Fun

News Feed - 2023-10-20 03:10:58

Martin Young2 hours agoEtherHiding: Why hackers may prefer Binance’s BNB Smart ChainAccording to cybersecurity analysts at 0xScope and CertiK, threat actors may prefer using BNB Smart Chain contracts because it’s cheaper and seen as having lower security than Ethereum.1147 Total views9 Total sharesListen to article 0:00Follow upJoin us on social networksDespite the name “EtherHiding,” the new attack vector that hides malicious code in blockchain smart contracts doesn’t have much to do with Ethereum at all, cybersecurity analysts have revealed.


As reported by Cointelegraph on Oct. 16, EtherHiding has been discovered as a new way for bad actors to hide malicious payloads inside smart contracts, with the ultimate goal of distributing malware to unsuspecting victims.


These cybercriminals tend to prefer using Binance’s BNB Smart Chain, it is understood.


Speaking to Cointelegraph, a security researcher from blockchain security firm CertiK, Joe Green, said most of this is due to BNB Smart Chain’s lower costs:“The handling fee of BSC is much cheaper than that of ETH, but the network stability and speed are the same because each update of JavaScript Payload is very cheap, meaning there’s no financial pressure.”


EtherHiding attacks are initiated by hackers compromising WordPress websites and injecting code that pulls partial payloads buried in Binance smart contracts. The website’s front end is replaced by a fake update browser prompt, which, when clicked, pulls the JavaScript payload from the Binance blockchain.


The actors frequently change the malware payloads and update website domains to evade detection. This allows them to continuously serve users fresh malware downloads disguised as browser updates, Green explained.Screenshot of malware updates being deployed in BSC smart contract. Source: Certik 


Another reason, according to security researchers at Web3 analytics firm 0xScope, could be because of increased security-related scrutiny on Ethereum.“While we are unlikely to know the EtherHiding hacker’s true motives for using BNB Smart Chain over other blockchains for their scheme, one possible factor is the increased security-related scrutiny on Ethereum.”


Hackers may face higher risks of discovery by injecting their malicious code using Ethereum due to systems such as Infura’s IP address tracking for MetaMask transactions, they said.


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The 0xScope team told Cointelegraph they recently tracked the money flow between hacker addresses on BNB Smart Chain and Ethereum.


Key addresses were linked to NFT marketplace OpenSea users and Copper custody services, it reported.


Payloads were updated daily across 18 identified hacker domains. This sophistication makes EtherHiding hard to detect and stop, the firm concluded.


Magazine: Should crypto projects ever negotiate with hackers? Probably# Blockchain# Smart Contracts# Ethereum# Malware# Hackers# BSCAdd reactionAdd reactionRead moreHow to build a DApp on EthereumWhy the 2024 Bitcoin halving may play out differently than in the pastExclusive: Hackers selling discounted tokens linked to CoinEx, Stake hacks

News Feed

Regulatory Roundup: Trump’s Cryptocurrency Proposals, IRS Changes Rule, China Quarantines Cash
Regulatory Roundup: Trump"s Cryptocurrency Proposals, IRS Changes Rule, China Quarantines Cash In this roundup, we cover numerous cryptocurrency regulatory developments in the U.
Iran Finds Scapegoat In ‘Easy Victim’ Bitcoin as Officials Shut Down 1,600 Mining Farms
Iran Finds Scapegoat In "Easy Victim" Bitcoin as Officials Shut Down 1,600 Mining Farms As Iran experiences rolling electricity blackouts, the country’s au
Jagjit Singh8 hours agoWhat is QuillBot, and how to use it?QuillBot is an AI-powered writing tool that helps users improve their writing once they simply enter the text and explore the suggestions.485 Total views35 Total
Nvidia delays next gen AI chip as investors issue ‘bubble’ warning
Tristan Greene7 hours agoNvidia delays next gen AI chip as investors issue ‘bubble’ warningAfter briefly breaking the $3 trillion market capitalization mark in June, things have taken a negative turn for the world’
Smart Marketing Token (SMT) Is on a Mission to Help Blockchain Projects Reach Their Goals
Smart Marketing Token (SMT) Is on a Mission to Help Blockchain Projects Reach Their Goals sponsored Blockchain developers can find it very daunting to attract an audience these days
Helen Partz11 hours agoRevolut US to delist ADA, MATIC and SOL in SeptemberCrypto-friendly neobank Revolut has halted purchases of Cardano, Polygon and Solana for U.S. customers, but holding and selling remains available
Martin Young3 hours agoCourt rules in favor of HelbizCoin investors; class action to go aheadA U.S. federal court has upheld claims by HBZ investors that the company acted fraudulently and also asserted that its token vi
CFTC Chairman Confirms Bitcoin, Ether Are Commodities
CFTC Chairman Confirms Bitcoin, Ether Are Commodities The chairman of the U.S. Commodity Futures Trading Commission (CFTC) says he is certain bitcoin and ether are commodities. He
The Genesis of BCH Tokenization: Over 10,000 SLP Tokens Built on Bitcoin Cash
The Genesis of BCH Tokenization: Over 10,000 SLP Tokens Built on Bitcoin CashThis week Bitcoin Cash fans have been discussing the milestone of over 10,000 Simple Ledger Protocol (SL
$200 Billion in Fines: Mega Banks Rack up Penalties From Illegal Activities
$200 Billion in Fines: Mega Banks Rack up Penalties From Illegal Activities Top U.S. banks have racked up almost $200 billion in fines and penalties over the pas
Ciaran LyonsJul 29, 2023US banking advocacy group supports Sen. Warren’s reintroduced crypto billAccording to the Bank Policy Institute, including digital assets in the Anti-Money Laundering framework is essential for
Bill Regulating Crypto Mining Submitted to Russian Parliament
Bill Regulating Crypto Mining Submitted to Russian Parliament A draft law tailored to regulate cryptocurrency mining has been filed with the lower house of Russian parliament, the