UNKNOWN

OCTOBER 2018

GLOBAL

WIREX

DESCRIPTION OF EVENTS

"Welcome to a world without borders. Where all currencies are finally equal and open to all. Welcome to Wirex! We do things with money you’ve never imagined." "Since its inception in 2015, Wirex has always prided itself on closing the gap between the regulated world of fiat currencies and the nascent, ever-changing world of cryptocurrencies." Wirex "registered office is Slavonska avenija 1C, Zagreb Croatia."

 

"We are Wirex - and we are on a mission to make cryptocurrency more accessible and available for everyone. Open an account for free, in a matter of minutes. It gives you instant access to a wide variety of crypto and traditional currencies in the palm of your hand, unbeatable OTC exchange rates, DeFi-powered earning and next-gen rewards."

 

"The vision of Wirex is not to simply ride the coattails of [metaverse and Web 3.0] developments, but to actively influence them with decentralised products and services that are fully equipped for optimum scalability within a Web 3.0 landscape. Wirex aims to “build upon the shoulders of giants”. That means actively learning from early blockchain and decentralised finance innovations to create multiple bridges between an ever-changing metaverse landscape and the physical (and political) reality of nation states, governance, regulation, technological change and consumer needs. While many advocate Web 3.0 and the metaverse at the expense of established and conventional financial institutions and infrastructure, Wirex sees a world where the two systems are gradually merged and mutually co-opted. Our goal is to lead this merger of systems with solutions that appeal to the widest global audience possible."

 

"You can't move your XRP from etoro to an offline wallet such as ledger nano or anywhere else for that matter. The good news however is neither can a hacker."

 

"To be clear my account was hacked prior to turning on 2FA." "My account was hacked early October and that's when one of them was from." "I immediately turned 2fa on and as I really like the app decided to use it to buy more and move straight to Nano. Another few weeks later there was another attempt. This time they didn't get access although they managed to register a device." "What I find odd is that after turning it on I had another failed attack that appears to have left a footprint of a verified device?"

 

"My Wirex account was hacked." "My attack happened last October." "[M]y Wirex account got emptied." "I had the account 3 weeks and was hacked by a man in the middle intercepting my emails." "Someone managed to register their device even after I had 2fa enabled." "The other [verified device] was around the time of another attempted hack. Why did Wirex not remove the first and how did the second get created is my unanswered question."

 

"I don't use Firefox at all. I have no idea how they verified a device after I turned on 2fa. 2fa is also enabled on my email account. I'm concerned and at a loss as to how they did this."

 

"Wirex don't give a hoot." "If you lose your crypto on Wirex their standard reply is. Sorry to hear that but too bad. Don't store your assets or cash on there. I know unfortunately."

 

"[H]i Wirex. I still haven't heard a word from you on my request / security concerns. Are you avoiding me? Seems that way." "I'm still waiting on a proper reply with an explanation from Oct last year. Are they vulnerable to Russian hackers?"

 

"For your security, your Memorable Word is now required to confirm your identity when you first use Wirex on a new device."

 

"Just too bad this wasn't introduced before some hack registered their device on my account and wiped me out. I expect Wirex to compensate me here!" "Wirex refuse to restore my account." "I want my XRP back and the £250 that was in my account before it got hacked whilst in your custody over a year ago."

 

"I'm taking up with ombudsman." "I have gone down the ombudsman route as believe Wirex security was to blame. They have since introduced new measures but that doesn't help me and they don't care."

 

"If you haven't already done so make sure you have all security features turned on including new password feature. There are scumbags out there targeting Wirex. I know from bitter experience. Be careful!"

 

"[T]hought it might be an insider. I don't trust Wirex. Sad cos their product is excellent." "Use Wirex. Just make sure you have all security especially MFA turned on or better still move to Nano after buying."

Wirex is a payment service provider which aims to make all currencies including cryptocurrency equal. They provide cards which can be used to make purchases.

 

Twitter user SambucciTony reports that their account was compromised in a man-in-the-middle attack. The attacker managed to add "verified devices" by breaching their email address, which were not removed when they set up two-factor authentication.

 

These verified devices were later used to empty the account and steal an unknown amount. There were no funds recovered even to this day.

HOW COULD THIS HAVE BEEN PREVENTED?

This incident could be prevented by setting up two-factor authentication with factors on at least 2 separate devices. Avoid the use of having a single factor that can be used on it's own to restore others like an email address or phone number.

 

The Wirex platform should have removed the verified devices when 2FA was first set up, and detected that the login was suspicious due to it being from a different IP address and proceeding straight to withdrawal. Once the failure happened, they should provide as much information as possible and assist the victim in filing a police report to recover their funds. Under our framework we propose an industry insurance fund which could assist victims in notable fraud cases.

 

Check Our Framework For Safe Secure Exchange Platforms

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.