Fun

Liminal blames compromised WazirX devices for hack, claims UI not responsible

News Feed - 2024-07-20 03:07:00

Christopher Roark5 hours agoLiminal blames compromised WazirX devices for hack, claims UI not responsibleCompromised WazirX devices provided “legit transaction details” to Liminal’s network, allowing the attacker to drain the exchange’s funds, the MPC provider claimed.5285 Total views10 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksMultiparty computation (MPC) wallet provider Liminal released a July 19 post-mortem report on the July 18 WazirX hack, claiming that its user interface was not responsible for the attack. According to the report, the hack occurred because three WazirX devices were compromised. 


Liminal also claimed that its multisignature wallet was set up to provide a fourth signature if WazirX provided the other three. This meant the attacker only needed to compromise three devices to perform the attack. The wallet was set up this way at the behest of WazirX, the wallet provider claimed.


In a July 18 social media post, WazirX claimed that its private keys were secured with hardware wallets. WazirX said the attack “stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents.”


According to the Liminal report, one of WazirX’s devices initiated a valid transaction involving the Gala Games (GALA) token. In response, Liminal’s server provided a “safeTxHash,” verifying the transaction’s validity. However, the attacker then replaced this transaction hash with an invalid one, causing the transaction to fail.


In Liminal’s view, the fact that the attacker was able to change this hash implies that WazirX’s device had already been compromised before the transaction was attempted.


The attacker then initiated an additional two transactions: one GALA and one USDT (USDT) transfer. In each of these three transactions, the attacker used a different WazirX admin account, for a total of three accounts used. All three of the transactions failed.Failed WazirX USDT transaction. Source: Liminal, Etherscan


After initiating these three failed transactions, the attacker extracted signatures from the transactions and used them to initiate a new, fourth transaction. The fourth transaction “was crafted in such a way that the fields used to verify policies were using legit transaction details” and “used the Nonce from the failed USDT transaction because that was the latest transaction.”


Because it used these “legit transaction details,” the Liminal server approved the transaction and provided a fourth signature. As a result, the transaction was confirmed on the Ethereum network, resulting in a transfer of funds from the joint multisig wallet to the attacker’s Ethereum account.


Liminal denied that its servers caused incorrect information to be displayed through the Liminal UI. Instead, it claimed that the incorrect information was provided by the attacker, who had compromised WazirX computers. In an answer to the posed question “How did the UI show a different value from the actual payload within the transaction?” Liminal said:“Based on our logs, given that three devices of the victim’s shared transactions sent out malicious payloads to Liminal’s server, we have reason to believe that the local machines were compromised giving the attacker complete access to modify the payloads and display misleading transaction details on the UI.”


Liminal also claimed that its servers were programmed to automatically provide a fourth signature if WazirX admins provided the other three. “Liminal only provides the final signature once the required number of valid signatures are received from the client’s side,” it stated, adding that in this case, “the transaction was authorised and signed by three of our client’s employees.”


The multisig wallet “was deployed by WazirX as per their configuration well before onboarding with Liminal,” and was “imported” into Liminal “per WazirX’s request.”


Related:WazirX breach post-mortem: Dismantling the $230M attack


WazirX’s post claimed that it had implemented “robust security features.” For example, it had required that all transactions be confirmed by four out of five keyholders. Four of these keys belonged to WazirX employees and one to the Liminal team. In addition, it required three of the WazirX keyholders to use hardware wallets. All destination addresses were required to be added to a whitelist ahead of time, WazirX stated, which was “earmarked and facilitated on the interface by Liminal.”


Despite taking all of these precautions, the attacker “appear[s] to have possibly breached such security features, and the theft occurred.” WazirX called the attack a “a force majeure event beyond [its] control.” Even so, it vowed that it was “leaving no stone unturned to locate and recover the funds.”


An estimated $235 million was lost in the WazirX attack. It was the largest centralized exchange hack since the DMM exploit of May 31, which resulted in even greater losses of $305 million.


Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express# Blockchain# Ethereum# Hackers# Cybersecurity# Hacks# RegulationAdd reaction

News Feed

John McAfee’s Body Is Still in a Spanish Morgue a Year After He Passed, His Widow Wants Answers
John McAfee"s Body Is Still in a Spanish Morgue a Year After He Passed, His Widow Wants Answers A year ago on June 23, the anti-virus software tycoon John McAfee was found dead in
Biggest Movers: DOGE, LTC Near 3-Week Lows on Thursday
Biggest Movers: DOGE, LTC Near 3-Week Lows on Thursday Dogecoin was trading close to a three-week low on Thursday, following the release of retail sales figures in the United Stat
A String of 200 ‘Sleeping Bitcoins’ From 2010 Worth $4.27 Million Moved on Friday
A String of 200 "Sleeping Bitcoins" From 2010 Worth $4.27 Million Moved on Friday While the price of bitcoin is holding above the $21K per unit range, four bitcoin block rewards mi
Donald Trump on Crypto: ‘I Don’t Want Other Currencies Coming Out and Hurting the Dollar’
Donald Trump on Crypto: "I Don"t Want Other Currencies Coming Out and Hurting the Dollar" Former U.S. President Donald Trump has commented on the growing popularity of cryptocurren
Cardano Price To $0.77? ADA’s Potential Path To Recovery
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
P2P Bitcoin Exchange Paxful Shuts Down Venezuela Operations to Comply With US Sanctions
P2P Bitcoin Exchange Paxful Shuts Down Venezuela Operations to Comply With US SanctionsPeer-to-peer (P2P) crypto exchange Paxful is shutting down its operations in Venezuela, appare
Zhiyuan Sun8 hours agoTrader swaps 131K stablecoins for $0 during USDR depegAn attempt to withdraw USDR stablecoins amid a liquidity crunch appears to have gone horribly wrong.2153 Total views33 Total sharesListen to art
UK’s FCA Suspends Epayments Service – Over £100M Frozen and Alleged Onecoin Connection
UK"s FCA Suspends Epayments Service - Over £100M Frozen and Alleged Onecoin Connection Epayments, one of the largest payment providers in the U.K., has halted operations after t
Watchdog: Visa–Mastercard ‘duopoly’ spends millions blocking competition
Tristan Greene3 hours agoWatchdog: Visa–Mastercard ‘duopoly’ spends millions blocking competitionAccording to a report, the two companies spent a combined $80 million lobbying against credit card competition acts.
Aave contemplates fee distribution in DeFi shake-up
Amaka Nwaokocha53 minutes agoAave contemplates fee distribution in DeFi shake-upThe fee switch will allow governance to control and adjust fee-related policies based on the platform’s needs and objectives.260 Total vie
How Should Crypto Prepare for Google’s ‘Quantum Supremacy’?
“Quantum supremacy.” The term inspires images of a giant world-brain supercomputer that can count the grains of sand on every beach on Earth. But what does Google’s official claim of supremacy mean and
Commodity Strategist Mike McGlone Says Cryptocurrencies May Be Facing Their First Real Recession
Commodity Strategist Mike McGlone Says Cryptocurrencies May Be Facing Their First Real Recession Bloomberg Intelligence’s senior commodity strategist Mike McGlone has warned