Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Policy & Regulation·

Oct 24, 2023

Seoul and Baobab Partners Face Controversy Over Unpaid Prize Winnings for SWF2023 Hackathon

Seoul and Baobab Partners Face Controversy Over Unpaid Prize Winnings for SWF2023 HackathonThe city of Seoul has come under public scrutiny for failing to pay the winners of the Seoul Web3 Festival (SWF2023) Hackathon a cash prize worth KRW 150 million (approximately $112,000). The Seoul Metropolitan Government has argued that since it was simply a naming rights sponsor, the responsibility for paying the prizes lies with Baobab Partners, who co-hosted the event. However, critics argue that the city did not properly vet Baobab Partners more rigorously before hosting the event.Photo by okaybuild on PixabayUnpaid prizes lingerThe SWF2023 Hackathon took place from July 31 to August 2 at Dongdaemun Design Plaza (DDP) and was co-hosted by the city of Seoul, the Seoul Design Foundation, and Baobab Partners. It offered a total prize pool of KRW 150 million attracting 417 participants who made up 115 teams.However, although over two months have passed since then, the winners are yet to be paid their prize money. “Baobab Partners initially proposed the SWF2023 event, and they were responsible for gathering the necessary sponsorship funds to run the event,” said a city representative.According to industry sources on Monday, the company’s CEO, Choi Jin-beom, issued a handwritten apology last Friday regarding the incident. “We promised to pay the winners by today, but we were unable to deliver on that promise. We explored multiple avenues, including investors, new contractors, and other assets, but were ultimately unable to secure the funds to do so,” he said. “The narrative that the funds were diverted elsewhere or invested in cryptocurrencies or stocks is untrue,” he added, clarifying that related information was transparently disclosed to the city of Seoul.Baobab Partners’ swift rise raises industry eyebrowsBaobab Partners had previously participated as an event planner at last year’s Blockchain Week in Busan, which turned out to be a success. “We also spoke with the Busan city government, who gave a positive opinion of the company,” the representative added. It was under this context that Seoul entered into a naming rights agreement with Baobab Partners. The agreement stipulated that the company would be in charge of attracting and managing sponsorships, and the prize money and operational costs would be covered by corporate sponsorship funds.Nevertheless, questions have arisen within the industry about Baobab Partners’ short track record and its successive collaborations with public organizations. Baobab Partners is a startup that was founded in May 2021. In November of the same year, the firm signed memoranda of understanding with three blockchain companies during NFT Busan 2021, a large-scale NFT fair held in the southern port city to share the latest blockchain trends. As a result of its efforts, it was listed alongside prominent companies such as Coinone and Onther despite only six months passing since its establishment. Subsequently, Baobab Partners relocated from Seoul to Busan, and the following year, it participated as an event planner at Blockchain Week in Busan.Accumulating allegationsSpeculation suggests that this success was not solely due to Baobab Partners’s capabilities. The company’s CEO is believed to have political connections, according to an anonymous industry insider. Choi denied such claims and stressed that its technical expertise should not be downplayed, citing the fact that Baobab Partners was the first entity in Korea to develop virtual reality (VR) banking technology and had received a KRW 15 billion investment from Finger, a KOSDAQ-listed company.Baobab Partners has also been mired in controversy over supposedly unpaid wages. In response to a claim made by an industry source that many former employees of Baobab Partners have still not received their due wages, a Seoul representative stated that there is no such dispute according to conversations with company representatives, seeking to dispel the dispute. Choi further explained, “We didn’t have wage disputes until last year. The difficulty in paying wages began in January this year due to the failure to execute promised investment funds.”The city said that it is currently conducting legal examinations and looking into necessary measures for two matters involving Baobab Partners, including the handling of hackathon winnings.

news
Web3 & Enterprise·

Nov 16, 2023

Korean pro female golfers to compete in WEMIX golf tournament this weekend

Korean pro female golfers to compete in WEMIX golf tournament this weekendThe world’s first blockchain-assisted golf tournament, WEMIX Championship 2023, will take place this weekend at the Haeundae Beach Golf and Resort in Busan. 24 female golfers from the Korea Ladies Professional Golf Association (KLPGA) — including the top 20 who earned the most WEMIX points during the preliminary Race to WEMIX Championship — are set to compete.Photo by Mick De Paola on UnsplashBringing blockchain to sportsNotably, blockchain technology is incorporated into all aspects of the tournament. This includes dynamic Real World Event NFTs that are available via NFT Is Life Evolution (NILE), Wemade’s decentralized autonomous organization (DAO) and NFT platform. These NFTs come in two categories: “ticket NFTs,” which function as admission tickets and food or parking vouchers for spectators, and “prize NFTs,” which contain WEMIX token awards for tournament winners. The total prize budget is one million WEMIX, or approximately KRW 2.4 billion ($1.9 million) as of 4:30 p.m. on Thursday (local time). The first-place winner will receive 250,000 WEMIXThe tournament venue will also have a Gallery Plaza with various activities and showcases for visitors to enjoy, like exhibitions for Volvo’s newest vehicles, photo zones and putting games. The food and beverage zone will serve BAYC-themed burgers from Californian burger brand Bored and Hungry, as well as beverages from Hide Me, Please, a Korean food and beverage NFT membership brand. BAYC is the globally renowned IP from the Bored Ape Yacht Club NFT collection.The competition’s top playersMeanwhile, the subject of many golfing enthusiasts’ interest is Im Jin-hee, the golfer who won the most WEMIX points during the Race to WEMIX Championship with 6,450 points. She secured 90,000 WEMIX for earning the top ranking, adding another personal achievement to her successful season this year. Coming in second and third place were Lee Ye-won and Kim Min-byeol. The final results of the competition were determined based on the golfers’ performances in the Lotte Rent-a-Car’s Ladies Open and the SK Shieldus-SK Telecom Championship.

news
Web3 & Enterprise·

Jan 15, 2024

Lotte Data Communication showcases metaverse and EV charging platform at CES 2024

Lotte Data Communication, the IT service management unit of South Korean conglomerate LG Group, brought its hyperrealistic metaverse platform Caliverse and electric vehicle charging platform EVSIS to the stage at CES 2024, attracting great interest from stakeholders from around the world, according to an article by South Korean news outlet KG News.Photo by GuerrillaBuzz on UnsplashExploring tomorrow's technologyCES is one of the biggest annual tech conventions in the world organized by Consumer Technology Association, where companies and other industry leaders gather in Las Vegas to showcase their innovations and visions for a future led by advanced technology. This year’s event was held from Jan. 9 to 12.  AI takes the spotlightIn particular, user-engaging technologies such as generative AI received much attention at the convention, such as AI mobile scanning, which allows anyone to take a picture of their product with a mobile device and virtually create their own digital object in less than five minutes. Another new technology called metaverse live streaming allows users to interact with each other in the virtual space in real-time by replicating their appearance. Standing at the forefront of the IT industryLotte’s Caliverse platform provides deeply immersive content based on world-class technologies such as ultra-high-definition VR shots, image synthesis and real-time rendering graphics. It can also be experienced through a head-mounted display (HMD) as well as most other electronic devices such as 3D monitors, PCs and smartphones, maximizing user accessibility. The company also showcased various EV chargers and digital platforms that are used in its other new product EVSIS, gaining popularity among visitors at the event. Lotte aims to further establish itself as a global market leader in the IT industry based on these cutting-edge platforms.

news
Loading