th, 2025 Sign Up Your Weekly Update On All Things Crypto TL;DR Abu Dhabi Invests $436.9M In Bitcoin ETF Changpeng Zhao Sparks Meme Coin Rumours Coinbase Finally Lists POPCAT & PENGU
📈 BTC’s realised price (average acquisition price) reached an all-time high of $43,000; State of Wisconsin Invest…
Thursday, February 27, 2025
BTC's realised price reached an all-time high of $43000; Abu Dhabi's Mubadala Investment disclosed its BTC ETF holdings; South Korea to allow universities and charities to sell crypto donations
HashKey Exchange's Interpretation of the Hong Kong SFC Virtual Asset Roadmap
Thursday, February 27, 2025
We are pleased to see the Hong Kong government release the forward-looking and pragmatic “ASPI-Re” roadmap for advancing the virtual asset industry. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Argentina’s stock market plummets amid President Javier Milei’s LIBRA memecoin scandal
Thursday, February 27, 2025
Argentina's economic landscape shaken as Milei's LIBRA endorsement turns into multi-billion dollar fiasco. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Heated AMA Debate: 0G Team Responds to Allegations of CFX Soft Rug, Overvaluation, and Token Commitment Concerns
Thursday, February 27, 2025
This AMA primarily focused on the relationship between Conflux and 0G Labs, discussing 0G Labs' high valuation, fundraising structure, technical direction, and community concerns over transparency.
Pectra: Ethereum’s Next Major Upgrade
Thursday, February 27, 2025
Breaking down key changes included in Ethereum's Pectra hard-fork ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏