Fun

Io.net responds to GPU metadata attack

News Feed - 2024-04-28 08:04:50

Amaka Nwaokocha12 hours agoIo.net responds to GPU metadata attackThe founder of Io.net will host a livestream on April 28 to demonstrate live cluster creation and calm fear, uncertainty and doubt.11193 Total views4 Total sharesNewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksIo.net, a decentralized physical infrastructure network (DePIN), recently experienced a cybersecurity breach. Malicious users exploited exposed user ID tokens to execute a system query language (SQL) injection attack, which led to unauthorized changes in device metadata within the graphics processing unit (GPU) network.


Husky.io, Io.net’s chief security officer, responded promptly with remedial actions and security upgrades to protect the network. Fortunately, the attack did not compromise the GPUs’ actual hardware, which remains secure due to robust permission layers.


The breach was detected during a surge in write operations to the GPU metadata application programming interface (API), triggering alerts at 1:05 am Pacific Standard Time on April 25.


In response, security measures were reinforced by implementing SQL injection checks on APIs and enhancing the logging of unauthorized attempts. Additionally, a user-specific authentication solution using Auth0 with OKTA was swiftly deployed to address vulnerabilities related to universal authorization tokens.Source: Hushky.io


Unfortunately, this security update coincided with a snapshot of the rewards program, exacerbating an expected decrease in supply-side participants. Consequently, legitimate GPUs that did not restart and update could not access the uptime API, causing a significant drop in active GPU connections from 600,000 to 10,000.


To address these challenges, Ignition Rewards Season 2 has been initiated in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.


The breach stemmed from vulnerabilities introduced while implementing a proof-of-work mechanism to identify counterfeit GPUs. Aggressive security patches before the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.


Related:AI has a hardware crisis: Here’s how decentralized cloud can fix it


The attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. Malicious actors compiled this leaked information into a database weeks before the breach.


The attackers leveraged a valid universal authentication token to access the “worker-API,” enabling changes to device metadata without requiring user-level authentication.


Husky.io emphasized ongoing thorough reviews and penetration tests on public endpoints to detect and neutralize threats early. Despite challenges, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform’s integrity while serving tens of thousands of compute hours per month.


Io.net planned to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services.


Magazine:Real AI use cases in crypto: Crypto-based AI markets, and AI financial analysis# Blockchain# Cryptocurrencies# Security# HacksAdd reaction

News Feed

KyberSwap hacker bridges $2.5M in stolen funds to Ethereum
Ezra Reguerra12 hours agoKyberSwap hacker bridges $2.5M in stolen funds to EthereumA wallet address linked to the KyberSwap exploiter was seen transferring $2.5 million from Arbitrum to Ethereum.1541 Total views4 Total s
Notorious ‘jaredfromsubway’ MEV bot returns with new attacks
Martin Young5 hours agoNotorious ‘jaredfromsubway’ MEV bot returns with new attacksThe “jaredfromsubway.eth” MEV bot appears to have relaunched with a better arsenal for carrying out attacks.2364 Total views3 Tot
Stablecoin Blues: $3 Billion Erased From the Dollar-Pegged Token Economy, HUSD Depegs, USDC Supply Drops 10%
Stablecoin Blues: $3 Billion Erased From the Dollar-Pegged Token Economy, HUSD Depegs, USDC Supply Drops 10% Over three billion in value was erased from the stablecoin economy duri
AMC and Sony to Gift NFTs to ‘Spider-Man: No Way Home’ Advance Opening Ticket Buyers
AMC and Sony to Gift NFTs to "Spider-Man: No Way Home" Advance Opening Ticket Buyers The theatre chain AMC and Sony Pictures are offering NFT’s as a present for early buyers
Bitcoin Will Be Legal Tender in 2 More Countries This Year, El Salvador’s President Predicts
Bitcoin Will Be Legal Tender in 2 More Countries This Year, El Salvador"s President Predicts El Salvador’s president has made six predictions relating to bitcoin for 2022. H
Between days in court, Donald Trump will meet crypto enthusiasts for NFT dinner
Turner Wright6 hours agoBetween days in court, Donald Trump will meet crypto enthusiasts for NFT dinnerAnyone who spent at least $4,653 on Trump’s “Mugshot” NFTs will be able to have dinner with the former presiden
Ezra Reguerra40 minutes agoHalf of stolen NFTs are sold within 3 hours: PeckShieldPeckShield reports that $2.27 million of NFTs were stolen in June, recording the lowest monthly figure for stolen NFTs in 2023.636 Total v
Chinese police capture StarkNet airdrop identity forger: Report
Zoltan Vardai13 hours agoChinese police capture StarkNet airdrop identity forger: ReportThe suspect has claimed over 40,000 STRK tokens that belonged to victims before converting them to over 90,000 USDT.4704 Total views
Russia to Track Crypto Transactions With Help From Sberbank-Owned Company
Russia to Track Crypto Transactions With Help From Sberbank-Owned Company The Federal Financial Monitoring Service of Russia is going to start tracking cryptocur
Tron Founder Justin Sun Purchases Joker Tpunk NFT for $10.5 Million
Tron Founder Justin Sun Purchases Joker Tpunk NFT for $10.5 Million Justin Sun, founder of Tron, a smart contract-enabled cryptocurrency, announced he purchased an NFT avatar for $
Binance executive tracked to Kenya, extradition underway
Amaka Nwaokocha4 minutes agoBinance executive tracked to Kenya, extradition underwayThe Nigerian government is now collaborating with Interpol and the Kenyan Police to bring Arjarwalla to the country to face charges leve
Amaka Nwaokocha1 hour agoCelsius Network approved to convert altcoins into BTC or ETHThe liquidations will pave the way for the distribution of the funds to creditors in the near future.1042 Total viewsListen to article