Fun

Over $1 Billion Ethereum-Based Tokens Vulnerable to ‘Fake Deposit Exploit’

News Feed - 2020-08-28 09:08:25

Over $1 Billion Ethereum-Based Tokens Vulnerable to "Fake Deposit Exploit"


A number of university researchers published a study that demystifies the “fake deposit vulnerability” in Ethereum-based smart contracts. The findings show that over 7,000 tokens worth more than $1 billion built on top of Ethereum are vulnerable to two types of attacks that exploit smart contracts.


Researchers from the University of Queensland, Beijing University of Posts and Telecommunications, Zhejiang University, and Peking University have published a paper that describes a vulnerability held by over 7,000 Ethereum-based tokens.


Essentially, the tokens created have verification methods that are subpar to ERC20 contracts released after 2017. The vulnerability allows the token’s codebase to be manipulated and hackers can easily steal millions of dollars by executing the “fake deposit vulnerability.”


What is worse is that there are more than 25 million smart contracts built using the Ethereum network and the researchers say only “0.36% of them have released their source code according to our dataset.”


Moreover, the paper discusses that the tokens are vulnerable on both decentralized exchanges (dex) and centralized exchanges (cex) because they allow these coins to be swapped “without comprehensive verification.”


The team of researchers leveraged a tool called “Deposafe,” which allows the testing of a large number of ETH-based smart contracts.


“In this work, we have systematically characterized the fake deposit vulnerability in Ethereum. Deposafe, an automated tool is proposed to perform the detection and verification of the vulnerability,” the paper states.


“We demonstrate the efficiency of Deposafe with experiments on a large number of smart contracts. Our observations reveal the prevalence of fake deposit vulnerability in the ERC20 smart contracts,” the university’s scholars wrote.


The investigators found that 7,735 tokens can be influenced by the fake deposit vulnerability using a “Type-I attack.” While “7,716 tokens that are vulnerable to “Type-II attack” with a market cap of over $1 billion.


“The number of holders and transactions would be 695K and 4.6 million respectively,” the paper stresses.


The paper also identifies the dexes that have high active trading on a daily basis and could suffer from the fake deposit attack. Dex platforms listed in the researcher’s paper include Ether Delta, DDEX, and IDEX.


Centralized exchanges (cex) that fall victim to the fake deposit attack could lose substantial amounts of funds.


“If a cex allows these tokens to be traded without comprehensive verification, the financial loss will be tremendous,” the paper highlights.


The authors of the report say that the efforts they have provided can “contribute to bring developer awareness” and hopefully “promote best operational practices across blockchains.”


The listed cex platforms mentioned in the researcher’s study include companies like Kraken, Binance, and Coinbase. ERC20s who are allegedly vulnerable to the fake deposit exploit include BRC token, PWR token, BAT, HPT token, Cloudbric, RPL token, Moviecredits, and more.


What do you think about the fake deposit attack? Let us know what you think about this subject in the comments section below.Banks in Mexico Pose Greater Money Laundering Risk Than Crypto Firms, Says ReportNEWS | 2 hours ago"Bitcoin Will Never Ditch You" Ad Dominates Front Page of Major Hong Kong NewspaperNEWS | 16 hours agoTags in this story1 billion, CEX, crypto, Deposafe, DEX, ERC20, ERC20 Tokens, ETH tokens, ETH-based smart contracts, Ethereum, Fake Deposit, Fake Deposit Exploit, Smart Contracts, subpar verification, Type-I attack, Type-II attack, verification methods, Vulnerability


Image Credits: Shutterstock, Pixabay, Wiki CommonsSpot-markets for Bitcoin, Bitcoin Cash, Ripple, Litecoin and more. Start your trading here.Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.Read disclaimerShow comments

News Feed

Ana Paula Pereira6 hours agoBinance considers legal action against Checkout​.com as partnership endsBinance Connect was shut down on Aug. 16 after Checkout.com discontinued supporting the crypto exchange.1428 Total vie
Savannah Fortis10 hours agoUpbit exchange overtakes Coinbase and OKX in trading volumeIn the month of July, Upbit outperformed both Coinbase and OKX in terms of spot trading volume for the first time.3795 Total views13 T
Ukraine Joins European Blockchain Partnership as Observer
Ukraine Joins European Blockchain Partnership as Observer Ukraine has been granted observer status in the European Blockchain Partnership (EBP). Officials in Kyiv hope the move wil
Savannah Fortis13 hours agoFriend.tech look-alike ‘Alpha’ emerges on Bitcoin networkA new social token network called Alpha has emerged, rivaling the popular Friend.tech platform but built on top of the Bitcoin block
Stablecoin Shuffle — Terra Fiasco Shakes up Fiat-Pegged Crypto Economy, Over $35 Billion Disappears
Stablecoin Shuffle — Terra Fiasco Shakes up Fiat-Pegged Crypto Economy, Over $35 Billion Disappears According to statistics on Friday, May 13, the top stablecoins by market capit
‘Bank of Jamaica Will Roll Out Digital Jamaican Dollar in 2022,’ Says Prime Minister
"Bank of Jamaica Will Roll Out Digital Jamaican Dollar in 2022," Says Prime Minister According to an announcement from Jamaica’s Prime Minister Andrew Holness the Bank of Ja
We Must Expedite the Move From Centralized Services to Viable DeFi Alternatives
We Must Expedite the Move From Centralized Services to Viable DeFi Alternatives There is a reason centralized exchanges have dominated despite being antithetical to crypto’s core
Dvision Network Announces Dvision World 2․0 Release In Beta Mode
Dvision Network Announces Dvision World 2․0 Release In Beta Mode press release PRESS RELEASE.As part of their ongoing development, Dvision Network has announcedthe launch of their
William Suberg13 hours agoBitcoin halving to raise ‘efficient’ BTC mining costs to $30KBitcoin miners may see “severe” economic consequences from BTC price action staying below $30,000 after the 2024 halving, Gla
LUNA Investor Arrested for Knocking on Do Kwon’s Door After Losing $2.4 Million in Terra Crash
LUNA Investor Arrested for Knocking on Do Kwon"s Door After Losing $2.4 Million in Terra Crash A crypto investor has been arrested after knocking on Do Kwon’s door following
Ripple to Participate in the Digital Dollar Project’s CBDC Sandbox Program
Ripple to Participate in the Digital Dollar Project"s CBDC Sandbox Program The non-profit organization promoting the creation of the digital dollar, the Digital Dollar Project, has
Bitcoin Under Siege: Bearish Pressure Keeps Price Below $99,575
Este artículo también está disponible en español. Bitcoinis under intense bearish pressure as it struggles to reclaim the $99,575 mark, a key resistance level that has pr