{"id":53616,"date":"2023-07-03T07:32:11","date_gmt":"2023-07-03T11:32:11","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=53616"},"modified":"2023-07-03T07:32:14","modified_gmt":"2023-07-03T11:32:14","slug":"huobi-fixes-cloud-storage-breach-risking-users-funds","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/huobi-fixes-cloud-storage-breach-risking-users-funds\/","title":{"rendered":"Huobi Fixes Cloud Storage Breach Risking Users\u2019 Funds"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/huobi-global-to-delist-10-trading-pairs.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Huobi,<\/a> a major crypto exchange, fixed a data breach that exposed credentials to its AWS S3 buckets, putting users' data and assets at risk since June 2021.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/HUobi-global.jpg\" alt=\"Huobi Fixes Cloud Storage Breach Risking Users\u2019 Funds\" class=\"wp-image-53618\" width=\"670\" height=\"377\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/HUobi-global.jpg 548w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/HUobi-global-300x169.jpg 300w\" sizes=\"(max-width: 670px) 100vw, 670px\" \/><\/figure>\n\n\n\n<p>According to white hat hacker and citizen journalist <a href=\"https:\/\/phillips.technology\/blog\/huobi-crypto-aws\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Aaron Phillips<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the breach involved the exposure of credentials granting write privileges to all of Huobi's <a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/UsingBucket.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">AWS S3 buckets<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, which the company uses for its cloud storage. <\/p>\n\n\n\n<p>Anyone with access to the credentials could have modified content on Huobi's domains, including huobi.com and hbfile.net. Additionally, Phillips said user data and internal documents were also at risk of exposure.<\/p>\n\n\n\n<p>Phillips added that the breach's severity was significant, alleging that it had the potential for attackers to <em>&#8220;carry out the largest crypto theft in history.&#8221;<\/em> <\/p>\n\n\n\n<p>Huobi, which handles over<strong> $10 billion<\/strong> in monthly trading volume according to The Block's data dashboard, deleted the compromised account and secured its cloud storage on June 20, as reported by Phillips.<\/p>\n\n\n\n<p>Huobi confirmed the breach in an email to The Block, stating that it involved the leakage of user contact information on a small scale <strong>(4,960 individuals). <\/strong><\/p>\n\n\n\n<p>The company said the incident occurred on June 22, 2021, due to <strong><em>&#8220;improper operations by personnel related to the S3 bucket in the testing environment of the Huobi Japanese AWS site.&#8221;<\/em><\/strong> The relevant user information was completely isolated on October 8, 2022.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;Huobi Japanese site and Huobi Global site are completely different entities. After being discovered by a white hat team, the Huobi Security Team promptly took action on June 21, 2023, immediately closing the relevant file access permissions. The current issue has been fixed, and all related user information has been deleted. We appreciate the contributions made by the white hat team to Huobi's security,&#8221;.<\/p>\n<cite>Huobi Global<\/cite><\/blockquote>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Breaking: White hat Aaron Phillips disclosed that the Huobi exchange had leaked nearly all OTC transaction information from 2017 to 2021 on a large scale in 2021; some user information, VIP user information and its own technical infrastructure. Read more: <a href=\"https:\/\/t.co\/QJx45LHLhg\" target=\"_blank\">https:\/\/t.co\/QJx45LHLhg<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/ln6pzpbjin\" target=\"_blank\">pic.twitter.com\/ln6pzpbjin<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Wu Blockchain (@WuBlockchain) <a href=\"https:\/\/twitter.com\/WuBlockchain\/status\/1675005132180955136?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 1, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-months-of-delay-and-vulnerability\">Months of delay and vulnerability<\/h4>\n\n\n\n<p>Phillips, however, disputed Huobi's response, saying that it took months for the white hat to receive a response from Huobi, and the leaked credentials remained online even after he first notified Huobi of the issue in June 2022. <\/p>\n\n\n\n<p>He also highlighted the vulnerability of Huobi's <a href=\"https:\/\/aws.amazon.com\/what-is\/cdn\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">content delivery networks (CDNs)<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> and websites, which can lead to the injection of malicious scripts.<\/p>\n\n\n\n<p>Phillip stated that the CDNs could have compromised every Huobi login page, potentially affecting every user who logged into a Huobi website or app over the last two years. <\/p>\n\n\n\n<p>He also shared screenshots of confidential reports containing user data and internal documents exposed by the breach. <\/p>\n\n\n\n<p>Phillips said he decided to go public with his findings after failing to get a satisfactory response from Huobi. He hoped his disclosure would raise awareness and accountability in the <a href=\"https:\/\/coinscreed.com\/staging\/crypto-industry-opposes-us-secs-defi-regulation-plan.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">crypto industry.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Huobi, a major crypto exchange, fixed a data breach that exposed credentials to its AWS S3 buckets, putting users&#8217; data and assets at risk since June 2021. According to white hat hacker and citizen journalist Aaron Phillips , the breach involved the exposure of credentials granting write privileges to all of Huobi&#8217;s AWS S3 buckets, [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":53618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[130],"tags":[202,15102,132,10588,11246],"class_list":["post-53616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain-news","tag-blockchain","tag-cdns","tag-crypto","tag-huobi-global","tag-security"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/HUobi-global.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/53616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=53616"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/53616\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/53618"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=53616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=53616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=53616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}