BlockThreat - Week 5, 2024
Ripple | Abracadabra | Binance | CheckDot | Affine | ADC | Iron Bank | Reservoir
Greetings!
The mystery behind the $477m FTX compromise in November of 2022 may have been solved. According to the recent DoJ indictment, the theft occurred as a result of a SIM-swap attack used to bypass 2FA. That’s $477m accessible by a single compromised employee and guarded by an SMS 2FA. Wild, but unsurprising given what we know about the state of FTX security before its collapse!
A massive private key compromise of Ripple’s Chris Larsen resulted in the theft of $112.5m. Siphoning of funds lasted for more than 11 hours and was later noticed by ZachXBT a day later. Binance was able to save $4.5m, as the stolen funds quickly moved to various exchanges.
A concerning trend is emerging around rounding error exploits. Starting with the $851k Hope Lending hack in October, 2023, there was a new hack involving this attack vector almost every other week. Channels ($320k), Radiant ($4.5m), Channels again ($250k), Wise Lending ($464k), and now Abracadabra ($6.5m).
In fact, if we look at the updated Top 10 DeFi Exploitation Vectors list so far this year, Rounding Errors is now prominently occupying number 2 slot right after Stolen Private Keys and above the traditional Price Oracle Manipulation attack vectors:
Stolen Private Keys - 5 - $27.2m
Rounding Errors - 4 - $11.7m
Price Oracle Manipulation - 4 - $8.1m
Arbitrary External Calls - 4 - $3.5m
Function Parameter Validation - 1 - $3.3m
Reward Manipulation - 4 - $239k
Insufficient Function Access Controls - 2 - $323k
Reentrancy - 2 - $310k
Misconfiguration - 1 - $60k
Spear-phishing - 1
PSA: DeFi developers and auditors should add rounding errors to your top exploitation vector checks.
This week also featured a number of smaller compromises not more than $100k each. It’s as if someone is systematically sweeping all chains for the most obvious exploits like an exposed delegatecall or a weak reward calculation logic.
To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.
In other news, deepfakes are getting more realistic already tricking someone in TradFi to send $25m. Be on the lookout for high quality deepfakes hitting crypto soon!
Let’s dive into the news!
News
The Mystery of the $400 Million FTX Heist May Have Been Solved. The DoJ indictment describes a trio using social engineering tactics to SIM-swap their victims to defeat 2FA authentication.
Hacker claims to have way to ‘subpoena’ Discord, Binance, Coinbase user info.
Crime
Insta mules and crypto mixers: How tech is transforming money laundering.
Police seize record 50,000 Bitcoin from now-defunct piracy site. Movie2k operator
Theft of more than $3 million worth of cryptocurrency lands 22-year-old Portland man in prison. According to the DoJ indictment, Daniel James Junk used SIM swapping to take over victim’s cryptocurrency exchange accounts.
UK Police Uncovered $1.7 Billion Bitcoin Linked to China Fraud.
BTC-e server admin indicted for laundering ransom payments, stolen crypto.
Policy
Phishing
Cryptocurrency scams metastasize into new forms by Sophos. Pig butchering scammers are now utilizing DeFi draining kits.
Emerging web3 attack vector: Restake Farming by Blockaid.
Scammers Are Pretending to Be CoinDesk Journalists on Social Media.
Reports of an ongoing fake Coinbase login phishing campaign.
Rocket Pool X account compromised with a fake airdrop phishing link.
Scams
Cybertrace warns of deep fake crypto scam featuring Aussie billionaire. The deep fake video is pretty bad, but scammers will likely to get better in the future.
Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’.
HyperVerse founder shills new crypto project hours after $1.7B fraud charge.
Malware
DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking.
Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware.
Exposed Docker APIs Under Attack in 'Commando Cat' Cryptojacking Campaign.
Contests
Onlypwner - Liquid Staking challenge was posted.
Media
Web3 Security in 2024 X Space with pashov, juliettech, bytes032, nisedo hosted by Cyfrin Audits.
Smart Bounties hosting JohnnyTime by tomie. Smart Contract Auditing Education, Effort Before Reward, Providing Value to the World.
Smart Bounties hosting sjkelleyjr by tomie. From Developer to Smart Contract Auditor, Auditing Processes and Financial Considerations.
Research
Inside the Massive Naz.API Credential Stuffing List by Troy Hunt.
Friend.tech App UX lack of synchronization + excessive ETH sent to the contract not returned / locked by Pawel Wylecial (h0wlu).
ERC1271 Replay - 15+ Teams Affected by curiousapple.
Exchange Rate Manipulation in ERC4626 Vaults by alcueca, zimbeme.
Transient storage - The future roadblock of the Ethereum's AA landscape by Agusx1211.
D.U.C.K. - Knowledge Base provides open source risk and incident response framework for Lido node operators.
Eigen Layer - Risk FAQ. A great threat model for restaking protocols.
Tools
Napalm by Joran Honig (Consensys Dilligence). A project management utility for custom solidity vulnerability detectors.
Mesc by storm. Effortlessly operate your tools in a multichain world.
Decoder by Blocktorch. Decoding web3 data into human readable format.
Enjoy reading BlockThreat? Consider sponsoring the next edition or becoming a paid subscriber to unlock the premium section with detailed information on hacks, vulnerability, indicators, special reports, and searchable newsletter archives.
Premium Content
Keep reading with a 7-day free trial
Subscribe to Blockchain Threat Intelligence to keep reading this post and get 7 days of free access to the full post archives.