Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Watch Out: Two-Factor Authentication Codes Leaked

CryptoExpert by CryptoExpert
March 2, 2024
in Technology
0
Hacker Exposes Leak of Two-Factor Authentication Codes
  • Facebook
  • Twitter
  • Pinterest


You might also like

ZIGChain integrates Ondo tokenized stocks, ETFs to expand onchain access

Real Finance, Anchorage Digital partner to expand RWA infrastructure

Coins.ph adds Bitcoin and Ethereum to Philippines QR payments

A security researcher has discovered an unprotected database governing access to services from some of the world’s biggest tech companies. The database belongs to a short message service (SMS) routing operator responsible for sending two-factor authentication (2FA) codes to users of Meta, Google, and possibly crypto firms.

The researcher, Anurag Sen, found that the company’s YX International database was exposed without a password on the public internet. Anyone who knew the public internet protocol (IP) address could view the data.

Users Affected by Two-Factor Authentication Leak

YX International sends security codes to people logging into platforms belonging to Meta, Google, and TikTok. The company ensures that users’ messages are routed speedily through mobile networks across the globe. Among the messages it sends are security codes that form part of a two-factor authentication scheme many large companies use to protect user accounts.

Some service providers, like Google, can send an SMS code to verify a user’s authenticity after entering a password. Other authentication options include generating a code from an authenticator app to complement a password.

okex

Read more: 15 Most Common Crypto Scams To Look Out For

Red Box Shows Weak Point of SMS 2FA Authentication | Source: All Things Auth

While two-factor authentication seeks to improve security, it is not a silver bullet. Accordingly, crypto exchange Coinbase warns that 2FA is a minimum security measure, but it is not foolproof. Hackers can still find a way to steal funds from crypto wallets.

“While 2FA seeks to improve security, it is not foolproof. Hackers who acquire the authentication factors can still gain unauthorized access to accounts. Common ways to do so include phishing attacks, account recovery procedures, and malware. Hackers can also intercept text messages used in 2FA,” Coinbase said.

Criminals Are Using These Methods to Beat 2FA

Last year, reports of criminals bypassing 2FA on Apple devices emerged. A hacker could access Apple’s cloud platform, iCloud, and replace a user’s phone number with their own. The scheme risked the funds in crypto wallet apps on Apple devices since some applications could have sent authentication codes to compromised phone numbers.

Criminals can also use SIM swaps to enact two-factor authentication crypto scams. In this line of attack, criminals convince mobile operators like AT&T or Verizon to transfer a phone number from the rightful owner to the fraudster. After that, the criminal only needs one other piece of information to access a self-custodial wallet app owned by the true owner of the phone number.

Given the surge in quantum technology, Apple recently improved the security of its Secure Enclave hardware device embedded in iPhones. The post-quantum cryptography scheme creates new keys every time a malicious actor compromises an old one.

This feature could help crypto wallet developers improve their clients’ crypto security by storing critical information in the Secure Enclave. So far, at least one vendor has already used the Secure Enclave to grant access to their wallet app.

Read more: What is a Private Key in Crypto?

BeInCrypto contacted Binance, the world’s largest cryptocurrency exchange, and Coinbase for comment on whether the XY International data leak affected their users. Neither company had responded by press time.

Disclaimer

All the information contained on our website is published in good faith and for general information purposes only. Any action the reader takes upon the information found on our website is strictly at their own risk.



Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

ZIGChain integrates Ondo tokenized stocks, ETFs to expand onchain access

by CryptoExpert
June 9, 2026
0
ZIGChain integrates Ondo tokenized stocks, ETFs to expand onchain access

ZIGChain adds Ondo tokenized stocks and ETFs to its ecosystem. Partnership expands onchain access to US financial markets. Rollout begins in phases across selected ZIGChain applications. ZIGChain announced...

Read more

Real Finance, Anchorage Digital partner to expand RWA infrastructure

by CryptoExpert
June 4, 2026
0
Real Finance, Anchorage Digital partner to expand RWA infrastructure

Real Finance and Anchorage Digital form RWA infrastructure pact. Partnership combines tokenization, custody, and settlement tools. Firms target institutional adoption of on-chain capital markets. Real Finance and Anchorage...

Read more

Coins.ph adds Bitcoin and Ethereum to Philippines QR payments

by CryptoExpert
May 21, 2026
0
Coins.ph adds Bitcoin and Ethereum to Philippines QR payments

Coins.ph adds BTC and ETH payments to the Philippines QRPh system. Users can spend crypto at 700,000 QRPh-enabled merchants. Stablecoins remain key for remittances and daily crypto payments....

Read more

PayPal set to purchase Cymbio to expand AI chatbot commerce tools

by CryptoExpert
January 22, 2026
0
PayPal set to purchase Cymbio to expand AI chatbot commerce tools

The Tel Aviv-based startup helps merchants expand product listings across AI chatbots. PayPal has agreed to acquire Cymbio, an Israeli platform that helps merchants sell products across AI...

Read more

Microsoft and Bristol Myers Squibb team up to deploy AI for early lung cancer detection

by CryptoExpert
January 20, 2026
0
Microsoft and Bristol Myers Squibb team up to deploy AI for early lung cancer detection

Microsoft has formed a partnership with Bristol Myers Squibb to accelerate early detection of lung cancer using AI-powered radiology tools, according to a Tuesday announcement. Lung cancer ranks...

Read more
Next Post
TON Foundation X AMA Session With BeInCrypto

TON Foundation X AMA Session With BeInCrypto

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 65,800.00
ethereum
Ethereum (ETH) $ 1,791.70
tether
Tether (USDT) $ 0.999072
bnb
BNB (BNB) $ 604.41
xrp
XRP (XRP) $ 1.22
usd-coin
USDC (USDC) $ 0.999669
solana
Solana (SOL) $ 73.83
tron
TRON (TRX) $ 0.316963
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?