Fun

News Feed - 2023-09-21 09:09:48

Brayden Lindrea8 hours agoBalancer blames ‘social engineering attack’ on DNS provider for website hijackBlockchain security firms SlowMist and CertiK also believe the crypto wallet drainer, Angel Drainer, was involved in the estimated $238,000 exploit.1939 Total views23 Total sharesListen to article 0:00Follow upJoin us on social networksThe team behind Balancer, an Ethereum-based automated market maker, believes a social engineering attack on its DNS service provider was what led to its website’s front end being compromised on Sept. 19, leading to an estimated $238,000 in crypto stolen.


“After investigation, it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs,” the firm explained in a Sept. 20 X post.


Approximately eight hours after the first warning of the attack, Balancer said its decentralized autonomous organization (DAO) was actively addressing the DNS attack and was working to recover the Balancer UI.


At 5:45 pm UTC on Sept. 20, Balancer said it was successful in securing the domain and bringing it back under the control of Balancer DAO. It also confirmed its subdomains “app.balancer.fi” and “balancer.fi” are safe to use again.After investigation it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs.

We are exploring deprecating the .fi TLD in order to move to a more secure registrar and suggest that other projects using the TLD do the same.

[2/2]— Balancer (@Balancer) September 20, 2023


However, it suggested any other projects using the same top-level domain should consider moving to a more secure registrar. 


EuroDNS is a Luxembourg-based domain name registrar and DNS service provider. Cointelegraph has reached out to EuroDNS for comment.Angel Drainer involved


Blockchain security firms SlowMist and CertiK reported that the attacker employed Angel Drainer phishing contracts.


SlowMist said the exploiters attacked Balancer’s website via Border Gateway Protocol hijacking — a process where hackers take control of IP addresses by corrupting internet routing tables.


The hackers then induced users to “approve” and transfer funds via the “transferFrom” function to the Balancer exploiter, it explained.


Related:Breaking: ‘All funds are at risk" — Steadefi exploited in ongoing attack


The hacker, whom SlowMist believes may be related to Russia, has already bridged some of the stolen Ether (ETH) to Bitcoin (BTC) addresses via THORChain before eventually bridging the ETH back to Ethereum, blockchain security firm SlowMist explained on Sept. 20.


SlowMist stated in an earlier post that the hacker transferred about 15 wrapped-Ether (wETH.e) on the Avalanche blockchain.Balancer Hack Update

So far, we have the following findings about the @Balancer exploiter:

1/ The attacker’s fee came from the phishing group #AngelDrainer. In other words, after the attacker (AngelDrainer) attacked the website via BGP hijacking, then induced users to… https://t.co/5g6P2aPEz8 pic.twitter.com/3PInfe9VC1— MistTrack️ (@MistTrack_io) September 20, 2023


Meanwhile, despite Balancer confirming its subdomains on “balancer.fi” to now be safe, the “Deceptive site ahead” warning still appears when attempting to access Balancer’s website.Balancer’s website as of Sept. 20 at 10:22 pm UTC. Source: Balancer.


Cointelegraph reached out to Balancer to confirm the amount of funds lost, but did not receive an immediate response.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Altcoin# Phishing# Hackers# DAO# DNS# Hacks# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingHuman vs. AI: Who is better at crypto investing?Decentralized finance needs alternatives to blockchain

News Feed

Spanish Deputy Suggests Spain Might Attract Kazakhstan Miners
Spanish Deputy Suggests Spain Might Attract Kazakhstan Miners Maria Muñoz, a Spanish deputy from the country’s Congress, wants to position its country as a reliable alt
Marcel Pechman4 hours agoBitcoin price holds steady as S&P 500 plunges to 110-day lowThe S&P 500 dropped to a 110-day low as the market digested what “higher for longer” meant for stocks. Will Bitcoin begin t
Latest Turkey Inflation Rate of 79.6% the Highest in 24 Years — Weakening Lira and Russia-Ukraine War Blamed
Latest Turkey Inflation Rate of 79.6% the Highest in 24 Years — Weakening Lira and Russia-Ukraine War Blamed According to the latest data from the Turkish Statistical Institute,
Mastercard Launches NFTs to Support Emerging Musicians Through Web3 Technologies
Mastercard Launches NFTs to Support Emerging Musicians Through Web3 Technologies According to Mastercard, the payments giant has launched non-fungible tokens (NFTs) that grant acce
Hive Blockchain Secures Order for 6,500 Next-Generation Bitcoin Miners From Canaan
Hive Blockchain Secures Order for 6,500 Next-Generation Bitcoin Miners From Canaan On October 29, the publicly listed firm Canaan announced the mining manufacturer has secured a fo
Cash App Introduces Paid in Bitcoin, BTC Roundup and Lightning Network Services
Cash App Introduces Paid in Bitcoin, BTC Roundup and Lightning Network Services At the Bitcoin 2022 conference in Miami, Block, Inc., formerly Square, Inc., announced three new bit
75 Companies Back Facebook Libra’s Competitor Celo
75 Companies Back Facebook Libra"s Competitor CeloCelo, a competing project to Facebook’s Libra cryptocurrency, has added 50% more new members to its alliance, bringing the to
Crypto Mining Farm Uncovered in Russia’s Oldest Prison
Crypto Mining Farm Uncovered in Russia’s Oldest Prison Russian law enforcement officials are investigating a crypto mining operation at Butyrka, Russia’s oldest prison. A
Multi-Billion Dollar Hedge Fund Goldentree Is Reportedly Adding Bitcoin to Its Balance Sheet
Multi-Billion Dollar Hedge Fund Goldentree Is Reportedly Adding Bitcoin to Its Balance Sheet The hedge fund Goldentree, a firm with $41 billion in assets under m
Tom Blackstone6 hours agoBALD token developer denies rug pull as price falls 85% post-launchThe BALD memecoin collapsed in price as collectors alleged an exit scam, but the developer claims not to have sold any coins.342
How to connect BNB Smart Chain to MetaMask
Marcel Deer12 hours agoHow to connect BNB Smart Chain to MetaMaskLearn how to connect the BNB Smart Chain to your MetaMask wallet and access a world of DApps, tokens and DeFi opportunities.550 Total views6 Total sharesLi
Venezuela’s Asonacrip: Bitcoin Bull Run Could Help Boost Usability of Cryptos Such as Petro
Venezuela"s Asonacrip: Bitcoin Bull Run Could Help Boost Usability of Cryptos Such as Petro The president of the National Association of Cryptocurrencies of Vene