BlockThreat - Week 28, 2024
Squarespace | Dough Finance | Minterest | OpSecCloud | Linking the World |
Greetings!
We are a few weeks behind, but what a fascinating month it has been! At least $3.5M stolen this week across 8 incidents. The exact impact numbers are starting to get fuzzy due to the sheer number of attacks against smart contracts and their users, wallets, DNS infra hijacked, SSH servers hacked, and more. Let’s dive into a few of the more impactful case studies.
Regular readers of BlockThreat may get an impression that our young industry is extremely insecure with weekly reports of compromises, phishes, and rug pulls. The reality couldn’t be further from the truth! Our ability to publicly identify and openly discuss incidents has helped raise awareness and enhance security operations among new developers and users. We are learning fast! Attackers have to constantly shift their tactics as was evident by the recently published Top 10 DeFi Threats list.
Do you want to know how things are handled in the traditional security space? If we trust the almost weekly compromise notification letters that I receive by mail, then literally everything in web2 has been hacked or they don’t know about it yet. Let’s look at just one company in the news this week. AT&T, a 100+ year old $400B+ behemoth with an army of security professionals, managed to have two back to back breaches so far this year. In March, they lost 70M detailed customer records (names, social security, passcodes, etc.). This week we learned they once again lost call, text, and location records for ALL of the 110M customers back in April. It took 4 months to detect and finally decide to notify affected parties. So get ready for the latest wave of vishing.
In our world blockchain analytics companies would be hitting alarm bells minutes following the compromise, SEAL 911 activating a war room and tracking down bad actors to the darkest alleys, while the rest of the Crypto Twitter is busy dissecting the root cause and advising other projects. This is exactly what happened when someone hijacked another piece of critical web2 infrastructure - a domain registrar. CoinList was hit first with the Squarespace account hack and immediately took to twitter to alert the industry. The Security Alliance put together a list of other vulnerable projects and started working with their devs. In the meantime, Squarespace identified the wrong root cause and called the bug fixed even as domain hijacks continued.
It’s easy to be pessimistic about the state of blockchain security, but relative to web2 security we are doing just great!
The premium version of the newsletter contains detailed notes and indicators for Dough Finance, Minterest, OpSecCloud, Linking the World, GAX, OpSecCloud, Smart Bank Token, and other incidents.
To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.
In other news, massage guns are a thing and increasingly used to cheat at “tapping” crypto games like Notcoin and Hamster Kombat.
Let’s dive into the news!
News
AT&T says criminals stole phone records of 'nearly all' customers in new data breach. Stolen data include calling, text, and location metadata. AT&T reportedly paid ransom for deletion of stolen call logs after culprit allegedly detained. Erin Binns was detained in Turkey for his role in the related T-Mobile hack which was part of a mass string of thefts following the Snowflake compromise.
Blockchain Security Standards Council Launches to Protect Blockchain Systems.
regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server.
Ethereum Foundation and Immunefi Launch ‘Attackathon’ With Plans to Raise $2 Million Reward Pool.
Thefts From Crypto Hacks and Exploits Surge in First Half of 2024 report by TRM. Private key theft is the top attack vector.
Money Laundering and Cryptocurrency - Trends and new techniques for detection and investigation by Chainalysis.
Meet the hackers that can help get your crypto life savings back.
Bitcoin devs finally admitting to major mistakes in Core software. The list of disclosed bugs includes code execution, denial of service, and other bugs.
Crime
Huione Guarantee: The multi-billion dollar marketplace used by online scammers by Elliptic. DMM attackers used the exchange to launder funds.
Abduction of Hong Kong toddler marks crime wave targeting crypto owners.
RM3.4b down the drain: Bitcoin mining blamed for massive electricity theft since 2018.
SEC Secures Default Judgments in $45 Million Coindeal Fraud Case.
Philippines Charges 2 Russians in $6.2 Million XRP Theft. Former consultants for the Philippine crypto exchange Coins.ph under Betur Inc., allegedly infiltrated the company’s systems, resulting in the theft of 12.2 million XRP, valued at over PHP340 million
Former Crypto.com compliance officer charged with money laundering, extortion. Another case of malicious insider with an extortion twist.
Crypto firm Payeer fined $10M for serving Russian customers.
Global Cryptocurrency Exchange BitMEX Pleads Guilty To Bank Secrecy Act Offense.
Policy
SEC drops its investigation into BUSD stablecoin following probe into Paxos.
Conduct Versus Code May Be the Defining Question in Roman Storm Prosecution.
Phishing
Mid-Year Phishing Report by Scam Sniffer. $314M stolen from 260,000 victims in H1. Losses doubled relative to the past year.
Inferno Drainer Malicious JavaScript Analysis from the Squarespace Domain Hijacking by alp1n3.eth.
Crypto's Achilles' Heel by Rekt.
American rapper Doja Cat’s X account was hacked to promote a now-collapsed token.
The tap-estry of threats targeting Hamster Kombat players by Kaspersky.
Ethena Discord gets hacked, users advised to not click any links.
Scams
Take the Money and Run by Rekt on the wild world Metamax.
Trip.com accused of "rug pull" as it shuts down its Trekki NFTs.
Scammer returns $9.3M DAI to victim 10 months after phishing them.
Malware
Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks
Avast secretly gave DoNex ransomware decryptors to victims before crims vanished.
Media
EthCC[7] - Security Track Videos.
FIL Dev Summit 4
Incident response lessons from spaceflight by Daniel Von Fange.
How to be secure by design and not pay millions? by Damian Rusinek.
Smart Contract Ready: Mastering Audit Prep with Perfect Timing & Expectations - Michael Lewellen.
How to find all the bugs in code review by Daniel Von Fange. Notes by dravee.eth.
Holding nothing back! My notes and process from the Optimism Fault Proof Contest by Alex the Enterprenerd.
Contests
HITCON CTF 2024 Writeup by DeFiHackLabs.
Research
A Squarespace Retrospective, or How to Coordinate an Industry-Wide Incident Response by Security Alliance.
Lazarus Tactics, Techniques, and Procedures by Tayvano. Threat Version.
Announcing the Bug Bounty program pack 1.0 by SecTemplates.
Reproducing the $41M Curve reentrancy hacks with Echidna by Rappie.
The Fundamentals of Ape framework and Interacting with Blockchain using web3.py by Mahmood Mohajer.
Security Audit Checklist for Account Abstraction Wallets by Slowmist.
Unlocking Blockchain’s Potential: The Power of Threshold Signatures by ImmuneBytes.
Comprehensive Upgrade to Public Blockchain Security Audit Guide by Slowmist.
Technical Dive: Shadowing factory contracts by Emily Hsia, Jon Becker.
Finding a Critical Vulnerability in Akash Network by Chainlight.
Forge Testing Leveling by Sigma Prime.
Use Yubikeys by Beryl Blizzard.
FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi Protocols.
Vulnerability Detection in Smart Contracts: A Comprehensive Survey.
EVIntent - Darkmatter in MEV by Yellow Propeller.
Vitalik Buterin pushes for Ethereum to respond to 51% attacks in a more automated way.
Tools
gevm - An Ethereum Virtual Machine (EVM) implementation from scratch, written in Go.
Flashbots Protect Explorer.
Auditor tools and tricks thread by InfectedCrypto.
Enjoy reading BlockThreat? Consider sponsoring the next edition or becoming a paid subscriber to unlock the premium section with detailed information on hacks, vulnerability, indicators, special reports, and searchable newsletter archives.
Premium Content
Keep reading with a 7-day free trial
Subscribe to Blockchain Threat Intelligence to keep reading this post and get 7 days of free access to the full post archives.