Hackers have allegedly targeted OKX, draining funds from at least two accounts through a sophisticated attack involving SMS risk notifications and the creation of new API keys. The incidents occurred on June 9, 2024, with affected users receiving notifications from Hong Kong.
According to SlowMist founder Yu Xian, the attackers created new API keys with withdrawal and trading permissions, allowing them to swap and drain coins from the platform. OKX’s Chinese branch has reached out to the affected users and is investigating the incidents, promising to take responsibility if the platform is at fault.
SIM swapping, a form of phone hijacking, has been a significant threat to crypto investors. For example, in 2021, Coinbase disclosed that hackers stole crypto from about 6,000 users by bypassing multi-factor authentication. Many crypto companies have moved away from SMS-based two-factor authentication due to such risks.
The full extent of the OKX attack remains unclear, but it underscores the need for more secure authentication methods in the crypto industry. This incident highlights the ongoing vulnerabilities and the importance of robust security measures for protecting digital assets.