{"id":12201,"date":"2024-04-02T12:51:34","date_gmt":"2024-04-02T09:51:34","guid":{"rendered":"https:\/\/forklog.com\/en\/opinion-kyc-is-no-upgrade-but-a-security-hole\/"},"modified":"2024-04-02T12:51:34","modified_gmt":"2024-04-02T09:51:34","slug":"opinion-kyc-is-no-upgrade-but-a-security-hole","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/opinion-kyc-is-no-upgrade-but-a-security-hole\/","title":{"rendered":"Opinion: KYC is no upgrade, but a security hole"},"content":{"rendered":"<p>In March 2024, the European Parliament\u2019s lead committees <a href=\"https:\/\/u1f987.com\/en\/news\/european-parliament-committees-endorse-ban-on-anonymous-crypto-transactions\">approved<\/a> a ban on anonymous transfers of digital assets. The new laws will take effect in three years if adopted by the EU Council and the Parliament.<\/p>\n<p><!--more--><\/p>\n<p>The team at <a class=\"tracking_link\" href=\"https:\/\/50x.com\/\" target=\"_blank\" rel=\"noopener\">50x.com<\/a> argues that blanket user identification will undermine the safety of personal data. Together with the exchange\u2019s developers, we examine why <span data-descr=\"Know your customer\" class=\"old_tooltip\">KYC<\/span> does not guarantee the security of services, and where to trade cryptocurrencies without verification.<\/p>\n<h2 class=\"wp-block-heading\">What problems KYC creates<\/h2>\n<p>In May 2023, hardware-wallet maker Ledger unveiled a service to recover private keys via a KYC procedure. Using Ledger Recover, the device splits a seed phrase into three encrypted fragments and sends them to external custodians.\u00a0<\/p>\n<p>Ledger chief Pascal Gauthier said there was demand for such a service from novice investors:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;The main problem with implementing self-custody of cryptocurrencies is precisely the ability to recover the seed phrase. Most users today either do not own their private keys or put them at risk by using less secure and more complex methods of non-custodial storage and protection of the seed phrase.&#8221;<\/em><\/cite><\/p><\/blockquote>\n<p>The community\u2019s response to Ledger Recover was mixed. For instance, 1inch co-founder Anton Bukov pointed to a breach of the hardware wallet\u2019s security model, which \u201cshould not have an <span data-descr=\"Application programming interface\" class=\"old_tooltip\">API<\/span> for revealing the seed phrase\u201d.<\/p>\n<p>Ledger co-founder and former CEO Eric Larchev\u00eaque acknowledged that the government could summon the custodians of encrypted seed fragments to court and gain access to bitcoin.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;This is precisely the vulnerability of services with verification: if you show your passport to restore access to your account, attackers can do the same.<\/em><\/p>\n<p><em>KYC and crypto are a toxic mix. They are poorly compatible with each other, both in spirit and purely technically. In <span data-descr=\"Traditional finance\" class=\"old_tooltip\">TradFi<\/span>, with documents people prove their connection to assets, for example for inheritance of funds or to challenge an illegal transaction.\u00a0<\/em><\/p>\n<p><em>In the blockchain nothing can be rolled back. If a hacker breaks into your account, the withdrawal transaction will remain on the network forever. In practice, KYC gives more room for theft rather than the return of assets,&#8221; \u2014 note representatives of 50x.com.<\/em><br \/><\/cite><\/p><\/blockquote>\n<p>They say a heavy reliance on third parties is why many view verification negatively:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;People with a lot of crypto experience don\u2019t like KYC. Not because they want to evade taxes or launder money. They know that by handing data to an exchange, users lose control over it. How do services store personal information? You cannot know for sure.<\/em><\/p>\n<p><em>Ledger is a telling example. In 2020, the email addresses, names and phone numbers of a million people <\/em><em>leaked<\/em><em> into the public domain. After that, clients began receiving messages with threats of physical violence. Scammers are still sending them phishing emails.&#8221;<\/em><\/cite><\/p><\/blockquote>\n<p>Crypto exchanges claim that KYC improves the security of client assets: in the event of suspicious activity, platforms will have more ways to identify the account owner.<\/p>\n<p>In practice, however, staff often check documents inadequately, and users find ways to bypass KYC.\u00a0<\/p>\n<p>For example, last year on-chain sleuth ZachXBT completed verification on Gate.io under the name Kim Jong-Un and with the email <span data-descr=\"a reference to the North Korean hacking group Lazarus Group\" class=\"old_tooltip\">notlazarus<\/span>.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">When stolen funds go to a crypto exchange people like to assume that there is a real person with a real identity tied to an account<\/p>\n<p>To disprove this I was able to create an account on <a href=\"https:\/\/twitter.com\/gate_io?ref_src=twsrc%5Etfw\">@gate_io<\/a> and KYC as \u201cKim Jong-Un\u201d with the email \u201cnotlazarus\u201d and within minutes I was verified <a href=\"https:\/\/t.co\/oCZLK4hBh9\">pic.twitter.com\/oCZLK4hBh9<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/twitter.com\/zachxbt\/status\/1655929037770899457?ref_src=twsrc%5Etfw\">May 9, 2023<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>In February, 404 Media journalists <a href=\"https:\/\/u1f987.com\/en\/news\/ai-generated-documents-service-circumvents-kyc-on-major-crypto-exchanges\">passed<\/a> KYC on OKX using a passport generated by AI algorithms via the OnlyFake service. Other enthusiasts managed to fool staff at Binance, Kraken, Bybit, HTX, Coinbase, Bitget, Revolut and PayPal.<\/p>\n<p>Despite the vulnerability of verification procedures, the crypto industry is trending toward their universal adoption.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;Almost all major <span data-descr=\"Centralized exchange\" class=\"old_tooltip\">CEX<\/span> restrict trading without KYC. KuCoin held out the longest, but in the middle of last year it too <\/em><em>introduced<\/em><em> mandatory identity checks.<\/em><\/p>\n<p><em>We see clear signs that regulators want to go further \u2014 to gain power not only over exchange accounts, but also over users\u2019 cryptocurrency wallets.<\/em><\/p>\n<p><em>Imagine how deep some <span data-descr=\"G-man (government man)\" class=\"old_tooltip\">G-man<\/span> will stick his hand into citizens\u2019 pockets with the inevitable disappearance of cash and the absence of alternatives in the form of KYC-free crypto services,&#8221; \u2014 note 50x.com.<\/em><br \/><\/cite><\/p><\/blockquote>\n<h2 class=\"wp-block-heading\">Where to trade cryptocurrencies without KYC<\/h2>\n<p><a class=\"tracking_link\" href=\"http:\/\/50x.com\" target=\"_blank\" rel=\"noopener\">50x.com<\/a> is one of the few centralized cryptocurrency exchanges without verification procedures. The platform runs on Any2Any technology, which allows digital currencies to be exchanged without base assets such as Tether or bitcoin.<\/p>\n<p>To register on the exchange, you need to provide an email and enable two-factor authentication (2FA). You can later add a separate code for withdrawals.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;You will not lose assets, even if you enter your password and 2FA on a phishing site. Different codes are required to log in to the exchange and to withdraw tokens,&#8221; \u2014 says the 50x.com website.<\/em><\/cite><\/p><\/blockquote>\n<p>A prerequisite for starting trading is creating a master key for a one-time account recovery. When it is activated, 50x.com initiates the automatic withdrawal of cryptocurrencies to predefined addresses (Emergency Withdrawal Addresses, EWA).<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\n<cite><em>&#8220;The master key will allow you to withdraw funds and close the account if you lose your password and\/or 2FA. It does not pose additional risks for users: if an attacker steals the master key, it will trigger the withdrawal of tokens to your addresses,&#8221; \u2014 note 50x.com.<\/em><\/cite><\/p><\/blockquote>\n<h2 class=\"wp-block-heading\">Conclusions<\/h2>\n<p>By 2024, all major exchanges had introduced mandatory verification. It should not be viewed as a \u201cnecessary evil\u201d, however. KYC checks do not ensure the safety of client funds and are vulnerable to attacks that use artificial intelligence.<\/p>\n<p>User identification has become standard practice in TradFi. The team at <a class=\"tracking_link\" href=\"https:\/\/50x.com\/\" target=\"_blank\" rel=\"noopener\">50x.com<\/a> believes that by its very nature it runs counter to the spirit of cryptocurrencies, restricts financial freedoms and exposes users\u2019 personal data to unjustified risks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In March 2024, the European Parliament\u2019s lead committees approved a ban on anonymous transfers of digital assets. The new laws will take effect in three years if adopted by the EU Council and the Parliament.<\/p>\n","protected":false},"author":1,"featured_media":12200,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[1144],"tags":[1292,1267],"class_list":["post-12201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-longreads","tag-aml-kyc","tag-cryptocurrency-trading"],"aioseo_notices":[],"amp_enabled":true,"views":"21","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/12201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=12201"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/12201\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/12200"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=12201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=12201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=12201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}