Fun

News Feed - 2023-11-16 04:11:22

Tom Blackstone4 hours ago46% of crypto lost from exploits is due to traditional Web2 flaws — ImmunefiThe security platform released a report categorizing Web3 exploits in 2022, concluding that nearly half came from “infrastructure” or centralized elements.1403 Total views9 Total sharesListen to article 0:00NewsJoin us on social networksA new report from blockchain security platform Immunefi suggests that nearly half of all crypto lost from Web3 exploits is due to Web2 security issues such as leaked private keys. The report, released on Nov. 15, looked back at the history of crypto exploits in 2022, categorizing them into different types of vulnerabilities. It concluded that a full 46.48% of the crypto lost from exploits in 2022 was not from smart contract flaws but rather from “infrastructure weaknesses” or issues with the developing firm’s computer systems.Categories of Web3 vulnerabilities. Source: Immunefi


When considering the number of incidents instead of the value of crypto lost, Web2 vulnerabilities were a smaller portion of the total at 26.56%, although they were still the second-largest category.


Immunefi’s report excluded exit scams or other frauds, as well as exploits that occurred solely because of market manipulations. It only considered attacks that occurred because of a security vulnerability. Of these, it found that attacks fall into three broad categories. First, some attacks occur because the smart contract contains a design flaw. Immunefi cited the BNB Chain bridge hack as an example of this type of vulnerability. Second, some attacks occur because, even though the smart contract is designed well, the code implementing the design is flawed. Immunefi cited the Qbit hack as an example of this category.


Finally, a third category of vulnerability is “infrastructure weaknesses,” which Immunefi defined as “the IT-infrastructure on which a smart contract operates—for example virtual machines, private keys, etc.” As an example of this type of vulnerability, Immunefi listed the Ronin bridge hack, which was caused by an attacker gaining control of five out of nine Ronin nodes validator signatures.


Related:Uniswap DAO debate shows devs still struggle to secure cross-chain bridges


Immunefi broke down these categories further into subcategories. When it comes to infrastructure weaknesses, these can be caused by an employee leaking a private key (for example, by transmitting it across an insecure channel), using a weak passphrase for a key vault, problems with tw-factor authentication, DNS hijacking, BGP hijacking, a hot wallet compromise, or using weak encryption methods and storing them in plaintext.


While these infrastructure vulnerabilities caused the greatest amount of losses compared to other categories, the second-largest cause of losses was “cryptographic issues” such as Merkle tree errors, signature replayability and predictable random number generation. Cryptographic issues resulted in 20.58% of the total value of losses in 2022.


Another common vulnerability was “weak/missing access control and/or input validation,” the report stated. This type of flaw resulted in only 4.62% of the losses in terms of value, but it was the largest contributor in terms of the number of incidents, as 30.47% of all incidents were caused by it.# Ethereum# Cybersecurity# DeFiAdd reactionAdd reactionRead moreWSJ debacle fueled US lawmakers’ ill-informed crusade against crypto3 things we might see from crypto as 2023 winds to an endVC Roundup: Private accounts, tokenization and healthcare infrastructure grab investor attention

News Feed

HTC launches no-code game creator for ‘Viverse’ metaverse
Tristan Greene5 hours agoHTC launches no-code game creator for ‘Viverse’ metaverseCreators can build out massively multiplayer games and social spaces using the in-world VR user interface.518 Total views13 Total shar
William Suberg53 minutes agoBitcoin halving can take BTC price to $148K by July 2025 — Pantera CapitalBTC price is right on track when it comes to cycle top and bottom timing, Bitcoin bull Pantera says.607 Total views1
Bitcoin, Ethereum Technical Analysis: BTC Begins the Weekend in Bearish Territory
Bitcoin, Ethereum Technical Analysis: BTC Begins the Weekend in Bearish Territory After a move above $20,000 on Friday, bitcoin was back in the red on Saturday, as prices fell clos
Fidelity Launches Ethereum Index Fund — Sees Client ‘Demand for Exposure to Digital Assets Beyond BTC’
Fidelity Launches Ethereum Index Fund — Sees Client "Demand for Exposure to Digital Assets Beyond BTC" A filing with the U.S. Securities and Exchange Commission has shown that Fi
‘Sleeping Bitcoin’ Spends Slow Down Considerably in 2022, as 92 Decade-Old BTC Worth $1.79 Million Wake Up
"Sleeping Bitcoin" Spends Slow Down Considerably in 2022, as 92 Decade-Old BTC Worth $1.79 Million Wake Up While the price of bitcoin has remained range bound and coasting along ju
XRP Flashes Death Cross From 2017 That Could Trigger 325% Rally To $9
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Dogecoin Whales Go on 470 Million DOGE Buying Spree Amid Bullish Recovery In Major Metrics
Este artículo también está disponible en español. Surprisingly, Dogecoin whales are on a massive buying spree, as new reports show that these large-scale investors have a
Optimism Plans to Enhance L2 Scaling Network With ‘Bedrock’ Upgrade in March 
Optimism Plans to Enhance L2 Scaling Network With ‘Bedrock’ Upgrade in March  The Ethereum scaling network Optimism, which operates as a layer two (L2) network, announced plan
Prashant Jha14 hours agoCanada central bank assesses innovations and challenges of DeFiThe staff note suggested that, although the DeFi ecosystem brings a ton of innovations in the financial sector, the regulatory challe
SIDUS HEROES Receives Investment From Animoca Brands, Alameda Research, Bloktopia, OKEX, Polygon and Master Ventures
SIDUS HEROES Receives Investment From Animoca Brands, Alameda Research, Bloktopia, OKEX, Polygon and Master Ventures press release PRESS RELEASE. February 04th–Sydney, Austra
Metaverse Company Condense Raises $4.5 Million to Accelerate VR Streaming Adoption
Metaverse Company Condense Raises $4.5 Million to Accelerate VR Streaming Adoption Condense, a Bristol, England-based metaverse company that produces technology to allow the stream
Arijit Sarkar10 hours agoAI a powerful tool for devs to change gaming, says former Google gaming headRyan Wyatt deciphers the the possibilities for AI to help gamers and game developers achieve.523 Total views42 Total sh