Fun

Io.net responds to GPU metadata attack

News Feed - 2024-04-28 08:04:50

Amaka Nwaokocha12 hours agoIo.net responds to GPU metadata attackThe founder of Io.net will host a livestream on April 28 to demonstrate live cluster creation and calm fear, uncertainty and doubt.11193 Total views4 Total sharesNewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksIo.net, a decentralized physical infrastructure network (DePIN), recently experienced a cybersecurity breach. Malicious users exploited exposed user ID tokens to execute a system query language (SQL) injection attack, which led to unauthorized changes in device metadata within the graphics processing unit (GPU) network.


Husky.io, Io.net’s chief security officer, responded promptly with remedial actions and security upgrades to protect the network. Fortunately, the attack did not compromise the GPUs’ actual hardware, which remains secure due to robust permission layers.


The breach was detected during a surge in write operations to the GPU metadata application programming interface (API), triggering alerts at 1:05 am Pacific Standard Time on April 25.


In response, security measures were reinforced by implementing SQL injection checks on APIs and enhancing the logging of unauthorized attempts. Additionally, a user-specific authentication solution using Auth0 with OKTA was swiftly deployed to address vulnerabilities related to universal authorization tokens.Source: Hushky.io


Unfortunately, this security update coincided with a snapshot of the rewards program, exacerbating an expected decrease in supply-side participants. Consequently, legitimate GPUs that did not restart and update could not access the uptime API, causing a significant drop in active GPU connections from 600,000 to 10,000.


To address these challenges, Ignition Rewards Season 2 has been initiated in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.


The breach stemmed from vulnerabilities introduced while implementing a proof-of-work mechanism to identify counterfeit GPUs. Aggressive security patches before the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.


Related:AI has a hardware crisis: Here’s how decentralized cloud can fix it


The attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. Malicious actors compiled this leaked information into a database weeks before the breach.


The attackers leveraged a valid universal authentication token to access the “worker-API,” enabling changes to device metadata without requiring user-level authentication.


Husky.io emphasized ongoing thorough reviews and penetration tests on public endpoints to detect and neutralize threats early. Despite challenges, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform’s integrity while serving tens of thousands of compute hours per month.


Io.net planned to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services.


Magazine:Real AI use cases in crypto: Crypto-based AI markets, and AI financial analysis# Blockchain# Cryptocurrencies# Security# HacksAdd reaction

News Feed

Crypto Exchanges See Bitcoin Reserves Drop by 70% Since Black Thursday’s Market Rout
Crypto Exchanges See Bitcoin Reserves Drop by 70% Since Black Thursday"s Market RoutSince the market carnage on March 12 otherwise known as Black Thursday, the exchange Bitmex has s
Kenyan Central Bank Orders Financial Institutions to Stop Dealing With Two Nigerian Fintechs
Kenyan Central Bank Orders Financial Institutions to Stop Dealing With Two Nigerian Fintechs In a letter addressed to the CEOs of financial institutions, the Central Bank of Kenya
Tokenized asset market could hit $16T on public blockchains — RippleX VP
Gareth Jenkinson14 hours agoTokenized asset market could hit $16T on public blockchains — RippleX VPInstitutional investors, asset managers and banks are racing to bring financial assets on-chain in a market estimated
Paraguay Warns About Growth of Illegal Bitcoin Mining Operations and Effect on Power Stability of the Country
Paraguay Warns About Growth of Illegal Bitcoin Mining Operations and Effect on Power Stability of the Country The growth of illegal bitcoin mining operations could affect the stabi
US Cash Crisis: Withdrawal Limits Spark Bank Run Fear
US Cash Crisis: Withdrawal Limits Spark Bank Run Fear The entire world has been focused on the economy as the coronavirus outbreak has devastated global markets. While stocks, co
Bitcoin maximalism is misguided — Satoshi Nakamoto was a 'Maxi Plus'
Michael Tabone9 hours agoBitcoin maximalism is misguided — Satoshi Nakamoto was a "Maxi Plus"Bitcoin Maximalism is often toxic and off-putting to cryptocurrency newcomers — along with everyone else. But “Bitcoin M
Amaka Nwaokocha14 hours agoAI tool revolutionizes brain tumor treatment by guiding surgeons: StudyAlthough the tool’s accuracy may not match current genetic tests, it can swiftly predict a tumor’s profile.3383 Total
Solana Halts Block Production, Validators Told to Prep for a Restart, Network’s Decentralization Criticized
Solana Halts Block Production, Validators Told to Prep for a Restart, Network"s Decentralization Criticized On June 1, 2022, the Solana network halted block production again as the
Bitcoin All-Time Price High Surpasses $28K, BTC’s Half Trillion Market Cap Now Bigger Than Visa
Bitcoin All-Time Price High Surpasses $28K, BTC"s Half Trillion Market Cap Now Bigger Than Visa Bitcoin markets have been seeing a lot of action this weekend, as
Bitget Wallet tops Nigeria’s app store as OKX exits market
Amaka Nwaokocha11 hours agoBitget Wallet tops Nigeria’s app store as OKX exits marketBitget Wallet’s surge in popularity among Nigerian users highlights its growing appeal in the Web3 space amid evolving digital fina
David Attlee12 hours agoUK publishes plans for stablecoins regulationNon-fiat-backed stablecoins will not be allowed into regulated payment chains.2152 Total views7 Total sharesListen to article 0:00NewsJoin us on social
Bitcoin Rally To Continue If This Level Holds, Is $110,000 The Next Stop?
Este artículo también está disponible en español. After surpassing its $100,000 milestone, Bitcoin (BTC) recorded its largest retrace in the past month before recovering.