Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Apr 19, 2023

Korean Web3 Enabler Participates in NFT.NYC 2023

Korean Web3 Enabler Participates in NFT.NYC 2023The Moon Labs, a Korean Web3 enabler, participated in NFT.NYC 2023 that took place in New York from April 12 to 14, according to Maeil Business Newspaper.Photo by Luca Bravo on UnsplashCollaborations with SuperchiefIn collaboration with New York-based underground artist supporter Superchief Gallery NFT, the Moon Labs advertised its decentralized autonomous organization project LeisureMetaverse on Time Square’s digital screen. Previously, the Moon Labs co-hosted NFT Korea Festival 2023 with Superchief Gallery NFT.A2E incentivization modelThe Moon Labs boasts the web 3.0 community LM Nova, the NFT marketplace PlayNomm, and its native wallet, LM Wallet. In particular, LM Nova has adopted an act-to-earn (A2E) model to provide incentives to users.About NFT.NYCNFT.NYC, one of the world’s largest NFT events, has been held annually since 2018. The show attracted not only crypto entrepreneurs but also artists, investors, and influencers. More than 500 brands took part in the event, and over 1,500 speakers delivered their talks at the conference.The Moon Labs CEO Moon Seong-eok said the company will seize this opportunity to expand global partnerships and further commit to the growth of the NFT ecosystem.

news
Policy & Regulation·

Apr 17, 2024

South Korea's prestigious university to launch philosophy major dedicated to Bitcoin

Hanyang University, one of South Korea’s most prestigious educational institutions, has embarked on launching a new major dedicated to Bitcoin and cryptocurrencies, named "Bitcoin Philosophy" at its graduate school. Yoon Seong-ho, the vice dean of the College of Humanities, will spearhead organizing the new major and overseeing its courses, according to local media ETNews.  The Bitcoin Philosophy major merges two different academic fields – philosophy and emerging blockchain studies. This unprecedented combination has drawn the attention of many local crypto investors and industry insiders. Typically, crypto or blockchain experts in Korea have educational backgrounds in computer science, software engineering, information security studies or cryptology. Photo by Karolina Grabowska on PexelsHumanistic approach to cryptocurrency The school stated that the planned major will be taking a humanistic approach to Bitcoin and cryptocurrencies, focusing less on their technological aspects. The specifics of the courses, however, are yet to be disclosed.  Hanyang University is no stranger when it comes to blockchain and cryptocurrencies. The institution has already established the Department of Blockchain Computing and Cryptoeconomics back in 2018, which started enrolling students the following year. Currently, around 20 experts from across various fields including engineering, business management, law and medicine, serve as faculty members.  Furthermore, the school is considering a proposal to establish a "Bitcoin Philosophy Research Center" on campus and dedicated courses for the Advanced Management Program (AMP). If approved, admissions for the new crypto major could open as early as next year.  

news
Web3 & Enterprise·

Mar 19, 2025

amana makes 300 additional cryptocurrencies available to app users

amana, a Dubai-based neo-broker, has announced that it is adding another 300 cryptocurrencies to its app. 450 crypto assetsA neo-broker is an online-based digital investment service provider that leverages technology and online tools to make investing and trading more accessible to the broader investing and trading public. The firm announced the product expansion via a press release published on its behalf by GlobeNewswire on March 17. Prior to the announcement, amana had offered its service users access to 150 cryptocurrencies. Expanding the range to a total of 450 cryptocurrencies makes it the leading broker in the Middle East and North Africa (MENA) region in terms of the breadth of digital assets it has made accessible to users.Photo by Christoph Schulz on UnsplashAll-in-one service offeringThe company described the offering as “unmatched,” allowing amana to firmly position itself as the go-to platform where the seamless trading of both traditional and digital assets is concerned. amana believes that its offering fills a gap in the market. Most platforms, it claims, either cater to the digital assets market or the traditional finance market. The platform sees itself as an all-in-one solution, making it unnecessary for investors and traders to create multiple accounts. Speaking to that gap in the market that the company wants to exploit, amana CEO Muhammad Rasoul stated: “We’re making it easier than ever for our customers to trade digital assets alongside stocks, forex, and commodities—all in one place, with zero hassle.” The firm added that the expansion isn’t just about offering a greater selection of digital assets. The announcement said that “it’s about seamless access, competitive pricing, and a frictionless trading experience.” The company described the amana app as “intuitive,” with the ability to empower both seasoned traders and new investors through the ease of trading within a few taps. Alongside the 450 digital assets, the platform provides users with access to U.S. stocks, FX, commodities, gold and global exchange-traded funds (ETFs). amana also facilitates users to trade using leverage and to avail of automated investment plans. Futures products and contracts for difference (CFDs) complete the product offering lineup. Having first launched in September 2022, the platform claimed recently that it has over 320,000 users accessing the service. Besides Dubai, amana has offices in London, Limassol and Beirut. The company is not the first online broker to bridge the gap between traditional finance and digital assets. American commission-free trading platform Robinhood has made in-roads into crypto. The company has plans to roll out its crypto offerings to the Singapore market later this year.  UK-based neobank Revolut has expanded into the world of investing, including crypto as part of that offering. It emerged last year that the firm has plans to launch a stablecoin. flatexDEGIRO, a European online broker that offers stocks, bonds and exchange-traded funds (ETFs), outlined last November that it plans to extend its product offering to include cryptocurrencies.

news
Loading