Cointime

Download App
iOS & Android

Fairyproof:Weekly Blockchain Security Watch(October 24 to October 30)

Validated Project

From October 24 to October 30, 2022, all security incidents that have occurred can be categorized into Security Hacks and Rug-pulls.

SECURITY HACKS:

1. A Fake ZKSYNC Twitter Account Posts Fake Message

On Oct 24, a Twitter account @zksync_io paraded as zkSync’s official account to send fake airdrop links.

2. Hacker Exploits QuickSwap by Leveraging Flashloans

On Oct 24, QuickSwap, a DeFi application deployed on Polygon was attacked.

Basically, the hacker leveraged a flashloan and exploited a vulnerability in Curve’s oracle which was used by QuickSwap to launch this attack.

Crypto assets worth around $220,000 were exploited in this incident.

At the time of writing, only Market XYZ was affected and QuickSwap’s contracts were safe. Since the assets that were used to back Market XYZ were provided by QiDAO, no retail users were affected.

Additional Details:

- Attacker’s Address: 0x4206d62305d2815494dcdb759c4E32FCA1D181a0 (Polygon)

- Attack Contract: 0xEb4c67E5BE040068FA477a539341d6aeF081E4Eb (Polygon)

- Hash Value of Attack Transaction:

0xb8efe839da0c89daa763f39f30577dc21937ae351c6f99336a0017e63d387558 (Polygon)

3. Hacker Exploits ULME

On Oct 25, ULME, an application deployed on the BNB chain was attacked.

The root cause was one of its functions lacked validation for a parameter.

The attacker flashloaned a certain quantity of BUSDs, iterated all the addresses that had been authorized to spend their BUSDs, transferred all these addresses’ BUSDs and pumped the ULME’s price, sold the ULMEs, and returned the flashloan.

The hacker eventually exploited around 50646 BUSDs.

Additional Details:

- Attacker’s Address: 0x056c20Ab7E25e4dd7E49568f964d98E415da63D3 (BNB chain)

- Attack Contract: 0x8523C7661850D0Da4D86587ce9674DA23369fF26 (BNB chain)

- Attacked Contract: 0xAE975a25646E6eB859615d0A147B909c13D31FEd (UniverseGoldMountain on BNB chain)

- Hash Value of Attack Transaction:

0xdb9a13bc970b97824e082782e838bdff0b76b30d268f1d66aac507f1d43ff4ed (BNB chain)

4. Hacker Attacks Melody

On Oct 25, a hacker attacked Melody, an application deployed on the BNB chain.

The root cause was its off-chain signature module had a vulnerability. The hacker exploited this vulnerability, bypassed its access control, and generated signatures to steal the SGS and SNS tokens.

Around 2225BNBs were exploited in this incident.

5. Hacker Attacks Bittrex

On Oct 25, a hacker attacked Bittrex, a famous centralized exchange.

Basically, Bittrex’s API was compromised and the hacker used the API to exploit 301 ETHs from the exchange.

6. Hacker Attacks Binance US

On Oct 25, a hacker attacked Binance US, a famous centralized exchange.

Basically, the CEX’s API was compromised and the hacker used the API to exploit 1053 ETHs from the exchange.

The hacker also exploited Bittrex.

7. Hacker Attacks Spookie Finance

On Oct 26, a hacker attacked Spookie Finance, an application deployed on Avalanche.

A Twitter account Mario Paladin claimed that Spookie Finance’s front-end was suspected to be attacked. Users would be tricked to authorize an address beginning with “0xe316Ba” to spend their tokens and all exploited tokens were transferred to “0x5451A25AFf1c14DDEF74D2AF703aaCc5d483782c”. At the time of writing Twitter account, @SpookieFinance had disappeared and the price of GHOST at WAVAX dropped to nearly 0.

8. Hacker Attacks Primordials’ Discord

On Oct 26, Primordials’ Discord server was attacked. Primordials is an NFT project.

9. Hacker Attacks UvToken

On 27 Oct, a hacker attacked UvToken, a wallet application that supports multiple blockchains.

The root cause was it have a vulnerability in its validation module. The hacker exploited 5011 BNBs ($1.5 million) and cashed them out via Tornado Cash on the BNB chain. At the time of writing, UVT’s price dropped by 99%.

Additional Details:

- Attacker’s Address: 0xf3e3ae9a40ac4ae7b17b3465f15ecf228ef4f760 (on BNB chain)

- Attacking Contract: 0x99d4311f0d613c4d0cD0011709Fbd7eC1BF87Be9 (on BNB chain)

- Hash Value of Attack Transaction:

0x54121ed538f27ffee2dbb232f9d9be33e39fdaf34adf993e5e019c00f6afd499 (on BNB chain)

10. Hacker Attacks Team Finance

On 27 Oct, a hacker attacked Team Finance, a DeFi application deployed on Ethereum.

The root cause was its migrate function didn’t validate the “_id” and “params” parameters.

The hacker exploited this vulnerability to migrate the tokens of WTH, CAW, USDC, TSUKA from its V2 pool to its V3 pool illegitimately, manipulated V3 pool’s initialized prices through sqrtPriceX96 and eventually stole crypto assets worth around $14.5 million.

Additional Details:

- Attacker’s Address: 0x161cebB807Ac181d5303A4cCec2FC580CC5899Fd (Ethereum)

- Attacking Contract: 0xCFF07C4e6aa9E2fEc04DAaF5f41d1b10f3adAdF4 (Ethereum)

- Attacked Proxy Contract: 0xE2fE530C047f2d85298b07D9333C05737f1435fB (LockToken on Ethereum)

- Attacked Implementation Contract: 0x48D118C9185e4dBAFE7f3813F8F29EC8a6248359 (on Ethereum)

- Hash Value of Attach Transaction:

0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce (Ethereum)

11. Hacker Attacks VIctor the Fortune

On 27 Oct, a hacker from 0x57c112cf4f1E4e381158735B12aaf8384B60E1cE on the BNB chain had attacked Victor the Fortune, an application deployed on the BNB chain.

The root cause was that its function lacked validation for parameters. The hacker leveraged a flashloan and exploited this vulnerability to attack this project.

Crypto assets worth around $58,000 were exploited in this attack.

12. Hacker Attacks Oxya’s Discord

On Oct 28, Oxya’s Discord server was attacked. Oxya is an NFT project.

13. Hacker Attacks Eden Network

On Oct 29, a hacker from 0x5C95123b1c8d9D8639197C81a829793B469A9f32 on Ethereum had attacked Eden Network, an application deployed on Ethereum.

The root cause was the private key of the project’s deployer was compromised and the hacker hijacked the access control. The hacker deployed a new token named NEDEN and claimed that the Eden Network team should burn 300 million NEDEN to take back the access control.

On Oct 14, a Twitter user Supremacy claimed that Eden Network’s private key was compromised due to a vulnerability in Profanity. However since the access control to the EDEN token had been transferred, this compromise didn’t cause a loss.

14. Hacker Attacks Chimpsons’ Discord

On Oct 30, Chimpsons’ Discord server was attacked. Chimpsons is an NFT project.

Rug-pulls:

1. A6 Rug-pulls

On Oct 24, A6, a token project deployed on the BNB chain was confirmed to be a rug-pull. The team exploited crypto assets worth around $56000 and the token’s price dropped by 91.38%.

The token contract’s address is 0xE77D77309027c71F006DfF5d2F1b76060F4F5F13

2. Mango Inu Rug-pull

On Oct 24, Avraham Eisenberg who exploited Mango Markets claimed on his Twitter account that he exploited $100,000 by rug-pulling Mango Inu and he didn’t do anything wrong.

According to his words, after he deployed a Mango Inu token, around $250,000 was attracted to buy it. However due to some operational issues he only got $100,000 within half an hour.

CONCLUSION-

16 notable security incidents related to security hacks have occurred in the past week. 14 were attacks and 2 were rug-pulls.

10 of 14 attacks were attacks on smart contracts or centralized exchanges and 4 on social media.

It is worth noting that 3 attacks were caused by missing validation for parameters.

A Reminder for Project Teams: Always test thoroughly. Do smart contract audits before deploying smart contracts on-chain. In addition, manage and store private keys with great care.

A Reminder for Crypto Users: Be cautious about suspicious links, emails, websites, and projects launched by teams without established reputations.

It is important for everyone in the crypto community to gain understanding and practice sufficient levels of cybersecurity.

Comments

All Comments

Recommended for you

  • BTC Surpasses $84,000

    Market data shows that BTC has surpassed $84,000, currently priced at $84,035.16, with a 24-hour increase of 1.16%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Zelensky Responds to Trump's Russia-Ukraine Ceasefire Statement: Ukraine Will Agree if Russia Accepts Energy Ceasefire

    According to Axios, Ukrainian President Zelensky stated that Trump's ceasefire statement was also a surprise to him. Ukraine will agree if Russia accepts an energy ceasefire.

  • CryptoBillis Ledger Attacker Deposits $3.89 Million in Crypto Assets to Binance

    On October 11, the attacker of CryptoBillis Ledger deposited approximately $3.89 million in crypto assets to Binance over the past two days, including 3.685 million USDT and 615,000 TRX (about $204,000). This attacker had previously stolen over $90 million in crypto assets. (PeckShieldAlert)

  • KillaXBT: BTC May Surge Before Midterm Elections, Drop After, Historical Probability 75% Bearish

    On October 11, Killa (@KillaXBT), a user on X, shared his perspective that the ideal path for BTC is to rise before the midterm elections, establishing a bullish narrative and surpassing previous highs. Following this, he anticipates a pullback post-election, similar to past cycles, but with higher lows instead of new cycle lows. He believes that if there is a decline before the elections, it is more likely to rise towards $95,000 afterward. Citing data, he noted that nearly $2 billion in long positions were just liquidated, with only three weeks until the midterm elections. Historically, in four midterm elections, three have seen bearish trends emerge one to two months after the elections, giving a probability of 75%. He stated that the worst-case scenario would be a price rebound leading into the elections, followed by a reversal that traps the other side before de-risking. He believes that the narrative for one side has already been liquidated, and the current exposure of shorts is higher than that of longs. The author claims to still hold 10x long positions and longs established at 62.6K and 76.4K, with all positions fully allocated and not closed. This represents his personal trading view and is not an objective event.

  • Argentine Central Bank Indicates Cryptocurrencies May Open to Banks

    On October 11, the Argentine Central Bank stated that during Milei's second term, cryptocurrencies may be opened to banks, lifting a ban that has been in place for four years.

  • Trump: Russia and Ukraine Agree to 'Energy Ceasefire'

    On October 11, U.S. President Trump announced that an 'energy ceasefire' has been reached in the Russia-Ukraine war, effective immediately. Both sides have agreed not to disrupt it.

  • CITIC Securities: Hong Kong Stocks' Fundamentals Expected to Have Bottomed Out

    On October 11, CITIC Securities' research report pointed out that for Hong Kong stocks, although the overseas interest rate hike cycle combined with the restart of AI-driven trading continues to pressure liquidity, the fundamental expectations have bottomed out, and the earnings growth expectations for major broad-based indices have begun to be revised upwards. There is a significant divergence in the adjustment of industry earnings expectations, with some specific sectors seeing upward revisions, while industries related to domestic demand still face downward pressure on earnings expectations. The upcoming third-quarter performance will be an important basis for assessing the progress of recovery. The report advises investors to maintain patience with Hong Kong stocks, expecting that short-term dividend strategies will continue to outperform.

  • Five Major U.S. TV Networks Boycott White House Coverage; DOJ Launches Antitrust Investigation

    On October 11, the U.S. Department of Justice announced it is investigating whether five television networks, including CNN, violated federal antitrust laws. This follows President Trump's ban on reporters from CNN and two other news organizations from entering the White House for coverage, prompting these five major media outlets to collectively boycott and refuse to report on White House activities in solidarity with the banned reporters. The antitrust division of the DOJ is examining CNN, NBC, CBS, Fox News, and ABC. These news organizations have formed a television broadcasting alliance to jointly cover presidential activities and share video footage. The DOJ stated that the members of this television press corps are boycotting White House coverage; such collective boycott actions among business competitors may violate the Sherman Antitrust Act. The antitrust division is investigating to determine if these news organizations have violated antitrust laws. Last month, Trump barred reporters from CNN, MS NOW, and Politico from entering the White House, citing that their coverage was unfavorable to him. Following this, major television networks suspended joint reporting. When CNN was removed from its scheduled coverage of Trump at the United Nations General Assembly, other networks refused to take its place.

  • Zelensky: Will Organize Ukrainian Elections if Putin Agrees to 60-Day Ceasefire

    On October 11, according to ABC News, Ukrainian President Zelensky responded to U.S. President Trump, stating that he would organize Ukrainian elections if Russian President Putin agrees to a 60-day ceasefire.

  • CITIC Securities: Hong Kong Stocks' Fundamentals Expected to Have Reached Bottom

    On October 11, CITIC Securities' research report indicated that for Hong Kong stocks, although the overseas interest rate hike cycle combined with the restart of AI-driven trading continues to pressure liquidity, the fundamental expectations have reached a bottom, and the earnings growth expectations for major broad-based indices have begun to be revised upward. There is a significant divergence in the adjustment of industry earnings expectations, with some specific sectors seeing upward revisions, while earnings expectations in domestic demand-related industries still face downward pressure. The upcoming third-quarter performance will be an important basis for assessing the progress of recovery. The report advises investors to maintain patience with Hong Kong stocks, expecting that short-term dividend strategies will still outperform.