Fun

News Feed - 2023-09-21 09:09:48

Brayden Lindrea8 hours agoBalancer blames ‘social engineering attack’ on DNS provider for website hijackBlockchain security firms SlowMist and CertiK also believe the crypto wallet drainer, Angel Drainer, was involved in the estimated $238,000 exploit.1939 Total views23 Total sharesListen to article 0:00Follow upJoin us on social networksThe team behind Balancer, an Ethereum-based automated market maker, believes a social engineering attack on its DNS service provider was what led to its website’s front end being compromised on Sept. 19, leading to an estimated $238,000 in crypto stolen.


“After investigation, it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs,” the firm explained in a Sept. 20 X post.


Approximately eight hours after the first warning of the attack, Balancer said its decentralized autonomous organization (DAO) was actively addressing the DNS attack and was working to recover the Balancer UI.


At 5:45 pm UTC on Sept. 20, Balancer said it was successful in securing the domain and bringing it back under the control of Balancer DAO. It also confirmed its subdomains “app.balancer.fi” and “balancer.fi” are safe to use again.After investigation it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs.

We are exploring deprecating the .fi TLD in order to move to a more secure registrar and suggest that other projects using the TLD do the same.

[2/2]— Balancer (@Balancer) September 20, 2023


However, it suggested any other projects using the same top-level domain should consider moving to a more secure registrar. 


EuroDNS is a Luxembourg-based domain name registrar and DNS service provider. Cointelegraph has reached out to EuroDNS for comment.Angel Drainer involved


Blockchain security firms SlowMist and CertiK reported that the attacker employed Angel Drainer phishing contracts.


SlowMist said the exploiters attacked Balancer’s website via Border Gateway Protocol hijacking — a process where hackers take control of IP addresses by corrupting internet routing tables.


The hackers then induced users to “approve” and transfer funds via the “transferFrom” function to the Balancer exploiter, it explained.


Related:Breaking: ‘All funds are at risk" — Steadefi exploited in ongoing attack


The hacker, whom SlowMist believes may be related to Russia, has already bridged some of the stolen Ether (ETH) to Bitcoin (BTC) addresses via THORChain before eventually bridging the ETH back to Ethereum, blockchain security firm SlowMist explained on Sept. 20.


SlowMist stated in an earlier post that the hacker transferred about 15 wrapped-Ether (wETH.e) on the Avalanche blockchain.Balancer Hack Update

So far, we have the following findings about the @Balancer exploiter:

1/ The attacker’s fee came from the phishing group #AngelDrainer. In other words, after the attacker (AngelDrainer) attacked the website via BGP hijacking, then induced users to… https://t.co/5g6P2aPEz8 pic.twitter.com/3PInfe9VC1— MistTrack️ (@MistTrack_io) September 20, 2023


Meanwhile, despite Balancer confirming its subdomains on “balancer.fi” to now be safe, the “Deceptive site ahead” warning still appears when attempting to access Balancer’s website.Balancer’s website as of Sept. 20 at 10:22 pm UTC. Source: Balancer.


Cointelegraph reached out to Balancer to confirm the amount of funds lost, but did not receive an immediate response.


Magazine:$3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story# Altcoin# Phishing# Hackers# DAO# DNS# Hacks# DeFiAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingHuman vs. AI: Who is better at crypto investing?Decentralized finance needs alternatives to blockchain

News Feed

Adshares Establishes Premium Partnership With Sandbox
Adshares Establishes Premium Partnership With Sandbox press release PRESS RELEASE.Adshares (ADS) is putting another stake in Metaverse’s advertising territory through a partn
Will the Real Polygon Please Stand Up — Spammers Wrongly Post Coin Drops on Video Game-Related Feed
Will the Real Polygon Please Stand Up — Spammers Wrongly Post Coin Drops on Video Game-Related Feed In a strange twist of fate, two companies named Polygon are
Blockchain gaming investments reached nearly $1B in April
Tristan Greene3 hours agoBlockchain gaming investments reached nearly $1B in AprilThe investment figures come alongside a record high 2.9 million daily unique active wallets (dUAW) for the month.430 Total views25 Total s
New York Giants’ Saquon Barkley Plans to Convert Endorsement Revenue to Bitcoin
New York Giants" Saquon Barkley Plans to Convert Endorsement Revenue to Bitcoin Another pro athlete in the National Football League (NFL) is planning to convert
Microsoft Reportedly Shutting Down Industrial Metaverse Focused Group
Microsoft Reportedly Shutting Down Industrial Metaverse Focused Group Software giant Microsoft is shutting down one of its most significant groups dedicated to the development and
Twitter Sues Elon Musk to Enforce $44 Billion Buyout Deal — Insists Breach Allegations Lack Merit
Twitter Sues Elon Musk to Enforce $44 Billion Buyout Deal — Insists Breach Allegations Lack Merit Twitter Inc. has filed a lawsuit against Elon Musk to force the Tesla CEO to go
Serbian National Arrested and Extradited to the US for His Role in a $70M Crypto Mining Case
Serbian National Arrested and Extradited to the US for His Role in a $70M Crypto Mining Case A Serbian national has been extradited to the United States to face
Global Markets, Bitcoin Defy Expectations After Fed’s Hawkish Taper Plan Announcement
Global Markets, Bitcoin Defy Expectations After Fed"s Hawkish Taper Plan Announcement Global markets have defied predictions as the U.S. Federal Reserve and several central banks w
Tom Mitchelhill7 hours agoApeFest attendees report ‘extreme pain’ and vision problems after eventSeveral attendees of Yuga Labs’ ApeFest event in Hong Kong reported eye pain and vision loss, claiming they were expo
Indiana vows outage-free energy for crypto miners, data centers
Arijit Sarkar13 hours agoIndiana vows outage-free energy for crypto miners, data centersIndiana plans to become a hub for the data center and crypto mining industries by promising uninterrupted, low-cost energy.3752 Tota
Some Indian Banks Ignore Supreme Court Verdict on Cryptocurrency, RBI Urged to Rectify
Some Indian Banks Ignore Supreme Court Verdict on Cryptocurrency, RBI Urged to Rectify Despite the Indian supreme court quashing the central bank’s ban on crypto, some majo
Nearly $13 Billion in Sales: Breaking Down 5 NFT Collections by Sales Volume 
Nearly $13 Billion in Sales: Breaking Down 5 NFT Collections by Sales Volume  Non-fungible token (NFT) assets have existed since at least 2014, but interest in them began to rise