The post SlowMist analysts sound alarm over vulnerabilities in $3.7B daily volume exchange appeared on BitcoinEthereumNews.com. Blockchain security firm SlowMistThe post SlowMist analysts sound alarm over vulnerabilities in $3.7B daily volume exchange appeared on BitcoinEthereumNews.com. Blockchain security firm SlowMist

SlowMist analysts sound alarm over vulnerabilities in $3.7B daily volume exchange

Blockchain security firm SlowMist has called out two cryptocurrency exchanges that it had identified with serious vulnerabilities affecting fund security on their respective platforms. 

SlowMist’s founder, who uses the pseudonym Evilcos, expressed frustration over the lack of response. 

“Unknown exchanges are truly unreliable,” he wrote on X. “Our security team discovered serious vulnerabilities in two exchanges (directly impacting fund security), but we couldn’t reach anyone, and even public mentions got no response.”

The exchanges in question handle significant daily trading volumes, with one having a 24-hour trading volume of $3.7 billion, while the other manages around $240 million, according to Evilcos.

Disclosure attempts rebuffed

SlowMist issued security notices to Seychelles-registered Azbit and Turkish exchange ICRYPEX Global on December 16 and December 17, respectively. The firm also claimed to have attempted to contact both platforms through direct messages and public posts, following standard responsible disclosure practices, but received no acknowledgment.

ICRYPEX, which was established in 2018 and holds virtual asset service provider licenses in two European Union countries, reports serving millions of users across more than 30 countries.

Azbit was launched in late 2019 and operates in Seychelles; however, earlier this year, the regulator in Seychelles stated that “the company does not, nor has it had any authorization to operate under the Virtual Asset Service Providers Act, 2024, and is simply an international business company (“IBC”) incorporated under the IBC Act.”

The failure to establish contact prompted SlowMist to take the unusual step of publicly disclosing the vulnerability discoveries before resolution, which is a bit concerning, although one may assume that the respective exchanges are already working on them. 

However, a public address or acknowledgement of SlowMist’s findings will go a long way to calm their customers.

Industry-wide security concerns

The incident occurs against a backdrop of persistent security challenges across the cryptocurrency sector. SlowMist’s 2024 annual security report documented 410 security incidents resulting in losses of over $2.013 billion.

Cybersecurity firm CertiK shared that crypto exchanges lost over $29 million in November 2025, ranking second in the list of losses by type after decentralized finance (DeFi).

Best practices recommend that cryptocurrency developers establish contact points for reporting security issues, including long-term public keys for secure communication.

Will the exchanges be reaching out?

SlowMist’s experience of reaching out and not getting any response, while not unique, shows that even established exchanges with considerable user bases may lack adequate channels for receiving critical security intelligence.

This also raises questions about the readiness of crypto exchanges to quickly address vulnerability disclosures.

SlowMist has worked with major exchanges, including Binance, OKX, HTX, and Crypto.com, lending credibility to its security assessments and in plugging the gaps that they find.

Last month, Cryptopolitan reported that the firm SlowMist led an investigation that uncovered vulnerabilities in NOFX AI, an open-source cryptocurrency futures trading system built on DeepSeek and Qwen’s large-language-model architecture, and also shared recommendations on how the issue could be resolved. 

Industry guidelines for responsible disclosure usually recommend that affected parties respond within two working days of initial contact. If no response is received after multiple attempts, security researchers often set a public disclosure of the matter to ensure transparency, especially when funds are involved.

Neither ICRYPEX nor Azbit had responded to the security notices or made public statements regarding the vulnerabilities as of this publication.

Get up to $30,050 in trading rewards when you join Bybit today

Source: https://www.cryptopolitan.com/slowmist-analysts-vulnerabilities-exchange/

Market Opportunity
FUND Logo
FUND Price(FUND)
$0.0092
$0.0092$0.0092
-8.00%
USD
FUND (FUND) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
Trump Reviews Candidates to Succeed Fed Chair Powell

Trump Reviews Candidates to Succeed Fed Chair Powell

The post Trump Reviews Candidates to Succeed Fed Chair Powell appeared on BitcoinEthereumNews.com. Key Points: Trump evaluates Fed Chair candidates, considering
Share
BitcoinEthereumNews2025/12/19 08:34
Will XRP Price Increase In September 2025?

Will XRP Price Increase In September 2025?

Ripple XRP is a cryptocurrency that primarily focuses on building a decentralised payments network to facilitate low-cost and cross-border transactions. It’s a native digital currency of the Ripple network, which works as a blockchain called the XRP Ledger (XRPL). It utilised a shared, distributed ledger to track account balances and transactions. What Do XRP Charts Reveal? […]
Share
Tronweekly2025/09/18 00:00