Cointime

Download App
iOS & Android

OpenZeppelin Releases Top 10 Blockchain Hacking Techniques of 2022

Cointime Official

OpenZeppelin, a cryptocurrency cybersecurity firm offering an open-source framework for secure smart contract development, released a report of the top 10 blockchain hacking techniques in 2022.

According to the report, the year 2022 witnessed significant growth in blockchain development and the introduction of novel technologies. However, it also resulted in a rise in new hacking methods and exploits, which caused losses exceeding $3.7 billion.

Here is the list of Top 10 blockchain hacking techniques 2022:

10 - Compound-TUSD Integration Issue Retrospective

The double-entry point issue described in Compound-TUSD Integration Issue Retrospective is a perfect example of a bug that subtly breaks one thing and can lead to significant consequences.

9 - The “6.2 L2 DAI Allows Stealing” issue from the StarkNet-DAI-Bridge Smart Contracts Code Assessment

During the code assessment of the StarkNet-DAI-Bridge Smart Contracts audit, a security issue was discovered in a Cairo smart contract. As a relatively low-level language, Cairo has several potential pitfalls, and this issue is a prime example of one such problem.

8 - Avalanche’s $350M Risk Report

The Statemind team’s Avalanche Vulnerability Report: How We Discovered A $350M Risk and Avalanche Vulnerability Report: Technical overview revealed a clever exploit of seemingly innocuous behavior in the precompile which allowed for the sending of native assets and an optional call to the receiver. 

7 - Read-only Reentrancy – a Novel Vulnerability class responsible for 100m+ funds at risk

In a recent talk, blog post, and post-mortem, ChainSecurity demonstrated that reentrancy to view functions can result in devastating consequences. This work uncovered a new vulnerability type; unfortunately, it is not the last time we will see it.

6 - How to Steal $100M from Flawless Smart Contracts

One of the three research pieces by PwningEth in this year’s top ten highlights the difficulty of introducing a precompile that doesn’t break the security assumptions of applications.

5 - Phantom Functions and the Billion-Dollar No-op

This bug is deceptively simple and could have resulted in a loss of billions if not identified.

It serves as a reminder to exercise caution when calling functions that don’t return a value - especially the permit function - as they may not revert when expected.

4 - How did I Save 70000 ETH and Win 6 Million Bug Bounty

This entry in the Top 10 Hacking Techniques of 2022 underscores the importance of considering delegatecalls in smart contract development.

3 - Could Wrapped Tokens Like WETH Be (forced) Insolvent?

This vulnerability allowed an attacker to empty all wrapped token contracts, and not only take over the balance of the wrapped token, but also buy other tokens from the DEX by using the wrapped token as a rubber check.

2 - A vulnerability disclosed in Profanity, an Ethereum vanity address tool

Despite being publicly disclosed, this bug remained relatively unnoticed until it was exploited approximately six months later.

1 - Attacking an Ethereum L2 with Unbridled Optimism

Saurik found a peculiar bug even deeper than precompiles. Discovering an exploit at the node level earns top place for this finding.

Comments

All Comments

Recommended for you

  • BTC Surpasses $74,000

    Market data shows that BTC has surpassed $74,000, currently priced at $74,011.04, with a 24-hour decline of 0.35%. The market is experiencing significant volatility, so please ensure proper risk management.

  • First Windows PCs with NVIDIA Chips Expected to Debut Next Week

    On May 30, Axios reported that sources indicate NVIDIA is set to enter the personal computer market, with the first Windows PCs featuring its chips as the main processors expected to be unveiled next week. NVIDIA and Microsoft will showcase their collaborative results and the initial PCs equipped with these chips at two major industry events: Computex in Taipei and the Microsoft Build Developer Conference. Sources suggest that PCs with NVIDIA chips are likely to appear in Microsoft's Surface brand as well as products from other manufacturers, including Dell. Microsoft is also expected to launch software that will allow users to more easily run AI agents locally on Windows PCs.

  • This Week, US Spot Bitcoin ETFs Experience Net Outflows of $1.4156 Billion

    On May 30, according to Farside monitoring, US spot Bitcoin ETFs experienced cumulative net outflows of $1.4156 billion this week. This includes: IBIT with net outflows of $966.3 million; GBTC with net outflows of $172 million; FBTC with net outflows of $169.1 million; BITB with net outflows of $46.3 million; ARKB with net outflows of $24.7 million; MSBT with net outflows of $1 million; and Grayscale BTC with net outflows of $33 million.

  • US Oil Giant Predicts Higher Oil Prices This Summer

    On May 30, according to CCTV Finance, during a conference hosted by investment firm Bernstein, Chevron CEO Mike Wirth stated that due to the situation in Iran, global crude oil inventories are continuously declining, and oil prices are likely to rise in the next two months. The Financial Times reported that Wirth's remarks reflect widespread concerns: even if the conflicting parties reach a ceasefire agreement, the negative impact of the conflict on energy prices will persist for months. Additionally, CNN reported on the 28th that due to the ongoing geopolitical conflicts in the Middle East, the U.S. Strategic Petroleum Reserve is declining at a rare pace not seen in recent years, and commercial crude oil inventories are also at low levels.

  • S&P 500 Index Set for Rare Nine-Week Winning Streak

    On May 29, hopes that a ceasefire agreement could bring an end to the Middle East conflict have propelled the U.S. stock market towards a rare weekly winning streak record, with a surge in artificial intelligence trading also boosting the market. The S&P 500 index has rebounded nearly 20% from the lows triggered by the war and is poised for its ninth consecutive week of gains, marking the longest winning streak since December 2023. Such a rare occurrence has only happened a few times since 1985. On Friday, the index edged higher, hovering near record highs.

  • Grayscale to Introduce $115 Million HYPE Token Seed Funding for Hyperliquid Staking ETF

    On May 29, Finance Feeds reported that Grayscale is in talks with Hyper Holdings Global LP to sell shares of its proposed Hyperliquid ETF in exchange for approximately 2 million HYPE tokens, valued at about $115 million at current prices, to serve as seed capital before the fund's listing. At the same time, Grayscale has renamed the product to 'Grayscale Hyperliquid Staking ETF', which is set to be listed on NASDAQ under the ticker HYPG. The new staking feature distinguishes it from a traditional spot ETF that solely tracks token prices.

  • BTC Falls Below $73,000

    Market data shows that BTC has fallen below $73,000, currently priced at $72,999.33, with a 24-hour decline of 0.4%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Spot Gold Reaches $4,550/oz, Up 1.20% for the Day

    Spot gold has reached $4,550 per ounce, rising 1.20% for the day.

  • S&P 500 Technology Sector Hits Record High, Up 1.7%

    On May 29, it was reported that the S&P 500 technology sector has reached a historic high, currently up 1.7%.

  • U.S. Stock Indices Open Slightly Higher; Dell Rises Over 30%

    On May 29, U.S. stocks opened with the three major indices slightly higher, with the Dow Jones up 0.18%, the S&P 500 up 0.09%, and the Nasdaq up 0.16%. Dell (DELL.N) surged over 30% as its first-quarter earnings exceeded expectations. Stocks of AI server manufacturers also rose, with Super Micro Computer (SMCI.O) up over 7% and HP (HPQ.N) up over 6%.