Posts

Showing posts with the label security

Scammers on the rise: three on-chain cybersecurity predictions for 2024 | Opinion

Image
Disclosure: The views and opinions expressed here belong solely to the author and do not represent the views and opinions of crypto.news’ editorial. 2023 has been characterized by bearish conditions flattening markets and a heavy focus on regulation and compliance through the lens of the large-scale collapses and fraud incidents in 2022.  You might also like: Crypto market on Christmas: historical trends and what to expect  However, things are rarely quiet for long in this industry, and change is already in the air. While the question of jail time for Sam Bankman-Fried and Changpeng Zhao may still be outstanding, the drama of the legal battles appears to be largely settled, and the sector is buzzing with anticipation of a new bull market as it looks ahead to the year ahead. An expected spot ETF approval and the upcoming Bitcoin halving are both adding to rising speculation.  While a change in market conditions is good news, it inevitably brings fresh challe...

New Tether security policy sees 41 crypto wallets frozen

Stablecoin issuer startup Tether froze 41 wallets earlier today, with on-chain data showing several of the crypto wallets used the services of Tornado Cash.  Tornado Cash is on Office of Foreign Assets Control’s (OFAC) Specially Designated Nationals (SDN) list. Tether made the move to halt the operations of the wallets with the help of data collected from blockchain intelligence company Chainargos. Ether crypto transactions data tracker Etherscan flagged one of the addresses, stating it was reportedly involved in the infamous Ronin Bridge hack. Collectively, the frozen virtual wallets moved most funds in Staked USDT (STUSDT). Nonetheless, it is not the first time Tether froze wallets linked to warfare, as it ceased the operations of 32 crypto money holders related to the wars in Ukraine and Israel. As reported by CNBC, the wallets held a collective sum of $873,118. In October, Tether stated it had collaborated with 31 agencies in 19 different global jurisdictions, facilitati...

Report reveals reason why wallet users lose crypto

Loading fake wallet apps on search engines is why many people lose coins. According to Bitrace, Telegram often implements malicious backdoors that identify surrogate addresses and cause funds to be sent to malicious addresses. The reason is that the anonymous nature of the blockchain network makes it difficult for ordinary investors and investigators to establish a connection between an on-chain address and a real person. Thereby, they miss the opportunity to freeze losses promptly. “Investors and investigators need to consider how to perceive threats before risky activity occurs, and monitor and promptly recover losses after they occur.” Bitrace Experts note that various search engines are fertile ground for the proliferation of fake websites. Fraudsters use SEO and SEM to promote phishing links online. You might also like: How blockchain security experts investigate hacks | Interview Clipboard hijacking is another classic attack method in which malware takes contro...

Blockaid, a MetaMask security partner, manages to raise $33 million.

Image
In tandem with an impressive $33 million fundraising effort, Blockaid proudly emerges from its shroud of secrecy, boasting a clientele that includes heavyweights such as MetaMask and OpenSea. Blockaid, the pioneering blockchain security startup and close affiliate of the renowned MetaMask cryptocurrency wallet, has successfully secured a whopping $33 million in funding to facilitate the expansion of its cutting-edge technology, engineered to thwart malevolent transactions. The Series A financing round for Blockaid was spearheaded by leading names in the world of venture capital, including the formidable Coinbase investor, Ribbit Capital, and the forward-thinking early-stage VC firm, Variant. Complementing this, Sequoia Capital, Cyberstarts, and Greylock Partners also joined the funding consortium. Breaking the news on October 23, Blockaid announced the end of its covert operations, unveiling its maiden customers: MetaMask, the OpenSea marketplace, the Rainbow wallet, and the Zerion ...

US says crypto mixers threaten national security amid Middle East conflict

The U.S. Treasury Department is currently pushing for new rules that enhance monitoring and reporting capabilities on virtual currency mixers leveraged by illicit actors and terrorist groups. On Oct. 19, the Wall Street Journal reported that President Biden’s administration is set to designate crypto mixers as a threat to national security . The move reportedly comes as the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) steps up vigilance against crypto terror financing citing geopolitical tension between Israel and Hamas. FinCEN published a Notice of Proposed Rule Making (NPRM) detailing its argument for this new legislation that would compel financial institutions to track, report on, and even block transactions linked with suspicious convertible virtual currency (CVC) mixers.  CVC mixing offers a critical service that allows players in the ransomware ecosystem, rogue state actors, and other criminals to fund their unlawful activities and ob...

SlowMist warns about ‘fake deposit’ flaw in Lido Token contract

Blockchain security firm SlowMist says malicious actors have already exploited the vulnerability in the LDO Token contract on several cryptocurrency exchanges. A blockchain security firm, SlowMist, took to X (formerly Twitter) to warn users about a “known operational issue” in the LDO Token contract , saying the vulnerability has already been exploited on trading platforms without naming them. In an X post published on Sept. 10, the blockchain firm cautioned users about the so-called “fake deposit” attack, which allows bad actors to remotely execute a transfer operation where the requested value is larger than what the victim owns. Specifically, when the LDO token contract executes a transfer operation with a quantity exceeding the user's actual holdings, it doesn't trigger the usual transaction rollback. Instead, it merely returns “false” as the outcome rather than indicating a failure. — SlowMist (@SlowMist_Team) September 10, 2023 Y...

Stake co-founder Eddie Craven shares details on $41m heist

Despite looting $41 million in cryptos, Stake co -founder Ed Craven said the hackers did not compromise private user info or access customer funds during the attack. Edward Craven, co -founder of crypto casino Stake, published preliminary findings from a Sept. 4 incident that the Federal Bureau of Investigation (FBI) says was masterminded by North Korean hackers. Craven wrote in a Medium blog post that the attacker targeted Stake’s ETH/BSC hot wallets. The sports betting platform uses these internet-linked wallets for daily transactions and large customer payouts, according to Craven. Stake’s security team stemmed the unauthorized transactions in four hours, but not before hackers siphoned $41 million in cryptocurrencies.  The exploiters withdrew their booty via Ethereum (ETH), Binance Smart Chain, and Polygon (MATIC). Funds from the attack were later bridged to Bitcoin’s blockchain through a basket of addresses. Craven noted that user info and private customer details were ne...

Crypto lawyer about SEC: ‘Problematic to imply all NFTs are securities’

Oscar Franklin Tan, the chief legal officer of NFT platform Enjin, told Cointelegraph that it’s very problematic to imply that all NFTs are securities, as it could hold back creators. The United States Securities and Exchange Commission’s (SEC) first enforcement action on a nonfungible token (NFT) project triggered responses from community members, who pointed out how the decision could be “problematic” for many NFT projects that fit the description and might be next on the SEC’s hit list.  On Aug. 28, the SEC charged the entertainment company Impact Theory for allegedly conducting the sales of unregistered securities . According to the SEC, the NFTs called “Founder’s Keys” were sold as an “investment into the business.” The company allegedly raised around $30 million through the sales. The SEC believes that the NFTs sold were investment contracts and qualified as securities. The filing noted that the firm violated the Securities Act of 1933 for selling the NFTs without registration. ...

PleasrDAO account compromised, losing over $1.2m

On July 19, the PleasrDAO’s head of operations announced a Twitter hack that resulted in the takeover of the organization’s account . Moreover, the head of operations Juan PaDulanto also noticed that the account of another team exec, Jamis, was taken over while he was recovering from a traumatic brain injury. He estimates that people lost over $1.2 million through interactions with the fake site/tweets. Zachxbt, a renowned on-chain sleuth and rug pull survivor, points to the address linked to the malicious activity, 0xCb721B27CA670C806A6aAA9AC9DF6D065d24bCd5. It has reportedly been the epicenter of a staggering $1.2 million (equivalent to 654 ETH) theft. Yesterday my associate in pleasing @_jamiis was hacked, and our @pleasrdao account was taken over and it appears people lost over 1.2m USD by interacting with the fake site/tweets Saddens me that this happens on the tail of Jamis recovering from a traumatic brain injury for the… https://t.co/MlXfzauKfq — jAPEs ...

MultiversX launches on-chain two-factor authentication standard

Blockchain protocol MultiversX has implemented a novel two-factor authentication mechanism to add additional security to its network. Two-factor authentication (2FA) is a tried and tested online security measure, and the technology is now being used as an additional transaction signing measure on MultiversX’s blockchain protocol. MultiversX CEO Beniamin Mincu unpacked the protocol’s new guardian service in conversation with Cointelegraph. The feature makes use of Google Authenticator, Authy, Duo, Microsoft Authenticator or biometrics to provide a second signature for transactions before they are processed on-chain. Mincu outlines the novelty of the approach, which allows users to make use of guarded transactions and accounts to act as a secondary security mechanism: “What the chain sees is a guarded account, if it has the feature activated, and for that account, it requires that any outgoing transaction carry two signatures, one from the account owner and the second one from the guar...

Gnosis launches Hashi bridge aggregator to help prevent hacks

Bridge protocols LayerZero, Celer, Wormhole, LiFi, and others have already committed to implementing the new protocol. Gnosis, the team behind Gnosis Safe multi-sig and Gnosis Chain, has launched a hash oracle aggregator for blockchain bridges, according to an announcement from the company. In a conversation with Cointelegraph, Gnosis CEO Martin Köppelmann stated that the new aggregator should make bridges more secure by requiring more than one bridge to validate a withdrawal before it can be confirmed. Multiple bridge protocols have already committed to integrating with Hashi, including Succinct Labs, DendrETH, ZK Collective, Connext, Celer, LayerZero, Axiom, Wormhole and LI.FI, according to the announcement.  Over $2 billion was stolen from bridges in 2021 and 2022, according to a report by Token Terminal. Bugs in the code have caused some bridge hacks, whereas others have been caused by the attacker taking over a multi-sig governance wallet. According to Köppelmann, Hashi can provi...

More than 280 blockchains at risk of ‘zero-day’ exploits, warns security firm

Dogecoin, Zcash and Litecoin have already patched the “critical” vulnerability, but hundreds of others may not have, risking billions' worth of crypto. 280 or more blockchain networks are estimated to be at risk of “zero-day” exploits that could put at least $25 billion worth of crypto at risk, according to cyber Security firm Halborn. In a Mar. 13 blog, Halborn warned of the vulnerability it dubbed “Rab13s” — adding it has already worked with some blockchains, such as Dogecoin, Litecoin and Zcash, to institute a fix for it. Halborn discovered massive #ZeroDay impacting Dogecoin and 280+ networks including Litecoin and Zcash, putting over $25 Billion of digital assets at risk! ... — Halborn (@HalbornSecurity) March 13, 2023 Halborn was contracted by Dogecoin in March 2022 to conduct a security review of its codebase and found “several critical and exploitable vulnerabilities.” It later determined those same vulnerabilities “affected over 280 other networks” that risked billi...

Developers seek solutions for Web3-related scams from internet browsers

A new suite of tools for Web3 businesses targets the safety and security of transactions, websites and smart contacts to combat exploits. A big concern for users in decentralized finance (DeFi) is its susceptibility to exploits. A report from Privacy Affairs revealed hackers stole $4.3 billion worth of cryptocurrency from January to November 2022 — a 37% increase from the previous year. Such exploits harm the integrity of companies and fuel skeptics from outside of the space in their case against cryptocurrencies. However, in a Feb. 2 announcement from Web3 Builders, the company revealed a suite of tools to combat this issue. The initial browser extension TrustCheck was created to flag Web3- related Scams before users continue to interact with them. This new suite of tools builds on that via a Web3 Builders transaction checker, website checker and smart contract checker. Ricky Pellegrini, the CEO of Web3 Builders, said this is an integral moment for the industry to prove its trust...

What is an NFT whitelist, and how can you join one?

Image
A whitelist is a list of wallet addresses with priority access to an NFT collection before making it available to the general public. Crypto-based scams are constantly sweeping the nonfungible token (NFT) space; therefore, staying updated is the most significant way to prevent both new and existing NFT scams. Other than fraud, intense rivalry for newly minted NFTs may cause prices to rise and transaction fees to skyrocket, making them unaffordable for early supporters.  Nonetheless, these issues have been solved by NFT providers by establishing whitelists or allowlists, giving special privileges and access to a newly minted nonfungible token. Before public minting begins, nonfungible token projects employ allowlists to restrict who can mint NFTs. For example, one can mint NFTs without being concerned about gas wars if they are on the whitelist. This article will discuss the NFT whitelisting concept and process, why NFT whitelists are used, and how to get on an NFT whitelist. What is a...

CFTC declares Ether as a commodity again in court filing

The community is hopeful that the assertion by the CFTC will put to bed claims that staked coins are securities according to the Howey Test. The Commodity Futures Trading Commission (CFTC) has again labeled Ether (ETH) as a commodity in a Dec. 13 court filing — in contrast to statements from chief Rostin Behnam on Nov. 30 suggesting that Bitcoin was the sole cryptocurrency that should be viewed as a commodity. According to the CFTC, as per their filing today, ETH is a commodity . This really should put any Security designation to rest. pic.twitter.com/PkHWredNK4 — Hal Press (@NorthRockLP) December 13, 2022 In its lawsuit against Sam Bankman-Fried, FTX, and sister company Alameda Research, the regulator on multiple occasions referred to Ether, Bitcoin (BTC) and Tether (USDT) "among others" as "commodities" under United States law. “Certain digital assets are “commodities,” including bitcoin (BTC), ether (ETH), tether (USDT) and others, as defined under Section 1a...