Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,309)
  • Analysis (2,461)
  • Bitcoin (3,064)
  • Blockchain (1,878)
  • DeFi (2,236)
  • Ethereum (2,172)
  • Event (80)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,284)
  • Press Releases (10)
  • Reddit (1,728)
  • Regulation (2,141)
  • Security (2,945)
  • Thought Leadership (3)
  • Uncategorized (1)
  • Videos (43)
Hand picked
  • Malaysia: Full autonomy to crypto exchanges for listing tokens
  • BLUE is available for exchange!
  • Everything About NEAR’s 14% Drop and Whether Traders Should Expect More Losses
  • XRP Price Drops 8% Despite Launch of Bitwise XRP ETF
  • When will this Bitcoin seller on Binance stop dumping? Long-term holders absorb 186,000 BTC or $15.5 billion in 6 weeks
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Security»Indonesian police arrest hacker for $398,000 crypto theft Markets.com
Security

Indonesian police arrest hacker for $398,000 crypto theft Markets.com

November 21, 2025No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Hacker exploits filing system flaw

Indonesian authorities have arrested a local hacker who allegedly manipulated security flaws in trading platform Markets.com’s deposit mechanism to steal cryptocurrency worth $398,000. The suspect, identified only as HS, was arrested on Saturday in Bandung, West Java, following a formal complaint from Finalto International Limited, the London-based company that owns Markets.com.

The police investigation revealed that HS had exploited what they called an “anomaly” in the platform’s nominal entry system. The system apparently generated USDT balances based on the deposit amount entered by the user, without proper back-end validation. This created an opportunity for fraudulent earnings simply by entering false deposit figures.

Fake accounts and stolen identities

According to police statements, the suspect created four separate fake accounts using the names Hendra, Eko Saldi, Arif Prayoga and Tosin. He allegedly obtained real Indonesian national identity information by scraping publicly accessible websites, then used that data to create convincing fake identities for the accounts.

Authorities described HS as a computer accessories distributor involved in cryptocurrency trading since 2017. They believe its experience in the technology and crypto markets helped it identify and effectively exploit the system vulnerability.

Seizure of significant assets

During the arrest operation, police confiscated important evidence and property, including a laptop, cell phone, CPU, ATM card and a 152 square meter store in Bandung. Specifically, they seized a cold wallet containing 266,801 USDT worth approximately $4.2 million. The presence of such a large sum in the cold wallet suggests that this may not have been the suspect’s only transaction.

Deputy Director of Cybercrime Andri Sudarmadi confirmed that HS was facing charges under Indonesia’s cybercrime and anti-money laundering laws. If convicted, he faces up to 15 years in prison and fines of up to $900,000.

Wider security implications

Cybersecurity consultant David Sehyeon Baek told reporters that the use of scraped credentials indicates the hacker was likely “someone connected to a much larger underground data ecosystem” rather than working alone. He expressed concern about the ease with which bad actors can now “create convincing false identities using leaked data and AI tools.”

“Many exchanges still treat KYC as a check-box exercise,” Baek noted, adding that “traditional KYC alone is no longer enough.” He urged trading platforms to adopt more comprehensive security measures, including continuous monitoring, device and network intelligence, and better cross-platform collaboration to quickly detect synthetic identities.

Baek sees this case as part of a “very clear industry trend” where attackers are moving away from complex smart contract hacks and toward “easier entry points into Web2 systems.” He specifically mentioned business logic flaws, weak APIs, faulty access control, and poor backend validation as common vulnerabilities being exploited.

According to the expert, these types of security issues can often be resolved through “basic secure coding practices, internal code review, and routine security testing.” The Markets.com incident is a reminder that even established trading platforms can have fundamental security flaws that sophisticated attackers can identify and exploit.

I think what’s interesting here is that the attacker didn’t need advanced technical skills, just an understanding of how the system works and how its validation processes fail. One wonders how many other platforms might have similar fundamental flaws in their deposit and balance systems.

Loading



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalaysia’s Tenaga Nasional Suffers Over $1 Billion Losses From Crypto Power Theft
Next Article Buy net profits of over $1.3 million in a flash

Related Posts

Security

XRP Price Drops 8% Despite Launch of Bitwise XRP ETF

November 22, 2025
Security

Incoin Financial Services Unveils Enhanced Trading Interface and APIs for Institutional-Grade Intelligent Execution

November 21, 2025
Security

Crypto Bull Run 2026: Top Trends and Insights

November 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Post-Event PR: Vienna Blockchain Week 2025 Asserts Europe’s Leadership in Digital Asset Innovation

November 19, 2025

Vienna Blockchain Week 2025 concluded after three dynamic days of keynotes, debates, regulatory deep dives,…

Event

Verifying Intelligence 3.0 – Where ZK Meets AI & x402

November 18, 2025

House of ZK announced Verifying Intelligence 3.0 – Where ZK Meets AI & x402, the…

1 2 3 … 62 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Everything About NEAR’s 14% Drop and Whether Traders Should Expect More Losses

November 22, 2025

Winter is Coming: Cryptocurrency Season Enters Dormant Phase as Bitcoin and Altcoins Pull Back

November 21, 2025

Michael Saylor Sends MSCI Index Response, Focuses on BTC

November 21, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 84,656.68
ethereum
Ethereum (ETH) $ 2,754.82
tether
Tether (USDT) $ 0.999833
xrp
XRP (XRP) $ 1.95
bnb
BNB (BNB) $ 837.75
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.276533
staked-ether
Lido Staked Ether (STETH) $ 2,752.88
dogecoin
Dogecoin (DOGE) $ 0.140054
cardano
Cardano (ADA) $ 0.408199