Cointime

Download App
iOS & Android

Weekly Blockchain Security Watch (November 28 to Dec 4)

Validated Project

From November 28 to December 4, 2022, all security incidents that have occurred are all Security Hacks.

SECURITY HACKS:

1. Hacker Attacks Prometheus

On Nov 28, Prometheus, a dApp deployed on the BNB chain was attacked.

In this incident, the hacker withdrew 467,398 PHI from the project’s OTC contract and exchanged them to 124,73 BNBs.

The Prometheus team got back 112.08 BNBs and kept them in a multi sig (0x69A03128a7cb580553acf1cf287d4A5Ce0A01c1F).

The hacker exploited 12.65 BNBs (worth around US $3,654.5) in this incident.

At the time of writing, the project’s gPHI and dPHI supply had not been exploited, and all the contracts had been paused, except the dividends pool.

Additional Details:

- Attacker’s Address: 0xc7233627c65f0dd1465938212a3adaa5dea50bf6 (BNB chain)

- Hash Value of Attack Transaction:

0x15472327df1fdace59c14eba5f4069ffb65c71c5f38f00355da990b68121d160

2. Hacker Attacks Shamanzs Discord Server

On Nov 28, a hacker had attacked Shamanzs’ discord server. Shamanzs is an NFT project deployed on Ethereum.

3. Hacker Leverages Flash-loan to Attack Seaman

On Nov 29, a hacker had attacked Seaman, a dApp deployed on the BNB chain.

The root cause was that its tokenomics design would result in price manipulation.

The attacker flash-loaned 500,000 BUSDs and exchanged them to GVCs. The hacker then called Seaman’s transfer function to transfer a small number of SEAMAN tokens and triggered the SEAMAN tokens to be exchanged to GVCs. This process would call the _splitlpToken() function to distribute the GVCs to lpUser and reduce the number of GVCs in the BUSD-GVC trading pair thus increasing the GVC’s price.

The hacker repeated the process and eventually exploited 7781 BUSDs worth US $7781 in this incident.

Additional Details:

- Attacker’s Address: 0x49fac69c51a303b4597d09c18bc5e7bf38ecf89c (BNB chain)

- Attacked Contract: 0xDB95FBc5532eEb43DeEd56c8dc050c930e31017e(GVC Token on BNB chain)

4. Hacker Attacks SmallBros Discord Server

On Dec 1, a hacker had attacked SmallBros’ discord server. SmallBros is an NFT project deployed on Ethereum.

5. Hacker Attacks Brainless Spikes Discord Server

On Dec 1, a hacker had attacked Brainless Spikes’ discord server. Brainless Spikes is an NFT project deployed on Ethereum.

6. Hacker Attacks Ankr

On Dec 2, a hacker attacked Ankr, a dApp deployed on the BNB chain.

The root cause was very likely that the Ankr Deployer’s private key was compromised.

The attacker exploited crypto assets worth around US $5 million in this incident.

For more details about this incident refer to:

https://twitter.com/FairyproofT/status/1598535802463875072?s=20&t=G7OlCC57pHNU-Bsgdjcb7w

Additional Details:

- Attacker’s Address: 0xf3a465C9fA6663fF50794C698F600Faa4b05c777 (BNB chain)

- Malicious aBNBc Contract: 0xd99955B615EF66F9Ee1430B02538a2eA52b14Ce4 (BNB chain)

- Ankr Deployer: 0x2Ffc59d32A524611Bb891cab759112A51f9e33C0 (BNB chain)

- Attacked Contract: 0xE85aFCcDaFBE7F2B096f268e31ccE3da8dA2990A (aBNBc on BNB chain)

- Initiator of Attack Transaction: 0x71699d5BD28F5C834eEe8E365848df056915Baa6 (BNB chain)

- Hash Value of Attack Transaction:

0xd07b210b872bc952b9f2250d8272a789f89a2f7a3621112fdd73addd7bdb080b (BNB chain)

CONCLUSION-

6 notable security incidents have occurred in the past week. Four out of them were attacks on smart contracts and two were attacks on social media accounts.

A Reminder for Project Teams: Always test thoroughly. Do smart contract audits before deploying smart contracts on-chain. In addition, manage and store private keys with great care.

A Reminder for Crypto Users: Be cautious about suspicious links, emails, websites, and projects launched by teams without established reputations.

It is important for everyone in the crypto community to gain understanding and practice sufficient levels of cybersecurity.

To stay updated on notable security incidents in the world of Web3.0, subscribe to our newsletter: https://fairyproof.substack.com/For a better understanding of all things Web3.0: https://medium.com/@FairyproofT

Looking to strengthen the security of your project or looking for an audit? Contact us at

Comments

All Comments

Recommended for you

  • ETH breaks through $3100

    the market shows ETH breaking through $3100, currently at $3100.29, with a 24-hour increase of 1.74%. The market is highly volatile, please manage your risks accordingly.

  • BTC breaks through $91,000

     the market shows BTC breaking through $91,000, currently at $91,011.99, with a 24-hour increase of 1.78%. The market is highly volatile, please manage your risk accordingly.

  • BTC breaks $90,000

    market shows BTC breaking through $90,000, currently at $90,009.99, the 24-hour decline narrowed to 0.57%, market volatility is high, please manage your risk properly.

  • The US spot Bitcoin ETF saw a net inflow of $54.8 million yesterday.

    according to data monitored by Farside Investors, the US spot Bitcoin ETF had a net inflow of 54.8 million USD yesterday.

  • The US spot Ethereum ETF saw a net outflow of $75.2 million yesterday.

     according to data monitored by Farside Investors, the US spot Ethereum ETF had a net outflow of 75.2 million USD yesterday.

  • Economists expect the Federal Reserve to cut interest rates in December, with two more cuts possible in 2026.

    according to economists surveyed, Federal Reserve officials are expected to vote next week to cut interest rates again to guard against the rising risk of a sharp deterioration in the labor market. The median of respondents shows that the Fed is expected to implement two more 25 basis point rate cuts within the year starting from March 2026. Next week's rate cut will continue the momentum of rate cuts from the policy meetings in September and October. A considerable majority also expect Fed officials to once again reiterate the statement that "the downside risks to employment have increased in recent months," as they did in October. The Federal Reserve will announce its decision at 2 PM Washington time on December 10, followed by a press conference held by Chairman Jerome Powell.

  • Bank of America: Markets will soon digest expectations of a Fed rate cut in January.

    Bank of America stated the market may soon price in the Federal Reserve's rate cut expectation in January. (Jin10)

  • He Lifeng held a video call with U.S. Treasury Secretary Bessant and Trade Representative Greer.

    He Lifeng, China's lead for China-US economic and trade relations and Vice Premier of the State Council, held a video call with the US leads, Treasury Secretary Janet Yellen and Trade Representative Katherine Tai. The two sides had in-depth and constructive exchanges on implementing the important consensus reached by the Chinese and US heads of state at the Busan meeting and the November 24 call, focusing on carrying out pragmatic cooperation and properly addressing mutual concerns in the economic and trade field. Both sides positively evaluated the implementation of the outcomes of the China-US economic and trade consultations in Kuala Lumpur, stating that under the strategic guidance of the two heads of state, they will continue to make good use of the China-US economic and trade consultation mechanism, continuously extend the cooperation list, reduce the list of issues, and promote the sustained, stable, and positive development of China-US economic and trade relations. 

  • Hassett: No discussion with US President Trump regarding the Federal Reserve Chair (selection)

    Director of the White House National Economic Council, Hassett, stated: He has not discussed the Federal Reserve Chair (candidate) issue with U.S. President Trump and supports Bassett's views on the Federal Reserve Chair. 

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.