Cointime

Download App
iOS & Android

Most Damaging Methods of Crypto Hacks and Exploits in 2022

Validated Project

47% of crypto funds were stolen by attackers using a diverse range of methods, in 2022

Cryptocurrency hacks and exploits caused $2.8 billion in losses last year, the highest since 2013.

47% of these funds were stolen using a diverse range of hacking and exploitation methods. These include bypassing verification processes, market manipulation, ‘crowd looting’, taking advantage of smart contract errors or loopholes etc.

This suggests that crypto hackers are exploring unconventional ways of stealing from projects and users, to get around improving defenses against the more traditional or standard exploitation methods like access control hacking and flash loan attacks.

Hackers relied on these diverse, unconventional methods for some of the biggest heists of 2022:

  • Wormhole Hack in February 2022 – Hackers pulled off the year’s second largest exploit on Wormhole, the main bridge connecting Solana to other blockchains. Wormhole failed to validate ‘guardian’ accounts, which allowed hackers to bypass verifications with a forged signature and mint $326 million worth of crypto, without needing the equivalent collateral.
  • Nomad Bridge Exploit in August 2022 – The third largest exploit of Nomad was caused by the first crypto ‘crowd looting’ event in August. An insecure configuration in Nomad’s smart contract allowed users to withdraw any amount of funds, without having to prove the transaction’s validity. Information spread after the original attack, and hundreds of users joined in by simply copying, in total looting $190 million.
  • Mango Markets Hack in October 2022 – Decentralized exchange Mango Markets was hacked in October. Avraham Eisenberg, who later admitted to being the hacker, used market manipulation to take advantage of the lack of liquidity. By purchasing and artificially inflating the price of the Mango (MNGO) tokens, the hacker managed to take out large under-collateralized loans from the Mango treasury, stealing $116 million.

The biggest heist of 2022 was caused by an access control hack

Sky Mavis’ Ronin bridge hack in March was by far the largest crypto exploit of the year in terms of losses, with the stolen $625 million single-handedly making up 58.3% of access control hacks in 2022. At the time, Ronin bridge was extremely popular among Axie Infinity players, who used it to transfer their assets between the Ronin chain and the Ethereum network.

The attackers, later determined to be the notorious North Korean hacking group Lazarus, gained access to five private keys. These were used to sign transactions from five of Ronin Network’s nine validator nodes, which allowed the attackers to drain 173,600 ether (ETH) and 25.5 million USD Coin (USDC) from the bridge.

In fact, 65% of funds stolen last year were from the top 5 bridge hacks. This comes amid bridges becoming more important, to connect between a rising number of blockchain networks. Malicious actors have therefore capitalized on the opportunity to target these bridges that investors use to move their funds across the crypto ecosystem.

Crypto hackers used flash loan attack, reentrancy, oracle issue and phishing methods the least

Flash loan attack was the third most popular method for crypto hackers, leading to $0.24 billion in stolen funds that accounted for 8.7% of the losses last year.

This was followed by reentrancy hacks and oracle issue hacks, which attackers used to steal $0.08 billion and $0.05 billion respectively in the same period. The two methods contributed to 2.9% and 1.9% of the year’s losses.

Phishing turned out to be the least favored by crypto hackers. As a standalone method, phishing caused just $0.02 billion in losses, or 0.6% of funds stolen.

Methodology

The study examined how much funds were lost as a result of each hack or exploit method in 2022, based on data from DeFiYield’s REKT Database. For the purpose of this study, the terms ‘hack’, ‘exploit’ and ‘attack’ were used interchangeably.

What are the different methods that attackers use for crypto hacks and exploits?

Access Control: Attackers gain access to cryptocurrency wallets or accounts when a private key is compromised, or gain control over a computer network and its security systems.

Flash Loan Attack: Attackers borrow a large amount of funds, through loans that need to be repaid within the same transaction and require little to no collateral. By manipulating a cryptocurrency’s price on one exchange and reselling it on another, the attacker can then repay the loan and keep the profits.

Reentrancy: Attackers use a malicious smart contract that repeatedly calls the ‘withdraw’ function to drain the cryptocurrency funds from a targeted smart contract, before the latter can update its balance.

Oracle Issue: Attackers gain access to an oracle, which usually supplies price feeds to cryptocurrency protocol, and manipulates the prices provided. This can lead to a smart contract failure, or funds stolen through flash loan attacks.

Phishing: Attackers use social engineering to steal user data, such as login credentials or private key, typically using email to target founders of decentralized finance (DeFi) protocols or funds.

What are cryptocurrency hacks and exploits?

In the crypto industry, hacks and exploits refer to attacks that take advantage of vulnerabilities, flaws, or loopholes in any code or system, in order to steal cryptocurrency coins or tokens. The individuals or groups that carry out hacks and exploits are usually referred to as ‘hackers’. As a result of such actions, cryptocurrency holders and projects suffer losses in their funds, which may or may not be recoverable or returned.

Methods of hacking and exploitation include taking access control, flash loan attacks, reentrancy attacks, oracle issues, phishing and more.

(By Lim Yu Qian)

Read more: https://www.coingecko.com/research/publications/crypto-hacks-exploits-by-method

Get the latest news here: Cointime channel — https://t.me/cointime_en

Comments

All Comments

Recommended for you

  • Trump: Details of US-Iran Agreement to Be Released After Signing on 19th

    On June 16, during the G7 summit in Évian-les-Bains, France, U.S. President Trump stated that the details of the US-Iran agreement will be made public after its official signing on the 19th. (Xinhua News Agency)

  • Iranian Foreign Minister Announces Memorandum Signing on June 19

    On June 15, Iranian Foreign Minister Amir-Abdollahian stated that a meeting between the heads of the Iranian and American negotiating delegations is expected to take place in Switzerland on June 19, during which a memorandum of understanding between Iran and the United States will be signed, followed by the first round of subsequent negotiations. (CCTV International News)

  • U.S. Senior Officials: U.S. and Iran Sign Memorandum of Understanding

    On June 16, a senior U.S. official stated that the United States has signed a memorandum of understanding with Iran. U.S. President Trump and Vice President Pence signed the memorandum, and the Speaker of the Iranian Islamic Consultative Assembly also signed the document. The official also mentioned that the agreement stipulates the immediate opening of the Strait of Hormuz and the lifting of U.S. sanctions on Iran. Traffic in the strait will significantly increase starting immediately.

  • BTC Surpasses $67,000

    Market data shows that BTC has surpassed $67,000, currently priced at $67,197.47, with a 24-hour increase of 4.94%. The market is highly volatile, so please ensure proper risk management.

  • Musk's Wealth Reaches $1.2 Trillion as SpaceX Surpasses TSMC in Valuation

    On June 15, according to the latest global billionaire rankings released by Forbes, Elon Musk, the head of Tesla and SpaceX, has seen his personal wealth soar to an astonishing $1.2 trillion, setting a historical record. He became the world's first 'trillionaire' in the previous trading day. This wealth phenomenon is primarily attributed to the strong performance of his two flagship companies. Recent market data shows that SpaceX (SPCX) has reached a total valuation of $2.28 trillion (approximately $2.28 trillion), surging 8% in a single day, officially surpassing semiconductor giant TSMC (TSM), which has a market value of $2.26 trillion, and entering the top tier of U.S. stock market valuations, ranking sixth. Currently, the top three in the U.S. stock market by total market value are Nvidia ($5.05 trillion), Google, and Apple. SpaceX, with its absolute dominance in the commercial space and Starlink sectors, continues to see its valuation skyrocket, becoming the core pillar of Musk's trillion-dollar fortune.

  • Philadelphia Semiconductor Index Soars 4.7% in Early Trading

    On June 15, the Philadelphia Semiconductor Index opened high, rising by 4.7%. Nvidia's stock price increased by 2.67%, TSMC's stock price rose by 3.76%, Broadcom's stock price went up by 3.37%, Micron Technology's stock price surged by 9.31%, Advanced Micro Devices' stock price climbed by 6.61%, and ASML's stock price gained 1.47%.

  • SpaceX Raises Approximately $85.7 Billion in Initial Public Offering

    On June 15, SpaceX announced that underwriters have fully exercised their over-allotment option in the IPO, purchasing an additional 83.33 million shares. SpaceX has raised approximately $85.7 billion through the IPO.

  • Nasdaq Golden Dragon China Index Rises Over 1%

    On June 15, the Nasdaq Golden Dragon China Index rose over 1%. Canaan Inc. increased by 13.84%, EHang soared by 10.86%, Zai Lab gained 5.59%, Xunlei rose by 5.16%, and Kingsoft Cloud climbed by 5.31%.

  • Anthropic Sued by User for Allegedly Inflating Subscription Usage Limits

    On June 15, according to The Wall Street Journal, a consumer is seeking compensation from Anthropic for its highest-tier subscription plan and has accused the company of exaggerating the usage limits provided. The lawsuit claims that Anthropic misled consumers regarding the usage restrictions of its Max 5x and Max 20x subscription plans. The cheapest Pro subscription for individual users costs between $17 and $20 per month, while the Max 5x costs $100 per month and the Max 20x costs $200 per month. The lawsuit alleges that Anthropic advertised the Max 5x and Max 20x plans as having 5 times and 20 times the usage limits of the Pro plan, respectively, but the actual limits are difficult to determine and appear to be far below the advertised levels. The lawsuit seeks to qualify for a class action on behalf of users who purchased these packages since April of last year.

  • ETH Surpasses $1800

    Market data shows that ETH has surpassed $1800, currently priced at $1804.82, with a 24-hour increase of 8.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.