Interview with Hwang Seok-jin, professor at Dongguk University's Graduate School of International Information Security
AI service expansion requires separation of inquiry, order and withdrawal permissions
Beware of mass phishing attacks combining data leaked from banks
'Even with customer assets in cold wallets, hot wallet risk remains'
"A knife in a chef's hands makes a meal. In a criminal's hands, it becomes a weapon. That is the dual nature of AI."
Hwang Seok-jin, a professor at Dongguk University's Graduate School of International Information Security, made the remark in an interview Tuesday when asked about "Artex AI," a tool identified as having been used in recent cyberattacks on South Korean financial institutions. A tool designed to detect system vulnerabilities and strengthen security, he said, can become a weapon depending on who wields it.
Artex is an AI-based autonomous penetration testing tool that won a security competition hosted by Baidu's Security Response Center. A technology developed for white-hat hacking has effectively been turned against the financial sector.
Hwang said digital asset exchanges should take this incident as a wake-up call, particularly because they manage not only personal data but also customer assets. "Digital assets, once stolen, can be moved to overseas exchanges or private wallets," he said. "The concern is not so much that AI creates new vulnerabilities, but that it can more easily find and exploit the weakest existing points."
Hwang identified AI services and application programming interface permissions as the top priorities for exchanges to review. APIs serve as the conduit through which external programs access exchange data — checking market prices and balances, placing orders and more. As AI-driven trading services proliferate, he said, the permissions granted through APIs must be managed with far greater precision.
Major domestic exchanges have been expanding their use of AI across market analysis, order assistance and automated trading. DigitalX on Tuesday launched an in-app chatbot that explains market information and generates order cards based on users' natural-language requests. Upbit also offers "Upbit Skill," a service that allows AI agents to use APIs to check prices and place orders, while Coinone operates an "AI Grid" service that automatically repeats buy and sell orders within a set price range.
"Exchanges have relatively fewer ancillary or affiliated services than traditional financial institutions, so their attack surface is not necessarily the same," Hwang said. "But as AI-related services expand, so do the points of contact."
He added that exchanges should examine areas where oversight can become lax compared with core trading systems — including customer service and back-office support systems, account recovery and identity verification processes, development and testing environments, and external API and partner accounts. "Even if peripheral systems are compromised, there must be step-by-step safeguards to prevent attackers from using stolen API credentials to move into core wallet systems," he said.
When delegating trades to AI, Hwang advised that action permissions be broken down in detail. Read-only access, analysis, order placement and withdrawals should each be separated, with only the necessary functions enabled. Any changes to withdrawal addresses or expansions of API permissions, he said, must require explicit user confirmation.
Blocking withdrawal permissions alone is no cause for comfort. "If AI repeatedly buys and sells or places orders at abnormal prices, enormous losses can occur even without a single withdrawal," Hwang said. He called for exchanges to set limits on order amounts, frequency and cumulative losses, and to equip themselves with a so-called kill switch that automatically halts abnormal trading.
Hwang drew a line against the interpretation that security incidents at banks would directly translate into breaches at exchanges connected through real-name verification accounts. The customer inquiry systems and employee support platforms that were compromised, he said, are separate from the systems that link banks and exchanges for deposits and withdrawals.
"It would be an overreach to assume that a breach of a bank's peripheral systems automatically spreads to an exchange," he said. "Rather than vague concern, the focus should be on examining the actual connection architecture." The key question, he said, is how far into an exchange's data and functions an attacker could reach if authentication credentials for a linked service were stolen.
The more immediate threat, he argued, is secondary attacks exploiting leaked customer data. AI can combine customer contact details or financial transaction records to generate large volumes of tailored phishing messages that appear to come from actual bank or exchange staff. Hwang warned users to be wary of schemes that demand app installations or authentication credentials under the pretext of flagging suspicious transactions, lifting withdrawal restrictions or verifying identity.
When exchanges collaborate with external AI firms, he said, the scope of data sharing must be clearly defined. "You need to verify what data a partner can access, where it is stored and whether it is shared with other companies," Hwang said, adding that API keys and customer identifiers must be managed so they do not end up embedded in AI inputs or logs.
Hwang cited the 2014 data breach at three South Korean credit card companies as an example. In that incident, customer data was leaked through an employee of KCB, the firm contracted to develop the security system. Card companies that had provided original customer records suffered damage, while those that had supplied processed data making individual identification difficult were spared.
Exchanges currently conduct security checks through simulated hacking exercises and bug bounty programs that reward vulnerability disclosures. Upbit offers rewards of up to 200 million won ($149,000) depending on severity. Bithumb also announced it would raise its maximum reward to the same level starting in the second half of this year.
Exchange security is directly tied to the protection of investor assets. Unlike in overseas markets, South Korean digital asset investors rely heavily on exchange custody. According to the Korea Financial Consumer Protection Foundation, 94.8 percent of domestic investors said they keep their assets at domestic exchanges rather than in personal wallets.
On this point, Hwang said that even if an exchange moves most customer assets to cold wallets isolated from external networks, some assets inevitably remain in hot wallets to facilitate withdrawals at any time. "That portion can be exposed to attack, so there is no room for complacency," he said.
Swiftly patching vulnerabilities discovered during security reviews is equally important. "What matters is not how many vulnerabilities are found, but how quickly they are eliminated after discovery," Hwang said. "Clear remediation deadlines should be set based on severity and exploitability."
He added that waiting is not an option when an immediate system overhaul is not feasible. "If you cannot replace the system right away, you must not simply wait," he said. "You should temporarily disable the relevant functions, strengthen multi-factor authentication, restrict accessible IP addresses and user permissions, and intensively monitor any unusual access or transactions."
kyoung@heraldcorp.com