Kai Sedgwick: KYC Requirements Are Making ICOs Riskier, Not Safersentinel n-featured kyc icos ico hackers hack data-leak crowdfunding bee-token bank-account bank aml
Once upon a time initial coin offerings were open to everyone. That time was last year, and since then gaining entry to ICOs has become increasingly difficult. In response to regulatory attention from the SEC, crypto startups have begun to perform due diligence on aspiring investors. Thanks to onerous KYC requirements, the pendulum has swung the other way, presenting hackers with an additional prize – the data of tens of thousands of investors.
KYC Requirements Are an Accident Waiting to Happen
Last year, the U.S. Securities and Exchange Commission went after a number of ICOs for failing to perform due diligence to ensure their investors didn’t hail from the U.S. Spurred partially by a desire to avoid censure or shutdown from the SEC, ICOs have taken things to the opposite extreme, using Know Your Customer procedures to weed out investors from the U.S., China, and a handful of other countries. To date, all of 2018’s major crowdsales have required some sort of KYC in order to gain admittance to their whitelist, with many outsourcing the task to third parties that specialize in such matters.
To merely be considered for a token sale, it is now commonplace for an individual to have to submit a passport scan, bank statement, and various other documents and to answer a string of questions about their background and the origin of their cryptocurrency. Legolas, for example, requested that investors “Provide as much detail as possible about the origin of the BTC”. Being whitelisted for a token sale is no guarantee of participation either. Oversubscribed ICOs such as Arcblock returned ether to hundreds of participants who had failed to contribute in time or who were deemed to have “cheated” by using over the prescribed gas limit. Twitter traders now encourage investors to submit KYC to as many promising ICOs as possible, just in case they later decide to participate.
A Data Leak In the Making
With ICOs now holding the passports and other identification documents of thousands of crypto investors together with their emails and wallet addresses, hackers have an added incentive to target crowdsales. Even if they’re unsuccessful in altering the contribution address, the raw data of tens of thousands of crypto holders is a honeypot of significant value in its own right. Some of that honey was stolen from The Bee Token, whose email database was accessed and used to send out phishing emails which raised over $1 million.
This week, Sentinel ICO had an even bigger fail after the passport data of its users was leaked. In a Medium post, the startup confessed that a website vulnerability had allowed uploaded files to be accessed by another user. To compound the problem, the user who discovered the flaw then claimed to have been reported to the police by Sentinel for their actions, despite having done nothing wrong.
KYC: Good for ICOs, Bad for Investors
It is hard to put a figure on the success rate for ICO whitelist applicants, though it’s likely to stand at less than 50%. At least half of the time, in other words, participants are submitting personally identifiable documents in exchange for nothing, be it due to whitelist oversubscription or network congestion that prevents them from contributing ether in time. The likelihood of that data being leaked is low, but cumulatively, over the course of dozens of KYC applications, those odds start to mount up. It only takes one failure to expose an individual’s data once and for all time. Email and wallet addresses can be changed; passports and driving licenses are permanent.
Gaining approval to participate in pre and public sales is now viewed by many ardent ICO participants as a game. The price for admission is the time it takes to complete the KYC registration process and the chance that none of the countless ICOs they apply to will suffer a catastrophic data breach. As if investing in ICOS wasn’t risky enough, KYC requirements have ironically made crowdsales even more hazardous.
Do you think KYC requirements for ICOs are excessive or necessary? Let us know in the comments section below.
Images courtesy of Shutterstock.
Keep track of the bitcoin exchange rate in real-time.
The post KYC Requirements Are Making ICOs Riskier, Not Safer appeared first on Bitcoin News.
Interested in Cryptocurrencies and ICO's?
Follow our telegram channel for daily cryptomarket reports!Join @cointrends
Original article was created by: Kai Sedgwick at news.bitcoin.comDisclaimer: This article should not be taken as, and is not intended to provide, investment advice. Please conduct your own thorough research before investing in any cryptocurrency or ICO.
|1 hour ago||n-featured|
|3 hours ago||n-featured|
|2 hours ago||ico|
|6 hours ago||ico|
|8 hours ago||aml|
|11 hours ago||crowdfunding|
|1 day ago||crowdfunding|
|12 hours ago||icos|
|2 days ago||icos|
|2 days ago||hack|
|3 days ago||hack|
|2 days ago||hackers|
|2 days ago||hackers|
|1 week ago||bank|
|1 week ago||bank-account|
|2 weeks ago||bee-token|
|6 days ago||kyc|
|2 months ago||data-leak|
Stay on top of Altcoins and ICO trends.
Subscribe to our free Weekly Cryptomarket report
Delivered once a week, strongly to your inbox.Subscribe to our mailing list
You may also be interested in:
February 19, 2018
While some state authorities and financial regulators might deride bitcoin, more people are using the cryptocurrency in their everyday lives. This has recently become evident by divorce cases around the globe involving bitcoin, with the latest example coming from Israel. Also Read: Half of Large...From: Avi Mizrahi
February 18, 2018
Bitcoin cash (BCH) is now available for trading in dozens of new physical locations across the US. The American ATM network Athena Bitcoin has added support for buying and selling the cryptocurrency for fiat cash on all its machines. Also Read: Polish Financial Authorities Paid Youtuber to...From: Avi Mizrahi
The US Commodity Futures Trading Commission (CFTC) has created a bounty to encourage whistleblowers coming forward in exposing “pump-and-dump” schemes. “Customers should not purchase virtual currencies, digital coins,” the CFTC warned, “or tokens based on social media tips or sudden...From: C. Edward Kelso
The government of Malta has come up with an idea that businesses dealing with cryptocurrencies may find interesting. A new policy document seeks to set up a special agency which will “certify” blockchain platforms and “verify” crypto transactions. It is supposed to “bring peace of...From: Lubomir Tassev
This is a paid press release, which contains forward looking statements, and should be treated as advertising or promotional material. Bitcoin.com does not endorse nor support this product/service. Bitcoin.com is not responsible for or liable for any content, accuracy or quality within the press...From: Bitcoin.com PR
Just days before the tiny nation of Gibraltar was said to draft their first initial coin offering (ICO) regulations, Financial Market Supervisory Authority (FINMA) of Switzerland appears to have stolen its thunder in an eleven page document published today. It could be the standard by which...From: C. Edward Kelso