en
Back to the list

TUSD Stablecoin Issuer Suffers Major Third-Party Security Breach

source-logo  thecryptobasic.com 16 October 2023 13:16, UTC

The company behind the TrueUSD (TUSD) stablecoin has informed customers of a major third-party security breach leading to the loss of substantial user data.

Stablecoin issuer TrueUSD has confirmed a large-scale breach involving one of its former major service providers, TrueCoin.

The hackers made away with substantial amounts of customer information, including email, location addresses, first and last names, bank accounts, and blockchain addresses linked to their TrueUSD accounts. Additionally, the hackers obtained the phone numbers of users who registered on TrueUSD between 2018 and 2019.

TrueUSD, like most stablecoin issuers and exchanges, collects user information to comply with know-your-customer and anti-money laundering (KYC/AML) requirements imposed by regulators. However, having access to such user information is often considered high-risk, as evidenced by the latest hack.

TUSD team was informed by TrueCoin that they received a third-party vendor's notification that the vendor’s Security Team detected “an anomalous account change within [TrueCoin’s] organization made by a compromised support vendor.”

— TrueUSD (@tusdio) October 16, 2023

In an update, TrueUSD claimed that neither its internal systems nor TrueCoin’s were compromised. Instead, the hack involved a third-party vendor that TrueCoin uses alongside its technology stack to provide product management, customer onboarding, and user onboarding services to TrueUSD.

The vendor notified TrueCoin of “an anomalous account change” to its account on their platform, which led to the loss of customer information. Notably, TrueUSD’s email to clients about the hack showed that TrueCoin could not obtain any logs revealing how the hackers altered or potentially stole customer information.

The affected third-party vendors, as well as TrueCoin and TrueUSD, have since made a concerted effort to mitigate a repeat hack. Yet the Justin Sun-backed stablecoin issuer urged customers to remain vigilant as hackers may leverage stolen data to attempt phishing hacks or other kinds of fraud.

TUSD Systems and Reserves Secure and Unaffected

In the wake of the security breach, TrueUSD sought to assure users that its systems and reserves backing the stablecoin remain secure. “Both TUSD system and TUSD’s reserves are UNAFFECTED,” the company wrote in an X post.

Meanwhile, the TUSD stablecoin has been unscathed by news of the security breach. TUSD currently trades at $0.9996, maintaining a relative parity with the U.S. dollar.

With its $3.4 billion market cap, TrueUSD ranks fourth on the list of the most popular USD-pegged stablecoins, trailing Tether (USDT), USDC (USDC), and DAI (DAI).

thecryptobasic.com