Modern Slave
  • Home
  • Bitcoin
    What Is Bitcoin’s Role in the Global Banking Crisis?

    How Bitcoin Can Emerge Victorious Amid Global Banking Crisis

    The UK Has Created Crypto Banking Problems

    The UK Has Created Crypto Banking Problems

    Crypto Long & Short: Bitcoin's Hedge Potential

    Crypto Long & Short: Bitcoin’s Hedge Potential

    Do You Believe in (Bitcoin) Magic?

    Do You Believe in (Bitcoin) Magic?

    Amazon's NFT Plans Teased in a Receipt Mailed Friday Afternoon

    Amazon's NFT Plans Teased in a Receipt Mailed Friday Afternoon

    Bank Consolidation Threatens Freedom, Makes Case for Bitcoin

    Bank Consolidation Threatens Freedom, Makes Case for Bitcoin

    Bitcoin vs. Hyperinflation

    Bitcoin as a Hedge Against Hyperinflation: The Future of Finance

    US Calls Off Extradition Request for BTC-e Operator Alexander Vinnik

    Bitcoin From Defunct BTC-e Exchange on the Move Again: Report

    Federal Reserve Says Custodia’s Crypto-Focused Business Model Is ‘Inconsistent’ With Approval

    Federal Reserve Says Custodia’s Crypto-Focused Business Model Is ‘Inconsistent’ With Approval

  • Blockchain
  • Celsius
  • Crypto Mining
  • Ethereum
  • Exchanges
  • Forex Trading
  • Market
  • Regulation
  • More
    • XRP
    • Stellar
    • Store
  • Home
  • Bitcoin
    What Is Bitcoin’s Role in the Global Banking Crisis?

    How Bitcoin Can Emerge Victorious Amid Global Banking Crisis

    The UK Has Created Crypto Banking Problems

    The UK Has Created Crypto Banking Problems

    Crypto Long & Short: Bitcoin's Hedge Potential

    Crypto Long & Short: Bitcoin’s Hedge Potential

    Do You Believe in (Bitcoin) Magic?

    Do You Believe in (Bitcoin) Magic?

    Amazon's NFT Plans Teased in a Receipt Mailed Friday Afternoon

    Amazon's NFT Plans Teased in a Receipt Mailed Friday Afternoon

    Bank Consolidation Threatens Freedom, Makes Case for Bitcoin

    Bank Consolidation Threatens Freedom, Makes Case for Bitcoin

    Bitcoin vs. Hyperinflation

    Bitcoin as a Hedge Against Hyperinflation: The Future of Finance

    US Calls Off Extradition Request for BTC-e Operator Alexander Vinnik

    Bitcoin From Defunct BTC-e Exchange on the Move Again: Report

    Federal Reserve Says Custodia’s Crypto-Focused Business Model Is ‘Inconsistent’ With Approval

    Federal Reserve Says Custodia’s Crypto-Focused Business Model Is ‘Inconsistent’ With Approval

  • Blockchain
  • Celsius
  • Crypto Mining
  • Ethereum
  • Exchanges
  • Forex Trading
  • Market
  • Regulation
  • More
    • XRP
    • Stellar
    • Store
No Result
View All Result
Modern Slave
No Result
View All Result
Home Market

Halborn Finds Zero-Day Hacks Affecting Over 280 Crypto Networks

by Source in article
March 15, 2023
in Market
0
Web3 Security Remains a Big Question in 2023 Following 167 Major Attacks Last Year

Crypto network vulnerabilities remain at large in 2023 after a disastrous 2022. In the latest example, a security research team revealed massive risks at Dogecoin, Litecoin, and Zcash, with developers warning of additional risks. 

Cryptocurrencies use an open-source codebase designed to allow anyone to inspect, modify, and distribute the software’s source code. This openness promotes transparency, accountability, and innovation, enabling the crypto community to continually develop and improve blockchain technology.

However, it also means that the code is vulnerable to exploitation by malicious actors who can identify and exploit its weaknesses.

Different Ways Bad Actors Can Penetrate Network

Here are some ways in which open-source codebase can have vulnerabilities that could affect the security of the blockchain.

  1. Coding errors: Even the most experienced developers can make coding errors that could leave the code open to exploitation. For instance, a developer might create a vulnerability by failing to perform proper input validation, making it possible for an attacker to inject malicious code into the system. Similarly, an error in memory allocation or data handling could cause data corruption or leaks.
  2. Lack of code review: Open-source codebases rely on peer reviews to identify and fix issues in the code. However, if the codebase lacks a rigorous review process, it can lead to security gaps that attackers can exploit. Additionally, inexperienced developers who make changes without fully understanding the implications of their modifications can introduce new vulnerabilities.
  3. Forked code: Forking is a process in which developers change an existing codebase to create a new project. Although forking is expected in the open-source community, it can introduce vulnerabilities if the developers fail to incorporate security updates or make improper changes. If a forked project becomes popular, attackers may target it due to its potential vulnerabilities.
  4. Software dependencies: Many open-source projects function correctly using third-party libraries and frameworks. While these dependencies can save time and effort, they can also introduce vulnerabilities if they contain flaws or are outdated. Attackers can exploit these vulnerabilities to access sensitive data or compromise the blockchain’s integrity.
  5. Social engineering: Even if the codebase is technically sound, attackers can still exploit human weaknesses to access the system. For example, they might use phishing attacks to obtain login credentials or trick developers into introducing malicious code into the system.

Crypto Platforms See Rise in Illicit Activities

In conclusion, the open-source nature of crypto coins’ codebase provides significant benefits, such as transparency and innovation. However, it also introduces potential vulnerabilities that attackers can exploit. Therefore, developers must continually review and improve the code to ensure its security and maintain the blockchain’s integrity.

Bad actors involved in cryptocurrency hacks rose by $3.80 billion last year. Illicit activities in 2022 were up 15% on 2021 figures ($3.30 billion) and dramatically up on the $0.50 billion stolen in 2020.

Crypto Hacks from 2016 to 2022 Source: Chainalysis

According to a finding from the cybersecurity firm Halborn, 2023 could have been even more disastrous. Vulnerabilities were discovered in over 280 major blockchains. These included Dogecoin, Litecoin, and Zcash. In total, about $25 billion of assets were put at risk.

🚨 Halborn discovered massive #ZeroDay impacting Dogecoin and 280+ networks including Litecoin and Zcash, putting over $25 Billion of digital assets at risk!

🧵👇…

— Halborn (@HalbornSecurity) March 13, 2023

Highlighting the Main Loophole

Halborn researchers evaluated DOGE’s open-source code base to test for unknown exploits, or “zero-day vulnerabilities,” in its code that could target blockchain miners’ funds. 

Zero Day Vulnerabilities Source: Panda Security
Zero Day Vulnerabilities Source: Panda Security

Researchers identified two critical gaps code-named Rab13s. The Dogecoin developers later solved the errors after being alerted by the security firm. 

4/ Another zero-day identified by Halborn was uniquely related to #Dogecoin, including an RPC vulnerability impacting individual miners.

Subsequently, variants of these 0-days were also discovered in similar blockchain networks potentially leading to DoS or RCE attacks.

— Halborn (@HalbornSecurity) March 13, 2023

Severe Consequences of Malicious Events

Identifying loopholes raised more doubts as variants of these zero-days were also discovered in similar blockchain networks, including Litecoin and Zcash. Keeping the gaps in mind could lead to severe consequences. 

Firstly, concerning the P2P messaging mechanisms, malicious consensus messages can be sent to each node, causing them to shut down and exposing the network to severe risks like 51% attacks. Moving on, attackers can execute code through the public interface (RPC) as a normal node user. The likelihood of an exploit is lower since a valid credential is required to carry out the attack.

Therefore, to prevent further damage, the team at the security firm recommended upgrading all UTXO-based nodes (e.g., Dogecoin) to the latest version (1.14.6).

In a further conversation over the mail, the security firm answered a few questions asked by BeInCrypto. When asked about how Zcash, Litecoin, and Dogecoin fixed the vulnerabilities, the team replied: 

Screenshot shared by the Halborn team 
Screenshot shared by the Halborn team 

Such incidents can have implications for the broader crypto ecosystem. Steve Walbroehl, the chief security officer and co-founder of Halborn, asserted:

“The longer the issues exist on public mainnets, the more likely it is found and exploited by hackers with malicious intentions. Since we had already finished the work with Dogecoin, we had the largest stakeholder already identify a solution and fix that could be given as an example for all the other chains. It was an honorable call to action for a positive outcome with disparate projects working to help each other solve a common threat.” 

BeInCrypto contacted core developers at Dogecoin and Zcash for comments regarding this topic. However, hasn’t received a response yet. 

Disclaimer

All the information contained on our website is published in good faith and for general information purposes only. Any action the reader takes upon the information found on our website is strictly at their own risk.



Source link

Recommended

Texas Moves Against Celsius Over Unregistered Securities

Ripple Says SEC ‘Picking’ Crypto Winners and Losers in XRP Fight – BloombergQuint

1 year ago
Payments DEX Stellar First L1 to Offer Integrated Automated Market Making

Celsius Network hires advisors to prepare for potential bankruptcy

8 months ago

Popular News

    Blockchain analyst firm Elementus raises funds at $160M valuation. Clients include Celsius and BlockFi creditors - Fortune

    Dogetti, Stellar, And Monero Are The Potential Gainers For The Future – NewsWatch

    March 26, 2023
    Blockchain analyst firm Elementus raises funds at $160M valuation. Clients include Celsius and BlockFi creditors - Fortune

    5 Best Crypto Exchanges of March 2023 – BSC NEWS

    March 26, 2023
    Blockchain analyst firm Elementus raises funds at $160M valuation. Clients include Celsius and BlockFi creditors - Fortune

    Weekly Forex Forecast – NASDAQ 100 Index, Gold, Bitcoin, USD/JPY – DailyForex.com

    March 26, 2023

    Must Read

    • Pairs in Focus This Week – EUR/USD, Gold, GBP/USD, USD/JPY … – DailyForex.com
    • Dogetti, Stellar, And Monero Are The Potential Gainers For The Future – NewsWatch
    • 5 Best Crypto Exchanges of March 2023 – BSC NEWS
    • Weekly Forex Forecast – NASDAQ 100 Index, Gold, Bitcoin, USD/JPY – DailyForex.com
    • Cardano (ADA), Ripple (XRP), and Uniswap (UNI) Brace for Impact as Orbeon Protocol (ORBN) Gears Up For Another … – Analytics Insight

    Category

    • Bitcoin
    • Blockchain
    • Celsius
    • Crypto Mining
    • Ethereum
    • Exchanges
    • Forex Trading
    • Market
    • Regulation
    • Stellar
    • XRP

    Important Pages

    • Home
    • Privacy Policy
    • Terms and Conditions
    • Social Media Disclaimer
    • Medical Disclaimer
    • FTC Compliance
    • Earnings Disclaimer
    • DMCA Compliance
    • Copyright Notice
    • Anti-Spam Policy
    • Contact Us

    About Us

    We provide latest News related to CryptoCurrency.

    • Home
    • Contact Us
    • Terms and Conditions
    • Privacy Policy
    • Copyright Notice

    © 2021 Modernslave.io

    No Result
    View All Result
    • Home
    • Bitcoin
    • Blockchain
    • Celsius
    • Crypto Mining
    • Ethereum
    • Exchanges
    • Forex Trading
    • Market
    • Regulation
    • Stellar
    • XRP

    © 2021 Modernslave.io

    By continuing to browse the site you are agreeing to our use of cookies
    x Logo: Shield Security
    This Site Is Protected By
    Shield Security →

    Subscribe For Latest Updates

    Sign up to best of crypto news, informed analysis and opinions on what matters to you.

    Invalid email address
    We promise not to spam you. You can unsubscribe at any time.
    Thanks for subscribing!