Fun

Io.net responds to GPU metadata attack

News Feed - 2024-04-28 08:04:50

Amaka Nwaokocha12 hours agoIo.net responds to GPU metadata attackThe founder of Io.net will host a livestream on April 28 to demonstrate live cluster creation and calm fear, uncertainty and doubt.11193 Total views4 Total sharesNewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksIo.net, a decentralized physical infrastructure network (DePIN), recently experienced a cybersecurity breach. Malicious users exploited exposed user ID tokens to execute a system query language (SQL) injection attack, which led to unauthorized changes in device metadata within the graphics processing unit (GPU) network.


Husky.io, Io.net’s chief security officer, responded promptly with remedial actions and security upgrades to protect the network. Fortunately, the attack did not compromise the GPUs’ actual hardware, which remains secure due to robust permission layers.


The breach was detected during a surge in write operations to the GPU metadata application programming interface (API), triggering alerts at 1:05 am Pacific Standard Time on April 25.


In response, security measures were reinforced by implementing SQL injection checks on APIs and enhancing the logging of unauthorized attempts. Additionally, a user-specific authentication solution using Auth0 with OKTA was swiftly deployed to address vulnerabilities related to universal authorization tokens.Source: Hushky.io


Unfortunately, this security update coincided with a snapshot of the rewards program, exacerbating an expected decrease in supply-side participants. Consequently, legitimate GPUs that did not restart and update could not access the uptime API, causing a significant drop in active GPU connections from 600,000 to 10,000.


To address these challenges, Ignition Rewards Season 2 has been initiated in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.


The breach stemmed from vulnerabilities introduced while implementing a proof-of-work mechanism to identify counterfeit GPUs. Aggressive security patches before the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.


Related:AI has a hardware crisis: Here’s how decentralized cloud can fix it


The attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. Malicious actors compiled this leaked information into a database weeks before the breach.


The attackers leveraged a valid universal authentication token to access the “worker-API,” enabling changes to device metadata without requiring user-level authentication.


Husky.io emphasized ongoing thorough reviews and penetration tests on public endpoints to detect and neutralize threats early. Despite challenges, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform’s integrity while serving tens of thousands of compute hours per month.


Io.net planned to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services.


Magazine:Real AI use cases in crypto: Crypto-based AI markets, and AI financial analysis# Blockchain# Cryptocurrencies# Security# HacksAdd reaction

News Feed

What pushed Bitcoin price below $60K? Charts point at potential Mt. Gox repayment
Zoltan Vardai12 hours agoWhat pushed Bitcoin price below $60K? Charts point at potential Mt. Gox repaymentBitcoin has been in a downtrend since the beginning of June, struggling to gain upward momentum despite positive E
Amaka Nwaokocha10 hours agoFTX debtors and UCC clash over asset control in restructuringFTX strongly criticized the UCC’s pursuit of asset control, recommending that debtors allocate nearly $2.6 billion from cash reser
Rise of the Underdog, Securypto Takes off as Investors Scramble To Get on Board
Rise of the Underdog, Securypto Takes off as Investors Scramble To Get on BoardThe time of ICO’s seems behind us and many blockchain projects have fallen off the grid but one
Biggest Movers: WAVES Falls to 1-Month Low, BCH Over 10% Higher on Wednesday
Biggest Movers: WAVES Falls to 1-Month Low, BCH Over 10% Higher on Wednesday WAVES fell to a one-month low during Wednesday’s trading session, as prices dropped for a second
Menlo Ventures launches $100M AI startup accelerator with Anthropic
Tristan Greene4 hours agoMenlo Ventures launches $100M AI startup accelerator with AnthropicDek: The partnership comes as Menlo Ventures continues to build out its AI portfolio.474 Total views5 Total sharesListen to arti
BTC price demands $63K flip as BlackRock CEO calls Bitcoin ‘legitimate’
William Suberg7 hours agoBTC price demands $63K flip as BlackRock CEO calls Bitcoin ‘legitimate’BTC price holds its weekend gains as Larry Fink confirms that he is no longer a Bitcoin “skeptic.”4704 Total views12
Report: Nigeria Debt Management Office’s $48.8 Billion Debt Contravenes the Law Says Expert
Report: Nigeria Debt Management Office"s $48.8 Billion Debt Contravenes the Law Says Expert The Nigerian Debt Management Office (DMO) contravened the law when its borrowings exceed
Canadian Regulator Insists Binance Is Unauthorized, Calls the Crypto Exchange’s Letter to Users ‘Unacceptable’
Canadian Regulator Insists Binance Is Unauthorized, Calls the Crypto Exchange"s Letter to Users "Unacceptable" The Ontario Securities Commission (OSC) claims that Binance has resci
Global Exchange LBank Starts off Brand Update Month With Logo Reveal and Diversity Video
Global Exchange LBank Starts off Brand Update Month With Logo Reveal and Diversity Video press release PRESS RELEASE.INTERNET CITY, DUBAI, Sep. 30, 2022 – Global crypto excha
Consensys Cuts Hundreds of Jobs This Year – About 25% of Its Staff Slashed
Consensys Cuts Hundreds of Jobs This Year - About 25% of Its Staff Slashed Ethereum-based company Consensys has cut hundreds of jobs since January. In its latest action, the US-base
The Bitcoin Treasuries List Exceeds $30 Billion – 29 Companies Hold BTC Reserves
The Bitcoin Treasuries List Exceeds $30 Billion - 29 Companies Hold BTC Reserves More than 1.1 million bitcoin or over $30 billion worth of the crypto asset is h
Arijit Sarkar39 minutes agoWorldcoin rebuts reports of lackluster takeup as Altman cites Japan queuesA video shared by Worldcoin co-founder Sam Altman shows a long queue of people in Japan reportedly waiting to collect $