Fun

Io.net responds to GPU metadata attack

News Feed - 2024-04-28 08:04:50

Amaka Nwaokocha12 hours agoIo.net responds to GPU metadata attackThe founder of Io.net will host a livestream on April 28 to demonstrate live cluster creation and calm fear, uncertainty and doubt.11193 Total views4 Total sharesNewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksIo.net, a decentralized physical infrastructure network (DePIN), recently experienced a cybersecurity breach. Malicious users exploited exposed user ID tokens to execute a system query language (SQL) injection attack, which led to unauthorized changes in device metadata within the graphics processing unit (GPU) network.


Husky.io, Io.net’s chief security officer, responded promptly with remedial actions and security upgrades to protect the network. Fortunately, the attack did not compromise the GPUs’ actual hardware, which remains secure due to robust permission layers.


The breach was detected during a surge in write operations to the GPU metadata application programming interface (API), triggering alerts at 1:05 am Pacific Standard Time on April 25.


In response, security measures were reinforced by implementing SQL injection checks on APIs and enhancing the logging of unauthorized attempts. Additionally, a user-specific authentication solution using Auth0 with OKTA was swiftly deployed to address vulnerabilities related to universal authorization tokens.Source: Hushky.io


Unfortunately, this security update coincided with a snapshot of the rewards program, exacerbating an expected decrease in supply-side participants. Consequently, legitimate GPUs that did not restart and update could not access the uptime API, causing a significant drop in active GPU connections from 600,000 to 10,000.


To address these challenges, Ignition Rewards Season 2 has been initiated in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.


The breach stemmed from vulnerabilities introduced while implementing a proof-of-work mechanism to identify counterfeit GPUs. Aggressive security patches before the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.


Related:AI has a hardware crisis: Here’s how decentralized cloud can fix it


The attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. Malicious actors compiled this leaked information into a database weeks before the breach.


The attackers leveraged a valid universal authentication token to access the “worker-API,” enabling changes to device metadata without requiring user-level authentication.


Husky.io emphasized ongoing thorough reviews and penetration tests on public endpoints to detect and neutralize threats early. Despite challenges, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform’s integrity while serving tens of thousands of compute hours per month.


Io.net planned to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services.


Magazine:Real AI use cases in crypto: Crypto-based AI markets, and AI financial analysis# Blockchain# Cryptocurrencies# Security# HacksAdd reaction

News Feed

Norway Mulls Backing Sweden’s Call for Euro Ban on Crypto Mining
Norway Mulls Backing Sweden’s Call for Euro Ban on Crypto Mining The government in Norway is considering ways to limit the environmental impact of cryptocurrency mining and may s
Robert Kiyosaki Says Bitcoin Isn’t the Problem — Calls Former FTX CEO the ‘Bernie Madoff of Crypto’
Robert Kiyosaki Says Bitcoin Isn"t the Problem — Calls Former FTX CEO the "Bernie Madoff of Crypto" The famous author of the best-selling book Rich Dad Poor Dad, Robert Kiyosaki,
Amaka Nwaokocha32 minutes agoBinance conducts 11th LUNC burn, 2.65 billion tokens destroyedThe Terra Classic burn mechanism automatically burns tokens whenever a transaction occurs on the network.334 Total views1 Total s
Spot Bitcoin ETF net inflows drop by 80% as BTC price dips below $69K
Prashant Jha13 hours agoSpot Bitcoin ETF net inflows drop by 80% as BTC price dips below $69KBlackRock’s ETF recorded the highest inflows of $350 million, while Grayscale saw $250 million in outflows.5970 Total views27
Palantir surges 11% after deal to sell AI to US defense, intel agencies
Tom Mitchelhill8 hours agoPalantir surges 11% after deal to sell AI to US defense, intel agenciesPalantir shares closed higher as the intelligence company announced a deal with Microsoft to sell AI services to the US int
The SEC Has Rejected Every Bitcoin ETF. This Firm Thinks It Has a Solution
One company thinks it knows how to get a bitcoin exchange-traded fund (ETF) approved by U.S. regulators. Wilshire Phoenix, a relatively young financial firm in New York, filed to la
Jesse Coghlan7 hours agoCrypto exchange HTX reinstates Bitcoin services after $30M hackJustin Sun said he expects functionality for other cryptocurrencies to gradually be reinstated, with full services returning by next
Kim Dotcom Discusses the Swelling Crypto Economy and His Plans to ‘Accelerate P2P Electronic Cash’
Kim Dotcom Discusses the Swelling Crypto Economy and His Plans to "Accelerate P2P Electronic Cash" This week, news.Bitcoin.com chatted with Kim Dotcom, the found
What’s Next in the Securities Case Against Ripple Over XRP
The Takeaway: Monday is the deadline for an XRP holder to file a response to Ripple’s motion to dismiss his suit against the company. That motion largely sidestepped the plaintiff’s argument that Ripple sold XRP as a
Martin Young3 hours agoNew York prosecutor charges hacker over $9M exploit of Solana-based exchangeA skilled computer security engineer has been charged with wire fraud and money laundering related to an attack on a dece
WATCH: What Are the Main Takeaways From Deribit’s $1.3 Million Flash-Crash?
  Delphi Digital Co-Founder Yan Liberman joined CoinDesk’s Brad Keoun on Monday, Nov. 4, to talk about last week’s flash crash on Deribit, a Netherlands-based cryptocu
Marathon Buys Additional 10,000 Antminers to Become Largest US Bitcoin Miner
Marathon Buys Additional 10,000 Antminers to Become Largest US Bitcoin Miner Nasdaq-listed Marathon Patent Group is buying 10,000 of the more efficient Antminer