Fun

News Feed - 2023-09-21 09:09:48

Brayden Lindrea8 hours agoBalancer blames ‘social engineering attack’ on DNS provider for website hijackBlockchain security firms SlowMist and CertiK also believe the crypto wallet drainer, Angel Drainer, was involved in the estimated $238,000 exploit.1939 Total views23 Total sharesListen to article 0:00Follow upJoin us on social networksThe team behind Balancer, an Ethereum-based automated market maker, believes a social engineering attack on its DNS service provider was what led to its website’s front end being compromised on Sept. 19, leading to an estimated $238,000 in crypto stolen.


“After investigation, it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs,” the firm explained in a Sept. 20 X post.


Approximately eight hours after the first warning of the attack, Balancer said its decentralized autonomous organization (DAO) was actively addressing the DNS attack and was working to recover the Balancer UI.


At 5:45 pm UTC on Sept. 20, Balancer said it was successful in securing the domain and bringing it back under the control of Balancer DAO. It also confirmed its subdomains “app.balancer.fi” and “balancer.fi” are safe to use again.After investigation it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs.

We are exploring deprecating the .fi TLD in order to move to a more secure registrar and suggest that other projects using the TLD do the same.

[2/2]— Balancer (@Balancer) September 20, 2023


However, it suggested any other projects using the same top-level domain should consider moving to a more secure registrar. 


EuroDNS is a Luxembourg-based domain name registrar and DNS service provider. Cointelegraph has reached out to EuroDNS for comment.Angel Drainer involved


Blockchain security firms SlowMist and CertiK reported that the attacker employed Angel Drainer phishing contracts.


SlowMist said the exploiters attacked Balancer’s website via Border Gateway Protocol hijacking — a process where hackers take control of IP addresses by corrupting internet routing tables.


The hackers then induced users to “approve” and transfer funds via the “transferFrom” function to the Balancer exploiter, it explained.


Related:Breaking: ‘All funds are at risk" — Steadefi exploited in ongoing attack


The hacker, whom SlowMist believes may be related to Russia, has already bridged some of the stolen Ether (ETH) to Bitcoin (BTC) addresses via THORChain before eventually bridging the ETH back to Ethereum, blockchain security firm SlowMist explained on Sept. 20.


SlowMist stated in an earlier post that the hacker transferred about 15 wrapped-Ether (wETH.e) on the Avalanche blockchain.Balancer Hack Update

So far, we have the following findings about the @Balancer exploiter:

1/ The attacker’s fee came from the phishing group #AngelDrainer. In other words, after the attacker (AngelDrainer) attacked the website via BGP hijacking, then induced users to… https://t.co/5g6P2aPEz8 pic.twitter.com/3PInfe9VC1— MistTrack️ (@MistTrack_io) September 20, 2023


Meanwhile, despite Balancer confirming its subdomains on “balancer.fi” to now be safe, the “Deceptive site ahead” warning still appears when attempting to access Balancer’s website.Balancer’s website as of Sept. 20 at 10:22 pm UTC. Source: Balancer.


Cointelegraph reached out to Balancer to confirm the amount of funds lost, but did not receive an immediate response.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Altcoin# Phishing# Hackers# DAO# DNS# Hacks# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingHuman vs. AI: Who is better at crypto investing?Decentralized finance needs alternatives to blockchain

News Feed

Bitcoin Trader Robbed During an In-Person Transaction, Kicked Out of Car in Hong Kong
Bitcoin Trader Robbed During an In-Person Transaction, Kicked Out of Car in Hong Kong An unnamed 37-year-old man was a victim of a theft from a gang of robbers w
Biggest Movers: DOGE Hits 1-Week High as Prices Rebound on Tuesday
Biggest Movers: DOGE Hits 1-Week High as Prices Rebound on Tuesday Dogecoin rose to a one-week high on Tuesday, as the meme coin rebounded from recent losses. The token rose by as
Marcel Pechman6 hours agoBitcoin continues to outperform Warren Buffett’s portfolio, and the gap is set to widenSpot and levered Bitcoin positions have outperformed Berkshire Hathaway’s stock performance since early
EU elections 2024: Pro-crypto parties pick up seats amid Green losses
Veronika Rinecker10 hours agoEU elections 2024: Pro-crypto parties pick up seats amid Green lossesThe European elections have caused a stir, but several pro-crypto or crypto-supportive parties have gained seats.560 Total
Tornado Cash developer guilty of money laundering
Zoltan Vardai12 hours agoTornado Cash developer guilty of money launderingPertsev has been under arrest in the Netherlands since August 2022 after the United States government blacklisted Tornado Cash.1770 Total views10
Kazakhstan Allows Registered Crypto Exchanges to Open Accounts at Local Banks
Kazakhstan Allows Registered Crypto Exchanges to Open Accounts at Local Banks Government officials in Kazakhstan have approved regulations that will govern interactions between aut
David Attlee59 minutes agoUS Anti-CBDC bill moves a step closer to passingThe “CBDC Anti-Surveillance State Act,” aimed at preventing the Federal Reserve from issuing a central bank digital currency, has passed the H
Venezuela Passes Law Legalizing Crypto Mining, Forces Miners to Join National Mining Pool
Venezuela Passes Law Legalizing Crypto Mining, Forces Miners to Join National Mining PoolReports say Venezuela has now legalized bitcoin mining following the decree recently issued
Phemex Mobile App: A One-Stop Shop for All Your Crypto Trading Needs
Phemex Mobile App: A One-Stop Shop for All Your Crypto Trading Needs sponsored As a crypto trader, you have to be on your toes. From checking market conditions to tracking your port
Mark Cuban Wants an Expiration Date on Stimulus Checks: Critics Says Proposal Is Right out of a Banana Republic Playbook
Mark Cuban Wants an Expiration Date on Stimulus Checks: Critics Says Proposal Is Right out of a Banana Republic PlaybookU.S. billionaire Mark Cuban wants the next stimulus check to
Protect Yourself With the Sim Encriptados, Travel to More Than 200 Countries, and Communicate With Security
Protect Yourself With the Sim Encriptados, Travel to More Than 200 Countries, and Communicate With Security press release PRESS RELEASE. When people talk about technology, the first
Derek Andersen6 hours agoRep. Tom Emmer proposes to defund SEC’s crusade against cryptoRep. Tom Emmer added a provision in the House GOP spending bill that would block the SEC from using government funds to pursue cryp