Virtual asset exchanges on AI hacking alert
Joint checks with real-name account banks underway
AI-based security analysis, response cited as key challenge
South Korea's virtual asset exchanges have launched emergency security checks after a series of AI-assisted hacking attempts were detected at both commercial and internet-only banks. No anomalies linked to hacking have been found so far, but the exchanges are keeping their guard up, conducting joint inspections with their real-name account partner banks.
According to financial authorities, the exchanges are carrying out internal security checks in coordination with the Digital Asset eXchange Alliance (DAXA), following a checklist provided by regulators. Any vulnerabilities identified during the process must be addressed, and results must be submitted to authorities by Thursday. Because the exchanges operate around the clock, they also conducted emergency checks of access logs and historical records over the three-day holiday period from Saturday through Monday.
Earlier, the Financial Supervisory Service distributed the attackers' IP addresses and security advisories to roughly 500 financial firms across the industry, ordering banks and card companies to complete emergency checks by Tuesday and securities firms, insurers, savings banks and electronic financial service providers to do so by Thursday. A DAXA official said no unusual incidents stemming from hacking attacks had been detected within the sector.
The checks begin with confirming whether the attackers' IP addresses shared by financial authorities have been blocked, and reviewing whether those addresses accessed systems or attempted intrusions — and whether any actual damage occurred. The inspections also cover historical access records, in case attacks confirmed at other financial firms were also attempted elsewhere.
Vulnerabilities in externally exposed systems and services are also under review. Exchanges are checking not only customer-facing services but also remote access channels used by employees and partner companies, and have been directed to remove unnecessary services and administrator pages to reduce potential entry points for hackers.
Authentication and access control checks are focused on preventing customer data leaks. Exchanges are verifying whether information can be accessed via URL alone without logging in, whether one customer's data can be viewed or altered by another, and whether enhanced authentication procedures are in place for critical services.
Detection and blocking systems for mass and automated attacks are also a key focus. Given that AI-powered automated attacks emerged as a central concern in this incident, exchanges have been directed to review systems that limit abnormally high volumes of access requests and detect suspicious activity in real time.
The Chinese open-source cybersecurity tool "ARTEX" is believed to have been used in the attacks. The intrusions were routed through more than 20 IP addresses across roughly 10 countries — including the United States, Japan and Germany — to evade tracking. Authorities have also added monitoring of administrator account access attempts made during nighttime hours and on holidays.
Exchanges are also checking whether the latest security updates have been applied to computer systems, terminals and network equipment. Devices that cannot receive security patches due to end-of-support from manufacturers are being separately identified and placed under enhanced monitoring to minimize blind spots in security management.
As hacking attempts have been confirmed at major commercial banks and, more recently, internet-only banks, exchanges are also raising their own security alert levels. Because exchanges rely on real-name account partner banks to process customers' won deposits and withdrawals, they are also examining whether incidents at those banks could affect their own operations.
The industry, however, believes the impact of the hacking incidents on exchange users' authentication or won transactions will be limited. Banks and exchanges operate separate authentication systems, and the bank customer inquiry and employee support systems implicated in this incident are distinct from the systems that handle deposit and withdrawal links with exchanges.
"We are sharing incident-related information with our partner bank and conducting joint checks," an official at one exchange said. "Based on threat intelligence from this hacking incident, we have reviewed access records and anomaly indicators in our own systems and taken necessary protective measures."
forest@heraldcorp.com