Bài đăng

Hiển thị các bài đăng có nhãn exploit

Solana dev library web3.js compromised to steal private keys

Solana’s web3.js library was compromised yesterday in a supply chain attack that installed malicious packages capable of stealing the private keys of users and draining their funds.   The attack was reported by Solana developer @trentdotsol and specifically affected versions 1.95.6 and 1.95.7 of the Solana web3.js library. Since then, a wave of Solana-based developers have come out to confirm they are not impacted by the exploit. Unaffected firms include Solflare, Phantom Wallet, and Helium.  Solana’s web3.js is a JavaScript library accessible to developers wanting to build Solana-based apps. Reports suggest that maintainers of the library may have been targeted by a phishing campaign as attackers gained access to the “publish-access account.” anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected) if you ...

DeFi vulnerability leading to $6.7M exploit 'not detected' by auditors

The project was previously audited by Trail of Bits and Hats Finance. Decentralized U.S. dollar stablecoin protocol Raft claims that despite multiple security audits, the firm still suffered a security exploit leading to the loss of $6.7 million last week. According to the project's Nov. 13 post-mortem report, a few days prior, a hacker borrowed 6,000 Coinbase-wrapped staked Ether (cbETH) on decentralized finance protocol Aave, transferred the sum to Raft, and minted 6.7 million Raft stablecoin, dubbed "R," using a smart contract glitch. The unauthorized minted funds were then swapped off the platform through liquidity pools on decentralized exchanges Balancer and Uniswap, netting $3.6 million in proceeds. The R stablecoin depegged after the attack.  According to the report: "The primary root cause was a precision calculation issue when minting share tokens, which enabled the exploiter to obtain extra share tokens. The attacker leveraged the amplified index value...

Ethereum DeFi protocol Hope Lend drained after exploit

The protocol, which had 526 Ether in total value locked, was emptied in an attack on Oct. 18. Ethereum decentralized finance (DeFi) protocol Hope Lend has next to zero assets left in its protocol after a devastating hack. According to multiple blockchain security firms, on Oct. 18, two individuals, a frontrunner who beat the original hacker after discovering the exploit , and the original hacker itself, stole a combined 526 Ether (ETH) from Hope Lend worth $825,357 at the time of publication. "The successful attacker gained 264 ETH and paid a 263 ETH bribe to an ETH validator," wrote CertiK.  Hope.money, the DeFi protocol 's developer, presented a different version of the story. In its X thread, developers claim that a single hacker ran off with 526 Ether worth of users' funds, paying 263.91 in bribes to a validator allegedly managed by Lido Finance, eventually netting a profit of 264.08 ETH. Hope.money staff said: "It is crucial to emphasize that all protocol...