Major crypto exchange Binance CEO, Changpeng Zhao (also known CZ), has commented on the exchange’s security revamp and investigation into this week’s $40 million hack in a security incident.
CZ apologized for having fuelled community concerns by openly discussing the possibility of incentivizing a blockchain re-organization (re-org) as a possible response to the attack.
Binance suffered a major and premeditated hack on May 7, which reportedly resulted in the theft of around 7,070 bitcoin (BTC) worth over $40 million at the time from the exchange’s hot wallets in a transaction that went undetected by the firm’s security systems.
The attack was reported to have been a combination of phishing and viruses resulting in the capture of a large number of 2FA codes and API keys. In his security update, Binance CEO, CZ said he was restricted in sharing too many details of the exchange’s response to the incident, noting that:
“Hackers are reading every word we post and watching every AMA we host. Sharing too many security details actually weakens our security response strategy.”
However, the CEO did disclose that the exchange team was ostensibly making progress in significantly revamping its security measures, procedures and practices. He anticipates that some of the changes will be implemented this week, and that a great deal more changes will follow going forward.
CZ noted changes to the areas exploited by the perpetrators of the theft — namely Binance’s API, 2FA and withdrawal validation areas. He also revealed the platform is aiming to improve its risk management, user behaviour analysis, Know Your Customer procedures and anti-phishing tactics, as well as revising other back-end security measures.
CZ also used the security incident update as an opportunity to apologize for having sparked a controversy in the crypto community by publicly raising the consideration of undertaking a possible blockchain re-org or rollback in the wake of the hack. He said:
“Given how much I talk, I sometimes say the wrong stuff, dirty words like ‘reorg’, for which I apologize. It is my strong view that our constant and transparent communication is what sets us apart from the “old way of doing things”, even and especially in tough times.”
During a post-hack live AMA and in a tweet thereafter, Binance CEO, CZ had revealed that Binance had considered — but rejected — the idea of responding to the hack with a re-org: i.e. taking steps to incentivize miners to form a consensus to wield 51% of the network’s hashing power to reorganize the blockchain’s transactions after the loss.
Heeding the intense critique of such a move from members of the community and industry experts, the CEO and exchange decided against the attempt quoting the likely reputational damage to bitcoin and threat to its immutability and decentralization principles.