BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Huobi Discovers and Fixes Major Security Flaw Putting Users at Risk

Critical Vulnerability Exposed Huobi's Cloud Storage for Over Two Years, Potentially Allowing Largest Cryptocurrency Theft in History

Huobi, one of the world’s largest cryptocurrency exchanges, found and fixed a security flaw that gave permissions to access its cloud storage. The credentials were out in the open for more than two years.

- Advertisement -

According to white hat hacker and journalist Aaron Phillips, the Amazon Web Services servers that were at risk hosted Huobi’s websites, as well as its CDN (Content Delivery Network).

There was information about its users and internal documentation that could have been leaked because of the bug.

In fact, according to the author of the report, if a hacker had detected Huobi’s security flaw before it was fixed, “he would have had the opportunity to carry out the largest cryptocurrency theft in history.” That’s because the blunder would have allowed him to steal both the accounts and assets of Huobi users.

Although Huobi removed the account exposed in the described security breach, the company still did not delete the file and the credentials can still be downloaded.

- Advertisement -

Fortunately for the company and its users, no one warned about this leak, which had been online since June 2021. It should be noted that there are no longer any security risks for users of the exchange, although there are privacy risks because of the data that has already been revealed.

Huobi, an exchange where millions are traded

Huobi, a Chinese cryptocurrency exchange founded in 2013, ranks among the top 15 exchanges with the highest daily trading volume in the world, with more than USD 390 million in the 24 hours prior to the writing of this article. For reference, Kraken, the third in this global ranking, trades more than USD 551 million every day.

In recounting how he came across this find, Aaron Phillips said, “As part of my effort to look through open Amazon Web Services (AWS) S3 buckets, I found a sensitive file containing AWS credentials. After some investigation, I discovered that the credentials were active and that the account belonged to Huobi.”

Huobi faced some problems in early 2023, following a wave of layoffs at the company. With the memory of the FTX exchange still fresh in the minds of many, rumors sparked a drop in the price of Huobi’s token.

However, the company, which counts renowned entrepreneur and Tron founder Justin Sun on its board of directors, seems to have weathered the storm.

READ NEXT

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Franklin Templeton Buys 250 Digital to Launch Crypto Unit

Franklin Templeton is establishing a dedicated crypto unit, Franklin Crypto, through the acquisition of...

Must Read

Buy Domain With Bitcoin: Top 8 Domain Registrars That Accept Bitcoin And Crypto

You are here because you want to buy a domain with bitcoin, right? If you are looking for domain registrars that accept bitcoin or...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading