Youbit Exchange Hack: Difference between revisions

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search
(Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/youbitexchangehack.php}} Details appear to have been slow to come out on this hack, which took place right after a government security inspection by South Korea. It appears to be some kind of malware which was installed on the operation. Youbit had been previously hacked in April, and would again suffer issues as CoinBin in the future. The exchange filed for insurance, but this was denied, causing...")
 
No edit summary
 
(One intermediate revision by the same user not shown)
Line 1: Line 1:
{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/youbitexchangehack.php}}
{{Imported Case Study 2|source=https://www.quadrigainitiative.com/casestudy/youbitexchangehack.php}}
{{Unattributed Sources}}


Details appear to have been slow to come out on this hack, which took place right after a government security inspection by South Korea. It appears to be some kind of malware which was installed on the operation. Youbit had been previously hacked in April, and would again suffer issues as CoinBin in the future. The exchange filed for insurance, but this was denied, causing them to file for bankruptcy, before eventually being purchased by another exchange CoinBin. This highlights the importance of using air-gapped multi-sig cold storage, where any transactions are signed in an isolated environment and a breach requires all parties to sign off. Had this been employed for the vast majority of funds, and a self-insurance model been employed for the narrow percentage of hot wallets, the bankruptcy would have been avoided.
Details appear to have been slow to come out on this hack, which took place right after a government security inspection by South Korea. It appears to be some kind of malware which was installed on the operation. Youbit had been previously hacked in April, and would again suffer issues as CoinBin in the future. The exchange filed for insurance, but this was denied, causing them to file for bankruptcy, before eventually being purchased by another exchange CoinBin. This highlights the importance of using air-gapped multi-sig cold storage, where any transactions are signed in an isolated environment and a breach requires all parties to sign off. Had this been employed for the vast majority of funds, and a self-insurance model been employed for the narrow percentage of hot wallets, the bankruptcy would have been avoided.


This exchange or platform is based in South Korea, or the incident targeted people primarily in South Korea.
This exchange or platform is based in South Korea, or the incident targeted people primarily in South Korea.<ref name="thecoinrepublic-5" /><ref name="newsdotbitcoin-62" /><ref name="cryptovest-63" /><ref name="bbc-64" /><ref name="qz-65" /><ref name="kylegibson-86" /><ref name="newsdotbitcoin-160" /><ref name="cointelegraph-171" /><ref name="cnnmoney-172" /><ref name="cointelegraph-173" /><ref name="newsbtc-174" /><ref name="bitcoinexchangeguide-218" /><ref name="bitkan-231" /><ref name="insurancebusinessmag-232" /><ref name="slowmisthacked-1160" /><ref name="youbitarchive-3727" />


== About YouBit ==
== About YouBit ==
Line 23: Line 24:


Don't Include:
Don't Include:
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
* Anything that wasn't reasonably knowable at the time of the event.
* Anything that wasn't reasonably knowable at the time of the event.
Line 44: Line 44:
!Description
!Description
|-
|-
|December 1st, 2017 12:00:55 AM
|December 1st, 2017 12:00:55 AM MST
|First Event
|Main Event
|This is an expanded description of what happened and the impact. If multiple lines are necessary, add them here.
|Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.
|-
|
|
|
|-
|-
|
|
Line 58: Line 54:


== Total Amount Lost ==
== Total Amount Lost ==
The total amount lost is unknown.
The total amount lost has been estimated at $2,650,000 USD.


How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Line 69: Line 65:


== Total Amount Recovered ==
== Total Amount Recovered ==
It is unknown how much was recovered.
There do not appear to have been any funds recovered in this case.


What funds were recovered? What funds were reimbursed for those affected users?
What funds were recovered? What funds were reimbursed for those affected users?
Line 75: Line 71:
== Ongoing Developments ==
== Ongoing Developments ==
What parts of this case are still remaining to be concluded?
What parts of this case are still remaining to be concluded?
== General Prevention Policies ==
Coming soon.
== Individual Prevention Policies ==
{{Prevention:Individuals:Placeholder}}
{{Prevention:Individuals:End}}
== Platform Prevention Policies ==
{{Prevention:Platforms:Placeholder}}
{{Prevention:Platforms:End}}


== Prevention Policies ==
== Regulatory Prevention Policies ==
Coming soon.
{{Prevention:Regulators:Placeholder}}
 
{{Prevention:Regulators:End}}


== References ==
== References ==
[https://www.thecoinrepublic.com/2020/01/21/south-korean-government-under-fire-as-3-more-crypto-platforms-hacked/ South Korean Government Under Fire As 3 More Crypto Platforms Hacked - The Coin Republic: Cryptocurrency , Bitcoin, Ethereum & Blockchain News] (Jan 30)
<references><ref name="thecoinrepublic-5">[https://www.thecoinrepublic.com/2020/01/21/south-korean-government-under-fire-as-3-more-crypto-platforms-hacked/ South Korean Government Under Fire As 3 More Crypto Platforms Hacked - The Coin Republic: Cryptocurrency , Bitcoin, Ethereum & Blockchain News] (Jan 31, 2020)</ref>


[https://news.bitcoin.com/hacked-cryptocurrency-exchange-youbit-re-emerges-amid-insurance-controversy/ Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy | News Bitcoin News] (Feb 6)
<ref name="newsdotbitcoin-62">[https://news.bitcoin.com/hacked-cryptocurrency-exchange-youbit-re-emerges-amid-insurance-controversy/ Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy | News Bitcoin News] (Feb 7, 2020)</ref>


[https://cryptovest.com/news/another-bitcoin-exchange-hacked-youbit-files-bankruptcy-after-losing-users-coins/ Another Bitcoin Exchange Hacked: Youbit Files Bankruptcy After Losing Users’ Coins - Cryptovest] (Feb 6)
<ref name="cryptovest-63">[https://cryptovest.com/news/another-bitcoin-exchange-hacked-youbit-files-bankruptcy-after-losing-users-coins/ Another Bitcoin Exchange Hacked: Youbit Files Bankruptcy After Losing Users’ Coins - Cryptovest] (Feb 7, 2020)</ref>


[https://www.bbc.com/news/technology-42409815 Bitcoin exchange Youbit shuts after second hack attack - BBC News] (Feb 7)
<ref name="bbc-64">[https://www.bbc.com/news/technology-42409815 Bitcoin exchange Youbit shuts after second hack attack - BBC News] (Feb 8, 2020)</ref>


[https://qz.com/1160573/bitcoin-exchange-youbit-files-for-bankruptcy-in-south-korea-after-latest-hack/ A South Korean bitcoin exchange has filed for bankruptcy after being hacked again] (Feb 7)
<ref name="qz-65">[https://qz.com/1160573/bitcoin-exchange-youbit-files-for-bankruptcy-in-south-korea-after-latest-hack/ A South Korean bitcoin exchange has filed for bankruptcy after being hacked again] (Feb 8, 2020)</ref>


[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents] (Jan 24)
<ref name="kylegibson-86">[https://medium.com/@kylegibson/100-crypto-thefts-a-timeline-of-hacks-glitches-exit-scams-and-other-lost-cryptocurrency-873c87fd5522 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents] (Jan 25, 2020)</ref>


[https://news.bitcoin.com/crypto-exchanges-wallets-hacked-korea/ Total of 7 Crypto Exchanges and 158 Wallets Hacked in South Korea, Police Find | Security Bitcoin News] (Feb 25)
<ref name="newsdotbitcoin-160">[https://news.bitcoin.com/crypto-exchanges-wallets-hacked-korea/ Total of 7 Crypto Exchanges and 158 Wallets Hacked in South Korea, Police Find | Security Bitcoin News] (Feb 26, 2020)</ref>


[https://cointelegraph.com/news/north-korea-accused-of-hacking-south-korean-bitcoin-exchange-youbit North Korea Accused of Hacking South Korean Bitcoin Exchange Youbit] (Feb 27)
<ref name="cointelegraph-171">[https://cointelegraph.com/news/north-korea-accused-of-hacking-south-korean-bitcoin-exchange-youbit North Korea Accused of Hacking South Korean Bitcoin Exchange Youbit] (Feb 28, 2020)</ref>


[https://money.cnn.com/2017/12/20/technology/south-korea-bitcoin-exchange-closes/index.html Bitcoin exchange goes bust after hack] (Feb 27)
<ref name="cnnmoney-172">[https://money.cnn.com/2017/12/20/technology/south-korea-bitcoin-exchange-closes/index.html Bitcoin exchange goes bust after hack] (Feb 28, 2020)</ref>


[https://cointelegraph.com/news/south-korea-insurance-company-denies-hacked-crypto-exchanges-damages-claim South Korea: Insurance Company Denies Hacked Crypto Exchange’s Damages Claim] (Feb 27)
<ref name="cointelegraph-173">[https://cointelegraph.com/news/south-korea-insurance-company-denies-hacked-crypto-exchanges-damages-claim South Korea: Insurance Company Denies Hacked Crypto Exchange’s Damages Claim] (Feb 28, 2020)</ref>


[https://www.newsbtc.com/2018/03/30/south-korean-exchange-youbit-is-denied-insurance-claim-following-decembers-devastating-cyberattack/ South Korean Exchange Youbit Denied Insurance Claim Following December’s Devastating Cyberattack | NewsBTC] (Feb 27)
<ref name="newsbtc-174">[https://www.newsbtc.com/2018/03/30/south-korean-exchange-youbit-is-denied-insurance-claim-following-decembers-devastating-cyberattack/ South Korean Exchange Youbit Denied Insurance Claim Following December’s Devastating Cyberattack | NewsBTC] (Feb 28, 2020)</ref>


[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 4)
<ref name="bitcoinexchangeguide-218">[https://bitcoinexchangeguide.com/bitcoin/scams-hacks/ Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com] (Mar 5, 2020)</ref>


[https://bitkan.com/en/news/topic/75739 Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy] (Mar 6)
<ref name="bitkan-231">[https://bitkan.com/en/news/topic/75739 Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy] (Mar 7, 2020)</ref>


[https://www.insurancebusinessmag.com/asia/news/breaking-news/hacked-cryptocurrency-exchange-resurfaces-after-insurance-fiasco-97219.aspx Hacked cryptocurrency exchange resurfaces after insurance fiasco | Insurance Business] (Mar 6)
<ref name="insurancebusinessmag-232">[https://www.insurancebusinessmag.com/asia/news/breaking-news/hacked-cryptocurrency-exchange-resurfaces-after-insurance-fiasco-97219.aspx Hacked cryptocurrency exchange resurfaces after insurance fiasco | Insurance Business] (Mar 7, 2020)</ref>


[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 25)
<ref name="slowmisthacked-1160">[https://hacked.slowmist.io/en/?c=Exchange SlowMist Hacked - SlowMist Zone] (Jun 26, 2021)</ref>


[https://web.archive.org/web/20180203185645/https://www.youbit.co.kr/ Youbit 당신의 가상화폐 거래소 유빗] (Oct 15)
<ref name="youbitarchive-3727">[https://web.archive.org/web/20180203185645/https://www.youbit.co.kr/ Youbit 당신의 가상화폐 거래소 유빗] (Oct 16, 2021)</ref></references>

Latest revision as of 10:32, 14 April 2023

Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' and 'General Prevention' sections to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Details appear to have been slow to come out on this hack, which took place right after a government security inspection by South Korea. It appears to be some kind of malware which was installed on the operation. Youbit had been previously hacked in April, and would again suffer issues as CoinBin in the future. The exchange filed for insurance, but this was denied, causing them to file for bankruptcy, before eventually being purchased by another exchange CoinBin. This highlights the importance of using air-gapped multi-sig cold storage, where any transactions are signed in an isolated environment and a breach requires all parties to sign off. Had this been employed for the vast majority of funds, and a self-insurance model been employed for the narrow percentage of hot wallets, the bankruptcy would have been avoided.

This exchange or platform is based in South Korea, or the incident targeted people primarily in South Korea.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16]

About YouBit

“Youbit, which lets people buy and sell bitcoins and other virtual currencies, has filed for bankruptcy after losing 17% of its assets in the cyber-attack.” "The cyber attack is the second for Youbit, previously known Yapizon. The exchange was previously targeted in April in an attack which South Korean officials believe was conducted with the support of neighboring North Korea. Recent reports indicate that intelligence services in South Korea suspect that North Korea is behind additional attacks against domestic cryptocurrency exchanges, including market-leader Bithumb." “Yapian obtained a DB Cyber Comprehensive Liability Insurance policy just 20 days before it declared bankruptcy” “DB Insurance, one of South Korea’s biggest property-and-casualty insurers, has denied the claim of 3 billion won (~USD$2.65 million) by Yapian, the operator of Youbit” “In a statement, Youbit said that customers would get back about 75% of the value of the crypto-currency they have lodged with the exchange.” “But, to claim the rest of the funds, the company stated that investors will have to wait until the final settlement of bankruptcy proceedings.” “Unfortunately, for Youbit investors, it may take several months to years to receive the remaining 25 percent of their personal funds, as the settlement of bankruptcy proceedings will have to be finalized before the company can credit its customers.” “The hack has been attributed to North Korean hackers” “While the investigation could take “weeks” to review the malware code, “the people said there were telltale signs and historical evidence that North Korea was behind the Youbit attack,” the news outlet detailed.” “According to Yonhap, the rights and duties related to the personal information of Youbit members and all assets were transferred to Coinbin on March 21.”

This exchange or platform is based in South Korea, or the incident targeted people primarily in South Korea.

The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.

Include:

  • Known history of when and how the service was started.
  • What problems does the company or service claim to solve?
  • What marketing materials were used by the firm or business?
  • Audits performed, and excerpts that may have been included.
  • Business registration documents shown (fake or legitimate).
  • How were people recruited to participate?
  • Public warnings and announcements prior to the event.

Don't Include:

  • Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
  • Anything that wasn't reasonably knowable at the time of the event.

There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.

The Reality

This sections is included if a case involved deception or information that was unknown at the time. Examples include:

  • When the service was actually started (if different than the "official story").
  • Who actually ran a service and their own personal history.
  • How the service was structured behind the scenes. (For example, there was no "trading bot".)
  • Details of what audits reported and how vulnerabilities were missed during auditing.

What Happened

The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.

Key Event Timeline - Youbit Exchange Hack
Date Event Description
December 1st, 2017 12:00:55 AM MST Main Event Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here.

Total Amount Lost

The total amount lost has been estimated at $2,650,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

There do not appear to have been any funds recovered in this case.

What funds were recovered? What funds were reimbursed for those affected users?

Ongoing Developments

What parts of this case are still remaining to be concluded?

General Prevention Policies

Coming soon.

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. South Korean Government Under Fire As 3 More Crypto Platforms Hacked - The Coin Republic: Cryptocurrency , Bitcoin, Ethereum & Blockchain News (Jan 31, 2020)
  2. Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy | News Bitcoin News (Feb 7, 2020)
  3. Another Bitcoin Exchange Hacked: Youbit Files Bankruptcy After Losing Users’ Coins - Cryptovest (Feb 7, 2020)
  4. Bitcoin exchange Youbit shuts after second hack attack - BBC News (Feb 8, 2020)
  5. A South Korean bitcoin exchange has filed for bankruptcy after being hacked again (Feb 8, 2020)
  6. 100 Crypto Thefts: A Timeline of Hacks, Glitches, Exit Scams, and other Lost Cryptocurrency Incidents (Jan 25, 2020)
  7. Total of 7 Crypto Exchanges and 158 Wallets Hacked in South Korea, Police Find | Security Bitcoin News (Feb 26, 2020)
  8. North Korea Accused of Hacking South Korean Bitcoin Exchange Youbit (Feb 28, 2020)
  9. Bitcoin exchange goes bust after hack (Feb 28, 2020)
  10. South Korea: Insurance Company Denies Hacked Crypto Exchange’s Damages Claim (Feb 28, 2020)
  11. South Korean Exchange Youbit Denied Insurance Claim Following December’s Devastating Cyberattack | NewsBTC (Feb 28, 2020)
  12. Bitcoin Scams and Cryptocurrency Hacks List - BitcoinExchangeGuide.com (Mar 5, 2020)
  13. Hacked Cryptocurrency Exchange Youbit Re-Emerges Amid Insurance Controversy (Mar 7, 2020)
  14. Hacked cryptocurrency exchange resurfaces after insurance fiasco | Insurance Business (Mar 7, 2020)
  15. SlowMist Hacked - SlowMist Zone (Jun 26, 2021)
  16. Youbit 당신의 가상화폐 거래소 유빗 (Oct 16, 2021)