Rebooting the Carbon Spot Market

Victims of the infostealer.Nimkey Trojan virus might have provided hackers with the necessary digital certificates and private electronic keys that temporarily shut down the spot carbon trading market in Europe this week.
After a rash of hacks of several national registries, including those in Austria, the Czech Republic, Germany and Romania, Commission officials estimate that about 2 million European Union allowances (EUAs), or 0.02 percent of EUAs in circulation, had been illegally transferred.
As a result, the Commission shut down the spot carbon trading market by preventing external or internal transfers of EUAs. Futures-based trading of EUAs, which represents about 80 percent of the carbon trading market, remains unaffected.
In the meantime, the Commission is in discussions with various national registries on how to improve security and set new standards. Once the national registries meet the new agreed security standards, they will be allowed to resume EUA transfers.
I doubt that the writers of Nimkey actually planned to shut down the carbon spot market. It's more likely that they went through their treasure trove of collected private keys and certificates and realized they had access to the various national registries—it was a crime of opportunity rather than a premeditated one.
However, it should be an object lesson for the rest of the markets when it comes to maintaining security of their networks. While digital certificates provide a decent level of security, Nimkey demonstrates their weakness. I would not be surprised if the Commission insists on not only password- and certificate-based security in the future, but on some token-based offering as well.
The major question now is whether to build the new systems themselves or move to an existing financial intranet that already provides that level of security and the clock is ticking. The longer the spot market remains closed, the more costly it will be to the industry. Yet, important decisions made in haste tend to be more expensive. I do not envy the Commission on this decision.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: https://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Trading Tech
The TNS–Radianz deal hints at underlying issues in trader voice
Waters Wrap: As part of its cost-cutting program, BT shipped its Radianz unit to TNS, but the deal didn’t include its Trading & Command trader voice property. Anthony finds that interesting.
OEMS interest sputters
Combined order and execution management systems once offered great promise, but large buy-side firms increasingly want specialization, leaving OEMS vendors to chase smaller asset managers in a world of EMS consolidation.
FactSet adds MarketAxess CP+ data, LSEG files dismissal, BNY’s new AI lab, and more
The Waters Cooler: Synthetic data for LLM training, Dora confusion, GenAI’s ‘blind spots,’ and our 9/11 remembrance in this week’s news roundup.
DORA delay leaves EU banks fighting for their audit rights
The regulation requires firms to expand scrutiny of critical vendors that haven’t yet been identified.
Etrading wins UK bond tape, R3 debuts new lab, TNS buys Radianz, and more
The Waters Cooler: The Swiss release an LLM, overnight trading strays further from reach, and the private markets frenzy continues in this week’s news roundup.
Fintech powering LSEG’s AI Alerts dissolves
ModuleQ, a partner and investment of Refinitiv and then LSEG since 2018, was dissolved last week after it ran out of funding.
Halftime review: How top banks and asset managers are tackling projects beyond AI
Waters Wrap: Anthony highlights eight projects that aren’t centered around AI at some of the largest banks and asset managers.
Speakerbus goes bust, Broadridge buys Signal, banks mandate cyber training, and more
The Waters Cooler: The Federal Reserve is reserved on GenAI, FloQast partners with Deloitte Australia, UBS invests in Domino Data Lab, and more in this week’s roundup.