Fun

News Feed - 2023-11-16 04:11:22

Tom Blackstone4 hours ago46% of crypto lost from exploits is due to traditional Web2 flaws — ImmunefiThe security platform released a report categorizing Web3 exploits in 2022, concluding that nearly half came from “infrastructure” or centralized elements.1403 Total views9 Total sharesListen to article 0:00NewsJoin us on social networksA new report from blockchain security platform Immunefi suggests that nearly half of all crypto lost from Web3 exploits is due to Web2 security issues such as leaked private keys. The report, released on Nov. 15, looked back at the history of crypto exploits in 2022, categorizing them into different types of vulnerabilities. It concluded that a full 46.48% of the crypto lost from exploits in 2022 was not from smart contract flaws but rather from “infrastructure weaknesses” or issues with the developing firm’s computer systems.Categories of Web3 vulnerabilities. Source: Immunefi


When considering the number of incidents instead of the value of crypto lost, Web2 vulnerabilities were a smaller portion of the total at 26.56%, although they were still the second-largest category.


Immunefi’s report excluded exit scams or other frauds, as well as exploits that occurred solely because of market manipulations. It only considered attacks that occurred because of a security vulnerability. Of these, it found that attacks fall into three broad categories. First, some attacks occur because the smart contract contains a design flaw. Immunefi cited the BNB Chain bridge hack as an example of this type of vulnerability. Second, some attacks occur because, even though the smart contract is designed well, the code implementing the design is flawed. Immunefi cited the Qbit hack as an example of this category.


Finally, a third category of vulnerability is “infrastructure weaknesses,” which Immunefi defined as “the IT-infrastructure on which a smart contract operates—for example virtual machines, private keys, etc.” As an example of this type of vulnerability, Immunefi listed the Ronin bridge hack, which was caused by an attacker gaining control of five out of nine Ronin nodes validator signatures.


Related:Uniswap DAO debate shows devs still struggle to secure cross-chain bridges


Immunefi broke down these categories further into subcategories. When it comes to infrastructure weaknesses, these can be caused by an employee leaking a private key (for example, by transmitting it across an insecure channel), using a weak passphrase for a key vault, problems with tw-factor authentication, DNS hijacking, BGP hijacking, a hot wallet compromise, or using weak encryption methods and storing them in plaintext.


While these infrastructure vulnerabilities caused the greatest amount of losses compared to other categories, the second-largest cause of losses was “cryptographic issues” such as Merkle tree errors, signature replayability and predictable random number generation. Cryptographic issues resulted in 20.58% of the total value of losses in 2022.


Another common vulnerability was “weak/missing access control and/or input validation,” the report stated. This type of flaw resulted in only 4.62% of the losses in terms of value, but it was the largest contributor in terms of the number of incidents, as 30.47% of all incidents were caused by it.# Ethereum# Cybersecurity# DeFiAdd reactionAdd reactionRead moreWSJ debacle fueled US lawmakers’ ill-informed crusade against crypto3 things we might see from crypto as 2023 winds to an endVC Roundup: Private accounts, tokenization and healthcare infrastructure grab investor attention

News Feed

Tom Mitchelhill8 hours agoCrypto miner Hive Digital CEO sees AI working in unison with blockchainDespite the competition between the two sectors, Hive Digital Technologies CEO Aydin Kilic said that blockchain and AI can
Bitcoin, Ethereum Technical Analysis: BTC, ETH Surge to Start the Weekend, Following Friday’s Payrolls
Bitcoin, Ethereum Technical Analysis: BTC, ETH Surge to Start the Weekend, Following Friday’s Payrolls Bitcoin moved closer to the $17,000 level to start the weekend, as traders
Russian Crypto Industry Association Asks Putin to Help With Regulations
Russian Crypto Industry Association Asks Putin to Help With Regulations The organization representing Russia’s crypto and blockchain sector has urged Vladimir Putin to spur regul
Report: Saudi Arabia Exploring Possibility of Implementing Blockchain in Government
Report: Saudi Arabia Exploring Possibility of Implementing Blockchain in Government The Kingdom of Saudi Arabia is looking into the possibility of implementing blockchain technolog
Helen Partz14 hours agoBinance to deactivate some deposit addresses for wallet upgradeCryptocurrency exchange Binance continues upgrading its wallet infrastructure, which requires affected users to get new wallet address
‘Magnificent seven’ stocks shed $2.6T in lead-up to busy earnings week
Martin Young3 hours ago‘Magnificent seven’ stocks shed $2.6T in lead-up to busy earnings weekThe world’s best-performing tech stocks have bled an average $125 billion market cap per day for the past 20 days while c
How To Trade Bitcoin During The US Election, Expert Reveals
Este artículo también está disponible en español. As the United States approaches its presidential election on Tuesday, November 5, 2024, the Bitcoin market is bracing fo
UK Bank Starling Blocks Payments to Crypto Platforms — Claims Crypto Is High Risk, Heavily Used for Criminal Purposes
UK Bank Starling Blocks Payments to Crypto Platforms — Claims Crypto Is High Risk, Heavily Used for Criminal Purposes Starling Bank has informed its customers that the bank no lo
Dinwiddie Leads Crypto Charge, Tokenizes His NBA Contract
Brooklyn Nets point guard Spencer Dinwiddie just announced his plans to tokenize his latest NBA contract to broaden his investment options now. | Credit: Wendell Cruz-USA TODAY Sports
The Highly Anticipated Carbon Social Platform Has Launched
The Highly Anticipated Carbon Social Platform Has Launched press release PRESS RELEASE. The highly anticipated new crypto friendly social platform, Carbon, has launched.
JPMorgan Admits Fraud, Agrees to Billion Dollar Settlement for Illegal Trading
JPMorgan Admits Fraud, Agrees to Billion Dollar Settlement for Illegal TradingJPMorgan Chase has admitted to fraud charges and agreed to settle with the U.S. Department of Justice,
Rich Dad Poor Dad’s Robert Kiyosaki Discusses ‘Best Investment Value Today’
Rich Dad Poor Dad"s Robert Kiyosaki Discusses "Best Investment Value Today" The famous author of the best-selling book Rich Dad Poor Dad, Robert Kiyosaki, has discussed what he bel