Another fun week in blockchain security where a compromised RubyGem account resulted in a cryptojacking code getting added to a popular Ruby library. More details were revealed on the massive Beaxy exchange hack and PlusToken scam.
Hacks
Malicious cryptojacking code found in 11 Ruby libraries - a compromised RubyGems maintainer account was used to upload multiple backdoored versions of the popular rest-client gem.
Indicators:C2 Host:
http://mironanoru.zzz.com[.]ua
Pastebin payload:https://pastebin[.]com/raw/5iNdELNX
Moscow's blockchain voting system cracked a month before election - a 15k USD bug bounty was claimed by a French security researcher who discovered a flaw in a smart contract based Moscow City Duma election system. The smart contract implemented a weak encryption scheme which could be cracked within 20 minutes on a standard personal computer.
Research
Beaxy — Incompetent. In Denial. Insolvent? - a great investigative report into the XRP partial payment hack of Beaxy exchange inc…
Keep reading with a 7-day free trial
Subscribe to Blockchain Threat Intelligence to keep reading this post and get 7 days of free access to the full post archives.