Posts

Showing posts with the label exploit

Bitcoin Lightning bug allows remote theft of bitcoin via LND nodes

A major bug panicked Bitcoin Lightning users today. Senior Bitcoin developer “Calle” alerted node operators running software older than Lightning Network Daemon (LND) Version 0.18.5 or LITD Version 0.14.1. The vulnerability relates to how LND checks description fields for the settlement of Lightning invoices. Clever hackers figured out a way to manipulate the payment state of such invoices to remotely drain funds. Satoshi Labs co-founder Pavol Rusnak rang a similar alarm bell. As posts gained tens of thousands of impressions, users of the Lightning network spread the message about the imminent threat of theft. Lightning is a mesh network of approximately 5,000 BTC that move faster and cheaper than regular, on-chain BTC. By routing payments through 44,000 public channels connecting over 16,000 nodes, Lightning users sacrifice the full security and decentralization of BTC for speed, thrift, and extra functions. They also expose themselves to Lightning-specific...

OKX DEX suffers exploit resulting in over $430k loss

Image
An X wallet for OKX Web3 confirmed in a post that a deprecated smart contract on OKX DEX had been compromised. While the official post-mortem is yet to come, analysts at SlowMist said in an X post that OKX DEX proxy admin owner’s private key was likely leaked, allowing hackers to take over the protocol and change its functionality. Once the protocol was upgraded with malicious functions, attackers began calling the DEX proxy contract to steal tokens from users, who previously gave the protocol permission to interact with their wallets. SlowMist Security Alert: OKX DEX Proxy Admin Owner's Private Key Suspected to be Leaked According to information from SlowMist Zone, the OKX DEX contract appears to have encountered an issue. After SlowMist's Analysis , it was found that when users exchange, they authorize… — SlowMist (@SlowMist_Team) December 13, 2023 You might also like: Smart contract exploit in TIME token leads to $188k loss According to preliminary...

DeFi exploits and access control hacks cost crypto investors billions in 2022: Report

Cyber criminals used a variety of methods to siphon funds through hacks and exploits in 2022, amounting to over $2.8 billion in losses. Cyber criminals used a variety of novel ways to carry out hacks and exploits in 2022, with over $2.8 billion of cryptocurrency stolen last year. According to a report from CoinGecko using data sourced from DeFiYield’s REKT Database, nearly half of the total crypto stolen in 2022 was fleeced using diverse methods. This includes bypassing verification processes, market manipulation, ‘crowd looting’ as well as smart contract and bridge exploits. The biggest hack of 2022 was carried out through an access control hack. Sky Mavis, the developer behind popular game Axie Infinity, saw its Ronin bridge hacked in March 2022, leading to $625 million being drained from the bridge between the Ronin chain and Ethereum network. It was later revealed that North Korean hacking group Lazarus gained access to five private keys which were used to sign transactions from...