Top

Crypto vulnerability uncovered with $1B in digital asset exposure

Policy & Regulation·November 22, 2023, 3:00 AM

Security vulnerabilities in the validator infrastructure of InfStones, an established infrastructure provider, have been disclosed by Tel Aviv-headquartered cybersecurity firm dWallet Labs.

Photo by Brett Jordan on Unsplash

 

Blockchain network validator vulnerability

In a detailed Medium blog post published on Tuesday, dWallet Labs shed light on a series of vulnerabilities that, when exploited, could potentially allow attackers to gain full control, execute code and extract private keys from numerous validators on major blockchain networks. Cryptocurrencies such as ETH, BNB, SUI, APT and others were identified as at risk, with potential direct losses estimated to exceed one billion dollars.

The vulnerabilities discovered by dWallet Labs opened the door for attackers to compromise the private keys of validators across multiple blockchain networks, putting over one billion dollars of staked assets at risk. In response to the findings, InfStones, a Web3 infrastructure platform, also released a statement on Tuesday acknowledging the potential threat. However, its representative, Darko Radunovic, disputed the figures provided by dWallet Labs in a statement sent to Cointelegraph. Radunovic stated that the vulnerabilities identified in the production environment account for below 0.1% of their active nodes launched to date, emphasizing that the impact would be limited to a small fraction of their operational nodes.

According to InfStones, “237 instances were in scope, of which 212 instances were deployed for our development and testing purposes, and 25 freshly deployed instances in the production environment.”

 

Mitigating steps taken

The company detailed the immediate actions taken to mitigate the vulnerabilities, including shutting down the affected ports, as well as rotating all credentials and keys within their platform. An internal review conducted by InfStones revealed no additional adverse effects. Notwithstanding that, the company took the additional step of hiring an external security firm to audit its systems and policies.

Meanwhile, dWallet Labs Founder and CEO Omer Sadika shared his thoughts on the X platform as to how he believes such events should be handled. Sadika wrote:

”The worst way to handle a cybersecurity vulnerability is not taking responsibility and lying. We were super open and transparent with the goal of eliminating the risk to web3. My take: it’s not about whether you are fully secure or not, because no one is, it’s about how you handle it and maintain the trust with your partners and customers.”

The collaboration between dWallet Labs and InfStones sheds light on the ongoing challenges faced by the cryptocurrency industry in maintaining the security and integrity of blockchain networks. While vulnerabilities were identified and addressed, the incident underscores the importance of proactive security measures to safeguard the assets and data within the rapidly evolving landscape of digital assets.

More to Read
View All
Web3 & Enterprise·

Nov 16, 2023

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaar

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaarCherry, a blockchain-powered donation platform, is set to hold a bazaar with non-profit organization (NPO) Yana at POSCO CHANGeUP GROUND in Seoul from Friday to Saturday. The objective of this event is to support children’s homes and care leavers.Photo by Markus Winkler on UnsplashMedical expense support for children’s homesThe bazaar is being organized by ongoing sponsors of Cherry and Yana. This event will feature sales of corporate-sponsored items, with the proceeds dedicated to assisting with medical and various other expenses at children’s homes and for those who have left care. Visitors can look forward to an array of products from companies like Solideo Systems, Jungsaemmool Beauty, Esther Formula, and Rebuy For You. Moreover, the bazaar will showcase a collection of dresses and cherished items from celebrated personalities, including actresses Shin Ae-ra and Park Jin-hee, comedian Park Na-rae and Kpop singer Sandara Park.In addition to sponsored items, the bazaar will offer a wide range of items, including clothing, shoes, cosmetics, eyewear, and food. A representative from Cherry mentioned that all the vendors have committed to donating a part of their sales proceeds. This arrangement allows visitors to enjoy their shopping experience while also contributing to socially responsible consumption, as their purchases will lead to donations.Attendance at the bazaar is priced at KRW 10,000 (approximately $7.7), and registration for the event is available through the Cherry app. For those unable to attend in person, there’s still an opportunity to contribute by purchasing a ticket, allowing for donations from anywhere around the world.Blockchain transparencyCherry is Korea’s first blockchain-based donation platform, designed to foster a culture of transparent donations by recording all donation flows on the blockchain. Since its inception in 2019, the platform has attracted over 380 donor organizations running more than 1,900 campaigns. The cumulative donations have surpassed KRW 11 billion.Yana allocates 100% of its donations to support projects for children’s homes and individuals transitioning out of care. This commitment to transparency in their donation processes is facilitated through the use of the Cherry platform.

news
Web3 & Enterprise·

May 13, 2024

Harvest Global CEO considers offering BTC and ETH ETFs to mainland Chinese investors

Tongli Han, the CEO and CIO of Harvest Global, has expressed openness to the possibility of applying to offer Bitcoin and Ether exchange-traded funds (ETFs) to mainland Chinese investors through the Stock Connect program. This consideration is contingent on favorable developments in the next two years. Harvest Global, along with China Asset Management (ChinaAMC) and Bosera HashKey, recently launched Asia's first spot Bitcoin and Ether ETFs on the Hong Kong Stock Exchange, aligning with Hong Kong's ambition to establish itself as a global cryptocurrency hub. Han's remarks were delivered during the Bitcoin Asia conference in Hong Kong, underscoring the potential for expansion into the mainland Chinese market.Photo by Jimmy Chan on PexelsUncertain regulatory landscape and growth prospectsDespite the introduction of spot crypto ETFs in Hong Kong, uncertainty looms over mainland Chinese investors' access to such products through the Stock Connect program. China's regulatory stance towards the cryptocurrency industry remains stringent, with most commercial crypto activities prohibited on the mainland. While there is speculation regarding the potential inclusion of crypto ETFs in the eligible securities list of the Stock Connect program, approval remains uncertain. The debut of Hong Kong's spot crypto ETFs recorded modest trading volumes compared to their U.S. counterparts, signaling a cautious start. However, Han anticipates the potential for growth in the Asia region, envisioning the Hong Kong ETFs to potentially double the size of their U.S. counterparts. Despite differing opinions on growth prospects, market observers highlight challenges such as the relatively small size of the Hong Kong ETF market and restrictions on mainland Chinese investors' participation, underscoring the complexities facing the expansion of crypto ETFs in the region. 

news
Markets·

Dec 21, 2023

Bitcoin layer-2 project Elastos sees ELA token surge

Bitcoin layer-2 project Elastos sees ELA token surgeSingaporean blockchain developer Elastos has unveiled its BeL2 layer-2 network set to run on top of the Bitcoin blockchain, eventually prompting a token price surge.50% increaseThe project aims to address challenges such as transaction volume limitations and the complexity of programmable contracts within the Bitcoin ecosystem. Despite the initial muted response from the crypto community after the late November announcement, Elastos’ native token, ELA, has experienced an extraordinary surge on Wednesday. Over the course of the past 24 hours, the token’s unit price has jumped from $2.06 to $3.09. That represents a 50% increase.Photo by Kanchanara on UnsplashBringing smart contracts to BitcoinOn Dec. 2, the project released its BeL2 whitepaper, describing it as “a transformative approach to enhancing Bitcoin’s functionality.” BeL2 has the potential to bring about significant advancements by leveraging SmartWeb technology to introduce staking solutions and incorporate zero-knowledge proof technology.A zk proof is a cryptographic method through which one party can prove to another party that a particular statement is true, all the while avoiding the leakage of any additional information aside from confirming the statement is true. Up until now, zk proofs have been largely the preserve of Ethereum-centric projects.Alongside zk proofs, BeL2 will utilize Bitcoin-powered Ethereum Virtual Machine (EVM) smart contracts. This approach is expected to expedite transactions within the network and introduce governance through a decentralized model.BeL2 roadmapThe roadmap for BeL2 includes a three-month development phase for a proof-of-concept, followed by an additional three months dedicated to the decentralization of relayers. These relayers, acting as third-party services facilitating communication and data transactions between different blockchain networks, play a crucial role in the overall implementation of BeL2.Elastos envisions BeL2 as a Layer 2 network built on Bitcoin, introducing sophisticated BTC transactions on its blockchain. Beyond staking, the network aims to provide direct yield and affordable transactions on native decentralized applications. The move marks a significant shift, allowing Bitcoin holders to stake their assets directly, unlocking potential value exceeding $700 billion.Looking ahead, Elastos plans to chart the decentralized finance (DeFi) course on BTC by enabling smart contract deployment and irreversible digital agreements between participants.As interest in Bitcoin continues to rise, driven by innovations like inscriptions and spot ETF discussions in the United States, Elastos’ BeL2 initiative is garnering greater attention, relative to the potential to usher in a new era of possibilities for the world’s most popular digital currency.The project was founded in 2017 by Rong Chen, a former senior software engineer at Microsoft. Taking to the X social media platform earlier this month, Chen wrote:“I don’t see any other paths to the final #Web3 destination except:(1) A #BTC merge mining blockchain, plus smart-contract sidechains as needed;(2) A #SmartWeb operating system (OS) to facilitate personal node to own data, plus personal-node to personal-node direct communication links;(3) Personal Cloud Compute (#PC2) Runtime sandbox, so individuals are on the same footing as big brothers;(4) Digital goods software-development-kits (embedded OS #SDKs), entrusting your data to nobody else but yourself, i.e., your own code to check access tickets/tokens before loading and rendering data.”The Elastos ecosystem employs three-layer consensus mechanisms: auxiliary proof-of-work, proof-of-integrity and bonded proof-of-stake. It’s hoped that the project can improve upon the original layer-2 solution for Bitcoin, the Lightning Network, which has had issues in terms of scalability and centralization risk.

news
Loading