Fun

News Feed - 2023-10-20 03:10:58

Martin Young2 hours agoEtherHiding: Why hackers may prefer Binance’s BNB Smart ChainAccording to cybersecurity analysts at 0xScope and CertiK, threat actors may prefer using BNB Smart Chain contracts because it’s cheaper and seen as having lower security than Ethereum.1147 Total views9 Total sharesListen to article 0:00Follow upJoin us on social networksDespite the name “EtherHiding,” the new attack vector that hides malicious code in blockchain smart contracts doesn’t have much to do with Ethereum at all, cybersecurity analysts have revealed.


As reported by Cointelegraph on Oct. 16, EtherHiding has been discovered as a new way for bad actors to hide malicious payloads inside smart contracts, with the ultimate goal of distributing malware to unsuspecting victims.


These cybercriminals tend to prefer using Binance’s BNB Smart Chain, it is understood.


Speaking to Cointelegraph, a security researcher from blockchain security firm CertiK, Joe Green, said most of this is due to BNB Smart Chain’s lower costs:“The handling fee of BSC is much cheaper than that of ETH, but the network stability and speed are the same because each update of JavaScript Payload is very cheap, meaning there’s no financial pressure.”


EtherHiding attacks are initiated by hackers compromising WordPress websites and injecting code that pulls partial payloads buried in Binance smart contracts. The website’s front end is replaced by a fake update browser prompt, which, when clicked, pulls the JavaScript payload from the Binance blockchain.


The actors frequently change the malware payloads and update website domains to evade detection. This allows them to continuously serve users fresh malware downloads disguised as browser updates, Green explained.Screenshot of malware updates being deployed in BSC smart contract. Source: Certik 


Another reason, according to security researchers at Web3 analytics firm 0xScope, could be because of increased security-related scrutiny on Ethereum.“While we are unlikely to know the EtherHiding hacker’s true motives for using BNB Smart Chain over other blockchains for their scheme, one possible factor is the increased security-related scrutiny on Ethereum.”


Hackers may face higher risks of discovery by injecting their malicious code using Ethereum due to systems such as Infura’s IP address tracking for MetaMask transactions, they said.


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The 0xScope team told Cointelegraph they recently tracked the money flow between hacker addresses on BNB Smart Chain and Ethereum.


Key addresses were linked to NFT marketplace OpenSea users and Copper custody services, it reported.


Payloads were updated daily across 18 identified hacker domains. This sophistication makes EtherHiding hard to detect and stop, the firm concluded.


Magazine: Should crypto projects ever negotiate with hackers? Probably# Blockchain# Smart Contracts# Ethereum# Malware# Hackers# BSCAdd reactionAdd reactionRead moreHow to build a DApp on EthereumWhy the 2024 Bitcoin halving may play out differently than in the pastExclusive: Hackers selling discounted tokens linked to CoinEx, Stake hacks

News Feed

China accessing high-level AI chips banned by the US: Report
Savannah Fortis12 hours agoChina accessing high-level AI chips banned by the US: ReportDocuments have surfaced revealing state-linked Chinese entities using Amazon cloud services or similar services to access advanced AI
Brayden Lindrea8 hours agoCoinbase crypto lobbying campaign to focus on 4 swing statesA poll of voters in New Hampshire, Nevada, Ohio and Pennsylvania found 55% would be less likely to vote for an anti-Web3 presidential
Weekly Chart Shows That Dogecoin Price Is Primed To Cross $11 In 2025, Here’s How
Este artículo también está disponible en español. Crypto analyst Dima Jameshas boldly predicted that the Dogecoin price could cross $11 in this new year. He alluded to DO
3 reasons why Bitcoin price struggles to reclaim $64K
Nancy Lubale5 hours ago3 reasons why Bitcoin price struggles to reclaim $64KBitcoin’s tumultuous week continues as data points to further downside in BTC price.2599 Total views5 Total sharesListen to article 0:00Market
Ezra Reguerra10 hours agoCrypto developer commits $2M rug pull fraud to fuel gambling addictionA Redditor described the developer’s gambling addiction excuse as a “weird way to rug,” as projects usually just run aw
Online Sleuths Believe Satoshi Nakamoto’s Bitcoin Stash Is a Blockchain Treasure Hunt Meant to Be Found
Online Sleuths Believe Satoshi Nakamoto’s Bitcoin Stash Is a Blockchain Treasure Hunt Meant to Be Found Over the last twelve years, the cryptocurrency communit
MahaDAO to List MAHA and ARTH With BitMax.io
MahaDAO to List MAHA and ARTH With BitMax.io press release PRESS RELEASE. BitMax.io(BTMX.com), an industry-leading digital asset trading platform built by Wall St
Goldman Sachs Urges Investors to Buy Commodities Now — Expects Equities to Suffer as Inflation Stays Elevated
Goldman Sachs Urges Investors to Buy Commodities Now — Expects Equities to Suffer as Inflation Stays Elevated Global investment bank Goldman Sachs has urged investors to buy comm
Amaka Nwaokocha1 hour agoCoinbase CEO champions DeFi, calls for court action to set legal precedentCoinbase CEO Brian Armstrong cautioned the United States Commodities and Futures Trading Commission (CFTC) to avoid takin
G7 Countries: We Will Ensure Russia Cannot Use Crypto Assets to Evade Sanctions
G7 Countries: We Will Ensure Russia Cannot Use Crypto Assets to Evade Sanctions The Group of Seven (G7) countries issued a joint statement stating that they “will ensure tha
9,404 Crypto Mining Devices Seized by Iranian Authorities Since March
9,404 Crypto Mining Devices Seized by Iranian Authorities Since March Iranian authorities have seized nearly 10,000 illegal cryptocurrency mining devices since March. According to
Bitfarms adopts shareholder rights plan as Riot attempts takeover
Derek Andersen5 hours agoBitfarms adopts shareholder rights plan as Riot attempts takeoverThe plan, which passed after Bitfarms’ shareholder meeting, will complicate Riot’s effort but not necessarily stop it from suc