BlockThreat - Week 50, 2020
BTC-e | Oyster | Metamask | Foxconn | PGMiner
|Peter Kacherginsky||Dec 15, 2020|
No major hacks or vulnerabilities reported this week, so we can finally catch up on a number of fun security conference talks from samczsun, Taylor Monahan, and a fireside chat with Stani, Julien and Sunny. Ledger’s Donjon posted solutions to the CTF, Metamask advises on an ongoing phishing campaign, a number of cryptocurrency companies are getting DDoSed, and other blockchain security news in this week’s edition.
Alexander Vinnik sentenced to 5 years in French prison for money laundering. Vinnik was one of the co-founders of the infamous BTC-e exchange involved in money laundering operations for various criminal enterprises such as CryptoWall ransomware, Fancy Bear APT, and others.
On December 11th, 2020 a vulnerability in Seal Finance was exploited to steal $58K worth of SEAL tokens.
Ongoing DDoS attacks targeting cryptocurrency companies including SatoshiLabs, Poloniex, The Block, and others.
Metamask warns users of an ongoing phishing campaign where attackers mimic wallet onboarding to steal seed phrases.
Foxconn factory in Mexico was attacked by the DoppelPaymer ransomware group which demands 1804.0955 BTC ransom not to leak files.
PGMiner cryptojacker targets vulnerable PostgreSQL instances in order to drop Monero miners.
Ransomware group created a portal to enable victims to pay Bitcoin for stolen MySQL database backups. http://hn4wg4o6s5nc7763[.]onion/
Fireside Chat on Security, DeFi Composability, & Interoperability featuring Stani Kulechov, Julien Bouteloup, and Sunny Aggarwal. There is an interesting discussion on front-running prevention using private, encrypted transactions sent directly to miners.
A Brief Breakdown of Monero’s Ongoing Network Attacks delves into the cat and mouse game between Monero developers and a persistent actor trying to deanonymize the network.
A Hypothetical Attack on the Bitcoin Codebase explores various scenarios of Bitcoin code base getting compromised such as rogue developers, kidnapping, unauthorized access, and others.
Early ETH2 nodes are getting slashed due to misconfigurations.
Scribble runtime verification tool by Consensys Dilligence.
Symbolic Execution with ds-test allows Ethereum developers to quickly write formal proofs for smart contracts.
Revoke is an Ethereum tool to enumerate Dapps which requested to spend excessive amounts of tokens on your behalf.
Donjon CTF - Exploiting Smart Contracts in CTF Challenges shares a solution for the EOSIO smart contract challenge.
Donjon CTF - Discovering SMPC through CTF Challenges shares a solution for the RenVM challenge.
A collection of bug bounties by Immunefi covering the entire cryptocurrency ecosystem.
Thanks for joining me this week and thank you for your donations in the latest Gitcoin round. Oh please don’t steal electricity to mine Bitcoin, unless you are Venezuelan Army trying to bypass sanctions.
-Peter Kacherginsky (iphelix)