Close Menu
    X (Twitter) Telegram
    Learn everything Crypto, Blockchain & Web3 | ApeSpace Learn
    • View Charts HOT
    • Rugs/Exploits
    • Tutorials & Tips
    • Sponsored & PR
    Telegram X (Twitter)
    Learn everything Crypto, Blockchain & Web3 | ApeSpace Learn
    Rugs/Exploits

    Huobi patches massive vulnerability after researcher allegedly tries for a year to disclose it

    By ApeSpaceJuly 3, 2023

    After the Huobi crypto exchange (finally) fixed a massive vulnerability, researcher Aaron Phillips published a blog post explaining what he had found. According to Phillips, two years ago, the exchange accidentally published a file containing Amazon Web Services (AWS) credentials, which could have allowed a bad actor to modify content on their websites and in their CDN, distribute malicious versions of their Android app, access user data and “whale reports” on high-value users, access OTC trade records and user data for OTC traders, and “carry out the largest crypto theft in history”. “I had full control over data from almost every aspect of Huobi’s business,” wrote Phillips.

    According to Phillips, it took months before he was able to get in touch with Huobi and convince them to act on the leak. Phillips first notified Huobi of the leak in June 2022, and after repeated efforts to contact the company, the credentials were only revoked in June 2023.

    Huobi has tried to downplay the hack, first stating that the user data leak was “on a small scale (4,960 individuals)” and “does not involve sensitive information and does not affect user accounts and fund security”. They also claimed the leaked OTC data was test data. “The log shows that only [Phillips] has downloaded, and [Phillips] has also stated that he has deleted. Therefore no leakage is actually caused,” they wrote.

    According to CoinGecko, Huobi is the seventeenth-largest cryptocurrency exchange by volume.


    • “Huobi’s Leaky Bucket Risked Massive Crypto Breach”
      , Aaron Phillips

    • “Crypto exchange Huobi says two-year data breach wasn’t that bad”
      , Protos
    Share. Twitter Telegram Facebook
    Avatar photo
    ApeSpace
    • Website
    • X (Twitter)

    The ultimate crypto analytics platform for all traders! REAL TIME! - Charting - Trading - Analytics #ApeSpaceIO

    Related Posts

    Seneca Protocol bug enables at least $3 million in stolen user funds

    February 28, 2024

    “Crypto inheritence” project Serenity Shield hacked, token price plummets 99%

    February 28, 2024

    Scammers hack Twitter account of late actor Matthew Perry, solicit “donations” for “substance abuse charity”

    February 27, 2024

    $440,000 stolen as MicroStrategy’s Twitter account is hacked

    February 26, 2024
    Latest Posts

    Will Crypto Go Back Up? A Deep Dive into Market Cycles

    June 23, 2025

    The End of PAWS Pre-Market: Is It Too Late to Jump In?

    June 23, 2025

    Unlock Crypto Gains: Charting Altcoin Opportunities

    June 22, 2025
    The ultimate crypto learning site | Learn everything from Crypto, Blockchain, Web3 and more from beginner to expert | ApeSpace Learn
    © 2025 ApeSpace An Innovative Fuse Ltd Brand

    Type above and press Enter to search. Press Esc to cancel.