Fun

News Feed - 2023-07-03 01:07:24

Martin Young4 hours agoPoly Network urges users to withdraw after exploit affects 57 crypto assetsThe Poly Network has been exploited again, this time due to compromised private keys, according to blockchain security firm Dedaub.3970 Total views7 Total sharesListen to article 0:00NewsJoin us on social networksFurther details are coming to light following a July 2 attack on cross-chain bridge platform Poly Network, with a hacker being able to issue billions of tokens out of thin air for profit.


In a July 2 tweet, Poly Network confirmed it became the latest decentralized finance (DeFi) exploit victim after attackers managed to manipulate a smart contract function on the cross-chain bridge protocol, adding it will be temporarily suspending services.


In the most recent update, the team revealed that the exploit affected 57 crypto assets on 10 blockchains, including Ethereum, BNB Chain, Polygon, Avalanche, Heco, OKX and Metis.


It did not specify how much was stolen in the attack, but PeckShield earlier reported that the exploiter had transferred out at least $5 million worth of crypto.Tokens transferred out of Poly Network. Source:Twitter/PeckShield


“We have already initiated communication with centralized exchanges and law enforcement agencies and sought their assistance,” the team stated in a July 3 update.


It also advised project teams and tokenholders to withdraw liquidity and unlock their liquidity provider tokens.’34 billion’ Poly Network hack breakdown


DeFi security analyst Arhat said the exploit resulted from a smart contract vulnerability that allowed the hacker to “craft a malicious parameter containing a fake validator signature and block header.”


This was accepted by the smart contract, enabling the hacker to bypass the verification process and allowing them to issue tokens from Poly Network’s Ethereum pool to their own address on other chains, such as Metis, BNB Chain, and Polygon.


The process was repeated for other chains enabling the token stash to pile up.


At one point, the hacker’s wallet held around $42 billion worth of tokens, but they were only able to convert and steal a fraction of them, said the analyst.“This way, the hacker was able to mint billions of tokens on various blockchains that did not exist before and transfer them to their own wallet addresses.”


Blockchain security solutions provider Dedaub dubbed the latest Poly Network exploit the “34 billion Poly Network hack.”Getting to the bottom of the "34 billion" Poly network hack with a technical postmortem.

TL ; DR

Poly network had a simple 3 of 4 multisig arrangement over 2 years!

Looking at the final event we found that the private keys to the addresses marked were compromised. pic.twitter.com/Y0eMJXcYso— Dedaub (@dedaub) July 2, 2023


Dedaub noted weaknesses in the protocol’s multisig, stating that it had a simple “3 of 4” multisignature arrangement over two years, adding:“Looking at the final event we found that the private keys to the addresses marked were compromised.”


Dedaub explained that the attack wasn’t complex, as no logic bugs were exploited. It added that Poly Network took seven hours to respond, which cost the platform $5.5 million in stolen crypto. Luckily, a lack of liquidity in many of the tokens prevented further losses.


Related:Over $204M lost to DeFi hacks and scams in Q2


Following the attack, Binance CEO, Changpeng Zhao reassured customers, stating that “This does not affect Binance users. We do not support deposits from this network.”Poly Network got rekt again; allegedly because of compromised hot keys.

It"s going to keep happening untill our industry changes our approach to security.

Smart contract audits only scratch the surface.

ps Poly network has NOTHING to do with Polygon. https://t.co/n1qI48b4Kb— Mudit Gupta (@Mudit__Gupta) July 2, 2023


Cointelegraph reached out to Poly Network for further details but received no response by publication.


In August 2021, the Poly Network was attacked in one of the industry’s largest-ever exploits. Hackers — later revealed to be linked with North Korean hacking collective, the Lazarus Group — made off with over $600 million.


Magazine: Tornado Cash 2.0: The race to build safe and legal coin mixers# Smart Contracts# Hackers# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to check an Ethereum transactionCybernetic organizations — BORGs — are doomed to failBinance caves to pressure over coin listings, scoring a win for privacyAttacker drains $800K from DeFi protocol Sturdy FinanceDeFi protocol Sturdy Finance offers $100K bounty to hacker if funds are returnedHashflow assures users will be made whole following $600K exploit

News Feed

Funds hacked in 2024 increased by 15.4% vs. the same period in 2023 — Immunefi
Zoltan Vardai10 hours agoFunds hacked in 2024 increased by 15.4% vs. the same period in 2023 — ImmunefiEthereum was the most targeted chain for hackers in 2024, accounting for 85% of the value lost in February.530 Tota
Bitcoin Miner Maker Ebang Narrows First Half Loss To $7 Million, as Covid-19 Hit Demand
Bitcoin Miner Maker Ebang Narrows First Half Loss To $7 Million, as Covid-19 Hit DemandEbang International Holdings Inc., the Chinese maker of bitcoin mining hardware, reported a ne
Tom Mitchelhill2 hours agoEpic Games lays off 830 staff, citing ‘unrealistic’ metaverse ambitions“Spending way more than we earn” — CEO Tim Sweeney blamed job cuts on major structural changes to the company’s
Boba Network Introduces ‘Wagmi’ Options for Developers and Builders
Boba Network Introduces "Wagmi" Options for Developers and Builders Boba Network, an L2 (layer 2) expansion layer for Ethereum, has announced the launch of what it calls “Wa
First-Time Bitcoin Buyers ‘Doubled’ in Square’s Q3 Report
Square processed $148 million in bitcoin sales in the third quarter of 2019. The payments company, founded by Twitter co-founder Jack Dorsey, released its earnings results on Wednes
US Inflation Jumps to 7.5%, CPI Climbs at Fastest Rate in 40 Years, Citizens See Little Wage Growth
US Inflation Jumps to 7.5%, CPI Climbs at Fastest Rate in 40 Years, Citizens See Little Wage Growth Inflation in the United States continues to rise as it climbed at its fastest ra
Bitcoin Final Push? Wave (5) Could Deliver A Spectacular Breakout
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Biggest Movers: DOT, ADA, SHIB Down Under 10%, as WAVES Rallies on Monday
Biggest Movers: DOT, ADA, SHIB Down Under 10%, as WAVES Rallies on Monday Monday’s downturn in crypto markets sent several tokens lower, with cardano, polkadot and shiba inu
US Government Has Seized Cryptocurrencies Worth $1.2 Billion So Far This Year
US Government Has Seized Cryptocurrencies Worth $1.2 Billion So Far This Year The U.S. government has seized cryptocurrencies worth $1.2 billion so far this year
Wolfgang Rückerl4 hours agoHow to improve your Web2 business with blockchainAlthough blockchain has become a mainstream topic in the finance and business worlds for several years now, it’s definitely not too late to j
Crypto Biz: Exchanges face new legal issues, Goldman Sachs’ clients eye crypto, and more
Ana Paula Pereira2 hours agoCrypto Biz: Exchanges face new legal issues, Goldman Sachs’ clients eye crypto, and moreThis week’s Crypto Biz explores crypto exchanges renewed challenges, BlackRock’s Bitcoin ETF inflo
Russia’s Digital Ruble Integrated Into Banking App
Russia’s Digital Ruble Integrated Into Banking App VTB has become the first Russian bank to add the digital ruble to its mobile application. The integration is currently being te