Indonesia Detains Hacker Tied to Markets.com Crypto Theft After $398K Loss
Indonesian authorities have arrested a local hacker who allegedly exploited security flaws in trading platform Markets.com's deposit system to steal $398,000 worth of cryptocurrency.
Police detained the suspect, identified only as HS, on Saturday in Bandung, West Java, following a complaint filed by Finalto International Limited, the London-headquartered owner of Markets.com, according to a local media report.
The operation resulted in losses totaling $398,000 (Rp 6.67 billion) for the trading platform, with HS facing charges under Indonesia's cybercrime and anti-money laundering laws, with potential penalties of up to 15 years in prison and fines reaching $900,000 (Rp 15 billion).
Decrypt has reached out to Finalto International for further comment.
Deputy Cybercrime Director Andri Sudarmadi said investigators uncovered how HS allegedly exploited an anomaly in Markets.com's nominal input system.
The platform reportedly generated USDT balances based on whatever deposit amount the attacker entered, creating an opening for fraudulent gains without proper backend validation.
According to police, HS created four fake accounts under the names Hendra, Eko Saldi, Arif Prayoga, and Tosin, sourcing real identity data by scraping Indonesian national ID information from publicly accessible websites.
Authorities say the suspect, a computer accessories distributor and crypto trader since 2017, used his experience to identify and exploit the system vulnerability.
Police seized a laptop, mobile phone, CPU unit, ATM card, a 152-square-meter shophouse in Bandung, and a cold wallet containing 266,801 USDT worth approximately $4.2 million (Rp 4.45 billion).
KYC "isn't enough anymore"
Cybersecurity consultant David Sehyeon Baek told Decrypt the scraped ID data indicates that the hacker was "someone plugged into a much bigger underground data ecosystem" rather than being a lone operator.
"A lot of exchanges still treat KYC like a checkbox exercise," he said, noting the ease with which bad actors can "build convincing fake identities using leaked data and AI tools."
"Traditional KYC alone just isn’t enough anymore," Baek said, urging exchanges to adopt “continuous monitoring, device and network intelligence, and better cross-platform collaboration” to detect synthetic identities early.
Baek said the case fits "a very clear industry trend." He explained that attackers are moving away from complex smart contract hacks and looking for "easier entry points in Web2 systems—things like business logic flaws, weak APIs, broken access control, and poor backend validation."
These kinds of issues can be addressed by "basic secure coding practices, internal code review, and routine security testing," the expert added.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
No More Concealed Allocations: ZKP Auctions Transform Fairness in Crypto
- ZKP's crypto presale uses daily on-chain auctions to distribute 35% of its 257 billion tokens, rejecting private allocations and hidden vesting schedules. - The 24-hour auction model allocates 200 million tokens proportionally based on pooled contributions, ensuring equal access without early-mover advantages. - Transparent on-chain visibility and $50,000 daily contribution caps prevent whale dominance, aligning with trustless system trends in crypto distribution. - This structure creates organic price d

Zcash (ZEC) Price Rally and the Revival of Privacy Coins: Regulatory Changes and Growing Institutional Interest Usher in a New Chapter
- Zcash (ZEC) surges over 7% in 24 hours, hitting $700+ amid 2025's privacy coin revival driven by regulatory clarity and institutional adoption. - U.S. Clarity/Genius Acts enable selective transparency for privacy coins, with Zcash's hybrid model outpacing Monero's mandatory anonymity in institutional appeal. - Cypherpunk's $100M Zcash treasury and Grayscale's ZCSH trust validate ZEC as a compliance-ready privacy asset, complementing Bitcoin's store-of-value role. - Zashi Cross Pay and Sapling upgrades en
Bitcoin News Update: Pakistan's Foreign Exchange Outflow Accelerates Amid Economic Instability and Lax Crypto Oversight
- Pakistan reports $600M forex loss via illicit crypto transactions, draining 23% of dollar inflows through unregulated channels. - ECAP reveals cash withdrawals from licensed firms fund crypto investments, straining reserves amid trade deficits and political instability. - SBP tightens forex controls but experts warn crypto outflows persist, mirroring global crypto losses and compounding weak enforcement. - Geopolitical shifts, including Trump's India-Pakistan ceasefire claims and U.S.-Pakistan military c

Cardano News Update: ZKP’s Open Presale Approach Disrupts Traditional Blockchain Speculation
- Investors are shifting from HBAR and ADA to ZKP, a 2025-focused blockchain project with transparent presale and real-world utility. - ZKP's $120M pre-launch funding and daily on-chain auctions contrast with HBAR's 36% decline and ADA's weak DeFi traction. - The project's Proof Pods hardware and "built-first" strategy differentiate it from legacy projects with delayed upgrades. - ZKP's fair allocation model and institutional partnerships position it as a paradigm shift in crypto project launches. - Analys

