Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Understanding The Risk And Phenomenon Of Crypto Assets
Articles

Understanding The Risk And Phenomenon Of Crypto Assets

Chris AdamsBy Chris AdamsApril 12, 2022Updated:January 3, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Level Finance Crypto Exchange Hacked, After Two Security Audits
Level Finance Crypto Exchange Hacked, After Two Security Audits
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As the world evolves from Web 2.0 to Web 3.0 – think decentralised protocols for crypto assets, identities, and computer-services leveraging blockchain technology – cyber threat teams too must evolve their understanding of the technology at play to stay ahead of threats.

Although the industry has evolved considerably since its inception, there is significant room for improvement. Security teams continue to battle with an array of challenges including the learning of Web 3.0 terminology, the understanding of new threat vectors, and the lack of support from existing toolsets to help analyse such threats. Meanwhile, crypto assets face significant challenges of their own. These challenges can be combatted with the right approach.

Should fear block cryptocurrency adoption?

Crypto assets are quickly becoming cyber criminals’ preferred bounty with £6.4bn of cryptocurrency laundered in 2021 alone, up by 30% from the previous year. As a result, there is a widespread belief that crypto assets, like Bitcoin, should not be adopted. Fear is a powerful motivator, with most people afraid to ‘gamble’ their money in what appears to be a volatile and risky market. But worst of all, it’s a new tool for cyber criminals to use to their advantage.

Tracking asset wallet addresses activity and transactions are far easier and quicker than the traditional flat currency, such as US dollars, that flows across boundaries and bank accounts. This is because the absence of banking systems in the transaction process makes transferring bitcoin in your name easier and cheaper than traditional currency. It is also important to note that transactions are kept and displayed on a public ledger, so anyone can see where money was sent to and from on the blockchain.

While this is seen as a strength of crypto assets, it’s also its greatest weakness. Cryptocurrency is the perfect getaway car for hackers as there aren’t any intermediary authorities like banks or governments, and no banking fees, which means you can truly do what you want with your money. Once your money is sent, there is no going back.

How do criminals obtain crypto assets?

Cyber attacks have dominated headlines over the last year. In 2021 we saw ransomware hackers being paid $11 million by JBS, $4.4 million by Colonial Pipeline and multiple groups selling data on the dark web. There is one thing in common with these attacks: cyber criminals wanted the funds in cryptocurrency.

Like all criminal activity, there are multiple pathways of entry. This includes ransomware, data exfiltration and crypto mining/jacking and these methods show no sign of slowing down. By 2025 experts predict that cybercrime will be costing the world more than $10.5 trillion annually. No organisation or individual should assume they are too insignificant and ensure they are taking the right precautions.

The US Government has started taking notice of crypto assets (referred to as virtual currencies) being used for criminal activity and is now acting upon it. The Financial Crimes Enforcement Network (U.S. Treasury Dept.) recently listed “cybercrime, including relevant cybersecurity and virtual currency considerations” as a national priority. This means security teams should expect those involved in criminal investigations and forensics to want details and a systematic means to track related threat data to support criminal cases. Threat intelligence systems of record, tools and analysis methodologies should support crypto assets fully so those details can be stored and managed like all other cyber threat intelligence.

Bringing crypto assets centre stage

The reality is that crypto assets have always been in the shadows. They play a background role as a note or an attribute but not a full-fledged supported object or entity.

Crypto Threat Intelligence provided by blockchain companies can be used by banking and financial institutions’ regulatory bodies to monitor, investigate, and prevent financial crimes such as ransomware, bitcoin mules and extortion. However, most security and threat intelligence platforms have limited understanding and capabilities in supporting this and are unable to provide crypto asset address details and related risk, wallet owners, their locations, transaction history and transaction risk.

The data sets that characterise typical threat actor behaviour, activity, and weaponry certainly carries over from traditional cyber threat intelligence where analysts are interested in cryptographic keys, file hashes, URLs, malware, IP addresses, hosts, and domains. But we need to accommodate for some of these new threat indicators in our system of record.

A Diamond Model for Diamond Hands

The threat actor uses capabilities (malware) to perform an attack and leverages infrastructure to host (malware) or operate, causing pain to the victim. Indicators to watch out for include malware file hashes and URLs or IP Addresses where the malware may be hosted or where command and control may be performed from.

Adopting an analysis-based approach, such as the Diamond Model for Intrusion Analysis, can help analysts piece together the most critical elements of an intrusion and uncover holes in infrastructure or exploitation tactics. It also helps capture trends of what actors do in hopes of prevention in the future.

By analysing the risks and threats of crypto assets, we will be able to explore how they can transition into mainstream use and become globally accepted currency. The concept of traditional flat currency has evolved greatly in our lifetime – from cash to plastic, to contactless. It is now time to allow crypto assets to do the same.

Chris Adams

Chris Adams, Director of Security Architecture at ThreatConnect

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

    May 20, 20265 Mins Read

    Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

    May 6, 20265 Mins Read

    Why OSINT deserves the same status as other intelligence disciplines

    March 17, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}