{"id":2258,"date":"2025-05-19T11:08:12","date_gmt":"2025-05-19T08:08:12","guid":{"rendered":"https:\/\/cryptodnes.bg\/cz\/?p=2258"},"modified":"2025-05-19T15:25:30","modified_gmt":"2025-05-19T12:25:30","slug":"hack-coinbase-zpusobil-skody-klientu-v-hodnote-miliard-korun-jak-se-ochranit","status":"publish","type":"post","link":"https:\/\/cryptodnes.bg\/cz\/hack-coinbase-zpusobil-skody-klientu-v-hodnote-miliard-korun-jak-se-ochranit\/","title":{"rendered":"Hack Coinbase zp\u016fsobil \u0161kody klient\u016f v hodnot\u011b miliard korun \u2013 jak se ochr\u00e1nit?"},"content":{"rendered":"
Nejv\u011bt\u0161\u00ed americkou kryptom\u011bnovou burzu Coinbase zas\u00e1hl v polovin\u011b p\u0159edchoz\u00edho t\u00fddne v\u00e1\u017en\u00fd hackersk\u00fd \u00fatok.<\/strong> Skupina \u00fato\u010dn\u00edk\u016f vyu\u017eila tzv. insidery, domluven\u00e9 zahrani\u010dn\u00ed pracovn\u00edky z\u00e1kaznick\u00e9 podpory. N\u00e1sledn\u011b si takto opat\u0159ila citliv\u00e1 data \u010d\u00e1sti klient\u016f a lst\u00ed z nich vyl\u00e1kala p\u0159eveden\u00ed kryptom\u011bn na sv\u00e9 \u00fa\u010dty. Firma odhadla celkov\u00e9 \u0161kody v rozmez\u00ed 180 az 400 milion\u016f dolar\u016f (a\u017e 8,9 miliardy K\u010d) a p\u0159isl\u00edbila, \u017ee po\u0161kozen\u00e9 klienty od\u0161kodn\u00ed.<\/p>\n Podle informac\u00ed Coinbase se \u00fanik t\u00fdkal m\u00e9n\u011b ne\u017e 1 % u\u017eivatel\u016f platformy.<\/strong> Mezi odcizen\u00fdmi informacemi byly osobn\u00ed \u00fadaje klient\u016f \u2013 jm\u00e9na, adresy, telefonn\u00ed \u010d\u00edsla a e-maily. D\u00e1le potom \u010d\u00e1st finan\u010dn\u00edch \u00fadaj\u016f, jako jsou \u010d\u00e1ste\u010dn\u011b maskovan\u00e1 \u010d\u00edsla bankovn\u00edch \u00fa\u010dt\u016f \u010di soci\u00e1ln\u00edho poji\u0161t\u011bn\u00ed. Dokonce se \u00fato\u010dn\u00edci dostali i ke kopi\u00edm doklad\u016f toto\u017enosti a nechyb\u011bly ani intern\u00ed z\u00e1znamy o stavech \u00fa\u010dt\u016f a historie transakc\u00ed.<\/p>\n Hacke\u0159i se okam\u017eit\u011b pustili do pr\u00e1ce a t\u011bchto dat ihned vyu\u017eili k phishingov\u00fdm \u00fatok\u016fm. Rozeslali klient\u016fm podvodn\u00e9 zpr\u00e1vy, ve kter\u00fdch se vyd\u00e1vali za podporu Coinbase. Pod z\u00e1minkou nal\u00e9hav\u00e9ho p\u0159esunu prost\u0159edk\u016f na \u201ebezpe\u010dn\u00e9 \u00fa\u010dty\u201c se jim poda\u0159ilo z n\u011bkter\u00fdch u\u017eivatel\u016f vyl\u00e1kat p\u0159evod kryptom\u011bn<\/a> na pen\u011b\u017eenky pod svou kontrolou. Na\u0161t\u011bst\u00ed se nedok\u00e1zali dostat p\u0159\u00edmo do z\u00e1kaznick\u00fdch \u00fa\u010dt\u016f a nez\u00edskali ani \u017e\u00e1dn\u00e9 p\u0159ihla\u0161ovac\u00ed \u00fadaje, 2FA k\u00f3dy nebo priv\u00e1tn\u00ed kl\u00ed\u010de.<\/strong><\/p>\n Po z\u00edsk\u00e1n\u00ed dat se hackersk\u00e1 skupina pokusila Coinbase vyd\u00edrat s po\u017eadavkem na v\u00fdkupn\u00e9 ve v\u00fd\u0161i 20 milion\u016f dolar\u016f.<\/strong> M\u011blo se jednat o odm\u011bnu za to, \u017ee unikl\u00e1 data nezve\u0159ejn\u00ed. Broker<\/a> v\u0161ak odm\u00edtl zaplatit a nab\u00eddku oto\u010dil proti \u00fato\u010dn\u00edk\u016fm. Vypsala odm\u011bnu 20 milion\u016f dolar\u016f za informace vedouc\u00ed k dopaden\u00ed a odsouzen\u00ed pachatel\u016f. Z\u00e1rove\u0148 okam\u017eit\u011b propustila zam\u011bstnance a dodavatele, kte\u0159\u00ed byli do \u00fatoku zapleteni.<\/p>\n Coinbase nen\u00ed jedin\u00e1 krypto burza, kter\u00e1 se v posledn\u00ed dob\u011b stala ter\u010dem \u00fatoku. Nap\u0159\u00edklad letos v b\u0159eznu infiltrovala nechvaln\u011b zn\u00e1m\u00e1 skupina Lazarus Group (napojen\u00e1 na Severn\u00ed Koreu) jednu z p\u0159edn\u00edch sv\u011btov\u00fdch burz Bybit a odcizila kryptom\u011bny v hodnot\u011b 1,4 miliardy dolar\u016f \u2013 p\u0159ev\u00e1\u017en\u011b v ethereu, p\u0159i\u010dem\u017e zna\u010dnou \u010d\u00e1st n\u00e1sledn\u011b p\u0159evedla na bitcoiny. Tyto rozs\u00e1hl\u00e9 kr\u00e1de\u017ee ukazuj\u00ed, \u017ee ani velk\u00e9 a platformy nejsou imunn\u00ed v\u016f\u010di sofistikovan\u00fdm \u00fatok\u016fm. Proto rad\u00edme nedr\u017eet na sv\u00e9m burzovn\u00edm \u00fa\u010dtu p\u0159\u00edli\u0161 velk\u00e9 mno\u017estv\u00ed kryptom\u011bn, a to jak bitcoin, tak ani altcoiny<\/a>.<\/strong><\/p>\n Jak jsme ji\u017e zm\u00ednili, nech\u00e1vat sv\u00e9 digit\u00e1ln\u00ed mince na \u00fa\u010dtech velk\u00fdch burz m\u016f\u017ee b\u00fdt velmi riskantn\u00ed.<\/strong> Experti jako Andreas M. Antonopoulos nebo Edward Snowden varuj\u00ed, \u017ee nen\u00ed vhodn\u00e9 nech\u00e1vat v\u011bt\u0161\u00ed mno\u017estv\u00ed kryptom\u011bn dlouhodob\u011b na krypto burz\u00e1ch<\/a> \u2013 ta se m\u016f\u017ee st\u00e1t ter\u010dem hacker\u016f nebo i zbankrotovat, jak uk\u00e1zaly p\u0159\u00edklady krachu FTX \u010di d\u0159\u00edve Mt. Gox.<\/p>\n Z pohledu zabezpe\u010den\u00ed p\u0159in\u00e1\u0161\u00ed snadn\u00e9 a obl\u00edben\u00e9 \u0159e\u0161en\u00ed digit\u00e1ln\u00ed krypto pen\u011b\u017eenka<\/a>. Ty se d\u011bl\u00ed na custodial a non-custodial a d\u00e1le podle ostatn\u00edch krit\u00e9ri\u00ed. U custodial pen\u011b\u017eenky spravuje kryptom\u011bny t\u0159et\u00ed strana \u2013 typicky burza nebo poskytoval slu\u017eby, kter\u00fd dr\u017e\u00ed priv\u00e1tn\u00ed kl\u00ed\u010de. Naproti tomu non-custodial pen\u011b\u017eenka d\u00e1v\u00e1 plnou kontrolu p\u0159\u00edmo majiteli \u00fa\u010dtu \u2013 jen u\u017eivatel s\u00e1m m\u00e1 p\u0159\u00edstup ke sv\u00fdm priv\u00e1tn\u00edm kl\u00ed\u010d\u016fm.<\/strong><\/p>\n Oba p\u0159\u00edstupy maj\u00ed sv\u00e9 klady i z\u00e1pory. Custodial pen\u011b\u017eenky (Binance Wallet<\/a>, Kraken Wallet, Coinbase Wallet) zpravidla nab\u00edzej\u00ed v\u011bt\u0161\u00ed pohodl\u00ed \u2013 pokud nap\u0159\u00edklad ztrat\u00edte p\u0159ihla\u0161ovac\u00ed \u00fadaje, provozovatel m\u016f\u017ee pomoci \u00fa\u010det obnovit. U non-custodial pen\u011b\u017eenky, jako nap\u0159\u00edklad Best Wallet, toto nen\u00ed mo\u017en\u00e9 a ztr\u00e1ta nebo odcizen\u00ed priv\u00e1tn\u00edho kl\u00ed\u010de znamen\u00e1 trval\u00e9 a nen\u00e1vratn\u00e9 ztracen\u00ed ulo\u017een\u00fdch prost\u0159edk\u016f. Na druhou stranu, non-custodial \u0159e\u0161en\u00ed odstra\u0148uje riziko protistrany a jej\u00edho zabezpe\u010den\u00ed.<\/strong><\/p>\n Best Wallet<\/a> je modern\u00ed non-custodial pen\u011b\u017eenka, kter\u00e1 je na trhu od roku 2023 a od t\u00e9 doby se dostala mezi \u0161pi\u010dku na trhu. U\u017eivatel\u00e9 maj\u00ed plnou kontrolu nad sv\u00fdmi aktivy i priv\u00e1tn\u00edmi kl\u00ed\u010di<\/strong>. Pen\u011b\u017eenka podporuje hlavn\u00ed blockchainy jako Ethereum, Polygon, BNB Chain, Arbitrum a dal\u0161\u00ed. D\u00edky integraci s aplikacemi Webu 3.0 a p\u0159\u00edm\u00e9 podpo\u0159e NFT a DeFi je vhodn\u00e1 i pro pokro\u010dil\u00e9 u\u017eivatele.<\/p>\n Aplikace neukl\u00e1d\u00e1 \u017e\u00e1dn\u00e9 osobn\u00ed \u00fadaje ani e-maily. Z\u00e1kladn\u00ed p\u0159\u00edstup je mo\u017en\u00fd pouze pomoc\u00ed seed fr\u00e1ze. Pen\u011b\u017eenka pou\u017e\u00edv\u00e1 end-to-end \u0161ifrov\u00e1n\u00ed a nezprost\u0159edkov\u00e1v\u00e1 p\u0159\u00edstup k soukrom\u00fdm kl\u00ed\u010d\u016fm ani samotn\u00fdm v\u00fdvoj\u00e1\u0159\u016fm. Registrace a pou\u017e\u00edv\u00e1n\u00ed t\u00e9to platformy nevy\u017eaduje \u017e\u00e1dn\u00e9 ov\u011b\u0159en\u00ed toto\u017enosti (KYC), tak\u017ee se nemus\u00edte b\u00e1t \u00faniku sv\u00fdch citliv\u00fdch dat.<\/strong> V\u00fdvoj\u00e1\u0159i nav\u00edc pl\u00e1nuj\u00ed zero-knowledge proof (ZKP) technologii pro je\u0161t\u011b vy\u0161\u0161\u00ed \u00farove\u0148 soukrom\u00ed.<\/p>\n Pen\u011b\u017eenku m\u016f\u017eete z\u00edskat jak pro za\u0159\u00edzen\u00ed s iOS, tak i s opera\u010dn\u00edm syst\u00e9mem Android. D\u00edky n\u00ed budete m\u00edt p\u0159\u00edstup ke stakingu t\u011bch nejzn\u00e1m\u011bj\u0161\u00edch kryptom\u011bn,<\/a> decentralizovan\u00fdm burz\u00e1m (DEX) nebo NFT tr\u017ei\u0161t\u00edm.<\/strong> Best Wallet tak\u00e9 umo\u017e\u0148uje propojen\u00ed s aplikacemi jako Uniswap, Aave nebo OpenSea, d\u00edky \u010demu\u017e se z n\u00ed st\u00e1v\u00e1 univerz\u00e1ln\u00ed n\u00e1stroj pro v\u0161echny u\u017eivatele.<\/p>\n Platforma tak\u00e9 p\u0159edstavila sv\u016fj nativn\u00ed token $BEST<\/a>, kter\u00fd slou\u017e\u00ed k placen\u00ed poplatk\u016f v aplikaci a p\u0159in\u00e1\u0161\u00ed exkluzivn\u00ed odm\u011bny dr\u017eitel\u016fm tokenu. Krom\u011b lep\u0161\u00edch stakingov\u00fdch odm\u011bn m\u016f\u017eete d\u00edky tokenu $BEST z\u00edskat tak\u00e9 ni\u017e\u0161\u00ed poplatky \u010di jin\u00e9 v\u00fdhody.<\/strong> Pen\u011b\u017eenka tak\u00e9 nab\u00eddne svou platebn\u00ed kartu Best Card, d\u00edky kter\u00e9 budete moci platit rovnou v kryptom\u011bn\u00e1ch a z\u00edsk\u00e1vat cashback a\u017e 8 %.<\/p>\nJak\u00e1 data se hacker\u016fm poda\u0159ilo ukr\u00e1st?<\/h2>\n
Coinbase nen\u00ed sama, \u00fatoky se mno\u017e\u00ed<\/h2>\n
Kde dr\u017eet kryptom\u011bny bezpe\u010dn\u011b?<\/h2>\n
Best Wallet \u2013 Nejl\u00e9pe hodnocen\u00e1 non-custodial pen\u011b\u017eenka na trhu s vlastn\u00edm tokenem $BEST<\/h3>\n
<\/p>\n