Research: Serious Shortcomings Exist in OKX Security Settings
Author: Dilation Effect Link: https://x.com/dilationeffect/status/1800116534133792841 Given the recent security incidents involving OKX users, we were curious about the causes of these attacks. As ordinary users, we decided to spend half an hour conducting a quick analysis of OKX’s user security settings, and the results were quite surprising. Note: The analysis was conducted on June 10, 2024, at 5 PM Singapore Time. 1. Despite users binding Google Authenticator (GA), verification allows switching to lower security methods, bypassing GA verification. Users bind GA considering its higher security level. However, OKX allows switching to lower security verification methods, such as SMS, during sensitive user operations like adding a whitelist address, withdrawals, and various verification changes, effectively bypassing GA verification. 2. Sensitive user operations, such as disabling phone verification, disabling GA verification, and changing the login password, do not trigger a 24-hour withdrawal ban. The withdrawal ban only triggers when logging in on a new device, representing a compromise in the risk control measures for password changes. 3. Whitelist address withdrawals do not employ dynamic verification based on withdrawal amounts. Once an address is added to the whitelist, withdrawals up to the limit can proceed without additional verification. Unlike other exchanges that set a limit requiring re-verification for larger amounts. This quick analysis reveals that OKX’s security settings lack baseline design. Possibly to enhance user experience, OKX has made significant compromises in security. Whether this design is good or bad, users will make their own judgments and choices. Dilation Effect would like to remind users to bind GA to their accounts. Otherwise, they may end up working for hackers, as email and SMS are easily susceptible to attacks. Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
Asia's weekly TOP10 crypto news (Jun 3 to Jun 9)
Sunday, June 9, 2024
1. Hong Kong Regulatory News This Week 1.1 Hong Kong Officials Visit Europe to Promote Web3 link On June 3, Christopher Hui, Secretary for Financial Services and the Treasury of Hong Kong, embarked on
Weekly Project Updates: EigenLayer Achieves Record TVL, Wormhole Launches Governance, StarkWare Backs Bitcoin Scal…
Saturday, June 8, 2024
1. EigenLayer TVL Surpasses $2 Billion, Continues to Achieve Historic Highs link EigenLayer's Total Value Locked (TVL) has surpassed $2 billion, marking a historical high and solidifying its
WuBlockchain Weekly: ECB Lowers Interest Rates, Bybit Unexpectedly Opens Registration for Mainland China Users, Bi…
Friday, June 7, 2024
1. Bitcoin Spot ETF Sees $887 Million Net Inflows on June 4, Sustains 17-Day Inflow Streak link On June 4, Grayscale's GBTC ETF experienced a net inflow of $28.195 million. On the same day, the
Mining News in May:Tether Mega-Investment, Riot Wants to Acquire BitFarms, Canaan's New Models, sponsored by Bitde…
Wednesday, June 5, 2024
Title sponsored by Bitdeer, a NASDAQ-listed mining company. 1. Bitdeer announces up to $150 million in private placement funding. Tether regard Bitdeer as one of the strongest vertically integrated
In-depth Analysis: Why was the Binance Account Stolen after Using the Malicious Plug-in?
Tuesday, June 4, 2024
By:@SlowMist_Team Source:https://web3caff.com/zh/archives/94779 https://foresightnews.pro/article/detail/61654 On March 1, 2024, according to Twitter user @doomxbt, there was an abnormal situation with
You Might Also Like
Let's make money from crypto WITHOUT trading
Friday, December 27, 2024
CRYPTODAY 139 ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
CryptoQuant CEO says US could feasibly cut debt by embracing strategic Bitcoin reserve
Thursday, December 26, 2024
Analysts see US Bitcoin reserve as symbolic step toward debt reduction, amid challenges and speculation. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Shen Yu's "Four Wallets" Strategy: A Guide to Crypto Investment Management
Thursday, December 26, 2024
This content summarizes an AMA hosted by E2M Research on Twitter Spaces, featuring Shen Yu (Twitter @bitfish1), Odyssey (Twitter @OdysseyETH), Zhen Dong (Twitter @zhendong2020), and Peicai Li (Twitter
Reminder: Bitcoin Hits A New ATH Once Again After Touching $108K
Thursday, December 26, 2024
Monday Dec 23, 2024 Sign Up Your Weekly Update On All Things Crypto TL;DR In this issue, we dive into: Bitcoin Hits A New ATH Once Again After Touching $108K Avery Ching To Become New Aptos Labs CEO As
Bitcoin sees brief rebound to $99,000 on Christmas day
Wednesday, December 25, 2024
Holiday excitement lifted Bitcoin past $99000, but it quickly corrected to $98000 where it still holds strong support. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Opinion: Market Panic After FOMC Shows Some Overreaction
Wednesday, December 25, 2024
Last night, the market experienced a significant pullback, primarily due to investor concerns over the Federal Reserve possibly shifting towards a more “hawkish” policy stance. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Trump’s pro-crypto pledge could see day-one executive orders, industry players hope
Tuesday, December 24, 2024
A Bitcoin strategic reserve, access to banking services, and the creation of a crypto council are among the items on the industry's 'wishlist.' ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
State of the Network’s 2024 Year in Review
Tuesday, December 24, 2024
A data-driven overview of events that shaped crypto in 2024 ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
OKExChain: Will the Federal Reserve and Jerome Powell Prevent the U.S. from Creating a National Bitcoin Reserve?
Tuesday, December 24, 2024
In the early hours of today, Federal Reserve Chairman Jerome Powell made it clear during a press conference following the monetary policy meeting that the Fed has no intention of participating in any
Crypto community cheers as Trump names pro-crypto advisors Stephen Miran and Bo Hines for economic and digital ass…
Monday, December 23, 2024
Trump fosters economic expansion and digital innovation with Miran and Hines at the helm of economic and crypto councils. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏