Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
  • CASINO
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
  • CASINO
Crypto Flexs
Home»TRADING NEWS»Beware: 2-Step Verification Code Leaks
TRADING NEWS

Beware: 2-Step Verification Code Leaks

By Crypto FlexsMarch 2, 20243 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Beware: 2-Step Verification Code Leaks
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers have discovered an unprotected database that manages access to services from some of the world’s largest technology companies. The database belongs to Meta, Google and Short Message Service (SMS) routing operators that send two-factor authentication (2FA) codes to users of cryptocurrency companies.

Researcher Anurag Sen discovered that the company’s YX International database was exposed without a password on the public Internet. Anyone who knows your public Internet Protocol (IP) address can view your data.

Users Affected by 2-Step Verification Leak

YX International sends security codes to people who log in to platforms belonging to Meta, Google and TikTok. The company ensures that users’ messages are quickly routed through mobile networks around the world. Among the messages it sends is a security code that forms part of the two-factor authentication scheme that many large companies use to protect user accounts.

Some service providers, such as Google, may send you an SMS code after you enter your password to verify your authenticity. Other authentication options include generating a code in an authenticator app to supplement your password.

Read more: 15 most common cryptocurrency scams to watch out for

Red boxes show weaknesses in SMS 2FA authentication | Source: Everything Verified

Two-factor authentication improves security, but it’s not a panacea. Accordingly, cryptocurrency exchange Coinbase warns that although 2FA is a minimum security measure, it is not perfect. Hackers can still find ways to steal funds from cryptocurrency wallets.

“2FA improves security, but it’s not perfect. Hackers who obtain the authentication factor can still gain unauthorized access to your account. Common ways to do this include phishing attacks, account recovery procedures, and malware. Hackers can also intercept text messages used for 2FA,” Coinbase said.

Criminals are using these methods to defeat 2FA.

Last year, reports emerged of criminals bypassing 2FA on Apple devices. Hackers can access Apple’s cloud platform, iCloud, and replace your phone number with their own. The scheme put funds in cryptocurrency wallet apps on Apple devices at risk because some of the applications were able to send verification codes to compromised phone numbers.

Criminals can also use SIM swaps to commit two-factor authentication encryption fraud. In this attack method, criminals persuade mobile carriers, such as AT&T or Verizon, to transfer the legitimate owner’s phone number to the fraudster. After that, criminals only need one piece of information to access a self-managed wallet app owned by the actual owner of the phone number.

Considering the surge in quantum technology, Apple recently improved the security of the Secure Enclave hardware device built into iPhone. Post-quantum cryptography generates new keys every time a malicious actor compromises an existing key.

This feature can help crypto wallet developers improve their clients’ crypto security by storing sensitive information in Secure Enclaves. So far, at least one vendor has already used Secure Enclave to grant access to wallet apps.

Read more: What is a cryptocurrency private key?

BeInCrypto has reached out to Binance and Coinbase, the world’s largest cryptocurrency exchanges, for comment on whether the XY International data breach affected users. Neither company responded by press time.

disclaimer

All information contained on our website is published in good faith and for general information purposes only. Any action you take upon the information on our website is strictly at your own risk.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The Animoca brand invests in a nice cat

August 11, 2025

Vitalik Buterin regains the title of ‘Onchain Billionaire’, where ether reaches $ 4.2K.

August 10, 2025

Did you miss the TRON ‘S (TRX) 100X? Ruvi AI (Ruvi)

August 9, 2025
Add A Comment

Comments are closed.

Recent Posts

FLOKI’s Valhalla MMORPG Storms U.S. Television With 60-Day National Commercial Blitz

August 11, 2025

A Global Initiative To Transform Crypto Education From The Ground Up

August 11, 2025

Cango Inc. Acquires 50 MW Bitcoin Mining Facility In Georgia, Laying Groundwork For Future Energy Strategy

August 11, 2025

SIM Mining Cloud Mining Allows Global Investors To Easily Earn BTC And DOGE Profits Using Just Their Smartphones (daily Income Of $23,999 USD)

August 11, 2025

MultiBank Group Delivers Record H1 Results With $209M Revenue And MBG Token Driving 7X Returns Since Launch.

August 11, 2025

The Animoca brand invests in a nice cat

August 11, 2025

Is Alt Season finally here, just as Ether Lee’s tearing and a small cap follows?

August 11, 2025

Flareonix airdrop is live! Under the share of 100m FXP today!

August 11, 2025

Carv can be used for transactions!

August 10, 2025

Ethereum (ETH), SEI (Sei), and Bonk (Bonk) gathered in July, but one token is prepared to dominate next.

August 10, 2025

Floki and OnDo expand their profits as Robinhood Listing strengthens.

August 10, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

FLOKI’s Valhalla MMORPG Storms U.S. Television With 60-Day National Commercial Blitz

August 11, 2025

A Global Initiative To Transform Crypto Education From The Ground Up

August 11, 2025

Cango Inc. Acquires 50 MW Bitcoin Mining Facility In Georgia, Laying Groundwork For Future Energy Strategy

August 11, 2025
Most Popular

Minutes Network Unveils New Technology to Increase Profitability for International Telecom Operators

December 28, 2023

Optimism that ETH withdrawals will be paused for an hour next week to test incident response systems

February 10, 2024

DAOs Are Not Scary, Part 1: Self-Enforcing Contracts And Factum Law

June 9, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.