• Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
Sunday, May 22, 2022
TheGreatNews.com
  • Home
  • MINDSET
  • WELL BEING
  • POSITIVE NEWS
  • WISDOM
  • PURPOSE
  • NEW TECHNOLOGIES
  • More Topics
    • ENTREPRENEUR
    • GREEN ENERGIES
    • SUCCESS
    • GOOD LIFE
No Result
View All Result
  • Home
  • MINDSET
  • WELL BEING
  • POSITIVE NEWS
  • WISDOM
  • PURPOSE
  • NEW TECHNOLOGIES
  • More Topics
    • ENTREPRENEUR
    • GREEN ENERGIES
    • SUCCESS
    • GOOD LIFE
No Result
View All Result
TheGreatNews.com
No Result
View All Result

BadgerDAO hackers stole $120 million in crypto with a simple but effective attack

in NEW TECHNOLOGIES
Reading Time: 6 mins read
A A
BadgerDAO hackers stole $120 million in crypto with a simple but effective attack
Share Share Share Share Share

On Wednesday night, someone drained funds from multiple cryptocurrency wallets connected to the decentralized finance platform BadgerDAO. According to the blockchain security and data analytics Peckshield, which is working with Badger to investigate the heist, the various tokens stolen in the attack are worth about $120 million.

While the investigation is still ongoing, members of the Badger team have told users that they believe the issue came from someone inserting a malicious script in the UI of their website. For any users who interacted with the site when the script was active, it would intercept Web3 transactions and insert a request to transfer the victim’s tokens to the attacker’s chosen address.

Because of the transparent nature of the transactions, we can see what happened once the attackers pounced. PeckShield points out one transfer that yanked 896 Bitcoin into the attacker’s coffers, worth more than $50 million. According to the team, the malicious code appeared as early as November 10th, as the attackers ran it at seemingly random intervals to avoid detection.

Decentralized finance (or DeFi) systems rely on blockchain technology to let crypto owners perform more typical finance operations like earning interest via lending. BadgerDAO promises users they can “rest easy knowing you never have to give up the private keys for your crypto, you can withdraw anytime you like, and our strategists are working day and night to put your assets to work.” Its protocol allows people who have Bitcoin to “bridge” their cryptocurrency over to the Ethereum platform via its token and take advantage of DeFi opportunities they otherwise might not have access to.

For now, the pause on smart contracts continues in order to prevent further withdrawals. Badger will share further updates as soon as they are available.

— ₿adgerDAO (@BadgerDAO) December 2, 2021

Once Badger became aware of the unauthorized transfers, it paused all smart contracts, essentially freezing its platform, and advised users to decline all transactions to the attacker’s addresses.

Thursday night, the company said it has “retained data forensics experts Chainalysis to explore the full scale of the incident & authorities in both the US & Canada have been informed & Badger is cooperating fully with external investigations as well as proceeding with its own.”

One of the things Badger is investigating is how the attacker apparently accessed Cloudflare via an API key that should’ve been protected by two-factor authentication. While the attack didn’t reveal specific flaws within Blockchain tech itself, it managed to exploit the older “web 2.0” technology that most users need to use to perform transactions. Multi-factor authentication systems protect our accounts against many phishing schemes or bulk credential stuffing attacks. Still, experts have repeatedly warned about targeted phishing attacks that can bypass it, while toolkits to automate the process have been available for years. An FBI notice in 2019 (pdf) called out criminals’ growing capabilities to bypass MFA and suggested changes or training that could make such attacks harder to pull off.

‘one of the most security minded teams in DeFi’

Getting two-factor authentication right can be tricky even within typical financial applications — just ask PayPal. But incidents like this one, or the stolen-and-returned $600 million hijack that Poly Network suffered in August, or the $53 million heist that hit the first DAO ever in 2016, are hopefully enough to expand awareness of security beyond protocols and encryption.

One commenter within Badger’s Discord summed up the situation by saying, “All [the] blockchain / smart contract audits in the world, and people lose 120m to a Cloudflare API leak by a sloppy team where a dude passes a new approval to his contract in the site header – GG – we still have a long way to go.” A member of the team said, “I’m sure we will have some mitigation procedures proposed after this.”

What funds can be recovered and how those affected will be made whole is still unknown. But for anyone living in the world of crypto, blockchain, and Web3 apps, it may ultimately be on them to learn how approvals, signing, and transactions really work and keep an eye on them. Particularly when millions of dollars in holdings can disappear in an instant even while managed by “one of the most security minded teams in DeFi,” as Badger refers to itself.

Image: BadgerDAO

Related articles

Apple display supplier could lose out on large iPhone 14 order after it was reportedly caught cutting corners

Crypto exchange FTX is getting into stock trading

Crypto/security people: we can’t *possibly* run a secure messaging app over the web because everything’s too insecure!

Dapp folks: let’s secure $100m using Javascript served by Cloudflare.

— Matthew Green (@matthew_d_green) December 2, 2021


Credit: Source link

ShareTweetSendPinShare
Previous Post

All 53,000 attendees of Anime NYC urged to get tested after one got Omicron

Next Post

Google will wait until the new year to make more return to office plans

Related Posts

Apple display supplier could lose out on large iPhone 14 order after it was reportedly caught cutting corners

Apple display supplier could lose out on large iPhone 14 order after it was reportedly caught cutting corners

May 21, 2022

Chinese display manufacturer Beijing Oriental Electronics (BOE) could lose out on 30 million display orders for the upcoming iPhone 14 after it reportedly altered the design...

Second country to adopt Bitcoin as national currency is the Central African Republic

Crypto exchange FTX is getting into stock trading

May 21, 2022

Cryptocurrency exchange FTX will soon allow for traditional stock trading alongside its crypto offerings, the company announced in a press release (via The Wall Street Journal)....

You can now ask Google to remove images of under-18s from its search results

Google will temporarily let Match use alternate payment systems ahead of 2023 trial

May 21, 2022

Google has reached an interim agreement with Match Group, the dating app provider behind Tinder, Hinge, and OkCupid, that will allow its apps to remain on...

Google’s Nest Wifi router and remote points are up to $100 off

Google’s Nest Wifi router and remote points are up to $100 off

May 21, 2022

There are many ways to get your weekend started right and, unsurprisingly, one of our favorites here at Verge Deals is with some quality tech deals....

Apple shipped me a 79-pound iPhone repair kit to fix a 1.1-ounce battery

Apple shipped me a 79-pound iPhone repair kit to fix a 1.1-ounce battery

May 21, 2022

Apple must be joking. That’s how I felt again and again as I jumped through hoop after ridiculous hoop to replace the battery in my iPhone...

Next Post
Google will wait until the new year to make more return to office plans

Google will wait until the new year to make more return to office plans

Our 8 Favorite Books in 2021 for Healthy Living

Our 8 Favorite Books in 2021 for Healthy Living

Can’t Keep Up? 4 Best Practices to Simplify Your Small Business

Can’t Keep Up? 4 Best Practices to Simplify Your Small Business

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Weekly Updates

The Horrifying Problem With the Way Web Design and Development Is Taught

The Horrifying Problem With the Way Web Design and Development Is Taught

May 17, 2022
Is Sharing Breast Milk Safe?

Is Sharing Breast Milk Safe?

May 20, 2022
As climate fears mount, people choose to relocate

As climate fears mount, people choose to relocate

May 19, 2022
Why Growth Means Removing Your Mask

Why Growth Means Removing Your Mask

May 22, 2022
Puberty Starts Earlier Than It Used To. No One Knows Why.

Puberty Starts Earlier Than It Used To. No One Knows Why.

May 19, 2022
Blockchain Technology is Revolutionizing the Real Estate Industry

Blockchain Technology is Revolutionizing the Real Estate Industry

May 19, 2022
TheGreatNews.com

This is an online news portal that aims to provide the latest updates about mindset, well being, positive news, wisdom, purpose, new technologies, entrepreneur, green energy, success, good life and stuff like that around the world. Feel free to get in touch with us!

© 2021 - TheGreatNews.com - All rights reserved!

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
No Result
View All Result
  • Home
  • MINDSET
  • WELL BEING
  • POSITIVE NEWS
  • WISDOM
  • PURPOSE
  • NEW TECHNOLOGIES
  • More Topics
    • ENTREPRENEUR
    • GREEN ENERGIES
    • SUCCESS
    • GOOD LIFE

© 2021 - TheGreatNews.com - All rights reserved!